Live data from Hacker News

Found hooked up to my router

reddit.com

341–350 of 358 posts

Re: Found hooked up to my router

#341
post #327
post #293

Is a disk image of one of these available anywhere? I find it much more likely that these are being used for what they say they are (basically a proxy so they can buy ads from a residential IP) than some crazy MITM device. The "Attacker" is basically renting an IP connection or paying a co-location fee for their little server. Plugging a device into your network doesn't make it magically see all the traffic. It would…

> Plugging a device into your network doesn't make it magically see all the traffic. Isn't that exactly what Wireshark's "promiscuous mode" does?

It will show you everything coming out of the switch port but only traffic to/from the connected device will come out the switch port.

You have to use ARP poisoning or some other trick to get other network devices to send ethernet frames to your mac address in order for the switch to forward them out your port.

Re: Found hooked up to my router

#342

Earlier quoted context omitted.

A lot of IT security teams do this. On one side it is depressing, but on another side it is annoying to have to hear them talk about it every staff meeting. All companies seem to have people with zero understanding of computers and will fall for anything. I wonder how effective the education is. I guess if it prevents one attack it can pay for itself.

> it is annoying to have to hear them talk about it every staff meeting Aren't you shooting the messenger?

Only a little bit. Most IT CyberSecurity teams can use bad stats to justify their value and additional staff, so they want to bring it up at every opportunity.

I don't necessarily disagree, but power users often get frustrated by red tape applied to everyone and not just those who consistently misuse their computer privileges.

Re: Found hooked up to my router

#343

> I have a Raspberry Pi right now in my hands fron rentyouraccont.com, i have it running diagnostics on an Air-Gapped pc. This thing is wild. Every second it tries to connect to bot-net programs. It not only buys ads on facebook (which btw i cannot find code that it actually does this) but it is creating links to malware ridden embeds. It is part of a Botnet, i can say for sure. Every second it tries to establish a c…

Eh.. no. It’s going to pickup worthless SSL encrypted TCP packets but not keystrokes.

People need to calm the hell down here. If you’re connecting HTTPS to most of the web, the only thing this thing is going to do is collect worthless packet traffic. Woot woot.

It’s not meant to collect data, it’s meant to act as an agent to a larger network of these things to collectively impact something or another in whatever way. But they could give 2 poops about the traffic on your local network.

Re: Found hooked up to my router

#344
post #293

Is a disk image of one of these available anywhere? I find it much more likely that these are being used for what they say they are (basically a proxy so they can buy ads from a residential IP) than some crazy MITM device. The "Attacker" is basically renting an IP connection or paying a co-location fee for their little server. Plugging a device into your network doesn't make it magically see all the traffic. It would…

Yes. You’re right. These things don’t care about local traffic. SSL would ruin its day if that where the case.

This is meant to be an agent to a network of these things. Not sure what the total point really is, but I can pretty much guarantee it has absolutely no cares about the local traffic.

Re: Found hooked up to my router

#345

Earlier quoted context omitted.

How is that better than epoxy squirted into all unused ports of your existing computers while also distributing fast charging USB wall warts across the office like confetti? Even the good ones are relatively cheap, especially if bought in bulk. Relative to the cost of a desktop computer they're practically free. (I'm genuinely surprised that the standard DELL and HP corporate workstation doesn't have its front USB po…

How do you know the wall wart is not a fake one?

How do you know your security guard is not a fake one?

Re: Found hooked up to my router

#346

Earlier quoted context omitted.

The X.500 series Common Name is a weird thing to fixate on here. It's an arbitrary free text "name". The only reason it's even sometimes useful in the modern era is that the CAB BRs say it has to match one of the SANs so it will probably be a DNS name. But even there good luck, it took until 2016 or so to get the last stragglers to obey that rule properly without "misunderstanding" it and unlike SANs it isn't defined…

Good luck finding anyone willing to issue you a cert that's valid for 20 years.

Leaf certificates have a maximum permitted lifespan of 825 days (down from 36 months)

But I wasn't talking about leaf certificates, I expressly mentioned this for the CN in _root_ certificates and it's pretty common for those to have a lifetime of ten, fifteen even twenty five years.

Here's an easy to remember example, https://crt.sh/?id=1 the first entry in the crt.sh database.

The Common Name on that certificate is "AddTrust External CA Root". So... who are AddTrust? I actually have no idea. This root is today controlled by Comodo, a CA in the United Kingdom but you'd never guess that from the certificate.

Re: Found hooked up to my router

#347
post #47

Earlier quoted context omitted.

They've gone well beyond the extension now. These days you have no idea if that "free" app you've installed has made a deal with Luminati to sell your bandwidth to the highest bidder. They also have an Android SDK too. I've received several emails like the following: > My name is Lior and I lead the SDK partnerships at Luminati.​ I assume your > software earns money by charging users for a premium subscription or by…

3 cents per user per month. Is that right? Is it hard to make 3 cents a month from a user?

3 cents more than what you were making before. It's free money

Re: Found hooked up to my router

#348
post #305

Earlier quoted context omitted.

Chrome changes the "Not secure" in the address bar from grey to red (and displays a red explamation mark symbol there) when data is entered into the form.

Which version/OS? I have the latest Chrome (69.0.3497.100) on macOS 10.13.3, and I see no red exclamation mark. Nothing changes or warns me at all when I start entering data in the fields. https://imgur.com/a/Q0rZWOS Maybe you have a browser extension, or setting turned on that I'm missing?

It's not enabled by default on the latest Chrome, at least for macOS (10.14). You can enable it using the #enable-mark-http-as flag, after which HTTP pages with password fields will look like this:

https://i.imgur.com/8kKWPjr.png

Re: Found hooked up to my router

#349

> I have a Raspberry Pi right now in my hands fron rentyouraccont.com, i have it running diagnostics on an Air-Gapped pc. This thing is wild. Every second it tries to connect to bot-net programs. It not only buys ads on facebook (which btw i cannot find code that it actually does this) but it is creating links to malware ridden embeds. It is part of a Botnet, i can say for sure. Every second it tries to establish a c…

Eh.. no. It’s going to pickup worthless SSL encrypted TCP packets but not keystrokes. People need to calm the hell down here. If you’re connecting HTTPS to most of the web, the only thing this thing is going to do is collect worthless packet traffic. Woot woot. It’s not meant to collect data, it’s meant to act as an agent to a larger network of these things to collectively impact something or another in whatever way.…

I agree, people are really looking into the keylogger theory, but actually I think the goal of the scammer is to have a "legitimate" (residential) internet connection with which to register hundreds of online accounts, or purchase ads, etc. If the IP gets blacklisted by a service (like Facebook), no problem, the account holder will probably notice that they can't get to Facebook anymore, call up the ISP and get a brand new IP address. All this for just $15/month.

Re: Found hooked up to my router

#350
post #296

Earlier quoted context omitted.

If you had never visited the site, how would modern security practices have prevented the attack? HSTS is useless in this case isn't it?

No. If the domain (and its subdomains) are preloaded - then a first visit is not required. The HSTS requirement is then baked into a list supported by modern browsers such as Firefox and Chrome.

Preloading always include subdomains (it's not possible to preload just tld).
Post reply on HN