Live data from Hacker News

A 100k Botnet Turns Home Routers to Email Spammers

blog.netlab.360.com

41–50 of 122 posts

Re: A 100k Botnet Turns Home Routers to Email Spammers

#41
post #38

So, what is the most secured option for the moment? Buy a x86 box and turn it into a router? But it consumes more power than a low-power router, and buying more network adapter is not that cheap. I am currently using the open source tomato firmware. However, since there is a bug/feature in the router so that I cannot flash an image too large, or otherwise it would not work. Also, the configuration is limited to 32 KB…

Find a not too old Cisco integrated services router, set it up to drop everything coming from outside, and run DHCP network(s) on the inside. Use WiFi routers in bridge/access point mode.

Drawback is they tend to be noisy, but if you have a basement/closet..

Re: A 100k Botnet Turns Home Routers to Email Spammers

#42
post #38

So, what is the most secured option for the moment? Buy a x86 box and turn it into a router? But it consumes more power than a low-power router, and buying more network adapter is not that cheap. I am currently using the open source tomato firmware. However, since there is a bug/feature in the router so that I cannot flash an image too large, or otherwise it would not work. Also, the configuration is limited to 32 KB…

You only need two network adapters, other devices could be connected by a switch.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#43
post #28

And OpenWrt users everywhere feel totally superior once again. Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates. Load it with a Linux-distro you can update yourself to keep it rolling and secure.

I keep looking into it and keep stopping at 'what should I buy'. I'm willing to / assume I need to buy new hardware. What do I buy that will run it well, and continue to?

This will depend on what kind of Internet connection you have, or expect to have in the future. Gigabit internet connections are becoming more common here in the US, and some lower powered devices just can't route packets faster than say 100-200 Mbit/s.

I can tell you what I did, which may or may not be helpful to you. I got Linksys WRT AC3200[0]. The "AC3200" bit refers to a type of wifi 802.11ac configuration that has a theoretical bandwidth of 600 Mbit/s using the 2.4Ghz radio (good for distance and passing through interior walls) and 2.6 Gbit/s on the 5Ghz wifi radio. This is not the fastest or fanciest of the 802.11ac configurations, but it's up there.

One note about the marketing of this device, the MU-MIMO feature that you may read about is not really a thing yet. I don't have any devices that support it, and it's possible I never will.

Disregarding the radios entirely, this device can easily push 1 Gbit/s over the the ethernet ports, and can easily exceed 800 Mbit/s using the up-and-coming Linux kernel based VPN WireGuard.

This device is supported by OpenWRT, but if you don't want to compile and build it yourself you need to get it from a helpful guy on the net who maintains community builds for this router[1] and related chipsets. Support is available through a community forum[2].

I'm quite pleased with this device and firmware setup. I like that it can interface with my switch to sort out VLAN tags, I like that I can run cutting edge VPN software like WireGuard on it, I like that it's reliable and I haven't hard to reboot it randomly to "fix" it.

[0]: https://www.amazon.com/gp/product/B01JOXW3YE

[1]: https://davidc502sis.dynamic-dns.net/releases/#3200acm

[2]: https://forum.openwrt.org/t/davidc502-wrt1200ac-wrt1900acx-w...

Re: A 100k Botnet Turns Home Routers to Email Spammers

#45
post #38

So, what is the most secured option for the moment? Buy a x86 box and turn it into a router? But it consumes more power than a low-power router, and buying more network adapter is not that cheap. I am currently using the open source tomato firmware. However, since there is a bug/feature in the router so that I cannot flash an image too large, or otherwise it would not work. Also, the configuration is limited to 32 KB…

For something really small the ubiquiti edgerouter devices which run their EdgeOS are a good choice. If there's a serious security vulnerability on the WAN-facing interface it will be patched. They run a fork of Vyatta. Ubiquiti employs most of the old Vyatta development team, who did not go to Brocade when Vyatta was acquired.

Or build a really small low power x86 system with a few Intel gigabit NICs in it and run open source VyOS.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#46

It's interesting to me that "pwn" has entered the respectable lexicon. If I were to talk about "haxxors" or "warez" I don't think I would be taken very seriously on here. I guess it's because "pwn" occupies a meaning not fully encompassed by any other word. There is "root" which is itself a slang term but it's too specific, I suppose, and "compromised" is just too long,

I imagine that most lingo dialects have a subset of terms which export more easily. A concise hacker community-originating term for compromise seems like a prime candidate.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#47
Reminds me I haven’t updated my pfSense router in awhile. Nor have I ever heard about a flaw like this for them as it were.

But also, can we stop with “pwns” in a serious website? Almost makes me think the comment section would start with someone saying “First!”.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#48

A much better, more thorough analysis, complete with affected router model numbers, graphs, charts, and area affected map are at the source post: https://blog.netlab.360.com/bcmpupnp_hunter-a-100k-botnet-tu...

I think you just killed the site. I get a 504 error.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#49
post #26

Earlier quoted context omitted.

If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…

Yeah, you can start by resetting the NVRAM of the router, (30-30-30 reset) then get a flash chip clip, read the data off the router flash using a raspberry pi, and compare it to the firmware binary from the router manufacturers website.

> user-friendly (or even relatively techy but not a network engineer user-friendly) instructions for... what to do.

I am an experienced SWE and this is not something I can do without setting aside a day or two to investigate all the tools and purchase an RPi.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#50

It's interesting to me that "pwn" has entered the respectable lexicon. If I were to talk about "haxxors" or "warez" I don't think I would be taken very seriously on here. I guess it's because "pwn" occupies a meaning not fully encompassed by any other word. There is "root" which is itself a slang term but it's too specific, I suppose, and "compromised" is just too long,

I can say "pwn" is not something I would ever write in a serious document, but I'm also an old fart.
Post reply on HN