Live data from Hacker News

MikroTik routers are forwarding owners’ traffic to unknown attackers

blog.netlab.360.com

41–50 of 151 posts

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#41
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear.

Another option would be your own hardware with pfsense (bsd) or ipfire(linux).

Even further would be your own hardware with linux and write your own nftables or bpf.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#42
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

For something with hardware offload, get a Ubiquiti EdgeRouter. I run one at home, it's debian based, I have lots of tools I've written in Go compiled and running on it for various purposes and you can install debian packages for things you need. The other option I've heard good things about are the PCEngines devices. They don't, as far as I'm aware, have hardware offload, so make sure their performance suits, but th…

I am curious what type of things you're running on your router. I have an ER-X, but haven't ever thought to run software on it (aside from some of the obvious packages like VPN and such).

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#43
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

I just last weekend retired a pair of Asus RT-AC66U routers/access points. They ran stable for years on Tomato (version tomato-RT-AC66U_AT-RT-AC6x-3.4-140-AIO-64K.trx) and I think all the hardware revisions work, but confirm that yourself. I retired them mostly because the Ubiquiti management is much easier and that hardware also affordable (though the software is not open, so not a fit for your use case).

I too did almost exactly this (albeit a few years ago) and moved to a Ubiquiti UniFi setup for my own place as well as a few small business sites I manage. The single biggest reason was that I became so sick of dealing with updates for "consumer" hardware, if there ever even were any. I didn't find open source to help much on that front either, the whole 30-30-30 song and dance or whatever it was and digging various supported versions up and dealing with the crummy UI and device-by-device work was a PITA and the hardware wasn't even generally cheaper.

It's absolutely not all roses on the UBNT side of things. They are exhibiting some of classic signs of expanding too fast and stretching themselves a bit too thin. In particular their hardware lineup is starting to get overly broad and they aren't being aggressive about retiring older products and keeping the matrix simple, which of course in turn represents an increasing maintenance burden. And some of their hardware which was disruptively priced and fantastic value at launch is now getting very old in the tooth. The UniFi controller UI can be shallow for more then simple usage of things like DNS/DHCP/RADIUS, granted a lot of HN types may have their own separate appliances/servers for that. Their USG has always been a bit of an orphan and only recently has really started getting the serious attention it needs. They've got some features on high end hardware that while niche still haven't been fleshed out. Their EdgeRouter hardware is keeping up better though.

That said the update process has continued to be pleasant and solid, and their support even for old devices has been excellent. There are no required ties to any external services. The hardware itself has been very reliable, and even the RMA process for when something burned out on us was decent (2 minute wait to online chat on a Sunday morning and immediate RMA approval). They've been quite good on security updates for a number of the major issues that have come up over the last year, and have had no major snafus (that MikroTik one storing passwords as plain text was painful/disturbing to see). While enterprises will have more advanced needs for SoHo situations even if they're not open source I think UBNT is worth consideration, particularly for those wearing plenty of hats already who are ready to cut down on cognitive load a bit.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#44

> After enabling the Mikrotik RouterOS HTTP proxy, the attacker uses a trick in the configuration by redirecting all the HTTP proxy requests to a local HTTP 403 error page, and in this error page a link for web mining code from coinhive.com is inserted. By doing this, the attacker hopes to perform web mining for all the proxy traffic on the users’ devices > What is disappointing for the attacker though, the mining co…

> Also, how is coinhive still a thing?

It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#45
post #43

Earlier quoted context omitted.

I just last weekend retired a pair of Asus RT-AC66U routers/access points. They ran stable for years on Tomato (version tomato-RT-AC66U_AT-RT-AC6x-3.4-140-AIO-64K.trx) and I think all the hardware revisions work, but confirm that yourself. I retired them mostly because the Ubiquiti management is much easier and that hardware also affordable (though the software is not open, so not a fit for your use case).

I too did almost exactly this (albeit a few years ago) and moved to a Ubiquiti UniFi setup for my own place as well as a few small business sites I manage. The single biggest reason was that I became so sick of dealing with updates for "consumer" hardware, if there ever even were any. I didn't find open source to help much on that front either, the whole 30-30-30 song and dance or whatever it was and digging various…

> UBNT is worth consideration, particularly for those wearing plenty of hats already who are ready to cut down on cognitive load a bit.

I've been running UniFi APs for years, but recently switched from my pfSense appliances to USG routers. I lost a lot of flexibility (especially for things like VPN configuration), but the simplicity and seamless management have been a huge time-saver.

I am puzzled by some of their new offerings—do they really expect any serious commercial customers to install lighting powered by PoE? Perhaps they're onto something innovative, but it seems like a distraction from their core business.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#46
post #35

Earlier quoted context omitted.

There are a lot of them, but depending on which features you need and where you live, it might be difficult to get one. Take a look e.g. at OpenWrt's list of devices "Ideal for OpenWrt": https://openwrt.org/toh/views/toh_available_864 Consider TP-Link Archer C7, for instance. It is an older one, but has reasonably fast hardware, supports IEEE 802.11ac and is available on Amazon. New costs ~75 USD, a "certified refurb…

Sadly, the Archer C7 cannot exceed 60Mbit/s without hardware offload when running OpenWRT. I had to replace mine with a Ubiquiti wireless access point and a dedicated pfSense box.

Source? Are you talking about wireless speed or wired speed? I am asking because I have never experienced such a huge limitation caused by the CPU bottleneck.

I have performed some simple tests using `iperf` tool on Archer C7 with OpenWrt and it was able to sustain wired network speeds of around 750 Mb/s and wireless speeds (IEEE 802.11ac) of around 300 Mb/s (maybe even more, but I do not remember exactly).

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#47
post #33
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

Here in Germany there is the Fritz brand. If I am not mistaken FRITZ!OS is a Linux distribution.

correct. But I don't know how much customization is possible after AVM disabled telnet (on the newer boxes).

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#48
Curious is this the VPNFilter malware or some new router virus?

Lately I’ve been having IP & Internet issues like....

- match suddenly banned me as a subscriber to okcupid and match. They won’t tell me why either & ive been a subscriber on/off for years. Never or ever would I do anything inappropriate though my match.com account I feel was hacked. Yet they don’t want to listen :-(

- my 6 month old roku device suddenly would no longer find my router.

- yesterday just bought a new Roku & was unable to activate it after many attempts.

Anyone else having weird Internet/IP device issues too?

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#49
post #44

> After enabling the Mikrotik RouterOS HTTP proxy, the attacker uses a trick in the configuration by redirecting all the HTTP proxy requests to a local HTTP 403 error page, and in this error page a link for web mining code from coinhive.com is inserted. By doing this, the attacker hopes to perform web mining for all the proxy traffic on the users’ devices > What is disappointing for the attacker though, the mining co…

> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

Any system that enables payments uncoupled from identity - or customer service - over the internet is going to be prone to abuse. Bad money pushes out good money, and paying with someone else's electric bill is always cheaper than paying with yours.

Which is to say that pretty much any form of cryptocurrency is likely to stay abuse-prone.

Practically speaking, the amount of electric bill you'd have to pay to make up the costs of what your currently pay for with data would almost certainly be shocking. I can't imagine that it costs anything like $5 to mine $5 worth of Monero on your average computer in the first world. And that would be just enough to pay for Gmail, never mind everything else!

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#50
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

I just pay the $10/month. The complete lack of hassle makes it worth it to me. Of all the things in the world I want to do, futzing with some OSS firmware is pretty close to the bottom of the list.

What’s your reason for suggesting friends buy a modem/router beyond the cost?

Post reply on HN