Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

141–150 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#141
post #138

Reminds me of a black hat I knew in the 90s. He bragged that if he ever gained access to a system, he'd start patching vulnerabilities so others wouldn't gain access and make it obvious the machine had been compromised.

I can attest that there was at least one such black hat in the 00's.

One of my IT guy's mom complained about her machine being slow and having "too many pop ups", so he planned to go to her place on the weekend and fix it. She called back a couple of days later and told him not to bother as it was "all fixed now".

o.O

I lent him one of our loaner laptops and he brought in her computer back and put it on our test DMZ to see what was up. Yep, somebody had scrubbed all the malware and "search bars" off the machine and installed a free anti-virus package. The exceptions on the anti-virus made it easy to track down what was happening; it was set to send spam every night between 1am and 7am but otherwise was pristine.

My colleague had to do some serious soul searching before he decided to wipe it instead of just returning it ...

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#142

Earlier quoted context omitted.

At least four things were admitted: that you received the information, somebody processed it, the approximate time you received/processed, and the intention to take action. I would hope any well-intentioned and reputable company would not mind, but some might not want to admit any of that! Plenty of ammo for anyone who subsequently blames you if you then fail to remedy the situation in a timely fashion.

A reputable company that deserves it's reputation is probably not hosting phishers pages on their site. Sure, shit happens, but anything above a micro company that's hosting pages should catch that. The shared hosting company I used caught a breach on my personal page once, another time Google notified me: it's not rocket surgery to catch these things is it. If the company is too small to monitor their own pages then…

You just can’t tell, when your job is hosting user content, e.g. managed website hosting (cpanel) or static pages (Azure static website hosting). I mention these two companies because I received 2 phishing attempts this week, both pretending to be from Microsoft, with the payload hosted on cpanel and Azure respectively.

Both have an abuse / phishing declaration form online. I signaled both pages, and they are still up for the moment.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#143

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people just don't put addresses they check often there.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#144
post #108

Earlier quoted context omitted.

Don't forget that a lot of the customer base for Mikrotik is in remote locations (ie: P2P connections in rural areas) or small ISPs. Having the router in your office die on you (even during office hours) is a little different than all your customers call you the same day their only internet connection is gone.

I used to be a customer of a remote WISP, P2P in a rural area. I can't speak for all WISP's, but we only had service about 12 hours a day, less if it was raining. Five minutes to reboot a router would have been invisible.

I used to contract with a WISP. I would regularly get calls to "reboot the router" from the owner. The "router" was a fiber switch at their CO. I would just do it when they asked. I wasn't a customer nor did I get paid enough to fix their network. Sorry if that was your connection. :)

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#145

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then I let a software company that supplies enterprise software know that their marketing emails are going to spam because their marketing email provider doesn't have an spf record on their domain. They know me personally but still never reply.

I told the same company that the certificate had expired in one of their sub-domains. It intrigued me that the first 3 of their tech team didn't know what that meant.

Still they never said thank you.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#146

Earlier quoted context omitted.

Vulnerabilities are almost unavoidable. Leaving a management port on a router open to the entire internet is a very bad practice. Would you leave an RDP port open to the world? If you require remote access, at least restrict it to known management IP addresses.

Why is it that vulnerabilities are almost unavoidable? I’m not trying to be a smart-ass; I’m an analyst at an MSP and I’m doing my first pen-test soon. I’m under no illusions that my job title or growing responsibilities make me a security expert (or anywhere near it). Is it because the software stack is just too complex for network programmers to handle? (Not that router OSes are the only pieces of software that hav…

I'm not an expert either, so take this with a grain of salt. At the risk of sounding glib, I'd think the biggest cause of this unavoidability is that security professionals have to be "right" (in the sense of plugging every hole) every time, whereas black-hats need to be right (in the sense of finding said vulnerabilities) only once (or a few times depending on the vector, but you get the idea). Being on a Blue Team strikes me as a hard, thankless job, and I'm grateful for the people who volunteer for it.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#147
post #113

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

>I do sometimes wonder what the internet has done to once-common human decency and politeness. Politeness essencially disappears once you can't see somebody's face. 10 minutes in any online game should be proof of concet enough.

Yeah, it's pretty bad. Some games try to gamify polite behavior (bonuses for getting tagged as helpful in a dungeon, etc), and that sort of works. Kind of sad that it's necessary, though.

I also think the rude behavior is a combination of both anonymity and "I'm never going to see or hear from this person again".

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#148
post #119

Earlier quoted context omitted.

Why so negative?

This is not at all negative. Imagine parent telling some underground rebel group that their revolution would be more successful if they organized it with Jira. Meanwhile, this concern is so far away from the rebels, who are doing just fine with pen and paper, and are more concerned with basic needs like surviving undetected. People are of course excited by this initiative, and wish to contribute how they know. Except…

Indeed, I try to avoid such good-intentioned bikeshedding by providing anecdotal solutions and listing tools I found helpful. That way, someone with a similar issue may find something useful or provide better advice to me.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#149
post #143

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…

>with the authority and means to shut down domains for exactly this

How do you get that authority to do that? What does "shut down" entail? Does that mean you can unregister or hijack domains? I'd like to know more about this, as well as the accountability process and where I can report abusive behavior that will actually get addressed.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#150
post #55

Earlier quoted context omitted.

Or that your email is the actual attack they need to worry about.

> I'm a security researcher and I discovered that your server has been compromised. Click this legitimate link to learn more.

more like "click this legitimate link TO YOUR OWN SERVERS to learn more". Big difference :)
Post reply on HN