Home » 

UK ISP News Archives

 » 
Sponsored Links

Worm Turns ISP Broadband Routers Into Malicious Botnets

Posted: 24th Mar, 2009 By: MarkJ
Anti-Virus firms have issued warnings about a new self-replicating computer program (worm) known as Psyb0t, which has the unique ability to turn home broadband routers and certain ADSL modems into Botnets. Such botnets are generally malicious and can be used to propagate a virus, distribute spam, attack other systems (DDoS) and or for stealing your personal data.

The worm itself goes straight for the router and attempts to gain access using a combination of bruteforce username/password attempts, harvested usernames and passwords through deep packet inspection (dpi) and can also scan for vulnerable phpMyAdmin and MySQL servers running over a network:

You are only vulnerable if:
•Your device is a mipsel device [some flavours of embedded linux].

•Your device has telnet, SSH or web-based interfaces available to the WAN.

•Your username and password combinations are weak, OR the daemons that your firmware uses are exploitable.
As such, 90% of the routers and modems participating in this botnet are participating due to user-error (the user themselves or otherwise). Unfortunately, it seems that some of the people covering this botnet do not understand this point, and it is making us look like a bunch of idiots.

Any device that meets the above criteria is vulnerable, including those built on custom firmware such as OpenWRT and DD-WRT. If the above criteria is not met, then the device is NOT vulnerable.

Further details:
http://www.dronebl.org/blog/8

It's understood that up to 100,000 routers could have been infected by the worm, which also blocks ports 22, 23 and 80 as part of the infection process (80 is used for http, web browsing) and locks you out of the router. Those that suspect their routers of being compromised should perform a HARD RESET to get rid of the rootkit. This is not to be confused with a soft reset or reboot (consult your manual).
Search ISP News
Search ISP Listings
Search ISP Reviews
Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
100Mbps
Gift: None
Hyperoptic UK ISP Logo
Hyperoptic £22.00 - 25.00
158Mbps
Gift: None
Youfibre UK ISP Logo
Youfibre £23.99
150Mbps
Gift: None
Vodafone UK ISP Logo
Vodafone £25.00
150Mbps
Gift: None
Sky UK ISP Logo
Sky £25.00
145Mbps
Gift: None
Large Availability | View All
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £19.00
300Mbps
Gift: None
Community Fibre UK ISP Logo
100Mbps
Gift: None
BeFibre UK ISP Logo
BeFibre £19.00
150Mbps
Gift: None
Hyperoptic UK ISP Logo
Hyperoptic £22.00 - 25.00
158Mbps
Gift: None
toob UK ISP Logo
toob £22.00
150Mbps
Gift: None
Large Availability | View All
Sponsored Links
The Top 15 Category Tags
  1. FTTP (6288)
  2. BT (3727)
  3. Politics (2836)
  4. Business (2548)
  5. Openreach (2475)
  6. Building Digital UK (2401)
  7. Mobile Broadband (2251)
  8. FTTC (2102)
  9. Statistics (1989)
  10. 4G (1900)
  11. Virgin Media (1857)
  12. Ofcom Regulation (1641)
  13. Fibre Optic (1509)
  14. Wireless Internet (1507)
  15. 5G (1505)
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms  ,  Privacy and Cookie Policy  ,  Links  ,  Website Rules