5 ms·
Well, for starters here is an article about malware specifically targeting ASUS routers. https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sigh
by Prickle 3y ago
Well, for starters here is an article about malware specifically targeting ASUS routers.
https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html https://www.trendmicro.com/en_us/research/22/c/cyclops-blink...
Hopefully that clears up the first question of "why does it need malware signature files?"
As for your router firmware? You should seriously update that. New exploits get found all the time.
Hackers use compromised routers as parts of a botnet, a intermediary route, or as an access point with which to steal data with Man in the Middle attacks.
- gcr 3y agoThat’s an attack on the router itself, not the network traffic it carries. Signature files are only useful to scan network traffic.
- Prickle 3y agoThis was literally a discussion about the firmware of a router. How is it not relevant? This person has not updated their router's firmware in over 3 years. The viral traffic needs to get to the router in the first place. I assume that the means of reaching the router is literally via network traffic? What am I missing?
- ploxiln 3y ago> Hopefully that clears up the first question of "why does it need malware signature files?" The malware signature files really don't help prevent your router joining a botnet. Firmware updates, maybe, maybe not. It is quite possible for other routers with less generally sloppy and advertised-feature-rich firmware to actually be more secure even without updates for 3 years. It's quite possible that they have no api endpoints available for super-easy mobile app integration remote management etc, just ssh from local subnet or physical serial console. There have been multiple cases of market-leading antivirus engines (symanted, mcaffee, etc) having sloppy code running with the highest possible privilege, parsing any files appearing on the system anywhere, and e.g. crashing a mail server that would otherwise be unaffected by the PoC samples being emailed through it by researchers. So, I also take some issue with people who have no understanding of how all this software around us is designed and built (in routers, in windows, on web servers) and thinking that just updating everything all the time and running antivirus is the best you can do. You really can do a lot better if you know what you're doing.
- joveian 3y agoRe: firmware updates, there is stuff like these remotely exploitable kernel wifi stack issues not that long ago: https://lwn.net/ml/oss-security/20221013101046.GB20615@suse.de/ https://lwn.net/ml/oss-security/20221013101046.GB20615@suse.... There can be driver specific remotely exploitable issues that might not be widely communicated. Until operating systems are written more robustly, just having admin level stuff set up robustly isn't always enough. Of course, updates can add bugs too.
- gcr 3y agoWhen I hear “signature file” I think of a list of signatures of known viruses and malware. These types of signature files aren’t meant to guard against exploits, SSH brute forcing, etc, even if the router applies them to inbound traffic in addition to forwarded traffic. To do that, you typically need a WAF or some clever fail2ban-like filtering rules. Even up-to-date signatures won’t prevent a router from getting 0wn3d if the ssh daemon has a security hole for example. As sites move to HTTPS, routers can’t even really filter networking traffic anymore. I don’t see why a router needs signature lists at all
- Prickle 3y agoThankyou for the insight.
- denton-scratch 3y ago> Hopefully that clears up the first question of "why does it need malware signature files?" Not really. The article doesn't mention signature files. It describes the operations of a certain malware once it has been executed on a router. But first it has to get onto the router; and the only way new software can get onto this router is via a firmware update.
- mrguyorama 3y ago>the only way new software can get onto this router is via a firmware update. That has never been the case. Software from consumer routers is often still in the "a trivial buffer overflow lets a malformed packet insert a payload into ram and convince the PC to jump to it." phase of software security. They are very much still wormable systems, like Windows 2000 style. Ever have your router glitch out and stop working and you have to reboot it? That's probably an exploitable bug.