{"id":7707,"date":"2018-10-12T14:09:09","date_gmt":"2018-10-12T18:09:09","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=7707"},"modified":"2020-08-25T10:16:29","modified_gmt":"2020-08-25T14:16:29","slug":"mysterious-russian-grey-hat-vigilante-patched-over-100000-routers","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/mysterious-russian-grey-hat-vigilante-patched-over-100000-routers\/","title":{"rendered":"A Mysterious Russian Grey Hat Vigilante has patched over 100,000 routers"},"content":{"rendered":"<h2>Hacking to help \u2013 and not everyone appreciates it.<\/h2>\n<p>In the interest of keeping things light on a Friday, let\u2019s turn our attention to a fascinating story that wa<a href=\"https:\/\/www.zdnet.com\/article\/a-mysterious-grey-hat-is-patching-peoples-outdated-mikrotik-routers\/\">s first reported on by ZDNet\u2019s Catalin Cimpanu<\/a>: a Russian-speaking grey-hat hacker has been breaking into people\u2019s MikroTik routers and patching them so they won\u2019t be exploited by crypto-miners and other kind of digital ne\u2019er-do-wells.<\/p>\n<p>On a Russian blog site, the Russian-speaking Grey Hat, Alexey, boasted that he had already patched over 100,000 MikroTik routers.<\/p>\n<blockquote><p>&#8220;I added firewall rules that blocked access to the router from outside the local network,&#8221; Alexey wrote. &#8220;In the comments, I wrote information about the vulnerability and left the address of the @router_os Telegram channel, where it was possible for them to ask questions.&#8221;<\/p><\/blockquote>\n<p>Unfortunately, the response has been tepid at best. About 50 people have contacted Alexey, a few to say thank you but most of them were angry at the invasion.<\/p>\n<p>There\u2019s a little bit to unpack here about Hacker hats, the MikroTik vulnerability and the ethics of this kind of activity.<\/p>\n<p>So, let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n<h2>What is a Grey Hat Hacker?<\/h2>\n<p>When discussing colored hats, there are three that relate to hackers and one that relates to the US president. We\u2019re going to focus on the first three.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7708\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/MAGA-300x214.png\" alt=\"A Mysterious Russian Grey-Hat Vigilante has patched over 100,000 routers\" width=\"300\" height=\"214\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/MAGA-300x214.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/MAGA.png 585w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>A White hat hacker is an ethical hacker, typically you see White hats in the context of penetration testing, where they\u2019re looking to break a system or application in order to better secure it. They are indeed hacking, but they\u2019re doing it for ethical reasons. And they typically have authorization to do what they&#8217;re doing.<\/p>\n<p>A Black hat hacker is on the opposite end of the spectrum, they have malicious intent and are looking to break into and exploit vulnerable systems. Pretty much every major hack that you see in the news is as a result of state-backed hackers or black hat hackers. Depending on who you talk to, those can actually be one in the same, but there is a distinction to be made between <a href=\"https:\/\/www.thesslstore.com\/blog\/apt28-apt29\/\">a group like Fancy Bear<\/a>, which is acting maliciously on behalf of a government and <a href=\"https:\/\/www.thesslstore.com\/blog\/magecart-newegg-breach\/\">a group like Magecart<\/a> that is acting maliciously in their own self-interest.<\/p>\n<p>So, let\u2019s talk about Grey hats. A grey hat hacker lives somewhere in the middle. Generally speaking, they are breaking laws and violating ethics, but their intent isn\u2019t malicious. A good example would be our friend Alexey, who is hacking into MikroTik routers to patch them. It\u2019s a net-positive, but there are some ethical questions created by that kind of conduct. We\u2019ll address that later.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h2>What was wrong with MikroTik routers?<\/h2>\n<p>It\u2019s been <a href=\"https:\/\/www.thesslstore.com\/blog\/vpnfilter-mitm-reset\/\">a bad year for routers in general<\/a>, but MikroTik specifically had an issue last April (<a href=\"https:\/\/n0p.me\/winbox-bug-dissection\/\">CVE-2018-14847<\/a>) that allowed attackers to bypass authentication and download the user database file, which can then be decrypted and harvested for usernames and passwords. This gives the attackers the ability to log into remote devices, jigger with OS settings and run scripts.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7711\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Wifi-Internet-Router-Outline-I-236356096-300x300.jpg\" alt=\"A Mysterious Russian Grey-Hat Vigilante has patched over 100,000 routers\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Wifi-Internet-Router-Outline-I-236356096-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Wifi-Internet-Router-Outline-I-236356096-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Wifi-Internet-Router-Outline-I-236356096-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Wifi-Internet-Router-Outline-I-236356096.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>MikroTik, which is a Latvian-based company that specializes in routers and wireless ISP systems, released a patch almost immediately. But when was the last time you patched your router? Seriously.<\/p>\n<p>Knowing full-well that most people wouldn\u2019t install the update, <a href=\"https:\/\/www.thesslstore.com\/blog\/2018-cybercrime-statistics\/\">cybercriminals<\/a> have been having a field day ever since.<\/p>\n<p>The majority of the exploits have involved crypto-jacking, but some attackers have also used the vulnerability to hijack DNS servers and redirect the traffic towards malicious websites.<\/p>\n<p>MikroTik is one of the larger router manufacturers in the world with over 2,000,000 currently in use\u2014so patching 100,000 of them is still only about 5%. However, only about 420,000 have given indications of infection.<\/p>\n<p>One group that hasn\u2019t had much luck with this exploit are botnet herders.<\/p>\n<blockquote><p>&#8220;The usual IoT blackhat botnet factory is basically clueless about the exploit, and how it can be deployed for a proper functioning botnet,&#8221; <a href=\"https:\/\/www.zdnet.com\/article\/a-mysterious-grey-hat-is-patching-peoples-outdated-mikrotik-routers\/\">Ankit Anubhav, a security researcher for NewSky Security told ZDNet<\/a>.<\/p><\/blockquote>\n<p>So maybe not every cybercriminal is having a field day.<\/p>\n<h2>Is this Ethical?<\/h2>\n<p>That\u2019s the million-dollar question and it\u2019s not one that is going to find a consensus anytime soon. Depending on your philosophy about the internet and technology in general, you may look at this as a necessary evil or a complete violation.<\/p>\n<p>The reason that Alexey has been able to patch so many routers is that the black hat hackers attacking them are being sloppy.<\/p>\n<blockquote><p>&#8220;The attackers are not closing [device ports] or patching the devices, so anyone who wants to further mess with these routers, can,&#8221; Anubhav told <em>ZDNet<\/em>.<\/p><\/blockquote>\n<p>This kind of activity is nothing new, in fact Cimpanu even lists a number of notable grey-hat events.<\/p>\n<ul>\n<li><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7709\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Thin-Lineart-Hacker-Or-Coder-I-225854374-300x300.jpg\" alt=\"A Mysterious Russian Grey-Hat Vigilante has patched over 100,000 routers\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Thin-Lineart-Hacker-Or-Coder-I-225854374-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Thin-Lineart-Hacker-Or-Coder-I-225854374-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Thin-Lineart-Hacker-Or-Coder-I-225854374-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Thin-Lineart-Hacker-Or-Coder-I-225854374.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>2014 \u2013 A grey hat hacks thousands of Asus routers and planted text warnings about files that were left exposed and reminding users to patch.<\/li>\n<li>2015 \u2013 A group of grey hats, ironically called the White team, releases a piece of malware that closes security holes in several models of Linux routers.<\/li>\n<li>2017 \u2013 A grey hat releases a piece of malware that punishes people for not patching their IOT devices by either deleting firmware or bricking them.<\/li>\n<li>2017 \u2013 A grey hat makes over 150,000 printers print a message to their owners about the dangers of leaving your printer exposed online.<\/li>\n<li>2018 \u2013 Another grey hat renames thousands of MikroTik and Ubiquiti routers \u201cHACKED\u201d to scare their owners into updating them.<\/li>\n<\/ul>\n<p>So is grey hat hacking ethical? Again, it depends on your outlook, but from the standpoint of legality, Alexey isn\u2019t exactly abiding the law. It\u2019s illegal to access someone else\u2019s computer or devices without authorization. And while Eastern Europe and Russia may have a more relaxed attitude about this kind of activity, there are plenty of cases in the US where antiquated laws and overzealous prosecutors have thrown the book at someone for activity far more trivial than this. This is almost the equivalent of breaking into someone&#8217;s house to fix their deadbolts and alarm system. Thanks, but you broke into my house.<\/p>\n<p>So, ethical? Maybe. Legal? Definitely not.<\/p>\n<p><em>As always, leave any comments or questions below\u2026<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7276\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" width=\"1559\" height=\"407\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w\" sizes=\"auto, (max-width: 1559px) 100vw, 1559px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hacking to help \u2013 and not everyone appreciates it. In the interest of keeping things light on a Friday, let\u2019s turn our attention to a fascinating story that was first&#8230;<\/p>\n","protected":false},"author":6,"featured_media":7710,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[337],"class_list":["post-7707","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-hacking","post-with-tags"],"views":31933,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Back-Panel-Of-Router-With-Sock-248512471.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=7707"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7707\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/7710"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=7707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=7707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=7707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}