Live data from Hacker News

A mysterious grey-hat is patching people's outdated MikroTik routers

zdnet.com

61–70 of 220 posts

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#61

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

How do they know that you can be trusted, and aren't just another spammer/phisher?

You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#62
post #45

Is anyone really surprised by this in today's outrage culture where everyone is offended by everything?

You seem to be outraged about culture itself.

Not really i'm just trying to give some helpful criticism however I lost hope in humanity a long time ago...

I'm just watching it burn with popcorn in hand.

Maybe add some more fuel to the fire in the form of sarcasm that everyone doesn't even realise is sarcasm... sigh...

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#63

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Security issues are tricky. Often making people aware of an issue is indistinguishable from having caused the issue.

Why would you hack someone and then tell them you did it (without asking for ransom or something)? Of course the person telling you has good intentions.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#64
post #20

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.

I've never come home to an unexpected plumber, but did have a greyhat "fix" my stuff once, and wasn't outraged at all. It felt like an intrusion, but I was grateful.

In ~ 2002 I was off to college with my Linux workstation. IIRC, the vulnerability was in the CUPS web UI. Someone filled the volume with a giant /tmp/YOUR_SYSTEM_IS_INSECURE_UPDATE_NOW file, and shutdown the affected service.

It could have been much worse.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#65
post #57

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

> "I added firewall rules that blocked access to the router from outside the local network," Alexey said. This could very well be what's causing the outrage from operators... suddenly losing connection with your router that's in some data center 3 hours away - requiring a drive-over just to discover it's some dude adding rules to your production equipment would be upsetting. There's legitimate reasons for remote oper…

Also, of course, only allowing remote access from a controlled list of source IP addresses.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#66

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

Do you ever follow-up in an isolated, safe, environment to determine if the file still exists? Curious to see if there is any correlation to the "admins" and the hackers themselves.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#67
If only ISPs would start disconnecting negligent customers who continue to use exploited or vulnerable equipment. The incentives are not right. If they did, they’d risk losing a paying customer, if they don’t, nothing bad really happens to them. I hate suggesting regulations and fines but it’s the only thing end users and ISPs will respond to.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#68
post #61

Earlier quoted context omitted.

Every now and then, when I am bored, I reverse engineer some of my phishing emails (Linkedin message, Fedex parcel etc). Very often I find that the phisherperson has embedded a rogue document (often .php) in a legitimate server. Sometimes I send a polite email to the admins of these sites warning them about the injected file. I NEVER received a thank you from any of these people. I don't care - I am not doing it for…

How do they know that you can be trusted, and aren't just another spammer/phisher? You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").

I don't think you need to trust the sender of the email. If someone emails me and there is a link to mywebsite.com and I click and it looks like the Google login page, I am going to be super alarmed and take the necessary action. Maybe they are out to get me (they hacked my website and put malware there), but if it's my own website that gets me, that's on me.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#69
post #20

>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.

It’s an intrusion. Would you be outraged if you came home one day and there was a plumber fixing your sink? “Oh hi, don’t worry about me, just fixing your sink. Let myself in, hope you don’t mind” You didn’t even know your sink was leaky let alone called a plumber.

If your home had a ruptured pipe, that was spraying sewage all over the sidewalk, I think someone stepping onto your property, and turning the firehose of shit off would be behaving ethically.

Trespass to save people from themselves is one thing. Trespass to save the public is quite another.

Re: A mysterious grey-hat is patching people's outdated MikroTik routers

#70
post #55

Earlier quoted context omitted.

> I NEVER received a thank you from any of these people. Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability?

Or that your email is the actual attack they need to worry about.

> I'm a security researcher and I discovered that your server has been compromised. Click this legitimate link to learn more.
Post reply on HN