Live data from Hacker News

Someone Has Infected at Least 500,000 Routers All Over the World

motherboard.vice.com

21–30 of 30 posts

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#22

Earlier quoted context omitted.

I believe this is what Antonov meant when he said: "A pre-designed scenario is being implemented, Again, we are being threatened. We warned that such actions will not be left without consequences." in response to the latest Syria strike. WWIII may not be nukes, but complete economic chaos after banks, hospitals, militaries, and electricity networks are taken down.

Good reasons to start being a prepper if you aren't already

And to watch all of Mr. Robot for ideas.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#24
post #6

Earlier quoted context omitted.

Depends on the target site. With half a million routers you could cause problems to 99% of sites out there. The percentage of websites that could handle 500k concurrent connections is very small.

If we assume each router has, on average, 0.5Mbps upstream (hopefully it's higher!) then that's a combined capacity of ~250Gbps. Some quick searching says the average DDOS size at one point in 2017 was measured at ~14Gbps and some larger attacks were peaking at ~120Gbps. Cloudflare's "biggest DDOS ever" was 800Gbps. Even if we assume a lot of these routers are clustered on specific ISPs or networks and the effective…

A lot of DDOS attacks use UDP-based amplification techniques. I know DNS and NTP were frequently used and could get amplification factors of up to 500x. This year there have been some amplification attacked using Memcache that could get 50,000x amplification.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#25

The state of SOHO router security is pretty sad. Sure, most of those infected were probably unpatched, possibly had remote-admin pages enabled, or were using default credentials but... why is it even possible to open the remote admin interface with default passwords? Why don't they all auto-update by default for critical vulnerabilities?

> Why don't they all auto-update by default for critical vulnerabilities?

Because it costs money for manufacturers to implement and maintain this functionality, and there's (currently) zero benefit to them for doing so and (currently) zero repercussions for doing what they do today after they sell you a device: nothing.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#26

The state of SOHO router security is pretty sad. Sure, most of those infected were probably unpatched, possibly had remote-admin pages enabled, or were using default credentials but... why is it even possible to open the remote admin interface with default passwords? Why don't they all auto-update by default for critical vulnerabilities?

If the auto update happens to brick the device, it becomes expensive for the manufacturer.

Most of them have many models. Probably many are developed with copy-paste fashion, meaning separate updates and separate testing for each model.

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#27

The journalism on this is awful. The Ukrainian statements are ridiculous and should have been challenged by VICE rather than sensationalized. A state actor isn't going to run the kill command on 500,000 routers to disrupt a soccer match. The intention of the compromise is for surveillance. Not nearly as sophisticated as the NSA capabilities - nearly every router in the world (besides the small percentage not produced…

Russians already killed and injured more than 100 000 people in Ukraine, including 2,500 children deaths. More than 2 000 000 left their homes. They shot civil plane full of passengers to blame Ukraine. They used chemical weapons in Syria. They completely destroyed their own major city. And so on.

Why they cannot damage few routers? What will stop them? USA and Britain will declare war?

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#28

The journalism on this is awful. The Ukrainian statements are ridiculous and should have been challenged by VICE rather than sensationalized. A state actor isn't going to run the kill command on 500,000 routers to disrupt a soccer match. The intention of the compromise is for surveillance. Not nearly as sophisticated as the NSA capabilities - nearly every router in the world (besides the small percentage not produced…

Russians already killed and injured more than 100 000 people in Ukraine, including 2,500 children deaths. More than 2 000 000 left their homes. They shot civil plane full of passengers to blame Ukraine. They used chemical weapons in Syria. They completely destroyed their own major city. And so on. Why they cannot damage few routers? What will stop them? USA and Britain will declare war?

Huh?

Conspiracy theories?

Re: Someone Has Infected at Least 500,000 Routers All Over the World

#30
post #2

According to DOJ [1], "Someone" is Fancy Bear [2] and the FBI has seized control [3] of the C&C domain (ToKnowAll.com) [1] https://www.justice.gov/opa/pr/justice-department-announces-... [2] https://en.wikipedia.org/wiki/Fancy_Bear [3] https://www.engadget.com/2018/05/24/fbi-seizes-domain-russia...

Let's just abbreviate "Someone" to "The Russian Government". They are mostly targeting Ukraine, but who know what else they are up to. Almost as troubling as the US government actions.
Post reply on HN