Strangely, Reddit cut off comment on the topic, before the device was clearly identified.
Yeah, I have no idea how it could accomplish what is alleged. Just lots of very bad no good end of world comments. Have none of these people ever used public wifi?
Found hooked up to my router
11–20 of 358 posts
Re: Found hooked up to my router
#12It's obviously located "inside" the residential end user's router/NAT, on their wifi, so it'll have something like an openvpn or ipsec daemon on it that initiates a connection to an endpoint elsewhere on the internet, building a tunnel for the botnet operators to control it remotely. Or via tor to a tor hidden service somewhere, like many purely software trojan botnets for win32/win64, but in this case it will have the vpn or tor binaries running on its own dedicated raspberry-pi class device.
If you have a botnet of several thousand devices which can be made to look indistinguishable from legitimate "ordinary non technical user sitting at home on their comcast connection with their laptop or tablet", you can do all sorts of things. Relay http/https traffic for a click farm in Bangladesh where people are upvoting reddit comments en masse to promote a product, sockpuppet facebook account comments for political campaigns and pushing political agendas (russian internet research agency, anyone?), etc. The goal here is to make the traffic look like legit single end user residential internet traffic and not traffic that's coming from netblocks of major colocation/dedicated server/VPS/VM hosting companies, whose ARIN/RIPE/APNIC space is all documented as such.
There's fraud detection systems which will trigger if you're trying to buy something like amazon gift cards from a /20 netblock of an ISP in Bulgaria, but are less "suspicious" if your traffic and useragent, etc, are all coming from a Frontier, Centurylink, Comcast etc netblock in a major American city. Stuff like the maxmind geolocation data correlating closely with the billing zipcode/shipping zip code of what you're trying to buy with a stolen credit card, or other identify theft type scams.
If you're doing some variation on a massive vote manipulation service, there's also fraud/botnet detection systems which will trigger on large volumes of upvotes (or similar manipulation) all coming from the same geographical location and netblocks. Your traffic look more like legitimate end users if it is geographically distributed across many states and provinces, many english-speaking countries (AU, NZ, CA, UK, etc), and across many ISPs and several different common end user browser useragents (edge, chrome, firefox, etc). Imagine if you threw 500 darts at a map of the USA on a wall and distributed all your botnet devices randomly around the map, vs having 300 devices all on the same network in the Chicago metro area, for instance.
Re: Found hooked up to my router
#13Re: Found hooked up to my router
#14Strangely, Reddit cut off comment on the topic, before the device was clearly identified.
Re: Found hooked up to my router
#15Earlier quoted context omitted.
Yes, this one is malfunctioning.
or time for proper network security? port-security and disabling unused ports works great in these cases, especially if you are the sole user of the network.
Re: Found hooked up to my router
#16Earlier quoted context omitted.
Yes, this one is malfunctioning.
or time for proper network security? port-security and disabling unused ports works great in these cases, especially if you are the sole user of the network.
Re: Found hooked up to my router
#17If I had to guess, it's providing VPN endpoint/relay services to scammers (CC fraud, etc) who need actual residential IPs to buy things from. Or to use to set up accounts/sockpuppet accounts for things like automated reddit vote manipulation. It's obviously located "inside" the residential end user's router/NAT, on their wifi, so it'll have something like an openvpn or ipsec daemon on it that initiates a connection t…
This is the first one that came up on google - https://stormproxies.com/ - I'm not saying that specific company is in any way related to this device or tactic (it is just the first on google for 'residential address ip proxy', but I think it is companies similar to this that will pay people for access to their routers and sell that access.
Re: Found hooked up to my router
#18Earlier quoted context omitted.
Yes, this one is malfunctioning.
or time for proper network security? port-security and disabling unused ports works great in these cases, especially if you are the sole user of the network.
Re: Found hooked up to my router
#19Strangely, Reddit cut off comment on the topic, before the device was clearly identified.
Re: Found hooked up to my router
#20If I had to guess, it's providing VPN endpoint/relay services to scammers (CC fraud, etc) who need actual residential IPs to buy things from. Or to use to set up accounts/sockpuppet accounts for things like automated reddit vote manipulation. It's obviously located "inside" the residential end user's router/NAT, on their wifi, so it'll have something like an openvpn or ipsec daemon on it that initiates a connection t…
There are companies out there that offer proxies from 'real' US resident IP addresses. I think these companies use tactics like this to be able to offer real residential IPs (and not IP ranges belonging to hosting companies) This is the first one that came up on google - https://stormproxies.com/ - I'm not saying that specific company is in any way related to this device or tactic (it is just the first on google for…
It's a slick html template and some marketing text masquerading in front of a service obviously sold to greyhat/blackhat end users.
(perspective: I work for a legit ISP that has real things that physically exist in many POPs at layer 1 in the OSI model).