Ehe... (broke someone's router)
Moderator: Thanas
Ehe... (broke someone's router)
I accidentally reflashed my neighbor's router w/ OpenWRT (unsecured, default password, accidentally left WLAN card on)... Should I just pretend nothing happened? I don't even know who he/she is or where is it, and attempting to reflash it again over the wireless is dangerous.... internet .seems to work, but the webif is different and less functional..
Anyway, I exchanged my v5 WRT54G router w/ a v4, and it's pretty sweet (more reliable than the v5, set up WPA-EAP on it- need to transfer the radius server from my real server to the router for additional reliability (server disconnects due to tripped over LAN cords kill all wireless connections))... The only thing I dislike is that OpenWRT does not come w/ an HTTPS secured web interface, and editing iptables scripts by hand is awful.
Anyway, I exchanged my v5 WRT54G router w/ a v4, and it's pretty sweet (more reliable than the v5, set up WPA-EAP on it- need to transfer the radius server from my real server to the router for additional reliability (server disconnects due to tripped over LAN cords kill all wireless connections))... The only thing I dislike is that OpenWRT does not come w/ an HTTPS secured web interface, and editing iptables scripts by hand is awful.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
- BloodAngel
- Padawan Learner
- Posts: 356
- Joined: 2005-05-25 10:47pm
- Location: DON'T GET TOO CLOSE OR ELSE!!!
You mean you accidentally thought your neighbor's router was yours? That's a weird event..
But anyway, morally speaking you probably should, but realistically speaking...don't ask, don't tell. Their fault for making their router that insecure, if you didn't do it someone else would've killed it sometime.
But anyway, morally speaking you probably should, but realistically speaking...don't ask, don't tell. Their fault for making their router that insecure, if you didn't do it someone else would've killed it sometime.
Blood Angel, the Hidden Name of Who You Know.
Zadius: "Done. I get turned on by shit. Nothin' else. "
Zadius: "Done. I get turned on by shit. Nothin' else. "
Bullshit. Leaving your front door unlocked doesn't make it your fault someone accidentaly entered your house thinking it was theirs.BloodAngel wrote: You mean you accidentally thought your neighbor's router was yours? That's a weird event..
But anyway, morally speaking you probably should, but realistically speaking...don't ask, don't tell. Their fault for making their router that insecure, if you didn't do it someone else would've killed it sometime.
Pu-239, own up to your mistake. You broke it, you fix it.
"If the facts are on your side, pound on the facts. If the law is on your side, pound on the law. If neither is on your side, pound on the table."
"The captain claimed our people violated a 4,000 year old treaty forbidding us to develop hyperspace technology. Extermination of our planet was the consequence. The subject did not survive interrogation."
"The captain claimed our people violated a 4,000 year old treaty forbidding us to develop hyperspace technology. Extermination of our planet was the consequence. The subject did not survive interrogation."
- Uraniun235
- Emperor's Hand
- Posts: 13772
- Joined: 2002-09-12 12:47am
- Location: OREGON
- Contact:
Uh, I can't- I don't even know who's it is. There are many different neighbors in the area. If I knew I'd have notified them ages ago about having an unsecured network in the first place (although there are asswipes who will think you've been hacking their network and press charges from another thread on this board...).Alyeska wrote:Bullshit. Leaving your front door unlocked doesn't make it your fault someone accidentaly entered your house thinking it was theirs.BloodAngel wrote: You mean you accidentally thought your neighbor's router was yours? That's a weird event..
But anyway, morally speaking you probably should, but realistically speaking...don't ask, don't tell. Their fault for making their router that insecure, if you didn't do it someone else would've killed it sometime.
Pu-239, own up to your mistake. You broke it, you fix it.
Should I go ahead and try reflashing it anyway, and risk bricking it?
It looks like some other idiot has set up yet another unsecured AP up... at least 6 unsecured in the area.
And the house scenario is pretty farfetched, since the houses must be in physically different locations.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
- Spanky The Dolphin
- Mammy Two-Shoes
- Posts: 30776
- Joined: 2002-07-05 05:45pm
- Location: Reykjavík, Iceland (not really)
Spyder: Nope- no access to any of the clients (and how would I know if they were wired?).
Not sure if it's even safe to upload a new flash over the OpenWRT web interface (right now they probably could care less, since most people don't bother enabling or even knowing what port forwarding and all the other settings are - they will notice if an attempt to reflash bricks it). I'm rather reluctant to attempt reflashing w/o physical access.
Apparently there is an option to download it to the RAM of the router and flash it from there, but then there may still be the bricking risks of me doing something stupid and flashing the wrong version in (I believe the firmware version was 4.20.6, since I checked mine in order to attempt to TFTP it over, which failed, which was when I used the web interface which caused this).
Should I just try this?
I suppose my options are:
A- Leave as is- it still works as an AP. If he/she notices, it can be flashable from the web interface (not sure how OpenWRT handles UPNP- checked the NVRAM, but it seems to have some stuff regarding that in it).
B- Attempt to reflash, and if that fails do C. Has a chance of needing to do C, and if that can't be done, he/she is even more fucked than if A was done.
C- contact my two immediately adjacent neighbors and attempt to explain to them (one of them already has somewhat of a grudge though against my extended family) immediately (it'd be somewhat odd to contact any of the others since I don't know them). Also, this opens up a legal can of worms, from what I gather from other postings about irate computer illiterates who think you are hacking and stealing whatever.
Not sure if it's even safe to upload a new flash over the OpenWRT web interface (right now they probably could care less, since most people don't bother enabling or even knowing what port forwarding and all the other settings are - they will notice if an attempt to reflash bricks it). I'm rather reluctant to attempt reflashing w/o physical access.
Apparently there is an option to download it to the RAM of the router and flash it from there, but then there may still be the bricking risks of me doing something stupid and flashing the wrong version in (I believe the firmware version was 4.20.6, since I checked mine in order to attempt to TFTP it over, which failed, which was when I used the web interface which caused this).
Should I just try this?
I suppose my options are:
A- Leave as is- it still works as an AP. If he/she notices, it can be flashable from the web interface (not sure how OpenWRT handles UPNP- checked the NVRAM, but it seems to have some stuff regarding that in it).
B- Attempt to reflash, and if that fails do C. Has a chance of needing to do C, and if that can't be done, he/she is even more fucked than if A was done.
C- contact my two immediately adjacent neighbors and attempt to explain to them (one of them already has somewhat of a grudge though against my extended family) immediately (it'd be somewhat odd to contact any of the others since I don't know them). Also, this opens up a legal can of worms, from what I gather from other postings about irate computer illiterates who think you are hacking and stealing whatever.
Last edited by Pu-239 on 2005-12-06 07:11am, edited 2 times in total.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
- Faram
- Bastard Operator from Hell
- Posts: 5271
- Joined: 2002-07-04 07:39am
- Location: Fighting Polarbears
To be safe choose number APu-239 wrote:Spyder: Nope- no access to any of the clients (and how would I know if they were wired?).
Not sure if it's even safe to upload a new flash over the OpenWRT web interface (right now they probably could care less, since most people don't bother enabling or even knowing what port forwarding and all the other settings are - they will notice if an attempt to reflash bricks it). I'm rather reluctant to attempt reflashing w/o physical access.
Apparently there is an option to download it to the RAM of the router and flash it from there, but then there may still be the bricking risks of me doing something stupid and flashing the wrong version in (I believe the firmware version was 4.20.6, since I checked mine in order to attempt to TFTP it over, which failed, which was when I used the web interface which caused this).
Should I just try this?
I suppose my options are:
A- Leave as is- it still works for it's purpose of acting as an AP for the internet.
B- Attempt to reflash, and if that fails do C. Has a decent chance of needing to do C, and if that can't be done, he/she is even more fucked than if A was done.
C- contact my two immediately adjacent neighbors and attempt to explain to them (one of them already has somewhat of a grudge though against my extended family) immediately (it'd be somewhat odd to contact any of the others since I don't know them). Also, this opens up a legal can of worms, from what I gather from other postings about irate computer illiterates who think you are hacking and stealing whatever.
You can get into plenty of trubble othervise.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
- Spyder
- Sith Marauder
- Posts: 4465
- Joined: 2002-09-03 03:23am
- Location: Wellington, New Zealand
- Contact:
Ah, good point. If they're newbies chances are none of them are wired.Pu-239 wrote:Spyder: Nope- no access to any of the clients (and how would I know if they were wired?).
Anyway, this may be a situation in which doing the right thing may require some deceit on your part.
Rather then tell your neighbors that you broke into their routers, simply tell them that someone in the area is running an unsecured wireless internet connection.
Non newbie response: "Oh shit, that's me. Thanks for the head's up."
Non newbie goes to fix his router, discovers that it needs reflashing, fixes it himself.
Newbie response: "I've got this thing that sends internet to my laptop, is that what you're talking about? There's something wrong with it though..."
Then you explain how having it the way it is means that anyone in the neighborhood could be using it which could cost him money.
"I don't really know how."
Offer to show him, say it won't take a second. If he agrees take a look at it "Hey what do you know, it needs reflashing. Good thing I stopped by..."
Now you're a hero going from door to door fixing people's routers and ridding them of pesky bandwidth theifs.
Good idea... however I've usually had difficulty convincing people to secure their networks- most simply express apathy (don't care if people steal bandwidth, believe that most people won't be malicious or f*ck something up, etc.). Anyway, broadband here is universally Cox (no DSL), and so it's flat rate anyway and doesn't cost them money, although there is a loosely enforced upload cap. I suppose one could claim theres the possiblity of creeps looking up illegal stuff...Spyder wrote:Ah, good point. If they're newbies chances are none of them are wired.Pu-239 wrote:Spyder: Nope- no access to any of the clients (and how would I know if they were wired?).
Anyway, this may be a situation in which doing the right thing may require some deceit on your part.
Rather then tell your neighbors that you broke into their routers, simply tell them that someone in the area is running an unsecured wireless internet connection.
Non newbie response: "Oh shit, that's me. Thanks for the head's up."
Non newbie goes to fix his router, discovers that it needs reflashing, fixes it himself.
Newbie response: "I've got this thing that sends internet to my laptop, is that what you're talking about? There's something wrong with it though..."
Then you explain how having it the way it is means that anyone in the neighborhood could be using it which could cost him money.
"I don't really know how."
Offer to show him, say it won't take a second. If he agrees take a look at it "Hey what do you know, it needs reflashing. Good thing I stopped by..."
Now you're a hero going from door to door fixing people's routers and ridding them of pesky bandwidth theifs.
People in the area are also leery of letting strangers in the house (I only know 3 of my neighbors- I might talk to them and ignore the rest - there has been a robbery earlier this year in the next townhouse unit. Also my sister is one of the bandwidth leachers... (sometimes uses it for large items instead of using our own due to aforementioned cap), so me getting it shut off will get me in trouble (although then she'll have no way of not paying half the cable bill if she doesn't feel like it, which is a good thing)).
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
- BloodAngel
- Padawan Learner
- Posts: 356
- Joined: 2005-05-25 10:47pm
- Location: DON'T GET TOO CLOSE OR ELSE!!!
That is why I put the whole suggestion under "realistically"; if Pu-239's neighbors happen to be the obstinate kind, they will just hear "I broke your router," and not "sorry, I can help fix it."Alyeska wrote:Pu-239, own up to your mistake. You broke it, you fix it.
It's a really big risk. Regrettable that such an event occurred, but trouble has to be avoided.
Blood Angel, the Hidden Name of Who You Know.
Zadius: "Done. I get turned on by shit. Nothin' else. "
Zadius: "Done. I get turned on by shit. Nothin' else. "
- Davis 51
- Jedi Master
- Posts: 1155
- Joined: 2005-01-21 07:23pm
- Location: In that box, in that tiny corner in your garage, with my laptop, living off Dogfood and Diet Pepsi.
That wasn't me, was it? Cause I got a Wireless Netgear, I live in Virginia, in an area where DSL is scarce (I was lucky to be in the range of DSL, barely.),
You don't happen to be in my area do you?
Just Kidding.
Anyways, Spyders suggestion seems to be the best.
You don't happen to be in my area do you?
Just Kidding.
Anyways, Spyders suggestion seems to be the best.
Brains!
"I would ask if the irony of starting a war to spread democracy while ignoring public opinion polls at home would occur to George W. Bush, but then I check myself and realize that
I'm talking about a trained monkey."-Darth Wong
"All I ever got was "evil liberal commie-nazi". Yes, he called me a communist nazi."-DPDarkPrimus
"I would ask if the irony of starting a war to spread democracy while ignoring public opinion polls at home would occur to George W. Bush, but then I check myself and realize that
I'm talking about a trained monkey."-Darth Wong
"All I ever got was "evil liberal commie-nazi". Yes, he called me a communist nazi."-DPDarkPrimus
Actually, I do live in VA (there are two unsecured NETGEARs btw in the neighborhood).Davis 51 wrote:That wasn't me, was it? Cause I got a Wireless Netgear, I live in Virginia, in an area where DSL is scarce (I was lucky to be in the range of DSL, barely.),
You don't happen to be in my area do you?
Just Kidding.
Anyways, Spyders suggestion seems to be the best.
But it was a Linksys.
ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer
George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor