用linksys router的各位注意一下

月下独酌

浪子
VIP
注册
2003-06-21
消息
32,109
荣誉分数
4,178
声望点数
373
A representative of an ISP located in Wyoming warned SANS Institute's Internet Storm Center (ISC) on Wednesday that over the last several days, a number ofcustomers have developed compromised Linksys routers. These routers, models E1000 and E1200, were scanning other IP addresses on port 80 and 8080 as fast as they could, thus saturating the available bandwidth.

Then on Thursday, the Internet Storm Center was updated again with a bit more detail, as the ISC researchers managed to capture the malware by using a system that was intentionally left open for an attack. Dubbed as "TheMoon," this worm compromises the Linksys router and then scans for other vulnerable devices. Unfortunately, the list of routers is longer than what was previously reported on Wednesday.

"We are aware of a worm that is spreading among various models of Linksys routers,"writes Johannes Ullrich, Ph.D. "We do not have a definite list of routers that are vulnerable, but the following routers may be vulnerable depending on firmware version: E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000,E900."

Ullrich says that first the worm connects to port 8080 to request the "/HNAP1/" URL, which will return an XML formatted fist of the router features and firmware versions. After extracting the router's hardware and firmware versions, the worm will send an exploit to a vulnerable CGI script running on the router.

"The request does not require authentication," Ullrich reports. "The worm sends random 'admin' credentials but they are not checked by the script. Linksys (Belkin) is aware of this vulnerability."

The worm's second request will launch a simple shell script. Once this code runs, the infected router will scan for other victims.

"An infected router will also serve the binary at a random low port for new victims todownload. This http server is only opened for a short period of time, and for each target, a new server with a different port is opened,” Ullrich continues.

The worm is about 2 MB in size, and has a list of around 670 different networks that appear to be linked to cable or DSL modem ISPs in various countries. The worm also appears to include strings that point to a command and control channel. Currently, the ISC team doesn't know if there is a command control channel up and running.

For now, all the worm does is spread.

"This may be a 'bot' if there is a functional command and control channel present," Ullrich warns.
 
怎么知道自己的router有没有中招?
 
我有一个E1000 , 怎么check?
 
家里还有好几个Cisco生产的Linksys router, 不知如何处理好。:crying:
 
给月下吧,估计他会笑纳.
家里还有好几个Cisco生产的Linksys router, 不知如何处理好。:crying:
 
我有一个E1000 , 怎么check?
我有两个E1000, 刷dd-wrt时一个成功,另一个成了砖。这个router速度极慢。
我现在用的E4500速度倒是不慢,但Firmware极臭。Cisco的程序员们的编程技术,好像是体育老师教的。
 
我有两个E1000, 刷dd-wrt时一个成功,另一个成了砖。这个router速度极慢。
我现在用的E4500速度倒是不慢,但Firmware极臭。Cisco的程序员们的编程技术,好像是体育老师教的。
自从用了asus rt-n66u生活质量瞬间提升了一大截子,刷的Merlin Firmware。
 
我有两个E1000, 刷dd-wrt时一个成功,另一个成了砖。这个router速度极慢。
我现在用的E4500速度倒是不慢,但Firmware极臭。Cisco的程序员们的编程技术,好像是体育老师教的。

lol我家的E1000+西红柿一点不慢

不懂你就真的别2了

这些firmware都是基于linux kernel, driver都是三方提供的,基本上就是个UI的区别,剩下的各种feature很多都是linux built-in的,比方说ip tables神马的。只是提供的多少的问题。

无线网络快慢要看你家周围有多少信号冲突,你家结构,router位置,输出功率,跟是否跟你的无线网卡匹配。有线网快慢真心看里面的broadcom的chip用的哪款,频率多少,内存多少。。。
 
我发现家里的baby monitor一开, 无线网速就奇慢。 如果你的网速慢, 查查邻居家有没有baby.:rolleyes:
 
后退
顶部