Jump to content

Wifatch good router virus?

Hi Community! 
Do you believe in Viruses that help people? Not? This might be one.

http://www.theverge.com/2015/10/1/9434521/router-virus-fights-off-malware-security

 

 

 

Routers are among the most hackable devices out there — rarely updated, easily compromised, and almost never scanned for viruses. But a new router virus might actually be making the devices safer, according to a report from the security firm Symantec. Dubbed Linux.Wifatch, the bug behaves like a regular virus from the outside: infecting the device, operating undetected, and coordinating actions through a peer-to-peer network. But instead of performing DDoS attacks or looking for sensitive data, Wifatch's main role seems to be keeping other viruses out. It stays up to date on virus definitions through its peer-to-peer network, deletes any malware discovered, and cuts off other channels malware would typically use to attack the router. In short, Wifatch is actually protecting its victims.

It's still unclear where Wifatch comes from or why it was created, but it seems to be very different from the average virus. First detected by a researcher in 2014, the virus seems to make little effort to conceal itself, and leaves various benign messages in its code. One, triggered when a user tries to access the Telnet feature, reminds users to update the device's firmware. Another, dropped as a comment in the source code, repeats a statement from free-software icon Richard Stallman: "To any NSA or FBI agents reading this: please consider whether defending the US constitution against all enemies, foreign or domestic, requires you to follow Snowden's example."
 

 

Symantec estimates "somewhere in the order of tens of thousands of devices" are infected with the virus, with infections largely focused on Brazil, China, and Mexico. Resetting a device is enough to remove the infection, but the firm warns that a router may become reinfected over time. "Symantec will be keeping a close eye on Linux.Wifatch and the activities of its mysterious creator," the post concludes. "Users are advised to keep their device’s software and firmware up to date."
 

Really cool thing imo. Didn't saw any post about but If there is one feel free to report my topic.
To be honest I don't believe this virus will harm anyone anytime soon, because it's known since 2014 and nothing has happend yet.

MfG Legion4-9-5

9 of 10 voices in my mind say I'm crazy. The tenth hums the melody of Tetris.

 

Link to comment
Share on other sites

Link to post
Share on other sites

that must have been an interesting find:

 

"errr ... we found a new virus, it's infecting routers"

"What does it do?"

"... it keeps other viruses out."

"0_o"

 

I can understand why Symantec want's to keep an eye on this though. What if the creator uses this to specifically let THEIR viruses (or other malicious software) in by having this virus give it the OK, or even disguise it.

 

Additionally, this means this virus is in the public domain, where more malicious folk may find how to crack it, or use it's own router penetration technique to put their own viruses into routers.

Aftermarket 980Ti >= Fury X >= Reference 980Ti > Fury > 980 > 390X > 390 >= 970 380X > 380 >= 960 > 950 >= 370 > 750Ti = 360

"The Orange Box" || CPU: i5 4690k || RAM: Kingston Hyper X Fury 16GB || Case: Aerocool DS200 (Orange) || Cooler: Cryorig R1 Ultimate || Storage: Kingston SSDNow V300 240GB + WD Black 1TB || PSU: Corsair RM750 || Mobo: ASUS Z97-A || GPU: EVGA GTX 970 FTW+

"Unnamed Form Factor Switch" || CPU: i7 6700K || RAM: Kingston HyperX Fury 16GB || Case: Phanteks Enthoo Evolv Mini ITX (White) || Cooler: Cryorig R1 Ultimate (Green Cover) || Storage: Samsung 850 Evo 1TB || PSU: XFX XTR 550W || Mobo: ASUS Z170I Pro Gaming || GPU: EVGA GTX 970 FTW+

Link to comment
Share on other sites

Link to post
Share on other sites

i router should be just a router dont had server functionality to it and you will be fine

+ disable ssh upnp etc

 

the pfsense mantra

If your grave doesn't say "rest in peace" on it You are automatically drafted into the skeleton war.

Link to comment
Share on other sites

Link to post
Share on other sites

its not really a virus then, its more a forceful firewall.

cpu: intel i5 4670k @ 4.5ghz Ram: G skill ares 2x4gb 2166mhz cl10 Gpu: GTX 680 liquid cooled cpu cooler: Raijintek ereboss Mobo: gigabyte z87x ud5h psu: cm gx650 bronze Case: Zalman Z9 plus


Listen if you care.

Cpu: intel i7 4770k @ 4.2ghz Ram: G skill  ripjaws 2x4gb Gpu: nvidia gtx 970 cpu cooler: akasa venom voodoo Mobo: G1.Sniper Z6 Psu: XFX proseries 650w Case: Zalman H1

Link to comment
Share on other sites

Link to post
Share on other sites

This is actually a really great idea. Like...someone picking up trash on the side of a highway. Technically not legal, but still for the better good.

Link to comment
Share on other sites

Link to post
Share on other sites

So we will start the virus off nice and harmless... Once we infect the entire world we will unleash its bad side and chaos will reign throughout the world!!!

Bwhahahaha

^ my impression of the person who made this lol

"If a Lobster is a fish because it moves by jumping, then a kangaroo is a bird" - Admiral Paulo de Castro Moreira da Silva

"There is nothing more difficult than fixing something that isn't all the way broken yet." - Author Unknown

Spoiler

Intel Core i7-3960X @ 4.6 GHz - Asus P9X79WS/IPMI - 12GB DDR3-1600 quad-channel - EVGA GTX 1080ti SC - Fractal Design Define R5 - 500GB Crucial MX200 - NH-D15 - Logitech G710+ - Mionix Naos 7000 - Sennheiser PC350 w/Topping VX-1

Link to comment
Share on other sites

Link to post
Share on other sites

Oh wow, this totally made my day and reminded me of this

post-75028-0-65822900-1443879218.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

i router should be just a router dont had server functionality to it and you will be fine

+ disable ssh upnp etc

 

the pfsense mantra

Only issue with disabling UPNP is that its used by a lot of devices for port forwarding. Like games consoles, disabling it can cause closed NAT type etc.

System Specs:

CPU: Ryzen 7 5800X

GPU: Radeon RX 7900 XT 

RAM: 32GB 3600MHz

HDD: 1TB Sabrent NVMe -  WD 1TB Black - WD 2TB Green -  WD 4TB Blue

MB: Gigabyte  B550 Gaming X- RGB Disabled

PSU: Corsair RM850x 80 Plus Gold

Case: BeQuiet! Silent Base 801 Black

Cooler: Noctua NH-DH15

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I've always said someone should create a virus that hunts other viruses.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

I've always said someone should create a virus that hunts other viruses.

Someone needs to do that, create a virus that detects and automatically gets rid of unauthorized software, and clears the registry every few weeks.

Link to comment
Share on other sites

Link to post
Share on other sites

Someone needs to do that, create a virus that detects and automatically gets rid of unauthorized software, and clears the registry every few weeks.

Too bad it can't be engineered to hunt down the ass-hats that make viruses and destroy their computers

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Too bad it can't be engineered to hunt down the ass-hats that make viruses and destroy their computers

If it detects a virus that's been installed on the computer, have it look up where the virus came from, and then send a signal to a botnet somewhere which will then DDoS the website that made the virus.

 

Kind of like an automatic 4chan.

Link to comment
Share on other sites

Link to post
Share on other sites

Well this is... interesting. A virus that benefits the end user.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×