· 10 years ago · Jun 22, 2016, 02:06 PM
1Preface
2When the Government, Telecommunications companies and Internet Service
3Providers, implant secret spying equipment in your home without your
4knowledge or consent under the guise of something else, then use that
5equipment to infect your computers and spy on your private network activity
6(not the internet), we believe you have a right to know.
7It is not possible to make these claims without actual proof and without
8naming the actual companies involved.
9These events coincide with the global surveillance systems recently disclosed
10and they further confirm the mass scale of the surveillance and how deeply
11entrenched the Governments are in our personal lives without our knowledge.
12The methods we disclose are a violation of security and trust. Good
13Information Security (InfoSec) dictates that when we discover such back
14doors and activity, we analyze, understand, publicize and fix/patch such
15security holes. Doing otherwise is morally wrong.
16What is revealed here is the missing piece to the global surveillance puzzle,
17that answers key InfoSec questions which include:
18How do the NSA/GCHQ perform Computer Network Exploitation?
19We reveal the actual methods used by the NSA/GCHQ and others that allows
20them to instantly peer into your personal effects without regard for your
21privacy, without your knowledge and without legal due process of law, thus
22violating your Human Rights, simply because they can.
23Disclosures
24The risks taken when such activity is undertaken is "Being Discovered" and
25the activity being "Publicly Exposed", as well as the "Loss of Capability".
26
27â–¶Anonymous 06/21/16 (Tue) 12:19:43 09d44b No.6407074
28>>6407070
29 6
30
31 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
32Source of this Information
33 "The simple knowledge that we may be clandestinely observed in our own
34 homes provided the determination to find the truth, which we did."
35This information is not the result of any knowledge of classified documents or
36leaks, but based on information in the public domain and our own fact finding
37mission due to Forensic and Network Analysis Investigations of private SOHO
38networks located in the UK.
39As we detail the methods used, you will see that information was uncovered
40fairly, honestly and legally and on private property using privately owned
41equipment.
42Our Laws
43There is no law that we are aware of that grants to the UK Government the
44ability to install dual use surveillance technology in millions of homes and
45businesses in the UK.
46Furthermore, there is no law we are aware of that further grant the UK
47Government the ability to use such technology to spy on individuals, families
48in their own homes on the mass scale that this system is deployed.
49If there are such hidden laws, the citizens of the UK are certainly unaware of
50them and should be warned that such laws exist and that such activity is
51being engaged in by their own Government.
52All of the evidence presented is fully reproducible.
53It is our belief that this activity is NOT limited to the UK.
54
55â–¶Anonymous 06/21/16 (Tue) 12:19:59 09d44b No.6407077>>6407080
56 7
57
58 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
59Companies
60BT are directly responsible for covertly embedding secret spy equipment in
61millions of homes and businesses within the UK as our evidence will
62demonstrate.
63BT have directly enabled Computer Network Exploitation (CNE) of all its
64home and business customers.
65Technical Nature of this Information
66The information described here is technical, this is because, in order to
67subvert technology, the attackers need to be able to fool and confuse experts
68in the field and keep them busy slowing them down, but regardless, the
69impact and effect can be understood by everybody.
70Your main take away from this disclosure is to understand conceptually how
71these attacks work, you can then put security measures in place to prevent
72such attacks.
73
74â–¶Anonymous 06/21/16 (Tue) 12:20:22 09d44b No.6407080>>6407086
75>>6407077
76 8
77
78 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
79Credibility of this Research
80We first made our discoveries in June 2013 and kept silent so that we could
81research the capabilities without being detected. As more Edward Snowden
82disclosures were published it became crystal clear that what we discovered is
83a major component of the surveillance system.
84Those who wish to discredit our evidence, feel free to do so, but do so on a
85technical level, simply claiming it "it's not true" or performing some social
86attack simply re-enforces it and identifies the "discreditor" as an agent of the
87NSA/GCHQ or an agent of the global surveillance system.
88Our evidence is based on public available UNMODIFIED firmware images.
89To verify our claims using UNMODIFIED images requires connecting a USB
90to serial port to the modem motherboard board which allows you to login
91(admin/admin) and verify yourself. As most people will find this difficult, we
92provided a link to third party MODIFIED images based on official BT release
93GNU source code that allow you to telnet to the device (192.168.1.1), this
94modified version includes the same backdoor. These can be found here:
95http://huaweihg612hacking.wordpress.com/
96and
97http://hackingecibfocusv2fubirevb.wordpress.com/
98The MODIFIED images have been publicly available since August, 2012, long
99before the Edward Snowden disclosures.
100The methods we published, allows confirmation without having to open the
101device. However if you are suspicious of the MODIFIED firmware from August
1022012, simply connect to the USB serial port of your own existing unmodified
103modem and login to verify, either way the results will be the same.
104
105â–¶Anonymous 06/21/16 (Tue) 12:20:25 dd24c2 No.6407082>>6407087
106the <script src=""> tag breaks it
107
108â–¶Anonymous 06/21/16 (Tue) 12:20:39 09d44b No.6407086>>6407096
109>>6407080
110 9
111
112 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
113Privacy vs Security
114Loss of privacy is a breach of personal security and the legal violation of
115privacy is purely a consequence of that security loss.
116We've focused on the technical breach of security i.e. the Computer
117Network Exploitation itself and by fixing that you can restore at least some of
118your personal privacy.
119This illustrates that there is no such thing as a balance between security and
120privacy, you have them both or you have none.
121 10
122
123 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
124 Motivation
125Motivation
126After studying in detail the revelations by the Edward Snowden, we realized
127there was a large missing part of the puzzle.
128There has been little to nothing published on specifically how the attackers
129technically achieve their goals. Most information published is based on
130theoretical situations.
131If we don't know how hackers actually achieve these security breaches, we
132cannot defend against such breaches.
133For example, a slide similar to the following was published, of all the slides
134released, it's uninteresting and easily dismissed, as it simply describes what is
135commonly known as a theoretical Man-In-The-Middle attack.
136The media focus of the slide is of course the Google's Servers, and your first
137thought might be, 'this is Google's problem to solve', but what if , 'Google
138Server' was 'My Banks Servers', you would probably be more concerned,
139because that may directly effect you.
140But we thought, what if, 'Google Server', was 'Any Server, Anywhere?'
141 11
142
143 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
144Our investigation led to us uncover, and understand how this attack really
145works in practice, how it is implemented and the hair-raising reality of its true
146nature and that is, this not just a back door, but an entire attack platform and
147distributed architecture.
148Terminology
149To ease explanation, we are going to use standard security terms from here
150on.
151Attacker - GCHQ, NSA, BT Group or any combination.
152The Hack  The technical method used by the attackers to illegally break into
153your home network computers and phones.
154
155â–¶Anonymous 06/21/16 (Tue) 12:20:39 dd24c2 No.6407087
156>>6407082
157sets off the 8ch block*
158
159â–¶Anonymous 06/21/16 (Tue) 12:21:03 09d44b No.6407096>>6407102
160>>6407086
161 12
162
163 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
164 Basic Security
165Your Home Network
166In order to explain how these Computer Network Exploitation attacks work,
167and how this affects you personally, we must first look at the architecture of a
168typical home or office network. Look familiar to you?
169Most Internet connections consists of an DSL type modem and one or more
170Ethernet ports attached to the modem that you connect your computers,
171devices and add-on switches etc.
172There are two security factors in operation here:
173 a) NAT based networking, meaning that your home computers are
174 hidden and all share a single public IP address
175 b) Your modem has a built-in firewall which is blocks inbound traffic. The
176 inherent security assumption is that data cannot pass from the inbound
177 DSL line to a LAN switch port without first being accepted or rejected by
178 the built-in firewall
179 13
180
181 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
182For the technical minded, these security assumptions are further re-enforced
183if the modems software is open source e.g. using Linux and that its source
184code is freely and openly available as per the GNU GPL requirements.
185Given that the above is the most common architecture on the Internet as it
186applies to almost every home and office, everywhere, lets now revisit that first
187slide, but this time, we ask one simple question:
188 How do the attackers get between You and Google or some other
189 service?
190On closer inspection of the diagram you will notice that "Google Request"
191and the Attacker (Log into Router) share the same router, when this slide
192was released, we all assumed that this router was either Google's own router
193or some upstream router, that way the attacker could intercept packets and
194perform a Man-In-The-Middle (MITM) attack.
195However, this would not work for every website or service on the Internet.
196The attacker would need to be upstream everywhere!
197So where does the attacker hide? Where is this Common
198Router? again we ask:
199 How do the attackers get between You and Google or
200 some other service?
201Lets examine the diagram one last time.
202
203â–¶Anonymous 06/21/16 (Tue) 12:21:42 09d44b No.6407102>>6407107
204>>6407096
205 14
206
207 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
208You guessed it, it's right inside your house. It's the router
209supplied by your trusted Internet Service Provider (ISP).
210If this is true, it means that you are being Internet wiretapped, because the
211attacker has as entered your private property and unlawfully accessed your
212computer equipment.
213Unlike a lawful interception in which a warrant is served on the third party
214(ISP), the intercept happens at the ISPs property upstream and outside your
215property.
216This is happening in your home or office, without your knowledge, without
217your permission and you have not been served with a search warrant as is
218required law.
219But worse, is the fact that this architecture is designed for Cyber Attacking
220in addition to passive monitoring as we will detail next.
221 15
222
223 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
224 The Hack
225The Hack
226This example is based on the UK version of what we are calling The Hack
227using BT Internet services. If you are not in the UK and regardless of the
228service, you should always assume that the exact same principles detailed
229here are always being used against you regardless of your country or ISP.
230The Hack is based on the fact that a second secret/hidden network and
231second IP address is assigned to your modem. Under normal use, you cannot
232detect or see this from your LAN, but the attacker has direct access to your
233modem and LAN in your house from the Internet.
234How it Works
235When the DSL connection is established a covert DHCP request is sent to a
236secret military network owned by the U.S. Government D.O.D. You are
237then part of that U.S. D.O.D. military network, this happens even before you
238have been assigned your public IP address from your actual ISP.
239This spy network is hidden from the LAN/switch using firewall rules and
240traffic is hidden using VLANs in the case of BT et al, it uses VLAN 301, but
241other vendors modems may well use different VLANs. The original slide has a
242strange number 242 with grey background, we think this represents the
243VLAN number/Vendor number so BT would be 301.
244This hidden network is not visible from your "Modem's Web Interface" and
245not subject to your firewall rules, also not subject to any limitations as far
246as the switch portion of your modem is concerned and the hidden network
247also has all ports open for the attacker.
248Other tools and services are permanently enabled inside the modem, which
249greatly aid the attacker, such as Zebra & Ripd routing daemons, iptables
250firewall, SSH remote shell server, along with a dhcp client.
251These tools allow the attacker to control 100% of the modem functionality
252from the Internet and in an undetectable manner. e.g., the attacker can
253
254â–¶Anonymous 06/21/16 (Tue) 12:22:21 09d44b No.6407107>>6407113
255>>6407102
256 16
257
258 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
259forward all your DNS requests to their private network, they can selectively
260route specific protocols, ports or networks or everything to their network and
261by default they do.
262Although the hidden network is owned by U.S. D.O.D., it is located within the
263UK as the ping time to the attacker's IP gateway is < 8ms from within the
264UK.
265This clearly demonstrates that the UK Government, U.S. Government, U.S.
266Military and BT are co-operating together to secretly wiretap all Internet
267users in their own homes (with few exceptions). The modems are provided by
268BT and locked down. If you cannot confirm otherwise, you must assume that
269all ISPs in the UK by policy have the same techniques deployed.
270Your home network actually looks something like the following diagram. To
271the right is the WHOIS record of the network our modems are automatically
272connected, yours may vary.
273The above hidden network is created automatically
274in all our test cases across a wide range of modems.
275It should be noted that even before your Point-to-Point over Ethernet (PPPOE)
276request is issued, this hidden network is already fully operational. So much
277so, that your LAN can be directly accessed even when you think your modem
278is off-line.
279This is an extremely complex and covert attack infrastructure and it's built
280 17
281
282 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
283right into your modems firmware which can also be updated remotely as
284required by the attacker using the built-in BTAgent.
285The Hack attack is turned on by default, but is selectively turned off for
286special purposes or specific dangerous customers, for example, for certain
287software, firmware and hardware developers/engineers (which may include
288you), so that these people don't discover The Hack.
289The attacker identifies these specific "threats" and marks their Internet
290connections as "NO DHCP", such that the same dhcpc requests from their
291telephone lines are ignored and while these requests are ignored, the hidden
292network will not appear inside their modem and is much harder to discover.
293Firmware engineers usually want to know if the modems are using Open
294Source software such as Linux and Busybox, in which case they are subject to
295the terms of the GNU Public License.
296These engineers as well as tech savvy users may wish to put their own
297software (e.g. OpenWRT) on these modems, maybe because they don't trust
298their ISP, but are prevented by their ISP for obscure reasons.
299Most modem providers usually violate copyright law by not releasing the
300source code and BT was no exception to this rule. Only by the threat of legal
301action did they release the source code. However, BT still prevents the
302modems from being updated by their customers or third parties.
303BT goes to extreme lengths to prevent anyone from changing the firmware,
304and those that come close are first subjected to Physical and Psychological
305Barriers explained later and the few that overcome that, are subjected to a
306separate NSA/GCHQ targeted Social Attack designed specifically to derail
307any engineering progress made, this is also explained later. These attacks are
308almost always successful.
309During these attacks, BT uses all the information discovered by the engineers
310to produce firmware updates that prevent anyone else using those same
311techniques under the guise of security and protecting the customer and this is
312performed without notice to any customers.
313As we move to new generations of hardware, the modems are very
314
315â–¶Anonymous 06/21/16 (Tue) 12:23:24 09d44b No.6407113>>6407119
316>>6407107
317As we move to new generations of hardware, the modems are very
318 18
319
320 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
321sophisticated and very covert, the engineers capable of even attempting to
322replace the firmware become practically non-existent.
323As we detail, the sole purpose of locking the modem is to prevent people
324discovering that they are actually being wiretapped by BT on behalf of
325NSA/GCHQ.
326As a side note NSA describe Linux/Open Source as Indigenous and a SIGINT target.
327NSA documents, describe this means of SIGINT collection as:
328Others include:
329and
330 19
331
332 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
333 Your Real Network
334Your Real Network
335The following is a more realistic view of your home network and what is now
336possible, given the attacker now has secret access to your home LAN.
337It is now a simple matter to use other tools and methods available to the
338attacker to penetrate your internal computers, this includes:
339 · Steal private VPN/SSH/SSL/PGP keys ·Steal content as required
340 · Infect machines with viruses ·Access Corporate VPNs
341 · Install key loggers ·Clean up after operations
342 · Install screen loggers ·Route traffic on demand (e.g. MITM)
343 · Clone/destroy hard drives ·Censorship and Kill Switch
344 · Upload/destroy content as required ·Passive observation
345 20
346
347 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
348 The Attacks
349The Attacks
350This section lists the attacks on you that are now possible by the NSA/GCHQ.
351Later, we show how you can defend against these attacks and it would be wise
352to implement our defenses with immediate effect.
353Unlike the revaluations so far by Snowden where the attacks occur out there
354somewhere on the Internet, these attacks happen in your home/office.
355The attacks listed are the most obvious attacks, some are mentioned in
356Edward Snowden revelations and referred to as Computer Network
357Exploitation (CNE).
358Internal Network Access
359The attacker has direct access to your LAN and is inside your firewall.
360Your modem acts as a server, it listens on lots of ports such as SSH (22) and
361TELNET (23), so the attacker can just hop on to it (but you cannot).
362This is possible because another hidden bridged interface exists with its own
363VLAN. Firewall rules do not apply to this interface, so the attacker can see
364your entire LAN and is not subject to your firewall rules because those rules
365apply to the BT link (black line) not the attackers link (red lines).
366When you scan your BT Public IP address from outside, you may well only see
367port 161 open (BTAgent, more on this later), but when scanned from the
368attackers network, all necessary ports are open and with an SSH daemon
369running (even the username and password are the basic admin:admin).
370Basically the attacker is inside your home network, and ironically, in most
371cases, right behind your actual curtain (where the modems are usually
372located).
373This is the digital version of Martial Law with a Cyber Attack Soldier in every
374home in the country.
375The first task of the attacker is to perform a site survey and learn as much as
376
377â–¶Anonymous 06/21/16 (Tue) 12:23:44 09d44b No.6407119
378>>6407113
379 21
380
381 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
382possible about all the devices attached to your network.
383All your hardware can be identified by the specific MAC addresses and then
384fingerprinted for specific protocols and software versions. All this cannot be
385detected unless you are logged into your locked modem.
386The above is just the base platform of the NSA/GCHQ from which hundreds of
387types of attacks are now possible, which now include all of the following:
388Man-In-The-Middle Attack
389The attacker controls all outbound routes, he can easily perform an HTTPS
390Man-In-The-Middle attack by forwarding specific traffic for port 443 or
391destination network to a dedicated MITM network which he controls (as per
392previous slides).
393The only thing required is a valid SSL certificates + keys for a specific domain
394(which he already has, see below), The attacker is between you and any
395site you visit or any service you use (not just websites). e.g. Skype, VOIP, SSH
396etc.
397The attacker simply creates a static route or more easily publishes a Routing
398Information Protocol Request (RIP) request to the Zebra daemon running in
399the router for the target network address and your traffic for that network
400will then be routed to the attackers network undetectable by you.
401The attacker can then use asymmetric routing and upon examination of the
402requests he can filter specific requests he is interested in and respond to
403those, but let the target website server or service respond to everything else.
404The key here, is, traffic from the target website back to the user does not
405then have to go via the attackers hidden network, it can go directly back to
406users public IP (which would be logged by the ISP).
407MITM can be on any port or protocol not just HTTPS (443), for example your
408SSH connections, all UDP or GRE, PPTP, IPSec etc. or any combination of
409anything.
410 22
411
412 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
413All SSL Certificates Compromised in Real-Time
414The security of Public Key Infrastructure (PKI) is based primarily on the
415security of the owners private keys. These private keys are not necessarily
416required in order to perform a MITM attack.
417All that is required is an actual duplicate signed certificate using NSA/GCHQ
418own private keys. The MITM attack can be as simple as running a transparent
419proxy and you will always see a valid certificate but unable to detect the
420attack.
421At the point of the proxy all your traffic is decrypted in real-time, at which
422point targeted packet injection can occur or simply monitored.
423It makes perfect sense that the trusted Certificate Authority (CA) actually
424make a second duplicate SSL certificate with a separate set NSA provided
425private keys, as the CA never sees the real certificate owners private keys.
426When you send your Certificate Signing Request (CSR) and order your SSL
427Certificate, a duplicate signed certificate is then automatically sent to the
428NSA and stored in their "CES Paring database" as per Snowden releases.
429We must therefore assume that NSA/GCHQ already have a duplicate of every
430PKI certificate+key (key different from yours).
431This means as soon as you revoke or renew your certificate, the NSA is ready
432and waiting again, allowing them to do real-time decryption on almost any
433site anywhere across any protocol that uses PKI.
434
43523
436
437 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
438Theft of Private Keys
439Home networks are usually very insecure, mainly because only you or family
440use them, your guard is down and your SSH, VPN, PGP, SSL keys are all
441vulnerable to theft by the attacker and his available methods.
442The Hack is the key mechanism that enables these thefts.
443As an example of the above, if you use the modems built-in VPN feature, you
444usually add your certificate and private key to the modem or generate them
445both via its web interface, at some later time, the attacker can just copy
446these keys to the "CES Pairing database" via his private network, the data
447collected from SIGINT can later be decrypted off-line or in real-time.
448In the case of keys extracted from the modems built-in VPN, the "CES Paring
449database" now contains the real key/cert pair, meaning the attacker can now
450attack the VPN server environment directly when that server would have not
451being exploitable otherwise.
452The attacker can also mask as the genuine user by performing the server
453attack from within the users modem (using the correct source IP address),
454this way nothing unusual will appear in the VPNs logs. Once inside the
455parameter of the VPN server the cycles repeats.
456You should assume that all "Big Brand" VPNs and routers use the exact same
457attack strategy and architecture with variances in the specific implementation
458e.g. Big Brand supports IPSec, Little Brand supports PPTP.
459The NSA Bullrun Guide states:
460 "The fact that Cryptanalysis and Exploitation Services (CES) works with
461 NSA/CSS Commercial Solutions Center (NCSC) to leverage sensitive,
462 cooperative relationships with specific industry partners".
463 Specific implementations may be identified by specifying Equipment
464 Manufacturer (Big Brand/Make/Model), Service Provider (ISP) or Target
465 Implementation (specific modem/router implementation).
466In this disclosure, we are interested in "Target Implementation", because in
467our example case, BT has covertly implanted these devices in homes where
468there is an absolute expectation of privacy, whereas the other
469implementations exist within the ISP or large corporations in which you
470cannot expect privacy.
471It's important to remember that "Big Brands" also make small SOHO DSL and
472
473â–¶Anonymous 06/21/16 (Tue) 12:24:51 09d44b No.6407130
474 24
475
476 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
477cable modems.
478Further evidence of the mass global distribution of this technology to at least
479the 14 Eyes: USA, GBR, CAN, AUS, NZL, FRA, DEU, DNK, NLD, NOR, ESP,
480ITA, BEL, SWE and almost certainly many more countries:
481Quote from GCHQ regarding their ability to steal your private keys:
482 It is imperative to protect the fact that GCHQ, NSA and their Sigint
483 partners have capabilities against specific network security technologies
484 as well as the number and scope of successes. These capabilities are
485 among the Sigint community's most fragile, and the inadvertent
486 disclosure of the simple "fact of" could alert the adversary and result in
487 immediate loss of the capability.
488 Consequently, any admission of "fact of" a capability to defeat encryption
489 used in specific network communication technologies or disclosure of
490 details relating to that capability must be protected by the BULLRUN
491 COI and restricted to those specifically indoctrinated for BULLRUN.
492 The various types of security covered by BULLRUN include, but are not
493 limited to, TLS/SSL, https (e.g. webmail), SSH, encrypted chat, VPNs
494 and encrypted VOIP.
495And
496 Reports derived from BULLRUN material shall not reveal (or imply) that
497 the source data was decrypted. The network communication technology
498 that carried the communication should not be revealed.
499From the NSA:
500
501â–¶Anonymous 06/21/16 (Tue) 12:26:03 09d44b No.6407148
502 25
503
504 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
505The Kill Switch
506Actual capabilities uncovered here include the actual ability to apply physical
507censorship on the Internet by governments directed at individuals, groups,
508companies, entire countries or the majority of the users of the Internet at
509once (given a coordinated government agreement). This is something that can
510be turned on globally within minutes.
511This "kill switch" is only a small portion of the total capabilities available that
512are in place right now. Essentially, any operation that can be applied using a
513single firewall or RIP router, can be applied to every customer at once.
514Uploading/Download Content
515The attacker can upload or download content via either your public ISPs
516network or via his private hidden network. The differences is that your ISP
517could confirm or deny from their logs the user did or did not upload/download
518content from/to a particular source.
519In other words, the possibilities and ability to frame someone cannot ever be
520overlooked.
521When the attackers steal content, that information always travels via the
522private network.
523Hacking in to a VOIP/Video Conferences in Real-Time
524As an example, it's a trivial matter for the attacker to route specific traffic for
525specific media protocol such as VOIP (SIP/H.323/RTSP) etc. to his network in
526real-time these protocols are usually not encrypted so no key theft is required.
527In the case of Skype, it's no stretch of the imagination to assume that
528Microsoft handed over the keys on day one.
529Those they do not redirect in real-time as we know, will be collected via
530upstream SIGINT.
531 26
532
533 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
534Tor User/Content Discovery
535Users of the Tor network can easily be discovered by LAN packet
536fingerprinting, but also by those who download the Tor client. The attacker
537can stain packets leaving your network and before entering the Tor network,
538making traffic analysis much easier than was previously known.
539All Tor traffic can be redirected to a dedicated private Tor network
540controlled by the attacker, in this way the attacker controls ALL Tor nodes
541and so can see everything you do from end-to-end.
542This is not something the Tor project can fix, it can only be fixed by the user
543following our methods.
544Tor hidden services should drop all traffic from un-trusted Tor nodes, this way
545clients running in the simulated Tor network will fail to connect to their
546destination.
547Encrypted Content
548The attacker is in your network and has all the tools necessary (such as
549operating system back doors) or zero day vulnerabilities to hack into your
550computers and steal your VPN, PGP, SSH keys as well as any other keys they
551desire. Also, content that is encrypted can be captured before encryption via
552any number of methods when the attacker is already inside your network.
553Covert International Traffic Routing
554The attacker can secretly route your traffic to the U.S. without your
555permission, consent or knowledge thus by passing any European data
556protection or privacy laws.
557Activists
558We have seen many activist groups, protest organizers identified and silenced
559over the few years, we believe this is the primary method used to capture
560activists. Knowing the victims ISP would indicate which ISPs are involved.
561Destroy Systems
562Released documents state that the U.S. Cyber Command have the ability to
563disable or completely destroy an adversaries network and systems, the first
564step to this would be to penetrate the adversaries network firewall making
565secondary steps much easier.
566
567â–¶Anonymous 06/21/16 (Tue) 12:26:05 dd24c2 No.6407149
568>>6406589
569This "pdf" is actually an html file.
570
571â–¶Anonymous 06/21/16 (Tue) 12:26:18 09d44b No.6407152
572 27
573
574 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
575Censorship
576The attacker has control of the hidden firewall, it is easy for the attacker to
577simply block traffic based on specific ports or based on destination address or
578network route, for example, the government can block port 8333 at source
579and therefore block all Bitcoin transactions.
580A coordinated attack on the Bitcoin network is possible by blocking ports of
581Minors around the world. Reducing the hash rate and blocking transactions.
582Mobile WIFI Attacks
583Mobile devices phones/tablets etc, are as easily accessible once they connect
584to your WIFI network which is, from the attackers perspective, just another
585node on the your LAN that the attacker can abuse.
586The level of sophistication or advanced encryption in use by your WIFI is no
587defense because the attacker has gained a trusted position in your network.
588All MAC addresses gathered from your LAN are stored in the XKEYSCORE
589database so they can be used to identity specific devices and specific
590locations, allowing the attacker to track you without the aid of GPS or where
591no GPS signal exists.
592Document Tracking
593Microsoft embeds the physical MAC addresses of the computer inside
594documents it creates. This allows the source of a document to be identified
595easily. The following is from the XKEYSCORE PowerPoint.
596 28
597
598 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
599 The Mobile Hack
6002G/3G/4G Mobile Attacks
601Given the NSA/GCHQ plan to spy on "any phone, anywhere, any time".
602The Hack detailed in this document is a carrier independent method to
603achieve that goal that works very well. The attacker will almost certainly re-
604use the same strategy for all Mobile phones or wireless broadband devices.
605Your mobile phone (2G/3G/4G) is almost certainly subject to this same attack
606architecture because from the attackers perspective, his side of the
607infrastructure would remain the same regardless of device being attacked.
608A mobile phone these days is simply a wireless broadband modem + phone,
609so any encrypted messaging system for example can be captured before
610encryption. Therefore mobile phones are subject to all the same and many
611more attacks as per The Hack.
612This would mean that mobile phone makers may well be in collusion with the
613NSA/GCHQ because they would need to implement the equivalent routing
614and firewall ability in each mobile phone as part of the OS if it was to remain
615hidden.
616The mobile phone version of The Hack is also much more difficult to detect
617than the broadband version. Mobile phones make more use of IPv6 and the
618overall complexity of IPv6 means that even experts may not know what they
619are looking at in the routing tables even if they could see them. Carriers often
620have multiple IPs for different services they provide.
621Even top-up mobile phones without any credit can be accessed, for example,
622the mobiles phones top-up services are always available and their DNS
623servers are always accessible regardless of your top-credit state.
624Modern kernels use multiple routing tables (e.g. ip rule show) for policy based
625routing, so again unless you confirm who owns a specific IP6 range, it will be
626difficult to spot, especially as firmware hackers are not even looking for such
627back doors. Maybe now they will.
628 We do not provide defense methods for Mobile Phones at this time.
629
630â–¶Anonymous 06/21/16 (Tue) 12:26:35 09d44b No.6407158
631 29
632
633 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
634 Basic Defense
635Basic Defense
636Knowing how you are being attacked is half the battle, but in this case, due to
637the attackers abuse of a privileged position and the fact that the attacker is
638your own government and its foreign partners, defense is much more difficult,
639compared to a common virus, worms or hackers.
640One of the best defenses is to take Legal action against BT or your ISP.
641If you are serious about your privacy, don't expect any help from your
642attackers (as attackers never help their victims). You must ensure your own
643privacy. Before we explain practical defenses, here are some good tips.
644Secure your end-points
645 · Never ever trust ISP supplied equipment (e.g. router, firewall, STBs),
646 always consider such devices as hostile and position them in your
647 network architecture accordingly i.e. in the Militarized Zone (MZ)
648 · Do not use any built-in features of ISP equipment (e.g. Firewalls, VPNs)
649 · Never ever trust a device that has any closed source firmware or other
650 elements, regardless of the excuses the your attacker gives you
651 · Never trust a device that you cannot change the firmware yourself,
652 regardless of "big brand" names
653 · Disable all protocols that you don't use or don't understand, especially
654 TR-069 and any other Remote Management features, these are all part of
655 the surveillance control system (e.g. BTAgent firmware update)
656 · Always use a second Linux firewall which you control, that you have built
657 · Control all your NAT on your second Linux firewall not the ISPs supplied
658 router
659 · Make sure you control all end-points whenever possible
660 · Ensure that 100% of packets UDP/TCP (e.g. including DNS) are
661 encrypted leaving your second firewall (this is the key to end-point
662 security), this requires using Outbound Defense method described
663 later
664 · Always use a VPN and remote proxy that you control or trust, disable
665 logging altogether to protect privacy. This requires using Outbound
666 Defense method described later
667 30
668
669 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
670 Inbound Defense
671Inbound Defense
672This defense method against most NSA/GCHQ Inbound attacks is fairly easy
673to implement and not too technical, everybody at a minimum should include
674this method in their defense strategy.
675The strategy will only prevent NSA/GCHQ from hacking into your home/office
676LAN. It cannot prevent other direct attacks because the attacker can still
677intercept and route all packets leaving your property.
678A second Linux firewall device (blue) that you control and manage is
679placed in front of the ISP router effectively placing the ISPs router in the
680Militarized Zone (MZ) i.e. the Internet. A single cable (red) is used to link the
681LAN of the ISP router to the Internet LAN port of the Linux firewall.
682Block all inbound access including multicast packets from the ISP router, run
683DHCP and NAT on your Linux firewall.
684Your second firewall can then issue PPPOE requests via its Internet port and
685create a local ppp0 device which will be its new Internet connection. All
686packets leaving the firewall will now be PPPOE encapsulated.
687
688â–¶Anonymous 06/21/16 (Tue) 12:26:46 09d44b No.6407160
689 31
690
691 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
692 Outbound Defense
693Outbound Defense
694This defense method should be used against all NSA/GCHQ Inbound and
695Outbound attacks. This is the only sure fire method to protect Tor clients.
696This defense requires that you (control/own/rent) a Server or VM elsewhere
697on the Internet (far away from your ISP) and preferably in a different country.
698Run a VPN such as OpenVPN between your Linux Firewall (blue) and the
699your VPS server (green cloud), there, you run Squid Proxy and DNS and
700block all inbound access except from your VPN. Always run your own DNS
701service on your VM/Server.
702 32
703
704 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
705An alternative short-term defense is to use OpenWRT router software that
706you install into the modem yourself so that you can confirm no hidden
707networks or IP addresses exists and that the firewall actually functions.
708However, this is technically impossible for must users.
709For open source router software visit https://openwrt.org/
710More Defense Tips
711 · Isolate your WIFI from your LAN and limit by MAC address + strong
712 passwords alternatively, Isolate your WIFI from your LAN and leave it
713 open as a free hot-spot.
714 · If you are capable, install your own router firmware (openwrt)
715 · Tell your ISP you do NOT want a router with back doors or malware in it,
716 ask them to confirm in writing that back doors do not exist, this will help
717 you in court when suing them
718 · Stop using any operating systems that is known to contain back doors
719 · Only use Tor if you are using Outbound Defense method, otherwise you
720 could be using a NSA/GCHQ wonderland version of the Tor network
721 · It cannot be emphasized enough, never trust closed source routers
722 · Never use your ISP DNS servers
723 33
724
725 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
726 MITM Defense
727MITM Defense
728Until now, it was not fully understood how a MITM actually worked with
729regard to how the attacker could get in the middle of any connection.
730Now we know with 100% confidence that the man is not in the middle, but in
731the modem and that's how any individual can be subjected to MITM attack.
732We hereby rename this attack Man-In-The-Modem attack.
733As an alternative defense for the future in place of the previous (admittedly
734complex outbound defense), you could use TcpCrypt. You can prevent this
735attack by ensuring that your client and servers are running TcpCrypt, which is
736a TCP protocol extension. It works without any configuration and
737automatically encrypts TCP connections if both server and client support it or
738it will fall back to no encryption. It's also 100% NAT friendly.
739Once installed, this works for any port not just port 80, it will also protects
740HTTPS, SMTP, SSH and every other service.
741
742â–¶Anonymous 06/21/16 (Tue) 12:27:07 09d44b No.6407167>>6407171
743>>640716034
744
745 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
746 TCPCRYPT
747TCPCRYPT
748TcpCrypt is a very secure approach to many of the problems posed by the
749NSA/GCHQ because its true native end-to-end encryption and does not
750require a certificate authority and is free open source software.
751The NSA have tried to kill this project a number of times and will continue to
752do so or limit its use, you must not let that happen.
753 Let's get all TCP connections
754 Encrypted by default!
755 Available now free open source for Linux, Windows and OSX visit:
756 http://www.tcpcrypt.org/
757 Kernel Developers - please support
758 TcpCrypt Kernel Module
759If you would like to see how NSA and GCHQ agents try to kill projects like
760this in public, view the video http://www.tcpcrypt.org/talk.php and go to
76126:22 and hear the voice of the NSA and then GCHQ.
762
763â–¶Anonymous 06/21/16 (Tue) 12:27:25 09d44b No.6407171
764>>6407167
765 35
766
767 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
768Frequently Ask Questions
769Why Full Disclosure?
770We are under no obligation to withhold this information from citizens of
771Europe, specifically we are not subject to any provisions of the Official
772Secrets Act of 1998 as we have never been:
773 · a member of the security and intelligence services
774 · a Crown servant or a government contractor
775But more importantly because:
776 · This information was discovered on private property
777 · As security conscious users of the Internet, we identified serious
778 intentional security flaws which need to be fixed, and fast
779 · The needs of the many outweigh the needs of the few
780 · Under the rule of law, the truth is an absolute defense and that is what
781 we present here
782 · lastly, Because we can
783Who should read this information
784The intended audience is citizens of Europe, but anyone who is or could be a
785victim of global surveillance systems, this includes everybody in the world
786now and in the future.
787Why does this document exist
788When a person(s) or government takes away your inalienable rights such as
789your Right to Privacy (especially in your own home), you take it back. This is
790not something that can be negotiated or traded.
791What about the debate, the balance?
792There is no such thing as a balance between privacy and security, you either
793have them both or you have none.
794I'm an American, does this apply to me
795The NSA would only use this technique in the U.S. if they really thought they
796could go undetected. In the UK they have gone undetected until now (since
7972011, as evidenced by the date of the firmware), you should assume that the
798U.S. is doing the same to all Americans and you should use the defenses as
799detailed herein as a precaution. We can turn off the lights ourselves.
800 36
801
802 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
803Will stopping BTAgent software stop these Attacks
804No. BTAgent is just misdirection. It is not required or directly used in the
805attacks. It can be used to update the firmware of a target modem should the
806attacker need specific functionality on the modem, but this would be
807unusual. So, killing BTAgent is does not help (you should kill it anyway).
808Is it possible that BT is unaware of this
809No, this is their firmware, controlled by BT, publish by BT, updated by BT,
810they also lock the modems.
811My equipment is completely different?
812The Hack is an NSA/GCHQ Global Strategy and its architecture is
813independent of a specific make or model of modem or mobile phone, it is also
814independent of the method transport e.g. dial-up vs. ADSL, DOCSIS, VDSL,
815Cable modem etc.. It sits at the top of the stack (TCP/UDP etc), so however
816you connect, it connects. Each implementation will vary and improve with
817each generation.
818You should only use, fully open source, firmware that is publicly verified.
819I've never done anything wrong
820Yes you have, you have allowed hackers to enter your home network and plant
821malware that infects your computers, which may now have become part of a
822zombie army with tentacles controlled by the NSA/GCHQ. This is worst than
823any virus or worm you can imagine.
824How can I verify this myself
825Following the instructions in the following sections, you can also create
826simulations off-line, but that is more technical.
827I would like to donate and support your work
828Thank you, please see the last page of this document for details.
829
830â–¶Anonymous 06/21/16 (Tue) 12:28:01 09d44b No.6407185>>6407190
831>>6407175
832 37
833
834 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
835How you can verify
836The following section explains how you can confirm that your modem has the
837GCHQ/NSA back door.
838In these examples, we use two BT OpenReach white modems, (but more
839accurately described as BT OverReach) models:
840Huawei EchoLife HG612 and ECI B-FOCuS VDSL2 modem.
841These two look almost identical. The HG612 is an earlier model.
842The process of confirmation is slightly different for each modem.
843We will show two of ways to verify the back door, the first is something
844anyone can do and requires just the ping command. The second requires re-
845flashing the firmware so you can login to the modem itself.
846Claims of Huawei modems (Left) having back-doors are false, the vendor
847(e.g. BT) build and install the OS for these modems. Huawei simply
848provided hardware. ECI Telecom Ltd, is the provider of the second modem
849(Right) Â the more dangerous of the two.
850 38
851
852 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
853Easy Confirmation
854Step 1. Remove Power from the modem and disconnect the telephone line.
855Step 2. On your PC (assumed Linux) add an IP address 192.168.1.100 i.e:
856 # ifconfig eth0:1 192.168.1.100 up
857Step 3. Start to ping 192.168.1.1 from your PC i.e:
858 # ping 192.168.1.1
859Step 4. Connect a network cable to LAN1
860Step 5. Plug-in the power cable to the modem and wait for about 30 seconds
861for the device to boot, you will then notice:
86264 bytes from 192.168.1.1: icmp_seq=115 ttl=64 time=0.923 ms
86364 bytes from 192.168.1.1: icmp_seq=116 ttl=64 time=0.492 ms
86464 bytes from 192.168.1.1: icmp_seq=117 ttl=64 time=0.514 ms
865You may notice up to ten responses, then it will stop.
866What is happening is the internal Linux kernel boots, the start up scripts then
867configure the internal and virtual interfaces and then turn on the hidden
868firewall at which point the pings stop responding.
869In other words, there is a short window (3-10 seconds) between when the
870kernel boots and the hidden firewall kicks in.
871You will not be able to detect any other signs of the hidden network without
872actually logging into the modem, which is explained in the next section.
873
874â–¶Anonymous 06/21/16 (Tue) 12:28:25 09d44b No.6407190
875>>6407185
876 39
877
878 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
879Hard Confirmation
880Method 1: (no firmware modification required)
881For this method, you need to connect a USB to serial port to the serial port
882pins on the modem motherboard as detailed here:
883http://hackingecibfocusv2fubirevb.wordpress.com/
884If you are unable to use this method because it requires opening the modem,
885please use method 2.
886Method 2: (public firmware modification required)
887For this method, you will need to re-flash the modem by following the
888instructions in the document called hg612_unlock_instructions_v1-3.pdf
889which is available from:
890http://huaweihg612hacking.files.wordpress.com/2011/11/hg612_unlock_instru
891ctions_v1-3.pdf
892Or you can navigate to: http://huaweihg612hacking.wordpress.com/
893and click "Unlocked Firmware Images for Huawei HG612" on the right
894panel.
895Once you have re-flashed your modem, you will be able to login to the modem
896via telnet as follows.
897Note: If your network is not 192.168.1.0, you will need to add the IP address
898to your PC as explained previously, i.e.
899# ifconfig eth0:1 192.168.1.100 up
900# telnet 192.168.1.1, then login
901# Username: admin, Password: admin
902# then type: shell to get the BusyBox shell prompt.
903Your telephone line (RJ11) cable should remain disconnected.
904To prevent your devices firmware from being updated, disable the following
905components, as they are not required for confirmation.
906Kill the pid of the /bin/sh /BTAgent/ro/start (See UN-Hack later)
907# kill pid
908# killall tftpd sshd MidServer btagent
909
910â–¶Anonymous 06/21/16 (Tue) 12:28:40 09d44b No.6407194>>6407197
911 40
912
913 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
914You will be surprised to learn there exists 16 network interfaces inside the
915device, most are legitimate, but others are part of The Hack.
916All IP + MAC addresses have been redacted to protect victims identities.
917# ifconfig a
918br0 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2 <redacted MAC address
919 inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0
920 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
921br1 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
922 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
923dsl0 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
924 [NO FLAGS] MTU:0 Metric:1
925eth0 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
926 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
927eth0.2 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
928 BROADCAST MULTICAST MTU:1500 Metric:1
929eth0.3 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
930 BROADCAST MULTICAST MTU:1500 Metric:1
931eth0.4 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
932 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
933eth0.5 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
934 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
935imq0 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
936 UP RUNNING NOARP MTU:16000 Metric:1
937 41
938
939 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
940imq1 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
941 UP RUNNING NOARP MTU:16000 Metric:1
942imq2 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
943 UP RUNNING NOARP MTU:16000 Metric:1
944pktcmf_sa Link encap:UNSPEC HWaddr FEFFFFFFFFFFFFFF0000000000000000
945 UP NOTRAILERS RUNNING NOARP MTU:0 Metric:1
946pktcmf_sw Link encap:UNSPEC HWaddr FEFFFFFFFFFFFFFF0000000000000000
947 UP NOTRAILERS RUNNING NOARP MTU:0 Metric:1
948ptm1 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
949 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
950ptm1.101 Link encap:Ethernet HWaddr 10:C6:1F:C1:27:A2
951 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
952ptm1.301 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A3
953 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
954 42
955
956 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
957Lets examine the routing table:
958# route n
959Kernel IP routing table
960Destination Gateway Genmask Flags Metric Ref Use Iface
961192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br0
962# ip route show
963192.168.1.0/24 dev br0 proto kernel scope link src 192.168.1.1
964# netstat n
965Active Internet connections (w/o servers)
966Proto RecvQ SendQ Local Address Foreign Address State
967tcp 0 0 192.168.1.1:23 192.168.1.100:57483 ESTABLISHED # telnet
968tcp 0 0 127.0.0.1:2600 127.0.0.1:33287 ESTABLISHED # Z>rip
969tcp 0 0 127.0.0.1:33287 127.0.0.1:2600 ESTABLISHED # rip>Z
970Active UNIX domain sockets (w/o servers)
971Proto RefCnt Flags Type State INode Path
972unix 3 [ ] STREAM CONNECTED 766 /var/BtAgentSocket # SPIES Socket
973Lets see what processes are running: (duplicate and uninteresting lines
974remove for brevity)
975# ps
976 PID Uid VSZ Stat Command
977 1 0 336 S init
978 101 0 SW [dsl0]
979 116 0 SW [eth0]
980 127 0 504 S mc
981 131 0 380 S /bin/msg msg
982 136 0 1124 S /bin/dbase
983 146 0 1680 S /bin/cms
984 147 0 1148 S /bin/cwmp
985 191 0 328 S zebra f /var/zebra/zebra.conf
986 193 0 332 S ripd f /var/zebra/ripd.conf
987 548 0 396 S dhcpc i ptm1.301 I ptm1.301 <HELLO?
988 552 0 504 S monitor
989 570 0 348 S dnsmasq conffile=/var/dnsmasq.conf
990 733 0 248 S tftpd p 69
991 741 0 292 S sshd E < HELLO?
992 762 0 1136 S MidServer
993 766 0 380 S /bin/sh /BTAgent/ro/start
994 780 0 832 S ./btagent
995All looks innocent at first. Now, lets plug-in the telephone line cable and wait
996few seconds:
997
998â–¶Anonymous 06/21/16 (Tue) 12:29:02 09d44b No.6407197
999>>6407194
1000 43
1001
1002 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1003NOTE: We have redacted some IP addresses assigned to us by the attacker
1004xx = redacted address.
1005# route n
1006Kernel IP routing table
1007Destination Gateway Genmask Flags Metric Ref Use Iface
1008192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br0
100930.150.xx.0 0.0.0.0 255.255.xxx.0 U 0 0 0 ptm1.301
10100.0.0.0 30.150.xx.1 0.0.0.0 UG 0 0 0 ptm1.301 <Default?
1011# ip route show
1012192.168.1.0/24 dev br0 proto kernel scope link src 192.168.1.1
101330.150.xx.0/21 dev ptm1.301 proto kernel scope link src 30.150.xx.xx
1014default via 30.150.xx.1 dev ptm1.301
1015We have a new IP address on VLAN 301, this is before any computers are
1016connected and before the PPPOE discover command has been issued from the
1017LAN connected Hub or PC. The default route sends all traffic to the
1018attacker by default @ 30.150.xx.1
1019How close is the attacker? very close, < 8ms
1020# ping 30.150.xx.1
1021PING 30.150.xx.1 (30.150.xx.1): 56 data bytes
102264 bytes from 30.150.xx.1: seq=0 ttl=64 time=7.174 ms
102364 bytes from 30.150.xx.1: seq=1 ttl=64 time=7.648 ms
102464 bytes from 30.150.xx.1: seq=2 ttl=64 time=7.685 ms
1025NOTE: You are now pinging the NSA/GCHQ
1026Now lets see what is happening at a socket level (comments on right after #):
1027# netstat an
1028Active Internet connections (servers and established)
1029Proto RecvQ SendQ Local Address Foreign Address State
1030tcp 0 0 0.0.0.0:161 0.0.0.0:* LISTEN # This is BTAgent
1031tcp 0 0 127.0.0.1:2600 0.0.0.0:* LISTEN # This is Zebra Router
1032tcp 0 0 127.0.0.1:8011 0.0.0.0:* LISTEN # Transparent tproxy
1033tcp 0 0 30.150.xx.xx:8081 0.0.0.0:* LISTEN # This NSA/GCHQ Services
1034tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN # This is DNS
1035tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN # This is SSH Server
1036tcp 0 0 0.0.0.0:23 0.0.0.0:* LISTEN # This is TELNET
1037tcp 0 55 192.168.1.1:23 192.168.1.100:57484 ESTABLISHED # This telnet session
1038tcp 0 0 127.0.0.1:2600 127.0.0.1:36825 ESTABLISHED # This is zebrarip
1039tcp 0 0 127.0.0.1:36825 127.0.0.1:2600 ESTABLISHED # This is rip>zebra
1040udp 0 0 0.0.0.0:69 0.0.0.0:* # TFTP Server for upgrades
1041Active UNIX domain sockets (servers and established)
1042Proto RefCnt Flags Type State INode Path
1043unix 3 [ ] STREAM CONNECTED 766 /var/BtAgentSocket # Special Agent BT
1044The device is now awaiting the hub/PC to issue a PPPOE discover request, at
1045which point you will receive your "Real Public IP".
1046At this point the attacker has complete control of the modem and your LAN,
1047extra firewall rules are added the moment the ptm1.301 VLAN device is
1048enabled by the dhcpc command.
1049
1050â–¶Anonymous 06/21/16 (Tue) 12:29:10 09d44b No.6407199>>6407204 >>6407345
1051 44
1052
1053 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1054 The UN-HACK
1055The UN-Hack
1056If you are able to login to your router (via serial port or LAN), there is a
1057defense which will prevent ALL the attacks using The Hack. This will un-
1058hack the modem and needs to be done after each reboot.
1059Step 1. Unplug the telephone cable and boot the Modem then login and issue
1060the following commands (in bold), the hash is the prompt (don't type that):
1061Kill the following processes:
1062# killall zebra ripd dnsmasq tftpd sshd MidServer
1063Kill the pids of the /bin/sh /BTAgent/ro/start:
1064# kill 766
1065Now, Kill all of the BTAgent processes:
1066# killall btagent
1067Unmount the BTAgent partition:
1068# umount /usr/BTAgent
1069Remove the attackers VLAN 301:
1070# vconfig rem ptm1.301
1071Kill the rogue dhcpc process with force (-9) or it will re-spawn
1072# killall -9 dhcpc
1073Remove all hidden firewall rules
1074# iptables -F -t mangle
1075# iptables -F -t nat
1076# iptables -F
1077Step 2. Plugin the telephone cable and the DSL will connect to BT (without
1078the NSA/GCHQ listening).
1079Step 3. Now start your PPPOE session from your second Linux firewall
1080machine as per the instructions for Inbound Defense and Outbound
1081Defense as applicable and Enjoy your privacy.
1082
1083â–¶Anonymous 06/21/16 (Tue) 12:29:28 09d44b No.6407204
1084>>6407199
1085 45
1086
1087 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1088 Special AgentBT
1089Special AgentBT
1090This "special" software installed on all modems provided by BT called
1091BTAgent.
1092This software listens on port 161, which is the IANA assigned port for Simple
1093Network Management Protocol (SNMP), anyone looking at this process would
1094automatically assume this to be the case. SNMP type programs are often
1095referred to as SNMP Agents.
1096The primary purpose of BTAgent is unpublished, but a version has been
1097partially reverse engineered and the software does download firmware and
1098update the modems flash.
1099BT responses to queries about their BTAgent is to claim that they need to
1100"remotely manage modems for security purposes".
1101User concerns with BTAgent:
1102 1. It's closed source
1103 2. Users cannot turn it of
1104 3. The secretive nature and responses from BT
1105 4. Users cannot upgrade the firmware using BTAgent
1106 5. Port 161 is open to the public internet
1107The second (special) purpose of the BTAgent is purely reverse reverse
1108psychology and designed to keep you wondering about it, to cause you to
1109waste your time reverse engineering it, when it may well be what it says on
1110the tin and while your thinking about BTAgent you're not thinking about the
1111other network interfaces such as ptm1.301 and the dhcpc requests which all
1112look innocent but actually perform the dirty deeds right in the open.
1113When you reverse engineer BTAgent and publish your results, this allows the
1114NSA/GCHQ to target you for other type of attacks.
1115We should remember, that with a single Firmware update from BTAgent, it
1116could morph itself and into what we originally feared!
1117
1118â–¶Anonymous 06/21/16 (Tue) 12:29:43 09d44b No.6407208
1119 46
1120
1121 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1122 Psychological and
1123 Physical Barriers
1124Barriers
1125The NSA/GCHQ will do anything and everything to stop the The Hack being
1126discovered. The first step is to deal with the majority of users and prevent
1127them from even thinking about opening it up or even touching the modem.
1128Some of the suggestions listed here may seem extreme, but the less interest
1129created in this box, the less attention it receives from consumers.
1130 1. It's a white box, psychologically it's not a "black box" so it should be safe
1131 2. It comes in a plain brown cardboard box, which contain no words or
1132 graphics whatsoever, with a single white bar-code label with make/model
1133 of the modem
1134 3. The BT engineer personally carries and installs it in your home, while
1135 other components such as BT Home Hub, the more expensive component
1136 are sent through the postal system. BT cannot leave this shiny white
1137 modem hanging around for a week while they allocate your connection,
1138 you may try to open it or do research about it online, and they want to
1139 know who is researching it
1140 4. The telephone socket (RJ11) is designed such that when you plug in the
1141 telephone cable, it becomes very difficult to remove it, much more so
1142 than a standard telephone RJ11. Its not just a case of pinching the lever,
1143 you have to pinch and push further in, then remove. This is subtle, but it
1144 will prevent a lot of people from even attempting to disconnect the
1145 telephone cable, just in case they break it
1146 5. The older model was easy to open, just a few screws, the newer models
1147 is almost impossible to open because it is clip locked closed, meaning
1148 that you will damage it if you attempt to open it
1149 6. Red Warning Sticker on the back  "Don't cover Air Holes", wise but
1150 scary
1151 7. The only documentation is a single piece of white paper detailing how it
1152 should be mounted, there is no instructions about which cables go
1153 where, this is designed never to be touched
1154 8. All internal serial port headers are removed so, you cant easily hack it
1155 9. The modem is plain white and square, extremely uninteresting, boring,
1156 "Nothing to see here, move along",
1157All of this subtle "Anti-Marketing" for the most advanced BT product?
1158
1159â–¶Anonymous 06/21/16 (Tue) 12:29:51 09d44b No.6407213
1160 47
1161
1162 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1163 Social Attacks on
1164 Engineers
1165Social Attacks on Engineers
1166Having discovered the attack architecture and disabled it, we decided to visit
1167some forums online, we were interested to see if anyone, anywhere is close
1168to uncovering The Hack and how the NSA/GCHQ react to such issues.
1169Generally, there are engineers chatting and sharing pictures of their modems
1170and how they solder wires on to the (usually hidden) serial ports, the
1171discussions usually leads to login and gaining root access of the modem or
1172replacing the firmware altogether.
1173When engineers start to get really close, something usually extra-ordinary
1174happens, almost like "superman to the rescue", someone who is highly
1175qualified, someone who has built up a reputation of being a ethical
1176hacker/security expert, introduces themselves and produces what appears to
1177be major break-through in gaining access to the modems.
1178However, because of the "ethical" element, superman instead of sharing the
1179method contacts BT, or BT contacts superman, directly and they agree to
1180allows BT to fix the flaw (e.g. giving BT a 30 days head start) after which,
1181superman will publish the method he used.
1182All things being equal, this is fair enough, but things are not all equal because
1183this was a complete smoke screen, played out to discourage the engineers
1184from further development knowing that in a few weeks "superman" will give
1185them access.
1186Many of the engineers/enthusiast waiting end-up getting caught by upgrades
1187of their modems firmware which then locks them out of the game.
1188This is a cat and mouse game, and engineers should be very wary of those
1189bearing gifts, their agenda is to slow you down and prevent you from making
1190any progress hoping you will just give up.
1191You can clearly see this on the BT forums as well others such as
1192http://www.psidoc.com, http://www.kitz.co.uk/, http://http://community.bt.com,
1193and others. Reverse engineering is legal, legitimate and it is a great source of
1194innovation.
1195
1196â–¶Anonymous 06/21/16 (Tue) 12:29:59 09d44b No.6407214
1197 48
1198
1199 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1200 Counter-Intelligence
1201Counter-Intelligence
1202The NSA/GCHQ et al. have being watching and attacking us, it's about time
1203we turned the tables, started defending ourselves and also watching them.
1204This section is not going to detail specific techniques, but rather suggest
1205overall approaches, some of which we have done over a period of months.
1206NSA Honeypots
1207Now we understand the attack architecture, we can simulate the modem in a
1208MIPS Virtual Machine (BTAgent is not required).
1209We can route the NSA/GCHQ traffic to your lab and just let them hack away in
1210a private cloud while we log traffic including how they attempt to use their
1211back doors and other dirty tricks.
1212You will need to forward and tap VLAN 301 (in the case of BT et al) to the
1213virtual modem where you can analyze its traffic in real-time or offline, you
1214should always store whatever information you gather forever, (just like they
1215do).
1216After gathering enough evidence, you can then publicize it and take legal
1217action, your logs can be used in court when you sue the conspirators and co-
1218conspirators under the "Computer Misuse Act 1990" as well as other laws.
1219
1220â–¶Anonymous 06/21/16 (Tue) 12:30:17 09d44b No.6407222
1221 49
1222
1223 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1224About the Authors
1225The authors of this document wish to remain anonymous. However we are
1226fully prepared to stand in a court of law and present our evidence.
1227We are a group of technical engineers, we are not associated with any
1228activists groups whatsoever. We don't have a name, but if we did it would
1229probably be "The Adversaries" according to NSA/GCHQ.
1230Our Mission
1231Freedom is only appreciated when lost. We are on the brink of a irreversible
1232totalitarian multi-government regime and even though the European
1233Parliament has stated that citizens should not have to defend themselves
1234against state sponsored Cybercrime, the fact remains that our own
1235Governments continue to attack us in our own homes while we sleep.
1236Our mission is defensive and legal. Our objectives are to expose the sources
1237and methods used by those that harm our personal freedoms and rights and
1238to provide practical information to individuals around the world allowing them
1239to defend themselves against such cyber attacks.
1240We believe this as well as future disclosures to be in the public interest.
1241Donations
1242Our ongoing work is technical, slow, tedious and expensive any donations are
1243very welcome. We only accept bitcoins at this time.
1244 bitcoin:1D6Hj37DS2mPTPm9u7TqS5ocddPHXjmau8
1245You can also support us by sending this document to a friend or host it on
1246your website.
1247Licensed under the Creative Commons Attribution-NoDerivs (CC BY-ND)
1248
1249â–¶Anonymous 06/21/16 (Tue) 12:30:31 09d44b No.6407226>>6407276 >>6407279
1250 50
1251
1252 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1253UPDATE 2
1254Documents released by Der Spiegel have confirmed our own findings, original
1255sources can be found here:
1256http://www.spiegel.de/international/topic/united_kingdom/
1257http://www.spiegel.de/international/topic/united_states/
1258The very fact that we reported these back-doors exactly as described in these
1259new leaks proves that our claims are legitimate and true. This is exactly what
1260we uncovered in BT's modems, the architecture, design and attackers
1261networks are exactly as we illustrated in our diagrams and descriptions and
1262list of capabilities.
1263We verified our results by purchasing and testing many modems directly from
1264the BT as well as third party sources, all of which had the back doors as
1265described.
1266Individual Der Spiegel documents relating to our claims can be found here:
1267Backdoors NSAGCHQ Verification Document
1268Firewalls http://cryptome.org/2013/12/nsa-ant-firewalls.pdf
1269Routers http://cryptome.org/2013/12/nsa-ant-router.pdf
1270QFIRE Attack Networks http://cryptome.org/2013/12/nsa-qfire.pdf
1271BULLRUN-NSA http://cryptome.org/2013/09/nsa-bullrun-2-16-guardian-13-0905.pdf
1272EDHEHILL http://cryptome.org/2013/09/nsa-decrypt-guardian-13-0905.pdf
1273BULLRUN-GCHQ http://cryptome.org/2013/09/nsa-bullrun-brief-nyt-13-0905.pdf
1274Public Comments http://cryptome.org/2013/12/full-disclosure-comments.htm