Slashdot Mirror


Vigilante Malware Protects Routers Against Other Security Threats

Mickeycaskill writes: Researchers at Symantec have documented a piece of malware that infects routers and other connected devices, but instead of harming them, improves their security. Affected routers connect to a peer-to-peer network with other compromised devices, to distribute threat updates. 'Linux.Wifatch' makes no attempt to conceal itself and even left messages for users, urging them to change their passwords and update their firmware. Symantec estimates 'tens of thousands' of devices are affected and warns that despite Wifatch's seemingly philanthropic intentions, it should be treated with caution.

"It should be made clear that Linux.Wifatch is a piece of code that infects a device without user consent and in that regard is the same as any other piece of malware," said Symantec. "It should also be pointed out that Wifatch contains a number of general-purpose back doors that can be used by the author to carry out potentially malicious actions." There is one simple solution to rid yourself of the malware though: reset your device

18 of 79 comments (clear)

  1. Misnomer by Anonymous Coward · · Score: 2

    I would call that palware and not malware.

    1. Re:Misnomer by Anonymous Coward · · Score: 4, Insightful

      No. It's whitehat.

      If you're dumber than a sack of hammers and never update your router to fix security problems with its firmware, then this worm (not malware, just a software worm) fixes it for you to prevent some other exploit from doing far, far worse.

      Grayhat is when it also MITM's your https sessions to steal financial details.

      Admittedly, we don't know if this particular worm is whitehat or grayhat yet. We do know for certain that it isn't pure blackhat. And that was pretty much what Symantec said, but in srsbsnss corporate terms.

    2. Re:Misnomer by TWX · · Score: 3, Informative

      I need proof that it effectively removes or disables itself once it's on there and has no possibility of later command-and-control and could not be directly co-opted by someone with bad intentions before I would call it white-hat. History is loaded with examples where someone or something appeared altruistic but turned out to be sinister in the end.

      --
      Do not look into laser with remaining eye.
    3. Re:Misnomer by fredgiblet · · Score: 2

      Nope, Microsoft released a version for Windows called Windows 10 though.

  2. How is it malware then? by hyperar · · Score: 5, Insightful

    Is doing good things, that's not malware.

    1. Re:How is it malware then? by Anonymous Coward · · Score: 4, Informative

      "It should also be pointed out that Wifatch contains a number of general-purpose back doors that can be used by the author to carry out potentially malicious actions."

      Patching systems or not, creating new backdoors really doesn't make it "doing good things."

    2. Re:How is it malware then? by OzPeter · · Score: 4, Insightful

      Is doing good things, that's not malware.

      If I walk into your house through the unlocked front door while you are not home, does it protect me from trespassing charges if while I am there I made your bed and did your dishes?

      --
      I am Slashdot. Are you Slashdot as well?
    3. Re:How is it malware then? by Krishnoid · · Score: 4, Funny

      Exactly how many dishes and how long have they been sitting in the sink?

    4. Re:How is it malware then? by Minwee · · Score: 2

      How do you know that it's doing good things?

      And even if it did good things for someone else, how would you know that it was still doing good things by the time it hit your router?

    5. Re:How is it malware then? by Minwee · · Score: 3, Funny

      Sure thing. Just post your address here along with the times when you will be out of the house with the doors unlocked and I assure you that everything will be cleaned out by the end of the day.

      Up. I meant up. You can totally trust me on that. Have I ever lied to you before?

    6. Re:How is it malware then? by Irate+Engineer · · Score: 2

      What a deal! My address is One Schroeder Plaza, Boston, MA 02120. I won't be around for a while, but you can go right in any time day or night.

      Bring doughnuts

      --

      Left MS Windows for Linux Mint and never looked back!

      Vote for Bernie in 2016!

  3. Finally! by Lab+Rat+Jason · · Score: 4, Insightful

    This. Is. Awesome!

    Finally someone has decided to return to the roots of hacking... making something change just to see the change happen!

    --
    Which has more power: the hammer, or the anvil?
  4. Let it be christen by megavlad · · Score: 2

    This type of virus-like good-guy software shall hereby be known as: Rogueware

    Rogueware: A stealth cyber agent which defends crapware.

  5. Symantec infects a device with a user's consent. by tlambert · · Score: 4, Informative

    It should be made clear that Symantec is a piece of code that infects a device /with/ user consent and in that regard is the same as any other piece of malware that is installed via a phishing attack.

  6. jailbreakme.com by tlambert · · Score: 4, Informative

    The original iPhone jailbreaking site, "jailbreakme.com", used the tiff library exploit to install the installer, and then patched the tiff exploit behind itself to prevent it being used for any other (nefarious) purpose, so this type of thing is not a unique or even new idea.

  7. defend the IO tower! by Thud457 · · Score: 2

    His name is TRON, he fights for the Users.

    --

    the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

  8. Fixing vulnerabilities is pretty common in malware by DougOtto · · Score: 3, Interesting

    Lots of malware actually does close security holes, after exploiting the device. If you've worked very hard (or shelled out large amounts of case) for a working zero day, the last thing you want is some other asshole compromising your hacked system and screwing up your back door.

    --
    Solving Unix problems since 1989...
  9. Hmmmmm by JustAnotherOldGuy · · Score: 2

    This....makes me uneasy.

    It appears to be benign (or even helpful) but this is a slippery slope...and I can see all sorts of things that can go wrong here.

    I want to root for the good guys here (pun intended, heh!) but I don't know...anything that fiddles with my PC or server without my explicit, informed consent and permission just doesn't sit well with me.

    It sort of reminds me of the viruses that infect your PC and then disable any competing viruses it finds, so it has your PC all to itself. It doesn't do it for benevolent reasons, it does it because it's greedy and doesn't want to share.

    So I dunno. I can't say as I like it, and I can't say as I don't. Major conflicted feelings here.

    --
    Just cruising through this digital world at 33 1/3 rpm...