Phlashing denial of service attack, the new hype


Imagine how surprised we were to discover that by accidentally bricking our router we were executing a brand new attack: Phlashing Denial Of Service (PDOS). This week at EUSecWest, researcher [Rich Smith] will present the theoretical PDOS attack. Instead of taking over control of an embedded system, the attacker turns it into a nonfunctioning brick by flashing it with a broken firmware. Anyone who has flashed a device knows the danger of interrupting the procedure.

Embedded systems, like wireless routers, network cameras, and printers require remote access to be upgraded. This could be over the network or just a USB cable. Unfortunately most devices go unpatched because of this lack of easy access. The upgrade procedure can be very insecure too. The last time we flashed a custom firmware on our La Fonera we had to set up a TFTP server for it to download the firmware from. The TFTP protocol has no authentication, so anyone could pose as the server and offer a bad firmware for download. Many embedded system upgrade tools use TFTP because of its ease of implementation and low hardware overhead.

The PDOS attack hasn't been seen in the wild and we don't expect to. Malware is a business and destroying hardware doesn't seem to have much income potential. The article presents this as an alternative to maintaining a botnet to perform a DDOS. With a DDOS, you deny the service, ask for ransom, and return service when they pay. With PDOS, you threaten to deny their service, they don't pay, and then you destroy their equipment and get nothing. We agree with [HD Moore] that a more successful attack would be installing your own custom firmware that gives you full control of the system and full access to the network to do as you please.

Outside of griefing, the PDOS attack is not a threat. In any case, firmware upgrade procedures for embedded devices need to be improved.

[via /.]

Recent Posts

Reader Comments

(Page 1)

Add your comments

Please keep your comments relevant to this blog entry: inappropriate or purely promotional comments may be removed. Email addresses are never displayed, but they are required to confirm your comments. To create a live link, simply type the URL (including http://) or email address and we will make it a live link for you. You can put up to 3 URLs in your comments. Line breaks and paragraphs are automatically converted — no need to use <p> or <br> tags.

Your name (required):

Your email address (required, will not be shown to the public):

Your site’s URL (optional):

Do you want us to remember your personal information for next time?
   
Add your comments:

hack a day serves up a fresh hack each day, every day from around the web and a special how-to hack each week.

send us your hacks

have a hack you'd like to see here? tell us about it

Hacks
aibo hacks (1)
cellphones hacks (60)
cons (47)
contests (20)
daily (58)
digital cameras hacks (66)
downloads hacks (9)
gameboy hacks (33)
google hacks (5)
gps hacks (35)
HackIt (15)
handhelds hacks (54)
home entertainment hacks (132)
home hacks (16)
how-to (13)
ipod hacks (73)
laptops hacks (44)
laser hacks (28)
macs hacks (38)
misc hacks (712)
news (81)
pcs hacks (135)
peripherals hacks (154)
playstation hacks (47)
podcasts (8)
portable audio hacks (42)
portable video hacks (24)
robots hacks (86)
roundup (1)
security hacks (12)
tablet pcs hacks (3)
tivo hacks (6)
tool-hacks (6)
transportation hacks (81)
wii hacks (14)
wireless hacks (81)
xbox hacks (48)

resources

rss newsfeeds

Powered by Blogsmith