· 10 years ago · Jun 21, 2016, 05:18 PM
1Full Disclosure
2
3The Internet Dark Age
4
5· Removing Governments on-line stranglehold
6· Disabling NSA/GCHQ major capabilities
7 (BULLRUN / EDGEHILL)
8· Restoring on-line privacy - immediately
9
10
11 by
12
13 The Adversaries
14
15
16 Update 2
17
18 Spread the Word
19
20 1
21
22 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
23
24
25
26On September 5th 2013, Bruce Schneier, wrote in The Guardian:
27
28
29"The NSA also attacks network devices directly: routers, switches, firewalls, etc. Most of these devices
30have surveillance capabilities already built in; the trick is to surreptitiously turn them on. This is an
31especially fruitful avenue of attack; routers are updated less frequently, tend not to have security software
32installed on them, and are generally ignored as a vulnerability".
33
34
35"The NSA also devotes considerable resources to attacking endpoint computers. This kind of thing is done by
36its TAO  Tailored Access Operations  group. TAO has a menu of exploits it can serve up against your
37computer  whether you're running Windows, Mac OS, Linux, iOS, or something else  and a variety of tricks
38to get them on to your computer. Your anti-virus software won't detect them, and you'd have trouble finding
39them even if you knew where to look. These are hacker tools designed by hackers with an essentially
40unlimited budget. What I took away from reading the Snowden documents was that if the NSA wants in to
41your computer, it's in. Period".
42
43
44
45http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-
46surveillance
47
48
49The evidence provided by this Full-Disclosure is the first independent
50technical verifiable proof that Bruce Schneier's statements are indeed
51correct.
52
53
54 (previous readers should start on page 51)
55
56
57 This update includes 10 pages of additional evidence,
58 courtesy of the U.S. Government.
59
60
61
62
63 2
64
65 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
66
67
68
69 Full Disclosure
70
71 NSA/GCHQ
72 Sources and Methods
73 Uncovered
74
75We explain how NSA/GCHQ: Internet Wire-Tapping
76
77 · Are Internet wiretapping you
78
79 · Break into your home network
80
81 · Perform 'Tailored Access
82 Operations' (TAO) in your home
83
84 · Steal your encryption keys
85
86 · Can secretly plant anything they
87 like on your computer WARNING:
88 BT Broadband
89 · Can secretly steal anything they Equipment Contain
90 like from your computer
91 NSA/GCHQ
92 · How to STOP this Computer Back Doors
93 Network Exploitation
94
95
96 We expose NSA/GCHQ's most
97 Secret Weapon - Control
98 and how you can defeat it!
99
100
101
102 Dedicated to the Whistle-Blower
103
104 Mr Edward J. Snowden.
105
106
107 3
108
109 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
110
111
112Table of Contents
113 Preface.............................................................................................................6
114 Disclosures....................................................................................................6
115 Source of this Information...............................................................................7
116 Our Laws.......................................................................................................7
117 Companies....................................................................................................8
118 Technical Nature of this Information...........................................................8
119 Credibility of this Research..........................................................................9
120 Privacy vs Security.....................................................................................10
121 Motivation...................................................................................................11
122 Terminology................................................................................................12
123 Your Home Network......................................................................................13
124 The Hack.....................................................................................................16
125 How it Works..............................................................................................16
126 The Attacks.................................................................................................21
127 Internal Network Access............................................................................21
128 Man-In-The-Middle Attack..........................................................................22
129 All SSL Certificates Compromised in Real-Time........................................23
130 Theft of Private Keys..................................................................................24
131 The Kill Switch............................................................................................26
132 Uploading/Download Content....................................................................26
133 Hacking in to a VOIP/Video Conferences in Real-Time..............................26
134 Tor User/Content Discovery.......................................................................27
135 Encrypted Content......................................................................................27
136 Covert International Traffic Routing..........................................................27
137 Activists......................................................................................................27
138 Destroy Systems.........................................................................................27
139 Censorship..................................................................................................28
140 Mobile WIFI Attacks...................................................................................28
141 Document Tracking....................................................................................28
142 2G/3G/4G Mobile Attacks...........................................................................29
143 Basic Defense.............................................................................................30
144 Secure your end-points..................................................................................30
145 Inbound Defense.........................................................................................31
146 Outbound Defense......................................................................................32
147 More Defense Tips......................................................................................33
148 MITM Defense............................................................................................34
149 TCPCRYPT..................................................................................................35
150 Frequently Ask Questions..............................................................................36
151 Why Full Disclosure?..................................................................................36
152 Who should read this information..............................................................36
153 Why does this document exist....................................................................36
154 What about the debate, the balance?.........................................................36
155 I'm an American, does this apply to me.....................................................36
156
157
158 4
159
160 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
161
162 Will stopping BTAgent software stop these Attacks..................................37
163 Is it possible that BT is unaware of this.....................................................37
164 My equipment is completely different?......................................................37
165 I've never done anything wrong.................................................................37
166 How can I verify this myself.......................................................................37
167 I would like to donate and support your work...........................................37
168How you can verify........................................................................................38
169 Easy Confirmation......................................................................................39
170 Hard Confirmation......................................................................................40
171 The UN-Hack..............................................................................................45
172 Barriers.......................................................................................................47
173 Social Attacks on Engineers.......................................................................48
174Counter-Intelligence......................................................................................49
175 NSA Honeypots...........................................................................................49
176About the Authors..........................................................................................50
177 Our Mission................................................................................................50
178 Donations....................................................................................................50
179UPDATE 2......................................................................................................51
180 U.S. DOD IP Addresses...............................................................................52
181 U.K. MOD IP Addresses..............................................................................52
182 Locations of Attacker Networks.................................................................53
183 Notes:..........................................................................................................60
184
185
186
187
188 5
189
190 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
191
192
193
194 Preface
195
196Preface
197
198
199When the Government, Telecommunications companies and Internet Service
200Providers, implant secret spying equipment in your home without your
201knowledge or consent under the guise of something else, then use that
202equipment to infect your computers and spy on your private network activity
203(not the internet), we believe you have a right to know.
204
205It is not possible to make these claims without actual proof and without
206naming the actual companies involved.
207
208These events coincide with the global surveillance systems recently disclosed
209and they further confirm the mass scale of the surveillance and how deeply
210entrenched the Governments are in our personal lives without our knowledge.
211
212The methods we disclose are a violation of security and trust. Good
213Information Security (InfoSec) dictates that when we discover such back
214doors and activity, we analyze, understand, publicize and fix/patch such
215security holes. Doing otherwise is morally wrong.
216
217What is revealed here is the missing piece to the global surveillance puzzle,
218that answers key InfoSec questions which include:
219
220
221How do the NSA/GCHQ perform Computer Network Exploitation?
222
223
224We reveal the actual methods used by the NSA/GCHQ and others that allows
225them to instantly peer into your personal effects without regard for your
226privacy, without your knowledge and without legal due process of law, thus
227violating your Human Rights, simply because they can.
228
229
230Disclosures
231
232
233The risks taken when such activity is undertaken is "Being Discovered" and
234the activity being "Publicly Exposed", as well as the "Loss of Capability".
235
236
237
238
239 6
240
241 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
242
243
244Source of this Information
245
246
247 "The simple knowledge that we may be clandestinely observed in our own
248 homes provided the determination to find the truth, which we did."
249
250
251This information is not the result of any knowledge of classified documents or
252leaks, but based on information in the public domain and our own fact finding
253mission due to Forensic and Network Analysis Investigations of private SOHO
254networks located in the UK.
255
256
257As we detail the methods used, you will see that information was uncovered
258fairly, honestly and legally and on private property using privately owned
259equipment.
260
261Our Laws
262
263
264There is no law that we are aware of that grants to the UK Government the
265ability to install dual use surveillance technology in millions of homes and
266businesses in the UK.
267
268
269Furthermore, there is no law we are aware of that further grant the UK
270Government the ability to use such technology to spy on individuals, families
271in their own homes on the mass scale that this system is deployed.
272
273
274If there are such hidden laws, the citizens of the UK are certainly unaware of
275them and should be warned that such laws exist and that such activity is
276being engaged in by their own Government.
277
278
279All of the evidence presented is fully reproducible.
280
281
282It is our belief that this activity is NOT limited to the UK.
283
284
285
286
287 7
288
289 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
290
291
292Companies
293
294
295BT are directly responsible for covertly embedding secret spy equipment in
296millions of homes and businesses within the UK as our evidence will
297demonstrate.
298
299
300BT have directly enabled Computer Network Exploitation (CNE) of all its
301home and business customers.
302
303Technical Nature of this Information
304
305
306The information described here is technical, this is because, in order to
307subvert technology, the attackers need to be able to fool and confuse experts
308in the field and keep them busy slowing them down, but regardless, the
309impact and effect can be understood by everybody.
310
311
312Your main take away from this disclosure is to understand conceptually how
313these attacks work, you can then put security measures in place to prevent
314such attacks.
315
316
317
318
319 8
320
321 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
322
323
324Credibility of this Research
325
326
327We first made our discoveries in June 2013 and kept silent so that we could
328research the capabilities without being detected. As more Edward Snowden
329disclosures were published it became crystal clear that what we discovered is
330a major component of the surveillance system.
331
332
333Those who wish to discredit our evidence, feel free to do so, but do so on a
334technical level, simply claiming it "it's not true" or performing some social
335attack simply re-enforces it and identifies the "discreditor" as an agent of the
336NSA/GCHQ or an agent of the global surveillance system.
337
338
339Our evidence is based on public available UNMODIFIED firmware images.
340
341
342To verify our claims using UNMODIFIED images requires connecting a USB
343to serial port to the modem motherboard board which allows you to login
344(admin/admin) and verify yourself. As most people will find this difficult, we
345provided a link to third party MODIFIED images based on official BT release
346GNU source code that allow you to telnet to the device (192.168.1.1), this
347modified version includes the same backdoor. These can be found here:
348
349
350http://huaweihg612hacking.wordpress.com/
351and
352http://hackingecibfocusv2fubirevb.wordpress.com/
353
354
355The MODIFIED images have been publicly available since August, 2012, long
356before the Edward Snowden disclosures.
357
358
359The methods we published, allows confirmation without having to open the
360device. However if you are suspicious of the MODIFIED firmware from August
3612012, simply connect to the USB serial port of your own existing unmodified
362modem and login to verify, either way the results will be the same.
363
364
365
366
367 9
368
369 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
370
371
372Privacy vs Security
373
374
375Loss of privacy is a breach of personal security and the legal violation of
376privacy is purely a consequence of that security loss.
377
378We've focused on the technical breach of security i.e. the Computer
379Network Exploitation itself and by fixing that you can restore at least some of
380your personal privacy.
381
382This illustrates that there is no such thing as a balance between security and
383privacy, you have them both or you have none.
384
385
386
387
388 10
389
390 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
391
392
393
394 Motivation
395
396Motivation
397After studying in detail the revelations by the Edward Snowden, we realized
398there was a large missing part of the puzzle.
399
400
401There has been little to nothing published on specifically how the attackers
402technically achieve their goals. Most information published is based on
403theoretical situations.
404
405
406If we don't know how hackers actually achieve these security breaches, we
407cannot defend against such breaches.
408
409
410For example, a slide similar to the following was published, of all the slides
411released, it's uninteresting and easily dismissed, as it simply describes what is
412commonly known as a theoretical Man-In-The-Middle attack.
413
414
415
416
417The media focus of the slide is of course the Google's Servers, and your first
418thought might be, 'this is Google's problem to solve', but what if , 'Google
419Server' was 'My Banks Servers', you would probably be more concerned,
420because that may directly effect you.
421But we thought, what if, 'Google Server', was 'Any Server, Anywhere?'
422
423
424 11
425
426 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
427
428
429
430Our investigation led to us uncover, and understand how this attack really
431works in practice, how it is implemented and the hair-raising reality of its true
432nature and that is, this not just a back door, but an entire attack platform and
433distributed architecture.
434
435Terminology
436To ease explanation, we are going to use standard security terms from here
437on.
438
439
440Attacker - GCHQ, NSA, BT Group or any combination.
441
442
443The Hack  The technical method used by the attackers to illegally break into
444your home network computers and phones.
445
446
447
448
449 12
450
451 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
452
453
454
455 Basic Security
456
457Your Home Network
458In order to explain how these Computer Network Exploitation attacks work,
459and how this affects you personally, we must first look at the architecture of a
460typical home or office network. Look familiar to you?
461
462
463
464
465Most Internet connections consists of an DSL type modem and one or more
466Ethernet ports attached to the modem that you connect your computers,
467devices and add-on switches etc.
468
469
470There are two security factors in operation here:
471
472
473 a) NAT based networking, meaning that your home computers are
474 hidden and all share a single public IP address
475
476
477 b) Your modem has a built-in firewall which is blocks inbound traffic. The
478 inherent security assumption is that data cannot pass from the inbound
479 DSL line to a LAN switch port without first being accepted or rejected by
480 the built-in firewall
481
482
483 13
484
485 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
486
487For the technical minded, these security assumptions are further re-enforced
488if the modems software is open source e.g. using Linux and that its source
489code is freely and openly available as per the GNU GPL requirements.
490
491
492Given that the above is the most common architecture on the Internet as it
493applies to almost every home and office, everywhere, lets now revisit that first
494slide, but this time, we ask one simple question:
495
496
497 How do the attackers get between You and Google or some other
498 service?
499
500
501On closer inspection of the diagram you will notice that "Google Request"
502and the Attacker (Log into Router) share the same router, when this slide
503was released, we all assumed that this router was either Google's own router
504or some upstream router, that way the attacker could intercept packets and
505perform a Man-In-The-Middle (MITM) attack.
506
507
508However, this would not work for every website or service on the Internet.
509The attacker would need to be upstream everywhere!
510
511
512So where does the attacker hide? Where is this Common
513Router? again we ask:
514
515
516 How do the attackers get between You and Google or
517 some other service?
518
519
520Lets examine the diagram one last time.
521
522
523
524
525 14
526
527 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
528
529
530
531
532You guessed it, it's right inside your house. It's the router
533supplied by your trusted Internet Service Provider (ISP).
534
535If this is true, it means that you are being Internet wiretapped, because the
536attacker has as entered your private property and unlawfully accessed your
537computer equipment.
538
539Unlike a lawful interception in which a warrant is served on the third party
540(ISP), the intercept happens at the ISPs property upstream and outside your
541property.
542
543This is happening in your home or office, without your knowledge, without
544your permission and you have not been served with a search warrant as is
545required law.
546
547But worse, is the fact that this architecture is designed for Cyber Attacking
548in addition to passive monitoring as we will detail next.
549
550
551
552 15
553
554 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
555
556
557
558 The Hack
559
560The Hack
561This example is based on the UK version of what we are calling The Hack
562using BT Internet services. If you are not in the UK and regardless of the
563service, you should always assume that the exact same principles detailed
564here are always being used against you regardless of your country or ISP.
565
566
567The Hack is based on the fact that a second secret/hidden network and
568second IP address is assigned to your modem. Under normal use, you cannot
569detect or see this from your LAN, but the attacker has direct access to your
570modem and LAN in your house from the Internet.
571
572How it Works
573When the DSL connection is established a covert DHCP request is sent to a
574secret military network owned by the U.S. Government D.O.D. You are
575then part of that U.S. D.O.D. military network, this happens even before you
576have been assigned your public IP address from your actual ISP.
577
578
579This spy network is hidden from the LAN/switch using firewall rules and
580traffic is hidden using VLANs in the case of BT et al, it uses VLAN 301, but
581other vendors modems may well use different VLANs. The original slide has a
582strange number 242 with grey background, we think this represents the
583VLAN number/Vendor number so BT would be 301.
584
585
586This hidden network is not visible from your "Modem's Web Interface" and
587not subject to your firewall rules, also not subject to any limitations as far
588as the switch portion of your modem is concerned and the hidden network
589also has all ports open for the attacker.
590
591
592Other tools and services are permanently enabled inside the modem, which
593greatly aid the attacker, such as Zebra & Ripd routing daemons, iptables
594firewall, SSH remote shell server, along with a dhcp client.
595
596
597These tools allow the attacker to control 100% of the modem functionality
598from the Internet and in an undetectable manner. e.g., the attacker can
599
600
601 16
602
603 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
604
605forward all your DNS requests to their private network, they can selectively
606route specific protocols, ports or networks or everything to their network and
607by default they do.
608
609
610Although the hidden network is owned by U.S. D.O.D., it is located within the
611UK as the ping time to the attacker's IP gateway is < 8ms from within the
612UK.
613
614
615This clearly demonstrates that the UK Government, U.S. Government, U.S.
616Military and BT are co-operating together to secretly wiretap all Internet
617users in their own homes (with few exceptions). The modems are provided by
618BT and locked down. If you cannot confirm otherwise, you must assume that
619all ISPs in the UK by policy have the same techniques deployed.
620
621
622Your home network actually looks something like the following diagram. To
623the right is the WHOIS record of the network our modems are automatically
624connected, yours may vary.
625
626
627
628
629The above hidden network is created automatically
630in all our test cases across a wide range of modems.
631
632
633It should be noted that even before your Point-to-Point over Ethernet (PPPOE)
634request is issued, this hidden network is already fully operational. So much
635so, that your LAN can be directly accessed even when you think your modem
636is off-line.
637
638
639This is an extremely complex and covert attack infrastructure and it's built
640
641
642 17
643
644 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
645
646right into your modems firmware which can also be updated remotely as
647required by the attacker using the built-in BTAgent.
648
649
650The Hack attack is turned on by default, but is selectively turned off for
651special purposes or specific dangerous customers, for example, for certain
652software, firmware and hardware developers/engineers (which may include
653you), so that these people don't discover The Hack.
654
655
656The attacker identifies these specific "threats" and marks their Internet
657connections as "NO DHCP", such that the same dhcpc requests from their
658telephone lines are ignored and while these requests are ignored, the hidden
659network will not appear inside their modem and is much harder to discover.
660
661
662Firmware engineers usually want to know if the modems are using Open
663Source software such as Linux and Busybox, in which case they are subject to
664the terms of the GNU Public License.
665
666
667These engineers as well as tech savvy users may wish to put their own
668software (e.g. OpenWRT) on these modems, maybe because they don't trust
669their ISP, but are prevented by their ISP for obscure reasons.
670
671
672Most modem providers usually violate copyright law by not releasing the
673source code and BT was no exception to this rule. Only by the threat of legal
674action did they release the source code. However, BT still prevents the
675modems from being updated by their customers or third parties.
676
677
678BT goes to extreme lengths to prevent anyone from changing the firmware,
679and those that come close are first subjected to Physical and Psychological
680Barriers explained later and the few that overcome that, are subjected to a
681separate NSA/GCHQ targeted Social Attack designed specifically to derail
682any engineering progress made, this is also explained later. These attacks are
683almost always successful.
684
685
686During these attacks, BT uses all the information discovered by the engineers
687to produce firmware updates that prevent anyone else using those same
688techniques under the guise of security and protecting the customer and this is
689performed without notice to any customers.
690
691
692As we move to new generations of hardware, the modems are very
693
694
695 18
696
697 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
698
699sophisticated and very covert, the engineers capable of even attempting to
700replace the firmware become practically non-existent.
701
702
703As we detail, the sole purpose of locking the modem is to prevent people
704discovering that they are actually being wiretapped by BT on behalf of
705NSA/GCHQ.
706
707
708As a side note NSA describe Linux/Open Source as Indigenous and a SIGINT target.
709
710
711
712
713NSA documents, describe this means of SIGINT collection as:
714
715
716
717
718Others include:
719
720
721
722
723and
724
725
726
727
728 19
729
730 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
731
732
733
734 Your Real Network
735
736Your Real Network
737The following is a more realistic view of your home network and what is now
738possible, given the attacker now has secret access to your home LAN.
739
740
741
742
743It is now a simple matter to use other tools and methods available to the
744attacker to penetrate your internal computers, this includes:
745
746 · Steal private VPN/SSH/SSL/PGP keys ·Steal content as required
747
748 · Infect machines with viruses ·Access Corporate VPNs
749
750 · Install key loggers ·Clean up after operations
751
752 · Install screen loggers ·Route traffic on demand (e.g. MITM)
753
754 · Clone/destroy hard drives ·Censorship and Kill Switch
755
756 · Upload/destroy content as required ·Passive observation
757
758
759
760
761 20
762
763 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
764
765
766
767 The Attacks
768
769The Attacks
770This section lists the attacks on you that are now possible by the NSA/GCHQ.
771
772Later, we show how you can defend against these attacks and it would be wise
773to implement our defenses with immediate effect.
774
775Unlike the revaluations so far by Snowden where the attacks occur out there
776somewhere on the Internet, these attacks happen in your home/office.
777
778The attacks listed are the most obvious attacks, some are mentioned in
779Edward Snowden revelations and referred to as Computer Network
780Exploitation (CNE).
781
782
783Internal Network Access
784The attacker has direct access to your LAN and is inside your firewall.
785
786Your modem acts as a server, it listens on lots of ports such as SSH (22) and
787TELNET (23), so the attacker can just hop on to it (but you cannot).
788
789This is possible because another hidden bridged interface exists with its own
790VLAN. Firewall rules do not apply to this interface, so the attacker can see
791your entire LAN and is not subject to your firewall rules because those rules
792apply to the BT link (black line) not the attackers link (red lines).
793
794When you scan your BT Public IP address from outside, you may well only see
795port 161 open (BTAgent, more on this later), but when scanned from the
796attackers network, all necessary ports are open and with an SSH daemon
797running (even the username and password are the basic admin:admin).
798
799Basically the attacker is inside your home network, and ironically, in most
800cases, right behind your actual curtain (where the modems are usually
801located).
802
803This is the digital version of Martial Law with a Cyber Attack Soldier in every
804home in the country.
805
806The first task of the attacker is to perform a site survey and learn as much as
807
808
809 21
810
811 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
812
813possible about all the devices attached to your network.
814
815All your hardware can be identified by the specific MAC addresses and then
816fingerprinted for specific protocols and software versions. All this cannot be
817detected unless you are logged into your locked modem.
818
819The above is just the base platform of the NSA/GCHQ from which hundreds of
820types of attacks are now possible, which now include all of the following:
821
822
823Man-In-The-Middle Attack
824The attacker controls all outbound routes, he can easily perform an HTTPS
825Man-In-The-Middle attack by forwarding specific traffic for port 443 or
826destination network to a dedicated MITM network which he controls (as per
827previous slides).
828
829The only thing required is a valid SSL certificates + keys for a specific domain
830(which he already has, see below), The attacker is between you and any
831site you visit or any service you use (not just websites). e.g. Skype, VOIP, SSH
832etc.
833
834The attacker simply creates a static route or more easily publishes a Routing
835Information Protocol Request (RIP) request to the Zebra daemon running in
836the router for the target network address and your traffic for that network
837will then be routed to the attackers network undetectable by you.
838
839The attacker can then use asymmetric routing and upon examination of the
840requests he can filter specific requests he is interested in and respond to
841those, but let the target website server or service respond to everything else.
842
843The key here, is, traffic from the target website back to the user does not
844then have to go via the attackers hidden network, it can go directly back to
845users public IP (which would be logged by the ISP).
846
847MITM can be on any port or protocol not just HTTPS (443), for example your
848SSH connections, all UDP or GRE, PPTP, IPSec etc. or any combination of
849anything.
850
851
852
853
854 22
855
856 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
857
858
859All SSL Certificates Compromised in Real-Time
860
861
862The security of Public Key Infrastructure (PKI) is based primarily on the
863security of the owners private keys. These private keys are not necessarily
864required in order to perform a MITM attack.
865
866All that is required is an actual duplicate signed certificate using NSA/GCHQ
867own private keys. The MITM attack can be as simple as running a transparent
868proxy and you will always see a valid certificate but unable to detect the
869attack.
870
871At the point of the proxy all your traffic is decrypted in real-time, at which
872point targeted packet injection can occur or simply monitored.
873
874It makes perfect sense that the trusted Certificate Authority (CA) actually
875make a second duplicate SSL certificate with a separate set NSA provided
876private keys, as the CA never sees the real certificate owners private keys.
877
878When you send your Certificate Signing Request (CSR) and order your SSL
879Certificate, a duplicate signed certificate is then automatically sent to the
880NSA and stored in their "CES Paring database" as per Snowden releases.
881
882We must therefore assume that NSA/GCHQ already have a duplicate of every
883PKI certificate+key (key different from yours).
884
885This means as soon as you revoke or renew your certificate, the NSA is ready
886and waiting again, allowing them to do real-time decryption on almost any
887site anywhere across any protocol that uses PKI.
888
889
890
891
892 23
893
894 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
895
896
897Theft of Private Keys
898Home networks are usually very insecure, mainly because only you or family
899use them, your guard is down and your SSH, VPN, PGP, SSL keys are all
900vulnerable to theft by the attacker and his available methods.
901
902The Hack is the key mechanism that enables these thefts.
903
904As an example of the above, if you use the modems built-in VPN feature, you
905usually add your certificate and private key to the modem or generate them
906both via its web interface, at some later time, the attacker can just copy
907these keys to the "CES Pairing database" via his private network, the data
908collected from SIGINT can later be decrypted off-line or in real-time.
909
910In the case of keys extracted from the modems built-in VPN, the "CES Paring
911database" now contains the real key/cert pair, meaning the attacker can now
912attack the VPN server environment directly when that server would have not
913being exploitable otherwise.
914
915The attacker can also mask as the genuine user by performing the server
916attack from within the users modem (using the correct source IP address),
917this way nothing unusual will appear in the VPNs logs. Once inside the
918parameter of the VPN server the cycles repeats.
919
920You should assume that all "Big Brand" VPNs and routers use the exact same
921attack strategy and architecture with variances in the specific implementation
922e.g. Big Brand supports IPSec, Little Brand supports PPTP.
923
924The NSA Bullrun Guide states:
925
926 "The fact that Cryptanalysis and Exploitation Services (CES) works with
927 NSA/CSS Commercial Solutions Center (NCSC) to leverage sensitive,
928 cooperative relationships with specific industry partners".
929
930 Specific implementations may be identified by specifying Equipment
931 Manufacturer (Big Brand/Make/Model), Service Provider (ISP) or Target
932 Implementation (specific modem/router implementation).
933
934In this disclosure, we are interested in "Target Implementation", because in
935our example case, BT has covertly implanted these devices in homes where
936there is an absolute expectation of privacy, whereas the other
937implementations exist within the ISP or large corporations in which you
938cannot expect privacy.
939
940It's important to remember that "Big Brands" also make small SOHO DSL and
941
942
943 24
944
945 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
946
947cable modems.
948
949Further evidence of the mass global distribution of this technology to at least
950the 14 Eyes: USA, GBR, CAN, AUS, NZL, FRA, DEU, DNK, NLD, NOR, ESP,
951ITA, BEL, SWE and almost certainly many more countries:
952
953Quote from GCHQ regarding their ability to steal your private keys:
954
955
956 It is imperative to protect the fact that GCHQ, NSA and their Sigint
957 partners have capabilities against specific network security technologies
958 as well as the number and scope of successes. These capabilities are
959 among the Sigint community's most fragile, and the inadvertent
960 disclosure of the simple "fact of" could alert the adversary and result in
961 immediate loss of the capability.
962
963 Consequently, any admission of "fact of" a capability to defeat encryption
964 used in specific network communication technologies or disclosure of
965 details relating to that capability must be protected by the BULLRUN
966 COI and restricted to those specifically indoctrinated for BULLRUN.
967
968 The various types of security covered by BULLRUN include, but are not
969 limited to, TLS/SSL, https (e.g. webmail), SSH, encrypted chat, VPNs
970 and encrypted VOIP.
971
972And
973
974 Reports derived from BULLRUN material shall not reveal (or imply) that
975 the source data was decrypted. The network communication technology
976 that carried the communication should not be revealed.
977
978From the NSA:
979
980
981
982
983 25
984
985 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
986
987The Kill Switch
988
989
990Actual capabilities uncovered here include the actual ability to apply physical
991censorship on the Internet by governments directed at individuals, groups,
992companies, entire countries or the majority of the users of the Internet at
993once (given a coordinated government agreement). This is something that can
994be turned on globally within minutes.
995
996This "kill switch" is only a small portion of the total capabilities available that
997are in place right now. Essentially, any operation that can be applied using a
998single firewall or RIP router, can be applied to every customer at once.
999
1000
1001Uploading/Download Content
1002The attacker can upload or download content via either your public ISPs
1003network or via his private hidden network. The differences is that your ISP
1004could confirm or deny from their logs the user did or did not upload/download
1005content from/to a particular source.
1006
1007In other words, the possibilities and ability to frame someone cannot ever be
1008overlooked.
1009
1010When the attackers steal content, that information always travels via the
1011private network.
1012
1013Hacking in to a VOIP/Video Conferences in Real-Time
1014As an example, it's a trivial matter for the attacker to route specific traffic for
1015specific media protocol such as VOIP (SIP/H.323/RTSP) etc. to his network in
1016real-time these protocols are usually not encrypted so no key theft is required.
1017
1018In the case of Skype, it's no stretch of the imagination to assume that
1019Microsoft handed over the keys on day one.
1020
1021Those they do not redirect in real-time as we know, will be collected via
1022upstream SIGINT.
1023
1024
1025
1026
1027 26
1028
1029 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1030
1031
1032Tor User/Content Discovery
1033Users of the Tor network can easily be discovered by LAN packet
1034fingerprinting, but also by those who download the Tor client. The attacker
1035can stain packets leaving your network and before entering the Tor network,
1036making traffic analysis much easier than was previously known.
1037
1038All Tor traffic can be redirected to a dedicated private Tor network
1039controlled by the attacker, in this way the attacker controls ALL Tor nodes
1040and so can see everything you do from end-to-end.
1041
1042This is not something the Tor project can fix, it can only be fixed by the user
1043following our methods.
1044
1045Tor hidden services should drop all traffic from un-trusted Tor nodes, this way
1046clients running in the simulated Tor network will fail to connect to their
1047destination.
1048
1049Encrypted Content
1050The attacker is in your network and has all the tools necessary (such as
1051operating system back doors) or zero day vulnerabilities to hack into your
1052computers and steal your VPN, PGP, SSH keys as well as any other keys they
1053desire. Also, content that is encrypted can be captured before encryption via
1054any number of methods when the attacker is already inside your network.
1055
1056
1057Covert International Traffic Routing
1058The attacker can secretly route your traffic to the U.S. without your
1059permission, consent or knowledge thus by passing any European data
1060protection or privacy laws.
1061
1062
1063Activists
1064We have seen many activist groups, protest organizers identified and silenced
1065over the few years, we believe this is the primary method used to capture
1066activists. Knowing the victims ISP would indicate which ISPs are involved.
1067
1068
1069Destroy Systems
1070Released documents state that the U.S. Cyber Command have the ability to
1071disable or completely destroy an adversaries network and systems, the first
1072step to this would be to penetrate the adversaries network firewall making
1073secondary steps much easier.
1074
1075
1076
1077 27
1078
1079 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1080
1081Censorship
1082The attacker has control of the hidden firewall, it is easy for the attacker to
1083simply block traffic based on specific ports or based on destination address or
1084network route, for example, the government can block port 8333 at source
1085and therefore block all Bitcoin transactions.
1086
1087A coordinated attack on the Bitcoin network is possible by blocking ports of
1088Minors around the world. Reducing the hash rate and blocking transactions.
1089
1090
1091Mobile WIFI Attacks
1092Mobile devices phones/tablets etc, are as easily accessible once they connect
1093to your WIFI network which is, from the attackers perspective, just another
1094node on the your LAN that the attacker can abuse.
1095
1096The level of sophistication or advanced encryption in use by your WIFI is no
1097defense because the attacker has gained a trusted position in your network.
1098
1099All MAC addresses gathered from your LAN are stored in the XKEYSCORE
1100database so they can be used to identity specific devices and specific
1101locations, allowing the attacker to track you without the aid of GPS or where
1102no GPS signal exists.
1103
1104
1105Document Tracking
1106Microsoft embeds the physical MAC addresses of the computer inside
1107documents it creates. This allows the source of a document to be identified
1108easily. The following is from the XKEYSCORE PowerPoint.
1109
1110
1111
1112
1113 28
1114
1115 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1116
1117
1118
1119 The Mobile Hack
1120
1121
11222G/3G/4G Mobile Attacks
1123Given the NSA/GCHQ plan to spy on "any phone, anywhere, any time".
1124The Hack detailed in this document is a carrier independent method to
1125achieve that goal that works very well. The attacker will almost certainly re-
1126use the same strategy for all Mobile phones or wireless broadband devices.
1127
1128Your mobile phone (2G/3G/4G) is almost certainly subject to this same attack
1129architecture because from the attackers perspective, his side of the
1130infrastructure would remain the same regardless of device being attacked.
1131
1132A mobile phone these days is simply a wireless broadband modem + phone,
1133so any encrypted messaging system for example can be captured before
1134encryption. Therefore mobile phones are subject to all the same and many
1135more attacks as per The Hack.
1136
1137This would mean that mobile phone makers may well be in collusion with the
1138NSA/GCHQ because they would need to implement the equivalent routing
1139and firewall ability in each mobile phone as part of the OS if it was to remain
1140hidden.
1141
1142The mobile phone version of The Hack is also much more difficult to detect
1143than the broadband version. Mobile phones make more use of IPv6 and the
1144overall complexity of IPv6 means that even experts may not know what they
1145are looking at in the routing tables even if they could see them. Carriers often
1146have multiple IPs for different services they provide.
1147
1148Even top-up mobile phones without any credit can be accessed, for example,
1149the mobiles phones top-up services are always available and their DNS
1150servers are always accessible regardless of your top-credit state.
1151
1152Modern kernels use multiple routing tables (e.g. ip rule show) for policy based
1153routing, so again unless you confirm who owns a specific IP6 range, it will be
1154difficult to spot, especially as firmware hackers are not even looking for such
1155back doors. Maybe now they will.
1156
1157
1158 We do not provide defense methods for Mobile Phones at this time.
1159
1160
1161 29
1162
1163 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1164
1165
1166
1167 Basic Defense
1168
1169Basic Defense
1170Knowing how you are being attacked is half the battle, but in this case, due to
1171the attackers abuse of a privileged position and the fact that the attacker is
1172your own government and its foreign partners, defense is much more difficult,
1173compared to a common virus, worms or hackers.
1174
1175One of the best defenses is to take Legal action against BT or your ISP.
1176
1177If you are serious about your privacy, don't expect any help from your
1178attackers (as attackers never help their victims). You must ensure your own
1179privacy. Before we explain practical defenses, here are some good tips.
1180
1181
1182Secure your end-points
1183
1184
1185 · Never ever trust ISP supplied equipment (e.g. router, firewall, STBs),
1186 always consider such devices as hostile and position them in your
1187 network architecture accordingly i.e. in the Militarized Zone (MZ)
1188 · Do not use any built-in features of ISP equipment (e.g. Firewalls, VPNs)
1189 · Never ever trust a device that has any closed source firmware or other
1190 elements, regardless of the excuses the your attacker gives you
1191 · Never trust a device that you cannot change the firmware yourself,
1192 regardless of "big brand" names
1193 · Disable all protocols that you don't use or don't understand, especially
1194 TR-069 and any other Remote Management features, these are all part of
1195 the surveillance control system (e.g. BTAgent firmware update)
1196 · Always use a second Linux firewall which you control, that you have built
1197 · Control all your NAT on your second Linux firewall not the ISPs supplied
1198 router
1199 · Make sure you control all end-points whenever possible
1200 · Ensure that 100% of packets UDP/TCP (e.g. including DNS) are
1201 encrypted leaving your second firewall (this is the key to end-point
1202 security), this requires using Outbound Defense method described
1203 later
1204 · Always use a VPN and remote proxy that you control or trust, disable
1205 logging altogether to protect privacy. This requires using Outbound
1206 Defense method described later
1207
1208
1209 30
1210
1211 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1212
1213
1214
1215
1216 Inbound Defense
1217
1218Inbound Defense
1219This defense method against most NSA/GCHQ Inbound attacks is fairly easy
1220to implement and not too technical, everybody at a minimum should include
1221this method in their defense strategy.
1222
1223The strategy will only prevent NSA/GCHQ from hacking into your home/office
1224LAN. It cannot prevent other direct attacks because the attacker can still
1225intercept and route all packets leaving your property.
1226
1227
1228
1229
1230A second Linux firewall device (blue) that you control and manage is
1231placed in front of the ISP router effectively placing the ISPs router in the
1232Militarized Zone (MZ) i.e. the Internet. A single cable (red) is used to link the
1233LAN of the ISP router to the Internet LAN port of the Linux firewall.
1234
1235Block all inbound access including multicast packets from the ISP router, run
1236DHCP and NAT on your Linux firewall.
1237
1238Your second firewall can then issue PPPOE requests via its Internet port and
1239create a local ppp0 device which will be its new Internet connection. All
1240packets leaving the firewall will now be PPPOE encapsulated.
1241
1242 31
1243
1244 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1245
1246
1247
1248 Outbound Defense
1249
1250Outbound Defense
1251This defense method should be used against all NSA/GCHQ Inbound and
1252Outbound attacks. This is the only sure fire method to protect Tor clients.
1253
1254This defense requires that you (control/own/rent) a Server or VM elsewhere
1255on the Internet (far away from your ISP) and preferably in a different country.
1256
1257Run a VPN such as OpenVPN between your Linux Firewall (blue) and the
1258your VPS server (green cloud), there, you run Squid Proxy and DNS and
1259block all inbound access except from your VPN. Always run your own DNS
1260service on your VM/Server.
1261
1262
1263
1264
1265 32
1266
1267 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1268
1269An alternative short-term defense is to use OpenWRT router software that
1270you install into the modem yourself so that you can confirm no hidden
1271networks or IP addresses exists and that the firewall actually functions.
1272
1273However, this is technically impossible for must users.
1274
1275For open source router software visit https://openwrt.org/
1276
1277
1278More Defense Tips
1279
1280
1281 · Isolate your WIFI from your LAN and limit by MAC address + strong
1282 passwords alternatively, Isolate your WIFI from your LAN and leave it
1283 open as a free hot-spot.
1284 · If you are capable, install your own router firmware (openwrt)
1285 · Tell your ISP you do NOT want a router with back doors or malware in it,
1286 ask them to confirm in writing that back doors do not exist, this will help
1287 you in court when suing them
1288 · Stop using any operating systems that is known to contain back doors
1289 · Only use Tor if you are using Outbound Defense method, otherwise you
1290 could be using a NSA/GCHQ wonderland version of the Tor network
1291 · It cannot be emphasized enough, never trust closed source routers
1292 · Never use your ISP DNS servers
1293
1294
1295
1296
1297 33
1298
1299 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1300
1301
1302
1303 MITM Defense
1304
1305MITM Defense
1306Until now, it was not fully understood how a MITM actually worked with
1307regard to how the attacker could get in the middle of any connection.
1308
1309Now we know with 100% confidence that the man is not in the middle, but in
1310the modem and that's how any individual can be subjected to MITM attack.
1311We hereby rename this attack Man-In-The-Modem attack.
1312
1313As an alternative defense for the future in place of the previous (admittedly
1314complex outbound defense), you could use TcpCrypt. You can prevent this
1315attack by ensuring that your client and servers are running TcpCrypt, which is
1316a TCP protocol extension. It works without any configuration and
1317automatically encrypts TCP connections if both server and client support it or
1318it will fall back to no encryption. It's also 100% NAT friendly.
1319
1320
1321
1322
1323Once installed, this works for any port not just port 80, it will also protects
1324HTTPS, SMTP, SSH and every other service.
1325
1326
1327 34
1328
1329 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1330
1331
1332
1333 TCPCRYPT
1334
1335TCPCRYPT
1336TcpCrypt is a very secure approach to many of the problems posed by the
1337NSA/GCHQ because its true native end-to-end encryption and does not
1338require a certificate authority and is free open source software.
1339
1340The NSA have tried to kill this project a number of times and will continue to
1341do so or limit its use, you must not let that happen.
1342
1343
1344
1345
1346 Let's get all TCP connections
1347 Encrypted by default!
1348
1349 Available now free open source for Linux, Windows and OSX visit:
1350
1351
1352 http://www.tcpcrypt.org/
1353
1354 Kernel Developers - please support
1355
1356 TcpCrypt Kernel Module
1357
1358
1359
1360If you would like to see how NSA and GCHQ agents try to kill projects like
1361this in public, view the video http://www.tcpcrypt.org/talk.php and go to
136226:22 and hear the voice of the NSA and then GCHQ.
1363
1364
1365
1366
1367 35
1368
1369 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1370
1371
1372Frequently Ask Questions
1373
1374Why Full Disclosure?
1375We are under no obligation to withhold this information from citizens of
1376Europe, specifically we are not subject to any provisions of the Official
1377Secrets Act of 1998 as we have never been:
1378
1379 · a member of the security and intelligence services
1380
1381 · a Crown servant or a government contractor
1382
1383But more importantly because:
1384
1385 · This information was discovered on private property
1386 · As security conscious users of the Internet, we identified serious
1387 intentional security flaws which need to be fixed, and fast
1388 · The needs of the many outweigh the needs of the few
1389 · Under the rule of law, the truth is an absolute defense and that is what
1390 we present here
1391 · lastly, Because we can
1392
1393Who should read this information
1394The intended audience is citizens of Europe, but anyone who is or could be a
1395victim of global surveillance systems, this includes everybody in the world
1396now and in the future.
1397
1398Why does this document exist
1399When a person(s) or government takes away your inalienable rights such as
1400your Right to Privacy (especially in your own home), you take it back. This is
1401not something that can be negotiated or traded.
1402
1403What about the debate, the balance?
1404There is no such thing as a balance between privacy and security, you either
1405have them both or you have none.
1406
1407I'm an American, does this apply to me
1408The NSA would only use this technique in the U.S. if they really thought they
1409could go undetected. In the UK they have gone undetected until now (since
14102011, as evidenced by the date of the firmware), you should assume that the
1411U.S. is doing the same to all Americans and you should use the defenses as
1412detailed herein as a precaution. We can turn off the lights ourselves.
1413
1414
1415
1416
1417 36
1418
1419 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1420
1421Will stopping BTAgent software stop these Attacks
1422No. BTAgent is just misdirection. It is not required or directly used in the
1423attacks. It can be used to update the firmware of a target modem should the
1424attacker need specific functionality on the modem, but this would be
1425unusual. So, killing BTAgent is does not help (you should kill it anyway).
1426
1427
1428Is it possible that BT is unaware of this
1429No, this is their firmware, controlled by BT, publish by BT, updated by BT,
1430they also lock the modems.
1431
1432
1433My equipment is completely different?
1434The Hack is an NSA/GCHQ Global Strategy and its architecture is
1435independent of a specific make or model of modem or mobile phone, it is also
1436independent of the method transport e.g. dial-up vs. ADSL, DOCSIS, VDSL,
1437Cable modem etc.. It sits at the top of the stack (TCP/UDP etc), so however
1438you connect, it connects. Each implementation will vary and improve with
1439each generation.
1440
1441You should only use, fully open source, firmware that is publicly verified.
1442
1443I've never done anything wrong
1444Yes you have, you have allowed hackers to enter your home network and plant
1445malware that infects your computers, which may now have become part of a
1446zombie army with tentacles controlled by the NSA/GCHQ. This is worst than
1447any virus or worm you can imagine.
1448
1449
1450How can I verify this myself
1451Following the instructions in the following sections, you can also create
1452simulations off-line, but that is more technical.
1453
1454
1455I would like to donate and support your work
1456Thank you, please see the last page of this document for details.
1457
1458
1459
1460
1461 37
1462
1463 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1464
1465
1466How you can verify
1467The following section explains how you can confirm that your modem has the
1468GCHQ/NSA back door.
1469
1470In these examples, we use two BT OpenReach white modems, (but more
1471accurately described as BT OverReach) models:
1472
1473Huawei EchoLife HG612 and ECI B-FOCuS VDSL2 modem.
1474
1475These two look almost identical. The HG612 is an earlier model.
1476
1477
1478
1479
1480The process of confirmation is slightly different for each modem.
1481
1482We will show two of ways to verify the back door, the first is something
1483anyone can do and requires just the ping command. The second requires re-
1484flashing the firmware so you can login to the modem itself.
1485
1486Claims of Huawei modems (Left) having back-doors are false, the vendor
1487(e.g. BT) build and install the OS for these modems. Huawei simply
1488provided hardware. ECI Telecom Ltd, is the provider of the second modem
1489(Right) Â the more dangerous of the two.
1490
1491
1492
1493 38
1494
1495 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1496
1497Easy Confirmation
1498
1499
1500Step 1. Remove Power from the modem and disconnect the telephone line.
1501
1502Step 2. On your PC (assumed Linux) add an IP address 192.168.1.100 i.e:
1503 # ifconfig eth0:1 192.168.1.100 up
1504
1505Step 3. Start to ping 192.168.1.1 from your PC i.e:
1506 # ping 192.168.1.1
1507
1508Step 4. Connect a network cable to LAN1
1509
1510Step 5. Plug-in the power cable to the modem and wait for about 30 seconds
1511for the device to boot, you will then notice:
1512
151364 bytes from 192.168.1.1: icmp_seq=115 ttl=64 time=0.923 ms
151464 bytes from 192.168.1.1: icmp_seq=116 ttl=64 time=0.492 ms
151564 bytes from 192.168.1.1: icmp_seq=117 ttl=64 time=0.514 ms
1516
1517You may notice up to ten responses, then it will stop.
1518
1519What is happening is the internal Linux kernel boots, the start up scripts then
1520configure the internal and virtual interfaces and then turn on the hidden
1521firewall at which point the pings stop responding.
1522
1523In other words, there is a short window (3-10 seconds) between when the
1524kernel boots and the hidden firewall kicks in.
1525
1526You will not be able to detect any other signs of the hidden network without
1527actually logging into the modem, which is explained in the next section.
1528
1529
1530
1531
1532 39
1533
1534 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1535
1536
1537Hard Confirmation
1538
1539
1540Method 1: (no firmware modification required)
1541For this method, you need to connect a USB to serial port to the serial port
1542pins on the modem motherboard as detailed here:
1543
1544http://hackingecibfocusv2fubirevb.wordpress.com/
1545
1546If you are unable to use this method because it requires opening the modem,
1547please use method 2.
1548
1549Method 2: (public firmware modification required)
1550For this method, you will need to re-flash the modem by following the
1551instructions in the document called hg612_unlock_instructions_v1-3.pdf
1552which is available from:
1553
1554http://huaweihg612hacking.files.wordpress.com/2011/11/hg612_unlock_instru
1555ctions_v1-3.pdf
1556
1557Or you can navigate to: http://huaweihg612hacking.wordpress.com/
1558and click "Unlocked Firmware Images for Huawei HG612" on the right
1559panel.
1560
1561Once you have re-flashed your modem, you will be able to login to the modem
1562via telnet as follows.
1563
1564Note: If your network is not 192.168.1.0, you will need to add the IP address
1565to your PC as explained previously, i.e.
1566
1567# ifconfig eth0:1 192.168.1.100 up
1568# telnet 192.168.1.1, then login
1569# Username: admin, Password: admin
1570# then type: shell to get the BusyBox shell prompt.
1571
1572Your telephone line (RJ11) cable should remain disconnected.
1573
1574To prevent your devices firmware from being updated, disable the following
1575components, as they are not required for confirmation.
1576
1577Kill the pid of the /bin/sh /BTAgent/ro/start (See UN-Hack later)
1578
1579# kill pid
1580# killall tftpd sshd MidServer btagent
1581
1582
1583
1584 40
1585
1586 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1587
1588
1589
1590
1591You will be surprised to learn there exists 16 network interfaces inside the
1592device, most are legitimate, but others are part of The Hack.
1593
1594All IP + MAC addresses have been redacted to protect victims identities.
1595
1596# ifconfig a
1597br0 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2 <redacted MAC address
1598 inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0
1599 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1600
1601br1 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
1602 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1603
1604dsl0 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
1605 [NO FLAGS] MTU:0 Metric:1
1606
1607eth0 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
1608 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1609
1610eth0.2 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
1611 BROADCAST MULTICAST MTU:1500 Metric:1
1612
1613eth0.3 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
1614 BROADCAST MULTICAST MTU:1500 Metric:1
1615
1616eth0.4 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
1617 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1618
1619eth0.5 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
1620 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1621
1622imq0 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
1623 UP RUNNING NOARP MTU:16000 Metric:1
1624
1625
1626 41
1627
1628 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1629
1630
1631imq1 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
1632 UP RUNNING NOARP MTU:16000 Metric:1
1633
1634imq2 Link encap:UNSPEC HWaddr 00000000000000000000000000000000
1635 UP RUNNING NOARP MTU:16000 Metric:1
1636
1637pktcmf_sa Link encap:UNSPEC HWaddr FEFFFFFFFFFFFFFF0000000000000000
1638 UP NOTRAILERS RUNNING NOARP MTU:0 Metric:1
1639
1640pktcmf_sw Link encap:UNSPEC HWaddr FEFFFFFFFFFFFFFF0000000000000000
1641 UP NOTRAILERS RUNNING NOARP MTU:0 Metric:1
1642
1643ptm1 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A2
1644 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1645
1646ptm1.101 Link encap:Ethernet HWaddr 10:C6:1F:C1:27:A2
1647 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1648
1649ptm1.301 Link encap:Ethernet HWaddr 10:C6:1F:C1:25:A3
1650 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
1651
1652
1653
1654
1655 42
1656
1657 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1658
1659Lets examine the routing table:
1660
1661# route n
1662Kernel IP routing table
1663Destination Gateway Genmask Flags Metric Ref Use Iface
1664192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br0
1665
1666# ip route show
1667192.168.1.0/24 dev br0 proto kernel scope link src 192.168.1.1
1668
1669# netstat n
1670Active Internet connections (w/o servers)
1671Proto RecvQ SendQ Local Address Foreign Address State
1672tcp 0 0 192.168.1.1:23 192.168.1.100:57483 ESTABLISHED # telnet
1673tcp 0 0 127.0.0.1:2600 127.0.0.1:33287 ESTABLISHED # Z>rip
1674tcp 0 0 127.0.0.1:33287 127.0.0.1:2600 ESTABLISHED # rip>Z
1675Active UNIX domain sockets (w/o servers)
1676Proto RefCnt Flags Type State INode Path
1677unix 3 [ ] STREAM CONNECTED 766 /var/BtAgentSocket # SPIES Socket
1678
1679
1680Lets see what processes are running: (duplicate and uninteresting lines
1681remove for brevity)
1682
1683# ps
1684 PID Uid VSZ Stat Command
1685 1 0 336 S init
1686 101 0 SW [dsl0]
1687 116 0 SW [eth0]
1688 127 0 504 S mc
1689 131 0 380 S /bin/msg msg
1690 136 0 1124 S /bin/dbase
1691 146 0 1680 S /bin/cms
1692 147 0 1148 S /bin/cwmp
1693 191 0 328 S zebra f /var/zebra/zebra.conf
1694 193 0 332 S ripd f /var/zebra/ripd.conf
1695 548 0 396 S dhcpc i ptm1.301 I ptm1.301 <HELLO?
1696 552 0 504 S monitor
1697 570 0 348 S dnsmasq conffile=/var/dnsmasq.conf
1698 733 0 248 S tftpd p 69
1699 741 0 292 S sshd E < HELLO?
1700 762 0 1136 S MidServer
1701 766 0 380 S /bin/sh /BTAgent/ro/start
1702 780 0 832 S ./btagent
1703
1704All looks innocent at first. Now, lets plug-in the telephone line cable and wait
1705few seconds:
1706
1707
1708
1709
1710 43
1711
1712 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1713
1714NOTE: We have redacted some IP addresses assigned to us by the attacker
1715xx = redacted address.
1716
1717# route n
1718Kernel IP routing table
1719Destination Gateway Genmask Flags Metric Ref Use Iface
1720192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br0
172130.150.xx.0 0.0.0.0 255.255.xxx.0 U 0 0 0 ptm1.301
17220.0.0.0 30.150.xx.1 0.0.0.0 UG 0 0 0 ptm1.301 <Default?
1723
1724# ip route show
1725192.168.1.0/24 dev br0 proto kernel scope link src 192.168.1.1
172630.150.xx.0/21 dev ptm1.301 proto kernel scope link src 30.150.xx.xx
1727default via 30.150.xx.1 dev ptm1.301
1728
1729We have a new IP address on VLAN 301, this is before any computers are
1730connected and before the PPPOE discover command has been issued from the
1731LAN connected Hub or PC. The default route sends all traffic to the
1732attacker by default @ 30.150.xx.1
1733
1734How close is the attacker? very close, < 8ms
1735
1736# ping 30.150.xx.1
1737PING 30.150.xx.1 (30.150.xx.1): 56 data bytes
173864 bytes from 30.150.xx.1: seq=0 ttl=64 time=7.174 ms
173964 bytes from 30.150.xx.1: seq=1 ttl=64 time=7.648 ms
174064 bytes from 30.150.xx.1: seq=2 ttl=64 time=7.685 ms
1741
1742NOTE: You are now pinging the NSA/GCHQ
1743
1744Now lets see what is happening at a socket level (comments on right after #):
1745
1746# netstat an
1747Active Internet connections (servers and established)
1748Proto RecvQ SendQ Local Address Foreign Address State
1749tcp 0 0 0.0.0.0:161 0.0.0.0:* LISTEN # This is BTAgent
1750tcp 0 0 127.0.0.1:2600 0.0.0.0:* LISTEN # This is Zebra Router
1751tcp 0 0 127.0.0.1:8011 0.0.0.0:* LISTEN # Transparent tproxy
1752tcp 0 0 30.150.xx.xx:8081 0.0.0.0:* LISTEN # This NSA/GCHQ Services
1753tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN # This is DNS
1754tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN # This is SSH Server
1755tcp 0 0 0.0.0.0:23 0.0.0.0:* LISTEN # This is TELNET
1756tcp 0 55 192.168.1.1:23 192.168.1.100:57484 ESTABLISHED # This telnet session
1757tcp 0 0 127.0.0.1:2600 127.0.0.1:36825 ESTABLISHED # This is zebrarip
1758tcp 0 0 127.0.0.1:36825 127.0.0.1:2600 ESTABLISHED # This is rip>zebra
1759udp 0 0 0.0.0.0:69 0.0.0.0:* # TFTP Server for upgrades
1760Active UNIX domain sockets (servers and established)
1761Proto RefCnt Flags Type State INode Path
1762unix 3 [ ] STREAM CONNECTED 766 /var/BtAgentSocket # Special Agent BT
1763
1764The device is now awaiting the hub/PC to issue a PPPOE discover request, at
1765which point you will receive your "Real Public IP".
1766
1767At this point the attacker has complete control of the modem and your LAN,
1768extra firewall rules are added the moment the ptm1.301 VLAN device is
1769enabled by the dhcpc command.
1770
1771
1772
1773 44
1774
1775 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1776
1777
1778
1779 The UN-HACK
1780
1781The UN-Hack
1782If you are able to login to your router (via serial port or LAN), there is a
1783defense which will prevent ALL the attacks using The Hack. This will un-
1784hack the modem and needs to be done after each reboot.
1785
1786Step 1. Unplug the telephone cable and boot the Modem then login and issue
1787the following commands (in bold), the hash is the prompt (don't type that):
1788
1789Kill the following processes:
1790# killall zebra ripd dnsmasq tftpd sshd MidServer
1791
1792Kill the pids of the /bin/sh /BTAgent/ro/start:
1793# kill 766
1794
1795Now, Kill all of the BTAgent processes:
1796# killall btagent
1797
1798Unmount the BTAgent partition:
1799# umount /usr/BTAgent
1800
1801Remove the attackers VLAN 301:
1802# vconfig rem ptm1.301
1803
1804Kill the rogue dhcpc process with force (-9) or it will re-spawn
1805# killall -9 dhcpc
1806
1807Remove all hidden firewall rules
1808# iptables -F -t mangle
1809# iptables -F -t nat
1810# iptables -F
1811
1812Step 2. Plugin the telephone cable and the DSL will connect to BT (without
1813the NSA/GCHQ listening).
1814
1815Step 3. Now start your PPPOE session from your second Linux firewall
1816machine as per the instructions for Inbound Defense and Outbound
1817Defense as applicable and Enjoy your privacy.
1818
1819
1820
1821 45
1822
1823 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1824
1825
1826
1827 Special AgentBT
1828
1829Special AgentBT
1830
1831This "special" software installed on all modems provided by BT called
1832BTAgent.
1833
1834This software listens on port 161, which is the IANA assigned port for Simple
1835Network Management Protocol (SNMP), anyone looking at this process would
1836automatically assume this to be the case. SNMP type programs are often
1837referred to as SNMP Agents.
1838
1839The primary purpose of BTAgent is unpublished, but a version has been
1840partially reverse engineered and the software does download firmware and
1841update the modems flash.
1842
1843BT responses to queries about their BTAgent is to claim that they need to
1844"remotely manage modems for security purposes".
1845User concerns with BTAgent:
1846
1847
1848 1. It's closed source
1849 2. Users cannot turn it of
1850 3. The secretive nature and responses from BT
1851 4. Users cannot upgrade the firmware using BTAgent
1852 5. Port 161 is open to the public internet
1853
1854
1855The second (special) purpose of the BTAgent is purely reverse reverse
1856psychology and designed to keep you wondering about it, to cause you to
1857waste your time reverse engineering it, when it may well be what it says on
1858the tin and while your thinking about BTAgent you're not thinking about the
1859other network interfaces such as ptm1.301 and the dhcpc requests which all
1860look innocent but actually perform the dirty deeds right in the open.
1861
1862
1863When you reverse engineer BTAgent and publish your results, this allows the
1864NSA/GCHQ to target you for other type of attacks.
1865We should remember, that with a single Firmware update from BTAgent, it
1866could morph itself and into what we originally feared!
1867
1868
1869 46
1870
1871 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1872
1873
1874 Psychological and
1875 Physical Barriers
1876Barriers
1877The NSA/GCHQ will do anything and everything to stop the The Hack being
1878discovered. The first step is to deal with the majority of users and prevent
1879them from even thinking about opening it up or even touching the modem.
1880
1881Some of the suggestions listed here may seem extreme, but the less interest
1882created in this box, the less attention it receives from consumers.
1883
1884 1. It's a white box, psychologically it's not a "black box" so it should be safe
1885 2. It comes in a plain brown cardboard box, which contain no words or
1886 graphics whatsoever, with a single white bar-code label with make/model
1887 of the modem
1888 3. The BT engineer personally carries and installs it in your home, while
1889 other components such as BT Home Hub, the more expensive component
1890 are sent through the postal system. BT cannot leave this shiny white
1891 modem hanging around for a week while they allocate your connection,
1892 you may try to open it or do research about it online, and they want to
1893 know who is researching it
1894 4. The telephone socket (RJ11) is designed such that when you plug in the
1895 telephone cable, it becomes very difficult to remove it, much more so
1896 than a standard telephone RJ11. Its not just a case of pinching the lever,
1897 you have to pinch and push further in, then remove. This is subtle, but it
1898 will prevent a lot of people from even attempting to disconnect the
1899 telephone cable, just in case they break it
1900 5. The older model was easy to open, just a few screws, the newer models
1901 is almost impossible to open because it is clip locked closed, meaning
1902 that you will damage it if you attempt to open it
1903 6. Red Warning Sticker on the back  "Don't cover Air Holes", wise but
1904 scary
1905 7. The only documentation is a single piece of white paper detailing how it
1906 should be mounted, there is no instructions about which cables go
1907 where, this is designed never to be touched
1908 8. All internal serial port headers are removed so, you cant easily hack it
1909 9. The modem is plain white and square, extremely uninteresting, boring,
1910 "Nothing to see here, move along",
1911
1912All of this subtle "Anti-Marketing" for the most advanced BT product?
1913
1914
1915
1916 47
1917
1918 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1919
1920
1921 Social Attacks on
1922 Engineers
1923
1924Social Attacks on Engineers
1925Having discovered the attack architecture and disabled it, we decided to visit
1926some forums online, we were interested to see if anyone, anywhere is close
1927to uncovering The Hack and how the NSA/GCHQ react to such issues.
1928
1929Generally, there are engineers chatting and sharing pictures of their modems
1930and how they solder wires on to the (usually hidden) serial ports, the
1931discussions usually leads to login and gaining root access of the modem or
1932replacing the firmware altogether.
1933
1934When engineers start to get really close, something usually extra-ordinary
1935happens, almost like "superman to the rescue", someone who is highly
1936qualified, someone who has built up a reputation of being a ethical
1937hacker/security expert, introduces themselves and produces what appears to
1938be major break-through in gaining access to the modems.
1939
1940However, because of the "ethical" element, superman instead of sharing the
1941method contacts BT, or BT contacts superman, directly and they agree to
1942allows BT to fix the flaw (e.g. giving BT a 30 days head start) after which,
1943superman will publish the method he used.
1944
1945All things being equal, this is fair enough, but things are not all equal because
1946this was a complete smoke screen, played out to discourage the engineers
1947from further development knowing that in a few weeks "superman" will give
1948them access.
1949
1950Many of the engineers/enthusiast waiting end-up getting caught by upgrades
1951of their modems firmware which then locks them out of the game.
1952
1953This is a cat and mouse game, and engineers should be very wary of those
1954bearing gifts, their agenda is to slow you down and prevent you from making
1955any progress hoping you will just give up.
1956
1957You can clearly see this on the BT forums as well others such as
1958http://www.psidoc.com, http://www.kitz.co.uk/, http://http://community.bt.com,
1959and others. Reverse engineering is legal, legitimate and it is a great source of
1960innovation.
1961
1962
1963
1964 48
1965
1966 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
1967
1968
1969
1970 Counter-Intelligence
1971
1972Counter-Intelligence
1973
1974
1975The NSA/GCHQ et al. have being watching and attacking us, it's about time
1976we turned the tables, started defending ourselves and also watching them.
1977
1978
1979This section is not going to detail specific techniques, but rather suggest
1980overall approaches, some of which we have done over a period of months.
1981
1982
1983NSA Honeypots
1984
1985
1986Now we understand the attack architecture, we can simulate the modem in a
1987MIPS Virtual Machine (BTAgent is not required).
1988
1989We can route the NSA/GCHQ traffic to your lab and just let them hack away in
1990a private cloud while we log traffic including how they attempt to use their
1991back doors and other dirty tricks.
1992
1993You will need to forward and tap VLAN 301 (in the case of BT et al) to the
1994virtual modem where you can analyze its traffic in real-time or offline, you
1995should always store whatever information you gather forever, (just like they
1996do).
1997
1998After gathering enough evidence, you can then publicize it and take legal
1999action, your logs can be used in court when you sue the conspirators and co-
2000conspirators under the "Computer Misuse Act 1990" as well as other laws.
2001
2002
2003
2004
2005 49
2006
2007 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2008
2009
2010About the Authors
2011The authors of this document wish to remain anonymous. However we are
2012fully prepared to stand in a court of law and present our evidence.
2013
2014We are a group of technical engineers, we are not associated with any
2015activists groups whatsoever. We don't have a name, but if we did it would
2016probably be "The Adversaries" according to NSA/GCHQ.
2017
2018
2019Our Mission
2020Freedom is only appreciated when lost. We are on the brink of a irreversible
2021totalitarian multi-government regime and even though the European
2022Parliament has stated that citizens should not have to defend themselves
2023against state sponsored Cybercrime, the fact remains that our own
2024Governments continue to attack us in our own homes while we sleep.
2025
2026Our mission is defensive and legal. Our objectives are to expose the sources
2027and methods used by those that harm our personal freedoms and rights and
2028to provide practical information to individuals around the world allowing them
2029to defend themselves against such cyber attacks.
2030
2031We believe this as well as future disclosures to be in the public interest.
2032
2033
2034Donations
2035Our ongoing work is technical, slow, tedious and expensive any donations are
2036very welcome. We only accept bitcoins at this time.
2037
2038
2039
2040
2041 bitcoin:1D6Hj37DS2mPTPm9u7TqS5ocddPHXjmau8
2042
2043You can also support us by sending this document to a friend or host it on
2044your website.
2045
2046Licensed under the Creative Commons Attribution-NoDerivs (CC BY-ND)
2047
2048
2049
2050
2051 50
2052
2053 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2054
2055
2056UPDATE 2
2057Documents released by Der Spiegel have confirmed our own findings, original
2058sources can be found here:
2059
2060
2061http://www.spiegel.de/international/topic/united_kingdom/
2062http://www.spiegel.de/international/topic/united_states/
2063
2064
2065The very fact that we reported these back-doors exactly as described in these
2066new leaks proves that our claims are legitimate and true. This is exactly what
2067we uncovered in BT's modems, the architecture, design and attackers
2068networks are exactly as we illustrated in our diagrams and descriptions and
2069list of capabilities.
2070
2071
2072We verified our results by purchasing and testing many modems directly from
2073the BT as well as third party sources, all of which had the back doors as
2074described.
2075
2076
2077Individual Der Spiegel documents relating to our claims can be found here:
2078
2079
2080Backdoors NSAGCHQ Verification Document
2081Firewalls http://cryptome.org/2013/12/nsa-ant-firewalls.pdf
2082
2083Routers http://cryptome.org/2013/12/nsa-ant-router.pdf
2084
2085QFIRE Attack Networks http://cryptome.org/2013/12/nsa-qfire.pdf
2086
2087
2088BULLRUN-NSA http://cryptome.org/2013/09/nsa-bullrun-2-16-guardian-13-0905.pdf
2089
2090EDHEHILL http://cryptome.org/2013/09/nsa-decrypt-guardian-13-0905.pdf
2091
2092BULLRUN-GCHQ http://cryptome.org/2013/09/nsa-bullrun-brief-nyt-13-0905.pdf
2093
2094Public Comments http://cryptome.org/2013/12/full-disclosure-comments.htm
2095
2096
2097
2098
2099 51
2100
2101 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2102
2103
2104U.S. DOD IP Addresses
2105We have always encouraged everyone to confirm our claims for themselves,
2106yet so called "Security Experts" dispute our claims in defense of BT, for
2107example, Robert Graham of Errata Security, his BT defense is here:
2108http://blog.erratasec.com/2013/12/dod-address-space-its-not-conspiracy.html
2109
2110
2111Robert states:
2112 "To be clear, that paper contains nothing that is evidence of NSA spying. I may have
2113 missed something, because I only skimmed it".
2114
2115
2116Robert, Security Experts don't miss things like huge open backdoors!
2117
2118
2119Robert even suggests that we should disregard RFCs and BCPs in favor of just
2120re-using so called un-allocated network address space  that's allocated to the
2121Government as "The way to go". Thank you Special Agent Robert. We advise
2122he read RFC 1918 http://tools.ietf.org/html/rfc1918.
2123
2124
2125At least when Sprint was caught out in 2011, they admitted to routing
2126consumer traffic through the D.O.D:
2127http://www.androidcentral.com/sprint-internet-dept-defense-and-you
2128
2129U.K. MOD IP Addresses
2130More recently, a YouTube video was published in which U.S. mobile phone
2131users are starting to check their IP addresses and discovering they belong to
2132the U.K. Ministry of Defence (MOD) as well as the U.S. DOD network.
2133http://www.youtube.com/watch?v=0W1ycfbKgCc
2134(User comments list many such address blocks, not just 30/8 & 25/8).
2135
2136
2137The question a "Real Security Expert" should ask is, why provide U.K. IP
2138addresses to Americans and U.S. IP addresses to the British?
2139
2140
2141The answer is of course simple, It allows the Government to by-pass the laws
2142of both countries. Essentially, this is the equivalent of creating a false paper
2143trail. Allowing the NSA to get the GCHQ to by-pass the U.S. Constitution
2144and the GCHQ to get the NSA to by-pass European Convention on Human
2145Rights. As we know they do, from other published revelations.
2146
2147
2148
2149
2150 52
2151
2152 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2153
2154IP traffic is not actually routed from the U.S. to the U.K or vice versa because
2155the latency (round trip delay) would be too high. But using IP blocks from
2156partner countries allow these Governments to claim that they do not spy on
2157their own citizens, for example, GCHQ would not attack a public U.K. IP
2158address, but may attack a U.S. IP address. The opposite is also true, the U.S.
2159can claim that they do not attack U.S. IP addresses, but may attack U.K. IP
2160addresses  get the picture!
2161
2162
2163The Governments proof it does not spy on its own citizens will be that they
2164use industry standard tools such as MaxMind IP geo-location databases etc. to
2165confirm foreign jurisdiction IP addresses, knowing full well that American
2166targets have been assigned foreign IP addresses allowing the NSA/CIA to
2167legitimately target Americans.
2168
2169Locations of Attacker Networks
2170While an IP address may well be foreign, it is under the control of the NSA
2171SCS SCIF site operating within local Embassies and Consulates (according to
2172their documents). Within the UK, it's probably located within the GCHQ.
2173
2174
2175
2176
2177We now know where the attackers networks infrastructures are located. This
2178also explains the low latency ping times we reported (8 ms) within UK.
2179
2180
2181 53
2182
2183 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2184
2185In the following NSA diagram:
2186
2187
2188
2189
21901. Yellow Dots depict compromised firewalls, routers i.e. your modem
21912. Red Dots are the location of the attackers networks as per SCS Global
21923. Red Dashed Lines represent hidden network paths
21934. Black Solid Lines represent Fibre Optic Cables
2194
2195
2196The above diagram is from 2012 and states that >50,000 implants, but this
2197list does not include the UK, CAN, NZL and AUS (the other Eyes). Given BT et
2198al. is the largest provider of compromised firewall/router modems in the UK,
2199the actual number is in the millions.
2200
2201
2202As a side note, we stated:
2203"But worse, is the fact that this architecture is designed for
2204Cyber Attacking in addition to passive monitoring as we will
2205detail next."
2206
2207
2208Now we discover, they even have a logo for
2209this!
2210
2211 54
2212
2213 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2214
2215Next, we see
2216
2217
2218
2219
22201. DoD Network - You know the one that's unused, yep, that one.
22212. Green Dots  Passive SIGINT (Real-Time Active Traffic Monitors)
22223. Red Dots  Active Defense  (i.e. Attack!)
22234. Blue Dots - Compromised router/firewall/modems "Implants (TAO)" being
2224remotely controlled by the attackers.
2225
2226
2227Titled: "Provides Centralized automated command/control of large network of
2228active implants".
2229
2230
2231Now do you believe our claims about your second hidden network?, no, well
2232read on.
2233
2234
2235
2236
2237 55
2238
2239 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2240
2241The following diagram is within the attackers network directly attached to
2242your BT (or other ISP) modem.
22431. Top left corner is the Attackers gateway, (i.e. BT modems default route)
22442. Thick Blue Lines are the Attackers network located in SCS SCIF site
2245operating within local Embassies and Consulates
22463. The virtual machines (VM1-VM4) is the command and control logic, this
2247sends requests to your BT modem via the hidden network to inject routes or
2248issue other requests to route specific or all traffic for MITM attacks. It should
2249be noted that the attacker can also simply telnet/ssh to your modem as well.
2250
2251
2252
2253
2254We previously stated the following:
2255
2256
2257tcp 0 0 30.150.xx.xx:8081 0.0.0.0:* LISTEN # This NSA/GCHQ Services
2258
2259
2260Which is the RPC/XML receiver tcp port (8081) on the BT modems hidden IP
2261address to receive the above command and control requests from the
2262Attacker.
2263
2264
2265Still not convinced? read on...
2266
2267 56
2268
2269 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2270
2271
2272
2273
2274Unclassified TAO Covert Network
2275 Covert=hidden
2276
2277
2278Remember BT VLAN 301?, It goes from your
2279home router to BT to GCHQ (or your local
2280NSA SCS) as shown in previous and right
2281diagrams.
2282
2283
2284The 1st generation modems, don't use a VPN,
2285which is why we did not mention it. However,
2286the 2ndgeneration do have a IPSec VPN built-
2287in (and other interesting stuff).
2288
2289
2290The use of a VPN is to hide the attackers
2291activities from counter surveillance.
2292
2293
2294
2295
2296The same document also refers to the TAO Covert Network as CovNet a.k.a.
2297MIDDLEMAN (Man In The Middle).
2298
2299
2300
2301
2302Surely, your convinced now?, no, read on.
2303
2304
2305
2306
2307 57
2308
2309 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2310
2311In this diagram we see your BT Modem! (bottom right)
2312
2313
2314
2315
2316Left hand side is the Attacker network infrastructure. The "Internet Option
2317A" is almost certainly used exclusively for GSM type (RF=Radio Frequency)
2318mobile phones and GSM based control devices.
2319
2320
2321Option A devices can only receive commands, they cannot return data
2322directly, they can do things like Turn on Microphone, Take Picture, Transmit
2323SMS protected data via SMS etc. Ask your mobile phone provider/maker for a
2324complete list of features in your phone (good case for OSS GSM module).
2325
2326
2327Option B concerns routers/firewalls/modems, now take a close look, you will
2328see Wireless Access Point (WAP) i.e. WIFI, slightly grayed  meaning the user
2329may not have it or it's disabled, otherwise the attacker can talk to your
2330wireless tablet/phone via your WIFI network.
2331
2332
2333NAT-GW is your official BT Public IP network. Lastly, you see "wired clients"
2334connected to any switch ports connected to your modem.
2335
2336
2337All of this is exactly how we described it 1 month ago.
2338Still not sure?, read on.
2339
2340
2341 58
2342
2343 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2344
2345We stated that "The Hack" as we call it, is an Architecture and regardless
2346of router or firewall, the architecture would remain the same, this strategy is
2347known as architectural design patterns, for example:
2348
2349
2350
2351
2352In the above NSA diagram, the "backdoor" is a hidden network to the
2353Attackers (NSA/GCHQ) network (Remote Operations Centre, ROC). If you
2354read all of the router and firewall documents released, you will notice the
2355same methods and design is re-used over and over.
2356
2357
2358These slides are approx. 5 years old and are 1st gen commercial routers, but
2359in 2011, the 2nd gen consumer firmware was installed (at least in the UK) and
2360in June 2013 the 3rd gen was installed in the UK.
2361In all generations "The Hack" is the same, a covert backdoor hidden
2362network.
23635 years on, you can bet your bottom dollar, this includes every smart-
2364phone which is effectively a broadband router+phone.
2365
2366
2367 59
2368
2369 Uncovered  //NONSA//NOGCHQ//NOGOV - CC BY-ND
2370
2371Response to BT
2372
2373
2374We discovered all of these details and published them on December 4th 2013,
2375almost a month before these new slides were released with the exact same
2376detail (actually much more detail) and we have now been proven to be correct
2377by U.S. Government documentation.
2378
2379
2380How could this be possible had we not discovered (and explained how and
2381why we discovered) this backdoor inside all our BT modems?
2382
2383
2384We know, you know, that we now knew the truth (that's spy speek!), the fact is
2385this was never a "Conspiracy Theory" as has been claimed, we are Systems
2386Architects, System Administrators, Security Engineers, Programmers, Pen
2387Testers, Cryptographers, Inventors and Innovators who grew up with a free
2388Internet in the days of SLIP@9600bps and floppy disks.
2389
2390
2391We know backdoors when we see them, after all our employers pay us to
2392secure some of the U.K.'s most successful online businesses, just like BT.
2393
2394
2395The Internet will always be for the next generation and cannot be owned or
2396used as a weapon against the peoples of the world. But our Governments are
2397not listening to us (well, except for the NSA/GCHQ), thanks to Mr Edward
2398Snowden, we are reclaiming the Internet.
2399
2400
2401Everyone fully understands that BT and other ISP businesses are somehow
2402compelled to act in the way they have and this can be forgiven and trust can
2403be restored, if BT demonstrate their business is worthy of our trust once
2404again.
2405
2406
2407Meaning, nothing short of what you would expect from us, complete
2408openness, namely unlock all your modems, remove these backdoors as other
2409major suppliers of routers/firewalls have agreed to do, aid innovation once
2410again, then it will be good to talk.
2411
2412
2413
2414Notes:
2415Bruce Schneier did not contribute in any way to our research, he did however, inspire its name "Full
2416Disclosure", because he called for that. "The Internet Dark Age" - that refers to the place the NSA/GCHQ and
2417other Eyes will soon be living.
2418
2419
2420
2421
2422 60
2423