republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » New Botnet Targets Routers, Dumb People » Nothing is sacred...
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« yes people are dumb but: don't blame the victims  
AuthorAll Replies


Eat Me

join:2002-09-25
Sussex, NJ
reply to S_engineer
Re: Nothing is sacred...

It's our plug and play culture. People just want to plug in things and have them work.

Security? What's that?

PapaMidnight

join:2009-01-13
Baltimore, MD

said by Eat Me See Profile :

It's our plug and play culture. People just want to plug in things and have them work.

Security? What's that?
Heh, 5 networks in range of me at home are still carrying the SSID's:
linksys
d-link
belkin
eHome


Noah Vail
Premium
join:2004-12-10
Lorton, VA
·RoadRunner Cable

Nothing is scared...

There is no evidence that an available SSID causes any significant security risk, in and of itself. It's weak or non-existent encryption; weak or non-existent passwords that make or break a routers security.

I manage dozens of routers that fall squarely in the zone for this bot. They're all running dd-wrt. I use MAC filtering and TPIK enhanced WPA2. My passwords are sufficiently strong, so I don't worry about having telnet and http access available via the web/LAN.

They're not going to get infected by this thing; not one.

However, I'm tempted to throw one out there as a honeypot so I can get a look at this bug.

The interesting thing will be how we deal with it. With a PC virus, we update our virus defs and maybe scan the system. Then we forget about it.

With this, we'd have to update the firmware, to either treat or prevent infection. That will mean having to enter our settings from scratch. That's a pain.

For giggles I stopped by the dd-wrt forums to see what they make of the bug and I found a grand total of 1 thread w/ 2 posts; neither by a mod. I had hoped for something a bit more proactive. Perhaps after enough news blurbs connecting their firmware with the bot, they'll feel a bit more attentive.

NV
--
In my perfect religion, a giant hole appears and sucks up all the lousy people.
I call it the Crapture.


DJMASACRE

join:2008-05-27
Nepean, ON
·TekSavvy Solutions..
·Bell Sympatico

reply to Eat Me
Re: Nothing is sacred...

said by Eat Me See Profile :

It's our plug and play culture. People just want to plug in things and have them work.

Security? What's that?
ya just like... watching stupid tv shows without actually thinking about if its actually a good show.


TomClancy
Freedom isn't free

join:2003-04-23
...
reply to Noah Vail
Re: Nothing is scared...

DD-WRT makes you change your password and your username before you can change any settings in the router.
--
Freedom isn't free!


sivran
Long Live The Suite
Premium
join:2003-09-15
Arlington, TX
clubs:
reply to Noah Vail
I think his point was the owners never bothered to change the defaults. We all know SSID hiding and MAC filtering are useless.


Eat Me

join:2002-09-25
Sussex, NJ
·PenTeleData
·Future Nine Corpor..
·VOIPo
·Vonage


1 edit
reply to Noah Vail
said by Noah Vail See Profile :

There is no evidence that an available SSID causes any significant security risk, in and of itself. It's weak or non-existent encryption; weak or non-existent passwords that make or break a routers security.
That is quite true. However, I believe his point was that one of the default SSIDs is usually a tip off that the router was never configured away from its default and is most likely still wide open.

Most non-savvy users will just buy a wireless router in a store, plug it in and once it works they're happy.

kpatz
MY HEAD A SPLODE
Premium
join:2003-06-13
Manchester, NH

reply to Noah Vail
said by Noah Vail See Profile :

The interesting thing will be how we deal with it. With a PC virus, we update our virus defs and maybe scan the system. Then we forget about it.

With this, we'd have to update the firmware, to either treat or prevent infection. That will mean having to enter our settings from scratch. That's a pain.
From what I've read, at present this malware doesn't touch the firmware, instead it loads into (volatile) RAM and runs from there; thus, it's gone as soon as you powercycle the router.

So, if something gets infected, just disconnect it from the WAN, powercycle it, then change the password to something stronger and/or disable telnet/ssh, plug it back in, and you're set.
--
To ISPs: Leave our ports alone! If I want ports blocked, I'll do it myself, thank you.


aefstoggaflm
Open Source Fan
Premium
join:2002-03-04
Bethlehem, PA
·Verizon Online DSL

 reply to TomClancy
said by TomClancy See Profile :

DD-WRT makes you change your password and your username before you can change any settings in the router.
That is half correct / half wrong.

In the newer ones it does. In the older ones, well you get the point...
--
Please use the "yellow (IM) envelope" to contact me and please leave the URL intact.
-
Forums » New Botnet Targets Routers, Dumb People« yes people are dumb but: don't blame the victims  


Thursday, 10-Dec 11:23:51 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [125] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [70] AT&T Hints At Usage-Based iPhone Data Pricing
· [66] Sprint Poised For A Turnaround?
· [66] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Cross Server Dungeon Experience [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· New Mediacom Email [Mediacom]
· Icecrown 5-man strats [World of Warcraft]
· Comcast refused to install 400' feet. [Comcast HSI]
· Battered Hilt Delimma [World of Warcraft]
· malware has been found hidden inside an Ubuntu screensaver [Security]
· ICC10 [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]