Earlier quoted context omitted.
It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.
I think it it's more like someone locking your front door.
A mysterious grey-hat is patching people's outdated MikroTik routers
171–180 of 220 posts
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#172A quick look at the system told me the root account had no password set. So I tried a telnet and wham - I was in.
A 'who' showed someone else was logged in. So I sent a broadcast message to them saying they need to secure their system better, and logged out.
I had the habit of using an obscure hotmail email to log into FTP servers, and had done that here. I was surprised to see an email from the owner - wanting to know how I found his system, etc. He was nice, but I didn't reply.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#173>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.
Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…
I usually only notify .edu or nonprofit organizations and completely ignore large corporations. Sending an email to a larger organization usually gets lost and nothing comes of it.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#174Earlier quoted context omitted.
> Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability? I'm curious, for vulnerability-by-inaction like this, would there be a legal difference if sent emails were posted to a public blockchain? The intent being, if you're later sued for harm caused by your compromised hardware / IoT devices, you cannot claim ignorance as easily. End goal, of course,…
Ignorantia juris non excusat.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#175Earlier quoted context omitted.
As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…
>with the authority and means to shut down domains for exactly this How do you get that authority to do that? What does "shut down" entail? Does that mean you can unregister or hijack domains? I'd like to know more about this, as well as the accountability process and where I can report abusive behavior that will actually get addressed.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#176Earlier quoted context omitted.
It's a tradeoff. You have to balance that negative against the negative of having botnets of millions of never-patched routers. Automatic updates should be the default, but you should be able to shut them off if you want to make a different tradeoff.
Automatic security updates should be the default, all other updates should absolutely not . In case of patching routers there isn't much crapware to be upsold, but in general, if we're ever going to develop some code of ethics in this industry, I wish a part of it would be a rule of hard separation between security patches and feature updates, and another rule that the latter should never be done automatically withou…
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#177Earlier quoted context omitted.
Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…
As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…
No reason to ask at all honesty, it's just been one of those curios that pops up in mind occasionally
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#178Earlier quoted context omitted.
As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…
Hey just because it may be a fair time until I next get a chance to ask someone who may have the answer - I've wondered a fair bit do you guys get a lot of spam at the abuse@ for domains or do spam bots know to not bother with them? No reason to ask at all honesty, it's just been one of those curios that pops up in mind occasionally
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#179Not sure what they mean by "mysterious". He isn't hiding and never was. He posted his photo, name and other personal details in articles about MikroTik on Russian IT blogging platform[1]. His name is Alexey Sopov, 34, from Novosibirsk. Quick search revealed his social network accounts: https://fb.com/100005153643926 https://vk.com/lmonoceros [1] https://habr.com/post/353530/
Clickbait?
I'm pretty sure the FBI would love to arrest him by now. Just like MalwareTech.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#180Back in college (early 90's) I would run ToneLoc overnight, and wake up to view the results. One time I had a hit, and I ftp'ed into some server on Mindspring's customer IP range. A quick look at the system told me the root account had no password set. So I tried a telnet and wham - I was in. A 'who' showed someone else was logged in. So I sent a broadcast message to them saying they need to secure their system bette…
Noooooo. Story started off well and then you tree fiddied me!