Advertisement
Promo

Security threats Toolkit

Worm targets Linux home routers

Tom Espiner ZDNet.co.uk

Published: 25 Mar 2009 13:06 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A worm has been used to build a botnet consisting of DSL routers running Linux, which may be still evolving, according to security training organisation the Sans Institute.

After becoming infected, the network of routers was used to launch a denial-of-service attack earlier in March against DroneBL, an organisation that maintains a DNS blacklist. Sans Institute handler GN White reported the issue in a blog post on Tuesday, noting that there was a chance the bot was "still evolving".

After analysing the worm, DroneBL researchers wrote in a blog post that, while a range of devices may be exploitable, devices are only vulnerable if they can run Mipsel, part of the Debian Linux distribution. To be vulnerable, devices must also have telnet-, SSH- or web-based WAN interfaces, and either weak username and password combinations or exploitable firmware, the researchers wrote.

The worm uses a brute-force dictionary attack to determine usernames and passwords. Once it has gained access to the device, it loads a Mipsel binary called psyb0t, which then scans a random IP range for vulnerable routers and modems. It also scans for vulnerable MySQL servers to infect.

DroneBL reported in its blog post that it had been the subject of a denial-of-service attack from a botnet consisting of at least 100,000 devices. The botnet appears to have been discontinued, according to IRC logs by 'DRS', who DroneBL said was the bot-controller.

The worm was first noted as psyb0t 2.5L in a paper by security researcher Terry Baume in January. The psyb0t iteration used to attack DroneBL was psyb0t 2.9L.


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
16 out of 16 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters