Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

171–180 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#171
post #20

Earlier quoted context omitted.

It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.

I think it it's more like someone locking your front door.

Occasionally I see a car with the window down, that someone appears to have parked and left mistakenly accessible. When I was younger I'd have opened the door and wound the window up (checking for pets and other occupants obvs). Now, I leave the car alone because if someone comes back at the wrong moment it just looks like you're breaking in.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#172
Back in college (early 90's) I would run ToneLoc overnight, and wake up to view the results. One time I had a hit, and I ftp'ed into some server on Mindspring's customer IP range.

A quick look at the system told me the root account had no password set. So I tried a telnet and wham - I was in.

A 'who' showed someone else was logged in. So I sent a broadcast message to them saying they need to secure their system better, and logged out.

I had the habit of using an obscure hotmail email to log into FTP servers, and had done that here. I was surprised to see an email from the owner - wanting to know how I found his system, etc. He was nice, but I didn't reply.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#173

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

I'm on my company's many distribution email list for info@ support@ and other common addresses. I do the exact same thing, but I've received a number of email responses saying thanks or asking for the original email headers.

I usually only notify .edu or nonprofit organizations and completely ignore large corporations. Sending an email to a larger organization usually gets lost and nothing comes of it.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#174
post #76

Earlier quoted context omitted.

> Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability? I'm curious, for vulnerability-by-inaction like this, would there be a legal difference if sent emails were posted to a public blockchain? The intent being, if you're later sued for harm caused by your compromised hardware / IoT devices, you cannot claim ignorance as easily. End goal, of course,…

Ignorantia juris non excusat.

This is not about of ignorance of the law, so this doesn't apply here.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#175
post #143

Earlier quoted context omitted.

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…

>with the authority and means to shut down domains for exactly this How do you get that authority to do that? What does "shut down" entail? Does that mean you can unregister or hijack domains? I'd like to know more about this, as well as the accountability process and where I can report abusive behavior that will actually get addressed.

Work for a registry with many TLDs. Shut down is removing NS records from the TLD zone. And yes, you can generally report this type of thing to a registry of a TLD. We often act quicker than many registrars, in my experience(though it depends on a TLDs owner/policies...some are much better wrt malicious activity than others).

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#176
post #21

Earlier quoted context omitted.

It's a tradeoff. You have to balance that negative against the negative of having botnets of millions of never-patched routers. Automatic updates should be the default, but you should be able to shut them off if you want to make a different tradeoff.

Automatic security updates should be the default, all other updates should absolutely not . In case of patching routers there isn't much crapware to be upsold, but in general, if we're ever going to develop some code of ethics in this industry, I wish a part of it would be a rule of hard separation between security patches and feature updates, and another rule that the latter should never be done automatically withou…

Automatic updates has some of the same issues as telemetry. Windows Update for example has to send information on things like drivers to scan for updates.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#177
post #143

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…

Hey just because it may be a fair time until I next get a chance to ask someone who may have the answer - I've wondered a fair bit do you guys get a lot of spam at the abuse@ for domains or do spam bots know to not bother with them?

No reason to ask at all honesty, it's just been one of those curios that pops up in mind occasionally

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#178
post #177
post #143

Earlier quoted context omitted.

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…

Hey just because it may be a fair time until I next get a chance to ask someone who may have the answer - I've wondered a fair bit do you guys get a lot of spam at the abuse@ for domains or do spam bots know to not bother with them? No reason to ask at all honesty, it's just been one of those curios that pops up in mind occasionally

I work(ed) for a TLD registry, not a registrar, so our information isn't in WHOIS. As such, it gets little to no abuse. We do get email from the big names in security research/abuse tracking guys.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#179
post #154

Not sure what they mean by "mysterious". He isn't hiding and never was. He posted his photo, name and other personal details in articles about MikroTik on Russian IT blogging platform[1]. His name is Alexey Sopov, 34, from Novosibirsk. Quick search revealed his social network accounts: https://fb.com/100005153643926 https://vk.com/lmonoceros [1] https://habr.com/post/353530/

Clickbait?

Probably the journalist didn't want to get this guy in trouble for doxxing him.

I'm pretty sure the FBI would love to arrest him by now. Just like MalwareTech.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#180
post #172

Back in college (early 90's) I would run ToneLoc overnight, and wake up to view the results. One time I had a hit, and I ftp'ed into some server on Mindspring's customer IP range. A quick look at the system told me the root account had no password set. So I tried a telnet and wham - I was in. A 'who' showed someone else was logged in. So I sent a broadcast message to them saying they need to secure their system bette…

> He was nice, but I didn't reply.

Noooooo. Story started off well and then you tree fiddied me!

Post reply on HN