the.bay.news

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

lemmy.world
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
cross-posted from: https://mander.xyz/post/56484546 [https://mander.xyz/post/56484546] > Here is the technical report: ENDLESSDOORS Is Phoning Home. Pick Up. [https://web.archive.org/web/20260807062545/https://www.vulncheck.com/blog/zbt-endlessdoors] > > … > > Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink. > > According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. > > They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The “phone home” implants have been codenamed ENDLESSDOORS. > > “ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux),” Jacob Baines, VulnCheck Chief Technology Officer, said. “Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server.” > > “The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell.” > Cybersecurity > > The “kworker” worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that’s configured to contact the following - > > …

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.