"Chuck Norris" Bot Infects Routers and DSL Adapters

Αναδημοσιεύσεις άρθρων και κειμένων που βρήκατε κάπου αλλού και θέλετε να μοιραστείτε μαζί μας .
Post Reply
User avatar
cypher
Venus Former Team Member
Posts: 6207
Joined: Mon Sep 29, 2008 9:12 pm
Academic status: Alumnus/a
Gender:

"Chuck Norris" Bot Infects Routers and DSL Adapters

Post by cypher » Tue Feb 23, 2010 11:25 am

Image
Czech researchers have uncovered a botnet running on broadband routers and DSL adapters. Click here for the original Czech report.

The research was the work of Jan Vykopal, head of the security project of Masaryk University, along with experts from the Brno Military Academy and the Defence Ministry. They said the main purpose of the botnet was to steal the usual sensitive data: bank accounts, e-mail inboxes, etc. Vykopal added that the botnet could be used for attacking other systems.

Botnets on devices like this are not new. I wrote about a very similar one almost a year ago. Research on the threat goes back further; it was brought up in 2007 by researcher and big-game botnet hunter Gadi Evron a couple of articles on CircleID.

This bot, named "Chuck Norris" for a comment in the source code referring to the American actor, star of many action films and Walker, Texas Ranger on TV. Like "psyb0t" from a year ago it attacks devices remotely by guessing at default passwords and can infect devices based on MIPS chips running Linux. The botnet covers Europe and South America and reaches into China. In an e-mail interview with IDG's Bob McMillan, Vykopal said that the bot also exploits a known vulnerability in certain D-Link Systems devices.

Compromising a router has advantages for an attacker: by being connected directly to the broadband network you are not blocked by any security software on the PCs; users don't update software often on routers; and you are closer to the network itself. But there are disadvantages: and power-cycling the router probably removes the bot. It's technically feasible for the bot to write itself to firmware, but there's no evidence any of them are doing this. A bot at the router could also be used as an infection vector for systems inside it.

As to the claim of the bot being used to steal confidential data, how that works can be tricky. A conventional bot on the PC can just monitor the keyboard for the data, but if the session is SSL-protected then a router-based bot will only see encrypted packets. The better way to execute an attack from a bot would be to use the fact that the router is a DNS proxy for the local network and redirect users to false sites, but this can be detected by many different methods.

Evron noted in his 2007 articles that ISPs would not do anything about the problems of weak security in broadband gateway devices until they had to. Perhaps this is the time they have to do something.
Πηγη:
http://blogs.pcmag.com/securitywatch/20 ... _route.php
ImageImageImageImageImageImageImage
User avatar
cypher
Venus Former Team Member
Posts: 6207
Joined: Mon Sep 29, 2008 9:12 pm
Academic status: Alumnus/a
Gender:

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by cypher » Tue Feb 23, 2010 11:27 am

:smt066
Image
ImageImageImageImageImageImageImage
The Punisher
Venus Former Team Member
Posts: 7561
Joined: Thu Oct 27, 2005 1:43 pm
Academic status: Alumnus/a
Gender:
Location: Boston, MA

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by The Punisher » Tue Feb 23, 2010 11:48 am

και πως μαθαίνεις αν είσαι infected ?
User avatar
Loner
Venus Former Team Member
Posts: 4004
Joined: Fri Oct 26, 2007 11:08 pm
Academic status: N>4
Gender:
Location: Στη ρωγμή του χρόνου

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by Loner » Tue Feb 23, 2010 11:50 am

Τώρα πλέον το ξέρεις...Είσαι :smt016
You either die a Spongebob or live long enough to see yourself become the Squidward.
User avatar
cypher
Venus Former Team Member
Posts: 6207
Joined: Mon Sep 29, 2008 9:12 pm
Academic status: Alumnus/a
Gender:

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by cypher » Tue Feb 23, 2010 11:51 am

The Punisher wrote:και πως μαθαίνεις αν είσαι infected ?
Yποθετω κοιτωντας αν εχεις αλλαγμενους dns η password και αν η απομακρυσμενη διαχειριση στο μοντεμ ειναι off οπως θα επρεπε. Αλλα απο οτι λεει το bot τρωει πορτα με το που κανεις reboot το μοντεμ. Το ζητημα ειναι τι εχει δει μεχρι τοτε ο Τσακ και πως θα χρησιμοποιησει αυτα τα στοιχεια. :shock:
ImageImageImageImageImageImageImage
User avatar
stoupeace
Wow! Terabyte level
Wow! Terabyte level
Posts: 5372
Joined: Tue Aug 26, 2008 4:08 pm
Academic status: High school
Gender:

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by stoupeace » Tue Feb 23, 2010 11:54 am

cypher wrote:
The Punisher wrote:και πως μαθαίνεις αν είσαι infected ?
Yποθετω κοιτωντας αν εχεις αλλαγμενους dns η password και αν η απομακρυσμενη διαχειριση στο μοντεμ ειναι off οπως θα επρεπε. Αλλα απο οτι λεει το bot τρωει πορτα με το που κανεις reboot το μοντεμ. Το ζητημα ειναι τι εχει δει μεχρι τοτε ο Τσακ και πως θα χρησιμοποιησει αυτα τα στοιχεια. :shock:
O OTE και το Conn-X εχουν προβλέψει για αυτή την απειλή. Το router χρειάζεται κάθε 2 ώρες restart.

Recognition, finally :smt023
Η καλύτερη μπάντα όλου του κόσμου: Sonata Antartika
Mpomp is building an army army. And I got my head back.
░░░░░███████ ]▄▄▄▄▄▄▄▄
▂▄▅█████████▅▄▃▂ ____☻/︻╦╤─
Il███████████████████]. /▌
_◥⊙▲⊙▲⊙▲⊙▲⊙▲⊙▲⊙◤.. . / \
The Punisher
Venus Former Team Member
Posts: 7561
Joined: Thu Oct 27, 2005 1:43 pm
Academic status: Alumnus/a
Gender:
Location: Boston, MA

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by The Punisher » Tue Feb 23, 2010 12:01 pm

χαχαχαχ :lol:
User avatar
zweistein
Wow! Terabyte level
Wow! Terabyte level
Posts: 4537
Joined: Sun Oct 15, 2006 10:49 pm
Gender:
Location: in your computer
Contact:

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by zweistein » Wed Feb 24, 2010 7:59 pm

cypher wrote::smt066
Image
downloading pron?? rather than porn? lol
Image
User avatar
cypher
Venus Former Team Member
Posts: 6207
Joined: Mon Sep 29, 2008 9:12 pm
Academic status: Alumnus/a
Gender:

Re: "Chuck Norris" Bot Infects Routers and DSL Adapters

Post by cypher » Wed Feb 24, 2010 8:16 pm

zweistein wrote:
cypher wrote::smt066
downloading pron?? rather than porn? lol
Γνωστη παραλλαγη, νομιζω απο 4chan. :-p
ImageImageImageImageImageImageImage
Post Reply

Return to “Αναδημοσιεύσεις”