New Muhstik Botnet Attacks Target Tomato Routers
#1
Information 
Quote:A new variant of the Muhstik botnet has appeared, this time with scanner technology that for the first time can brute-force web authentication to attack routers using Tomato open-source firmware, researchers have found.
 
Researchers at Palo Alto Networks’ Unit 42 discovered the new variant harvesting vulnerable routers and IoT devices in early December, they reported in a blog post Tuesday. Muhstik, showing a wormlike self-propagating capability that can infect Linux servers and IoT devices, has been active since March 2018.
 
“The new Muhstik variant scans Tomato routers on TCP port 8080 and bypasses the admin web authentication by default credentials bruteforcing,” researchers wrote in their report. The default in this case being “admin:admin” and “root:admin.” “We captured the Tomato router web authentication brute-forcing traffic,” wrote Palo Alto researchers who co-authored the blog Cong Zheng, Yang Ji and Asher Davila.

Read more: https://threatpost.com/muhstik-botnet-at...rs/152079/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AdGuard for Android 4.12.3
AdGuard for Androi...harlan4096 — 17:18
Replit Pro – One Month Free
Replit Pro     C...hanso — 17:02
Free 4 months Adobe Express subscription
Free 4 months Ado...hanso — 12:27
QOwnNotes
26.2.8  Added a s...Kool — 10:17
11 Little-Known AI Tools That Feel Like ...
11 Little-Known AI T...hanso — 09:30

[-]
Birthdays
Today's Birthdays
avatar (38)Michaelaburi
avatar (46)dpascoal
Upcoming Birthdays
avatar (46)dimaWeami
avatar (44)Baihu

[-]
Online Staff
hanso's profile hanso

>