Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Linksys » Linux embedded devices being used in botnet
Search Topic:
Uniqs:
1703
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Wireless] Internet issues with new router »
« [Wired] Help with port forwarding for my reps  
AuthorAll Replies


koitsu
Premium
join:2002-07-16
Mountain View, CA

Linux embedded devices being used in botnet

The below two URLs don't really explain *how* they gained access to said DD-WRT/OpenWRT/Tomato boxes, but based on what I can figure out, it's this:

If you have SSH or telnet open to the world (e.g. WAN-side), and have a fairly insecure password (such the default password of "admin" in Tomato), brute-force SSH/telnet attempts will eventually succeed.

Those who don't permit incoming SSH/telnet to the router via WAN, or allow SSH but disallow passwords (instead requiring keys) should be fine.

OpenWRT apparently leaves telnet open until you've set a root password.

»dronebl.org/blog/8

»it.slashdot.org/article.pl?sid=0···from=rss
--
Making life hard for others since 1977.
I speak for myself and not my employer/affiliates of my employer.

pandora
Premium
join:2001-06-01
Outland
  Isn't the default for Tomato not to enable remote access?


koitsu
Premium
join:2002-07-16
Mountain View, CA

said by pandora See Profile :

Isn't the default for Tomato not to enable remote access?
Correct. I don't think there's any portion of the Tomato installation where telnet/SSH are left open on the WAN side.

This is mainly for people using OpenWRT, and for DD-WRT/Tomato/etc. users who *have* permitted telnet/SSH open via WAN.

tlhIngan

join:2002-07-08
Richmond, BC
reply to koitsu
Also works if you don't change your password and your computer gets infected behind the router. Or if you get infected while out and about, then bring your laptop back home...


koitsu
Premium
join:2002-07-16
Mountain View, CA

said by tlhIngan See Profile :

Also works if you don't change your password and your computer gets infected behind the router. Or if you get infected while out and about, then bring your laptop back home...
I didn't know there were Windows trojans which were brute-forcing SSH/telnet passwords on LAN routers. I don't think the original article mentioned anything of the such -- are you aware of anything like this in the wild?

KodiacZiller

join:2008-09-04
73368

reply to tlhIngan
said by tlhIngan See Profile :

Also works if you don't change your password and your computer gets infected behind the router. Or if you get infected while out and about, then bring your laptop back home...
Care to explain how an infected Windows box would be able to infect a router running DD-WRT/Tomato/OpenRT?


Bill_MI
Bill In Michigan
Premium,MVM
join:2001-01-03
Royal Oak, MI
·Comcast


2 edits
reply to koitsu
Thanks for the heads up on such bad reporting all over the place.

I'm glad to see »dronebl.org/blog/8 "Update 4 -- Before you read anything else, read this".

Headlines such as: »OpenWRT/DD-WRT vulnerability
...are laughable since it would take some rather poor setup. Definitely not defaults.

I did some quick searching but can't find what default setups may be this bad. Anyone?

I then alerted the OpenWrt forum. They had nothing I could find on this.


Potty Time

join:2005-07-03
united state

reply to koitsu
So for a Tomato user who has never messed with any of the SSH/telnet settings, am I safe? How can I check and be certain that I don't have it open WAN-side?? I would hate for my precious little router to become infected or whatever this does

Thank you.


koitsu
Premium
join:2002-07-16
Mountain View, CA


4 edits
said by Potty Time See Profile :

So for a Tomato user who has never messed with any of the SSH/telnet settings, am I safe? How can I check and be certain that I don't have it open WAN-side?? I would hate for my precious little router to become infected or whatever this does :( :( :(
Yes, out-of-the-box you're safe. Tomato, at no stage during installation or post-installation, permits SSH or telnet via the WAN interface (only the LAN).

If you want to verify what your settings are:

Administration -> Admin Access -> SSH Daemon


It doesn't appear that Telnet is ever permitted WAN-side, unless you explicitly create a firewall rule using a start-up script or via some other means. And that's good, especially since Telnet passwords are sent in plaintext over the socket. :-)

HTH...

pandora
Premium
join:2001-06-01
Outland
·ooma
·Future Nine Corpor..
·Comcast

 reply to Potty Time
said by Potty Time See Profile :

So for a Tomato user who has never messed with any of the SSH/telnet settings, am I safe? How can I check and be certain that I don't have it open WAN-side?? I would hate for my precious little router to become infected or whatever this does

Thank you.
You can visit »https://www.grc.com/x/ne.dll?bh0bkyd2 and let "Shields Up" determine if you have any open ports. It is safe, and easy to do. It requires that your browser permit scripting.
--
"People demand freedom of speech as a compensation for the freedom of thought which they seldom use."


Bill_MI
Bill In Michigan
Premium,MVM
join:2001-01-03
Royal Oak, MI
·Comcast


1 edit
reply to koitsu
Things are coming together. A very bad condition existed on some DSL modems and there's a good paper on this: »www.adam.com.au/bogaurd/PSYB0T.pdf

Having a specific target explains why someone would make code that runs in Debian-mipsel, which all the routers we're talking about do.

But please don't loose perspective. 100,000+ worms exist that will infect PCs and now embedded Linux in modems and routers has... 1! And it takes a pretty bad setup to expose. And such a bad setup has been vulnerable all along!

(pssst... pandora... Steve Gibson would *never* require scripts except to specifically test scripting. Try all of grc.com with NoScript blocking everything and even the menus all work fine. I watched him develop those menus in html quite specifically.)


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage

said by Bill_MI See Profile :

(pssst... pandora... Steve Gibson would *never* require scripts except to specifically test scripting. Try all of grc.com with NoScript blocking everything and even the menus all work fine. I watched him develop those menus in html quite specifically.)
And I'll bet that he coded it all using a programmer's text editor, not a fancy GUI html code generator application.
--
A well-regulated militia, being necessary to the security of a free State, the right of the people to keep and bear arms shall not be infringed.
»portscan.dcs-net.net
»nature-pics.com
-
Forums » Equipment Support » Hardware By Brand » Linksys[Wireless] Internet issues with new router »
« [Wired] Help with port forwarding for my reps  


Saturday, 28-Nov 17:22:57 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [63] Weekend Open Thread
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Why would I want an e reader? [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· how to use the 2nd line with phone hooked to the 1st line? [VOIP Tech Chat]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Opera 10.10 keeps opening ICF ports - security issue? [Security]
· Gizmo5 has added a Google Voice section in its members area. [VOIP Tech Chat]
· Windows 7 - Dell ALPS Touchpad driver [Microsoft Help]
· Samsung LCD TV No Picture but has Sound [Electronics]