Earlier quoted context omitted.
I doubt that most ISPs who can't be bothered to apply security updates are going to notice a 5 minute reboot. Split the difference - email the user that an update will apply on $date unless they do it first, or if they delay it (and don't let them delay it indefinitely).
You can already script something like this into RouterOS (Mikrotik's OS).
A mysterious grey-hat is patching people's outdated MikroTik routers
211–220 of 220 posts
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#212Earlier quoted context omitted.
I once got a really good phishing email pretending to be ebay. It included my full legal name and my ebay id. It was some BS threatening to sue me for nonpayment if I didn't paypal them money or some stupid shit like that. So I forwarded it to spoof@ebay.com with the message "reporting phishing email" or something. Somehow that report got "handled" by a clueless, non-technical, front line rep who thought I thought th…
I think you should have used abuse@ebay.com
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#213>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.
It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#214Earlier quoted context omitted.
I think you should have used abuse@ebay.com
No, eBay's website specifically says to forward phishing emails to spoof@ebay.com.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#215Earlier quoted context omitted.
domainabuse@tucows.com, apac-domain.manager@endurance.com, ipadmin@websitewelcome.com, qkhldjwp@whoisprivacyprotect.com, ipadmin@publicdomainregistry.com, abuse@publicdomainregistry.com, cpanel@webhostbox.net
Thanks. I've already emailed most of these, but will try the others.
Typically a registry will just fwd it on to the registrar. That said, registrars tend to take complaints from the registry more seriously imo.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#216Earlier quoted context omitted.
I get an email claiming that I have unread Linkedin messages. The email uses their Logos. But if I were to click any of the links in the email, it would send me to a php or html file that contains a Javascript redirect script. That script, if executed, then goes to the phishers actual page. Sometimes, there is an additional DNS redirect at the JS redirected page. For some reason, the JS redirect tries to hide the red…
The solution should be to just stop using human generated passwords and instead have each site generate their own and for browsers and apps use password managers built into the OS and offer to fill them in based on the domain. This is increasingly happening. We need the large sites to move to this to eliminate phishing entirely. So https://f00l.com isn’t same as https://fool.com
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#217Earlier quoted context omitted.
The solution should be to just stop using human generated passwords and instead have each site generate their own and for browsers and apps use password managers built into the OS and offer to fill them in based on the domain. This is increasingly happening. We need the large sites to move to this to eliminate phishing entirely. So https://f00l.com isn’t same as https://fool.com
All you've done there is move the attack target from the website to the users device. The obvious solution is to remove all users from the internet.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#218>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.
Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…
* their IT person I think was really just the person who was best with computers.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#219Earlier quoted context omitted.
But still, why would you upset? At the very least this guy has made you aware of a known security hole in your router. Sure, the timing maybe inconvenient, but at least you now know there is a problem you have to attend. Would you rather leave the hold open and be happy in your ignorance if the security problem in your network?
It is trivial to secure a system by powering it off and disconnecting it from the Internet. That also makes said system useless for getting work done. Many people do not care about security at all; they just care that it "works". If we want the world to be more secure, the best (but hardest) way to make that happen is to make it cheaper/easier/faster to be secure than to be open (for example, Let's Encrypt).
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#220Devices at vulnerable routerOS version and not already compromised would not be vulnerable if the firewall was enabled. It's that simple. Not great that these boxes used to ship in this default state and I can _understand_ a home user unfamiliar with what they're dealing with but what reason is there for deploying infrastructure this way at an ISP or hospital or whatever org?