Nový worm infikující DSL modem/routery

Problematika připojení - hardware i software.

Moderátor: Don

Odpovědět
Shit
Odborník PCT
Odborník PCT
Uživatelský avatar
Registrován: 20. pro 2003
Bydliště: Hradec Králové

Nový worm infikující DSL modem/routery

Příspěvek od Shit »

http://apcmag.com/Content.aspx?id=3687
A new botnet, “psyb0t” is the first known to be capable of directly infecting home routers and cable/DSL modems.

It is suspected that the botnet originated in Australia, as the first activity from the botnet was detected here. Australian IT consultant Terry Baume first observed it infecting a Netcomm NB5 modem/router. You can read his full analysis here.

The botnet binary was further analysed by members of the website DroneBL (a real-time IP tracker that scans for and botnets and vulnerable machines) which came to the conclusion that the “psyb0t” or "Network Bluepill" botnet was mostly a test run to prove the technology. After the botnet's discovery and public outing, the botnet operator swiftly shut it down.

The first generation targeted very few models of router, though the current, most recently discovered generation (dubbed 'version 18' in the code) targets a wide range of devices.

The malware contains the shellcode for over 30 different Linksys models, 10 Netgear models, and a variety of other cable and DSL modems (15 different shellcodes)...
Odpovědět

Zpět na „Sítě, modemy a Internet“