Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…
MikroTik routers are forwarding owners’ traffic to unknown attackers
51–60 of 151 posts
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#52Using the hardware reset button doesn't fix things, so heads up for others in that situation. Use MikroTik's NetInstall to re-install RouterOS instead.
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#53Earlier quoted context omitted.
Sadly, the Archer C7 cannot exceed 60Mbit/s without hardware offload when running OpenWRT. I had to replace mine with a Ubiquiti wireless access point and a dedicated pfSense box.
Source? Are you talking about wireless speed or wired speed? I am asking because I have never experienced such a huge limitation caused by the CPU bottleneck. I have performed some simple tests using `iperf` tool on Archer C7 with OpenWrt and it was able to sustain wired network speeds of around 750 Mb/s and wireless speeds (IEEE 802.11ac) of around 300 Mb/s (maybe even more, but I do not remember exactly).
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#54Earlier quoted context omitted.
For something with hardware offload, get a Ubiquiti EdgeRouter. I run one at home, it's debian based, I have lots of tools I've written in Go compiled and running on it for various purposes and you can install debian packages for things you need. The other option I've heard good things about are the PCEngines devices. They don't, as far as I'm aware, have hardware offload, so make sure their performance suits, but th…
I am curious what type of things you're running on your router. I have an ER-X, but haven't ever thought to run software on it (aside from some of the obvious packages like VPN and such).
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#55> After enabling the Mikrotik RouterOS HTTP proxy, the attacker uses a trick in the configuration by redirecting all the HTTP proxy requests to a local HTTP 403 error page, and in this error page a link for web mining code from coinhive.com is inserted. By doing this, the attacker hopes to perform web mining for all the proxy traffic on the users’ devices > What is disappointing for the attacker though, the mining co…
> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#56Earlier quoted context omitted.
For something with hardware offload, get a Ubiquiti EdgeRouter. I run one at home, it's debian based, I have lots of tools I've written in Go compiled and running on it for various purposes and you can install debian packages for things you need. The other option I've heard good things about are the PCEngines devices. They don't, as far as I'm aware, have hardware offload, so make sure their performance suits, but th…
I am curious what type of things you're running on your router. I have an ER-X, but haven't ever thought to run software on it (aside from some of the obvious packages like VPN and such).
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#57Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…
Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear. Another option would be your own hardware with pfsense (bsd) or ipfire(linux). Even f…
The best option in my opinion is something Intel based running a well known Linux distro with automated security updates that is fully in your control. Shorewall can do everything needed for a home router. This option is a lot more expensive though.
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#58Earlier quoted context omitted.
I too did almost exactly this (albeit a few years ago) and moved to a Ubiquiti UniFi setup for my own place as well as a few small business sites I manage. The single biggest reason was that I became so sick of dealing with updates for "consumer" hardware, if there ever even were any. I didn't find open source to help much on that front either, the whole 30-30-30 song and dance or whatever it was and digging various…
> UBNT is worth consideration, particularly for those wearing plenty of hats already who are ready to cut down on cognitive load a bit. I've been running UniFi APs for years, but recently switched from my pfSense appliances to USG routers. I lost a lot of flexibility (especially for things like VPN configuration), but the simplicity and seamless management have been a huge time-saver. I am puzzled by some of their ne…
Yes, although I want to emphasize again that while they made a new hire specifically for the USG and it's seen dramatic improvements in the last year [1] it was still a kind of orphan child for a while and I still need to drop down to the shell sometimes for initial setup. Rock solid after that and simple and good integration with the overall site sure but it hasn't always been clear for someone starting from scratch how to get it up the first time in common SoHo situations. Also for those with gigabit links who want to run Suricata IDS/IPS (which requires turning off hardware offload), Ubiquiti just doesn't offer anything even remotely SoHo priced with the muscle for that right now. The low end USG "3P" (~$110) maxes out around 150 Mbps with IPS after the most recent update (an improvement from 85 Mbps before that) while the Pro (~$300) maxes out around 430-450. Only the XG can handle a gigabit or higher but that's $2500 and built with 8x 10G links, it's ludicrous overkill for those who don't want its other features and routing. Granted gigabit fiber links are far from the norm but they're gradually increasing and the HN crowd may be more likely to go for them then many, and the hardware in the USG 3P and USG Pro is just old now.
>I am puzzled by some of their new offerings—do they really expect any serious commercial customers to install lighting powered by PoE? Perhaps they're onto something innovative, but it seems like a distraction from their core business.
I definitely agree about distractions, though at the same time we should recognize that of course different divisions and people can be doing different things at the same time, development and engineering talent isn't necessarily fungible there. Still, they aren't a megacorp, overall resources and management bandwidth isn't unlimited either.
On the other hand at one point Ubiquiti had a real effort in the IOT space called MFi, but due to a lot of internal technical debt issues there (IIRC there) it essentially got canned, and they planned to eventually resurrect it on top of their more advanced foundations but haven't had the bandwidth. Maybe the lighting and their efforts to improve their security offerings are some first baby steps towards getting back into that? In fairness IOT has some of the same properties in terms of suckage that have made their networking efforts successful, and could also be a major market. Updates are often a pain or non-existent, the security story is awful, and much of it insists on using 3rd party cloud dependencies. There could be a real valuable hole there for Ubiquiti to fill were they to execute well enough, though I'd feel better about it if their core felt more tightly managed and foundations a bit steadier. We'll see I guess, and at least lighting should have been a pretty low R&D way experiment with it?
---
1: And for better or worse, the very fact of a piece of cheaper networking gear seeing years of support and improvements is depressingly unusual in the industry.
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#59Earlier quoted context omitted.
I am curious what type of things you're running on your router. I have an ER-X, but haven't ever thought to run software on it (aside from some of the obvious packages like VPN and such).
Which VPN do you run on it? Wireguard? How's the performance, I ask as I too have an ER-X.
So speeds are kind a slow, around 50-90 megabits (i have gigabit fiber, that the er-x otherwise can fill out completely).
Re: MikroTik routers are forwarding owners’ traffic to unknown attackers
#60Earlier quoted context omitted.
> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.
Any system that enables payments uncoupled from identity - or customer service - over the internet is going to be prone to abuse. Bad money pushes out good money, and paying with someone else's electric bill is always cheaper than paying with yours. Which is to say that pretty much any form of cryptocurrency is likely to stay abuse-prone. Practically speaking, the amount of electric bill you'd have to pay to make up…