Live data from Hacker News

A 100k Botnet Turns Home Routers to Email Spammers

blog.netlab.360.com

111–120 of 122 posts

Re: A 100k Botnet Turns Home Routers to Email Spammers

#111
post #88
post #74

Earlier quoted context omitted.

Is that v2 as in >v1, or is there a v3+ that I don't want? That is, can I just buy from Amazon [0] with a fairly safe assumption that a new C7 is OK? [0]: https://www.amazon.co.uk/TP-Link-AC1750-Dualband-Zertifizier...

So, 2 or 3 years ago I did just that. And it was flakey as f*ck. It rebooted itself roughly once a day, and would stop routing traffic to my fibre modem and need manually rebooted at least once a day. The Openwrt support forums were... not helpful. All this was such a shame, because the Openwrt feature set is so much capable than the stock firmware - I so wanted it to work, but had such a bad experience I haven't gon…

You have to be specific about the hardware you buy.

Throughout my time I've bought around 2 or 2 routers with the naive assumption "oh it will probably work out fine", and that's definitely not how it works. That has certainly left me with disappointment.

IME it pays off greatly to upfront research the specific model (and revision) and buy exactly that. Like in this case, the Archer C7 v2 (of which I've recently bought two).

It's running OpenWrt flawlessly and I would have zero issues recommending that particular model to anyone.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#112

Is there any easy way to check if your router is vulnerable/compromised? Or instructions for disinfecting it as well as patching it? Like, based on actually being exploitable or compromised, not firmware versions or whatever. I actually suspect mine is compromised, it's been behaving funny for a month or two, needing to be restarted a lot. (Which, ironically, is a signal of a _buggy_ compromise, your router of course…

Google your router model - see if it's Broadcom based. See if you're running the uPNP service. I wish this article gave out more info - I want to know what versions of the service are affected.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#113
post #88

Earlier quoted context omitted.

So, 2 or 3 years ago I did just that. And it was flakey as f*ck. It rebooted itself roughly once a day, and would stop routing traffic to my fibre modem and need manually rebooted at least once a day. The Openwrt support forums were... not helpful. All this was such a shame, because the Openwrt feature set is so much capable than the stock firmware - I so wanted it to work, but had such a bad experience I haven't gon…

You have to be specific about the hardware you buy. Throughout my time I've bought around 2 or 2 routers with the naive assumption "oh it will probably work out fine", and that's definitely not how it works. That has certainly left me with disappointment. IME it pays off greatly to upfront research the specific model (and revision) and buy exactly that. Like in this case, the Archer C7 v2 (of which I've recently boug…

Ah, I got confused - it's a stock TP-LINK AC1750 Archer C7 that I have now, and it was an older TP-LINK I'd tried OpenWrt on. I forget the model, but I had been specific about the hardware I bought, making sure it was in OpenWrt's list of supported devices.

Strangely, the C7 I have now advertises itself as 'v2/v3'!

Re: A 100k Botnet Turns Home Routers to Email Spammers

#114
post #26

Earlier quoted context omitted.

If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…

In general, I am cautious of running my own open source thing without being an expert in the relevant area (or interested in becoming one) -- having to put something together (and maintain it) yourself seldom, in my experience, ends up _more_ secure or _more_ maintainable, when you don't know what you're doing. However, routers may be an exception. Apparently the industry has basically no business motivation to keep…

You're going to have to upgrade your firmware anyway, so why not upgrade to something that actually cares about basic functionality?

Some people unused to open source solutions sometimes have this idea that all software developed by enthusiasts by necessity is hard to use or require tinkering, but that's not a fair picture. When developers share your interests, that's when software gets usable. That interest might not always be UI, but sometimes it is.

OpenWRT (and friends!) is clearly much easier to use and delivers richers functionality than any of the software it replaces. If your router is listed as supported, go for it.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#115

I think it's time for windows, and ios, and firewall / antivirus companies to scan for info about the routers used and alert people that their network is easily hacked, may already be hacked, and is in danger of being used by criminals to attack other countries and companies. Extra info such as, the router you are using has not had any available firmware updates for 3 years and likely needs to be replaced. It's obvio…

What about building an ethical hacking company that hacks these routers, closes the holes and then shows a warning to the user?

This would quickly bypass any resources hackers have anyway, and could work closely with the governments IFF the hacking is purely ethical.

The amount of inefficiency due to these devices being freely available to the user should be a huge money-saver.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#116

I think it's time for windows, and ios, and firewall / antivirus companies to scan for info about the routers used and alert people that their network is easily hacked, may already be hacked, and is in danger of being used by criminals to attack other countries and companies. Extra info such as, the router you are using has not had any available firmware updates for 3 years and likely needs to be replaced. It's obvio…

We actually offer such a monitoring service at Shodan, though it's largely aimed at companies so you need to use the API. Here's an article on how to setup a real-time monitor for your network: https://help.shodan.io/guides/how-to-monitor-network

How would this work for a consumer network which doesn't have a fixed public IP?

Re: A 100k Botnet Turns Home Routers to Email Spammers

#117
post #22

What if someone did that, but to use the routers for some charitable distributed computing project? Or mining crypto currencies and giving the proceeds to the router's owners? Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free? Or a distributed P2P social network?

I like the outside the box thinking for positive, however the environmental impact of crypto makes the latter seem like a net negative, given the compute efficiency :/

Sure, but if the increase in power usage is marginal enough, maybe it'd be worth it for the router owner and be useful for the community at large.

Even if it's a crime to do it without permission ;-)

Re: A 100k Botnet Turns Home Routers to Email Spammers

#118

Earlier quoted context omitted.

In general, I am cautious of running my own open source thing without being an expert in the relevant area (or interested in becoming one) -- having to put something together (and maintain it) yourself seldom, in my experience, ends up _more_ secure or _more_ maintainable, when you don't know what you're doing. However, routers may be an exception. Apparently the industry has basically no business motivation to keep…

You're going to have to upgrade your firmware anyway , so why not upgrade to something that actually cares about basic functionality? Some people unused to open source solutions sometimes have this idea that all software developed by enthusiasts by necessity is hard to use or require tinkering, but that's not a fair picture. When developers share your interests, that's when software gets usable. That interest might n…

The good reviews of OpenWRT help. The caution is mostly because it's unclear to me how hard it would be to switch it back. But yeah, probably will.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#119

Earlier quoted context omitted.

You're going to have to upgrade your firmware anyway , so why not upgrade to something that actually cares about basic functionality? Some people unused to open source solutions sometimes have this idea that all software developed by enthusiasts by necessity is hard to use or require tinkering, but that's not a fair picture. When developers share your interests, that's when software gets usable. That interest might n…

The good reviews of OpenWRT help. The caution is mostly because it's unclear to me how hard it would be to switch it back. But yeah, probably will.

Not to mention the idea that you might Bork your router during installation and have no internet therefore no way to install the old fw version.
Post reply on HN