Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

211–220 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#211
post #162

Earlier quoted context omitted.

I doubt that most ISPs who can't be bothered to apply security updates are going to notice a 5 minute reboot. Split the difference - email the user that an update will apply on $date unless they do it first, or if they delay it (and don't let them delay it indefinitely).

You can already script something like this into RouterOS (Mikrotik's OS).

Good - they should make it the default!

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#212
post #126

Earlier quoted context omitted.

I once got a really good phishing email pretending to be ebay. It included my full legal name and my ebay id. It was some BS threatening to sue me for nonpayment if I didn't paypal them money or some stupid shit like that. So I forwarded it to spoof@ebay.com with the message "reporting phishing email" or something. Somehow that report got "handled" by a clueless, non-technical, front line rep who thought I thought th…

I think you should have used abuse@ebay.com

No, eBay's website specifically says to forward phishing emails to spoof@ebay.com.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#213
post #20

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.

If your house has a gas leak, in the UK the local gas distribution network has the right to enter your property to stop the leak because it may well cause damage, injury or even death.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#214
post #212

Earlier quoted context omitted.

I think you should have used abuse@ebay.com

No, eBay's website specifically says to forward phishing emails to spoof@ebay.com.

You're right: https://www.ebay.com/help/account/protecting-account/recogni... Thanks for the information.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#215

Earlier quoted context omitted.

domainabuse@tucows.com, apac-domain.manager@endurance.com, ipadmin@websitewelcome.com, qkhldjwp@whoisprivacyprotect.com, ipadmin@publicdomainregistry.com, abuse@publicdomainregistry.com, cpanel@webhostbox.net

Thanks. I've already emailed most of these, but will try the others.

try abuse@pir.org, also.

Typically a registry will just fwd it on to the registrar. That said, registrars tend to take complaints from the registry more seriously imo.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#216
post #59

Earlier quoted context omitted.

I get an email claiming that I have unread Linkedin messages. The email uses their Logos. But if I were to click any of the links in the email, it would send me to a php or html file that contains a Javascript redirect script. That script, if executed, then goes to the phishers actual page. Sometimes, there is an additional DNS redirect at the JS redirected page. For some reason, the JS redirect tries to hide the red…

The solution should be to just stop using human generated passwords and instead have each site generate their own and for browsers and apps use password managers built into the OS and offer to fill them in based on the domain. This is increasingly happening. We need the large sites to move to this to eliminate phishing entirely. So https://f00l.com isn’t same as https://fool.com

Yes, that's exactly how U2F works (it's scoped to domain/origin). FIDO2 builds on top of that.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#217
post #59

Earlier quoted context omitted.

The solution should be to just stop using human generated passwords and instead have each site generate their own and for browsers and apps use password managers built into the OS and offer to fill them in based on the domain. This is increasingly happening. We need the large sites to move to this to eliminate phishing entirely. So https://f00l.com isn’t same as https://fool.com

All you've done there is move the attack target from the website to the users device. The obvious solution is to remove all users from the internet.

Is this a joke?

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#218

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

I was once repeatedly getting phishing emails from a small fire company a few states away. It seemed that one individuals email there had been comprised. I called the fire company and asked to speak with him. He was super embarrassed and thanked me. Their IT person* there apparently didn’t know how to fix the issue, so I suggested a few possible solutions and we parted ways. I didn’t get any more emails from his address so maybe it worked ?

* their IT person I think was really just the person who was best with computers.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#219
post #125

Earlier quoted context omitted.

But still, why would you upset? At the very least this guy has made you aware of a known security hole in your router. Sure, the timing maybe inconvenient, but at least you now know there is a problem you have to attend. Would you rather leave the hold open and be happy in your ignorance if the security problem in your network?

It is trivial to secure a system by powering it off and disconnecting it from the Internet. That also makes said system useless for getting work done. Many people do not care about security at all; they just care that it "works". If we want the world to be more secure, the best (but hardest) way to make that happen is to make it cheaper/easier/faster to be secure than to be open (for example, Let's Encrypt).

yes, you can also dump toxic waste into the river, and that "works" just as well, but it makes you a bad citizen. of course, most people don't care about that, so it takes other people to force them to stop dumping.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#220

Devices at vulnerable routerOS version and not already compromised would not be vulnerable if the firewall was enabled. It's that simple. Not great that these boxes used to ship in this default state and I can _understand_ a home user unfamiliar with what they're dealing with but what reason is there for deploying infrastructure this way at an ISP or hospital or whatever org?

according to Mikrotik, the firewall is off by default, but the web interface also listens LAN only by default. this is a more secure configuration because it prevents people going "hurr durr firewall breaking muh videos" (in part because of shitty video games telling everybody to turn off their firewalls and antiviruses) and creating the security problems.
Post reply on HN