AfterDawn: Tech news

New Linux worm targeting your home routers, security cameras, more

Written by Andre Yoskowitz @ 30 Nov 2013 11:25 User comments (1)

New Linux worm targeting your home routers, security cameras, more

Researchers have found a new and scary Linux worm that is infecting home routers, set-top boxes, security cameras and other devices with an Internet connection.
Linux.Darlloz can target devices that run on Intel-made CPUs, so right now the threat is considered 'low-level.'

Symantec researcher Kaoru Hayashi says minor modifications could make the worm potent, if they incorporate available executable and linkable format (ELF) files. Those ELF files can attack devices running on ARM, PPC, MIPS, and MIPSEL architectures.

"Upon execution, the worm generates IP addresses randomly, accesses a specific path on the machine with well-known ID and passwords, and sends HTTP POST requests, which exploit the vulnerability," Hayashi explained (via Ars). "If the target is unpatched, it downloads the worm from a malicious server and starts searching for its next target. Currently, the worm seems to infect only Intel x86 systems, because the downloaded URL in the exploit code is hard-coded to the ELF binary for Intel architectures."



The worm exploits devices with outdated open source code, many of which cannot even be updated due to aging hardware that cannot meet the minimum requirements.

Previous Next  

1 user comment

12.12.2013 06:35

Please, be calm and don't send your old routers to the trash just yet.

The key of the article is "with well-known ID and passwords".

Meaning: "If you are dumb enough to let the http port of your device open to the wild outside world without changing its default ID and password, you deserve to be infected with whatever evil junk is out there, because you're asking very loudly to be hacked and it's quite a miracle that such thing hadn't happened until now".

This message has been edited since its posting. Latest edit was made on 03 Dec 2013 @ 1:50

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive