Re: [VulnDiscuss] ADSL Routers and Sasser

"AJ Butcher, Information Systems and Computing" <[email protected]> Mon, 17 May 2004 08:53:37 +0100
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>

--On 12 May 2004 17:16 +0100 Security Info <[email protected]> wrote:

> I have noticed a considerable increase in what appears to be DoS attacks
> on BT Routers. (For those of you not in the UK, BT pretty much own the
> xDSL market over here)
> Almost all ADSL installations in the UK have a BT branded Efficient
> Networks 5861 ADSL Router.
> A bugtraq post on 10th January
> (http://seclists.org/lists/bugtraq/2003/Jan/0069.html) details a DoS
> attack caused by a simple port scan.
> My limited understanding of the Sasser worm and it's variants leads me to
> believe that upon infection, a machine then sends a SYN packet to a
> random IP address (52% of the time). This I believe, is causing
> widespread denial of service attacks to UK ADSL customers. BT deny all
> knowledge of any problems, and the engineers have not been informed of a
> firmware update at this time.
> If anyone can prove me wrong or shed any more light on the subject I
> would be grateful for your comments.

Whilst a SYN scan may well affect EN5861 routers detrimentally, I'd say 
that most UK ADSL users are using various USB ADSL modems such as the 
Alcatel "Frog" or equivalent Fujitsu or Intel devices. Only two people I 
know have ever used EN5861s, and they were both technically sophisticated 
early-adopter types. One of these people is now using a ZyXEL router, too.

Now that there are reasonable ADSL routers from around 30GBP and 
"wires-only" ADSL provision is a popular choice, I wouldn't expect the 
number of deployed EN5861 devices to increase much, if at all.

Also, I think it's fair to reserve the term "DoS Attack" for instances 
where the DoS is the intended outcome, rather than a side effect of 
attempting to discover vulnerable machines. It doesn't sound like this is 
the case in this instance.

> Regards,
> Greg.

Best Regards,
Alex.
-- 
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing             GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9