Live data from Hacker News

MikroTik routers are forwarding owners’ traffic to unknown attackers

blog.netlab.360.com

121–130 of 151 posts

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#121
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

I have one of the Linksys WRT-AC series (WRT-1900ACS but they are all pretty similar I think) - they're very well supported by OpenWRT (stock firmware is a derivative of OpenWRT in fact at least on some of them). Hardware specs are good, including reasonably fast CPUs (good enough to saturate a VPN at 100Mbit at least which is the uplink I have here). The open source wireless chipset support is towards the better end too - not perfect but a lot better than some others.

If you're flashing your own images of OpenWRT, there are a few conveniences which are a bit more uncommon in the hardware which are useful if you ever need to debrick - eg easily openable case, UART header comes pre-installed (you don't need to solder your own), etc.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#122

Earlier quoted context omitted.

Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear. Another option would be your own hardware with pfsense (bsd) or ipfire(linux). Even f…

I am a big fan of PFSense. Not a huge fan of Netgate as a company and the direction they are taking the product. In any case, you can load it onto some fairly low cost hardware for your typical home user. It's fantastic. I am not a huge fan of the Ubiquiti routers. They required loading a config onto them just to get DHCP enabled and NAT setup for a typical 1 WAN and 1 LAN environment. Why on earth they would ship wi…

They come with a wizard for setting up basics like that now.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#123
post #82

Earlier quoted context omitted.

https://community.ubnt.com/t5/EdgeRouter/UDP-packet-loss-on-... I was one of the people involved in some of the measurements on there. I avoid ubnt networking gear in general after that experience (although ER-X seems good and I use one at home as a smart switch). Their specialty is in APs, which work really great.

The last update of the first post says that this was fixed in v1.10.0, and the release notes concur: https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-E...

Open to the idea I’ve got a different issue, but I’m still seeing an issue with 1.10.5.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#124
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

The Netgear Nighthawk series is almost always available on Amazon and is generally well supported by dd-wrt. Specifically, the best deals can be had on the oldest model, the R6700v3, from an Amazon warehouse deal for $70. This is what I use, and it works without issue with dd-wrt. You'll need to flash it 3 times. The best device is probably the R7800 model. It uses a very fast, non-Broadcom (OpenWRT-supported), moder…

+1 to OpenWRT 18.x / Netgear R7800.

It's one of the only WiFi routers I've ever worked with that has a fallback flash mode in the bootloader, and the only one that I know you can buy today. This is invaluable when you're not sure if something you're doing could make it fail to boot, like installing an upgrade without knowing whether it uses the same partition layout as you had. When it does you can just try again. (I've needed this once already.)

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#125
post #82
post #71

Earlier quoted context omitted.

> There is a longstanding firmware issue that introduces packet loss for routed packets Interesting, do you have any more about this? Got an ER-PoE that intermittently loses packets and have never got to the bottom of why (I gave up and bought a non-Ubnt router, just haven’t got around to configuring it yet).

https://community.ubnt.com/t5/EdgeRouter/UDP-packet-loss-on-... I was one of the people involved in some of the measurements on there. I avoid ubnt networking gear in general after that experience (although ER-X seems good and I use one at home as a smart switch). Their specialty is in APs, which work really great.

Thanks, and agreed. It was my first Ubnt gear, and I suspect it will be my last. It was so much cheaper than some of the alternatives though (that should probably have been a red flag…) but firmware that’s at best in continuous beta really isn’t good enough.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#126
post #14

Can anyone suggest a wireless router that someone can buy today that either ships with or can be flashed with OSS firmware? I've been trying to shop around for one compatible with DD-WRT or OpenWRT and been rather disheartened so far; every promising model I've found either requires you to play roulette with the specific hardware version of the router that you receive (which is never advertised on product pages), or…

I know this doesn't help friends and non-technical folks, but I finally gave up and bought an APU[0], installed Debian, and configured dnsmasq+hostapd+iptables. With unattended updates, it was the most secure thing I could think of. Well, I suppose using openbsd would have been potentially more secure, but there were driver issues with the wireless card that I wanted. [0] https://pcengines.ch/apu2.htm

I really, really love these machines. I'm using one with OPNsense myself. They're just fast enough to get gigabit throughput, but no faster (or more power hungry). Personally I like to separate switching from the firewall and so I've got everything attached to an unmanaged switch or a Unifi AP.

My one complaint about this approach is that there are so many interactions happening at the software level that any time I set up a network stack, I always feel as though the whole thing is very fragile and only works because everything is precisely configured. Since I like to tinker, I want a system that feels more reliable, and so I go for the router-in-a-box approach of pfsense or opnsense. I wish it was easy to get a network configuration that "just works".

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#127

Earlier quoted context omitted.

Ubiquiti EdgeOS based edgerouters are what I prefer as a greybeard sysadmin type who has dealt with everything under the sun. It's VyOS (Vyatta) based, they are now complying with gpl afaik, and their hardware is really good for the price/performance ratio. The edgerouter-x or lite can be found for ~$99 and is a great piece of gear. Another option would be your own hardware with pfsense (bsd) or ipfire(linux). Even f…

Sorry for the spam, I seem to post this regularly but the Ubiquiti EdgeRouter Lite will happily run OpenBSD. It supports the onboard packet accelerator with some extra configuration.

I wonder if the EdgeRouter Lite is similar enough to the Unifi Security Gateway to port that...

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#128
post #110

Earlier quoted context omitted.

What OS or software is that? Is that a Mikrotik router with default firmware that accepts such rules as you posted?

Yes, vanilla mikrotik (on the latest firmware -- interface-list is pretty new) The concept isn't hard -- block non-established incoming traffic from everywhere except where you want management to happen from. I have a few extra rules. Generally if you leave yourself wide open don't expect to be immune from zero-days.

Didn't know there were consumer routers that support command lines! I mean, fritzbox used to have a telnet interface that you could enable by dialing a dect number, but it wasn't meant to be used for anything or supported in any way (and later they removed it).

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#129
post #84

It's worth pointing out that the default configuration of almost every Mikrotik router these days comes with a firewall that blocks inbound access to all ports. Admins have to go out of their way to expose winbox to the internet (as many did - including myself - under the belief the protocol was somewhat secure running over TLS). Unfortunately NIH syndrome runs at an all time high at Mikrotik. Even the RouterOS webse…

>...so I no longer open up anything and rely on port forwarding to more secure and battle-tested services like OpenSSH / Wireguard for remote management.

Absolutely. I purchased an rb2011uiasrm when I got gig fiber at home. I enjoyed hardening the router and ran IPsec VPN for a bit but prefer using another box w/OpenVPN and HMAC auth. I just don't see no matter the promise of security a good reason for explicitly allowing remote access from internet to a core device, MikroTik or otherwise.

Re: MikroTik routers are forwarding owners’ traffic to unknown attackers

#130

Earlier quoted context omitted.

Same case for me. I had an AC88U. I got tired of it because the 5GHz 802.11ac radio seemed like it'd be forever broken in OSS firmwares. I felt asuswrt was pretty crappy too. I went ubiquiti. Their management is nice, and they actually seem interested in fixing bugs in their firmware.

On the AC66U, 5GHz radio seemed to work well and I got consistent 105-ish Mbps in the same room as the AP. (I'm not disputing your experience, but don't want other readers to conclude that 5GHz doesn't work on any of them.)

Is that the expected rate on an AC66U? I'm getting close to 300 Mbps real-world speeds in a very noisy environment on my Unifi lite.
Post reply on HN