Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

91–100 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#91

Devices at vulnerable routerOS version and not already compromised would not be vulnerable if the firewall was enabled. It's that simple. Not great that these boxes used to ship in this default state and I can _understand_ a home user unfamiliar with what they're dealing with but what reason is there for deploying infrastructure this way at an ISP or hospital or whatever org?

How long ago was it that Mikrotik shipped devices that listened on the WAN port? The Mikrotik hEX and RB3011 I bought last year most assuredly was not configured that way even though the version of ROS on them was many revisions out of date.

I've purchased a rack-mounted RB2011 and wAP ac, more commonly known as RBwAPG-5HacT2HnD (lol these model names), within the last 3 years that did not have firewall enabled and contained no firewall rules by default. If I had to guess it was around ROS 6.32 or 6.33 release for 2011 and recently for the wAP.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#94
post #61

Earlier quoted context omitted.

How do they know that you can be trusted, and aren't just another spammer/phisher? You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

What I do in my emails is tell them the exact URL of the bad page. All they need to do is look at the file with a text editor (they are admins, after all). Once they have done this, they will see strange Javascript. They will know it has nothing to do with their own (or their clients) web pages. There are no links per se in my email (except the URL, but I leave off the http:).

Don't you worry that if you email spammy/virus-laden links then your email address could get flagged?

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#96
post #20

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.

[deleted]

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#98
post #61

Earlier quoted context omitted.

How do they know that you can be trusted, and aren't just another spammer/phisher? You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

What I do in my emails is tell them the exact URL of the bad page. All they need to do is look at the file with a text editor (they are admins, after all). Once they have done this, they will see strange Javascript. They will know it has nothing to do with their own (or their clients) web pages. There are no links per se in my email (except the URL, but I leave off the http:).

Most site admins aren't really aware/in-charge of the javascript on their pages.

Most webmaster@ or admin@ e-mails aren't monitored at all, or so flooded with spam that it's easy for things to get lost.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#99

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

> I NEVER received a thank you from any of these people. Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability?

"Thanks for the info, I'll check this out :)"

There, nothing was admitted.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#100

> As for MikroTik, the Latvian company has been one of the most responsive vendors in terms of security flaws, fixing issues within hours or days, compared to the months that some other router vendors tend to take. It would be unfair to blame this situation on them. Patches have been available for months, but, yet again, it is ISPs and home users who are failing to take advantage of them. A system that requires users…

It takes effort to purchase, install, and configure MikroTik products rather than just using the router/AP combo you got from your ISP. Anyone who has done that is capable of patching occasionally. [EDIT:] And actually now that I've read TFA I learn that many of these are actually "edge" routers used by ISPs on their own premises. There's no excuse for an ISP not to keep up with patches.
Post reply on HN