Lizard Stresser DDoS-for-Hire Service Built On Hacked Home Routers
tsu doh nimh writes: The online attack service launched late last year by the same criminals who knocked Sony and Microsoft's gaming networks offline over the holidays is powered mostly by thousands of hacked home Internet routers, reports Brian Krebs. From the story: "The malicious code that converts vulnerable systems into stresser bots is a variation on a piece of rather crude malware first documented in November by Russian security firm Dr. Web, but the malware itself appears to date back to early 2014. As we can see in that writeup, in addition to turning the infected host into attack zombies, the malicious code uses the infected system to scan the Internet for additional devices that also allow access via factory default credentials, such as 'admin/admin,' or 'root/12345.' In this way, each infected host is constantly trying to spread the infection to new home routers and other devices accepting incoming connections (via telnet) with default credentials.
Thank you for your interest in joining the Gay Wigger Association of DICE* (GayWAD)! GayWADs worldwide are happy that you'd like to become part of our
constantly enlarging member ship (come sail away 8====D~)
Unlike other geek fraternities that you might have heard about, GayWAD accepts members of all races, creeds, and colors. We don't even have a technical inclination requirement. As our founders stated in the Annals of GayWAD, Chapter 1: "You don't have to be a geek, as long as you like it Greek." They were, of course, referring to the penis in anus style of sexual relations. Don't despair, as attaining full fabulous lifetime status in GayWAD is easy. The only prerequisites for membership in Gay Wigger Association of DICE* are that you meet all of the following conditions:
To submit your Gay Wigger Association of DICE* Membership Application, simply do nothing. Congratulations, you're now a GayWAD!
If you require a specific membership number for purposes such as framing, docking, or prestigious inclusion upon your business cards and resume, please take down this number: 69.
Optionally, you may complete the following survey by replying to this post, indicating affirmative responses with an X in each appropriate box:
GayWAD Membership Survey (OPTIONAL)
[ ] I am gay
[ ] I am a wigger
[ ] I have used SLASHDOT BETA to find a sex partner
After completion of this optional survey, your Slashdot post ID shall serve as your unique Gay Wigger Association of DICE* membership ID.
Your GayWAD membership kit** is on its way.
* GayWAD is neither affiliated with nor endorsed by DICE.
** GayWAD membership kit no longer includes HIV self-test catheter.
Factory passwords is what separates humans from the beasts.
Why do all routers of the same model need to come with the same initial credentials?
Dark Helmet: So the combination is... one, two, three, four, five? That's the stupidest combination I've ever heard in my life! That's the kind of thing an idiot would have on his luggage!
Get free satoshi (Bitcoin) and Dogecoins
Get some hardware, install pfSense, configure, never worry about this shit again.
"In this way, each infected host is constantly trying to spread the infection to new home routers and other devices" ... there used to be a name for this, oh, it's on the tip of my tongue. W.. W.. Wor..
The Beta sucks. Why will it not let me posts? Why is this not working?
Most home routers I've dealt with don't enable remote administration by default. Allowing administration from outside one's LAN seems like a more serious problem than using a default password.
That's not the problem. The problem is allowing logins from the WAN side by default. That's a ridiculous thing to allow, however, I feel that the blame more likely likes with ISPs shipping routers with their own poorly-modified firmware than with hardware manufacturers.
get at me sexyduck!
krebz noz dem and dere haxxin
to knock out a bunch of compromised routers...
"The botnet is not made entirely of home routers; some of the infected hosts appear to be commercial routers at universities and companies, and there are undoubtedly other devices involved."
What would be the name of the Operating System that these other devices run on?