‘Misfortune Cookie’ poised to deal cyber-blow to millions, says Checkpoint

As Israeli government offices around the world shore up their cyber-defenses, a top protection firm reveals a major hacking threat

Israel’s National Cyber Bureau and security company Checkpoint will work together to develop an early-detection system to stamp out attacks on Israeli government offices in foreign countries. The system will include a series of alarms and sensors connected to a central office manned by Checkpoint employees that will alert government cyber-security officials in the event of a mass hacking attack on an office or organization.

Just in time, too – because the routers that some of those office may be using provide an open invitation for hackers to get into a network and steal data, interrupt communications, or do anything else they please. According to Checkpoint, at least 12 million residential gateway (SOHO router) devices, including several models by a number of makers, are vulnerable to what researchers have dubbed the “Misfortune Cookie.” It is, Checkpoint said, “one of the most widespread vulnerabilities revealed in recent years.”

While there are no documented cases of hackers actually using the vulnerability – which, Checkpoint said, has been floating around since 2003 – that doesn’t mean it hasn’t actually been used. “We feel we can assume certain attackers have already discovered and exploited the vulnerability, remaining undetected for extensive periods of time,” Checkpoint said.

The flaw is due to an old programming error within the router’s controller software HTTP cookie management mechanism that allows an attacker to determine the ‘fortune,’ or direction, of a request by manipulating cookies in the device’s memory, altering application states. In effect, it tricks the attacked device into allow hackers to run a session with administrative privileges, enabling the hacker to control it with their “infected” cookies, according to Checkpoint researchers.

Especially today, with so many home items connected to the Internet via a router – and that includes computers, phones, tablets, printers, security cameras, and even refrigerators or toasters – the vulnerability gives hackers unprecedented access to devices. An attacker exploiting the Misfortune Cookie could easily monitor Internet connections, steal credentials and personal or business data, infect machines with malware, and burn your toast in the case of a networked toaster, Checkpoint said.

According to Checkpoint, at least 200 different models of devices of various manufacturers and brands are exposed. The list includes models by D-Link, Edimax, Huawei, TP-Link, ZTE, and ZyXEL, among others. Responsible for the flaw is a piece of software called RomPager, which is common to the models in question, Checkpoint believes. “We suspect that the source for inclusion of the vulnerable piece of software is a common chipset SDK (distributed to the different manufacturers), however this cannot be confirmed at this point.”

Allegro Software, maker of RomPager, said that it had issued patches for the bug at least nine years ago, but Checkpoint said that its research had determined that a large number of users have not installed the patches. The best way to protect networks, the company added, was to apply the updates and install security software (it recommends its own ZoneAlarm product).

While most of the affected routers are branded as “residential gateways,” meaning they are meant for home use, many are also in use in small office environments – exactly the kind of offices representing Israeli economic, agricultural, government, and other interests abroad. Checkpoint’s defense project is an extension of the wide security blanket cyber-officials are spreading over Israeli government offices within the country. On an average day, according to Professor Isaac Ben-Israel, head of the National Cyber Bureau and director of Tel Aviv University’s Yuval Neeman Workshop for Science, Technology, and Security, Israeli government institutions get an average of about 100,000 attacks– a number that can climb to as many as a million during periods of high tension, such as during Operation Protective Edge this past summer.

And that’s with a comprehensive end-to-end protection system installed and with the network under the control of Israeli security experts who are cognizant of the issues involved and know what to look for – which is not necessarily the case in a foreign land, where the Foreign Ministry rents space in regular office buildings for a plethora of Israeli economic and diplomatic missions.

There, organizations are doubly vulnerable – the target of the ire of anti-Israel hackers, but unable to fully implement the security they would get within Israel. The Checkpoint program, said Foreign Ministry director Nissim Ben-Sheetrit, would be a good way to spread Israel’s cyber-defensive blanker abroad – and protect the damage that hackers could attempt to wreak using the Misfortune Cookie trick, or by other methods. “It is good news in the further development of a national cyber-security policy,” said Ben-Sheetrit, “and an increased opportunity to defend the diplomatic activity of Israel abroad.”

Most Popular
read more:
If you’d like to comment, join
The Times of Israel Community.
Join The Times of Israel Community
Commenting is available for paying members of The Times of Israel Community only. Please join our Community to comment and enjoy other Community benefits.
Please use the following structure: example@domain.com
Confirm Mail
Thank you! Now check your email
You are now a member of The Times of Israel Community! We sent you an email with a login link to . Once you're set up, you can start enjoying Community benefits and commenting.