New Linux worm targets routers, cameras, “Internet of things” devices
arstechnica.com
arstechnica.com
This make no sense. Running Linux (or an OSS stack in general) is not what makes devices out of date. Not updating them does.
If updates are not automatic then the vast majority of people will not perform them. If they're not automatic and a pain in the ass to do (ever tried updating the firmware on a TV?) then even less will do it.
I'm not saying I want auto updates for everything (I personally don't like them though the option is nice) but for the vast majority of folks it's the right option. $NON_TECH_SAVVY_RELATIVE is not going to keep tabs on the latest exploits for her router and know when to login to the management console (assuming she can login) and apply an update.
I can see how you'd read it that way, but I think the intent of the sentence is to state that they're running woefully out of date versions of Linux, not that Linux itself is woefully out of date.
Had it instead said:
*"they typically run Linux versions that are woefully out of date."*
or *"they typically run versions of Linux or other operating systems that are out of date."*
then there would not be a problem.Since the real problem is out of date software, not the license that software happens to have, mentioning the license makes it sound like the author is blaming the license (a problem that is made worse by not including some "version" wording).
Considering the awkwardness of the phrase "other types of open source code" (what do we mean other "types"? Other licenses? Other languages? I don't think they intend either of those, what they mean is other projects, not types), I have to assume that the author did not intend any sort of slight and this is just a misunderstanding.
They probably included the "other types of open source code" section because that is frankly what is common with these sort of devices. It is an incidental detail that got confused with the point because the author is not as precise with the language surrounding this topic as we are.
Note that the article mentions Intel routers (x86 cpus?). Those are indeed not very common to my knowledge.
I think you can do this by serving the user a hidden form that e.g. sends a firmware to the device, and a real form that they are likely to submit. The hidden form is the one that actually gets submitted. But I thought anything via XHR wouldn't work. Which is needed for a brute force attack say.
What did you find?
In which case, I woner why more sites (or evil ads via an ad network) don't attack our home routers?
My first router could only do the 192.168 range so I got in the habit of it. Later with subsequent routers, all my devices were already set up on a specific class C network, so it was easier to change the router than go through all the devices and change them.