Worm targets Linux routers
A new worm has been uncovered which targets routers based on the Linux operating system and makes them part of an IRC controlled botnet.
Category: News
Publish Date: Thu, 26 Mar 2009 12:45:13 +0000
Read more...
Source: bit-tech.net Feed
Description: Computer hardware, games and technology reviews and news
Worm targets Linux routers
Moderator: Forum Moderators
-
- Salmon Ninja Pirate Gayer
- Posts: 1215
- Joined: December 13th, 2006, 14:27
-
- Morbo
- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
I'm kind of glad that 90% of people out there are lazy or ill-informed. That means that all but the most determined virus-writers will go for techniques that are easily preventable. Still, even though I've changed the default password on my router, the thought of something brute forcing it and leaving me faced with bricking it or giving away account details gives me the fear.
-
- Shambler In Drag
- Posts: 780
- Joined: March 16th, 2007, 20:22
- Location: on the sofa
- Contact:
I'm with dogpants about the lazy and illinformed - it helps a lot.
I don't tend to worry about bruteforce techniques though as I generally don't even allow connection to router logons from unknown IP's.
Most people only log in from a select number of IP's, and if you are unfortunate to be on DHCP, finding out your ISP's IP range and limiting connection to that eliminates 99.99% of the net, particularly the nasty bits.
If someone does get in, you should have their time & IP - and being UK you at least have some chance of causing hassle on the IP that attacked you (or at least fixing it if it is also broken and simply a proxy)
I don't tend to worry about bruteforce techniques though as I generally don't even allow connection to router logons from unknown IP's.
Most people only log in from a select number of IP's, and if you are unfortunate to be on DHCP, finding out your ISP's IP range and limiting connection to that eliminates 99.99% of the net, particularly the nasty bits.
If someone does get in, you should have their time & IP - and being UK you at least have some chance of causing hassle on the IP that attacked you (or at least fixing it if it is also broken and simply a proxy)