Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

191–200 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#191
post #20

Earlier quoted context omitted.

It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.

Actually I once heard a story of a neighbor who let themselves in when the house was literally flooding and he saved the owner thousands of dollars worth of damage. That's more like what's happening with these patched routers. I also heard a story of a guy who's house burned down. The neighbor saw it very early and did nothing about it cuz not her problem. The homeowner was devastated. So yes, if you see incredible d…

Also, how many times have you seen someone's fly undone and very quietly and unobtrusively informed them of the fact? You can get quite different reactions, everything from grateful thanks to "how dare you inform me that I am embarrassing myself" or just be ignored.

Different people will react differently to any help you may give them. In this case, one could possibly agree that getting these machines locked down so they longer present as a threat to others is the moral thing to do, irrespective of the legality of the action.

But that is a judgement call for the individual to make knowing that there are potential consequences for their actions.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#192

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

“I wanted to stay insecure dam it” - Them probably

Obligatory: https://xkcd.com/1172

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#193
post #61

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

How do they know that you can be trusted, and aren't just another spammer/phisher? You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

> How do they know that you can be trusted, and aren't just another spammer/phisher?

That's not it, not all of the time anyway.

Over the summer I discovered a third party mail server with a missing DNS entry. It was like that for months and all their mail was getting flagged as spam.

I sent them an email (from an account that wasn't flagging their mail as spam) pointing it out. They fixed it within 24 hours but I never got a single reply.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#194
post #76

Earlier quoted context omitted.

> I NEVER received a thank you from any of these people. Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability?

> Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability? I'm curious, for vulnerability-by-inaction like this, would there be a legal difference if sent emails were posted to a public blockchain? The intent being, if you're later sued for harm caused by your compromised hardware / IoT devices, you cannot claim ignorance as easily. End goal, of course,…

I doubt a court would make a distinction. The claimant (plaintiff) would have to prove the defendant knew about the emails being sent to the public blockchain and decided not to do anything about it.

That's not necessarily easy to prove, in the same way the defendant could claim emails were trapped in spam filters, etc. or more realistically, the burden of proof is on the claimant so the defendant wouldn't say anything if they're smart.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#195
post #143

Earlier quoted context omitted.

As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…

I'm currently dealing with this from jetigroup.?rg. The registry information is invalid, the contact emails I found for the guy who ran the company at one time bounce back, but a weak password on a mailman install let someone create a distribution list that allows every recipient to post. They broke the unsubscribe part of the script, so nobody can get off the list. Until I made a rule to kill all mail from the domai…

domainabuse@tucows.com, apac-domain.manager@endurance.com, ipadmin@websitewelcome.com, qkhldjwp@whoisprivacyprotect.com, ipadmin@publicdomainregistry.com, abuse@publicdomainregistry.com, cpanel@webhostbox.net

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#197

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

I do the same. Which reminds me -- when you get a 404 from utwente.nl you're redirected to a domain squatter / advertising site.

I can't be bothered to report it to them.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#198
post #90
post #59

Earlier quoted context omitted.

The solution should be to just stop using human generated passwords and instead have each site generate their own and for browsers and apps use password managers built into the OS and offer to fill them in based on the domain. This is increasingly happening. We need the large sites to move to this to eliminate phishing entirely. So https://f00l.com isn’t same as https://fool.com

I use Keepass and still manually paste and autosave my passwords. Have browsers extensions improved for this? When I last checked 5 and 10 years ago, it didn't seem to work.

Oh yes.

1Password X for Firefox and Chrome, 1Password on Safari have pretty much solved this problem. The vast majority of passwords I fill are CMD + [shortcut].

Generating and saving new ones works like that maybe 50% of the time. The failure rate however is driven less by the extension technology and more by the password form itself.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#199

Earlier quoted context omitted.

Vulnerabilities are almost unavoidable. Leaving a management port on a router open to the entire internet is a very bad practice. Would you leave an RDP port open to the world? If you require remote access, at least restrict it to known management IP addresses.

Why is it that vulnerabilities are almost unavoidable? I’m not trying to be a smart-ass; I’m an analyst at an MSP and I’m doing my first pen-test soon. I’m under no illusions that my job title or growing responsibilities make me a security expert (or anywhere near it). Is it because the software stack is just too complex for network programmers to handle? (Not that router OSes are the only pieces of software that hav…

There is a saying "If someone can make it, someone can break it"

This applies to physical security also.

There are way too many attack vectors for you to plug every possible hole.

20 years ago do you think anyone was considering that you could determine the contents of memory otherwise inaccessible your process just by reading the memory accessible to you in certain manners (Rowhammer, [1])

Or that a device taped under your desk could read your encryption keys right out of the air? [2][3]

Or that an attacker could intentionally cause errors by overclocking/undervolting "glitching" your device to cause it to skip certain instructions in order to gain access to it? [4][5][6]

Or that exploiting flaws in the way a CPU tries to predict the next instructions could lead to privileged information leakage? [7]

A sibling commenter hit the nail on the head. You have a large surface area to protect. They only need to find one tiny crack.

But by far the most common vulnerabilities are simply someone not properly validating input[8][9][10][1] https://en.wikipedia.org/wiki/Row_hammer

[2] https://www.theregister.co.uk/2015/06/20/tempest_radioshack/

[3] https://www.tau.ac.il/~tromer/radioexp/

[4] https://toothless.co/blog/bootloader-bypass-part1/

[5] https://av.tib.eu/media/32392

[6] https://www.multichannel.com/news/black-sunday-fix-dbs-pirat...

[7] https://www.wired.com/story/foreshadow-intel-secure-enclave-...

[8] https://www.pcworld.com/article/148007/security.html

[9] https://blog.detectify.com/2016/04/06/owasp-top-10-injection...

[10] https://codecurmudgeon.com/wp/sql-injection-hall-of-shame/

[11] https://engineering.purdue.edu/ResearchGroups/SmashGuard/BoF...

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#200

Earlier quoted context omitted.

How long ago was it that Mikrotik shipped devices that listened on the WAN port? The Mikrotik hEX and RB3011 I bought last year most assuredly was not configured that way even though the version of ROS on them was many revisions out of date.

I've purchased a rack-mounted RB2011 and wAP ac, more commonly known as RBwAPG-5HacT2HnD (lol these model names), within the last 3 years that did not have firewall enabled and contained no firewall rules by default. If I had to guess it was around ROS 6.32 or 6.33 release for 2011 and recently for the wAP.

6.32 came out in 2015. 2011 was the early 5.x days
Post reply on HN