Mystery malware destroys 600,000 routers from a single ISP during 72-hour span

termain@programming.dev to Technology@lemmy.world – 204 points –
Mystery malware destroys 600,000 routers from a single ISP during 72-hour span
arstechnica.com
26

You are viewing a single comment

As someone who works with 100Gbps networking:

  • why the heck do these routers run Lua of all things???

OpenWRT uses Lua for its web UI. The interpreter can be really small which works well for tiny embedded devices with mere megabytes of storage, and it's much safer than writing a web GUI entirely in C.

Yeah I completely forgot about the consumer side of things. I was expecting there being Cisco iOS/FRR router configs, not a full web dashboard.

I imagine the malware binary includes a lua interpreter for executing scripts fetched from its command and control server.