A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and troubleshooting tools, where a poorly handled hostname or parameter can become a route to running commands on the device. Similar exposure fueled older router botnet campaigns when unsupported hardware remained online. The scans matter because these functions are designed to let an administrator test connectivity, not to process input. If a router joins user-supplied text directly to a system command, an attacker may be able to make the device execute something entirely different and take control of it. Analysts at Internet Storm Center identified the pattern after seeing sources...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!