read the forum (if you can stomach the asshattery) 5.6.2 had active infections changning passwords 5.6.6 (i think) was when they dropped the script support, but it was still writing the files, but was bricking the hell out of radios when it wasnt dumping links its up to 5.6.9 right now with a mysterious security fixes in the release notes ubnt fanboying on their handling of this isnt in order AFIK they still havent resolved the underlying vulnerability (you can still write files to the unit without credentialing in) they just blocked the mechanism for utilizing the payload
Im glad it happenned, it served two very good purposes, first it really brought to the forefront the importance of solid network management on "cost effective" networks (any network for that matter) and it was the ubnt nail in the coffin to phase out all ubnt M to epmp since historically and forward, UBNT will always be a risk to move to the latest "secure" firmware, considering the volume of issues between 5.6.4 and 5.6.9 and the number of customers lost due to the performance hits required for the "security" On Wed, Sep 7, 2016 at 9:17 PM, Mike Hammett <[email protected]> wrote: > No, it wasn't. 5.6.4 was out and 5.5.10u2, 5.5.11 and 5.6.2 were fine. > > > > ----- > Mike Hammett > Intelligent Computing Solutions <http://www.ics-il.com/> > <https://www.facebook.com/ICSIL> > <https://plus.google.com/+IntelligentComputingSolutionsDeKalb> > <https://www.linkedin.com/company/intelligent-computing-solutions> > <https://twitter.com/ICSIL> > Midwest Internet Exchange <http://www.midwest-ix.com/> > <https://www.facebook.com/mdwestix> > <https://www.linkedin.com/company/midwest-internet-exchange> > <https://twitter.com/mdwestix> > The Brothers WISP <http://www.thebrotherswisp.com/> > <https://www.facebook.com/thebrotherswisp> > > > <https://www.youtube.com/channel/UCXSdfxQv7SpoRQYNyLwntZg> > ------------------------------ > *From: *"That One Guy /sarcasm" <[email protected]> > *To: *[email protected] > *Sent: *Wednesday, September 7, 2016 8:08:11 PM > *Subject: *Re: [AFMUG] Ubnt password hack with public IP radios > > actually at the time of the last fiasco, the current firmware had been > vulnerable > > but how anybody is still getting hit by this is amazing to me > > On Wed, Sep 7, 2016 at 7:56 PM, Mathew Howard <[email protected]> > wrote: > >> They weren't necessarily backhauls... but a few firewall rules at the >> edge of the network and/or not running ancient firmware would have >> prevented it... >> >> On Wed, Sep 7, 2016 at 6:57 PM, Chris Wright <[email protected]> wrote: >> >>> This sums up the kind of person who programs a public IP into their >>> backhauls. >>> >>> http://25.media.tumblr.com/tumblr_m8d8vusNcL1qa9jn1o2_500.gif >>> >>> Chris Wright >>> Network Administrator >>> Velociter Wireless >>> 209-838-1221 x115 >>> >>> >>> -----Original Message----- >>> From: Af [mailto:[email protected]] On Behalf Of Josh Reynolds >>> Sent: Wednesday, September 07, 2016 4:47 PM >>> To: [email protected] >>> Subject: Re: [AFMUG] Ubnt password hack with public IP radios >>> >>> Yep, it was widely talked about on the forum, the Brothers WISP podcast, >>> and through direct emails from UBNT to customers who have basically ever >>> sent them a working email address for anything.... >>> amongst other places. >>> >>> https://community.ubnt.com/t5/airMAX-Updates-Blog/Important- >>> Security-Notice-and-airOS-5-6-5-Release/ba-p/1565949 >>> >>> >>> On Wed, Sep 7, 2016 at 6:42 PM, Jaime Solorza <[email protected]> >>> wrote: >>> > Seems like a local WISP got radios hacked and passwords changed. >>> Someone >>> > told him there is a virus that sniffs Ubnt radios with public IPs and >>> > changes password to Moth3rfuck3r or something like that. Supposedly a >>> > telnet script can remedy this matter.... Anyone know about this? Tak >>> >>> >>> >>> >> > > > -- > If you only see yourself as part of the team but you don't see your team > as part of yourself you have already failed as part of the team. > > -- If you only see yourself as part of the team but you don't see your team as part of yourself you have already failed as part of the team.
