Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

181–190 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#181
post #61

Earlier quoted context omitted.

How do they know that you can be trusted, and aren't just another spammer/phisher? You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

They wouldn't trust the sender they would assign a dev to inspect the referenced file, decision making would start at that point.

The dev got his $99 two years ago and had long since taken up other contracts.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#182

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

A few months ago I received a random confirmation of my order from one of those fast food ordering aggregator sites, based in a different country that I'd never used.

I logged in and reset the password to gibberish and emailed them to let them know what had happened, assuming user error (email was a firstlast@domain, so relatively easy to mess up I guess)

A couple of days later I received an email from the company asking for my photo ID. I politely said I wouldn't feel comfortable providing that and advised they get email confirmation from users.

I didn't hear back for a couple of weeks and thought nothing more of it. Then a notification that 'my' payment to a fast food place had bounced (or been charged back, it was hard to work out tbh). I figured I'd ignore it because extradition to the states over $36 seemed unlikely.

A few days later I get another mail from them replying to my earlier mail about email confirmation and not mentioning the charges. Never heard any more from them.

The whole thing was a bit odd, but I can't help but think letting them know early saved us all a whole bunch of hassle, and maybe they'll fix their registration flow.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#183
post #46

Earlier quoted context omitted.

Sidenote: how does phishing via LinkedIn work? Recruiter spam?

I get an email claiming that I have unread Linkedin messages. The email uses their Logos. But if I were to click any of the links in the email, it would send me to a php or html file that contains a Javascript redirect script. That script, if executed, then goes to the phishers actual page. Sometimes, there is an additional DNS redirect at the JS redirected page. For some reason, the JS redirect tries to hide the red…

I would be interested!

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#184

Earlier quoted context omitted.

As opposed to Microsoft ramming updates down your throat whether you like them or not, and whether they break things or not? The lock on your house door is 'opt-in'. If you don't lock it and someone steals something, is it the lock manufacturer's fault? The home builder's fault? Did they construct an insecure house? Ignorance of the proper operation of the lock is not an excuse not to lock it and doesn't shift the re…

The pervasiveness of insecure systems is not a justification for designing an insecure system.

Indeed. Quite the opposite. When working with multiple layers of systems that will eventually have vulnerabilities discovering, you must design your environment to remain secure regardless.

The chances of someone infiltrating a properly designed(and maintained) environment without detection are very slim.

Defense in depth.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#185

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

In the cases where the problem is fixed, I think you'll find that the explanation is as simple as this:

They view the message as showing up a failure on their part and they do not want anything showing that they have made a mistake in some way. So, they do not acknowledge your message as it provide a means of tracking that failure.

For those cases where it is not fixed, there is no-one who cares to do so.

In the past, I have made communications with website admins about various aspects of their sites (non-security related) when they poorly relate to those of us who are getting older and have increasing eyesight difficulties. The usual response has been "No one else has complained, so take a long jump off a short pier - our site is perfect." I sometimes try to explain that people won't continue to visit if the experience is bad, nor will they bother highlighting that there are problems. They will generally still respond with "shut-up and go away."

You just leave them to their ineffective site and move on. Very occasionally, you get back a thanks and see improvements made, but that is rare.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#186
post #116

Earlier quoted context omitted.

Typically when sending an email with content like that for a notification you'll "defang" the URL by rendering it like "hXXp:// foo (dot) bar (dot) com" or something along those lines to ensure that it isn't automatically flagged and filtered, though it's also common on the receiving end to apply no spam filters to their abuse@ email as well. You'll usually have better luck sending this information to the abuse email…

> you'll "defang" the URL Wow, that's a phrase I haven't heard in ages.

This is the business: https://en.wikipedia.org/wiki/MIMEDefang

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#187
This reminded me of last years "BrickerBot" malware [0] by grey-hat The Janit0r / The Doctor who bricked IoT devices with the stated purpose of preventing the same devices from being hacked by botnet-malware, which allegedly puts the whole internet at risk.

[0] https://www.bleepingcomputer.com/news/security/brickerbot-au...

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#188

This particular effort seems to be a mix of fun, braggadocio, and altruism. Could this sort of thing be organized with a social network and a list of tasks/problems using a tool like Trello or Jira but for solving any problem? The result would be anyone in the world could help/volunteer to fix real problems with free time. Use: 1) Problem is posted 2) Investigated and confirmed to be real 3) Volunteers start to fix a…

Archive Team does distributed grey-hat activities on volunteer-run computers all the time, but only for archival projects.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#189
post #143

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…

Can you shut down SMS? I recently have been bombarded with SMS from varying numbers, they all use the same $NAME

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#190
post #143

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…

I'm currently dealing with this from jetigroup.?rg. The registry information is invalid, the contact emails I found for the guy who ran the company at one time bounce back, but a weak password on a mailman install let someone create a distribution list that allows every recipient to post. They broke the unsubscribe part of the script, so nobody can get off the list. Until I made a rule to kill all mail from the domain, the flood of "remove me, I'm contacting the secretary of state" messages were simultaneously hilarious, annoying, and sad.
Post reply on HN