A 100k Botnet Turns Home Routers to Email Spammers
blog.netlab.360.com
blog.netlab.360.com
Like, based on actually being exploitable or compromised, not firmware versions or whatever.
I actually suspect mine is compromised, it's been behaving funny for a month or two, needing to be restarted a lot. (Which, ironically, is a signal of a _buggy_ compromise, your router of course be compromised and you'd never know it if the malware was well-behaved enough to stay out of the way of your usual use).
I can (painfully) update the firmware... but I don't trust that the vendor's most recent firmware actually solves it. Nor do I trust that once compromised a firmware update is enough to eliminate the malware.
For such a widespread compromise... we could use more user-friendly (or even relatively techy but not a network engineer user-friendly) instructions for... what to do.
I guess the reality is that most (non-techy) users will, if they notice at all (due to malware that buggily causes things not to work well for intended uses, instead of staying out of the way), will just decide their equipment is "broken", throw it out and buy new stuff... that hopefully won't get compromised again. Which I guess works for the consumer network harder vendors.
I'd be confident that flashing your device with modern open source firmware would solve the problem, but if you're paranoid just recycle the device and get a new one. In any event, I don't see a solution for you that doesn't involve some homework.
I am an experienced SWE and this is not something I can do without setting aside a day or two to investigate all the tools and purchase an RPi.
Oh, you sold a piece of shit insecure WiFi lightbulb that's mining bitcoin, here's a fine for every penny you made.
However, routers may be an exception. Apparently the industry has basically no business motivation to keep consumer-grade networking hardware secure, at all. Irrelevant to their profits or reputation.
I'll consider it. When I bought my router I intentionally got one that can run OpenWRT, but never ended up installing it, cause, who's got time for that? But perhaps there isn't really an alternative, unless you want a bot-net-ed router. Which honestly, and with shame, I'd just ignore the botnet sending out spam to other people if I didn't think it was compromising the functionality (and security) of my router for me. Last thing I wanna do is spend time becoming a network engineer after a day of getting paid to write software, but i guess that's where we're at.
(Oh crap, I just realized it could be my DSL modem instead of or in addition to my (wired and wifi) router. I know even LESS about that thing. I think none of these consumer products, owned by people who know a lot less than me, are ever gonna be protected, if even I am intimidated by trying to figure it out).
OpenWRT is not a pain to use -- it's not all that different than the web GUI that ships with most routers.
They provide routers with DD-WRT or Tomato pre-installed. Yes, you should probably know how to update your router at some point in the future, but your starting point is probably much safer than depending on the poorly-tested and heavily-exploited factory firmware.
Some people unused to open source solutions sometimes have this idea that all software developed by enthusiasts by necessity is hard to use or require tinkering, but that's not a fair picture. When developers share your interests, that's when software gets usable. That interest might not always be UI, but sometimes it is.
OpenWRT (and friends!) is clearly much easier to use and delivers richers functionality than any of the software it replaces. If your router is listed as supported, go for it.
And, like so many other attempts to "simplify" supposedly complex configuration, in addition to being a massive security hole to attackers, it's almost useless to the home users for whom it was meant because it only works under a very narrow, mostly undocumented set of assumptions and if any of those assumptions are invalid, it fails silently.
You're implying that all routers are vulnerable?
Your router is either vulnerable to this exploit, or it's not. Afaict from the article, the exploit relies on a UPnP-enabled router; if UPnP isn't enabled, I don't believe your router is vulnerable.
The GP asked:
> If I have UPnP disabled, am I safe?
The answer is yes: If you can disable UPnP, your router will be safe from this particular exploit. Which is, I think, what he was asking.
Everyone should disable UPnP in their routers. It won't make your router "safe" from all exploits, but it will make it safe from this one, and you can do it now, immediately, without replacing hardware or firmware.
It's not clear what the solution is - update firmware? I am on the latest. Use OpenWRT (or whatever it's called these days)? Every time I look into it (I really want to!) I stop at the simple 'I want to do this, I will happily buy a new router, which one do I buy and know it works well and will continue to work well with updates?'
Worrying, if that's the case.
Extra info such as, the router you are using has not had any available firmware updates for 3 years and likely needs to be replaced.
It's obvious we are not going to get this info to most people from the IOT manufacturers.
This could be quite beneficial for those who hook up thier phones to different wifi networks as well - a pop up showing that their router / internet gateway model has been shown to be used in at least 100,000 other malware exploits, and should not be trusted like your cell connection -
It's time to start shaming and naming - the bad guys already know how to get this info, we need to make it easier for the end users to become aware.
A service that will email you when firmware is available for your equipment, or your equipment is listed on shodan, blackhathacksrus, or other places may be beneficial as well. Set it up to take serial numbers scanned with an app, and give notices on recalls and physical theft recovery.
We obviously need something, and possibly many things tp help with this.
I can't believe a certain router company a few years ago did not offer to send a rebate if I returned their no-longer-updated-hardware when I emailed them inquiring about a published exploit and lack of updates. I no longer use that brand or suggest it. They could of kept a customer and made things better, they did neither.
You could also change/ update your private firehose every day though that would require a bit more technical skill. You could basically do:
MYIP=`shodan myip`
shodan alert create home-network $MYIP
shodan stream --alerts=all
That would create an alert for your current IP and then subscribe to any events.This would quickly bypass any resources hackers have anyway, and could work closely with the governments IFF the hacking is purely ethical.
The amount of inefficiency due to these devices being freely available to the user should be a huge money-saver.
Seriously though: this is why you don’t let your device run unvetted firmware by vendors who don’t provide updates.
Load it with a Linux-distro you can update yourself to keep it rolling and secure.
Plus: good performance, a lot of flexibility, and a nice web interface (if one wants it).
OpenWrt has really been a good experience for me.
This build gets ~750 mbps NAT speed as opposed to vanilla openwrt, which is around ~300 mbps.
It is fair mentioning that this model is discontinued from TP-Link and you will probably have to buy it second hand. It also comes in at least 5 revisions, with various levels of support, making life a little bit more difficult for the average, uninformed buyer.
As a side note: I have a 350mbps symmetrical FTTH link and I've had no issues maxing this line with regular, official OpenWRT builds.
Unless you need significantly higher speeds and can prove that official builds can't do it, I see no reason to go with unofficial, unsupported builds.
As long as you have enough flash to install the modules, I can't see why this shouldn't work on any router.
That is, can I just buy from Amazon [0] with a fairly safe assumption that a new C7 is OK?
[0]: https://www.amazon.co.uk/TP-Link-AC1750-Dualband-Zertifizier...
Consult the openwrt table of hardware[1] for more details.
[1] https://openwrt.org/toh/tp-link/archer-c7-1750
Edit: eBay seems a lot better for this task - https://m.ebay.com/sch/i.html?_from=R40&_trksid=m4084.l1313&...
And it was flakey as f*ck. It rebooted itself roughly once a day, and would stop routing traffic to my fibre modem and need manually rebooted at least once a day.
The Openwrt support forums were... not helpful.
All this was such a shame, because the Openwrt feature set is so much capable than the stock firmware - I so wanted it to work, but had such a bad experience I haven't gone near it since and it will likely stay that way.
Throughout my time I've bought around 2 or 2 routers with the naive assumption "oh it will probably work out fine", and that's definitely not how it works. That has certainly left me with disappointment.
IME it pays off greatly to upfront research the specific model (and revision) and buy exactly that. Like in this case, the Archer C7 v2 (of which I've recently bought two).
It's running OpenWrt flawlessly and I would have zero issues recommending that particular model to anyone.
Strangely, the C7 I have now advertises itself as 'v2/v3'!
I can tell you what I did, which may or may not be helpful to you. I got Linksys WRT AC3200[0]. The "AC3200" bit refers to a type of wifi 802.11ac configuration that has a theoretical bandwidth of 600 Mbit/s using the 2.4Ghz radio (good for distance and passing through interior walls) and 2.6 Gbit/s on the 5Ghz wifi radio. This is not the fastest or fanciest of the 802.11ac configurations, but it's up there.
One note about the marketing of this device, the MU-MIMO feature that you may read about is not really a thing yet. I don't have any devices that support it, and it's possible I never will.
Disregarding the radios entirely, this device can easily push 1 Gbit/s over the the ethernet ports, and can easily exceed 800 Mbit/s using the up-and-coming Linux kernel based VPN WireGuard.
This device is supported by OpenWRT, but if you don't want to compile and build it yourself you need to get it from a helpful guy on the net who maintains community builds for this router[1] and related chipsets. Support is available through a community forum[2].
I'm quite pleased with this device and firmware setup. I like that it can interface with my switch to sort out VLAN tags, I like that I can run cutting edge VPN software like WireGuard on it, I like that it's reliable and I haven't hard to reboot it randomly to "fix" it.
[0]: https://www.amazon.com/gp/product/B01JOXW3YE
[1]: https://davidc502sis.dynamic-dns.net/releases/#3200acm
[2]: https://forum.openwrt.org/t/davidc502-wrt1200ac-wrt1900acx-w...
https://www.flashrouters.com/linksys-wrt1200ac-ddwrt-router
No need to install DD-WRT yourself, just pay a little extra and have it shipped to you pre-installed.
I am currently using the open source tomato firmware. However, since there is a bug/feature in the router so that I cannot flash an image too large, or otherwise it would not work. Also, the configuration is limited to 32 KB, if configure too much, then the configuration file will become gibberish and some random feature in the router would be missing, and required a factory reset to fix. So, I am stuck with an older version of tomato which guarantee some kind of vulnerability is not fixed.
Not sure what I can get in the form size of a router. Raspberry pi may work but too few ports available. I heard that the CPU would get hot for intense network traffic.
Drawback is they tend to be noisy, but if you have a basement/closet..
Or build a really small low power x86 system with a few Intel gigabit NICs in it and run open source VyOS.
ALIX boards are reasonably energy efficient. fli4l can run from read-only media. This is no panacea (see fileless malware) but at least you can be sure that after a reboot your system is clean. Security is a primary goal [3] of the fli4l project and they maintain a public Security Archive.
If you want to go the modern (better) route, enterprise equipment such as ubiquity or cisco with strict rules are likely your best bet. The budget option being a openwrt install with one of their recommended routers
If you want to go this route, used Intel NICs are cheap. I recently picked up a 4-port gigabit NIC (PCI-E) for £13.99. I'm running on a machine that would be on anyway, so the power usage is negligible.
Sounds easy but doesn't work IRL. The service providers don't build the units and rely on the supplier. The supplier might have patched it but wants money, the ISP doesn't want to pay. Maybe the patch breaks something else and the ISP don't want to put that on all their users.
Also, not all vulnerabilities are equal. Some are more serious than others and require patching urgently, others less so.
And not all ISPs can push a patch so how do you tell everyone to update and what happens when it doesn't work and 1M people are calling Customer Support?
Vulnerabilities should be prioritized of course. But I honestly don't mind when someone creates a worm that bricks crappy devices that isps know are vulnerable. It's a public service at that point.
When the main players of an industry demonstrate unwillingness to take it upon themselves to resolve problems that negatively affect society at large, something needs to be done for sure.
I am generally in favor of regulation, and it might be the answer in this case also. However, I worry that the regulations that would be introduced to fight router vulnerability might lead to a situation where router owners no longer have the possibility of flashing third-party firmwares such as DD-WRT.
In my opinion, being able to flash third-party firmwares is more important than a lot of people might realize.
Firstly, router makers necessarily target the market as a whole, and as such the factory firmwares found in consumer grade routers are generally lacking in advanced features that only a small portion of the market has a need/desire for.
Secondly, open source firmwares can more readily be audited for backdoors. Of course, backdoors could still exist in parts of the router hardware that are not controlled by the main firmware though...
Anyway, the reason I worry that regulation might threaten the possibility of running third-party firmware is two-fold:
1. The regulations might specify that bootloaders need to be locked down, etc.
2. Router makers might decide to lock down the routers even if the regulations don’t directly require it, in order to be able to prove that security demands are met.
3. Router makers might use regulation as an excuse to lock down routers even if there is no real reason to do so.
We expect to pay a low, fixed, monthly price for unlimited bandwidth, but what happens when someone else gets their hands on that bandwidth?
It's nice to hold manufacturers accountable for their woes, like shipping routers with "admin":"" creds, but what about all the other reasons devices get pwned, like users downloading malware or falling for those fake download-button ads or using something like Hola VPN that turns them into an open relay?
Some ISPs will give you a phone call or shut you down entirely if they probabilistically think your bandwidth is compromised, but that involves a lot of complexity.
If ISPs weren't racing to the bottom with the meaning of the word "unlimited", they could be honest about bandwidth prices and service levels instead of using a complicated throttling system to maintain the facade that bandwidth really is unlimited.
Also, there would be natural filtering pressure against, say, insecure IoT devices that end up impacting people's ISP bill.
I can’t think of any good reason they should be listening on an external interface, but maybe the port scanning is happening on the inside.
However maybe we should have them knocking on doors having ppl set up their home network.
Obviously a lot of responsibility is being pushed back on companies to make this easier, but still we have all these old devices out there humming along.
https://www.newamerica.org/cybersecurity-initiative/reports/...
Look up the Pinout for the flash chip, find the write-enable line, and put it on a switch to lock firmware updates.
This won’t protect you against non-persistent malware, but it will prevent malicious updates.
One could attach a bit of logic and an LED to this line to switch on when a flash is attempted. Then you know something bad is in the stream.
The LED logic should signal you when there's an update coming in OTA, and you can verify for yourself if there's a legitimate update (and possibly load it yourself).
Or mining crypto currencies and giving the proceeds to the router's owners?
Or perhaps a globally distributed weather prediction system that automatically detects network enabled weather stations and predicts weather everywhere for free?
Or a distributed P2P social network?
Even if it's a crime to do it without permission ;-)
You don't suddenly have the right to use someone else's personal belongings as you see fit just because they left a door or window unlocked.
Are you okay with XYZ Tech Company snooping on your private messages, emails, or credit card transactions? The impact that you'd see would be minimal (aside from more targeted ads, perhaps), and it's data which would otherwise be "wasted" if nobody was mining it.
Not to mention consent...
Sure, it's (probably) a good cause. It's still wrong.
https://blog.netlab.360.com/bcmpupnp_hunter-a-100k-botnet-tu...
Aside from that, it's very interesting and a good, quick read. Makes me sad that Apple got out of the router business.
But also, can we stop with “pwns” in a serious website? Almost makes me think the comment section would start with someone saying “First!”.