1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Worm affecting Routers and Modems

Discussion in 'Security and Privacy' started by Master Green, 2009/04/24.

  1. 2009/04/24
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Just wanted to bring attention to information I have recieved about a new worm that is out and is affecting Lynksys and Netgear routers and modems. Since I am under the impression this is relatively new, it's uncertain if other routers and modems are or will be affected. It's call "bluepill" or "psybot "...

    The only information I have read that explains what to do if you get it is, to first try shutting off the router and if that doesn't work then the router needs to be reset and that supposedly will kill the worm.
     
  2. 2009/04/24
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Links?

    Although not as serious as actual threats, false alarms can be disruptive also. :(

    Edit:

    Please don't blindly pass around/forward rumours you have heard from friends or received via email etc.

    It would be an amazing piece of work for a worm to infect all netgear and lynksys routers/modems. If you seriously believe this threat to be real do a little research. Start with the Netgear/Lynksys websites and follow with known valid anti-malware sites. Don't search for things like bluepill as many of those sites will infect your system with malware.

    I apologise if I sound condesensing but it's posts like yours that cause a lot of the problems.

    Happy surfing and practice safe hex ;)
     
    Last edited: 2009/04/24

  3. to hide this advert.

  4. 2009/04/24
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    The problem this particular worm does is blocks certain ports. It is also believed to affect the routers where the default settings are used and weak passwords. As for the Modems, the ones targeted are DSL modems. It is alledged to be the first of it's kind to affect routers and modems. Just what we all needed.
     
  5. 2009/04/24
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Again, I'll ask for links?

    Malware blocking ports, now that's new ;)

    Who believes it?

    One last time, links or your source.
     
  6. 2009/04/24
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Hi,
    I never did and never will post anything related to emails from friends, rumors, etc...I think I am too experienced for that...Anyways, my first source of information came from Internet Security news via email newsletter sent by them...Before posting any information on it here, I went to google and typed in "worm infection affecting routers" and came up with the same info as recieved by Internet Security...After viewing more info on it, that is when I posted what seems to be the only info available on it...If more info is needed please advise as I never want to be responsible for passing along any incorrect info...
     
  7. 2009/04/24
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Hi Master Green,

    Again I will ask for a link from a recognised anti-malware site regarding this. Up to now the information you have supplied is incomplete and also incorrect (psyb0t is not psybot).

    Any valid information you supply will help others reading this thread.
     
  8. 2009/04/24
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    I doubled and tripled checked Google and many sources are reporting it but to grant the request I kept searching for what I hope to be satisfactory as far as reliability: http://home.mcafee.com/VirusInfo/VirusProfile.aspx?key=154392&ctst=1

    P.S... I WOULD LIKE TO RECOMMEND THAT EVERYONE READING THIS ALSO DO A GOOGLE SEARCH LIKE I HAVE DONE AND THEY WILL SEE THE MANY REPORTS ON IT.
     
    Last edited: 2009/04/24
  9. 2009/04/24
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Psybot

    1. Not all Linksys and Netgear router use embedded Linux, the newer Cisco-Linksys routers use a Cisco op sys.

    2. All one need do to be safe is to use the router settings "Block WAN Access and Remote Administration ".

    If a LAN computer has this worm it can brute force all it wants and it wonk crack a 8-10 character password using upper & lower case, numbers & special characters. The brute force attack has to come from a dictionary.

    The people who will get their routers infected are still using the default router login credentials.

    BluePill is a worm that targets Vista.
     
    Last edited: 2009/04/24
  10. 2009/04/25
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Hi,
    Thank you Wildfire and Tony T for your assistance, greatly appreciated.
     
  11. 2009/04/25
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
  12. 2009/04/25
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Hi Tony T
    Good information and hopefully others will read it...My good intentions was to just bring it to everyones attention and since it was believed to be the first of it's kind that made it even more neccessary to post something about it. Even though this particular worm may only affect certain routers, I was also concerned about the effects it will have on the DSL Modems it made mention of...As long as we are aware of it and that it's considered a low threat, I'm pleased that everyone will atleast have some knowledge of it's existence.
    Thank you again.
     
  13. 2009/04/25
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Master Green,

    Please accept my apologies for my posts yesterday.

    My neighbour was assaulted by several people outside my door and obviously I was upset by this. Although unacceptable, human nature only sees bad in the world during those times.

    I admit I gave you bad reputation but have since asked for it to be removed and Admin has done so.

    Once again my apologies and happy computing :D

    : peace :
     
  14. 2009/04/25
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Hi Wildfire,
    Not a problem here and if I gave the impression it was an issue I too apologize... What you originally said is true and as far as I'm concerned it never hurts to make sure everyone knows that type of information needs to confirm it's source...So you and I are good to go...As for asking for it to be removed, that request "if it was made" was not from me...If it is removed since I posted it under general security, hopefully an explaination will be forthcoming so I can prevent or atleast make sure I stay within this forum guidelines for posting such in the future...

    P.S...I am employed by a Law Enforcement Agency and can fully understand
    your feelings towards that unfortunate situation that occurred in your
    neighborhood, I hope it gets resolved and your neighbor is okay.
     
  15. 2009/04/25
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Wildfire returns control of Web cam back to city IT engineers, points camera away from Master Green's house.
     
  16. 2009/04/25
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Good one...
     
  17. 2009/04/26
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    :D

    @Master Green,

    No one requested I remove the negative reputation I gave you but I made an error in judgement due to unrelated circumstances and requested it be removed.

    The neighbour is fine, after a couple of hours in A&E he was released, you just don't expect that kind of thuggery to happen on your doorstep.

    Thanks for understanding.
     
  18. 2009/04/26
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Hi Wildfire,
    I fully understand and thank you for the clarafication but in all honesty I really didn't take any of your posted blogs negatively so if they leave any of those that's perfectly fine with me...Plus it makes others aware of what they need to do or not do and between us I think that painted picture is clear...It's up to you but personally leave it as is...I think what really matters is you taking the time out to be as helpful as you can at this forum (like many others do here on a regular basis)...I know I always appreciate it.

    P.S...Enjoy the weekend, and I'm glad to hear things are a little better for the time being anyways in the neighborhood...
     
  19. 2009/04/26
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Just so you understand, this forum has a feature called Reputation. Members can award or penalize other members here by "giving them" positive or negative Reputation points.

    Wildfire gave you negative points but then realized the error of his ways and requested that a forum administrator correct your Reputation points.

    The Reputation points is that greem icon under your name to the left of posts.
     
  20. 2009/04/26
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Hi TonyT,
    I didn't seem to realize there was such a thing and didn't know my response to any of his warranted that...I appreciate his correction but I as a result I think I will avoid any future postings or attempts to assist anyone SO IT DOES NOT HAPPEN AGAIN...It's not worth losing a reputation over. Thank you
     
  21. 2009/04/26
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    No no no! Keep posting!
    Just if you have news to post, esp security stuff like this, post any kind on warning you want and any opinion you wish to voice, but also include a link to a source of the news. That's what triggered wildfire's response.

    All too often someone posts some alarming news like, "I was told that Obama appeared in pron movies when he was in college." That is sure to cause concern in some folks. But there's nothing wrong with posting that so long as a link to a source accompanies it. That way a reader can be self-determined about it and make up his own mind about it, add to it or take away from it.

    Keep helping others, keep posting your opinions...there are no barriers.

    Also, show me a reputation that's never been tarnished a bit and I'll show you someone who avoids life!
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.