Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

71–80 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#71
post #61

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

How do they know that you can be trusted, and aren't just another spammer/phisher? You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

What I do in my emails is tell them the exact URL of the bad page. All they need to do is look at the file with a text editor (they are admins, after all). Once they have done this, they will see strange Javascript. They will know it has nothing to do with their own (or their clients) web pages. There are no links per se in my email (except the URL, but I leave off the http:).

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#72
post #61

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

How do they know that you can be trusted, and aren't just another spammer/phisher? You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

They wouldn't trust the sender they would assign a dev to inspect the referenced file, decision making would start at that point.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#73

Earlier quoted context omitted.

Actually I once heard a story of a neighbor who let themselves in when the house was literally flooding and he saved the owner thousands of dollars worth of damage. That's more like what's happening with these patched routers. I also heard a story of a guy who's house burned down. The neighbor saw it very early and did nothing about it cuz not her problem. The homeowner was devastated. So yes, if you see incredible d…

I've heard that in US you could be shot for trespassing. It might be very dangerous to try fixing it.

Similarly, unsolicited help with computer infrastructure can land you in jail under CFAA. No good deed goes unpunished.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#74
> As for MikroTik, the Latvian company has been one of the most responsive vendors in terms of security flaws, fixing issues within hours or days, compared to the months that some other router vendors tend to take. It would be unfair to blame this situation on them. Patches have been available for months, but, yet again, it is ISPs and home users who are failing to take advantage of them.

A system that requires users to opt in to security is not a secure system.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#76

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

> I NEVER received a thank you from any of these people. Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability?

> Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability?

I'm curious, for vulnerability-by-inaction like this, would there be a legal difference if sent emails were posted to a public blockchain?

The intent being, if you're later sued for harm caused by your compromised hardware / IoT devices, you cannot claim ignorance as easily.

End goal, of course, being that people care more about patching their devices.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#78

Devices at vulnerable routerOS version and not already compromised would not be vulnerable if the firewall was enabled. It's that simple. Not great that these boxes used to ship in this default state and I can _understand_ a home user unfamiliar with what they're dealing with but what reason is there for deploying infrastructure this way at an ISP or hospital or whatever org?

I've heard that this was the default for these routers. I have a RB951G-2HnD using NAT, and, although I patched it long ago, as far as I can tell the relevant ports were never open on the WAN side, nor any ports that I haven't manually forwarded. Was that not the default?

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#79

Earlier quoted context omitted.

Security issues are tricky. Often making people aware of an issue is indistinguishable from having caused the issue.

Only if you're technologically-illiterate.

... which many people are.

What's your point?

Post reply on HN