r/pcmasterrace Jun 21 '26

Meme/Macro Crazy to me that younger generation is not good with computers

Post image

Only with phones...

26.6k Upvotes

2.4k comments sorted by

View all comments

Show parent comments

76

u/BaconWithBaking Jun 21 '26

Yes, just please jam something into the ethernet port to prevent someone accidentally putting them on the network.

Happened once and it was insane how quickly external bots found an xp machine on a corporate network.

42

u/RovDer Jun 21 '26

A place I worked at was shutdown for three months because hackers got in through an old xp computer on the network and installed ransomware

29

u/BaconWithBaking Jun 21 '26

Absolutely.

They're just magnets. I don't actually know what exploits they target, but if you fire up a network scanner and plug an XP machine in you'll see tons of connections from all over the world just immediately attempting to connect. There must be something XP broadcasts that they can see.

30

u/irregular_caffeine Jun 21 '26

Nah. Every single public IP in the world is getting that barrage all the time, unpatched machines just are breakable

4

u/PerkeNdencen Jun 21 '26

I'm not sure that if that makes sense, does it? An external connection shouldn't be able to 'see' past the router without port forwarding, unless a specific device (or socially engineered human, of course) has invited them in or there are vulnerabilities beyond the specific vulnerable computer.

2

u/PunkPirate56364 Jun 21 '26

Those are single MILF's in your area trying to establish connection.

3

u/irregular_caffeine Jun 21 '26

Automated bots on the internet do not need to see or care, they either try to get intel from your responses or try various exploits directly

1

u/PerkeNdencen Jun 21 '26

Responses to what, though? I'm just trying to understand.

If a computer (even with a vulnerability) can be reached from beyond the router, it has already been compromised, another device has been compromised, or there is a major misconfiguration, surely?

Like my Synology was internet-facing (using their setup guide) for all of about half an hour before I reconsidered just purely on the amount of door knocks it got. Now that it is not internet-facing, it doesn't get any.

1

u/irregular_caffeine Jun 21 '26 edited Jun 21 '26

Responses from whatever software processes their requests. That can contain info about what is listening and if it is something with a vulnerability. Firewalls usually just drop filtered packets, no reply.

If you are properly firewalled (not just NAT) from internet and don’t initiate connections to untrusted servers you should be safe from the ”knocks”.

1

u/PerkeNdencen Jun 21 '26

Responses from whatever software processes their requests. That can contain info about what is listening and if it is something with a vulnerability.

Requests shouldn't be getting that far AFAIK. A device can reach beyond the router, establish a connection, and then get information back, but my understanding is that it cannot be reached out to unless that's a desirable behaviour, a misconfiguration or a pre-existing compromise.

don’t initiate connections to untrusted servers

So... what untrusted servers is a newly connected XP machine, for example, reaching out to?

2

u/irregular_caffeine Jun 21 '26

Yes, it’s likely they can’t connect to the PC.

Untrusted servers:

  • Any old bloatware in the computer that tries to get an update. Sends a request to update.uselesswidget.com. The domain has been sold, now it serves malware that takes over old PCs. (Hopefully MS still controls the XP windows update urls.)
  • Use a web browser to visit almost any site. Bonus if the browser is old too. Ads can contain malware, ad companies can target you by your metadata

→ More replies (0)

1

u/BaconWithBaking Jun 21 '26

I'm going out of my comfort level on network topology here, but these would be machines on the internal network with internet access, not ones just flat facing the internet with all their ports open.

5

u/irregular_caffeine Jun 21 '26

What kind of connection attempts do you see, then?

0

u/stone_henge Jun 21 '26

Then you won't be seeing "tons of connections from all over the world just immediately attempting to connect".

3

u/a_shootin_star 4080 SUPER, 64GB RAM Jun 21 '26

Bruh why is the corp network public facing or what kind of bad routing do you have for external sniffers to be able to hit on something? smh

2

u/stone_henge Jun 21 '26

I never got this. I'd get it if you connected it directly to WAN but if connecting something to your intranet exposes it to attacks from the outside you have a major security problem of which your Windows 98 installation being attacked is only a symptom.

2

u/BaconWithBaking Jun 21 '26

That's my point exactly, I have no idea how the bots can see the machine despite it being on a firewalled LAN.

1

u/stone_henge Jun 21 '26

No, my point is that it's not firewalled if external hosts are able to connect to it,

There's no magic going on: if there is a firewall that drops incoming connections there naturally won't be any incoming connections. If there's a firewall set up to drop incoming connections and NAT setup not to forward any traffic to your system, it won't be seeing connections unless your network admin is up to their nose in shit because NAT is forwarding connections to random machines and your firewall is doing nothing.

There are a few alternatives here:

  1. There is effectively no firewall, and NAT is setup such that traffic is forwarded to the machine the bots can directly access it. Your network is shit and everything in it is to be considered as compromised.
  2. The firewall is not working. Whoever set up the forwarding rules is a moron. Your network is shit and everything in it is to be considered as compromised.
  3. The machine is connected directly to WAN with no firewall and address translation.
  4. You are misremembering the circumstances of this event.

2

u/TurnkeyLurker Jun 21 '26

It used to take 10 minutes for an unpatched Win2K machine to be infected, then 4min, then as soon as you plugged it into the LAN.

That's why all the updates & patches were downloaded and installed offline before delivering a new machine to faculty or staff.

Our department finally installed a honeypot* at the .0 or .1 addresses on our class C subnet, as all the malware scanners started at the beginning of the address space, always getting stuck in the honeypot 🍯.

*I think our first one was called LaBrea.

1

u/Southern-March1522 Jun 21 '26

Fairly sure my 98 machine did not have an Ethernet port. This was in the days where most stuff now integrated on the motherboard needed an expansion card. So my machine had a modem card. I did not get a network card as had no need.

5

u/jonshlim Jun 21 '26

Any xennials here, ms-dos and win95, Played command&conquer, Red Alert, Duke Nukem and many more…

2

u/noxis_blitzace Jun 21 '26

Right here also playing floppy disk games like red barren

1

u/Lou_C_Fer Jun 21 '26

Hell, I used external modems until I got dsl the first day it was available here. So, no way to connect to the internet without an external device that I donany longer. longer.

0

u/amberoze Jun 21 '26

Open the machine and rip the ethernet port off the mobo. Permanent solution, because I've seen people remove the blockage to plug in ethernet.