Breaking
February 7, 2025

This Week in Security: Medical Backdoors, Strings, and Changes at Let’s Encrypt Jonathan Bennett | usagoldmines.com

There are some interesting questions afoot, with the news that the Contec CMS8000 medical monitoring system has a backdoor. And this isn’t the normal debug port accidentally left in the firmware. The CISA PDF has all the details, and it’s weird. The device firmware attempts to mount an NFS share from an IP address owned by an undisclosed university. If that mount command succeeds, binary files would be copied to the local filesystem and executed.

Additionally, the firmware sends patient and sensor data to this same hard-coded IP address. This backdoor also includes a system call to enable the eth0 network before attempting to access the hardcoded IP address, meaning that simply disabling the Ethernet connection in the device options is not sufficient to prevent the backdoor from triggering. This is a stark reminder that in the firmware world, workarounds and mitigations are often inadequate. For instance, you could set the gateway address to a bogus value, but a slightly more sophisticated firmware could trivially enable a bridge or alias approach, completely bypassing those settings. There is no fix at this time, and the guidance is pretty straightforward — unplug the affected devices.

Reverse Engineering Using… Strings

The Include Security team found a particularly terrifying “smart” device to tear apart: the GoveeLife Smart Space Heater Lite. “Smart Space Heater” should probably be terrifying on its own. It doesn’t get much better from there, when the team found checks for firmware updates happening over unencrypted HTTP connections. Or when the UART password was reverse engineered from the readily available update. It’s not a standard Unix password, just a string comparison with a hardcoded value, and as such readily visible in the strings output.

Now on to the firmware update itself. It turns out that, yes, the device will happily take a firmware update over that unencrypted HTTP connection. The first attempt at running modified firmware failed, with complaints about checksum failures. Turns out it’s just a simple checksum appended to the firmware image. The device has absolutely no protection against running custom firmware. So this leads to the natural question, what could an attacker actually do with access to a device like this?

The proof of concept attack was to toggle the heat control relay for every log message. In a system like this, one would hope there would be hardware failsafes that turn off the heating element in an overheat incident. Considering that this unit has been formally recalled for over 100 reports of overheating, and at least seven fires caused by the device, that hope seems to be in vain.

AMD Releases

We wrote about the mysterious AMD vulnerability a couple weeks ago, and the time has finally come for the full release. It’s officially CVE-2024-56161, “Improper signature verification in AMD CPU ROM microcode patch loader”. The primary danger seems to be malicious microcode that could be used to defeat AMD’s Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) technology. In essence, an attacker with root access on a hypervisor could defeat this VM encryption guarantee and compromise the VMs on that system.

This issue was found by the Google Security Team, and there is a PoC published that demonstrates the attack with benign effects.

The Mirai Two-fer

The Mirai botnet seems to have picked up a couple new tricks, with separate strains now attacking Zyxel CPE devices and Mitel SIP phones. Both attacks are actively being exploited, and the Zyxel CPE flaw seems to be limited to an older, out-of-support family of devices. So if you’re running one of the approximately 1,500 “legacy DSL CPE” devices, it’s time to pull the plug. Mitel has published an advisory as well, and is offering firmware updates to address the vulnerability.

Let’s Encrypt Changes

A service many of us depend on is making some changes. Let’s Encrypt is no longer going to email you when your certificate is about to expire. The top reason is simple. It’s getting to be a lot of emails to send, and sending emails can get expensive when you measure them in the millions.

Relatedly, Let’s Encrypt is also about to roll out new six-day certificates. Sending out email reminders for such short lifetimes just doesn’t make much sense. Finally from Let’s Encrypt is a very useful new feature, the IP Address certificate. If you’ve ever found yourself wishing you didn’t have to mess with DNS just to get an HTTPS certificate, Let’s Encrypt is about to have you covered.

Bits and Bytes

There’s a Linux vulnerability in the USB Video Class driver, and CISA has issued an active exploit warning for it. And it’s interesting, because it’s been around for a very long time, and it was disclosed in a Google Android Security Bulletin. It’s been suggested that this was a known vulnerability, and was used in forensic tools for Android, in the vein of Cellebrite.

Pretty much no matter what program you’re using, it’s important to never load untrusted files. The latest application to prove this truism is GarageBand. The details are scarce, but know that versions before 10.4.12 can run arbitrary code when loading malicious images.

Ever wonder how many apps Google blocks and pulls from the app store? Apparently better than two million in 2024. The way Google stays mostly on top of that pile of malware is the use of automated tools, which now includes AI tools. Which, yes, is a bit terrifying, and has caused problems in other Google services. YouTube in particular comes to mind, where channels get content strikes for seemingly no reason, and have trouble finding real human beings at Google to take notice and fix what the automated system has mucked up.

And finally, echoing what Kee had to say on the subject, cryptocurrency fraud really is just fraud. And [Andean Medjedovic] of Canada found that out the hard way, after his $65 million theft landed him in jail on charges of wire fraud, computer hacking, and attempted extortion.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Hackaday Podcast Episode 307: CNC Tattoos, The Big Chill in Space, and PCB Things Al Williams | usag...

Split-Flap Clock Makes a Nice Side Quest in Larger Project Dan Maloney | usagoldmines.com

Quix Furniture for Modular Furniture Fun Navarre Bartz | usagoldmines.com

RC Cars With First Person Video, All With An ESP32 Jenny List | usagoldmines.com

Solid Tips for Designing Assistive Technology (Or Anything Else, Really) Donald Papp | usagoldmines....

Social Engineering Scams Costing Coinbase Users $300,000,000+ per Year: On-Chain Analyst Mark Emem |...

Young Hacker Used ‘Glitch’ To Steal $48,800,000 in Crypto From Trading Platform KyberSwap, Allege Fe...

Bank of America Sued for Allegedly Short-Changing Customers With ‘Bait and Switch’ Credit Card Tacti...

T1 is a RISC-V Cray Al Williams | usagoldmines.com

Running Doom on an Apple Lightning to HDMI Adapter Maya Posch | usagoldmines.com

A Great Use for AI: Wasting Scammers Time! Al Williams | usagoldmines.com

Lorentz Cannon Fires Lightning Al Williams | usagoldmines.com

How Do We Deal With Microplastics In The Ocean? Lewin Day | usagoldmines.com

Lorem Ipsum 36? Dolor Sit Amet Keyboard! Kristina Panos | usagoldmines.com

Lorem Ipsum 36? Dolor Sit Amet Keyboard! Kristina Panos | usagoldmines.com

A Tube, The Wooden Kind Al Williams | usagoldmines.com

This Thermometer Rules! Jenny List | usagoldmines.com

Making Products for Fun and (Probably No) Profit Navarre Bartz | usagoldmines.com

Investigating Electromagnetic Magic in Obsolete Machines Bryan Cockfield | usagoldmines.com

Good-Looking HAT Does Retro Displays Right Kristina Panos | usagoldmines.com

FLOSS Weekly Episode 819: Session, It’s all Abot the Metadata Jonathan Bennett | usagoldmines.com

Investigating Why Animals Sleep: From Memory Sorting to Waste Disposal Maya Posch | usagoldmines.com

Hacking the 22€ BLE SR08 Smart Ring With Built-In Display Maya Posch | usagoldmines.com

What Happens If You Die In Space? Lewin Day | usagoldmines.com

Breaking: USPS Halts Inbound Packages From China and Hong Kong Tom Nardi | usagoldmines.com

Breaking: USPS Halts Inbound Packages From China and Hong Kong Tom Nardi | usagoldmines.com

How 3D Printing Helps Bring USS Cod Memorial to Life Tom Nardi | usagoldmines.com

Custom PCB is a Poor Man’s Pick and Place Dan Maloney | usagoldmines.com

Bank Employee Allegedly Drains $2,300,000 From Bank Accounts in Massive Fraud Scheme: Report Alex Ri...

The Lowest-Effort Way Yet To Make 3D Printed Lenses Clear Donald Papp | usagoldmines.com

Inside Project Delilah Al Williams | usagoldmines.com

What Is the Hour? It’s XVII o’ Clock Kristina Panos | usagoldmines.com

Cyberbass Brings Bass Guitar To Modern Era Bryan Cockfield | usagoldmines.com

What Is the Hour? It’s XVII o’ Clock Kristina Panos | usagoldmines.com

Telling Time Used to be a Ball Al Williams | usagoldmines.com

Telling Time Used to be a Ball Al Williams | usagoldmines.com

Freedesktop and Alpine Linux Looking for New Hosting Maya Posch | usagoldmines.com

A Closer Look At The Tanmatsu Jenny List | usagoldmines.com

Homebrew Foil and Oil Caps Change Your Guitar’s Tone Dan Maloney | usagoldmines.com

Understanding the T12 Style Soldering Iron Tip Maya Posch | usagoldmines.com

The Clever Design Behind Everyday Traffic Poles Heidi Ulrich | usagoldmines.com

Bicycle Adds Reliability With Second Chain Bryan Cockfield | usagoldmines.com

More Details On Why DeepSeek is a Big Deal Donald Papp | usagoldmines.com

Communicating With Satellites Like It’s 1957 Bryan Cockfield | usagoldmines.com

Examining the Vulnerability of Large Language Models to Data-Poisoning Maya Posch | usagoldmines.com

Underwater Robotics Hack Chat Dan Maloney | usagoldmines.com

Keebin’ with Kristina: the One with the Keyboard Configurator Kristina Panos | usagoldmines.com

A Cordless Soldering Iron With A Difference Jenny List | usagoldmines.com

USB Hub-A-Dub-Dub: Weird Edge Cases Are My Ruin Lewin Day | usagoldmines.com

BLE Rain Gauge Sips Water and Batteries Al Williams | usagoldmines.com

Stepper Motor Operating Principle and Microstepping Explained Maya Posch | usagoldmines.com

Do, Dare or Don’t? Getting Inked by a 3D Printer Heidi Ulrich | usagoldmines.com

How the Main Frame Became the Mainframe: an Etymological Dissertation Maya Posch | usagoldmines.com

Hackaday Links: February 2, 2025 Dan Maloney | usagoldmines.com

Is Fire Conductive Enough To Power a Lamp? Maya Posch | usagoldmines.com

Giving a Proprietary Power Supply the Boot Al Williams | usagoldmines.com

Wearable Tech Tips Directly From the Queen Kristina Panos | usagoldmines.com

Custom Smartwatch Makes Diabetes Monitoring Easier for Kids Dan Maloney | usagoldmines.com

Tiny RC Four-Wheeler Gets Chassis Upgrade For More Traction Lewin Day | usagoldmines.com

Inside a Vintage Oven Controlled Crystal Oscillator Maya Posch | usagoldmines.com

Using Microwave Heating to Locally Anneal CNT-Coated FDM Prints Maya Posch | usagoldmines.com

Could Non-Planar Infill Improve The Strength Of Your 3D Prints? Lewin Day | usagoldmines.com

Taking A $15 Casio F91W 5,000 Meters Underwater Maya Posch | usagoldmines.com

Billion-Dollar Bank Allegedly Loses $15,500,000 To Criminals in ‘Shocking’ Display of Incompetence a...

RedBox In The 80s: Meet The VHS Vending Behemoth Lewin Day | usagoldmines.com

Billion-Dollar Bank Says Account Numbers, Names and Other Sensitive Info Exposed As Insider Triggers...

Time vs Money, 3D Printer Style Elliot Williams | usagoldmines.com

Casio Calculator Gets New Keyboard Al Williams | usagoldmines.com

Antique-Style GPS Looks Like Steampunky Fun Lewin Day | usagoldmines.com

A New Case and Keyboard For The Timex Sinclair 1000 Lewin Day | usagoldmines.com

Electroplating DIY PCB Vias At Home Without Chemical Baths Maya Posch | usagoldmines.com

US Senators Accuse JPMorgan Chase, Bank of America, Wells Fargo, Citibank, US Bank, PNC and Truist o...

Automating The Process Of Drawing With Chalk Lewin Day | usagoldmines.com

Why Not Build Your Quadcopter Around An Evaluation Board? Lewin Day | usagoldmines.com

Winter-Proof (And Improve) Your Resin 3D Printing Donald Papp | usagoldmines.com

Hackaday Podcast Episode 306: Bambu Hacks, AI Strikes Back, John Deere Gets Sued, and All About Capa...

Ancient Pocket Computer Gets a USB-C Upgrade Lewin Day | usagoldmines.com

This Week in Security: DeepSeek’s Oopsie, AI Tarpits, And Apple’s Leaks Jonathan Bennett | usagoldmi...

A History of Copper Pours Al Williams | usagoldmines.com

Handy Online Metric Screw, Nut, and Washer Generator Donald Papp | usagoldmines.com

The Jell-O Glow Tensegrity Toy You Didn’t Know You Needed Heidi Ulrich | usagoldmines.com

Patching Up Failing Hearts With Engineered Muscle Tissue Maya Posch | usagoldmines.com

Copper Candle Burns Forever… Just add Fuel Al Williams | usagoldmines.com

Comparing Adhesives for Gluing PETG Prints Maya Posch | usagoldmines.com

Retrotechtacular: The Tyranny of Large Numbers Dan Maloney | usagoldmines.com

Digital Paint Mixing Has Been Greatly Improved With 1930s Math Lewin Day | usagoldmines.com

A 1962 Test Gear Teardown Al Williams | usagoldmines.com

Forgotten Internet: Giving (or Getting) the Finger Al Williams | usagoldmines.com

RGB LED Display Simply Solves The Ping-Pong Ball Problem Donald Papp | usagoldmines.com

Lessons Learned, When Restoring An Amiga 1000 Jenny List | usagoldmines.com

Inside Vacuum Fluorescent Displays Al Williams | usagoldmines.com

Using Guanella Baluns As Impedance Transformers Maya Posch | usagoldmines.com

Going Brushless: Salvaging A Dead Drill Heidi Ulrich | usagoldmines.com

FLOSS Weekly Episode 818: I Don’t Care About the Roman Empire Jonathan Bennett | usagoldmines.com

Taylorator Makes Mischief on the Airwaves Tom Nardi | usagoldmines.com

FLOSS Weekly Episode 818: I Don’t Care About the Roman Empire Jonathan Bennett | usagoldmines.com

Supercon 2024: Joshua Wise Hacks the Bambu X1 Carbon Elliot Williams | usagoldmines.com

Paper Tape – With LASERs! Jenny List | usagoldmines.com

Cool Kinetic Sculpture Has Tooling Secrets to Share Dan Maloney | usagoldmines.com

Parcae: A Trio of Spy Satellites Al Williams | usagoldmines.com

Leave a Reply