Symantec Suspects Bot in Attacks on D-Link Routers
Posted: Fri Mar 28, 2008 4:55 pm
Symantec Suspects Bot in Attacks on D-Link Routers
Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose.
Gregg Keizer, Computerworld
Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose and infiltrating the popular brand's devices using a three-year-old vulnerability, security researchers at Symantec Corp. said today.
The security company issued a warning Monday night to customers of its DeepSight threat notification service saying that there were "reliable reports" of an in-the-wild worm or bot that was attacking, then installing itself, on D-Link routers. By Tuesday, however, Symantec had taken a step back.
"After looking into it further, we decided that that was a little misleading," said Oliver Friedrichs , a director of Symantec's security response team. "It's unconfirmed at this point. But we have definitely seen an increase in attack activity, and that activity appears to be coming from other D-Link devices."
In other words, although Symantec's researchers haven't gotten their hands on a worm or bot sample, all the evidence points in that direction. "We suspect that it's a bot," he said.
[url=\"http://www.pcworld.com/article/id,143823/article.html?tk=nl_dnxnws\"]Read The Full Article[/url]
Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose.
Gregg Keizer, Computerworld
Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose and infiltrating the popular brand's devices using a three-year-old vulnerability, security researchers at Symantec Corp. said today.
The security company issued a warning Monday night to customers of its DeepSight threat notification service saying that there were "reliable reports" of an in-the-wild worm or bot that was attacking, then installing itself, on D-Link routers. By Tuesday, however, Symantec had taken a step back.
"After looking into it further, we decided that that was a little misleading," said Oliver Friedrichs , a director of Symantec's security response team. "It's unconfirmed at this point. But we have definitely seen an increase in attack activity, and that activity appears to be coming from other D-Link devices."
In other words, although Symantec's researchers haven't gotten their hands on a worm or bot sample, all the evidence points in that direction. "We suspect that it's a bot," he said.
[url=\"http://www.pcworld.com/article/id,143823/article.html?tk=nl_dnxnws\"]Read The Full Article[/url]