Worm going through unpatched Ubiquiti routers
community.ubnt.com
community.ubnt.com
To paraphrase: "It was working perfectly, so I didn't bother checking for security updates, for my over 3000 access points, for over a year. Oh yeah and of course I exposed the admin interface over public http instead of something secure."
I would very much disagree. I've been involved in the operation of several WISPS over the last 15 years and it's been my observation that they are typically run by people who do not understand basic networking and don't have the mindset to do things securely, and since they are small enough, they get away with it. And they make a ton of money doing it.
Lets say I start a WISP in a typical Florida retirement community with 500 residential units.
50% penetration (because they don't have a choice) at $75/month per customer = $18,000/month.
Get a 1GB Level3 fiber for $7000/month(it can be had cheaper). 8 to 1 oversubscribe rate gives you about 30mb/s per customer.
Tower: $5000 Routers: $2500 Customer installation (Labor and equipment): Passed on to customer(about $200 each) Antennas and radios for tower: $2000 Operating labor $3000/month ( 1 person full time to do troubleshooting and support)
So we have less than $10,000 build out, with up to $50,000 in customer equipment purchase. And $10,000/month in operating costs. 6 month ROI on the initial expense (Shorter if you can get all 250 hooked up in the frist month) then $96,000/yr in your pocket, minus Uncle Sam's cut of course.
You could do the installs for free with a 1yr contract and still have a sub 12-month ROI
What part of WISP is expensive?
The concept of a suburban area that isn't already wired for DSL and/or cable sounds surprising to me. AFAIK WISPs are mostly in low-density rural areas which multiplies costs. I do get the impression that many WISPs are something like a hobby crossed with community service and aren't run professionally.
But you are correct many WISPs are in primarily rural areas, but then the costs are reduced if your customer base is reduced also, and you have the benefit of things like water towers, silos, etc... to use, often you can just give the owner of such structure free service in exchange for the use of it.
The toughest area for a WISP is a heavily wooded rural area.
Anywhere the ground is flat and trees are low or spares is a WISP paradise.
This guy's blog[2] is usually fairly interesting, though I think he's drank a little too much of the Mimosa kool-aid.
[1] http://www.saddlebaglakeresort.net/ (disclaimer: I am not involved in any way with the WISP that covers that area.)
Maybe did some important things back in the day but for the past 10 years the situation has largely shifted from idealism to pragmatism.
Yes, there are a lot of WISPs that are run basically as a hobby. There are also a lot of WISPs (and more broadly xISPs) that do things professionally.
Puts my dads friend in a tough place -- he's afraid that he won't be able to sell his home with only satellite internet as an option.
Also remember that it's 2016, and phone companies (cough Verizon) have no interest in providing phone service anymore. I looked into getting a backup DSL connection -- the POTS equipment here is so decrepit that the most Verizon would offer was 1.5/0.5 DSL for $50. And I live in a city, about 2 miles from the the big regional Verizon CO.
I opted for a TMobile hotspot instead.
Luckily there is a very good WISP in the area that I currently have a 120mb/s connection from, but they do not like nor want do residential service. I was able to get my connection because of my relationship with the owners, but the rest of my neighborhood is not so lucky.
For areas such as dad's friend, check out the Connect America Fund[1] -- there are grants and funds available (after sufficient hoop-jumping of course) for lots of currently underserved areas. Getting a WISP to bite might be a challenge but could be worth investigating. Or start your own.
[1] https://www.fcc.gov/general/connect-america-fund-caf
Edit: added link oops
Source: I run a small WISP in my copious spare time and have been involved in the WISP online scene since it began.
The $3000/month isn't for someone with a deep and good understanding of network security -- that should be you (the one making the $96k piece) -- it's for someone that can answer the phone, help people set their routers to DHCP, etc... $17/hr isn't bad pay(at least around here) for someone with basic network knowledge.
Also many places the bandwidth is cheaper, some it's more expensive, but, being a WISP, you might be in a position to pipe your bandwidth from somewhere cheap to where you are.
If your bandwidth isn't cheap, then you provide 10mb/s service instead of 30. While not considered actual broadband, it's plenty for gaming, netflix, most general web usage.
(digression) There's a kind of WISP valley of death roughly between the hobby WISP (0-500 users) with a owner/operator and one or two employees, maybe running on business DOCSIS for upstream and Ubiquity and/or Mikrotik radios & routers and the professional carrier WISP (2-5k+ users) with biz people, experienced ops people, longhaul fiber or licensed microwave for backhaul, etc.
Small WISPs often can't afford the time or money to be proper (if they even have the experience to know what proper is) until they pass the valley of death. Many fall to bankruptcy or burnout trying to get past the valley.
I've had all sorts of problems with "normal" routers due to too many connections (too many devices on the LAN -- don't ask), I was never able to make full use of my 50/50 pipe.
I've recently been upgraded to 100/100 for free (and soon 300/100), and it's still running like a champ.
That being said, it was the first router that I wasn't able to configure just by clicking around.
But they're advancing greatly on the UX part with every firmware release, so it's actually friendly enough to recommend now.
http://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-Ed...
(During boot the router was working as pure ethernet switch - i.e. in a typical home deployment you would be wide open to the internet during this time.)
As far as I can tell, this was there for quite some time. In order to find the fix I had to find and read the user forums.
I also couldn't find either a security update email list or an automatic firmware update feature. I guess you're supposed to follow their forum if you care about security...
Given what we know now (and this isn't the first time UBNT has had issues), it would be a reasonable thing to ask vendors to ship products without insecure out-of-the-box configurations.
On the other hand, it makes me sad as an industry that it's certain doom if you don't follow that kind of advice. Why don't we have simple web servers that offer secure admin interfaces that can be plugged in for various products? It's not as if the user interface for a router's configuration is bleeding edge technology.
Agreed
>> It's not as if the user interface for a router's configuration is bleeding edge technology.
Not sure I agree. Have you seen some of these modern interfaces? They are doing deep packet inspection, providing many different visualizations of usage, geo-location, captive portal, ... the feature list - and attack surface - is huge.
LD_LIBRARY_PATH=/etc/persistent/.mf/ ./curl -s -m 4 -F "file=@/etc/$wh;filename=../../etc/$to" -H "Expect:" "$ur/login.cgi" -k 2>/dev/null >/dev/null
.. is used to upload files onto the target system, in particular a passwd file and some ssh keys. After this, it'll ssh in easily because of the passwd/keys and extract a copy itself from a .tar and worm on.
So does that mean that "login.cgi" can be tricked into writing uploaded http files into /etc without authentication? Rough.
IoT will be a slaughter.
The session is initiated from the client, but if you can MITM it or compromise the provisioning server all bets are obviously off.
I have mixed feelings about TR-069, but don't see how devices can stay current without something like it.
About TR-069, criminals don't do BGP hijacking to pop a few routers (yet?). Still, why the hell is that not encrypted. (I know why, it's just that I'm sad.)
See http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/ for one of my "favourites". I daren't push my $200 TP-Link too hard for fear of finding something like this.
Mistake #1. Never do this. If possible set it so that it's only accessible by the hard-wired ports, or if by radio at least only the local private subnet.