Live data from Hacker News

Found hooked up to my router

reddit.com

11–20 of 358 posts

Re: Found hooked up to my router

#11
post #6

Strangely, Reddit cut off comment on the topic, before the device was clearly identified.

Yeah, I have no idea how it could accomplish what is alleged. Just lots of very bad no good end of world comments. Have none of these people ever used public wifi?

It's clearly not good to have an unknown but presumptively malicious in some way, shape, or form computer on your home network. And I would be cautious about uploading the device's file system and strongly consider changing various passwords. But, yeah, it's not like the computer suddenly has root access to everything else on the network.

Re: Found hooked up to my router

#12
If I had to guess, it's providing VPN endpoint/relay services to scammers (CC fraud, etc) who need actual residential IPs to buy things from. Or to use to set up accounts/sockpuppet accounts for things like automated reddit vote manipulation.

It's obviously located "inside" the residential end user's router/NAT, on their wifi, so it'll have something like an openvpn or ipsec daemon on it that initiates a connection to an endpoint elsewhere on the internet, building a tunnel for the botnet operators to control it remotely. Or via tor to a tor hidden service somewhere, like many purely software trojan botnets for win32/win64, but in this case it will have the vpn or tor binaries running on its own dedicated raspberry-pi class device.

If you have a botnet of several thousand devices which can be made to look indistinguishable from legitimate "ordinary non technical user sitting at home on their comcast connection with their laptop or tablet", you can do all sorts of things. Relay http/https traffic for a click farm in Bangladesh where people are upvoting reddit comments en masse to promote a product, sockpuppet facebook account comments for political campaigns and pushing political agendas (russian internet research agency, anyone?), etc. The goal here is to make the traffic look like legit single end user residential internet traffic and not traffic that's coming from netblocks of major colocation/dedicated server/VPS/VM hosting companies, whose ARIN/RIPE/APNIC space is all documented as such.

There's fraud detection systems which will trigger if you're trying to buy something like amazon gift cards from a /20 netblock of an ISP in Bulgaria, but are less "suspicious" if your traffic and useragent, etc, are all coming from a Frontier, Centurylink, Comcast etc netblock in a major American city. Stuff like the maxmind geolocation data correlating closely with the billing zipcode/shipping zip code of what you're trying to buy with a stolen credit card, or other identify theft type scams.

If you're doing some variation on a massive vote manipulation service, there's also fraud/botnet detection systems which will trigger on large volumes of upvotes (or similar manipulation) all coming from the same geographical location and netblocks. Your traffic look more like legitimate end users if it is geographically distributed across many states and provinces, many english-speaking countries (AU, NZ, CA, UK, etc), and across many ISPs and several different common end user browser useragents (edge, chrome, firefox, etc). Imagine if you threw 500 darts at a map of the USA on a wall and distributed all your botnet devices randomly around the map, vs having 300 devices all on the same network in the Chicago metro area, for instance.

Re: Found hooked up to my router

#14
post #6

Strangely, Reddit cut off comment on the topic, before the device was clearly identified.

I think it's the subs moderators that cut off new posts. I think that's something they do quite frequently when something has been identified to a reasonable level.

Re: Found hooked up to my router

#15
post #13

Earlier quoted context omitted.

Yes, this one is malfunctioning.

or time for proper network security? port-security and disabling unused ports works great in these cases, especially if you are the sole user of the network.

I dunno. Locking down some things may make sense. But, for the most part, assuming that physical security for your wired home network is sufficient doesn't seem like an unreasonable assumption combined with standard practices for your systems.

Re: Found hooked up to my router

#16
post #13

Earlier quoted context omitted.

Yes, this one is malfunctioning.

or time for proper network security? port-security and disabling unused ports works great in these cases, especially if you are the sole user of the network.

Still, network security is extremely hard when the actor has physical access to your networking hardware. I currently live in a dorm situation and put each roommate on their own separate vlan on their own separate wireless gateway behind an f5 firewall running snort and I'd still be at risk if one of my roommates decided to put something between my gateway and the router.

Re: Found hooked up to my router

#17

If I had to guess, it's providing VPN endpoint/relay services to scammers (CC fraud, etc) who need actual residential IPs to buy things from. Or to use to set up accounts/sockpuppet accounts for things like automated reddit vote manipulation. It's obviously located "inside" the residential end user's router/NAT, on their wifi, so it'll have something like an openvpn or ipsec daemon on it that initiates a connection t…

There are companies out there that offer proxies from 'real' US resident IP addresses. I think these companies use tactics like this to be able to offer real residential IPs (and not IP ranges belonging to hosting companies)

This is the first one that came up on google - https://stormproxies.com/ - I'm not saying that specific company is in any way related to this device or tactic (it is just the first on google for 'residential address ip proxy', but I think it is companies similar to this that will pay people for access to their routers and sell that access.

Re: Found hooked up to my router

#18
post #13

Earlier quoted context omitted.

Yes, this one is malfunctioning.

or time for proper network security? port-security and disabling unused ports works great in these cases, especially if you are the sole user of the network.

Roommates have physical access to the network. Principles of security tell us you can't defend against that. Need to change the network.

Re: Found hooked up to my router

#20

If I had to guess, it's providing VPN endpoint/relay services to scammers (CC fraud, etc) who need actual residential IPs to buy things from. Or to use to set up accounts/sockpuppet accounts for things like automated reddit vote manipulation. It's obviously located "inside" the residential end user's router/NAT, on their wifi, so it'll have something like an openvpn or ipsec daemon on it that initiates a connection t…

There are companies out there that offer proxies from 'real' US resident IP addresses. I think these companies use tactics like this to be able to offer real residential IPs (and not IP ranges belonging to hosting companies) This is the first one that came up on google - https://stormproxies.com/ - I'm not saying that specific company is in any way related to this device or tactic (it is just the first on google for…

What I find noteworthy about that stormproxies website is that unlike any sort of legit ISP, there's no information on what company is actually behind it, phone number, mailing address/street address, etc. I bet if you played follow the money with its credit card payments the money goes to a bank account in Cyprus or something.

It's a slick html template and some marketing text masquerading in front of a service obviously sold to greyhat/blackhat end users.

(perspective: I work for a legit ISP that has real things that physically exist in many POPs at layer 1 in the OSI model).

Post reply on HN