What happened with ASUS routers this morning?
downtowndougbrown.com
downtowndougbrown.com
If you are using one of the routers that has true VLAN support like the AX86U Pro, there are anecdotal reports of people getting it to work but it's hacks and workarounds.
https://www.snbforums.com/threads/ax86u-pro-vlan.83996/
VLAN support in the AX86U (not Pro) would be a win. But it looks very hacky.
https://www.reddit.com/r/HomeNetworking/comments/l47ocn/secu...
seeing weird IP addesses pinging my router from the outside is normal, but when i see something _inside_ my network trying to get _out_, that's when I know it's time to start reformatting
So far, no issues, and it has the ability to let me ssh in, and install third party untilites via n opkg-style interface.
My error was a complaint about a lack of disk space in the logs, fwiw. RT-AX92U.
I have d-link mesh satellites, and needed 4 around the house just so I didn't have any blindspots. To show how bad they are, when my laptop is within a metre of the d-link main satellite, I get the full 150Mbs of my upstream, but 2 metres away but with line of sight, it drops to ~130Mbs. Leave the room, and it's about 90Mbs :(
I was hoping something like Ubiquiti would be something like the full upstream speed without the horrible dropout-per-metre I'm getting right now. Happy to get a few of them in mesh (if that's how they work) if I can get full speed from my office which is curretly 4 hops away.
https://store.ui.com/products/u6-lr-us this single long range one should cover most of your home (depending on walls etc). and if it's not enough, just get another one from this list: https://www.ui.com/wi-fi#compare
of course, if you can't/won't use ethernet cables for your APs, you can try this mesh: https://store.ui.com/products/access-point-wifi-6-mesh
as a reference, a single long range AP covered a 7 bedroom house (wood), with just a couple of minor blind spots. but for a double wall brick house we needed 3x U6 lite.
Oh. I actually didn't know this. Damn.
> power-over-ethernet
I used to use PoE and was getting great speeds everywhere in the house, but then I got solar panels and an inverter. Turns out, that a lot of people ended up having the same issues as me on whirlpool.net.au :(
But yeah, I've also considered getting an electrician in and wiring some rooms with CAT-6 and go wireless AP in that room. But sounds like it's still going to be the same as mesh doing this and halving my speed?
Awesome! Thank you for the links. I'll check them out!
as long as there is an ethernet cable from your switch/router to the AP, then speed will not halve. speed halves only when using mesh.
> Awesome! Thank you for the links. I'll check them out!
no problem. i started out my career in networking, and have always kept a soft spot for it even thou i'm doing software these days.
the minimum you need is:
- 1x Dream Machine (Pro or SE doesn't matter)
- 1x Access Point (could be long range, could be lite, depends on your needs)
you plug in the internet and the AP into the Dream Machine and that's about it.
from this barebones setup you can add further hardware depending your needs. for example I've added a PoE switch and another smaller non-poe switch (that funnily enough is powered by the other PoE switch).
Edit: to be honest, I'm actually excited to try this out now. I've been on bad wireless for at least 4 years
Mesh networks can use Ethernet as backhaul and they can also use dedicated radios on 6GHz for backhaul. I’m using a mix of both (still have a couple I need to run Ethernet to) and it’s fantastic.
I wouldn’t recommend wireless backhaul to people who have bad experience with WiFi. Some people have bad WiFi because their (older?) buildings have problems with wireless in general: I am not saying they live in a faraday cage but still their if their WiFi isn’t great, wireless backhaul won’t be either. Go wired if you have a choice.
Thus, in older houses, WiFi signal may not be great, and brick walls will make wiring the house an absolute pain.
I have seen some people dropping wire outside of the house, which is not great either (surges can and will happen).
For sure, that's why I mentioned that I'm still in the process of switching over to pure ethernet for backhaul.
That said, if you have enough nodes, 6GHz for backhaul works pretty nice right now. My home has concrete block exterior walls with some interior concrete and plaster walls and the nodes that use dedicated 6GHz for backhaul are doing just fine as is.
I would never consider 5GHz for backhaul, though.
It can be used on the same coax as is used for your cable modem, though if you can isolate the coax you want to use as an ethernet link, you might have better results.
I've used the competing standard DECA in the past, as it was significantly cheaper than MOCA about 5-8yrs ago ($25/unit vs $150/unit) but MOCA is now the much better option with it supporting GB speeds and pricing being down around ~$50/unit. I think the max speeds I saw over DECA was about 100Mbps, maybe 200Mbps on shorter runs.
Mesh dropping bandwidth is less of an issue these days as we have much more bandwidth and you are unlikely to run the largest channel width anyway, then newer solutions support mu-mimo with separate backhaul.
This is only true for single band networks. You can use one band as backhaul, another for AP, and still get ~300Mbps.
> of course, if you can't/won't use ethernet cables for your APs, you can try this mesh
All of the latest UniFi APs support meshing. Ubiquiti is not great at naming their products, apparently.
Also, I would advise against the LR. It does output more power and has a larger antenna than the lite, but there is little to it for indoors use, compared to the Pro, which I believe is cheaper and definitely is speedier.
good one, this is true, i was mistaken.
Agreed it's best to connect the access points with Ethernet.
802.11r accelerates the multi step handshake that you have to perform with WPA enterprise when you roam from one access point to another. There is a much shorter handshake for WPA personal so there is no advantage to enabling 802.11r if you’re not using Enterprise auth.
For WPA3-SAE and WPA3-OWE it is required as each client has a different (session) key.
I see you got recommended Ubiquity. That is good. Better than consumer grade shit.
*Downvoted for telling the truth about how shit WiFi is, classic HN. You are mostly programmers lol. "WiFi works lule" For some Netflix sure.
I think this plus laying cable should last me another 10-20 years
It supports poe, wifi ax (but only on 5 GHz), wpa 3 and can broadcast 4 separate networks, each on its own vlan (but it doesn't do any routing). It's been great for random iot junk that I don't want on my main network.
Routing is handled by an old HP elitedesk I've saved from the bin at work.
This programmer's task for the weekend is to buy a couple of cheap second-hand Ethernet switches, by the way, as part of an on-going effort to switch to networking infrastructure that doesn't compete with at least 13 of my neighbours. (-:
… which is about the most bandwidth intensive application most households ever use.
If you can’t get CAT6 where you need it, I have found MOCA to Ethernet adapters work well. Something like this. https://a.co/d/6FYGrga
If COAX is not available, I have also had a good experience with Powerline to Ethernet adapters. https://a.co/d/ddGHPOG
Take the face plate off your phone jack and if you see a wire with four pairs of wires inside, only two connected to the jack, you may be in luck. I had rented a few townhomes which were like that, enabling me to build out a simple wired network without modifying or drilling at all.
Below are the complete contents of the file:
DISTRIB_ID='LEDE'
DISTRIB_RELEASE='17.01.6'
DISTRIB_REVISION='r3979-2252731af4'
DISTRIB_CODENAME='reboot'
DISTRIB_TARGET='ar71xx/ubnt'
DISTRIB_ARCH='mips_24kc'
DISTRIB_DESCRIPTION='LEDE Reboot 17.01.6 r3979-2252731af4'
DISTRIB_TAINTS='no-all mklibs busybox'
Edited: Added newlines for file content. I originally posted this from mobile in a hurry. Copy/pasting from the ssh session on my phone resulted in newlines being lost.
By separating the router from the Wi-Fi access point, even if you only use one AP, you’re able to put the AP in the best place for full coverage. I hired an electrician to run the cable for me when I bought a house about 10 years ago- he charged a reasonable price, cut a minimum number of holes in the wall, and I was left with a cable in the center ceiling of the house which gave me excellent service throughout with a ceiling mounted AP.
Since then I’ve added on to the house and run additional wires to more ceiling mounted APs to get consistent 5ghz only access throughout the house. Rock solid and never have to think about it (although it is always tempting to tweak)
Now I'm running a Turris Omnia with the bundled OpenWRT fork for router tasks and that seems to work fine.
GPON does.
It’s pretty stable but frustrations remain. Their Edge series are more powerful but the UI is painful and much must be done via the CLI. The Unifi line doesn’t support such things. For example, on an edge router it was fairly easy to make a rule saying “any port 53 traffic that isn’t coming from the Pihole, redirect back to the Pihole”.
The Dream Machine Pro isn’t 100% stable and occasionally requires the config to be reloaded. It’s support for more modern VPN types has been slow to materialise.
The UDMP has been vastly superior to my crappy IDP supplier routers.
> APU router is the most open-source network device you can buy. It comes with open-source BIOS, open-source operating system of your choice and open hardware schematics. It's not locked down in any way.
I bought mine with opnsense pre-installed and it has been absolutely rock solid. For wi-fi, I've just used an old router with wifi in "ap-mode" connected to my APU router -- interestingly it turns out that the throughput bandwidth for wi-fi increased by orders of magnitude as soon as the poor Asus box didn't have to perform any logic on the packets passing through.
[1]: https://teklager.se/en/products/routers/apu4d4-open-source-r... -- I have no affiliation with the company, just a happy customer.
We have Rukus unleashed (AP) + PfSense at one of my hotel
But I prefer Aruba Instant on APs. Most easist and simple.
However, it was kind of a bear to get all setup. In terms of setup difficulty it goes Mikrotik -> EdgeRouter - any consumer focused router. I've been putting off setting up VLANs for about a year and a half because I just know I'm going to break everything.
It is certainly a step up from "plug in and it works" consumer routers/APs but the setup has gotten much easier since the early days.
Recommended. And if you check you can even find some of their hardware can run OpenWRT so you have that as a backup.
I have had an Asus for years and use the vendor firmware, and update it semi-regularly when I remember to, and have never had an issue.
I bought an Asus because they have decent capabilities out-of-box, but also because there is the option of using third-party firmware (which I've never bothered to do).
Even with this event I'll probably stick with the OEM firmware.
You're looking at your phone on a day to day basis. Using your desktop. The router/switch/lightbulb/etc? All stuff that sits in the background and gets forgotten. Those things should do self maintenance - especially with zero days and issues that require updates to not be pwned the instant you connect to the www.
But realistically, it's definitely better for the "masses" to have stuff that just takes care of itself. Grandma don't know how to update router firmware and people like that are why stuff like Apple's "appliance" model is better than Androids more hands on approach.
I do prefer Android for streaming devices, there’s just too much value added from using Android there. But I use an iPhone because I just want my phone to work. And I limit my desktop computer count to exactly one. For networking, I use Asus Merlin. I don’t use it for its flexibility or features, just for the stability which this recent news confirmed was a good idea. The only special features I even use are an OpenVPN server, and secure DNS over TLS to cover my devices that don’t support DNS over HTTPS.
(add.: and I don't mean "different kinds of people" in a condescending way, but that we value different aspects and have different methods for going about these things)
Depends a lot on the use case, though.
Yes, because I can plan for it. I can do it on a weekend or a local holiday. I can do it in the evening after work, or in the morning so that I have the whole day to go out and buy a replacement. If it's not critical, it can wait until my vacation.
And even without any risk of bricking, it should still be done on my schedule. I don't want the connection to glitch while I'm in the middle of a live stream, or an online multiplayer game, or a call with a distant relative.
Normal case: You lose some features / quality of life / stability improvements for a day / week / month (whenever you get around to updating it).
Best case is that you aren't in general population of bricked routers like everyone else today.
Worst case scenario is that you're late to a zero-day exploit. Although, the tech news cycle tends to report those stories pretty well, so you'd be aware of it.
The pros definitely outweight the cons in my opinion, especially on something critical like my internet access.
So against the one time you win by manually updating, you are weighing hundreds of times you had to research before clicking ‘update’ to see if there were any reports of this update bricking routers?
Because if you don’t do that, you just click the update button whenever you get round to it, you are running your router in a ‘vulnerable to zero days’ configuration, AND you’re going to brick your router the one time they ship an update that goes bad.
That's great for people who are into opsec as a hobby. But with the proverbial Aunt Millie I want auto-updates so they're patched.
Asus allows the option of having auto-updates enabled or disabled (forget which is the default).
Hardware and software companies have a story of implementing anti-user features in very shady ways (ie silent update to T&C allowing the org to track and share data with third parties and/or brokers).
I don't care if my smart Philips light bulb shares all its data with god knows who. My router? that's the device that manages all connections including critical ones. I want it to be impeccable and transparent. That's why I refuse to buy from manufactures that require a could account like Eeroo or that require weird connections to work properly like Tenda (a friend had a Tenda mesh and it wouldn't work if we blocked connections to Baidu, Weibo and others)
I have auto-updates disabled.
What in Earthly existence does not break eventually?
It's about dealing with the odds and rates of breakage.
Years ago I bought a $100 gigabit Linksys router, immediately flashed it with openwrt, and set it up. I assumed my isp was the reason my download speeds were struggling to hit 100mbps (new house and network all at once), and later when I bought my first NAS I assumed hdds are just inherently slow.
I had abysmal network performance for over a year before I figured out my gigabit router was the performance bottleneck, my isp was giving me 3x what the router could handle. The reason for the terrible performance was that openwrt doesn't have the closed source binary blobs to run hardware accelerated routing, instead everything gets squeezed through the cpu, and my router couldn't do it.
So basically, many routers lose performance, in my case I got a 10x performance drop, and openwrts website is all but useless for telling you which routers to buy.
All I can say is be careful blindly installing openwrt unless your router has a CPU that's complete overkill for what you want to do...and none of the mid range consumer combined routers/access points meet that criteria.
/edit I might be getting mixed up with netgear!
- Traffic prioritization (real-time, prioritized, background), and access profiles (per-device data budget, filters, max online time).
- Per device statistics on max data rate, current throughput, Wi-Fi standard, encryption, signal properties (e.g. MU-MIMO or not), etc.
- Special LAN port for guests, without access to the rest of the network (good for that ad filled smart TV).
- Extra LED with customizable function (can light up if there's anybody in the guest network, or a device plugged in the USB, or data cap is exceeded, etc).
- Energy consumption graphs for each major component (CPU, Wi-Fi, USB devices, etc).
- More information about my DSL cable than I know what to do, including spectrum graphs, line attenuation, latency, and even approximate line length.
- Security diagnostics with provider info, firmware status, login credentials type, open ports, egress filters, Wi-Fi security, etc.
- Also has features for smarthome, telephony, NAS, and media center, but I've never tried those.
I've read about routers disabling 5GHz when they detect RADAR, because 5GHz can interfere with that use, and RADAR has higher priority. Here's an article on this, official from the manufacturer and for your specific model (another point for them in my book):
https://avm.de/service/wissensdatenbank/dok/FRITZ-Box-7530-A...
I wanted to say there used to be Freetz which was neat but they ensured this wouldn't work anymore. But I learned it is continued in form of Freetz-NG!
My ISP (Freedom Internet) allows me to rent a modem for 2 EUR per month. A steal.
it kept adjusting the settings I had configured after some period of time
e.g. set up a hole for SSH. I then tested it to ensure that it worked
then a few days later, trying to use it for real... finding out the device had decided to change the DNAT target ip
I replaced it with a mikrotik box that cost 1/6th as much and has functioned perfectly ever since
OpenWRT is fine but I've found that if you're shopping around for devices it's hard to find ones that will do 1gbps with traffic shaping enabled for an affordable price.
Modern routing appliances are like a vcr/tv combo. You will have a better time if you split the functionality apart. It allows you to change/upgrade pieces of your network infrastructure more easily.
1. Use the ext4 image and extend the main partition to the full size of the disk. This requires a lot of "fiddling" later in case of upgrade (as parent wrote).
2. Use the combined squashfs image and don't touch the image layout (no resizing, keep the ~100 MB free default / partition). Easy upgrade experience like other embedded devices (get image, open ui or ssh, upload, flash, reboot, done). Oddly, this isn't made clear by the official Wiki at all and the simplest option.
IMO, the best configuration is running your x86 box with Proxmox and run the squashfs OpenWrt in a VM. There is no need for more than 100 MB of space and if you need to install so many packages or apps, better create another VM and use a standard Linux distro. It will also be more standard for many apps to be installed on a full fledged OS instead of the custom OpenWrt layout.
You only need 2vcpu and 256 MB of ram to run standard OpenWrt at 1 Gbps (SQM included if you have a recent CPU). The rest of your box ressource can be used for anything you want.
Can you elaborate? I wasn't a fan, but it's an option compared to pfSense CE.
I basically don't care about "features," but I wanted the latest WIFI standards because of reception issues in my house, and at least 4 wired ethernet ports. (I don't want to have to buy dongles / extenders for wired ethernet ports.)
It was surprisingly hard to find an OpenWRT router that supports the latest WIFI features, so I just went with a proprietary router.
In the presence of a collision, the Intel cards are able to successfully receive the stronger signal of the two as long as there's enough of a difference in signal strength.
The cards with Realtek chipsets on the other hand, are only able to receive the stronger of the two frames if the stronger frame started being transmitted first.
It's as if Intel's receiver is always looking for frame preambles even when a valid preamble has been heard and the radio is in the middle of receiving a frame. The other receivers stop looking for preambles while in the middle of receiving a frame.
If you live in an urban environment and have wifi problems, you'll likely have an observable improvement if you upgrade.
I don't know how well Qualcomm and Broadcom chipsets perform, but I wouldn't be surprised if at least Qualcomm works as well as Intel.
1. Reboot the router via pulling and reconnecting the power cord
2. Log in to WWW interface
3. Go to Administration > System. Enable SSH (enable login/password as well, choose a port of your taste)
4. SSH to your router: ssh admin@192.168.50.1 -p 2424 (assuming your user name is admin, the IP is 192.168.50.1 and you chose port 2424 for ssh). Password is the same as for the web UI
5. In SSH session, type: rm /jffs/asd/chknvram20230516
6. In SSH session, type: reboot
Seems to have done the trick for me.
With the recent ASUS motherboard over voltage, emergency BIOS update, warranty void if update used then reverse that threat.... the insanity of it all. Many people are saying that.
The Net Gear one that I have done as well.
Set up and forget.
I understand the frustration, but after some initial anger, people will eventually get there.
The router is a brick now, the worst that can happen is that it’ll be a brick after.
I wonder how many TB of "family isn't watching television; advertise funeral homes to relatives and travel insurance packages to primary user" it has sent home in that time.
I'd be interesting to know what percentage of internet routers are plugged in and forgotten on a disused internet connection at any given time. I'd guess ~ 1%, and that the percentage will increase as wireless broadband gets more popular.
My last router was an Asus. It was the best one I'd ever had, not counting an old 25MHz 386 that booted Linux off a floppy disk. The new one (PC Engines + OpenBSD) is better, though, starting two days ago, something keeps kicking my Mac off my unifi wifi networks (full WiFi signal, no connection, all other devices work, and the mac can talk to the starlink WiFi).
The latest version available is 3.0.0.4.386.49693 from 2022/07/21.
Source: https://www.asus.com/pl/networking-iot-servers/whole-home-me...
inquiring minds want to know...how long did that boot take?
It is trivially easy to blow right past the size capping on systems that use the old "newsyslog" style of external logfile rotation from the 20th century, and something that is logging a short string "[chknvram_action] Invalid string" over and over very fast is exactly how to do this.
For those interested in investigation, therefore, I would suggest looking at logfile sizes, and seeing whether it was logs eating all of the free space on /jffs and /var .
The underlying cause would be whatever is logging "[chknvram_action] Invalid string" thousands of times over, but the mechanism would be log files filling the tmpfs that the article mentions, which would explain why the system had no memory for forking new processes.
My wild speculation about "[chknvram_action] Invalid string" is that something somewhere in whatever "chknvram" is, the name being suggestive of something checking non-volatile RAM, has either bad data or a broken parser, and the recovery semantics are to retry immediately, incessantly, as fast as possible.
Dec 2 01:09:41 hostname syslogd: last message repeated 10 times
The threshold's pretty low and most of the "repeated" messages say "repeated 1 times" however. [2023-05-18 07:12:21] [E] Invalid event 0x1AF2 received from ...
[2023-05-18 09:44:01] [I] Last message repeated 10 times
I care less about how many times the message was repeated - I care about timestamps, which I might want to correlate to other activities.In any new-ish production system I'd probably want to use anything other than syslogd anyways.
https://github.com/freebsd/freebsd-src/blob/main/usr.sbin/sy...
If I'm dealing with equipment failures, bugs in third-party software, or other such random tech bullshit, as an individual or a team, then I don't know in advance when and what precision I'll need.
Sometimes those data points don't matter - like if they're generated by some program stuck in an infinite loop. But in other cases, they do - like e.g. if each message is caused by some event, like another program doing some processing, or user pressing a key, etc. - then timestamps will be useful to identify the exact cause (e.g. logs only happen when process X is processing mouse input, or when user presses one of 20 specific keys on their keyboard, or only when my microwave oven is running).
…by default, but it can be disabled:
-c Disable the compression of repeated instances of the same line
into a single line of the form "last message repeated N times"
when the output is a pipe to another program. If specified
twice, disable this compression in all cases.
* https://man.freebsd.org/cgi/man.cgi?query=syslogd* https://www.snbforums.com/threads/what-is-asd-process.76242/...
So some somewhat more informed speculation is that the new signature file either yesterday or today either broke a parser or was itself corrupt. The error-handling path for this is still poor.
I guess Asus quickly discovered their mistake and removed the faulty file from their servers, but affected devices never got to the point where they'd look for a newer file but just choked on the local one.
Why does a router need malware signature files? It has no business monitoring my traffic, except in accordance with the firewall rules that I set myself.
From the article:
> not keeping my firmware up to date
I've had this (non-Asus) router for three years. I've never updated the firmware.
Botnet operators are very grateful for your cooperation, you are helping them a lot
It's probably not 95%, but it's certainly significant. And yes, most consumer routers are obviously accessible from the internet, that's how they work (they're generally not behind a firewall, they are a firewall, and can have vulnerabilities). You might want to read up on it [1, key quotes below], and I know I certainly wouldn't be willing to wager my consumer router wasn't infected, because how would I ever have any idea?
> Out of the box, most routers suck when it comes to security. Vulnerable firmware is an easy target. Backdoors have been discovered in just about every brand of router... It's possible you will never even know your device is infected...
> When we're talking about routers, these aren't the enterprise-level gear made by the likes of Cisco, Sonicwall, or Palo Alto... We're talking about what you would get off the shelf at Wal-Mart or Best Buy — the D-Links, Netgears, and Linksyses of the world.
> The problems start with the cheap, antiquated MIPS architecture used by a lot of these devices' processors... One substantial problem comes from a security flaw that goes back to 2001. Per one deep yet fascinating paper, the chips lack basic defensive abilities against malicious code execution. Combine this with manufactures commonly implementing out-of-date, vulnerable Linux kernels in their devices, and then putting this device on the edge of your network completely exposed to the internet.
But to sum up -- not updating your router's firmware is a terrible idea. It's not something to be proud of.
[1] https://www.cbtnuggets.com/blog/certifications/security/your...
Most of these routers are likely becoming part of the botnet for enabling external web management and/or using default creds (especially if SSH is exposed externally).
Security isn't exceptionally hard, if you actually put some effort into it.
Many of the big manufacturers have been tackling that issue by forcing a password change at setup and not allowing an insecure default to be chosen.
Why is the web interface left on? Just turn that off, there shouldn't be much to do with that.
Most consumer routers do not support disabling the web interface on the local network, as it's the primary (only?) means of administration for them. This attack relies on getting users to browse to an address with default creds by some means, with a URL prepended that will cause the desired action to occur. More often than not a popular action is to modify the DNS servers used, so that DNS traffic can then me manipulated to point to malicious servers used for the ultimate attack.
Issues like this don't happen across such a wide area by accident.
Basic professional practices have any updates tested beforehand on physical hardware at multiple stages before any push happens, and they leave it up to the user because pushing an update without the owner's explicit consent to a device they own, runs afoul of the same hacking abuse laws. The legal exposure is massive.
It also doesn't account for the fact that firmware was attempted to be updated on devices which were set to not update. ASUS has a lot to explain. They didn't release any kind of statement so the lawyers and computer forensics people will likely need to get involved to get to the bottom of it.
I look forward to eventually hearing about what really happened.
https://www.trendmicro.com/en_us/research/22/c/cyclops-blink...
Hopefully that clears up the first question of "why does it need malware signature files?"
As for your router firmware? You should seriously update that. New exploits get found all the time.
Hackers use compromised routers as parts of a botnet, a intermediary route, or as an access point with which to steal data with Man in the Middle attacks.
Signature files are only useful to scan network traffic.
How is it not relevant? This person has not updated their router's firmware in over 3 years.
The viral traffic needs to get to the router in the first place. I assume that the means of reaching the router is literally via network traffic?
What am I missing?
The malware signature files really don't help prevent your router joining a botnet.
Firmware updates, maybe, maybe not. It is quite possible for other routers with less generally sloppy and advertised-feature-rich firmware to actually be more secure even without updates for 3 years. It's quite possible that they have no api endpoints available for super-easy mobile app integration remote management etc, just ssh from local subnet or physical serial console.
There have been multiple cases of market-leading antivirus engines (symanted, mcaffee, etc) having sloppy code running with the highest possible privilege, parsing any files appearing on the system anywhere, and e.g. crashing a mail server that would otherwise be unaffected by the PoC samples being emailed through it by researchers.
So, I also take some issue with people who have no understanding of how all this software around us is designed and built (in routers, in windows, on web servers) and thinking that just updating everything all the time and running antivirus is the best you can do. You really can do a lot better if you know what you're doing.
https://lwn.net/ml/oss-security/20221013101046.GB20615@suse....
There can be driver specific remotely exploitable issues that might not be widely communicated. Until operating systems are written more robustly, just having admin level stuff set up robustly isn't always enough. Of course, updates can add bugs too.
These types of signature files aren’t meant to guard against exploits, SSH brute forcing, etc, even if the router applies them to inbound traffic in addition to forwarded traffic. To do that, you typically need a WAF or some clever fail2ban-like filtering rules. Even up-to-date signatures won’t prevent a router from getting 0wn3d if the ssh daemon has a security hole for example.
As sites move to HTTPS, routers can’t even really filter networking traffic anymore. I don’t see why a router needs signature lists at all
Not really. The article doesn't mention signature files. It describes the operations of a certain malware once it has been executed on a router. But first it has to get onto the router; and the only way new software can get onto this router is via a firmware update.
That has never been the case. Software from consumer routers is often still in the "a trivial buffer overflow lets a malformed packet insert a payload into ram and convince the PC to jump to it." phase of software security. They are very much still wormable systems, like Windows 2000 style. Ever have your router glitch out and stop working and you have to reboot it? That's probably an exploitable bug.
They argue that he doesn't understand and he's stupid to want to be part of a botnet and that Asus obviously know what they're doing.
The sea gate drive failed soon after and I lost tons and tons of files. Not to mention it silently corrupted almost every file before biting the dust, videos stopped playing suddenly.
It would explain why the router is downloading “updates” but not firmware upgrades.
Also, these signature files contain tons of hex strings and unusual characters used to identify the actual malware (IOCs).
We rollback these updates all the time when a bad malware signature update pegs the AV scan daemon. They are released several times per month depending on the vendor.
Someone more knowledgeable about ASUS asd can probably confirm/deny.
See https://jdebp.uk/FGA/do-not-use-logrotate.html for everything from Bryan Cantrill to comments in GNU source code. (-:
Also, you have an amazing website. Looking forward to reading more.
That name already sounds creepy enough, but searching for that string (with the quotes) currently returns only 4 results, of people asking what it is. My guess is some sort of hidden backdoor, disguised as an ostensibly useful feature.
So DSP magic?
This is very common when I look to find source for embedded devices like this. What I expect is the next step is that you will find (or be given) a borderline useless blob of source that doesn't explain any of it's build process, which is absurd because the GPL clearly defines the build "glue" as part of the source.
Is ASUS another company that is doing a poor job of GPL compliance in this space?
Is it intentional?
That seems to be the way to keep consumer grade routers from requiring the user walk over and reboot them once a week...
Domestic routers, in particular, are infamous for their web interface and management daemons often calling command line programs through system() to configure the network (and other system management tasks), instead of directly using the APIs these command line programs use. Not only is this inefficient and fragile, it also not rarely leads to being vulnerable to shell injection attacks (if you're lucky, only exploitable by authenticated users of the web interface).
In this particular case, the set of states that the device is in when it boots is relatively small compared to the set of states that device may be in a week later. More generally, all individual complex systems need to be "restarted" periodically, it's just a question of how often.
https://news.yahoo.com/rise-copper-theft-officials-concerned...
My dad works as a network engineer, and he told me a story that one of the banks in Poland lost one of the internet providers. They investigated and found out that thieves stole hundreds of meters of a fiber cable, because they thought that it's copper.
I don't think it has any relation, but since it's the first time it's happened, it was kind of a freaky coincidence!
May be i am old fashioned but shouldn't hardware appliances be designed as standalone devices that have minimal external dependencies.
If there was no firmware update or patch applied -- the functionality of the device shouldn't change.
Do all routers these days "phone home" anyway and modify settings on autopilot? Even if user has chosen to turn off updates?
Users won't apply fixes.
Therefore auto-updates became the norm.
You can trust the users implicitly, or you can trust ASUS implicitly.
It seems that the appropriate place to deal with network traffic security issues is with the network bandwidth provider, which would be your ISP.
This would imply that the ISP has abilities to interpose between malicious traffic and the user that, with modern technologies like DNS-over-HTTP, they simply don’t have. To most ISPs (that don’t force you to install MITM CA certs), user traffic is increasingly a black box. Which means that attacker traffic can blend right in as part of said black box. The only thing that can see into the black box is the device on the end of the line.
It's not about catching related traffic when it occurs, more managing the immediate implications from insecure devices on the network. The ISP can see the device, it doesn't need to inspect the traffic.
Have we all forgotten how Nest thermostats turned off the heat in the middle of January 2016 because of a botched software update? (Probably. It was hard to get Google to surface a link without a date due to so much SEO bullshit).
https://www.nytimes.com/2016/01/14/fashion/nest-thermostat-g...
(Though replacing a smart thermostat with a mercury switch one is a five minute job if you're comfortable with it.)
At least in this case, ASUS routers all have local firmware install functionality, so this particular case is certainly not an example of engineers not knowing it’s possible to write offline updates.
Now if you’re really lamenting the lack of computing devices that cannot be updated remotely by design, that’s a different story, and might be on a ship that sailed a while back. The problem there is that local updates are inconvenient enough for most people that they aren’t done, which is problematic from support and security perspectives, even though there are legit problems with remote updates too…
Google no longer does search, it does "recommendation" and it sucks hard.
Now get off my lawn ))
The scary part of auto update is when a company does a bad job of it. For example: letting the auto update site domain expire or point to an IP at a hosting provider that someone might pick up and if the devices don't do proper endpoint validation folks can use it to force downloads of compromised images.
All of these things have happened.
Depends.
"Homemade" routers running open source OS that computer owner can compile themselves need not "phone home" against owner intent. "Home" is the computer owner, not some company.
Commercial routers running closed source OS that owner cannot edit and re-compile can be expected to try to phone home for something, IMHO. A disturbing trend certainly not started by ASUS but which seems to be infecting most hardware sold with pre-installed closed source OS.
I know I would prefer something like that for my non-savvy people. Considering there are smart light bulbs with vulnerabilities which are years away from the landfill. The only question is which botnet will they join the next time they power cycle.
1. A modem that handles ADSL/VDSL/fibre incoming and 10GB ethernet outgoing with passthrough to:
2. A good wifi 6 mesh router + APs (eg Netgear or equivalent).
I don't want them to do anything but:
a) Support both DHCP and fixed assigned IPv4 configuration b) IPv6 /56 subnet assignment c) NAT outgoing IPv4, no incoming connections allowed d) IPv6 ingress/egress
I don't want them scanning the traffic, protecting me from malware, upgrading themselves, doing anything fancy.
I want the bandwidth of my home ISP connection to be supported and I want the bandwidth of my 5G wifi and 10GB internal LAN to be fully supported.
[1] https://sschueller.github.io/posts/wiring-a-home-with-fiber/...
All ADSL and VDSL connections known to man will have adequate bandwidth over 1000BASE-T, simple and cheap modems that support RFC 1483 bridging abound. If you've got >1Gb/s fibre, presumably your ISP provides equipment to support such, and why not simply have a router with SFP+?
Why would they do that? If they sell me 10GBit but I can only reasonably use 1, then they can sell the same thing to 10x the people with the same hardware.
I used to run a full 10gb-t datacenter switch (dell) and put the fiber right into the sfp+ ports to do my own routing, but once the ISP started providing modems that could actually network at 2.5G it was overkill and I moved back to modem -> APs and modem->smaller 10G switch for PCs and Servers.
I called Charter and they blamed the router, but I was a bit suspect since in January of 2022, we had another issue where the call center blamed our router and after a bit of testing was able to prove to them it wasn't our router. This was kind of interesting as well, they finally sent out a second service tech that had some sort of spectrum analyzer and he found our line it was being overwhelmed with noise. Turns out the drop from the pole wasn't shielded and a new T-Mobile 5G tower was bleeding into the line (acting like an antennae). The tech put a new wire up and it immediately solved the issue.
In both occasions, the help desk told us the signal coming to the router was fine though. This time a factory reset seemed to do the trick, but I seemed to have the latest firmware to start with so I'm not sure what's going on.
I'll have to go through the thread again, but I'm not sure we know what the root cause is yet? Log files were filling up, but I didn't catch why.
Sadly given the large amount of software that's closed source there I don't see them working towards open sourcing any of it as, even technically, it would be a massive effort.
Thank you for writing this blogpost. I just upgraded firmware. So happy when something has an explanation. !
To downgrade, they pointed to the 'Method 2: Update Manually' section of this support FAQ: https://www.asus.com/support/FAQ/1008000/#a2
Other comments from ASUS chat support:
- Asus is "in the process of fixing the issue".
- When a new firmware update is available "it will be just on the ASUS website to the router itself". [I presume they're referencing the router's web GUI admin tool?]
- When asked for an 'official Asus forum or support site' to monitor for updates regarding this issue, they said: "We don't have a forum page for newly released updates but this should be posted on the ASUS website main page."
----
[0] ASUS chat support session ending at 12:32:46 PT on 2023-05-18
I recommended it to my friends when they changed their routers over, and it fixed a lot of issues for them as well. The ones who regularly used VR reported that the stuttering issues they had on VR over WiFi with their Netgear WiFi 6 routers were solved.
Have owned both ASUS and Netgear in the past and the experience was terrible -- the high-end ASUS router regularly bricked itself during auto update. So I bought a more expensive ASUS router for around $600, and you guessed it, it did the same thing just less frequently. The NETGEAR routers never bricked themselves, but across the 3 models we've owned nearly all of them would lose most of their throughput (around 90%) on a daily basis and would need a daily reset to get proper ISP speeds again.
I had a Dream Machine Pro for around a year before I moved it to my office to run the network in the office. Funnily enough it has probably been less stable than the tp-link router, but nonetheless the UDM Pro is still a great piece of kit and probably the last router you'd ever need if it's in your budget and you have a place to put it (awkward form factor for home).
Re: Open WRT I ran this around 3 years ago on a D-Link router that I had, and the stability was unpredictable.. better than ASUS and NETGEAR but probably leaning on the side of poor compared to tp-link and UDM Pro. It would randomly get slow once per fortnight or so, and would need to be rebooted. Sometimes it would panic and completely lose internet connection. There are plugins designed to reboot the router as soon as a loss of connection is detected, but why is this even necessary? It's annoying too. Drops all your connections.
Sorry for long.
I would just pick one up available from this list that matches your manufacturer preference(brand loyalty), desired feature set, and availability in the electronic stores you usually make your purchases.
No problems so far at all after 4 months.
As far as I could tell, they were the only source of medium-performance boards with excellent open source support that didn't change the design every 12 months for no f---ing reason.
It's good for a learning experience :)
And now, the ISP routers have caught up imo
I just use that now and it is fine. Plug in as much as possible with Ethernet. If that fails, it's probably a router issue or ISP network issue, and then it's on the ISP side to fix.
Immediately brought a smile to my face. This profession makes us detail-oriented detectives. It's a joyful power and a powerful joy :-) Now I know it's not a good personality trait. I guess one's hobbies should ideally be complete opposites, based on intuition and a feel for things.
I found that one just after spending all day chasing an odd WAN issue for a customer. A few years ago in the era of half/full duplex in ethernet, duplex mismatches sometimes manifested in some truly weird ways. It was at that point that I did start to believe in ghosts. At least ghosts in the network.
Pesky upgrade. Now have full wire capturing going on on public side.
I originally bought these on a recommendation while I was looking for gigabit mesh systems. I’m back in the market after yesterday.
For Asus routers it is wrong. Install Asuswrt-Merlin.
Leaving us ASUS users dangling with that comment is like leaving us hanging in there ... pondering WHY?
I still want to know what happened. It feels like a good excuse to get a new non-asus router barring any other explanation
https://arstechnica.com/information-technology/2023/05/asus-...
So, what wifi ap should I buy to replace this POS?
My guess based on reading the article is that it's mostly logs filling the disk. You can find out for sure with some version of
du -a | sort -hr | head
Then just start deleting logs at or near the top of the list - I suppose this would get you back running. Sure, constantly writing to logs sounds terrible for performance, but did you even notice when it was working properly? If it's actually Ubuntu running on this router, you could even install (or configure if it's already there) logrotate to probably prevent this from happening again at all.Then you still have a POS router, but one that might get the job done.
Fortunately, I checked for a firmware update from the car before I left and found the golden patch. Kicked it off and left for work.
Figuring all is fine now. What a wild trip though.
Wild trip? Man I am getting old.
I also have an ASUS RT-AC86U (running 3.0.0.4.386_51255), but as a node in the mesh, it's still online.
However, my RT-AX55 (3.0.0.4.386_50460) in the mesh has been down all day and I haven't noticed before this post because the other nodes picked up the slack (with spotty/slow signal).
Also have an RT-AX82U (3.0.0.4.388_22525) as the mesh leader and it also doesn't seem impacted.
EDIT: crap, I just checked again and two of my nodes are offline now. Only the root node is working. Too late in the evening to fix it now, guess I’ll be working on that in the morning.
* https://news.ycombinator.com/item?id=35984706
* https://news.ycombinator.com/item?id=35984725
The service fix is for ASUS to make a malware scanner that doesn't have such bad behaviour in the case of a signature file that it cannot process, and to not use a logging mechanism that we knew had this flaw in the 1980s, and improved upon in the 1990s. (-:
The frustrating part was that my home assistant raspberry pi was hardwired into one of the nodes that died, so my automation to change my thermostat wasn't working and it was stuck on a setting that I normally only set for one hour in the day. Obviously I could change it manually, but I didn't realize that it hadn't changed until it had been like 5 hours.
Asus has been pretty good about open source firmware and being relatively transparent about their operating system and hardware, but I can't afford to replace my router/AP every 2 years because of a crappy radio IC that is prone to failure.
I run an RT-AC87U (3.0.0.4.382_52545-ga0245cc) as the main router
I have an RT-AC86U (3.0.0.4.386_51255-g486ded6) and an RT-AC68U (3.0.0.4.386_51255-g486ded6) running in AP mode.
Tried checking whether there was an update available for the RT-AC87U, but it looks like the ASUS firmware site is unreachable (overloaded?) for me at the moment.
I logged into my router and checked for new firmware, then installed it, and it started working again.
I use an Deciso OPNsense where it doesn't insist on breaking itself on the orders of corporate overlords.
I’ve just restarted mine and gone into the admin page and told it to update its firmware.
No expectation it really helps, but it seems a good step before sshing in to delete a file…?
idk ... but if your model is in the device compatibility-list, your should always be able to change to an alternative FOSS firmware. for example to https://openwrt.org or to some maintained tomato-clone like https://freshtomato.org
ps. i'm a happy owner of a 10+ years old RT N16 - it runs really great on openwrt ...
cheers, v
"dnsmasq-dhcp[1489]: failed to write /var/lib/misc/dnsmasq.leases: No space left on device (retry in 60s)”
Not amazing, to be sure, and I don't know what those devices cost, but I think the situation is less dire than your post would suggest.
[0] https://openwrt.org/toh/views/toh_available_16128_ax-wifi
(Despite routers capable of gigabit speeds being commonly both free and available on eBay for pennies)
Latest proof of that in my case was with a new Wi-Fi 6 router Netgear WAX206. After indeterminate time clients would just stop receiving packets and would require reconnecting. WAX206 latest factory firmware is based on OpenWRT from 2016 (Netgear still refuses to open source parts of it). After flashing current OpenWRT the connection is rock solid.
These projects are great, but against the background of 100s of new crappy devices every year, nothing can ever be decently finished. Hardware is simply not sold anymore before any device fully matures, and vendors are very stingy with firmware.
Brainslayer is so obsessively paranoid about the idea someone might "steal" and "sell" DD-WRT devices that he obfuscates building the firmware as much as possible.
The devices also are just the stock garbage vendor GPL tarball with DD-WRT's UI on top. So you'll still be stuck with stuff like an ancient kernel full of bugs
This significantly shrinks the number of devices they support, but the devices that are supported have their lifespans increased significantly
Doesn't mean everything MTK does shines under the sun, but in Linux WiFi, they are probably the most open and well supported in the modern age.
6.x kernel is not expected to land anytime soon (late this year or early next year maybe?)
If you have a 6.x kernel, this is probably a fork of OpenWrt.
What a ride.
"I installed version X.Y.Z and so far so good"
"I tried all available updates and it keeps crashing".
There is no transparency in the published updates. Take that firmware blob (which is probably 99% GPL licensed by the way) and shut up. That's basically what the vendors are saying.
What's ironic is that most OEM are using some sort of out of date openwrt derivatives as a base for their closed source firmwares, which are obvious GPL violations.
Do you have a source of that or am I out of date? Based on my knowledge, outdated, GPL-violation OpenWRT would still be a massive upgrade over what's usually developed in-house by OEMs.
Musk's "Starlink" router is also OpenWRT based
Buying $30-$40 access points on eBay is a bit of a hobby of mine. I've been using a Netgear R8000 as an access point for a few months. There's no OpenWRT support, but it's supported by FreshTomato. Qualitatively, it seems to work well in terms of latency and throughput when the signal is strong. It seems to perform worse than the WRT1200AC that I was previously using at that location, when at the fringe. When I'm at the center of my house, my phone tends to associate with it but then struggle to get packets through. Maybe I just need to dial down the AP's TX power, though.
These system are almost always built on the official SDK provided by Qualcomm, known as QSDK.
QSDK is a fork of an old OpenWRT version (chaos calmer, 2018). Unlike the open source version, it includes proprietary drivers and many changes. Openwrt devs refer to it as a "frankenfirmware".
Hard pass. Not interested in Microsoft's latest malware/adware of an OS.
I've been running Linux on laptops for nearly 20 years now. Sure, it was a pain in the ass in the earlier days, but nowadays things just work, as long as you're willing to do your research ahead of time to choose a laptop where the hardware is fully supported.
Yes of course it was. The only reason.
Delusuional.
You think some conspiracy created Ubuntu so people can point to the Amazon thing?
That said, if the OS is aggressively pushing recommendations for their first party news, videos, and search engine, and every one of those things shows 3rd party ads, I don't think that single step removed absolves win 11.
This is flatly untrue.
It preinstalls Spotify, Disney+, Instagram, Facebook, Tiktok, and a tonne of other tools.
A list with screenshots:
https://www.digitalcitizen.life/windows-10-bloatware/
If you want to argue that preinstalled links to 3rd party websites, prominently displayed in the Start menu, do not count as "ads", then you are acting in bad faith and your arguments can be dismissed.
A bundled link to external properties is an advertisement.
Some of us like to keep our work device ad-free