Will a router stop these kinds of threats?

  • DNS Benchmark v2 Release 5 with Consultant License
    Guest:
    If you own any earlier release of our DNS Benchmark you may immediately download its release #5 replacement. Running an earlier release will detect the new release and help you upgrade.

    Although this release is cosmetic, appearance matters and affects ease of use. The biggest change, as seen in the image above, is that the DNS Benchmark now has a traditional Windows application menu to more fully expose its many features. This release is also "Consultant License Aware" and GRC will now issue a Consultant version when owners have previously purchased four "Personal Use" licenses. If you have previously purchased four DNSB licenses, or if you wish to upgrade your "Personal Use" license to Consultant, GRC's purchase process will direct you through that process.
    /Steve.
  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in please checkout the “Tips & Tricks” page for some very handy tips!

    /Steve.
  • BootAble – FreeDOS boot testing freeware

    To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.

    GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.

    The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.

    You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.

    (You may permanently close this reminder with the 'X' in the upper right.)

JorgeA

Well-known member
Dec 4, 2023
63
3
The AskWoody newsletter posted a piece today discussing how the rise of AI is rendering traditional anti-virus software ineffective. The author writes that

Most hackers now get into your computing environment by using stolen credentials, vulnerable supply chains, and easy-to-infect Internet of Things (IoT) firmware.

My question for the forum here is: wouldn't a stealthed system as per Steve's ShieldsUP! be well protected from attacks against IoT devices?

More generally, I sense a high degree of alarmism in the article, especially considering that to address the threat he recommends EDR solutions that are not only very expensive, but also seem to require an amount of expertise that's way beyond the capabilities of most home users. However, it's possible that my B.S. detector isn't working properly in this case.

Thanks for your thoughts.
 
  • Like
Reactions: PaulH
attacks against IoT devices?
Depends on how the IoT device is vulnerable. If it can be sent some message by proxy or from the HQ that makes it do things you wouldn't want it to be doing, then it will be doing that bad thing on the network it exists on, which would whatever network of yours you have put the device into. It might be possible to corrupt a DNS entry and redirect the device to a place other than HQ, and then come under control of the bad guys. It might have open WiFi or Bluetooth of its own and a drive by attacker might take advantage of that to corrupt it in some way to start doing bad things, or to redirect it to a new controlling HQ that then starts attacking. I'm sure there are other approaches I can't immediately think up.
 
Depends on how the IoT device is vulnerable. If it can be sent some message by proxy or from the HQ that makes it do things you wouldn't want it to be doing, then it will be doing that bad thing on the network it exists on, which would whatever network of yours you have put the device into.
Thanks for that. Would I be right to think that the scenario you describe in the quote, would mean that the server for the IoT device's manufacturer was compromised, as opposed to the user's device being compromised directly?
 
would mean that the server for the IoT device's manufacturer was compromised
That's certainly one option. Think of the supply chain attacks that Steve has mentioned in the past. If the attackers can get some malware into the network of the device manufacturer, perhaps they can add their payload into a new firmware build that gets pushed out to your device. Or perhaps they can exfiltrate keys for the device, and build and deliver their own firmware by some other means (corrupting a DNS entry for example.) It's unfortunate that for the bad guys there are just so many ways to "break" things, but for us good guys, we need everything to always work to plan to stay safe.
 
Thanks again, that was helpful. Yeah, as they say, a chain is only as strong as its weakest link.
 
Might not stop some threats (hard-coded credentials, bad authentication code, etc.), but having the router have some intrusion detection, and blacklist might help. Also blocking all new outside connections would help some. Nothing is 100% reliable, but might reduce some of the lesser attacks
 
Thanks, that jibes with what I've been reading.

So it sounds like stealth ports are far from a complete solution. My concern reading the article in AskWoody was that the writer is claiming that consumer-level security solutions are inadequate to protect from the expected flood of AI-driven attacks, and instead recommends that home PC users purchase enterprise-level EDR platforms, with all the expense and expertise that such an approach requires, and I have to wonder (a) how practical this advice could be in the real world, as well as (b) if there are simple and inexpensive but effective solutions for home users.

Not sure if Steve has addressed this topic yet, I'm a little behind my Security Now listening.
 
I purchased a MikroTik RouterBoard hexS router and used Claude as the tutor for setup. Latvia is part of the EU, and the processor is made by the Taiwanese company MediaTek.
✅ You get enterprise-grade networking features
✅ CLI commands are MikroTik-specific (not standard Linux)
✅ Configuration is saved in RouterOS format
✅ You have tight hardware-OS optimization

I'd be interested in opinions. And I've forgotten most of what I learned, but I don't leave WinBox open.