Live data from Hacker News

A 100k Botnet Turns Home Routers to Email Spammers

blog.netlab.360.com

1–10 of 122 posts

Re: A 100k Botnet Turns Home Routers to Email Spammers

#5
How many home routers aren't compromised or have known vulnerabilities? It would interesting if a study looked at a random sample of the population of home routers to determine this. Go to people's homes and actually check. These articles always seem to look at it from the "how many compromised routers have we found so far" angle. I suspect that if the story was "90% of home routers have known unpatched vulnerabilities", these security issues would be taken more seriously by the companies responsible for them. And if they don't act, regulate them out of existence.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#6

How many home routers aren't compromised or have known vulnerabilities? It would interesting if a study looked at a random sample of the population of home routers to determine this. Go to people's homes and actually check. These articles always seem to look at it from the "how many compromised routers have we found so far" angle. I suspect that if the story was "90% of home routers have known unpatched vulnerabiliti…

> And if they don't act, regulate them out of existence.

Sounds easy but doesn't work IRL. The service providers don't build the units and rely on the supplier. The supplier might have patched it but wants money, the ISP doesn't want to pay. Maybe the patch breaks something else and the ISP don't want to put that on all their users.

Also, not all vulnerabilities are equal. Some are more serious than others and require patching urgently, others less so.

And not all ISPs can push a patch so how do you tell everyone to update and what happens when it doesn't work and 1M people are calling Customer Support?

Re: A 100k Botnet Turns Home Routers to Email Spammers

#7

A much better, more thorough analysis, complete with affected router model numbers, graphs, charts, and area affected map are at the source post: https://blog.netlab.360.com/bcmpupnp_hunter-a-100k-botnet-tu...

Came here to ask for this. Thank you very much.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#8
> Universal Plug-n-Play

And, like so many other attempts to "simplify" supposedly complex configuration, in addition to being a massive security hole to attackers, it's almost useless to the home users for whom it was meant because it only works under a very narrow, mostly undocumented set of assumptions and if any of those assumptions are invalid, it fails silently.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#9
post #6

How many home routers aren't compromised or have known vulnerabilities? It would interesting if a study looked at a random sample of the population of home routers to determine this. Go to people's homes and actually check. These articles always seem to look at it from the "how many compromised routers have we found so far" angle. I suspect that if the story was "90% of home routers have known unpatched vulnerabiliti…

> And if they don't act, regulate them out of existence. Sounds easy but doesn't work IRL. The service providers don't build the units and rely on the supplier. The supplier might have patched it but wants money, the ISP doesn't want to pay. Maybe the patch breaks something else and the ISP don't want to put that on all their users. Also, not all vulnerabilities are equal. Some are more serious than others and requir…

Comcast has functionality where they will email and/or text you if your connection has botnet or other nefarious activity on it and will disconnect you until it's resolved. Not a fan of them, but it's something they get right.

https://i.imgur.com/cYKXtII.png

Re: A 100k Botnet Turns Home Routers to Email Spammers

#10

> Universal Plug-n-Play And, like so many other attempts to "simplify" supposedly complex configuration, in addition to being a massive security hole to attackers, it's almost useless to the home users for whom it was meant because it only works under a very narrow, mostly undocumented set of assumptions and if any of those assumptions are invalid, it fails silently.

If I have UPnP disabled, am I safe?
Post reply on HN