RSS



Go Back   bit-tech.net Forums > bit-tech.net > Article Discussion

Reply
 
Thread Tools
Old 18th Jun 2008, 11:33   #1
CardJoe
Player Character
bit-tech Staff
 
CardJoe's Avatar
 
Join Date: Apr 2007
Posts: 7,940
CardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to behold
Trojan modifies routers' DNS

http://www.bit-tech.net/news/2008/06...-routers-dns/1

SecureComputing has reported a new variant of the DNSChanger trojan, a nasty bug which attempts to reconfigure your broadband router to point at compromised DNS servers.

__________________
CardJoe is offline   Reply With Quote
Old 18th Jun 2008, 11:47   #2
Amon
inch-perfect
 
Amon's Avatar
 
Join Date: Jun 2007
Location: cannoning into the reds, Toronto, Canada
Posts: 2,456
Amon is on a distinguished road
Clearly, this is a problem for those with shite routers.
__________________
**Defunct** Socket 939 San Diego 4000+::2GB PC3200::Radeon 9600 SE 128MB::200GB HDD::24" Dell 2407WFP-HC::WinXP x64/x86 dual boot
Dell Vostro 1500 laptop::Socket P Merom T7100::2GB PC5400::Go 8600m GT 256MB::660GB HDD::15.4" WXGA+, 24" Dell 2407WFP-HC::WinXP::Fanatec 911 Wheel+Pedals
Amon is offline   Reply With Quote
Old 18th Jun 2008, 11:54   #3
Glider
/dev/null
 
Glider's Avatar
 
Join Date: Aug 2005
Location: Belgium
Posts: 4,102
Glider has a spectacular aura aboutGlider has a spectacular aura about
Or real insecure setups
__________________
There Are 10 Types Of People, Those Who Know Binary and Those Who Don't
Glider is offline   Reply With Quote
Old 18th Jun 2008, 12:18   #4
taliban_raider
Just some guy; you know
 
taliban_raider's Avatar
 
Join Date: Feb 2003
Location: Brisbane, Australia
Posts: 773
taliban_raider is on a distinguished road
or
Admin
Admin
__________________
taliban_raider is offline   Reply With Quote
Old 18th Jun 2008, 13:11   #5
liratheal
Just got a great book on tape
 
liratheal's Avatar
 
Join Date: Nov 2005
Location: High Wycombe, UK
Posts: 3,551
liratheal is a splendid one to beholdliratheal is a splendid one to beholdliratheal is a splendid one to beholdliratheal is a splendid one to beholdliratheal is a splendid one to beholdliratheal is a splendid one to beholdliratheal is a splendid one to behold
What are factory defaults?

=P
__________________
Gigabyte MA790FX, X4 9950 Black Edition, 8gb Geil Black Dragon, 2x4870 512mb, Antec TruePower Quattro 850w

I game, Do you?
liratheal is offline   Reply With Quote
Old 18th Jun 2008, 13:41   #6
proxess
Victim of AdvancedModernCapitalism
 
Join Date: Nov 2006
Location: The town of Love, Funchal
Posts: 597
proxess is on a distinguished road
DD-WRT <3
__________________
Netbook: Asus eeePC 901; 12Gb SDD; Custom Ubuntu 9.04 Minimal Compiz Standalone.
Laptop: Intel Centrino Duo T5500 1.66ghz; 2048mb RAM; ATI Mobility Radeon x2300; Hitachi 120gb iPod Classic 120GB; Maxtor 160GB External; Ubuntu 9.10 x64 and Windows 7 x64.
proxess is offline   Reply With Quote
Old 18th Jun 2008, 13:46   #7
DXR_13KE
Madeira's banana is the best!!!
 
DXR_13KE's Avatar
 
Join Date: Sep 2005
Location: Madeira ; Portugal
Posts: 6,461
DXR_13KE is a splendid one to beholdDXR_13KE is a splendid one to beholdDXR_13KE is a splendid one to beholdDXR_13KE is a splendid one to beholdDXR_13KE is a splendid one to beholdDXR_13KE is a splendid one to beholdDXR_13KE is a splendid one to behold
Quote:
Originally Posted by proxess View Post
DD-WRT <3
still vulnerable if you are an idiot and leave it as admin admin or something daft like that....
__________________
Renegade X - 0.40 Release! <---- CLICK!
DXR_13KE is offline   Reply With Quote
Old 18th Jun 2008, 14:08   #8
Bluephoenix
Spoon? What spoon?
 
Bluephoenix's Avatar
 
Join Date: Dec 2006
Location: Daytona Beach, FL
Posts: 936
Bluephoenix is on a distinguished road
these have actually been used on larger targets for much longer, since some corporations insist on not using customized settings in favor of shorter deployment time.

its interesting though that its now being used for standard phishing scams rather than corporate espionage.
Bluephoenix is offline   Reply With Quote
Old 18th Jun 2008, 14:39   #9
Firehed
Why not? I own a domain to match.
 
Firehed's Avatar
 
Join Date: Feb 2004
Location: An hour north of Boston
Posts: 12,576
Firehed has a spectacular aura aboutFirehed has a spectacular aura aboutFirehed has a spectacular aura about
Quote:
Originally Posted by Amon
Clearly, this is a problem for those with shite routers.
No, it's a problem for those with shite habits (one of which being leaving the router password as default, and of course doing stupid things that get you trojans in the first place). There's no need for AV software if you don't act like a tool on your computer, no matter what OS you're using. Not so much for firewalls, but that's a separate issue.
__________________
hire me @ eric-stern.com - web developer and php ninja
pics @ my smugmug :: Twitter @firehed :: blog @ firehed.net
40D|580EXII|285HV|AB800|70-200f/4LIS|17-50f/2.8|150f/2.8Macro|50f/1.8
MacPro @ 8x2.8GHz, 10GB FBDDR2, 3TB HD :: MBP @ 2x2.2GHz, 4GB DDR2, 320GB HD
Firehed is offline   Reply With Quote
Old 18th Jun 2008, 15:12   #10
DannyDirect
Banned
 
Join Date: Apr 2008
Posts: 21
DannyDirect is on a distinguished road
This is why I have memorized a 12 character password which is consisted of totally random numbers, caps and letters. Even then, my router makes use of technologies to make it virtually invisible apart from the computer IP's which I assign to it.
Noting is ever 100% secure, however, if you just take your time to actually setup your router and network properly with relevant security measures taken then it shouldn't be a problem.
DannyDirect is offline   Reply With Quote
Old 18th Jun 2008, 15:35   #11
-EVRE-
Supermodder
 
-EVRE-'s Avatar
 
Join Date: May 2004
Location: Idaho U.S.A
Posts: 343
-EVRE- is on a distinguished road
I thought a router wouldnt respond to a login attempt from the wan side, only the lan side....?
__________________
(Phenom II 940)(Foxcon A7DA)(8gb OCZ DDR2 800 )(8800gt aka hair dryer)(Big yellow case, CPU, GPU)(Enermax Liberty 500w)(lite-on DVD-RW w/LightScribe)(Seagate 300gb sata)(Seagate 320gb x2)(WD 200gb)(Dell 3007WFP 30"LCD, 19" Samsung, Acer 1280x720 projector)
-EVRE- is offline   Reply With Quote
Old 18th Jun 2008, 15:44   #12
plagio
Multimodder
 
Join Date: May 2004
Location: Rome, Italy
Posts: 140
plagio is on a distinguished road
Quote:
Originally Posted by -EVRE-
I thought a router wouldnt respond to a login attempt from the wan side, only the lan side....?
Yeah, me too. Maybe this trojan first has to enter your PC.
plagio is offline   Reply With Quote
Old 18th Jun 2008, 15:50   #13
Gareth Halfacree
WIIGII!
 
Gareth Halfacree's Avatar
 
Join Date: Dec 2007
Location: Bradford, UK
Posts: 433
Gareth Halfacree is on a distinguished road
Quote:
Originally Posted by plagio
Yeah, me too. Maybe this trojan first has to enter your PC.
Bingo. It infects Windows PCs, then attacks whatever IP is assigned as the default gateway.
__________________
gareth.halfacree.co.uk | twitter!
bit-tech news correspondent
Gareth Halfacree is offline   Reply With Quote
Old 18th Jun 2008, 17:41   #14
mclean007
Officious Bystander
 
mclean007's Avatar
 
Join Date: May 2003
Location: Nodnol
Posts: 1,595
mclean007 is on a distinguished road
I'm sorry to admit it, but I'm actually quite impressed by the devious ingenuity of this. Not that there's any excuse for this sort of thing mind.

The clever part is that most people don't ever check their router's settings unless their internet connection disappears. This attack very effectively puts a man in the middle for every computer in the network, which can get there by infecting a single machine with a Trojan and which remains there even if the Trojan is removed or if the whole computer is removed.
__________________
Demand Naked DSL in the UK!
mclean007 is offline   Reply With Quote
Old 18th Jun 2008, 20:12   #15
chrisb2e9
Dont do that...
 
chrisb2e9's Avatar
 
Join Date: Jun 2007
Location: Alberta, Canada
Posts: 3,068
chrisb2e9 has a spectacular aura aboutchrisb2e9 has a spectacular aura about
so it infects your pc and then goes after the router, so if I run something like AVG i'm safe right?
but that would have to be on every pc on the network, and if someone comes over to my house and I let them on my network and they have the trojan, then I'm in danger?
right?
or did I miss something.
Once a router gets affected by this how would you know about it and how would you fix it?
__________________
attack life, it's going to kill you anyway.
Long-term relationships are like urban tomatoes: they only grow under special conditions. - Prestidigitweeze
Don't hold on to the reigns once you've fallen off the horse, your just going to get dragged to death - SNiiPE_DoGG
chrisb2e9 is offline   Reply With Quote
Old 18th Jun 2008, 20:22   #16
Tomm
I also ride trials :¬)
 
Tomm's Avatar
 
Join Date: Apr 2004
Location: Fallowfield, Manchester
Posts: 2,233
Tomm is on a distinguished road
It is somewhat worrying that my PC (albeit via Firefox which is largely bulletproof) knows the passwords to my router login anyway... A 12 digit random password is no use if it's stored on your (infected) PC!
__________________
Carrot cake cheesecake
Shuttle SN85G4V2 | A64 3200+ / Apple PowerBook 12
Tomm is offline   Reply With Quote
Old 18th Jun 2008, 22:38   #17
Redbeaver
Hypermodder
 
Redbeaver's Avatar
 
Join Date: Feb 2006
Location: Ontario, CANADA
Posts: 718
Redbeaver will become famous soon enough
Quote:
Originally Posted by Gareth Halfacree
Quote:
Originally Posted by plagio
Yeah, me too. Maybe this trojan first has to enter your PC.
Bingo. It infects Windows PCs, then attacks whatever IP is assigned as the default gateway.
not necessarily. some routers by default provide admin access from WAN as well. or remote-management firewall turned on by default. or zero firewall policies even. and to top it off, there are ways to spoof ur way into the router confusing WAN and LAN.

oh there are ways.

Quote:
Originally Posted by taliban_raider
or
Admin
Admin
gotta love this one.

or admin - 1234
or admin - smc1234
or admin - [blank]
or administrator - [blank]

list goes on and on...
__________________
Monita DFI NF4 Expert - X2 3800+ 2.925Ghz - 2x1Gb OCZ Gold XTC DDR500 - 2x eVGA 7900GT SLI - 2x80Gb Seagate 7200.9 [RAID-0 4k] - Enermax Liberty 500 - Vista Ultimate x86 - Silverstone Kublai [Modded]
Keisha DFI BloodIron P35 - Q6600 3.6Ghz - 4x1Gb OCZ Gold XTC2 DDR2-800 - eVGA 8800GTS 640MB - 2x80Gb Seagate 7200.9 [RAID-0 4k] - OCZ GameXstream 700 - Vista Ultimate x86 - Silverstone TJ-06 [Modded]
www.pecelayam.com
Redbeaver is offline   Reply With Quote
Old 18th Jun 2008, 22:42   #18
Redbeaver
Hypermodder
 
Redbeaver's Avatar
 
Join Date: Feb 2006
Location: Ontario, CANADA
Posts: 718
Redbeaver will become famous soon enough
Quote:
Originally Posted by chrisb2e9
so it infects your pc and then goes after the router, so if I run something like AVG i'm safe right?
but that would have to be on every pc on the network, and if someone comes over to my house and I let them on my network and they have the trojan, then I'm in danger?
right?
or did I miss something.
Once a router gets affected by this how would you know about it and how would you fix it?
well once it succesfully infects ur router, it could care less if there's any trojan in any computer of the network.

once the router's whacked, anything under the router's network will get some really bad domain name redirection.

how would u kno about it? tough. i recommend just resetting ur router to factory default and/or update/refresh its firmware, THEN lock it down; such as giving it a tough password and turning off remote access from WAN n stuff...

edit: actually, the trustedsource link there gives a couple good examples on how to test if ur infected or not
__________________
Monita DFI NF4 Expert - X2 3800+ 2.925Ghz - 2x1Gb OCZ Gold XTC DDR500 - 2x eVGA 7900GT SLI - 2x80Gb Seagate 7200.9 [RAID-0 4k] - Enermax Liberty 500 - Vista Ultimate x86 - Silverstone Kublai [Modded]
Keisha DFI BloodIron P35 - Q6600 3.6Ghz - 4x1Gb OCZ Gold XTC2 DDR2-800 - eVGA 8800GTS 640MB - 2x80Gb Seagate 7200.9 [RAID-0 4k] - OCZ GameXstream 700 - Vista Ultimate x86 - Silverstone TJ-06 [Modded]
www.pecelayam.com
Redbeaver is offline   Reply With Quote
Old 18th Jun 2008, 23:48   #19
Amon
inch-perfect
 
Amon's Avatar
 
Join Date: Jun 2007
Location: cannoning into the reds, Toronto, Canada
Posts: 2,456
Amon is on a distinguished road
My router password isn't even English.
__________________
**Defunct** Socket 939 San Diego 4000+::2GB PC3200::Radeon 9600 SE 128MB::200GB HDD::24" Dell 2407WFP-HC::WinXP x64/x86 dual boot
Dell Vostro 1500 laptop::Socket P Merom T7100::2GB PC5400::Go 8600m GT 256MB::660GB HDD::15.4" WXGA+, 24" Dell 2407WFP-HC::WinXP::Fanatec 911 Wheel+Pedals
Amon is offline   Reply With Quote
Old 19th Jun 2008, 01:01   #20
Veles
DUR HUR
 
Veles's Avatar
 
Join Date: Nov 2005
Location: Bristol, UK
Posts: 5,676
Veles will become famous soon enoughVeles will become famous soon enough
Wow, I just realised my router doesn't even have a login screen thingy
__________________
Veles on: Xbox Live (My Halo stats), Steam Community, Twitter

Quote:
Originally Posted by Fod View Post
spam gangsters might as well tap into all those machines for their zombie networks.
Veles is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 18:58.
Powered by: vBulletin Version 3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.