Earlier quoted context omitted.
A factory reset, according to Cisco, will fix it. Correction: according to the original report a reset will mitigate the stage 2 and 3 attack only Source: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...
It's really too bad that nobody makes hardware with the obvious solution - put the firmware in ROM. Then it cannot be altered by malware. If the vendor really, really wants to update the firmware, have the write-enable switch be a physical one, not a software switch.
FBI tells router users to reboot now to kill malware infecting 500k devices
191–200 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#192Just calling out the good guys at Microtik. They patched their router a year before being notified by Cisco.
As a Mikrotik devote, I love the active development and patches being pushed for their Packages and RouterBoard. If anyone maintains a Mikrotik router and/or switches and hasn't heard about the vulnerability and actively patched their systems, then they're completely at fault and putting themselves and possibly they're companies at risk.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#193How can I verify some malicious code is actually present on my router? What does this code do? Could the FBI put their own malicious code on the router, via this supposed exploit? Why should I trust the FBI? Excuse my ignorance but I'm not not going to ask these types of questions. EDIT: After reading a bit - it seems the control is somehow "transferred" to the FBI rather than the malicious actor - any other external…
Explain how the FBI would leverage an advantage by telling you to reboot. Explain in a way, which doesn't depend on an unprovable. The best I can come up with is a false sense of security, which given they actually expect you to also patch and upgrade and proffer advice to patch and upgrade, is a bit weak. Basically, I cannot construct a scenario where there is a significant, could-not-be-found-by-white-hat reason th…
According to ArsTech in this article (https://arstechnica.com/information-technology/2018/05/hacke...) the VPNFilter exploit can survive a reboot - so how can a simple reboot disinfect if the only delta is the owner of [one of] the second stage callback IP addresses? I haven't seen any mechanics explained that would actually disinfect the router.
I appreciate your response with actual critical thinking tips and not just flippancy - I don't know where else to have these types of discussions.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#194How can I verify some malicious code is actually present on my router? What does this code do? Could the FBI put their own malicious code on the router, via this supposed exploit? Why should I trust the FBI? Excuse my ignorance but I'm not not going to ask these types of questions. EDIT: After reading a bit - it seems the control is somehow "transferred" to the FBI rather than the malicious actor - any other external…
>Why should I trust the FBI? Because this is their job. And you'll probably need to reboot your router anyway in the near future so why now do it now just in case? >Could the FBI put their own malicious code on the router, via this supposed exploit? Sure. So could space aliens.
Your second point is not clear to me. Space aliens aren't an extant authority on our planet (afaik)
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#195Earlier quoted context omitted.
If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.
Free software is generally delivered as is, without any guarantees. Router software is part of something you actually pay for, so there should be liability.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#196Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
Considering the nation state initiating this shit is barely being punished, it seems absolutely premature to even start down this avenue.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#197Earlier quoted context omitted.
> There shouldn't be liability for bugs; there should be liability for negligence. All bugs can be argued as being the result of negligence.
Mistakes are inevitable. Deciding to ship without any upgrade capability is a choice. A deliberate, negligent choice.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#198Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
Because then they'd all exit the router business. Nobody wants to expose themselves to unlimited liability.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#199How can I verify some malicious code is actually present on my router? What does this code do? Could the FBI put their own malicious code on the router, via this supposed exploit? Why should I trust the FBI? Excuse my ignorance but I'm not not going to ask these types of questions. EDIT: After reading a bit - it seems the control is somehow "transferred" to the FBI rather than the malicious actor - any other external…
So don't. No one is forcing you to reboot your router. No one who cares about this issue cares about your personal Jason Bourne fantasies.
Reboot. Don't reboot. For the rest of the world, your decision makes zero difference.
because skeptic
It's just like English. Close enough.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#200Earlier quoted context omitted.
If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.
> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…
Next time you get a prescription filled, ask yourself if you're willing to pay that much for a router.