VPNFilter malware infecting 500K devices is worse than was thought
1–10 of 45 posts
Re: VPNFilter malware infecting 500K devices is worse than was thought
#2That way, destructive updates could be blocked for as long as possible. Or save you from having to re-flash your receiver through desoldering a TSOP.
Perhaps we need the same thing on routers.
Or a group to run a “honeypot” of routers with a sensor on this EEPROM pin to identify when unauthorized updates have been installed and need investigation.
This won’t work for non-persistent hacks. But for anything that wants to last longer than a reboot...
Re: VPNFilter malware infecting 500K devices is worse than was thought
#3Re: VPNFilter malware infecting 500K devices is worse than was thought
#4Anyone else having fun with the minor panic attacks incited by slow page-loads?
Re: VPNFilter malware infecting 500K devices is worse than was thought
#5Re: VPNFilter malware infecting 500K devices is worse than was thought
#6Obviously the idea is to make sure the image in ROM is simple enough that it's really damn unlikely that it can be attacked, or attacked before the correct and intended firmware is downloaded and installed.
Re: VPNFilter malware infecting 500K devices is worse than was thought
#7Re: VPNFilter malware infecting 500K devices is worse than was thought
#8The most concerning aspect of this is the lack of details surrounding the initial attack vector and the fact that the IoC list is effectively useless to anyone downstream of these devices which sit at the perimeter of your network. Anyone else having fun with the minor panic attacks incited by slow page-loads?
So unless you were capturing incoming packets at that time, we may not know.
Re: VPNFilter malware infecting 500K devices is worse than was thought
#9Re: VPNFilter malware infecting 500K devices is worse than was thought
#10That sounds as sophisticated as a drug dealer calling their pills “beans” or “almonds”. Like, it’s intelligent, but it’s just 1 step removed from just coding in the IP directly.