Malware on RPi
#1
Seems that there is some malware on the loose, called Linux.MulDrop.14, that infects linux based systems with a default user called pi presumably on Rasmbmc OS.
This malware then changes the password to “\$6\$U1Nu9qCp\$FhPuo8s5PsQlH6lwUdTwFcAUPNzmr0pWCdNJj.p6l4Mzi8S867YLmc7BspmEH95POvxPQ3PzP029yT1L3yi6K1” searches for other RPi's on your network and also starts to mine bitcoin.

I suspect it wouldn't be out of the question for the malware to be modded to check for and thus infect other distributions like LibreElec, OpenElec, OSMC, etc.

Guess this just goes to show how bad it is for a distribution to not allow the user to change default user and password during an install process.
This behaviour is up there with the poor security focus often seen by those developing POE security cameras that are oh so hackable Tongue

Here is another link discussing Linux.MulDrop.14 which also links to SMB vulnerability discussion...

Does Team Kodi have any opinions on such maters and do you guys have any sway in pushing for better security standards within distributions like LibreELec, OpenElec, Zbian, Raspbmc, OSMC, etc that contain Kodi?

Is it worth having a security forum?
I'm a XBMC novice :)
Reply


Messages In This Thread
Malware on RPi - by skylarking - 2017-06-09, 04:57
RE: Malware on RPi - by sraue - 2017-06-09, 05:48
RE: Malware on RPi - by GreySkies - 2017-06-09, 14:12
RE: Malware on RPi - by noggin - 2017-06-10, 14:14
RE: Malware on RPi - by ActionA - 2017-06-10, 15:03
RE: Malware on RPi - by KungFu - 2017-06-15, 15:33
RE: Malware on RPi - by cat2115 - 2017-06-09, 14:30
RE: Malware on RPi - by bry - 2017-06-09, 14:38
RE: Malware on RPi - by Sam.Nazarko - 2017-06-10, 19:59
RE: Malware on RPi - by Sholander - 2017-06-15, 18:38
RE: Malware on RPi - by KungFu - 2017-06-15, 18:51
RE: Malware on RPi - by nickr - 2017-06-15, 22:37
RE: Malware on RPi - by ActionA - 2017-06-15, 22:58
Logout Mark Read Team Forum Stats Members Help
Malware on RPi0