Live data from Hacker News

Found hooked up to my router

reddit.com

101–110 of 358 posts

Re: Found hooked up to my router

#101
post #53

One comment in that thread[1] gives a full explanation of what such a Raspberry Pi device hooked up to the router can do: forward all the network traffic, replace router's stock firmware with its own, install software on the network connected devices via known vulnerabilities, spoof websites by acting as custom DNS server. In my opinion, it looks like "a Pi-hole[2], but for phishing". [1] https://www.reddit.com/r/wha…

It's amazing how many people forget that Raspbian is still Linux under all the Wolfram and Raspberry Pi stuff. So you essentially have a tiny computer that can be plugged into almost anything you can program for.

Re: Found hooked up to my router

#103

In the days when USB sticks were more common it was an easy tactic for someone to drop one in a company parking lot labeled “salary data” and with almost certainty that thing would get plugged into a device on the corporate network. The biggest security vulnerability in most cases is still users doing dumb things.

USB sticks are still pretty common.

Re: Found hooked up to my router

#104

If someone would ship this to our office with a note like "attach this to a LAN port" chances are it will get attached. And we're a software house. People tend to pay attention to viruses, etc.. but not physical security.

This is why, as much as I hate it most of the time, it's a good idea not to have your devs with access to your network setup. If your a small shop, limit the access as much as reasonably possible.

Re: Found hooked up to my router

#106

If someone would ship this to our office with a note like "attach this to a LAN port" chances are it will get attached. And we're a software house. People tend to pay attention to viruses, etc.. but not physical security.

At a previous employer (Fortune 500, not a software co.) the IT security team would sometimes seed the parking lots with thumb drives that were "infected" with a program that would phone home to them if plugged into a PC on the corporate network. IIRC there was a depressingly high (> 50%) rate of them being plugged in.

Re: Found hooked up to my router

#107
post #47
post #29

Earlier quoted context omitted.

Luminati.io merely uses the Hola extension to power a massive residential IP network. Hardware is so 2000.

They've gone well beyond the extension now. These days you have no idea if that "free" app you've installed has made a deal with Luminati to sell your bandwidth to the highest bidder. They also have an Android SDK too. I've received several emails like the following: > My name is Lior and I lead the SDK partnerships at Luminati.​ I assume your > software earns money by charging users for a premium subscription or by…

>Israeli company

>Sketchy as fuck

Can't say I'm surprised.

Re: Found hooked up to my router

#108
post #35

Earlier quoted context omitted.

Looks like a nano pi neo: https://www.friendlyarm.com/index.php?route=product/product&...

Of course, but that tells you nothing. What software is in it?

likely armbian based on the filenames, with custom files in /conf and in /scripts.

Re: Found hooked up to my router

#109
post #91
post #88

Earlier quoted context omitted.

How many users do you know of who manually check hashes on downloaded executables? And of course the user is going to ignore the untrusted source warning on an executable they intentionally downloaded and are trying to run.

I think what he means is that it seems like a lot of trouble to hack someone who is not necessarily hackworthy? Like what kind of things would you expect to gain from someone who would be as computer illiterate as to allow all that to come to fruition?

I agree that $25 / month is more than the average bot is generating. That said, there's a lot of value to many people's computers if properly exploited: https://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hac...

Re: Found hooked up to my router

#110
post #78

If someone would ship this to our office with a note like "attach this to a LAN port" chances are it will get attached. And we're a software house. People tend to pay attention to viruses, etc.. but not physical security.

This is how stuxnet got into the Natanz facility I think. They left a usb stick in the parking lot. Someone picked it up, plugged it in.

No, iirc stuxnet spread itself without anyone physically leaving a USB stick anywhere. On a system infected via the network, it would try to infect any USB drives connected to the system.
Post reply on HN