4 ms·
Here are some of the things we can learn from the Moris worm: 1) DO NOT CREATE PRODUCTS WITH DEFAULT PASSWORDS - I believe that the Moris worm spread because s
by StressedDev 3y ago
Here are some of the things we can learn from the Moris worm:
1) DO NOT CREATE PRODUCTS WITH DEFAULT PASSWORDS - I believe that the Moris worm spread because some versions of Unix had default passwords and users never changed the default password.
2) PROMPTLY INSTALL SECURITY PATCHES - I also believe the Moris worm spread by exploiting know security vulnerabilities.
Here are some other lessons:
- Use strong random passwords - For best results, use a password with 20-24 characters (i.e. about 128 bits of entropy).
- Always change default passwords
- clwg 3y agoIt's really a sad state of affairs when those issues are still predominant on the internet. You're absolutely right that these are lessons we should take away from it; I just think the lessons needed to have been learned 35 years ago to have made any real difference.
- ethbr1 3y agoUp until ~2005, I believe ISPs were still shipping WAPs that all used the same hardcoded credentials, unless the user changed them. Wardriving was a lot easier then.
- tlavoie 3y agoAlso easier to compromise the access point, since the wardriving got you onto the WLAN side. Oh, and default IP for the thing too, for bonus ease.
- eichin 3y agoGood lessons for later years, but anachronistic in this context :-) It included a surprisingly short (400ish?) password entry table to try, but they were poorly chosen human passwords - I don't recall much being popular enough to even have default passwords. As for security patches - I don't know if there was evidence, but given the not-previously-known exploits it did use, we figured that the previous week's ftpd release (with a bunch of features to bury the obvious-in-retrospect buffer overrun fixes) was a trigger for launching early, before any of the other holes got discovered. (The vulnerabilities were known conceptually but these specific places and ways of exploiting them, not so much.)