Forum Discussion

JCH1's avatar
JCH1
New Member
4 years ago

Mirai Botnet

There are multiple articles published saying the Hughesnet router HT2000W is vulnerable to the Mirai Botnet security issue.  The articles recommend getting a patch from the device provider or ISP.  When will Hughesnet have a patch or an update for our routers?  How can we get it?

  • Good morning folks,

     

    Thanks for the discussion! Just wanted to let you know that Arcadyan is addressing this matter and we are in touch with them. You'll hear from us on further updates.

     

    Your patience and understanding are much appreciated.

     

    Thanks,

    Liz

     

    Edit:

     

    In the meantime, wouldn't hurt to do an overall security check of your devices. Google periodically reminds me to review my security settings, would be good to apply the same to everything else. Here are some tips.

  • GabeU's avatar
    GabeU
    Distinguished Professor IV

    They're likely already looking into it.  

     

    If/when they release a patch, it will be done automatically.  

    • chuckyofterror's avatar
      chuckyofterror
      New Poster

      I am going to go out on a limb, and say that unless you have Static IP enabled on your account (Only SME accounts can do that, residential can't), then you should be OK for the time being, as no one can remotely access your terminals.  Those that do have an SME account with Static IP, could very well become impacted.

      Hmm, not sure why I posted under this account... -C0RR0SIVE

      • MarkJFine's avatar
        MarkJFine
        Professor

        For those that are curious about what it is and what it does this is pretty comrehensive: What is the Mirai Botnet? 

         

        I suspect that hackers trying to deploy this incrementally scan IPs looking for IoT devices via /HNAP1 or /thinkphp or /TP/public/index.php signatures. Once a target is found, they attempt to use default passwords to get control of it.

        As chuckyofterror (er, @C0RR0SIVE) mentioned, they cannot even get to the HN2000W modem on standard residential networks because of the double-NAT that's in-place. That is not the case with Business accounts with static IPs, which are accessible from the outside.

    • maratsade's avatar
      maratsade
      Distinguished Professor IV

      I hope a rep chimes in about this. 

       


      GabeU wrote:

      They're likely already looking into it.  

       

      If/when they release a patch, it will be done automatically.  


       

  • Good morning folks,

     

    Thanks for the discussion! Just wanted to let you know that Arcadyan is addressing this matter and we are in touch with them. You'll hear from us on further updates.

     

    Your patience and understanding are much appreciated.

     

    Thanks,

    Liz

     

    Edit:

     

    In the meantime, wouldn't hurt to do an overall security check of your devices. Google periodically reminds me to review my security settings, would be good to apply the same to everything else. Here are some tips.

    • Danny89's avatar
      Danny89
      Junior

      Glad to hear they are working on it! :D

      One thing I have a question about, or to make a statement on, wouldnt any exploiters need to be physically close to our modem in order to hack it, at least for residential users? That should be a great comfort for us if so :P Im pretty sure I'd have to make a huge wifi dish to broadcast my signal to my nearest neighbors!

      Obviously though, all security issues must be fixed since even if we are protected by the nature of geosynchronous satellite....some hacker could probably figure out how to exploit the exploit to exploit further exploits and start using our data to stream Amazon Prime at 9k USHD Mega and melt our modems down

      • maratsade's avatar
        maratsade
        Distinguished Professor IV

        Mark has already explained this in this thread and elsewhere.  I would guess that if someone is sitting on your driveway and you have a very weak password or are using the passwords that came with the device, they would be able to get in. 

         


        Danny89 wrote:


        One thing I have a question about, or to make a statement on, wouldnt any exploiters need to be physically close to our modem in order to hack it, at least for residential users?