Crypto Ticker:
sysadmin from Cyber Security News

Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

Tushar Subhra Dutta
7 hours ago
6 Views
0 Comments
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and troubleshooting tools, where a poorly handled hostname or parameter can become a route to running commands on the device. Similar exposure fueled older router botnet campaigns when unsupported hardware remained online. The scans matter because these functions are designed to let an administrator test connectivity, not to process input. If a router joins user-supplied text directly to a system command, an attacker may be able to make the device execute something entirely different and take control of it. Analysts at Internet Storm Center identified the pattern after seeing sources...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!