HNHacker News
TopNewBestAskShowJobs

wasipwned

186 karma · joined December 1, 2022

submissionscomments
wasipwned··on Ask HN: Was I pwned? [resolved]
Not to my knowledge, but I will double checking to make sure. The odd part is the issue only started recently, but I haven't made any major changes to my network recently.
wasipwned··on Ask HN: Was I pwned? [resolved]
Yes I posted the IP address here: https://news.ycombinator.com/item?id=33820749 and it appears to be AT&T's CGNAT IP address and communicating over port 4500 (IPsec), so the likely culprit is Wi-Fi calling which uses IPsec.

I'm running Ubuntu 20.04. I don't use livepatch, but I do update/reboot frequently. I'm mostly running Chrome, Firefox, and Docker. Occasionally GIMP and LibreOffice.

wasipwned··on Ask HN: Was I pwned? [resolved]
I can't explain this part yet. I was asleep when this happened, so I wasn't even using my phone. I may be wrong about 300Mbps being to the AT&T. public IP, as my router shows a much lower rate. That might have just been the total traffic I was seeing internally on my private network from multicast.
wasipwned··on Ask HN: Was I pwned? [resolved]
I can't fully explain this part yet, but I am currently expecting that I will see the issue again even with my desktop disconnected.

I am also probably wrong about it being 300Mbps to AT&T. It was probably 300Mbps of multicast traffic internally.

wasipwned··on Ask HN: Was I pwned? [resolved]
Out of curiosity, how do you know it's CGNAT? Is it just because all of AT&T's mobile traffic is through CGNAT?
wasipwned··on Ask HN: Was I pwned? [resolved]
False alarm. Really appreciate everyone helping me sanity check this. The randomized MAC is part of iOS' Wi-Fi privacy, and my phone is using Wi-Fi calling for AT&T. The randomized MAC and the fact that I thought I saw the traffic originating from my desktop (it wasn't, it was just multicast traffic) really threw me off.
wasipwned··on Ask HN: Was I pwned? [resolved]
Thanks for reminding me of this. This is looking less and less malicious at this point as `10.0.0.3` is my phone (using AT&T, which is where all the traffic was destined).
wasipwned··on Ask HN: Was I pwned? [resolved]
Yeah, I'm now realizing that this might be multicast traffic I'm seeing from another device, and I do use AT&T which is making me think this may not actually be malicious.
wasipwned··on Ask HN: Was I pwned? [resolved]
I probably am mistaken that it's originating from my desktop. It is entirely possible that it is multicast traffic I am seeing.

See https://news.ycombinator.com/item?id=33821387

wasipwned··on Ask HN: Was I pwned? [resolved]
Circling back, this discussion thread seems to be the most likely culprit. In my panicked state, I didn't even consider multicast traffic being the reason why I saw this traffic in tcpdump. I'm digging into this a bit more. I probably wasn't pwned, but I am still currently operating as if I were. I appreciate everyone's response here.
wasipwned··on Ask HN: Was I pwned? [resolved]
Unfortunately, I did not save any packet captures, so I only saw that it was on the IPsec port.
wasipwned··on Ask HN: Was I pwned? [resolved]
This actually makes the most sense so far. I hadn't even considered the possibility of multicast. Let me see if I can dig in further.
wasipwned··on Ask HN: Was I pwned? [resolved]
Yeah, that was exactly what I was thinking as well. I do use KVM to run a few VMs, but they were the only VMs I could find, and they were both stopped the whole time.
wasipwned··on Ask HN: Was I pwned? [resolved]
I had run lsof on my desktop and I did not see any of the IP addresses in question. I did not check specifically for port 4500 though.
wasipwned··on Ask HN: Was I pwned? [resolved]
I'm using a UDM Pro, and I had just recently patched. The only container running on the router is unifi-os itself. I keep repeating myself because I want to make sure I can't be missing something, but tcpdump on my desktop is showing the traffic which is why I'm assuming that it's my desktop that is compromised.
wasipwned··on Ask HN: Was I pwned? [resolved]
Ethernet, and wifi is disabled. But even if it was wifi or another network interface getting the IP, I should have been able to find it in ip a / ifconfig I'm assuming
wasipwned··on Ask HN: Was I pwned? [resolved]
Not running BGP that I'm aware of. Network is comprised of mostly UniFi switches and one MikroTik switch.
wasipwned··on Ask HN: Was I pwned? [resolved]
And by looking it's coming from my desktop, I mean the tcpdump was run directly on my desktop and I saw the traffic there. So I assume it had to be routed through my desktop unless I am missing something.
wasipwned··on Ask HN: Was I pwned? [resolved]
So interestingly, it looks like Unifi did classify the traffic as wifi calling, but it was doing a lot of traffic in the middle of the night when I was asleep. And the biggest question mark in my head is: how is this traffic looking like it's coming from my desktop?
wasipwned··on Ask HN: Was I pwned? [resolved]
There are corporate laptops on my network. I had originally thought maybe that could be related. But I can't explain how this source IP was showing up on a tcpdump from my desktop if that was the case, so at this point I'm assuming it's an issue originating from my desktop.
wasipwned··on Ask HN: Was I pwned? [resolved]
Yes and yes.
wasipwned··on Ask HN: Was I pwned? [resolved]
It was given an IP via DHCP (but not that specific IP, that was more for illustrative purposes).

I'm currently ruling out that it is any other device given I'm seeing the traffic from my desktop, and it shouldn't be acting as a router for another physical device. But I'd like to know if I could be wrong about htat.

wasipwned··on Ask HN: Was I pwned? [resolved]
Nothing is exposed directly to the internet, but I had some development services that were accessible on my private network.

I do use Dropbox, but the odd part was it seemingly IPsec traffic.

I really should have grabbed a pcap when it was occurring. I only have a screenshot of tcpdump which is not very useful.

wasipwned··on Ask HN: Was I pwned? [resolved]
Yeah. That's definitely the plan, but I want to see if there's anything I can learn from the machine before I even do so.

The IP address was 107.122.31.71.