Title :
XCS based hidden firmware modification on embedded devices
Author :
Bencsáth, Boldizsár ; Buttyán, Levente ; Paulik, Tamás
Author_Institution :
Dept. of Telecommun., Budapest Univ. of Technol. & Econ., Budapest, Hungary
Abstract :
Most contemporary embedded devices, such as wireless routers, digital cameras, and digital photo frames, have Web based management interfaces that allow an administrator to perform management tasks on the device from a Web browser connecting to the device´s Web server. It has been shown earlier that many of these devices are vulnerable to Cross Site Scripting type attacks whereby some malicious JavaScript code can be injected in the Web pages stored on the device. When such infected pages are opened by the administrator, the malicious script is executed with admin privileges, and it can potentially fully compromise the embedded device. In this paper, we demonstrate that such full compromise of embedded devices is indeed possible in practice by showing how the injected malicious script can install an arbitrarily modified firmware on the device. We present the general framework of this kind of hidden firmware modification attacks, and report on our proof-of-concept implementation that targets Planex MZK-W04NU wireless routers. In addition, we also show how this vulnerability can be exploited to install botnet clients on embedded devices, and by doing so, to create embedded botnets. Our work proves that the risk of this type of attacks on embedded systems is considerable, and it will further increase in the future.
Keywords :
embedded systems; firmware; invasive software; JavaScript code; Planex MZK-W04NU wireless routers; Web based management interfaces; Web browser; Web server devices; XCS based hidden firmware; cross site scripting type attacks; digital cameras; digital photo frames; embedded botnet client; embedded devices; hidden firmware modification attacks; malware; wireless routers; Browsers; Communication system security; Object recognition; Performance evaluation; Security; Servers; Wireless communication; Cross Channel Scripting; Cross Site Scripting; Embedded systems; botnets; hidden firmware modification; malicious code; malware; security;
Conference_Titel :
Software, Telecommunications and Computer Networks (SoftCOM), 2011 19th International Conference on
Conference_Location :
Split
Print_ISBN :
978-1-4577-1439-9