Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

Tushar Subhra Dutta
7 hours ago
5 Visninger
0 Kommentarer
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and troubleshooting tools, where a poorly handled hostname or parameter can become a route to running commands on the device. Similar exposure fueled older router botnet campaigns when unsupported hardware remained online. The scans matter because these functions are designed to let an administrator test connectivity, not to process input. If a router joins user-supplied text directly to a system command, an attacker may be able to make the device execute something entirely different and take control of it. Analysts at Internet Storm Center identified the pattern after seeing sources...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!