3 ms·
There is a chance you might’ve been hacked. You would be surprised to see how easy it is to hack domestic routers. 1. Find and disinfect the devices, includin
by DethNinja 4y ago
There is a chance you might’ve been hacked.
You would be surprised to see how easy it is to hack domestic routers.
1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router.
2. Use 30 character long random password on the router.
3. Disable UPnP.
4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well, especially IOT ones.
- malfist 4y agoWhy would you disable UPnP? You're gonna break most collaboration tools/video games/etc.
- kunwon1 4y agoDisabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it
- d2wa 4y agoIt’s absolutely required for most multiplayer games. Many need random ports and some even refuse to work if UPnP is blocked even if you manually open a port for them.
- aaronmdjones 4y agoI've never had UPnP enabled and I don't have any problems doing online gaming / flight sim / video chatting / etc.
- emikulic 4y agoSame. I've found the biggest problem was SNAT rewriting the (source) port number. netfilter, by default, doesn't do this. pf does but you can configure it not to.
- Zizizizz 4y agoOn series X you can set up port forwarding really easily. I had to do it for openwrt
- malfist 4y agoWhat's your solution for the grandmother who just wants to make a zoom call to her grandson? Have her log into her router portal and setup a static ip for her laptop and then port forwarding routes for zoom?
- Karrot_Kream 4y agoSTUN servers? Also, while I (not GP) do think UPnP is dangerous, I also think it's only something you disable if you know you can live without.
- thayne 4y agoI don't think zoom uses UPnP. If it did, that would cause problems on corporate networks that typically have UPnP disabled.
- zinekeller 4y agoTo be frank, that's exactly the problem with NAT-PMP et al. assuming that there's no router bugs: the ability to forward ports has been abused to set up bot relays on hacked IoT devices. This is why I predict that even in IPv6 era we would still have to rely on a TURN-equivalent.
- malfist 4y agoThat's exactly the problem with NAT-PMP? So what's your alternative for peer to peer connections? Static routing that the common end user can't figure out? Re-centralize connections? UPnP is necessary.
- zinekeller 4y agoI'm simply pointing the problem, a real-world an realistic problem, and you're acting like it's a non-issue. Point me a CGNATted network which has enable port forwarding. Does it break a lot of things? Oh, absolutely. Did the carriers still not activated it? Yes. Automatic port forwarding is only beautiful when you know how would your device react. It's ugly when you're a network administrator who don't control all devices. There is no "perfect" solution here because the real world is a messy place with devices that you cannot personally vouch for.
- deleted 4y ago[deleted]
- mh- 4y agoMy assumption is also that something on his network is compromised, and getting his IP into reputation issues. Tarpitting (serving content slowly from the edge, in order to slow down bots) is necessarily one of the most expensive tools in a WAF/CDN's toolbox. It's much more likely that something on his network is sending sketchy traffic to CF-fronted/Google sites, and the slow loading he's experiencing elsewhere is because his upstream is being saturated by whatever is happening on his network.
- d2wa 4y ago(Author here.) My router isn’t a domestic router. It’s a MikroTik running RouterOS, completely unsupported by the ISP. Outgoing connections and DNS is logged. UPnP is only allowed for the Xbox, PS4, and off-most-of-the-time gaming PC. Nothing out of the ordinary in the logs.
- alexforster 4y ago> It’s a MikroTik running RouterOS https://google.com/search?q=mikrotik+botnet https://google.com/search?q=mikrotik+botnet These things are the absolute scourge of the internet.
- d2wa 4y agoThey're a powerful tool that lets you shopt off your foot and half your brains with the same bullet. However, this my router isn't compromised. MikroTik routers can easily be misconfigured to be insecure or misbehave. It's a Cisco clone, so that is the product you're buying. I don't recommend them to anyone who doesn't enjoy and are familiar with the lower-level intricacies of network operations.
- aaronmdjones 4y ago> It’s a MikroTik running RouterOS It's almost certainly compromised.
- d2wa 4y agoNo. It isn't.