Worm invades routers to build botnet
By Stuart Turton
Posted on 24 Mar 2009 at 14:17
Researchers claim to have identified a new type of worm that is hijacking routers and DSL modems to form a botnet.
Researchers at DroneBL claim the worm, called psyb0t, is the first of its kind and has infiltrated an estimated 100,000 devices.
According to a post on the DroneBL site, the botnet has already been used to carry out distributed denial-of-service attacks and is thought to have the ability to use deep-packet inspection to harvest user names and passwords.
Vulnerable devices include any home router or modem that uses Linux Mipsel, and has an administration interface, sshd, or telnet in a DMZ, and has a weak password.
DroneBL claims to have stumbled upon the worm after the botnet flooded its network infrastructure two weeks ago.
"This technique is one to be extremely concerned about because most end users will not know their network has been hacked, or that their router is exploited," says the DroneBL post.
"This means that in the future, this could be an attack vector for the theft of personally identifying information. This technique is not going away."
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
- Can you send a truly anonymous email?
- Is it safe to send bank details over email?
- Sainsbury's Bank bans password storage
- MobileMe triggers credit card blocks
- How to stay safe against session hijacking
advertisement
