|
|||||||
![]() |
|
|
Thread Tools |
|
|
#1 |
|
Player Character
bit-tech Staff
Join Date: Apr 2007
Posts: 7,940
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Trojan modifies routers' DNS
http://www.bit-tech.net/news/2008/06...-routers-dns/1
SecureComputing has reported a new variant of the DNSChanger trojan, a nasty bug which attempts to reconfigure your broadband router to point at compromised DNS servers.
__________________
|
|
|
|
|
|
#2 |
|
inch-perfect
Join Date: Jun 2007
Location: cannoning into the reds, Toronto, Canada
Posts: 2,456
![]() |
Clearly, this is a problem for those with shite routers.
__________________
**Defunct** Socket 939 San Diego 4000+::2GB PC3200::Radeon 9600 SE 128MB::200GB HDD::24" Dell 2407WFP-HC::WinXP x64/x86 dual boot
Dell Vostro 1500 laptop::Socket P Merom T7100::2GB PC5400::Go 8600m GT 256MB::660GB HDD::15.4" WXGA+, 24" Dell 2407WFP-HC::WinXP::Fanatec 911 Wheel+Pedals |
|
|
|
|
|
#3 |
|
/dev/null
Join Date: Aug 2005
Location: Belgium
Posts: 4,102
![]() ![]() |
Or real insecure setups
__________________
There Are 10 Types Of People, Those Who Know Binary and Those Who Don't |
|
|
|
|
|
#4 |
|
Just some guy; you know
Join Date: Feb 2003
Location: Brisbane, Australia
Posts: 773
![]() |
or
Admin Admin
__________________
|
|
|
|
| taliban_raider |
| View Public Profile |
| Find More Posts by taliban_raider |
|
|
#6 |
|
Victim of AdvancedModernCapitalism
Join Date: Nov 2006
Location: The town of Love, Funchal
Posts: 597
![]() |
DD-WRT <3
__________________
Netbook: Asus eeePC 901; 12Gb SDD; Custom Ubuntu 9.04 Minimal Compiz Standalone.
Laptop: Intel Centrino Duo T5500 1.66ghz; 2048mb RAM; ATI Mobility Radeon x2300; Hitachi 120gb iPod Classic 120GB; Maxtor 160GB External; Ubuntu 9.10 x64 and Windows 7 x64. |
|
|
|
|
|
#7 |
|
Madeira's banana is the best!!!
Join Date: Sep 2005
Location: Madeira ; Portugal
Posts: 6,461
![]() ![]() ![]() ![]() ![]() ![]() ![]() |
still vulnerable if you are an idiot and leave it as admin admin or something daft like that....
__________________
Renegade X - 0.40 Release! <---- CLICK! |
|
|
|
|
|
#8 |
|
Spoon? What spoon?
Join Date: Dec 2006
Location: Daytona Beach, FL
Posts: 936
![]() |
these have actually been used on larger targets for much longer, since some corporations insist on not using customized settings in favor of shorter deployment time.
its interesting though that its now being used for standard phishing scams rather than corporate espionage. |
|
|
|
| Bluephoenix |
| View Public Profile |
| Find More Posts by Bluephoenix |
|
|
#9 | |
|
Why not? I own a domain to match.
Join Date: Feb 2004
Location: An hour north of Boston
Posts: 12,576
![]() ![]() ![]() |
Quote:
__________________
hire me @ eric-stern.com - web developer and php ninja
pics @ my smugmug :: Twitter @firehed :: blog @ firehed.net 40D|580EXII|285HV|AB800|70-200f/4LIS|17-50f/2.8|150f/2.8Macro|50f/1.8 MacPro @ 8x2.8GHz, 10GB FBDDR2, 3TB HD :: MBP @ 2x2.2GHz, 4GB DDR2, 320GB HD |
|
|
|
|
|
|
#10 |
|
Banned
Join Date: Apr 2008
Posts: 21
![]() |
This is why I have memorized a 12 character password which is consisted of totally random numbers, caps and letters. Even then, my router makes use of technologies to make it virtually invisible apart from the computer IP's which I assign to it.
Noting is ever 100% secure, however, if you just take your time to actually setup your router and network properly with relevant security measures taken then it shouldn't be a problem. |
|
|
|
| DannyDirect |
| View Public Profile |
| Find More Posts by DannyDirect |
|
|
#11 |
|
Supermodder
Join Date: May 2004
Location: Idaho U.S.A
Posts: 343
![]() |
I thought a router wouldnt respond to a login attempt from the wan side, only the lan side....?
__________________
(Phenom II 940)(Foxcon A7DA)(8gb OCZ DDR2 800 )(8800gt aka hair dryer)(Big yellow case, CPU, GPU)(Enermax Liberty 500w)(lite-on DVD-RW w/LightScribe)(Seagate 300gb sata)(Seagate 320gb x2)(WD 200gb)(Dell 3007WFP 30"LCD, 19" Samsung, Acer 1280x720 projector) |
|
|
|
|
|
#12 | |
|
Multimodder
Join Date: May 2004
Location: Rome, Italy
Posts: 140
![]() |
Quote:
|
|
|
|
|
|
|
#13 | |
|
WIIGII!
Join Date: Dec 2007
Location: Bradford, UK
Posts: 433
![]() |
Quote:
|
|
|
|
|
|
|
#14 |
|
Officious Bystander
Join Date: May 2003
Location: Nodnol
Posts: 1,595
![]() |
I'm sorry to admit it, but I'm actually quite impressed by the devious ingenuity of this. Not that there's any excuse for this sort of thing mind.
The clever part is that most people don't ever check their router's settings unless their internet connection disappears. This attack very effectively puts a man in the middle for every computer in the network, which can get there by infecting a single machine with a Trojan and which remains there even if the Trojan is removed or if the whole computer is removed.
__________________
Demand Naked DSL in the UK! |
|
|
|
|
|
#15 |
|
Dont do that...
Join Date: Jun 2007
Location: Alberta, Canada
Posts: 3,068
![]() ![]() |
so it infects your pc and then goes after the router, so if I run something like AVG i'm safe right?
but that would have to be on every pc on the network, and if someone comes over to my house and I let them on my network and they have the trojan, then I'm in danger? right? or did I miss something. Once a router gets affected by this how would you know about it and how would you fix it?
__________________
attack life, it's going to kill you anyway. Long-term relationships are like urban tomatoes: they only grow under special conditions. - Prestidigitweeze Don't hold on to the reigns once you've fallen off the horse, your just going to get dragged to death - SNiiPE_DoGG |
|
|
|
|
|
#16 |
|
I also ride trials :¬)
Join Date: Apr 2004
Location: Fallowfield, Manchester
Posts: 2,233
![]() |
It is somewhat worrying that my PC (albeit via Firefox which is largely bulletproof) knows the passwords to my router login anyway... A 12 digit random password is no use if it's stored on your (infected) PC!
__________________
Carrot cake cheesecake Shuttle SN85G4V2 | A64 3200+ / Apple PowerBook 12 |
|
|
|
|
|
#17 | |||
|
Hypermodder
Join Date: Feb 2006
Location: Ontario, CANADA
Posts: 718
![]() |
Quote:
oh there are ways. Quote:
or admin - 1234 or admin - smc1234 or admin - [blank] or administrator - [blank] list goes on and on...
__________________
Monita DFI NF4 Expert - X2 3800+ 2.925Ghz - 2x1Gb OCZ Gold XTC DDR500 - 2x eVGA 7900GT SLI - 2x80Gb Seagate 7200.9 [RAID-0 4k] - Enermax Liberty 500 - Vista Ultimate x86 - Silverstone Kublai [Modded] Keisha DFI BloodIron P35 - Q6600 3.6Ghz - 4x1Gb OCZ Gold XTC2 DDR2-800 - eVGA 8800GTS 640MB - 2x80Gb Seagate 7200.9 [RAID-0 4k] - OCZ GameXstream 700 - Vista Ultimate x86 - Silverstone TJ-06 [Modded] www.pecelayam.com |
|||
|
|
|
|
|
#18 | |
|
Hypermodder
Join Date: Feb 2006
Location: Ontario, CANADA
Posts: 718
![]() |
Quote:
once the router's whacked, anything under the router's network will get some really bad domain name redirection. how would u kno about it? tough. i recommend just resetting ur router to factory default and/or update/refresh its firmware, THEN lock it down; such as giving it a tough password and turning off remote access from WAN n stuff... edit: actually, the trustedsource link there gives a couple good examples on how to test if ur infected or not
__________________
Monita DFI NF4 Expert - X2 3800+ 2.925Ghz - 2x1Gb OCZ Gold XTC DDR500 - 2x eVGA 7900GT SLI - 2x80Gb Seagate 7200.9 [RAID-0 4k] - Enermax Liberty 500 - Vista Ultimate x86 - Silverstone Kublai [Modded] Keisha DFI BloodIron P35 - Q6600 3.6Ghz - 4x1Gb OCZ Gold XTC2 DDR2-800 - eVGA 8800GTS 640MB - 2x80Gb Seagate 7200.9 [RAID-0 4k] - OCZ GameXstream 700 - Vista Ultimate x86 - Silverstone TJ-06 [Modded] www.pecelayam.com |
|
|
|
|
|
|
#19 |
|
inch-perfect
Join Date: Jun 2007
Location: cannoning into the reds, Toronto, Canada
Posts: 2,456
![]() |
My router password isn't even English.
__________________
**Defunct** Socket 939 San Diego 4000+::2GB PC3200::Radeon 9600 SE 128MB::200GB HDD::24" Dell 2407WFP-HC::WinXP x64/x86 dual boot
Dell Vostro 1500 laptop::Socket P Merom T7100::2GB PC5400::Go 8600m GT 256MB::660GB HDD::15.4" WXGA+, 24" Dell 2407WFP-HC::WinXP::Fanatec 911 Wheel+Pedals |
|
|
|
|
|
#20 |
|
DUR HUR
Join Date: Nov 2005
Location: Bristol, UK
Posts: 5,676
![]() ![]() |
Wow, I just realised my router doesn't even have a login screen thingy
|
|
|
|
![]() |
| Thread Tools | |
|
|