Live data from Hacker News

Found hooked up to my router

reddit.com

121–130 of 358 posts

Re: Found hooked up to my router

#121
post #78

Earlier quoted context omitted.

This is how stuxnet got into the Natanz facility I think. They left a usb stick in the parking lot. Someone picked it up, plugged it in.

No, iirc stuxnet spread itself without anyone physically leaving a USB stick anywhere. On a system infected via the network, it would try to infect any USB drives connected to the system.

Stuxnet is fascinating. Still, as far as I can tell, the most complex, interesting malware ever found in the wild. I believe it's unclear how stuxnet found its way into the enrichment facilities.

Re: Found hooked up to my router

#123

Earlier quoted context omitted.

> the IT security team would sometimes seed the parking lots with thumb drives that were "infected" with a program that would phone home to them if plugged into a PC on the corporate network. Which is clever, but given the current level of small scale integration you could just as easily hide the same exploits inside of a charging cable, a USB fan, or really any other small-form factor USB-pluggable gadget. The probl…

Anecdotally, I heard of a toy radio control quadcopter belonging to western military personnel in Afghanistan that turned out to be trying to phone home to ${badguy} when they plugged it into a laptop to charge. This stuff is everywhere, and has been for years.

This is why I keep a large supply of "USB Condoms" (little dongles that short circuit the data, and allow charging/power only)

Re: Found hooked up to my router

#124
post #53

One comment in that thread[1] gives a full explanation of what such a Raspberry Pi device hooked up to the router can do: forward all the network traffic, replace router's stock firmware with its own, install software on the network connected devices via known vulnerabilities, spoof websites by acting as custom DNS server. In my opinion, it looks like "a Pi-hole[2], but for phishing". [1] https://www.reddit.com/r/wha…

I still don't understand how this device could steal login details. Everything should be encrypted and authenticated through PKI when using any website that accepts login details. Whenever I visit a website with an expired certificate, for example, Chrome gives me a big red warning banner before allowing me to continue to the site.

I think the idea is that it could proxy communication. Mitm

Re: Found hooked up to my router

#125

Earlier quoted context omitted.

The first comment in the thread you link to says the Raspberry Pi connects to botnets and records all network traffic.

> It records EVERY KEYSTROKE sent of the network, even SSL connection. One wonders how it does that.

A microphone and some basic ML?

Sort of tongue in cheek, since I don't know the range of state of the art acoustic side-channel taps. I guess you'd also probably have power fluctuations and network timing channels to exploit.

Plus, a lot of different points at which to attempt to insert a second stage into the connected devices themselves, using all the tricks everyone else in this thread has mentioned.

Re: Found hooked up to my router

#126
post #124

Earlier quoted context omitted.

I still don't understand how this device could steal login details. Everything should be encrypted and authenticated through PKI when using any website that accepts login details. Whenever I visit a website with an expired certificate, for example, Chrome gives me a big red warning banner before allowing me to continue to the site.

I think the idea is that it could proxy communication. Mitm

you still have to install the proxy certs

Re: Found hooked up to my router

#127
post #91
post #88

Earlier quoted context omitted.

How many users do you know of who manually check hashes on downloaded executables? And of course the user is going to ignore the untrusted source warning on an executable they intentionally downloaded and are trying to run.

I think what he means is that it seems like a lot of trouble to hack someone who is not necessarily hackworthy? Like what kind of things would you expect to gain from someone who would be as computer illiterate as to allow all that to come to fruition?

You only have to set this up once, then flash it to each device you're sending out.

Re: Found hooked up to my router

#128
post #116

Earlier quoted context omitted.

Oh, please, no-one would fall for that! FY2018_salary_data.xls.exe, on the other hand... :P

It wasn't uncommon to see hot_new_song.mp3.exe back in the gnutella heyday.

I made that mistake once when I was a teen. My father was not pleased one bit.

Re: Found hooked up to my router

#129

Earlier quoted context omitted.

No, iirc stuxnet spread itself without anyone physically leaving a USB stick anywhere. On a system infected via the network, it would try to infect any USB drives connected to the system.

Stuxnet is fascinating. Still, as far as I can tell, the most complex, interesting malware ever found in the wild. I believe it's unclear how stuxnet found its way into the enrichment facilities.

It did contain a USB device exploit delivering a dropper with a completely separate payload specifically targeted at the Natanz facility. A compromised USB device picked up in the parking lot would do the trick, but there are certainly other ways to get something through the front door and that information is unlikely to be public knowledge any time soon.

Re: Found hooked up to my router

#130

Whilst it's certainly a scam to do with advertising [0], I doesn't look like there's any evidence that the scam has anything to do with 'stealing' anything from network / network traffic: > Facebook has several mechanisms in place to protect your account. We make every attempt to work within the these constraints. In order to keep your account from being locked we use a small device called a Raspberry Pi. This device…

Look lower down that thread for the FAQ from the company: they're using the roommate's Facebook account to purchase targeted ads on Facebook in order to evade Facebook's internal controls. https://www.reddit.com/r/Scams/comments/2vd1g8/scam_rentyour...
Post reply on HN