Live data from Hacker News

A 100k Botnet Turns Home Routers to Email Spammers

blog.netlab.360.com

91–100 of 122 posts

Re: A 100k Botnet Turns Home Routers to Email Spammers

#91
post #85

Earlier quoted context omitted.

There's no way to be "safe". You might be safer if you disable UPnP, it certainly decreases the attack surface.

> There's no way to be "safe". You're implying that all routers are vulnerable?

I think the point is that any software system is vulnerable

Re: A 100k Botnet Turns Home Routers to Email Spammers

#92
I think it's time for windows, and ios, and firewall / antivirus companies to scan for info about the routers used and alert people that their network is easily hacked, may already be hacked, and is in danger of being used by criminals to attack other countries and companies.

Extra info such as, the router you are using has not had any available firmware updates for 3 years and likely needs to be replaced.

It's obvious we are not going to get this info to most people from the IOT manufacturers.

This could be quite beneficial for those who hook up thier phones to different wifi networks as well - a pop up showing that their router / internet gateway model has been shown to be used in at least 100,000 other malware exploits, and should not be trusted like your cell connection -

It's time to start shaming and naming - the bad guys already know how to get this info, we need to make it easier for the end users to become aware.

A service that will email you when firmware is available for your equipment, or your equipment is listed on shodan, blackhathacksrus, or other places may be beneficial as well. Set it up to take serial numbers scanned with an app, and give notices on recalls and physical theft recovery.

We obviously need something, and possibly many things tp help with this.

I can't believe a certain router company a few years ago did not offer to send a rebate if I returned their no-longer-updated-hardware when I emailed them inquiring about a published exploit and lack of updates. I no longer use that brand or suggest it. They could of kept a customer and made things better, they did neither.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#93

Earlier quoted context omitted.

Yeah, you can start by resetting the NVRAM of the router, (30-30-30 reset) then get a flash chip clip, read the data off the router flash using a raspberry pi, and compare it to the firmware binary from the router manufacturers website.

> user-friendly (or even relatively techy but not a network engineer user-friendly) instructions for... what to do. I am an experienced SWE and this is not something I can do without setting aside a day or two to investigate all the tools and purchase an RPi.

This is the reason IOT security should be enforced by law.

Oh, you sold a piece of shit insecure WiFi lightbulb that's mining bitcoin, here's a fine for every penny you made.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#94

It's interesting to me that "pwn" has entered the respectable lexicon. If I were to talk about "haxxors" or "warez" I don't think I would be taken very seriously on here. I guess it's because "pwn" occupies a meaning not fully encompassed by any other word. There is "root" which is itself a slang term but it's too specific, I suppose, and "compromised" is just too long,

I can say "pwn" is not something I would ever write in a serious document, but I'm also an old fart.

It depends on the age... usually for the board, we use 'compromised', because every one of those guys is scared of compromising pictures coming out (snorting milk powder off a friend's breasts for example)

Re: A 100k Botnet Turns Home Routers to Email Spammers

#95
post #85

Earlier quoted context omitted.

> There's no way to be "safe". You're implying that all routers are vulnerable?

I think the point is that any software system is vulnerable

Vulnerable to this particular exploit?

Your router is either vulnerable to this exploit, or it's not. Afaict from the article, the exploit relies on a UPnP-enabled router; if UPnP isn't enabled, I don't believe your router is vulnerable.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#96
post #26

Earlier quoted context omitted.

If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…

In general, I am cautious of running my own open source thing without being an expert in the relevant area (or interested in becoming one) -- having to put something together (and maintain it) yourself seldom, in my experience, ends up _more_ secure or _more_ maintainable, when you don't know what you're doing. However, routers may be an exception. Apparently the industry has basically no business motivation to keep…

It may not be as hard as you think. Doing a little homework, flashing the router with the OpenWRT firmware, and getting a basic config up and running should take most folks an afternoon. If you already understand concepts like CIDR addressing, DNS, DHCP, and NAT then it's an hour tops.

OpenWRT is not a pain to use -- it's not all that different than the web GUI that ships with most routers.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#97
post #26

Earlier quoted context omitted.

If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…

In general, I am cautious of running my own open source thing without being an expert in the relevant area (or interested in becoming one) -- having to put something together (and maintain it) yourself seldom, in my experience, ends up _more_ secure or _more_ maintainable, when you don't know what you're doing. However, routers may be an exception. Apparently the industry has basically no business motivation to keep…

Another option is to buy a pre-configured router from someone like FlashRouters.com (not affiliated, but a customer).

They provide routers with DD-WRT or Tomato pre-installed. Yes, you should probably know how to update your router at some point in the future, but your starting point is probably much safer than depending on the poorly-tested and heavily-exploited factory firmware.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#98

Earlier quoted context omitted.

the $48 ER-X is much faster than 99% of peoples' residential last mile broadband connections, it's good for up to about 750 Mbps of NAT and default route outbound to a gateway.

I have a gigabit fiber line with no PoE from the fiber box. Between the 2 I think the ERLite-3 should work better.

I have no problems with a gigabit symmetrical line on ERLite-3. UniFi Security Gateway is the same hardware but in a nicer interface that works with UniFi APs & Switches if you want to go that route but you have to also host a controller. You can also upgrade to a ER-4 for a much faster CPU but I don't think you need to.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#99
post #25
post #22

What if someone did that, but to use the routers for some charitable distributed computing project? Or mining crypto currencies and giving the proceeds to the router's owners? Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free? Or a distributed P2P social network?

It's morally wrong. You don't suddenly have the right to use someone else's personal belongings as you see fit just because they left a door or window unlocked.

This appeal to morality is useless. ok its wrong to you but doesn't mean it wrong to me.

Re: A 100k Botnet Turns Home Routers to Email Spammers

#100
post #28

And OpenWrt users everywhere feel totally superior once again. Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates. Load it with a Linux-distro you can update yourself to keep it rolling and secure.

I keep looking into it and keep stopping at 'what should I buy'. I'm willing to / assume I need to buy new hardware. What do I buy that will run it well, and continue to?

I'll try a recommendation:

https://www.flashrouters.com/linksys-wrt1200ac-ddwrt-router

No need to install DD-WRT yourself, just pay a little extra and have it shipped to you pre-installed.

Post reply on HN