• IP addresses are NOT logged in this forum so there's no point asking. Please note that this forum is full of homophobes, racists, lunatics, schizophrenics & absolute nut jobs with a smattering of geniuses, Chinese chauvinists, Moderate Muslims and last but not least a couple of "know-it-alls" constantly sprouting their dubious wisdom. If you believe that content generated by unsavory characters might cause you offense PLEASE LEAVE NOW! Sammyboy Admin and Staff are not responsible for your hurt feelings should you choose to read any of the content here.

    The OTHER forum is HERE so please stop asking.

Linksys Routers Targeted by Mysterious New Worm

HallOates

Alfrescian (Inf)
Asset
Joined
Jan 21, 2014
Messages
149
Points
0

Linksys Routers Malware ‘The Moon’ Spreading


By Adnan Farooqui on 02/17/2014

linksys_cisco_selling.jpeg


Linksys router users might want to take some extra precautions.

Johannes B. Ullrich, a security researcher at the SANS Technology Institute, has revealed that the company’s wireless routers are being targeted by malware, essentially a self replicating worm, which exploits code execution and authentication bypass vulnerabilities.

Basically the Linksys router malware is spreading from router to router, attacking the existing firmware and then replicating itself. It dubbed as “The Moon.”

Ullrich says that The Moon scans for vulnerable devices as it looks to continue spreading, over 1,000 Linksys E1000, E1200 and E2400 are already believed to be infected by the malware.

The way The Moon spreads is by first remotely calling the Home Network Administration Protocol or HNAP through which networking devices can be managed, configured and identified.

Once the model and firmware version is obtained, and the device is found to be vulnerable, the malware sends a CGI script exploit in order to get local command execution access.

Belkin, Linksys’s parent company, has confirmed that there exists a security flaw in the HNAP1 implementation, and that its exploit code can be found online.

They’re still analyzing what the worm exactly does, but at this time it appears that all it does is spread from one device to another without wreaking havoc.

If you happen to use a Linksys router, particularly the models mentioned, then it would be best to disable remote administration outright, or just limit the remote administration rights that have been provided to a select few trusted IP addresses.


 
Back
Top