Earlier quoted context omitted.
There's no way to be "safe". You might be safer if you disable UPnP, it certainly decreases the attack surface.
> There's no way to be "safe". You're implying that all routers are vulnerable?
A 100k Botnet Turns Home Routers to Email Spammers
91–100 of 122 posts
Re: A 100k Botnet Turns Home Routers to Email Spammers
#92Extra info such as, the router you are using has not had any available firmware updates for 3 years and likely needs to be replaced.
It's obvious we are not going to get this info to most people from the IOT manufacturers.
This could be quite beneficial for those who hook up thier phones to different wifi networks as well - a pop up showing that their router / internet gateway model has been shown to be used in at least 100,000 other malware exploits, and should not be trusted like your cell connection -
It's time to start shaming and naming - the bad guys already know how to get this info, we need to make it easier for the end users to become aware.
A service that will email you when firmware is available for your equipment, or your equipment is listed on shodan, blackhathacksrus, or other places may be beneficial as well. Set it up to take serial numbers scanned with an app, and give notices on recalls and physical theft recovery.
We obviously need something, and possibly many things tp help with this.
I can't believe a certain router company a few years ago did not offer to send a rebate if I returned their no-longer-updated-hardware when I emailed them inquiring about a published exploit and lack of updates. I no longer use that brand or suggest it. They could of kept a customer and made things better, they did neither.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#93Earlier quoted context omitted.
Yeah, you can start by resetting the NVRAM of the router, (30-30-30 reset) then get a flash chip clip, read the data off the router flash using a raspberry pi, and compare it to the firmware binary from the router manufacturers website.
> user-friendly (or even relatively techy but not a network engineer user-friendly) instructions for... what to do. I am an experienced SWE and this is not something I can do without setting aside a day or two to investigate all the tools and purchase an RPi.
Oh, you sold a piece of shit insecure WiFi lightbulb that's mining bitcoin, here's a fine for every penny you made.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#94It's interesting to me that "pwn" has entered the respectable lexicon. If I were to talk about "haxxors" or "warez" I don't think I would be taken very seriously on here. I guess it's because "pwn" occupies a meaning not fully encompassed by any other word. There is "root" which is itself a slang term but it's too specific, I suppose, and "compromised" is just too long,
I can say "pwn" is not something I would ever write in a serious document, but I'm also an old fart.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#95Earlier quoted context omitted.
> There's no way to be "safe". You're implying that all routers are vulnerable?
I think the point is that any software system is vulnerable
Your router is either vulnerable to this exploit, or it's not. Afaict from the article, the exploit relies on a UPnP-enabled router; if UPnP isn't enabled, I don't believe your router is vulnerable.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#96Earlier quoted context omitted.
If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…
In general, I am cautious of running my own open source thing without being an expert in the relevant area (or interested in becoming one) -- having to put something together (and maintain it) yourself seldom, in my experience, ends up _more_ secure or _more_ maintainable, when you don't know what you're doing. However, routers may be an exception. Apparently the industry has basically no business motivation to keep…
OpenWRT is not a pain to use -- it's not all that different than the web GUI that ships with most routers.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#97Earlier quoted context omitted.
If I were you I'd check to see if your router can run one of the several open source firmware packages like OpenWRT, dd-wrt, or Tomato. In my personal experience the OpenWRT/lede team is on top of security issues, and the router web interface and tooling is completely fine. I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the devi…
In general, I am cautious of running my own open source thing without being an expert in the relevant area (or interested in becoming one) -- having to put something together (and maintain it) yourself seldom, in my experience, ends up _more_ secure or _more_ maintainable, when you don't know what you're doing. However, routers may be an exception. Apparently the industry has basically no business motivation to keep…
They provide routers with DD-WRT or Tomato pre-installed. Yes, you should probably know how to update your router at some point in the future, but your starting point is probably much safer than depending on the poorly-tested and heavily-exploited factory firmware.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#98Earlier quoted context omitted.
the $48 ER-X is much faster than 99% of peoples' residential last mile broadband connections, it's good for up to about 750 Mbps of NAT and default route outbound to a gateway.
I have a gigabit fiber line with no PoE from the fiber box. Between the 2 I think the ERLite-3 should work better.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#99What if someone did that, but to use the routers for some charitable distributed computing project? Or mining crypto currencies and giving the proceeds to the router's owners? Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free? Or a distributed P2P social network?
It's morally wrong. You don't suddenly have the right to use someone else's personal belongings as you see fit just because they left a door or window unlocked.
Re: A 100k Botnet Turns Home Routers to Email Spammers
#100And OpenWrt users everywhere feel totally superior once again. Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates. Load it with a Linux-distro you can update yourself to keep it rolling and secure.
I keep looking into it and keep stopping at 'what should I buy'. I'm willing to / assume I need to buy new hardware. What do I buy that will run it well, and continue to?
https://www.flashrouters.com/linksys-wrt1200ac-ddwrt-router
No need to install DD-WRT yourself, just pay a little extra and have it shipped to you pre-installed.