Live data from Hacker News

A 100k Botnet Turns Home Routers to Email Spammers

blog.netlab.360.com

31–40 of 122 posts

Re: A 100k Botnet Turns Home Routers to Email Spammers

#31
It's interesting to me that "pwn" has entered the respectable lexicon. If I were to talk about "haxxors" or "warez" I don't think I would be taken very seriously on here. I guess it's because "pwn" occupies a meaning not fully encompassed by any other word. There is "root" which is itself a slang term but it's too specific, I suppose, and "compromised" is just too long,

Re: A 100k Botnet Turns Home Routers to Email Spammers

#32
post #26

Is there any easy way to check if your router is vulnerable/compromised? Or instructions for disinfecting it as well as patching it? Like, based on actually being exploitable or compromised, not firmware versions or whatever. I actually suspect mine is compromised, it's been behaving funny for a month or two, needing to be restarted a lot. (Which, ironically, is a signal of a _buggy_ compromise, your router of course…

If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…

Yeah, you can start by resetting the NVRAM of the router, (30-30-30 reset) then get a flash chip clip, read the data off the router flash using a raspberry pi, and compare it to the firmware binary from the router manufacturers website.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#33
post #25
post #22

What if someone did that, but to use the routers for some charitable distributed computing project? Or mining crypto currencies and giving the proceeds to the router's owners? Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free? Or a distributed P2P social network?

It's morally wrong. You don't suddenly have the right to use someone else's personal belongings as you see fit just because they left a door or window unlocked.

What if the router was being unused? What if the power usage was minimal? I think it is unethical not to utilize resources that are being wasted.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#34
post #26

Earlier quoted context omitted.

If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…

Yeah, you can start by resetting the NVRAM of the router, (30-30-30 reset) then get a flash chip clip, read the data off the router flash using a raspberry pi, and compare it to the firmware binary from the router manufacturers website.

[deleted]

Re: A 100k Botnet Turns Home Routers to Email Spammers

#35
post #28

And OpenWrt users everywhere feel totally superior once again. Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates. Load it with a Linux-distro you can update yourself to keep it rolling and secure.

I keep looking into it and keep stopping at 'what should I buy'. I'm willing to / assume I need to buy new hardware. What do I buy that will run it well, and continue to?

Buy the Archer C7 version 2, and install the optimized version of openwrt: https://github.com/infinitnet/lede-ar71xx-optimized-archer-c...

This build gets ~750 mbps NAT speed as opposed to vanilla openwrt, which is around ~300 mbps.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#36
They are currently talking about creating a cyber civilian corps that would be under the Department of Homeland Security. The purpose would be some yet to be defined “assisting businesses and state / local governments in crisis”.

However maybe we should have them knocking on doors having ppl set up their home network.

Obviously a lot of responsibility is being pushed back on companies to make this easier, but still we have all these old devices out there humming along.

https://www.newamerica.org/cybersecurity-initiative/reports/...

Re: A 100k Botnet Turns Home Routers to Email Spammers

#37
post #25

Earlier quoted context omitted.

It's morally wrong. You don't suddenly have the right to use someone else's personal belongings as you see fit just because they left a door or window unlocked.

What if the router was being unused? What if the power usage was minimal? I think it is unethical not to utilize resources that are being wasted.

I hope your parents taught you to ask before invading somebody's personal property.

Are you okay with XYZ Tech Company snooping on your private messages, emails, or credit card transactions? The impact that you'd see would be minimal (aside from more targeted ads, perhaps), and it's data which would otherwise be "wasted" if nobody was mining it.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#38
So, what is the most secured option for the moment? Buy a x86 box and turn it into a router? But it consumes more power than a low-power router, and buying more network adapter is not that cheap.

I am currently using the open source tomato firmware. However, since there is a bug/feature in the router so that I cannot flash an image too large, or otherwise it would not work. Also, the configuration is limited to 32 KB, if configure too much, then the configuration file will become gibberish and some random feature in the router would be missing, and required a factory reset to fix. So, I am stuck with an older version of tomato which guarantee some kind of vulnerability is not fixed.

Not sure what I can get in the form size of a router. Raspberry pi may work but too few ports available. I heard that the CPU would get hot for intense network traffic.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#39
post #6

How many home routers aren't compromised or have known vulnerabilities? It would interesting if a study looked at a random sample of the population of home routers to determine this. Go to people's homes and actually check. These articles always seem to look at it from the "how many compromised routers have we found so far" angle. I suspect that if the story was "90% of home routers have known unpatched vulnerabiliti…

> And if they don't act, regulate them out of existence. Sounds easy but doesn't work IRL. The service providers don't build the units and rely on the supplier. The supplier might have patched it but wants money, the ISP doesn't want to pay. Maybe the patch breaks something else and the ISP don't want to put that on all their users. Also, not all vulnerabilities are equal. Some are more serious than others and requir…

If an ISP can't push reliable updates to their hardware they shouldn't be in business.

Vulnerabilities should be prioritized of course. But I honestly don't mind when someone creates a worm that bricks crappy devices that isps know are vulnerable. It's a public service at that point.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#40

How many home routers aren't compromised or have known vulnerabilities? It would interesting if a study looked at a random sample of the population of home routers to determine this. Go to people's homes and actually check. These articles always seem to look at it from the "how many compromised routers have we found so far" angle. I suspect that if the story was "90% of home routers have known unpatched vulnerabiliti…

I think a solution that generalizes and has the possibility of actually working is for the result of compromised hardware to show up in the consumers' bill.

We expect to pay a low, fixed, monthly price for unlimited bandwidth, but what happens when someone else gets their hands on that bandwidth?

It's nice to hold manufacturers accountable for their woes, like shipping routers with "admin":"" creds, but what about all the other reasons devices get pwned, like users downloading malware or falling for those fake download-button ads or using something like Hola VPN that turns them into an open relay?

Some ISPs will give you a phone call or shut you down entirely if they probabilistically think your bandwidth is compromised, but that involves a lot of complexity.

If ISPs weren't racing to the bottom with the meaning of the word "unlimited", they could be honest about bandwidth prices and service levels instead of using a complicated throttling system to maintain the facade that bandwidth really is unlimited.

Also, there would be natural filtering pressure against, say, insecure IoT devices that end up impacting people's ISP bill.

Post reply on HN