3 ms·
> Disabling the 'backdoor' seems to just involve disabling SSH. Maybe. My guess these are essentially Linux systems, so if attackers know that their exploits a
by lotharcable 1y ago
> Disabling the 'backdoor' seems to just involve disabling SSH.
Maybe. My guess these are essentially Linux systems, so if attackers know that their exploits are widely known then they will likely try to figure out ways to install kernel mod rootkits.
It'll then end up in a situation with Windows XP/Vista days were IT desktop support staff would run malware removal tools to get rid of porn pop-ups on desktops only to have "reinfections" pop up a day or week or two later.
They'd blame users for this, but really they just never actually removed the command and control botnet features. They just addressed their payloads. The machines were never actually fixed in the first place.
- Saris 1y agoYeah the article says the fix is just a factory reset or disabling SSH, so at least it's easy to solve this one.
- lotharcable 1y agoMy point was that if the attackers cared enough to put (not much) effort into keeping control of these routers then neither of those approaches is likely to be sufficient. This sort of thing is why there is such a emphasis on TPM and trusted boot on modern PCs.
- mrandish 1y agoFor a home user, you can also set SSH to be Local LAN only, which is how I have mine set anyway.
- ChocolateGod 1y ago> Maybe. My guess these are essentially Linux systems IIRC ASUS router firmware is based on an old fork of Tomato, which is a Linux based router OS.