▲ 254 ▼ Chinese malware removed from SOHO routers after FBI issues covert commands (arstechnica.com) submitted 2 years ago by throws_lemy@lemmy.nz to c/technology@lemmy.world 50 comments fedilink hide all child comments
[–] HeartyBeast@kbin.social 5 points 2 years ago (2 children) How would you like the router owners to have been alerted? permalink fedilink source parent hideshow 4 child comments replies: [–] Darkassassin07@lemmy.ca 22 points 2 years ago (2 children) Perhaps via the contact information they provided to their ISP? permalink fedilink source parent hideshow 4 child comments replies: [–] HeartyBeast@kbin.social 9 points 2 years ago I suspect it might have been problematic to tip off the malware operators that the network was about to be shut down. Apparently customers are going to be informed via their ISPs now. I guess some if them may decide to junk the routers. permalink fedilink source parent [+] shalafi@lemmy.world -10 points 2 years ago (5 children) My ISP has never had info on my router, for 20+ years. Was there something in the story I missed about these being ISP issued routers? permalink fedilink source parent hideshow 10 child comments replies: [–] Darkassassin07@lemmy.ca 29 points 2 years ago The ISPs don't need info on the routers... The FBI has identified the routers; if they're able to connect to them and issue commands, they clearly know the IPs of those routers and thus the ISP servicing that IP. The ISP knows which of their customers is/was assigned a particular IP. permalink fedilink source parent [–] BakedCatboy@lemmy.ml 19 points 2 years ago* (2 children) Your ISP knows the Mac address of your router since it requests a public IP from them using DHCP. That's why if you contact support they usually can confirm the brand of your router by doing an oui lookup. In theory the FBI could have collected a list of MACs and optionally used an ASN lookup on the public IP and then handed each ISP their list of MACs, which the ISP could associate back to customers to contact. It would only not work for customers who spoof their router WANs ethernet mac. But I think just patching it is a normal and fine solution imo. permalink fedilink source parent hideshow 4 child comments replies: [–] Tangent5280@lemmy.world 2 points 2 years ago (1 child) Do you work in networking? How did you learn the magicks of the computer tongue? permalink fedilink source parent hideshow 2 child comments replies: [–] BakedCatboy@lemmy.ml 2 points 2 years ago* I only do web development, but my networking knowledge mostly comes from being the designated person to call the ISP for tech support and being in charge of setting up the WiFi in every place that I've lived, in addition to participating and running community scale mesh wifi tech meetups for many years (think NYCMesh except just 4 guys who never accomplished much aside from buying and flashing lots of routers with openwrt lmao) I also ran 12Us of homelab for a few years in my basement, which was powered by an overkill fiber to the home setup (courtesy of tricking Comcast into undercharging me for gigabit pro) that necessitated a 10G switch and firewall. permalink fedilink source parent [–] Case@lemmynsfw.com 1 point 2 years ago Or I mean, Shodan exists. I'm sure the gov has better. A theoretical botnet I was looking at on github used shodan to identify possible targets to infect. permalink fedilink source parent [–] gregorum@lemm.ee 6 points 2 years ago Oh, sweet Summer child permalink fedilink source parent [–] HeartyBeast@kbin.social 5 points 2 years ago Probably works the other way around - FBI detects the problem at various IP addresses, patches them, then contacts the iISP and asks them to contact the customer who had x.y.z IP address permalink fedilink source parent [–] squeakycat@lemmy.ml -2 points 2 years ago I would imagine you are in the vast minority :) permalink fedilink source parent [–] NeoNachtwaechter@lemmy.world 8 points 2 years ago (2 children) How would you like the router owners to have been alerted? By two men in black showing up at their doors, of course. :-) permalink fedilink source parent hideshow 4 child comments replies: [–] AnUnusualRelic@lemmy.world 3 points 2 years ago "We're musicians maam" permalink fedilink source parent [–] Tangent5280@lemmy.world 2 points 2 years ago* We are here to help. permalink fedilink source parent
[–] Darkassassin07@lemmy.ca 22 points 2 years ago (2 children) Perhaps via the contact information they provided to their ISP? permalink fedilink source parent hideshow 4 child comments replies: [–] HeartyBeast@kbin.social 9 points 2 years ago I suspect it might have been problematic to tip off the malware operators that the network was about to be shut down. Apparently customers are going to be informed via their ISPs now. I guess some if them may decide to junk the routers. permalink fedilink source parent [+] shalafi@lemmy.world -10 points 2 years ago (5 children) My ISP has never had info on my router, for 20+ years. Was there something in the story I missed about these being ISP issued routers? permalink fedilink source parent hideshow 10 child comments replies: [–] Darkassassin07@lemmy.ca 29 points 2 years ago The ISPs don't need info on the routers... The FBI has identified the routers; if they're able to connect to them and issue commands, they clearly know the IPs of those routers and thus the ISP servicing that IP. The ISP knows which of their customers is/was assigned a particular IP. permalink fedilink source parent [–] BakedCatboy@lemmy.ml 19 points 2 years ago* (2 children) Your ISP knows the Mac address of your router since it requests a public IP from them using DHCP. That's why if you contact support they usually can confirm the brand of your router by doing an oui lookup. In theory the FBI could have collected a list of MACs and optionally used an ASN lookup on the public IP and then handed each ISP their list of MACs, which the ISP could associate back to customers to contact. It would only not work for customers who spoof their router WANs ethernet mac. But I think just patching it is a normal and fine solution imo. permalink fedilink source parent hideshow 4 child comments replies: [–] Tangent5280@lemmy.world 2 points 2 years ago (1 child) Do you work in networking? How did you learn the magicks of the computer tongue? permalink fedilink source parent hideshow 2 child comments replies: [–] BakedCatboy@lemmy.ml 2 points 2 years ago* I only do web development, but my networking knowledge mostly comes from being the designated person to call the ISP for tech support and being in charge of setting up the WiFi in every place that I've lived, in addition to participating and running community scale mesh wifi tech meetups for many years (think NYCMesh except just 4 guys who never accomplished much aside from buying and flashing lots of routers with openwrt lmao) I also ran 12Us of homelab for a few years in my basement, which was powered by an overkill fiber to the home setup (courtesy of tricking Comcast into undercharging me for gigabit pro) that necessitated a 10G switch and firewall. permalink fedilink source parent [–] Case@lemmynsfw.com 1 point 2 years ago Or I mean, Shodan exists. I'm sure the gov has better. A theoretical botnet I was looking at on github used shodan to identify possible targets to infect. permalink fedilink source parent [–] gregorum@lemm.ee 6 points 2 years ago Oh, sweet Summer child permalink fedilink source parent [–] HeartyBeast@kbin.social 5 points 2 years ago Probably works the other way around - FBI detects the problem at various IP addresses, patches them, then contacts the iISP and asks them to contact the customer who had x.y.z IP address permalink fedilink source parent [–] squeakycat@lemmy.ml -2 points 2 years ago I would imagine you are in the vast minority :) permalink fedilink source parent
[–] HeartyBeast@kbin.social 9 points 2 years ago I suspect it might have been problematic to tip off the malware operators that the network was about to be shut down. Apparently customers are going to be informed via their ISPs now. I guess some if them may decide to junk the routers. permalink fedilink source parent
[+] shalafi@lemmy.world -10 points 2 years ago (5 children) My ISP has never had info on my router, for 20+ years. Was there something in the story I missed about these being ISP issued routers? permalink fedilink source parent hideshow 10 child comments replies: [–] Darkassassin07@lemmy.ca 29 points 2 years ago The ISPs don't need info on the routers... The FBI has identified the routers; if they're able to connect to them and issue commands, they clearly know the IPs of those routers and thus the ISP servicing that IP. The ISP knows which of their customers is/was assigned a particular IP. permalink fedilink source parent [–] BakedCatboy@lemmy.ml 19 points 2 years ago* (2 children) Your ISP knows the Mac address of your router since it requests a public IP from them using DHCP. That's why if you contact support they usually can confirm the brand of your router by doing an oui lookup. In theory the FBI could have collected a list of MACs and optionally used an ASN lookup on the public IP and then handed each ISP their list of MACs, which the ISP could associate back to customers to contact. It would only not work for customers who spoof their router WANs ethernet mac. But I think just patching it is a normal and fine solution imo. permalink fedilink source parent hideshow 4 child comments replies: [–] Tangent5280@lemmy.world 2 points 2 years ago (1 child) Do you work in networking? How did you learn the magicks of the computer tongue? permalink fedilink source parent hideshow 2 child comments replies: [–] BakedCatboy@lemmy.ml 2 points 2 years ago* I only do web development, but my networking knowledge mostly comes from being the designated person to call the ISP for tech support and being in charge of setting up the WiFi in every place that I've lived, in addition to participating and running community scale mesh wifi tech meetups for many years (think NYCMesh except just 4 guys who never accomplished much aside from buying and flashing lots of routers with openwrt lmao) I also ran 12Us of homelab for a few years in my basement, which was powered by an overkill fiber to the home setup (courtesy of tricking Comcast into undercharging me for gigabit pro) that necessitated a 10G switch and firewall. permalink fedilink source parent [–] Case@lemmynsfw.com 1 point 2 years ago Or I mean, Shodan exists. I'm sure the gov has better. A theoretical botnet I was looking at on github used shodan to identify possible targets to infect. permalink fedilink source parent [–] gregorum@lemm.ee 6 points 2 years ago Oh, sweet Summer child permalink fedilink source parent [–] HeartyBeast@kbin.social 5 points 2 years ago Probably works the other way around - FBI detects the problem at various IP addresses, patches them, then contacts the iISP and asks them to contact the customer who had x.y.z IP address permalink fedilink source parent [–] squeakycat@lemmy.ml -2 points 2 years ago I would imagine you are in the vast minority :) permalink fedilink source parent
[–] Darkassassin07@lemmy.ca 29 points 2 years ago The ISPs don't need info on the routers... The FBI has identified the routers; if they're able to connect to them and issue commands, they clearly know the IPs of those routers and thus the ISP servicing that IP. The ISP knows which of their customers is/was assigned a particular IP. permalink fedilink source parent
[–] BakedCatboy@lemmy.ml 19 points 2 years ago* (2 children) Your ISP knows the Mac address of your router since it requests a public IP from them using DHCP. That's why if you contact support they usually can confirm the brand of your router by doing an oui lookup. In theory the FBI could have collected a list of MACs and optionally used an ASN lookup on the public IP and then handed each ISP their list of MACs, which the ISP could associate back to customers to contact. It would only not work for customers who spoof their router WANs ethernet mac. But I think just patching it is a normal and fine solution imo. permalink fedilink source parent hideshow 4 child comments replies: [–] Tangent5280@lemmy.world 2 points 2 years ago (1 child) Do you work in networking? How did you learn the magicks of the computer tongue? permalink fedilink source parent hideshow 2 child comments replies: [–] BakedCatboy@lemmy.ml 2 points 2 years ago* I only do web development, but my networking knowledge mostly comes from being the designated person to call the ISP for tech support and being in charge of setting up the WiFi in every place that I've lived, in addition to participating and running community scale mesh wifi tech meetups for many years (think NYCMesh except just 4 guys who never accomplished much aside from buying and flashing lots of routers with openwrt lmao) I also ran 12Us of homelab for a few years in my basement, which was powered by an overkill fiber to the home setup (courtesy of tricking Comcast into undercharging me for gigabit pro) that necessitated a 10G switch and firewall. permalink fedilink source parent [–] Case@lemmynsfw.com 1 point 2 years ago Or I mean, Shodan exists. I'm sure the gov has better. A theoretical botnet I was looking at on github used shodan to identify possible targets to infect. permalink fedilink source parent
[–] Tangent5280@lemmy.world 2 points 2 years ago (1 child) Do you work in networking? How did you learn the magicks of the computer tongue? permalink fedilink source parent hideshow 2 child comments replies: [–] BakedCatboy@lemmy.ml 2 points 2 years ago* I only do web development, but my networking knowledge mostly comes from being the designated person to call the ISP for tech support and being in charge of setting up the WiFi in every place that I've lived, in addition to participating and running community scale mesh wifi tech meetups for many years (think NYCMesh except just 4 guys who never accomplished much aside from buying and flashing lots of routers with openwrt lmao) I also ran 12Us of homelab for a few years in my basement, which was powered by an overkill fiber to the home setup (courtesy of tricking Comcast into undercharging me for gigabit pro) that necessitated a 10G switch and firewall. permalink fedilink source parent
[–] BakedCatboy@lemmy.ml 2 points 2 years ago* I only do web development, but my networking knowledge mostly comes from being the designated person to call the ISP for tech support and being in charge of setting up the WiFi in every place that I've lived, in addition to participating and running community scale mesh wifi tech meetups for many years (think NYCMesh except just 4 guys who never accomplished much aside from buying and flashing lots of routers with openwrt lmao) I also ran 12Us of homelab for a few years in my basement, which was powered by an overkill fiber to the home setup (courtesy of tricking Comcast into undercharging me for gigabit pro) that necessitated a 10G switch and firewall. permalink fedilink source parent
[–] Case@lemmynsfw.com 1 point 2 years ago Or I mean, Shodan exists. I'm sure the gov has better. A theoretical botnet I was looking at on github used shodan to identify possible targets to infect. permalink fedilink source parent
[–] HeartyBeast@kbin.social 5 points 2 years ago Probably works the other way around - FBI detects the problem at various IP addresses, patches them, then contacts the iISP and asks them to contact the customer who had x.y.z IP address permalink fedilink source parent
[–] squeakycat@lemmy.ml -2 points 2 years ago I would imagine you are in the vast minority :) permalink fedilink source parent
[–] NeoNachtwaechter@lemmy.world 8 points 2 years ago (2 children) How would you like the router owners to have been alerted? By two men in black showing up at their doors, of course. :-) permalink fedilink source parent hideshow 4 child comments replies: [–] AnUnusualRelic@lemmy.world 3 points 2 years ago "We're musicians maam" permalink fedilink source parent [–] Tangent5280@lemmy.world 2 points 2 years ago* We are here to help. permalink fedilink source parent
[–] AnUnusualRelic@lemmy.world 3 points 2 years ago "We're musicians maam" permalink fedilink source parent
[–] Tangent5280@lemmy.world 2 points 2 years ago* We are here to help. permalink fedilink source parent