Live data from Hacker News

A 100k Botnet Turns Home Routers to Email Spammers

blog.netlab.360.com

21–30 of 122 posts

Re: A 100k Botnet Turns Home Routers to Email Spammers

#21
I wish this botnet would delete the infected hosts facebook accounts. Like it asks fb for deletion, then hides the confirmation mail. After 30 days when the account is permanently deleted , it would erase itself from the host + patch the vulnerability.

I would've awarded the worm author the prize for contributing to the mental wellbeing of the society.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#22
What if someone did that, but to use the routers for some charitable distributed computing project?

Or mining crypto currencies and giving the proceeds to the router's owners?

Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free?

Or a distributed P2P social network?

Re: A 100k Botnet Turns Home Routers to Email Spammers

#23
post #22

What if someone did that, but to use the routers for some charitable distributed computing project? Or mining crypto currencies and giving the proceeds to the router's owners? Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free? Or a distributed P2P social network?

I like the outside the box thinking for positive, however the environmental impact of crypto makes the latter seem like a net negative, given the compute efficiency :/

Re: A 100k Botnet Turns Home Routers to Email Spammers

#24

A much better, more thorough analysis, complete with affected router model numbers, graphs, charts, and area affected map are at the source post: https://blog.netlab.360.com/bcmpupnp_hunter-a-100k-botnet-tu...

Is there any reason we can't replace the link on the front page with this one? It's clearly a much better article.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#25
post #22

What if someone did that, but to use the routers for some charitable distributed computing project? Or mining crypto currencies and giving the proceeds to the router's owners? Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free? Or a distributed P2P social network?

It's morally wrong.

You don't suddenly have the right to use someone else's personal belongings as you see fit just because they left a door or window unlocked.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#26

Is there any easy way to check if your router is vulnerable/compromised? Or instructions for disinfecting it as well as patching it? Like, based on actually being exploitable or compromised, not firmware versions or whatever. I actually suspect mine is compromised, it's been behaving funny for a month or two, needing to be restarted a lot. (Which, ironically, is a signal of a _buggy_ compromise, your router of course…

If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine.

I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the device and get a new one. In any event, I don't see a solution for you that doesn't involve some homework.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#27

> Universal Plug-n-Play And, like so many other attempts to "simplify" supposedly complex configuration, in addition to being a massive security hole to attackers, it's almost useless to the home users for whom it was meant because it only works under a very narrow, mostly undocumented set of assumptions and if any of those assumptions are invalid, it fails silently.

I disabled it after this post, but it appears Plex switches to 'indirect' mode (it goes out to the Internet and back in) without it; i.e. I am using UPnP.

It's not clear what the solution is - update firmware? I am on the latest. Use OpenWRT (or whatever it's called these days)? Every time I look into it (I really want to!) I stop at the simple 'I want to do this, I will happily buy a new router, which one do I buy and know it works well and will continue to work well with updates?'

Re: A 100k Botnet Turns Home Routers to Email Spammers

#28

And OpenWrt users everywhere feel totally superior once again. Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates. Load it with a Linux-distro you can update yourself to keep it rolling and secure.

I keep looking into it and keep stopping at 'what should I buy'. I'm willing to / assume I need to buy new hardware. What do I buy that will run it well, and continue to?

Re: A 100k Botnet Turns Home Routers to Email Spammers

#29

A much better, more thorough analysis, complete with affected router model numbers, graphs, charts, and area affected map are at the source post: https://blog.netlab.360.com/bcmpupnp_hunter-a-100k-botnet-tu...

We've changed the URL to that from https://nakedsecurity.sophos.com/2018/11/12/botnet-pwns-1000.... Thanks!

Re: A 100k Botnet Turns Home Routers to Email Spammers

#30
post #22

What if someone did that, but to use the routers for some charitable distributed computing project? Or mining crypto currencies and giving the proceeds to the router's owners? Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free? Or a distributed P2P social network?

Well, the increased power consumption of the hardware not entering sleep mode would be a non-marginal amount of power theft.

Not to mention consent...

Post reply on HN