PDA

View Full Version : psyb0t



ivze
March 24th, 2009, 02:44 PM
It has been reported in some articles, that very new kind of malware has been detected on the Internet: worm, called psyb0t, that attacks home user routers. The articles (sharing much common, despite I am not sure, which is the orign of which) can be seen here:
http://snapvoip.blogspot.com/2009/03/psyb0t-botnet-targeting-wireless.html
http://www.irc-junkie.org/2009-03-22/psyb0t-a-stealthy-router-based-botnet-discovered/

IMHO, the target needs being discussed.

One more link: http://www.dronebl.org/blog/8

Naiki Muliaina
March 24th, 2009, 02:51 PM
Thanks for the heads up

Giant Speck
March 24th, 2009, 03:33 PM
I'm glad I don't use a router. :)

MikeTheC
March 24th, 2009, 03:38 PM
I wonder the extent to which DD-WRT is impacted by this...

Icehuck
March 24th, 2009, 03:47 PM
I'm glad I don't use a router. :)

Just using a router has nothing to do with it. I use a router but I am not able to be affected by this.

You are only vulnerable if:

* Your device is a mipsel device.
* Your device has telnet, SSH or web-based interfaces available to the WAN
* Your username and password combinations are weak, OR the daemons that your firmware uses are exploitable.

I do not have telnet, ssh, or web-based interfaces available to the WAN connection. Which most users will not have turned on if they use the defaults on their routers. However, if you do have these interfaces available to the WAN then you are an idiot if you use weak passwords.


I wonder the extent to which DD-WRT is impacted by this...

They are just as vulnerable as any other router if the above criteria is met.

solitaire
March 24th, 2009, 03:54 PM
Glad my Router won't be affected.
It has the web interface turned on and no password set up for it.....

But it's been sitting in the corner un-plugged for the past month...:D:D

Go 3G dongle!!!! :D