PDA

View Full Version : Brickerbot



KG4CGC
04-17-2017, 08:40 AM
https://www.theregister.co.uk/2017/04/08/brickerbot_malware_kills_iot_devices/

Someone tell me what I should think about this. TIA.

WØTKX
04-17-2017, 10:30 AM
https://www.youtube.com/watch?v=69fPof-ZTnU

n2ize
04-17-2017, 02:00 PM
https://www.theregister.co.uk/2017/04/08/brickerbot_malware_kills_iot_devices/

Someone tell me what I should think about this. TIA.
Oh that's beautiful !!! Basically it writes random garbage from /dev/urandom to the devices virtual disc (memory partitions). Then it reformats the memory and dumps the routing table to /dev/null and then halts and reboots the device. When the device reboots it's basically a box of electronics that does nothing useful To fix it the memory disc) would have to be cleaned and the operating system reinstalled and reconfigured.

What to do ? First check to see if you have a router or device that uses Linux and has access to the busybox shell. Make sure you are not running the devices default password and change it to a password that would be difficult to determine via a brute force attack. Then disable access to the busybox shell, i.e. shut off telnet.

NQ6U
04-17-2017, 04:23 PM
Since most device makers dumb down the networking controls, you should disable remote administration access unless you really know what you're doing.

n2ize
04-17-2017, 05:17 PM
Since most device makers dumb down the networking controls, you should disable remote administration access unless you really know what you're doing.
Yep.

WØTKX
04-17-2017, 08:25 PM
Telnet is just not a good thing anymore. Maybe on a closed network. We still use it for out "IoT" devices at work.
But they are NOT allowed on the IntErnet. Just our IntrANet.

You know' BacNet HVAC controls, bigass UPS devices, solar panels/inverters, etc., etc.
These things are pretty cool, actually. Our new HVAC control system is spiffy!

n2ize
04-19-2017, 01:32 AM
I rarely use telnet these days except perhaps for running tests on servers.