DDoS Botnet Leverages Thousands of Insecure SOHO Routers
New Post has been published on http://www.newsnish.com/technology/web-social/ddos-botnet-leverages-thousands-of-insecure-soho-routers/
DDoS Botnet Leverages Thousands of Insecure SOHO Routers
Small office and home office (SOHO) routers are an increasingly common target for cybercriminals, not because of any vulnerability, but because most routers are loosely managed and often deployed with default administrator credentials.
A new report suggests that hackers are using large botnet of tens of thousands of insecure home and office-based routers to launch Distributed Denial-of-Service (DDoS) attacks. Security researchers from DDoS protection firm Incapsula uncovered a router-based botnet, still largely active while investigating a series of DDoS attacks against its customers that have been underway since at least last December, 2014.
Over the past four months, researchers have recorded malicious traffic targeting 60 of its clients came from some 40,269 IP addresses belonging to 1,600 ISPs around the world.
Almost all of the infected routers that were part of the botnet appear to be ARM-based models from a California-based networking company Ubiquiti Networks, sold across the world.
This makes researchers believed that the cyber criminals were exploiting a firmware vulnerability in the routers.
What’s revealed in the close inspection?
However, this assumption was proved wrong when inspected deeply, revealing that…
All of the compromised routers could be remotely accessible on the default ports (via HTTP and SSH). Almost all of those accounts continued to make use of vendor-provided login credentials
This basically opens the door for an attacker to man-in-the-middle (MitM) attacks, eavesdrop on all communication, cookie hijack, and allows hackers to gain access to other local network devices such as CCTV cameras.
Router makers design their devices in such a way that it can be easily connected, and therefore they give each user the same administrator credential, without giving any warning to change the default credentials. Moreover, instead of allowing users to turn on remote administration, the manufacturers make it on by default.
“Given how easy it is to hijack these devices, we expect to see them being exploited by additional perpetrators,” researchers wrote. “Even as we conducted our research, the Incapsula security team documented numerous new malware types being added—each compounding the threat posed by the existence of these botnet devices.”
Almost all of the infected routers that were part of the botnet appear to be ARM-based models from a California-based networking company Ubiquiti Networks, sold across the world. This makes researchers believed that the cyber criminals were exploiting a firmware vulnerability in the routers.