Live data from Hacker News

200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

badpackets.net

41–50 of 76 posts

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#41
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Ubiquiti makes great little boxes, Edgerouter Lite, Edgerouter POE and Edgerouter 4 have all served me well over the years. They have hardware offloading for routing and iptables, will route 900Mbps, and get regular software updates. Edgerouter Lite is $99, and draws about 5W.

Their wired hardware is okay but some is subject to some pretty embarrassing bugs that Ubiquiti is extremely slow to fix [0] and in my own experience, their support is utterly abysmal.

I would recommend buying something else.

0: https://community.ubnt.com/t5/EdgeRouter/EdgeRouter-X-SFP-le... (reported 2017-03, still alive as of 2018-08)

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#42
post #32

I have several hAP ac Mikrotik routers and upgrading them is a pain. You can not just download an image from their website, flash and reboot. If you do so, your router will likely be locked in a bootloop. I managed to have consistent upgrades by using only the main package and Netinstall, but it is still a huge pain in the ass. Mikrotik makes stable routers, but they messed up the upgrade process completely.

What? I have updated all my MikrotikDevices by literally just dropping the new firmware image onto the device and restarting the device. That's it.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#43
post #25

Does anyone know if Ubiquiti's edgerouters are any good?

In my experience, no, they're not. Their wireless gear is great but when it comes to wired, I'd avoid them. There's a serious bug [0] on the ER-X-SFP that's been around for over a year without any serious action from Ubiquiti. Their support when I tried to get an RMA for said issue was utterly abysmal.

[0]: https://community.ubnt.com/t5/EdgeRouter/EdgeRouter-X-SFP-le...

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#44
post #37

Earlier quoted context omitted.

Huh? With the exception of them converting all master > slave port configs to bridges in 6.41 I believe, I have never had any issues using System > Packages > Check for updates, selecting bugfix as opposed to current branch and downloading and installing in Winbox. SwOS devices I need to download a binary and upgrade through web (no Winbox) but still have never had any issues.

Try doing it through the web interface, you'll be unpleasantly surprised. I just upgraded my last hAP ac from 6.39.2 to 6.42.9 through the web interface, entered the bootloop, then did the Netinstall of the system package only, then manually restored the configuration.

This is why we do backups :) I always assume something will go wrong, but make sure to have a backup of any critical device that is being updated (mikrotik or not).

Did your hAP run out of flash disk space? I notice that it only has 16MB.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#45
I'm really curious, where are these routers? The problem is that the admin interface port is exposed to the internet, which is something any competent administrator would ensure isn't accessible. So are there incompetent admins managing 200k devices or is someone distributing these to residential users?

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#46

I'm really curious, where are these routers? The problem is that the admin interface port is exposed to the internet, which is something any competent administrator would ensure isn't accessible. So are there incompetent admins managing 200k devices or is someone distributing these to residential users?

When I first started reading about these reports over the past week I believe around 90%+ were in Brazil. If you peruse BPR timeline on Twitter they mention type of orgs using them. One of hardest hit I believe was ISP in Arizona or New Mexico, US.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#47
IMHO Mikrotik are being sloppy by introducing breaking changes to their stable channel. Hence ISPs are reluctant to update automatically, fearing some subtle bridge/VLAN change which is sadly set to happen again (6.43 -> 6.44!). Also doesn't help that the underlying Linux stable kernel updates more than once a week.

Every Internet connected device needs some automatic update functionality by default. It's tricky for routers since you typically do not want any downtime and it's really difficult/expensive (well at least 2x the cost for hardware alone) to do a blue/green (or is it red/black?) deployment. Not to mention since Mikrotik is low end, there is no state replication functionality between routers.

Here is a config for Mikrotik that updates my non-ISP hardware once a week at 3AM: https://gist.github.com/kaihendry/59a656c3883450d2df2fd52574...

And when the ISP opts out of the suggested automatic update default, they need to make the commitment to test and roll up updates in a timely fashion. As we all know this is hugely expensive, and I strongly believe a vendor/"computer program" should be able to provide this service. Customers with these ISPs who didn't update are probably seeing some crazy packetloss.

So the future I'd like to see is Mikrotik updates being automatic, staged to some degree & ultimately non-breaking. Cons are downtime for some & I guess allowing your device to be remotely controlled by Latvians. ;)

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#48
post #47

IMHO Mikrotik are being sloppy by introducing breaking changes to their stable channel. Hence ISPs are reluctant to update automatically, fearing some subtle bridge/VLAN change which is sadly set to happen again (6.43 -> 6.44!). Also doesn't help that the underlying Linux stable kernel updates more than once a week. Every Internet connected device needs some automatic update functionality by default. It's tricky for…

AFAIK, most Mikrotik employees speak native Russian and only passable Latvian. "Remotely controlled by Russians living in Latvia".

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#49
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

I gave up on all-in-one firewall/router/wireless AP units recently and now have a more complex setup I'd only recommend to those who enjoy setting these things up and learning.

For the firewall I've got pfSense (FreeBSD based firewall) running on an small Intel box from Aliexpress with 6x ethernet ports. I overspecced the machine so I knew it would last for years, whilst allowing running intrusion detection (snort), reverse proxy, auto blacklisting and much more.

This is also acting as my router, but if & when my home network expands I'll add a dedicated one (and probably put 4x ethernet ports bonded using lagg into it as it'll still be controlling my vlans).

I got a dedicated ceiling mount wireless AP from TP-Link.

This has only slightly higher power and space requirements than what I had, but that buys me so much flexibility. I can upgrade and augment individual components when needed (particularly wifi). I have individual vlans, firewalled off from each other, running over three wifi SSIDs - trusted, guest and internet-of-shit. I'm currently connected into my trusted vlan over OpenVPN, so I can connect to my server without having to open any ports to the outside world.

The downsides are that it did take a couple of days to set it all up to my liking, but personally I've learned so much doing it it's been worth every minute.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#50
post #48
post #47

IMHO Mikrotik are being sloppy by introducing breaking changes to their stable channel. Hence ISPs are reluctant to update automatically, fearing some subtle bridge/VLAN change which is sadly set to happen again (6.43 -> 6.44!). Also doesn't help that the underlying Linux stable kernel updates more than once a week. Every Internet connected device needs some automatic update functionality by default. It's tricky for…

AFAIK, most Mikrotik employees speak native Russian and only passable Latvian. "Remotely controlled by Russians living in Latvia".

That's patently false, and also irrelevant.
Post reply on HN