Vigilante Router Worm. it hacks the router and makes it more secure...

blankslate

Diamond Member
Jun 16, 2008
8,776
556
126
http://thehackernews.com/2015/10/hack-wifi-router.html

http://www.techworm.net/2015/10/new-vigilante-malware-protects-routers-against-security-threats.html

Ifwatch software is a mysterious piece of “malware” that infects routers through Telnet ports, which are often weakly secured with default security credentials that could be open to malicious attack. Instead, Ifwatch takes that opportunity to set up shop, close the door behind it, and then prompts users to change their Telnet passwords, if they are actually going to use the port.

According to Symantec’s research, it also has code dedicated to removing software that has entered the device with less altruistic intentions. Ifwatch finds out and removes “well-known families of malware targeting embedded devices,”

“We have no idea who is behind this — or what their full intention is,” Saengphaibul said. However, it has been found to infect more than 10,000 Linux-based routers, mostly in China and Brazil.

Ifwatch was first discovered by an independent researcher in 2014 and connects routers to a peer-to-peer network that is used to distribute threat updates.

Even though it initially looked like just another botnet, Symantec researchers found Ifwatch was “more sophisticated” than a normal infection. They found that Ifwatch removed well-known families of malware that usually target routers, and it even tells users to change their password and upgrade firmware, which is another way to defend against malicious hackers.

It looks like the Ifwatch’s creator wanted it to be discovered. The Ifwatch author left a comment in the source code that references an email signature used by software freedom activist Richard Stallman, which reads:

“To any NSA and FBI agents reading my email: please consider whether defending the U.S. Constitution against all enemies, foreign or domestic, requires you to follow Snowden’s example.”

The Symantec researchers are quick to point out that Ifwatch is illegal and uses the same backdoors that more malicious hackers enter through. However, after months of investigation, the researchers have found that Ifwatch’s creator has yet to do anything malicious making them wonder whether this altruistic hack is an attempt to improve everyone’s privacy or just a very smart diversion.

Supposedly a hard reset on the router to return it to the factory default state will remove the worm... although anyone would be smart to change the default settings on any router they set up to reduce the chances of getting compromised.

Interesting development imo considering the comment in the code.


....
 

master_shake_

Diamond Member
May 22, 2012
6,425
292
121
Sounds like the opposite of malware to me.

It's more like an antivirus utility. But this one actually does something
No wonder Symantec doesn't like it.