Live data from Hacker News

MikroTik routers are forwarding owners’ traffic to unknown attackers

blog.netlab.360.com

61–70 of 151 posts

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#61
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear. Another option would be your own hardware with pfsense (bsd) or ipfire(linux). Even f…

Sorry for the spam, I seem to post this regularly but the Ubiquiti EdgeRouter Lite will happily run OpenBSD. It supports the onboard packet accelerator with some extra configuration.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#62
post #57

Earlier quoted context omitted.

Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear. Another option would be your own hardware with pfsense (bsd) or ipfire(linux). Even f…

The ERL family is pretty bad as a router, in my experience. There is a longstanding firmware issue that introduces packet loss for routed packets (it doesn't multiplex across the dual cores correctly, which leads to out of order packets). If you really want to use Ubiquiti, I would suggest using an ER-X which is cheaper, doesn't have this problem, and is quadcore. The best option in my opinion is something Intel base…

Interesting that the more expensive router has this problem. I've been really happy with my ER-X, it works great with my internet service (500Mbs up/500Mbs down). I had some speed issues at first but this was solved by upgrading to the latest firmware and making sure hardware offloading was enabled.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#63
post #60
post #49

Earlier quoted context omitted.

Any system that enables payments uncoupled from identity - or customer service - over the internet is going to be prone to abuse. Bad money pushes out good money, and paying with someone else's electric bill is always cheaper than paying with yours. Which is to say that pretty much any form of cryptocurrency is likely to stay abuse-prone. Practically speaking, the amount of electric bill you'd have to pay to make up…

On an average computer it would take weeks or months to mine $5 worth of Monero but it is doable.

I don't mean to suggest in any way, shape, form, or manner that it cannot be done! Only that it cannot be done in a way that is anything resembling cost-effective.

The sheer, staggering inefficiency involved might help incentivize usage away from a proxy for micropayments and towards malware.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#64
post #44

> After enabling the Mikrotik RouterOS HTTP proxy, the attacker uses a trick in the configuration by redirecting all the HTTP proxy requests to a local HTTP 403 error page, and in this error page a link for web mining code from coinhive.com is inserted. By doing this, the attacker hopes to perform web mining for all the proxy traffic on the users’ devices > What is disappointing for the attacker though, the mining co…

> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

> I'd much rather live in a world where websites are financed with my electric bill rather than my data.

In general, I wouldn't mind that much if I had to pay some extra "Internet subscription" to cover publisher costs, if reasonable. I don't think electricity bill is the right place to include it in. And I definitely do not want this charge to be included by the means of cryptocurrencies - they're wasteful at their very core (as opposed to every other financial instrument in existence), and I don't want to support such ideas. Not to mention that, like 'Kalium observes, it would take extreme amounts of power use to "send" a publisher some reasonable amount of money.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#65
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

I've had good luck running OpenWRT on this TP-Link model: https://www.tp-link.com/us/products/details/cat-9_Archer-C26... . I believe there's only one hardware version so no gamble there.

Same here. Just picked one up a few weeks back and used the stock web-gui to upload the newest OpenWRT. Worked without a hitch.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#66
post #44

> After enabling the Mikrotik RouterOS HTTP proxy, the attacker uses a trick in the configuration by redirecting all the HTTP proxy requests to a local HTTP 403 error page, and in this error page a link for web mining code from coinhive.com is inserted. By doing this, the attacker hopes to perform web mining for all the proxy traffic on the users’ devices > What is disappointing for the attacker though, the mining co…

> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

I dunno about you, but wasting vast amounts of energy in some incredibly inefficient* techno-currency Ponzi scheme is just stupid and I'd rather we figure out something better than these two alternatives.

* ASICs are roughly 100x more power-efficient at essentially any crypto mining algorithm

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#67
post #66
post #44

Earlier quoted context omitted.

> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

I dunno about you, but wasting vast amounts of energy in some incredibly inefficient* techno-currency Ponzi scheme is just stupid and I'd rather we figure out something better than these two alternatives. * ASICs are roughly 100x more power-efficient at essentially any crypto mining algorithm

> ASICs are roughly 100x more power-efficient at essentially any crypto mining algorithm

That's half of the problem.

The other half is that cryptocurrencies rely, in a structural way, on their generation to be difficult, so when enough ASICs get deployed, the currency ups its "difficulty factor", multiplying the amount of power you have to burn for the same reward.

Really, if I were a supervillain who wanted to accelerate energy crisis and climate change by exploiting human greed, cryptocurrencies is the scheme I would come up with.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#68
post #44

> After enabling the Mikrotik RouterOS HTTP proxy, the attacker uses a trick in the configuration by redirecting all the HTTP proxy requests to a local HTTP 403 error page, and in this error page a link for web mining code from coinhive.com is inserted. By doing this, the attacker hopes to perform web mining for all the proxy traffic on the users’ devices > What is disappointing for the attacker though, the mining co…

> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

I'd much rather live in a world where we can share things without paid somethings, where people contribute not split information where everyone is copying each other.

90% of work, data copied on Internet have no value. Dunno why we need to pay for Clickbait article, or article without value or translated article (EN->FR)

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#69
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

I personally love pfSense and there’s tons of hardware for $100-250 that supports it.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#70
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

Until very recently I would just go to Microcenter and purchase a cheap refurbished small form factor PC plus two Intel NICs and run OpenBSD. For less than $200 you have a fully functional router albeit at a higher power cost than a true appliance.

If you really need a small / low power usage appliance then some Ubiquiti devices run OpenBSD as I mentioned in another reply below.

Anecdotally OpenBSD also supports wireguard if that's a concern.

https://www.openbsd.org/octeon.html

https://marc.info/?l=openbsd-ports&m=152712417729497&w=2

Post reply on HN