Sinisterly
Malware targets Linux/Raspberry Pi - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: General (https://sinister.li/Forum-General)
+--- Forum: World News (https://sinister.li/Forum-World-News)
+--- Thread: Malware targets Linux/Raspberry Pi (/Thread-Malware-targets-Linux-Raspberry-Pi)



Malware targets Linux/Raspberry Pi - Ecks - 06-11-2017

If you're a Raspberry Pi user who's never changed the default password of the "pi" user, then heed this warning: change it. A brand new piece of malware has hit the web, called "Linux.MulDrop.14", and it preys on those who haven't secured their devices properly... After scanning for RPis with an open (and default) SSH port, the "pi" user is logged into (if the password is left default), and the password is subsequently changed. After that, the malware installs ZMap and sshpass software, and then it configures itself. The ultimate goal of Linux.MulDrop.14 is to make digital money for someone else, namely the author of the malware, using your Raspberry Pi.

Read more : https://hothardware.com/news/malware-infects-raspberry-pis-making-them-cryptocurrency-mining-zombies


RE: Malware targets Linux/Raspberry Pi - Darkbyte - 06-11-2017

This has been going on for years and its not just pis its multiple devices with default passwords and ssh servers like dvrs and some smart home devices.


RE: Malware targets Linux/Raspberry Pi - Ecks - 06-11-2017

Every source of technology will have someone there to exploit it, without hackers and crackers security would be a joke. This is just another tool that is currently hitting people, but anyone who doesn't change the defaults(user/pass), kind of deserves whatever happens.


RE: Malware targets Linux/Raspberry Pi - d0ntjump - 06-12-2017

I believe that if you are naive/foolish enough to leave a server with default settings you are placing a welcome mat at the door...


RE: Malware targets Linux/Raspberry Pi - Blink - 06-12-2017

(06-12-2017, 01:48 AM)d0ntjump Wrote: I believe that if you are naive/foolish enough to leave a server with default settings you are placing a welcome mat at the door...

^ This

Note: This is very similar to Mirai's technique, only less successful

It would be interesting to set up a scanner just to see how many default {RPi}s there are


RE: Malware targets Linux/Raspberry Pi - d0ntjump - 06-12-2017

(06-12-2017, 01:54 AM)Ender Wrote:
(06-12-2017, 01:48 AM)d0ntjump Wrote: I believe that if you are naive/foolish enough to leave a server with default settings you are placing a welcome mat at the door...

^ This

Note: This is very similar to Mirai's technique, only less successful

It would be interesting to set up a scanner just to see how many default {RPi}s there are

That would be interesting... I'm sure there are scripts out there that do just that. Possibly there is a Metasploit module for this as well, not sure. Don't they use ssh?


RE: Malware targets Linux/Raspberry Pi - mothered - 06-12-2017

(06-11-2017, 10:23 PM)n3r0x1d3 Wrote: without hackers and crackers security would be a joke.

Although due to hackers exposing vulnerabilities thereby forcing the vendor to patch whatever It Is they've Implemented and designed, security Is still a joke and always will be.

Those who don't change the default settings on their device, well, expect to be exploited.


RE: Malware targets Linux/Raspberry Pi - Ecks - 06-12-2017

Well yes as we grow and technology expands and becomes more complicated the generations growing up with that technology will be able to break things the previous generation thought impossible, just look at the state of encryption, it by its nature must keep growing and becoming more complicated in order to make it harder to be cracked, but nothing will ever be 100% secure. I read an article few years back where hackers even found a way to exploit air gapped mainframes and systems, how they did it was complicated and unusual but by god they found a way to do it.


RE: Malware targets Linux/Raspberry Pi - mothered - 06-12-2017

Agree.

It's a lot more difficult from a security standpoint. You need to look at every possible configuration and vulnerability and try and patch everything Identified as some sort of weakness Into your system. From a hacker's perspective, all you need Is "one" gateway that allows access.

And then there's the "user" operating the technological side of things. You can have the most secure system, but If the user Is not trained and does not have the skill set and know-how to combat human manipulation and exploitation (SE'ing), then that speaks for Itself.