Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Security & Privacy
Weekly Brief
Windows Vista
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Networking HardwareHackersOffice Hardware

Symantec Suspects Bot in Attacks on D-Link Routers

Gregg Keizer, Computerworld

Tuesday, March 25, 2008 3:00 PM PDT
Recommend this story?

Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose and infiltrating the popular brand's devices using a three-year-old vulnerability, security researchers at Symantec Corp. said today.

The security company issued a warning Monday night to customers of its DeepSight threat notification service saying that there were "reliable reports" of an in-the-wild worm or bot that was attacking, then installing itself, on D-Link routers. By Tuesday, however, Symantec had taken a step back.

"After looking into it further, we decided that that was a little misleading," said Oliver Friedrichs , a director of Symantec's security response team. "It's unconfirmed at this point. But we have definitely seen an increase in attack activity, and that activity appears to be coming from other D-Link devices."

In other words, although Symantec's researchers haven't gotten their hands on a worm or bot sample, all the evidence points in that direction. "We suspect that it's a bot," he said.

Attack Details

According to Friedrichs, the attacks against the D-Link routers begin with hackers scanning TCP port 23 for an active SNMP (Simple Network Management Protocol) service, a flaw that first showed up in D-Link router firmware in 2005. "It looks like they're exploiting the SNMP vulnerability to reset and reconfigure the administrative password on the routers," said Friedrichs, perhaps to conduct "drive-by pharming" attacks that change a router's settings so its users are unknowingly directed to bogus or malicious Web sites instead of the real URLs.

"Having port 23 open on the Internet-facing side is a bad idea in general," said Petko Petkov , a prolific penetration tester from the U.K who, with a partner, Adrian Pastor, has published research on hacking routers. "But I guess this is due to the fact that the attacked devices have only one Ethernet port and users can unwillingly expose otherwise privileged services on the Internet."

Router vulnerabilities are up and attacks against routers are on the upswing -- especially attacks that target devices used by consumers and small businesses to create wireless networks, said Friedrichs. "Attackers are increasingly looking beyond the desktop," he said, for new places to install -- and hide -- their malware.

Petkov wasn't shocked to hear of Symantec's warning. "We're not surprised at all, as all embedded-device(s) we have tested so far are vulnerable to all kinds of interesting vulnerabilities," Petkov said in an e-mail Tuesday. Nor would creating a worm or bot Trojan be tough. "Anybody can code a worm which attacks routers on a massive scale quite easily. Most of the research information is out there, so it is a matter of putting the pieces of the puzzle together."

Friedrichs characterized the port 23 scanning activity Symantec is seeing as "moderate" and said the researchers will continue to investigate. He and his team, however, had not been able to verify that the vulnerability had been patched, and if so, when, or which specific models of D-Link's routers might be at risk.

D-Link officials did not respond to a call for comment.

For the moment, the best advice Friedrichs had for D-Link router owners is to make sure that the SNMP service was not exposed to the Internet.


Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.


Recommend this story?
Related Searches: symantec d-link routers bot deepsight

Comments
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
Toshiba plans to begin mass production of Direct Methanol Fuel Cells by March next year and to have a television based on the... 09-May-2008
In the not-too-distant future, people could use computer printers to make simple medicines as part of a do-it-yourself model... 09-May-2008
Microsoft will launch Worldwide Telescope, a tool for exploring images of the night sky, by the end of May, free to anyone who... 09-May-2008
The growing disaster in Myanmar caused by Cyclone Nargis could have been at least party avoided had people living in the path... 09-May-2008
Spray them with water, subject them to extreme temperatures or drop them on the ground, NEC's rugged ShieldPro laptops are... 09-May-2008
Shipments of the Gran Turismo series of car racing games edged past the 50 million unit mark at the end of April, Sony said... 09-May-2008
Samsung has launched a high-definition (HD) video camera that can also snap high-resolution digital photos and take smooth... 09-May-2008
They say everything comes to those that wait. A year after it went on sale in the rest of the world customers in Japan will... 08-May-2008
Two giant offers for free Wi-Fi extended, one from AT&T to iPhone users, and another from Cablevision for its millions of home territory broadband subscribers. 08-May-2008
In the wake of collapsed talks with Yahoo, Microsoft reportedly is sniffing around social-networking site Facebook. 08-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)