본문 바로가기
IT 보안소식

모뎀에서도 botnet이 활동하고 있다.

by 잡다한 처리 2009. 3. 24.
반응형
홈라우터를 이용하여 모뎀에서도 botnet이 퍼져 현재 10만개 이상의 호스트를 공격한다고 한다.

무섭다 ㅡ.ㅡ; 자세한 내용은 원문으로 확인하시길...

원문보기 : http://www.theregister.co.uk/2009/03/24/psyb0t_home_networking_worm/

Worm breeds botnet from home routers, modems More than 100,000 hosts invaded

By Dan Goodin in San Francisco • Get more from this author

Security researchers have identified a sophisticated piece of malware that corals consumer routers and DSL modems into a lethal botnet.

The "psyb0t" worm is believed to be the first piece of malware to target home networking gear, according to researchers from DroneBL, which bills itself as a real-time monitor of abusable internet addresses. It has already infiltrated an estimated 100,000 hosts. It has been used to carry out DDoS, or distributed denial of service, attacks and is also believed to use deep-packet inspection to harvest user names and passwords.

"This technique is one to be extremely concerned about because most end users will not know their network has been hacked, or that their router is exploited," the DroneBL researchers wrote here. "This means that in the future, this could be an attack vector for the theft of personally identifying information. This technique is not going away."

Vulnerable devices include any home router or modem that uses Linux Mipsel, has an administration interface, sshd, or telnet in a DMZ, and employs a weak password. Once the malware takes hold, it locks legitimate users out of the device by blocking telnet, sshd, and web access. It then makes the devices part of a botnet. The researchers said they first learned of the worm while investigating DDoS attacks that hit DroneBL's infrastructure two weeks ago.

The worm also helps identify exploitable phyMyAdmin and MySQL servers. More information about psyb0t is available from this research paper (PDF) published in January

댓글