Live data from Hacker News

MikroTik routers are forwarding owners’ traffic to unknown attackers

blog.netlab.360.com

71–80 of 151 posts

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#71
post #57

Earlier quoted context omitted.

Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear. Another option would be your own hardware with pfsense (bsd) or ipfire(linux). Even f…

The ERL family is pretty bad as a router, in my experience. There is a longstanding firmware issue that introduces packet loss for routed packets (it doesn't multiplex across the dual cores correctly, which leads to out of order packets). If you really want to use Ubiquiti, I would suggest using an ER-X which is cheaper, doesn't have this problem, and is quadcore. The best option in my opinion is something Intel base…

> There is a longstanding firmware issue that introduces packet loss for routed packets

Interesting, do you have any more about this?

Got an ER-PoE that intermittently loses packets and have never got to the bottom of why (I gave up and bought a non-Ubnt router, just haven’t got around to configuring it yet).

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#72
post #66
post #44

Earlier quoted context omitted.

> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

I dunno about you, but wasting vast amounts of energy in some incredibly inefficient* techno-currency Ponzi scheme is just stupid and I'd rather we figure out something better than these two alternatives. * ASICs are roughly 100x more power-efficient at essentially any crypto mining algorithm

Just because you don't understand how something works or are ideologically opposed to its existence doesn't mean it's a ponzi scheme.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#73
post #44

> After enabling the Mikrotik RouterOS HTTP proxy, the attacker uses a trick in the configuration by redirecting all the HTTP proxy requests to a local HTTP 403 error page, and in this error page a link for web mining code from coinhive.com is inserted. By doing this, the attacker hopes to perform web mining for all the proxy traffic on the users’ devices > What is disappointing for the attacker though, the mining co…

> Also, how is coinhive still a thing? It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.

It's not just your electric bill; that power is being generated somehow. Until that process is clean and green and completely accounts for externalities I prefer whatever wastes less electricity.

I'd personally much rather live in a world where websites are financed up-front or not at all. It would disincentivize the low-effort creation of pointless or misleading material simply to direct time and attention to ads and miners.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#74
post #35

Earlier quoted context omitted.

There are a lot of them, but depending on which features you need and where you live, it might be difficult to get one. Take a look e.g. at OpenWrt's list of devices "Ideal for OpenWrt": https://openwrt.org/toh/views/toh_available_864 Consider TP-Link Archer C7, for instance. It is an older one, but has reasonably fast hardware, supports IEEE 802.11ac and is available on Amazon. New costs ~75 USD, a "certified refurb…

Sadly, the Archer C7 cannot exceed 60Mbit/s without hardware offload when running OpenWRT. I had to replace mine with a Ubiquiti wireless access point and a dedicated pfSense box.

There are newer firmwares that allow me to get WAN to LAN ~500 Mbit over 5ghz, and WAN to LAN 950 Mbit over Ethernet

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#75
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

Anything that you can install OpenWRT on :)

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#76
post #66

Earlier quoted context omitted.

I dunno about you, but wasting vast amounts of energy in some incredibly inefficient* techno-currency Ponzi scheme is just stupid and I'd rather we figure out something better than these two alternatives. * ASICs are roughly 100x more power-efficient at essentially any crypto mining algorithm

> ASICs are roughly 100x more power-efficient at essentially any crypto mining algorithm That's half of the problem. The other half is that cryptocurrencies rely, in a structural way, on their generation to be difficult, so when enough ASICs get deployed, the currency ups its "difficulty factor", multiplying the amount of power you have to burn for the same reward. Really, if I were a supervillain who wanted to accel…

If I were a socialist who was politically opposed to the huge benefits of cryptocurrency gaining major adoption I would boil it down to "exploiting human greed" and pretend it's operating under the assumption that the energy expenditures are a "waste" and therefor detrimental to climate change.

If you can't understand the compound harm to the environment (for starters) of nations states existing and controlling currency, I feel bad for you. If you do understand it, you should know you're rightly fearful of this technology, because it's going to play a major factor in your future demise.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#77
btw this is the actual vulnerability (since MT release logs do not mention the CVE cited in the article):

https://blog.mikrotik.com/security/winbox-vulnerability.html

(referenced here : https://forum.mikrotik.com/viewtopic.php?f=21&t=137284&start...)

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#79
> Attackers mainly interested in port 20, 21, 25, 110, and 143, corresponding to FTP-data, FTP, SMTP, POP3, and IMAP traffic.

That strongly suggests password harvesting. Those ports/protocols often (not always) are used for unencrypted user/pass combinations. :(

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#80

Earlier quoted context omitted.

Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear. Another option would be your own hardware with pfsense (bsd) or ipfire(linux). Even f…

Sorry for the spam, I seem to post this regularly but the Ubiquiti EdgeRouter Lite will happily run OpenBSD. It supports the onboard packet accelerator with some extra configuration.

I didn't know that, wow. I found some resources on this [1] [2] [3] but it seems like everything is working? Have you tried WireGuard on OpenBSD/octeon?

[1] https://www.openbsd.org/octeon.html

[2] https://news.ycombinator.com/item?id=10079210

[3] https://an.undulating.space/post/180411-erl-openbsd-upgrade/

Post reply on HN