{"id":3877,"date":"2024-06-04T09:06:22","date_gmt":"2024-06-04T14:06:22","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/cox-biz-auth-bypass-bug-millions-devices-takeover"},"modified":"2024-06-04T09:06:22","modified_gmt":"2024-06-04T14:06:22","slug":"cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/04\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover\/","title":{"rendered":"Cox Biz Auth-Bypass Bug Exposes Millions of Devices to Takeover"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd5e736e94dc27eb9\/6632a1e57bed0fb3b861e1c2\/api_Wright_Studio_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An API <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fortra-discloses-critical-auth-bypass-vuln-in-goanywhere-mft\" rel=\"noopener\">authorization-bypass flaw<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in the infrastructure of a leading US <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/vixie-the-unintended-consequences-of-internet-privacy-efforts\" rel=\"noopener\">broadband provider<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> exposed millions of business customer devices to attacks, giving threat actors access to permissions on the devices as if they were a member of an Internet service provider (ISP) support team.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cox Communications fixed the flaw, identified by independent bug researcher Sam Curry, who released <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/samcurry.net\/hacking-millions-of-modems\" rel=\"noopener\">a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> about the issue on June 3. If exploited, attackers not only could have gained access to business customers&#8217; personally identifiable information (PII), but also Wi-Fi passwords and info on connected devices. They also could have executed arbitrary demands on the devices, updated them, or <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/critical-security-bug-cisco-broadworks-complete-takeover\" rel=\"noopener\">taken over<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> customer accounts, he wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Curry found the root of the vulnerability in 700 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/meta-ai-models-cracked-open-exposed-api-tokens\" rel=\"noopener\">exposed APIs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on Cox\u2019s back-end infrastructure, &#8220;with many giving administrative functionality,&#8221; such as the ability to query the connected devices of a modem, he explained in the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Each API suffered from the same permission issues, where replaying HTTP requests repeatedly would allow an attacker to run unauthorized commands,&#8221; Curry wrote. This issue ultimately resulted from an error in the Spring code used to proxy API requests to a dedicated Cox backend while serving front-end files in a different way. Spring is a widely used Java framework for simplifying the development of Web apps and services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This series of vulnerabilities gave an external attacker with no prerequisites permission to execute commands, modify the settings of millions of modems, access any business customer&#8217;s PII, and gain &#8220;essentially the same permissions of an ISP support team,&#8221; he wrote.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Discovering the Cox Modem Attack Scenario\">Discovering the Cox Modem Attack Scenario<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cox is the largest private broadband provider and the third-largest cable TV provider in the US, with millions of customers, including Curry.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The researcher first noticed something was amiss several years ago while working on his home network to exploit a blind <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/portswigger.net\/web-security\/xxe\" rel=\"noopener\">XML external entity injection<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (XXE) vulnerability that required an external HTTP server to exfiltrate files. In the course of his research, he ran a simple Python webserver to receive the traffic from the vulnerable server, then sent a cURL request from his home computer to make sure that it could receive external HTTP requests.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He found that he was able to receive network traffic on the box and then encountered &#8220;something very unexpected&#8221; when, 10 seconds later, an unknown IP address that Curry later discovered was linked to several domains used <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/tax-cons-targeting-small-business-with-phishing-emails\" rel=\"noopener\">in phishing campaigns<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, 159.65.76.209, replayed the exact same HTTP request.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Somewhere, between my home network and the AWS box, someone had intercepted and replayed my HTTP traffic,&#8221; he wrote. &#8220;This traffic should not be accessible. There is no intermediary between these two systems who should be seeing this.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Curry immediately thought he had been hacked and went to Cox to switch out his modem to a new one, which worked without incident. Several years later, through collaboration with fellow security-researcher friends and an opportunity to help someone set up a new Cox modem, he went deeper with an investigation into his own personal incident. Along the way, he &#8220;accidentally&#8221; realized that there was an &#8220;authorization bypass on the Cox back-end API.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Exploiting the Cable Box Bug\">Exploiting the Cable Box Bug<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The flaw discovered by Curry allows an attacker to bypass authorization on vulnerable API endpoints by simply replaying an HTTP request multiple times, with &#8220;over 700 other API requests that we could hit,&#8221; he wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To exploit the issue, an attacker could search for a Cox business target through any one of the hundreds of exposed APIs using their name, phone number, email address, or account number. The attacker then could retrieve the customer&#8217;s full account PII via querying the returned universally unique identifier (UUID) from the initial search, including device MAC addresses, email, phone number, and business address.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Next, an attacker could query the customer&#8217;s hardware MAC address to retrieve Wi-Fi passwords and info on other connected devices. Finally, this would allow the attacker to execute arbitrary commands, update any device property, and takeover victim accounts, Curry said.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cox: A Prompt Response &amp; Mitigation\">Cox: A Prompt Response &amp; Mitigation<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Curry reported the vulnerability to Cox through its responsible disclosure program on March 4, and it was patched a day later. The broadband provider also informed him that there is no history of it being abused by attackers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, the story might have another chapter to come because, if true, this means that the original issue Curry experienced on his modem and which set him off on his investigation (as well as the involvement of the phishing-related IP address) had nothing to do with the vulnerability he eventually discovered, thus remaining a mystery, he noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I&#8217;m still super-curious on the exact way in which my device was compromised, as I had never made my modem externally accessible nor even logged in to the device from my home network,&#8221; Curry wrote, adding that his research &#8220;aims to highlight vulnerabilities in the layer of trust between <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/isp-security-do-we-expect-too-much-\" rel=\"noopener\">the ISP and customer devices<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/cox-biz-auth-bypass-bug-millions-devices-takeover\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An API authorization-bypass flaw in the infrastructure of a leading<\/p>\n","protected":false},"author":12,"featured_media":3878,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3877","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=1000%2C562&ssl=1",1000,562,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=1000%2C562&ssl=1",1000,562,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=1000%2C562&ssl=1",1000,562,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=1000%2C562&ssl=1",1000,562,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?resize=825%2C562&ssl=1",825,562,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/cox-biz-auth-bypass-bug-exposes-millions-of-devices-to-takeover.jpg?fit=1000%2C562&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3877","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3877"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3877\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3878"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}