RE: [fw-wiz] Worms, Air Gaps and Responsibility

From: Frank Knobbe (frank_at_knobbe.us)
Date: 05/18/04

  • Next message: Kelly, Chris W.: "RE: [fw-wiz] Worms, Air Gaps and Responsibility - Cisco"
    To: Dana Nowell <DanaNowell@cornerstonesoftware.com>
    Date: Mon, 17 May 2004 23:06:00 -0500
    
    
    

    On Mon, 2004-05-17 at 13:02, Dana Nowell wrote:
    > Multiplatform attacks are due but I personally doubt the router is the
    > secondary target of choice, unfortunately my money's on PDAs and cell
    > phones via sync software and wireless.

    Perhaps for viruses, but not for worms as these devices tend not to be
    permanently wired or reachable.

    Several years ago, the folks from Phenoelit were presenting exploits on
    Cisco routers and HP printers. I had $20 on a worm that spreads through
    printers since there are frighteningly many printers directly connected
    to the Internet (after all, it's just a printer, right? :)
    Likewise, a worm ripping through Cisco routers gives me the creeps, but
    luckily these are often setup with a decent or secure enough
    configurations. (I don't recall there actually being a printer worm.)

    But what about Cable modems or DSL routers? Any component that is not a
    computer, or has services open, tends to be ignored/dismissed too
    quickly. Once we were shown that laser printers can be converted to do
    thy bidding in the form of password brute forcing and other... uhm...
    non-paper related tasks. Who would have thought...

    But you are right... It seems I'm dismissing cell phones and PDAs here,
    and I shouldn't be doing that.

    I believe there will be a worm at some time that will be totally
    unexpected. While we are busy securing hosts and networks, something
    nasty will rip. Not because we failed to protect ourselves, but because
    we didn't see it coming from that angle. Not a lack of ACLs, but a lack
    of contemplation, dare I say imagination.

    Better get your thumpers ready, worms signs are increasing....

    Regards,
    Frank

    
    

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



  • Next message: Kelly, Chris W.: "RE: [fw-wiz] Worms, Air Gaps and Responsibility - Cisco"

    Relevant Pages

    • RE: [fw-wiz] Worms, Air Gaps and Responsibility
      ... similar connections (yes some stuff is/can be built in by design but buffer ... >Cisco routers and HP printers. ... I had $20 on a worm that spreads through ...
      (Firewall-Wizards)
    • Re: a real way to stop an http based worm
      ... a real way to stop an http based worm ... suggest respectfully that routers are the first step to start of with, ... Those peering agreements, most do NOT allow blocking of any traffic, are a ... against any current worm, but also a fast and sure defense against new ones. ...
      (Vuln-Dev)
    • RE: nimda tries to send mail after reboot
      ... nimda tries to send mail after reboot ... routers. ... > Messages bearing the worm are starting to trickle in, ...
      (Incidents)
    • Re: What Is A "Weak Network Share"
      ... system with BUGBEAR Virus or Worm or whatever it is. ... > symptoms is it sends print job after print job to shared printers. ...
      (microsoft.public.win2000.networking)
    • Re: Can a router be infected?
      ... Linksys Routers. ... firmware could be conceived. ... "As described in the Drone BL Blog the worm works with a brute force attack using ...
      (alt.computer.security)