Live data from Hacker News

200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

badpackets.net

21–30 of 76 posts

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#21
post #20

Earlier quoted context omitted.

Turris omnia. Open source (both hardware and software), lets you ssh into it directly out of the box (well, after you have set a root password in the gui) They provide regular software updates, and it is imho a good hacker/tinkerer router.

300€ is about 5 times what I would consider a price to pay for a home router though.

this depends on what you want out of it I guess. I wanted a tinker router, one which doesnt treat me like an absolute idiot, with a spf for fiber, can do gigabit easily and is expandable.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#22
post #9
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

See my post above: APU2 by pcengines. Put debian on it.

I have one running pfSense. It's never given me any trouble.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#23
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Mikrotik is trustworthy enough. The update that fixed this was released in April, the first exploit appeared a few months later but this story gets regurgitated every couple of weeks because so many people use insecure configurations and don't bother upgrading their routers.

As to their update availability - I'm fairly certain I could take something they manufactured 15 years ago and update it to the current version, as it all uses the same OS, and they still support every architecture they've used.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#24
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

I bought a mini PC with 4 Gigabit Ethernet ports and Wifi, i5, 4G RAM, 32G SSD (probably way overkill for a router but I can do other stuff on it) on Aliexpress for about 250 USD and put Debian on it. I heard it works well with pfsense too.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#26
post #17
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Germany (or rather DACH) has AVM, a German manufacturer that is making the "Fritz!Box" product line and supplied security updates to all affected routers they ever sold after somebody discovered and exploited a bug in the firmware to remotely call premium numbers via VoIP in various countries. Their routers were also not affected by the KRACK WPA2 exploit last year. AVM products cost a lot more than their competitors…

I can agree with that, AVM Fritz!Box are also quite capable routers, the only problem I ever had was that it doesn't properly forward IPv6 ICMP.

It's 100% worth the extra cash getting an AVM over most ISP routers you get in germany.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#27
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Mikrotik is trustworthy enough. The update that fixed this was released in April, the first exploit appeared a few months later but this story gets regurgitated every couple of weeks because so many people use insecure configurations and don't bother upgrading their routers. As to their update availability - I'm fairly certain I could take something they manufactured 15 years ago and update it to the current version,…

Also, while Mikrotik security practices are not great (as I recall, before this vulnerability, admin passwords were stored in plain text), by default, I think zero services listen on the WAN port. Owners must specifically configure their device in a not recommended manner (exposing the low-quality web admin interface to the world) for this vulnerability. It's like exposing your printer web interface to the world and expecting it not to get hacked.

The main problem with Mikrotik is that the configuration interface is too low-level and it's easy to fall into such traps.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#28
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Mikrotik is trustworthy enough. The update that fixed this was released in April, the first exploit appeared a few months later but this story gets regurgitated every couple of weeks because so many people use insecure configurations and don't bother upgrading their routers. As to their update availability - I'm fairly certain I could take something they manufactured 15 years ago and update it to the current version,…

I wonder how networking equipment manufacturers can motivate regular users to update their equipment more regularly? Auto update would seems like a logical one but plenty of people have reasons to not update and don't want there router going down at times they cannot control.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#29
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Ubiquiti makes great little boxes, Edgerouter Lite, Edgerouter POE and Edgerouter 4 have all served me well over the years.

They have hardware offloading for routing and iptables, will route 900Mbps, and get regular software updates.

Edgerouter Lite is $99, and draws about 5W.

Post reply on HN