Hit By Misfortune Cookie | Router Breached 03-05-2015, 05:44 AM
#1
Yep! As a brilliant bombshell to finish the day on, I believe I've been hit by the oh-so-known Misfortune Cookie. I never really thought anything of this vuln other than "someone's gonna get a lot of dildo power". Anyway, let's get on with it!
I was trolling @Blunt, as he was I, earlier so I logged into my router to check up on my settings and to check the system logs and firewall settings etc and started noticing some suspicious looking logs. The first ones being:
This got me interested, as I knew for sure I hadn't ran a port scan on myself. So I delved a little further and found the following logs by switching to "sort by type > Type Security":
I instantly assumed Misfortune Cookie from this. Then @Yagmi started informing me about an open gateway on my connection and eventually pinned it down to a remote access service (TR-069) and I then disabled it. However there are multiple logs suggesting that I have in fact been breached by Misfortune Cookie. What's confusing me though, is on the official information website for Misfortune, there's this segment:
There are many logs. Some notifying me of changes to my router via TR-069 and some of actual access logs.
We'll see where this goes. If any more suspicious activities ensues, I'll just revert back to my old device. I'm removing all inactive and unknown devices just to be on the safe side. You never know!
Here are some more fun logs for you guys:
I was trolling @Blunt, as he was I, earlier so I logged into my router to check up on my settings and to check the system logs and firewall settings etc and started noticing some suspicious looking logs. The first ones being:
Quote:01:54:26 05/03/2015 | Security | Warning | Detect UDP port scan attack, scan packet from IP.
This got me interested, as I knew for sure I hadn't ran a port scan on myself. So I delved a little further and found the following logs by switching to "sort by type > Type Security":
Quote:08:34:08 04/03/2015 Security Warning Intrusion -> SRC=78.189.153.180 DST= LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=29663 DFPROTO=TCP SPT=45520 DPT=23 WINDOW=5808 RES=0x00 SYNURGP=0
00:34:04 04/03/2015 Security Warning Intrusion -> SRC=78.166.38.159 DST= LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=34266 DFPROTO=TCP SPT=33414 DPT=23 WINDOW=5808 RES=0x00 SYNURGP=0
16:28:50 03/03/2015 Security Warning Intrusion -> SRC=222.186.21.70 DST= LEN=40 TOS=0x00 PREC=0x00 TTL=104 ID=256 PROTO=TCP SPT=77 DPT=9064 WINDOW=16384 RES=0x00 SYNURGP=0
08:26:06 03/03/2015 Security Warning Intrusion -> SRC=41.77.212.176 DST= LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=22630 DFPROTO=TCP SPT=4271 DPT=23 WINDOW=5440 RES=0x00 SYNURGP=0
I instantly assumed Misfortune Cookie from this. Then @Yagmi started informing me about an open gateway on my connection and eventually pinned it down to a remote access service (TR-069) and I then disabled it. However there are multiple logs suggesting that I have in fact been breached by Misfortune Cookie. What's confusing me though, is on the official information website for Misfortune, there's this segment:
Quote:Can I detect if I was compromised using Misfortune Cookie?
Typically you would not have logs or other traces of Misfortune Cookie exploitation. General warning signs may be the inability to log in to the web interface or the discovery of changed settings in your device.
There are many logs. Some notifying me of changes to my router via TR-069 and some of actual access logs.
We'll see where this goes. If any more suspicious activities ensues, I'll just revert back to my old device. I'm removing all inactive and unknown devices just to be on the safe side. You never know!
Here are some more fun logs for you guys:
Quote:----------- TODAY -----------
02:24:53 05/03/2015 User Level Notice CWMP:Cwmp post inform success.
02:24:53 05/03/2015 User Level Notice CWMP inform message: parameter change.
02:24:53 05/03/2015 User Level Notice CWMP inform message: event: 4 VALUE CHANGE.
02:24:48 05/03/2015 System Notice WAN connection INTERNET_TR069_R_0_38:IPv4 connected.
02:24:37 05/03/2015 System Notice WAN connection INTERNET_TR069_R_0_38:IPv4 disconnected.(ERROR_NONE)
02:24:37 05/03/2015 User Level Warning WAN configuration: User admin Modify PPP connection : INTERNET_TR069_R_0_38.
------- YESTERDAY ---------
21:06:20 04/03/2015 WIFI Notice 28-CC-01-D7-B1-DD-Wireless is connected. [I HAVE NO CLUE WHAT THIS DEVICE IS LOLOL]
20:40:33 04/03/2015 Security Warning Detect UDP port scan attack, scan packet from 192.168.1.7. [ANOTHER PORT SCAN LOL - I wasn't even in my house yesterday.
All other suspicious logs are the above intrusion logs.
















![[Image: F4Z9Dqw.png]](https://i.imgur.com/F4Z9Dqw.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)







