Reply to topic  [ 1 post ] 
Router Botnet 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
http://www.heise.de/ct/artikel/Aufstand ... 60334.html (German extract, full article behind paywall)

Routers running unpatched WRT software (Asus, Linksys, TP-Link, Bufallo among others) are susceptible to a botnet. The botnet uses a hole that WRT closed a while back, but most router manufacturers haven't gotten around to implementing the fix, even in new routers, let alone updating old routers.

It slips in a script (/ etc / init.d / rcS (withouth the spaces, the forum objects), which is in the Linux equivalent of the Autostart folder in Windows) and a command (dsniff) to sniff all packets going through the router. This means that it affects all traffic on the network, regardless of whether it is a PC, a tablet or a smartphone. It can only affect routers accessible from the Internet side (open remote ports for http/https, which has a bug). Routers shouldn't be accessible from the Internet side anyway, so unless the manufacturer incorrectly configures the router or the user opens up the ports to the outside world, there shouldn't to many problems.

That said, c't used the Shodan search engine to look for affected routers and they found over 25,000 devices.

They also managed to get (legal) access to a few infected routers and could trace the botnet back to two servers that were still active, one in Estonia and one by 1&1 in Germany, is being investigated by the LKA Niedersachsen (Lower Saxony state police).

Edit: sorry, the botnet owners stopped using the 1&1 server in August, the LKA didn't take it down. They had taken over the server by getting the credentials of the owner over his hijacked router. The owner of the server was innocent, they just set up an anonymous dropbox for collated data on his server.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Mon Sep 30, 2013 4:11 am
Profile ICQ
Display posts from previous:  Sort by  
Reply to topic   [ 1 post ] 

Who is online

Users browsing this forum: No registered users and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.