Return Policies Enable a Firmware Backdoor Pipeline

▶ Watch (7:18)

Matei Josephs formulated a simple hypothesis: retailers do not check returned devices for firmware tampering before reselling them. He bought 15 TP-Link routers from 5 reputable retailers. His methodology: modify the firmware, return the devices, then buy them back when reposted as pre-owned. He built a Discord scraper to catch listings immediately. The backdoor sent an HTTP GET request to his EC2 instance with a self-destruct after 3,000 requests, restoring the device after 21 days.

Extracting and Replacing Firmware on Consumer Routers

▶ Watch (11:40)

Josephs extracted firmware using SPI and analyzed it with binwalk. He modified the squashfs filesystem to add a service that called home every 10 minutes. The original firmware used XZ compression. His modified version used Zlib, requiring the compression flag in make squashfs to match. Uploading via the web interface failed on some devices due to signature checks. TFTP recovery mode worked as a workaround, allowing firmware replacement without opening the case.

All 15 Backdoored Devices Passed Retail Inspection

▶ Watch (15:05)

All 5 retailers accepted returns without questions. One device had been physically opened with broken seals. None connected to Josephs’s server while on retailer networks, suggesting staff only checked if the device powered on. His scraper detected all 15 reposted as repackaged within days. He bought back 13. Two sold to other buyers who were faster. All 15 devices eventually phoned home, including the two sold to strangers, confirming the backdoor survived the return and resale process.

The Greater Risk: Rogue Resellers

▶ Watch (18:13)

Josephs argues the real risk is not retail returns but rogue resellers. A threat actor could open an online store, buy thousands of devices, modify firmware, and sell below market value. The seller knows buyer addresses, enabling targeted backdoor activation. For consumers, Josephs recommends avoiding repackaged devices and questioning whether every IoT device needs internet connectivity. For researchers, he urges reporting firmware-overwrite vulnerabilities even when programs deem physical access out of scope.

Q&A

Would buying directly from the manufacturer prevent this attack? Yes, but the devices may still be vulnerable to resale by others. ▶ 26:57

How did you extract the filesystem and find the correct offsets? The firmware was completely unencrypted and unobfuscated, so binwalk worked directly. ▶ 27:32

Notable Quotes

all it does is make a simple get request Matei Josephs · ▶ 8:51

I guarantee you that no one will notice. Matei Josephs · ▶ 21:02

devices ordered by their targets. Matei Josephs · ▶ 25:12

Key Takeaways

  • Retailers did not check firmware integrity before reselling returned routers.
  • A simple HTTP backdoor survived the factory reset process on all 15 devices.
  • The attack vector is more dangerous through rogue resellers than retail returns.

About the Speaker(s)

Matei Josephs breaks things for a living - especially if they beep, blink, or pretend to be “smart”. Printers, kiosks, routers, and random IoT junk live in fear when he’s nearby. He’s a Senior Penetration Tester at Happening, he discovered 9 CVEs and loves hacking at scale. In this talk, “Smart Devices, Dumb Resets? Testing Firmware Persistence in Commercial IoT”, Matei reveals how threat actors can implant persistent backdoors in smart devices, then return them for resale through legitimate retailers. Because factory reset processes often fail to wipe firmware-level compromises, attackers can exploit the trust users place in brand-name resellers—turning returned devices into credible, persistent attack vectors.