HomeSecurityD-Link: Firmware encryption key exposed in unencrypted image

D-Link: Firmware encryption key exposed in unencrypted image

Security researchers have found a method to decrypt firmware images embedded in D-Link routers.

Firmware is the piece of code that powers low-level functions in hardware devices.

Companies encrypt firmware images on their devices to prevent reverse engineering by competitors and threat actors and to prevent their customers – (or better yet malware) – from replacing the device with custom firmware.

D-Link firmware

To decrypt anything, one would need either the secret decryption key or a means to break the algorithm . If firmware images are indeed encrypted, how could they be decrypted so easily?

D-Links encrypted firmware image analysis

At the beginning of his analysis, Starke had downloaded the latest version of D-Link firmware (1.11B02) from the support website and proceeded to use Binwalk to analyze.

Binwalk is a simple reverse engineering utility specifically designed for firmware extraction and analysis.

To the researcher's surprise, Binwalk revealed nothing:

D-Link: Firmware encryption key exposed in unencrypted image

The result was a direct indication that the firmware was encrypted.

Interestingly, decompressing an older version “1.02B03” obtained from the same D-Link support website revealed two firmware files:

  • DIR3040A1_FW102B03.bin
  • DIR3040A1_FW102B03_unencrypted.bin

The presence of one binary ending in “…_uncrypted.bin” was a direct indication that it was potentially unencrypted, while the other was probably encrypted.

Binwalk analysis of “DIR3040A1_FW102B03_uncrypted.bin” revealed some useful information:

firmware

The above information told researchers that the image contained an unencrypted firmware binary that they could then extract and analyze for stored decryption keys.

“Bingo, a uImage header and the accompanying filesystem. We can extract it using binwalk -eM DIR3040A1_FW102B03_uncrypted.bin. Looking at the filesystem, the first thing I did was look for certificates,” Starke explains on his blog.

Keys embedded in older firmware

Upon further analysis, his suspicions were correct and both decryption and encryption keys were found embedded in the binary.

D-Link firmware

In addition to the key and certificate files, there was also a program called /bin/imgdecrypt, which is the decryption tool for encrypted images.

D-Link firmware

After taking a series of steps, the researcher was able to create the environment to sufficiently allow decryption of the latest version 1.11B02.

Running the binary imgdecrypt against the encrypted firmware image revealed the secret key: C05FBF1936C99429CE2A0781F08D6AD8

D-Link

“It not only extracts the key to decrypt the firmware image file, but also places the decrypted version in /tmp/.firmware.orig,” the post states.

This means that a reverse engineer could now proceed to analyze the firmware image that had been encrypted.

The same technique was used earlier this month by another security researcher, Rick Sanchez, who did an in-depth static analysis of the decryption algorithm in a blog post that was divided into several parts.

Sanchez, who originally discovered this flaw, relied on purchasing a physical D-Link device, which can cost up to $200, as explained in Part 1 of his post.

As the secret key remains the same for all encrypted firmware (on any device), obtaining a previous image from a support website will achieve the same goal.

Both researchers discovered the flaw independently at different times, and there are clear differences in their research approaches and the tools used.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS