Skip the navigation
News

Symantec suspects bot in attacks on D-Link routers

2005 bug left SNMP service exposed, says researcher; attack activity up

By Gregg Keizer
March 25, 2008 12:00 PM ET

Computerworld - Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose and infiltrating the popular brand's devices using a three-year-old vulnerability, security researchers at Symantec Corp. said today.

The security company issued a warning Monday night to customers of its DeepSight threat notification service saying that there were "reliable reports" of an in-the-wild worm or bot that was attacking, then installing itself, on D-Link routers. By today, however, Symantec had taken a step back.

"After looking into it further, we decided that that was a little misleading," said Oliver Friedrichs, a director of Symantec's security response team. "It's unconfirmed at this point. But we have definitely seen an increase in attack activity, and that activity appears to be coming from other D-Link devices."

In other words, although Symantec's researchers haven't gotten their hands on a worm or bot sample, all the evidence points in that direction. "We suspect that it's a bot," he said.

According to Friedrichs, the attacks against the D-Link routers begin with hackers scanning TCP port 23 for an active SNMP (Simple Network Management Protocol) service, a flaw that first showed up in D-Link router firmware in 2005. "It looks like they're exploiting the SNMP vulnerability to reset and reconfigure the administrative password on the routers," said Friedrichs, perhaps to conduct "drive-by pharming" attacks that change a router's settings so its users are unknowingly directed to bogus or malicious Web sites instead of the real URLs.

"Having port 23 open on the Internet-facing side is a bad idea in general," said Petko Petkov, a prolific penetration tester from the U.K who, with a partner, Adrian Pastor, has published research on hacking routers. "But I guess this is due to the fact that the attacked devices have only one Ethernet port and users can unwillingly expose otherwise privileged services on the Internet."

Router vulnerabilities are up and attacks against routers are on the upswing -- especially attacks that target devices used by consumers and small businesses to create wireless networks, said Friedrichs. "Attackers are increasingly looking beyond the desktop," he said, for new places to install -- and hide -- their malware.

Petkov wasn't shocked to hear of Symantec's warning. "We're not surprised at all, as all embedded-device(s) we have tested so far are vulnerable to all kinds of interesting vulnerabilities," Petkov said in an e-mail today. Nor would creating a worm or bot Trojan be tough. "Anybody can code a worm which attacks routers on a massive scale quite easily. Most of the research information is out there, so it is a matter of putting the pieces of the puzzle together."

Friedrichs characterized the port 23 scanning activity Symantec is seeing as "moderate" and said the researchers will continue to investigate. He and his team, however, had not been able to verify that the vulnerability had been patched, and if so, when, or which specific models of D-Link's routers might be at risk.

D-Link officials did not respond to a call for comment.

For the moment, the best advice Friedrichs had for D-Link router owners is to make sure that the SNMP service was not exposed to the Internet.

Read more about Security in Computerworld's Security Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs