Jedi Packet Trick punches holes in firewalls

By hacking networking cards, researchers can break into networks and PCs

Hackers have hit on a new way to break into computers: by attacking the firmware used in networking cards.

Independent security researcher Arrigo Triulzi is set to unveil one such attack on Friday at the CanSecWest security conference. He calls his technique the Jedi Packet Trick. It essentially installs a clandestine virtual private network inside a firewall by hacking the firmware of the victim's networking cards.

Using a little-known remote factory diagnostic mechanism used by certain Broadcom cards, Triulzi has developed a way of installing customized firmware that instructs the card to directly pass packets to another card without telling the operating system. "You trick the operating system into believing that packets going between two different network cards don't exist," he said.

Triulzi wouldn't say what cards his attack works on, but he said that he has tried it on two similar cards, both of them about four years old.

He sends specially crafted packets to the network's firewall, which must be running a vulnerable networking card. It receives the packets and then installs the malicious firmware. That update is then leveraged to seek out and attack a second vulnerable networking card, creating a firewall-free tunnel into the network.

Because networking cards have direct access to the computer's memory, Triulzi is able to use his firmware to install code on the computer's graphics card that he can then use as a virtually undetectable back door to his victim's computer. The networking card doesn't have enough memory to handle this kind of space, but today's graphics cards are more than up to the job, he said.

Triulzi isn't the only one looking at networking card vulnerabilities at the conference. Separately, two researchers from the French Network and Information Security Agency, Yves-Alexis Perez and Loic Duflot, developed an attack that exploits a bug in an obscure remote-management feature in Broadcom's NetXtreme cards.

Their attack lets them install a back door on a Linux computer, though it could easily be modified to target any operating system, Duflot said.

For Duflot and Perez's NetXtreme attack to work, the card must have enabled a remote management feature called Alert Standard Format 2.0. Broadcom has worked out a fix for the problem and has pushed that out through its OEM partners.

This work illustrates a new type of attack that can sneak right by traditional detection techniques, said Colin Ames, a researcher with Attack Research in Santa Fe, New Mexico, who is attending the conference. "This stuff is the scary stuff," he said. "Because it's low-level."

None of the researchers at CanSecWest is releasing their code, so it's unlikely that these techniques will be used in any type of widespread attack. However, with security professionals increasingly worried about professional, targeted attacks aimed at stealing state secrets and corporate intellectual property, they raise concerns.

Duflot said hardware companies should be thinking seriously about security, especially as they develop firmware-based technologies such as Intel's Active Management Technology and Intelligent Platform Management Interface. "Nowadays, hardware is using too much embedded software," he said.

That software, he explained, can lead to bugs that give the hacker a way in. And if the hacker comes in through the network card, "the machine itself cannot even see that it has been compromised."

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags Jedi Packet TrickCanSecWestArrigo Triulzinetworking cards

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?