Live data from Hacker News

A 100k Botnet Turns Home Routers to Email Spammers

blog.netlab.360.com

11–20 of 122 posts

Re: A 100k Botnet Turns Home Routers to Email Spammers

#11
Is there any easy way to check if your router is vulnerable/compromised? Or instructions for disinfecting it as well as patching it?

Like, based on actually being exploitable or compromised, not firmware versions or whatever.

I actually suspect mine is compromised, it's been behaving funny for a month or two, needing to be restarted a lot. (Which, ironically, is a signal of a _buggy_ compromise, your router of course be compromised and you'd never know it if the malware was well-behaved enough to stay out of the way of your usual use).

I can (painfully) update the firmware... but I don't trust that the vendor's most recent firmware actually solves it. Nor do I trust that once compromised a firmware update is enough to eliminate the malware.

For such a widespread compromise... we could use more user-friendly (or even relatively techy but not a network engineer user-friendly) instructions for... what to do.

I guess the reality is that most (non-techy) users will, if they notice at all (due to malware that buggily causes things not to work well for intended uses, instead of staying out of the way), will just decide their equipment is "broken", throw it out and buy new stuff... that hopefully won't get compromised again. Which I guess works for the consumer network harder vendors.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#13

How many home routers aren't compromised or have known vulnerabilities? It would interesting if a study looked at a random sample of the population of home routers to determine this. Go to people's homes and actually check. These articles always seem to look at it from the "how many compromised routers have we found so far" angle. I suspect that if the story was "90% of home routers have known unpatched vulnerabiliti…

> regulate them out of existence

When the main players of an industry demonstrate unwillingness to take it upon themselves to resolve problems that negatively affect society at large, something needs to be done for sure.

I am generally in favor of regulation, and it might be the answer in this case also. However, I worry that the regulations that would be introduced to fight router vulnerability might lead to a situation where router owners no longer have the possibility of flashing third-party firmwares such as DD-WRT.

In my opinion, being able to flash third-party firmwares is more important than a lot of people might realize.

Firstly, router makers necessarily target the market as a whole, and as such the factory firmwares found in consumer grade routers are generally lacking in advanced features that only a small portion of the market has a need/desire for.

Secondly, open source firmwares can more readily be audited for backdoors. Of course, backdoors could still exist in parts of the router hardware that are not controlled by the main firmware though...

Anyway, the reason I worry that regulation might threaten the possibility of running third-party firmware is two-fold:

1. The regulations might specify that bootloaders need to be locked down, etc.

2. Router makers might decide to lock down the routers even if the regulations don’t directly require it, in order to be able to prove that security demands are met.

3. Router makers might use regulation as an excuse to lock down routers even if there is no real reason to do so.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#14

> Universal Plug-n-Play And, like so many other attempts to "simplify" supposedly complex configuration, in addition to being a massive security hole to attackers, it's almost useless to the home users for whom it was meant because it only works under a very narrow, mostly undocumented set of assumptions and if any of those assumptions are invalid, it fails silently.

If I have UPnP disabled, am I safe?

There's no way to be "safe". You might be safer if you disable UPnP, it certainly decreases the attack surface.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#15
And OpenWrt users everywhere feel totally superior once again.

Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates.

Load it with a Linux-distro you can update yourself to keep it rolling and secure.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#17

A much better, more thorough analysis, complete with affected router model numbers, graphs, charts, and area affected map are at the source post: https://blog.netlab.360.com/bcmpupnp_hunter-a-100k-botnet-tu...

Iceland and India are either the best or the worst places to be to avoid this exploit. The map doesn't have a scale, so it's hard to tell.

Aside from that, it's very interesting and a good, quick read. Makes me sad that Apple got out of the router business.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#18

How many home routers aren't compromised or have known vulnerabilities? It would interesting if a study looked at a random sample of the population of home routers to determine this. Go to people's homes and actually check. These articles always seem to look at it from the "how many compromised routers have we found so far" angle. I suspect that if the story was "90% of home routers have known unpatched vulnerabiliti…

> regulate them out of existence When the main players of an industry demonstrate unwillingness to take it upon themselves to resolve problems that negatively affect society at large, something needs to be done for sure. I am generally in favor of regulation, and it might be the answer in this case also. However, I worry that the regulations that would be introduced to fight router vulnerability might lead to a situa…

Perhaps the regulation should mandate support for third-party software, such as DD-WRT.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#19

And OpenWrt users everywhere feel totally superior once again. Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates. Load it with a Linux-distro you can update yourself to keep it rolling and secure.

Personally, I can no longer even conceive running the standard firmware on a critical piece of my home's infrastructure.

Plus: good performance, a lot of flexibility, and a nice web interface (if one wants it).

OpenWrt has really been a good experience for me.

Post reply on HN