Page 1 of 1

Symantec Suspects Bot in Attacks on D-Link Routers

Posted: Fri Mar 28, 2008 4:55 pm
by NightStorm
Symantec Suspects Bot in Attacks on D-Link Routers
Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose.

Gregg Keizer, Computerworld

Suspicious port scanning that's been tracked back to D-Link Inc. routers may mean a worm or bot is on the loose and infiltrating the popular brand's devices using a three-year-old vulnerability, security researchers at Symantec Corp. said today.

The security company issued a warning Monday night to customers of its DeepSight threat notification service saying that there were "reliable reports" of an in-the-wild worm or bot that was attacking, then installing itself, on D-Link routers. By Tuesday, however, Symantec had taken a step back.

"After looking into it further, we decided that that was a little misleading," said Oliver Friedrichs , a director of Symantec's security response team. "It's unconfirmed at this point. But we have definitely seen an increase in attack activity, and that activity appears to be coming from other D-Link devices."

In other words, although Symantec's researchers haven't gotten their hands on a worm or bot sample, all the evidence points in that direction. "We suspect that it's a bot," he said.

[url=\"http://www.pcworld.com/article/id,143823/article.html?tk=nl_dnxnws\"]Read The Full Article[/url]