Live data from Hacker News

How to exploit home routers for anonymity

danmcinerney.org

1–10 of 80 posts

Re: How to exploit home routers for anonymity

#2
So basically this Shodan service scans the web, indexing devices such as IP cameras and routers. You can then search their database by device type or model, and then try the default user/passwords on these devices and create a VPN account for your own use?

I wonder how many botnets use this technique instead of randomly scanning, whether it's their own implementation/database or using a service such as this. Also an interesting business model, "I've got the addresses of 10,000 XYZ routers, model 1234, for $50.00"

Re: How to exploit home routers for anonymity

#3
post #2

So basically this Shodan service scans the web, indexing devices such as IP cameras and routers. You can then search their database by device type or model, and then try the default user/passwords on these devices and create a VPN account for your own use? I wonder how many botnets use this technique instead of randomly scanning, whether it's their own implementation/database or using a service such as this. Also an…

Botnets typically just infect a site and do drive-by exploiting of the client. Then they don't need a proxy and they get to siphon user information. Proxies/VPNs are only useful for things like C&C servers.

Re: How to exploit home routers for anonymity

#7
The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2].

I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares containing sensible information. His closing remarks echo the sentiment of the article under discussion here: "I considered not posting this, but I suspect 'bad people' already know..,"[0]

What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety?

[0] http://blog.steve.org.uk/secure_your_rsync_shares__please_.h...

[1] A cleverly-built, fast network scanner, https://zmap.io/

[2] http://danmcinerney.org/how-to-exploit-home-routers-for-anon...

Re: How to exploit home routers for anonymity

#8
post #6

Ah. Great. Anonymity in the identity-theft way.

This is, incidentally, the reason why government-resistant anonymity services need to be legal. If you don't care about stealing credit card numbers or hurting people then you don't care about breaking into some poor sucker's router. But if you're blowing the whistle on some organizational malfeasance, you won't, so you need the likes of Tor.
Post reply on HN