Router hacked? How can I avoid this?<p align=left><font face=Arial size=2></font> </p> <p>Background info of incident:</p> <p align=left> </p> <p align=left>I was trying out windows home server and went to DYNDNS.ORG for their free domain name service.</p> <p align=left>My internet connection is dynamic so I thought to use that.</p> <p align=left>The ports on my router that i opened at first were 443,4125 and 80 on tcp.</p> <p align=left>The router I was using was the BEFSX41 router form linksys.</p> <p align=left>The router's firmware was not at first updated.</p> <p align=left> </p> <p align=left>What happened:</p> <p align=left> </p> <p align=left>I had enabled the ports listed above (80,4125 and 443). At first I had issues with connection over the internet. So I disabled all the firewall options except for the SPI. Then enabled each one by one while checking on another connection to see if I still could connect to the home server (also had UPNP enabled).</p> <p align=left> </p> <p align=left>It got hacked, I could not chose anything on the gui for changes, my logs were all gone, time zone, date were changed and everything was select to open (it was as if my router was not even there). This was not too long after I had signed on to the DDNS through the router and after I made a free account there. The only way to reset the router was manually.</p> <p align=left> </p> <p align=left>So I went to linksys's site and saw there was a recent update (pathing a upnp vulnerability.. upgraded the firmware and it took. </p> <p align=left> </p> <p align=left>So I changed modems around, made a new account with dyndns and watched the connections for a bit the next day using a different connection.</p> <p align=left>a few hits came (this time I only set up 443 and 4125 and closed 80) in then I looked at the security for firewall and saw 113 was open (it was closed before). Noted the IP and moved on. a few minutes later I checked and it was completely toasted again (the linksys router). Wide OPEN to the internet.</p> <p align=left> </p> <p align=left>Needless to say I am not sure what to do. I am a engineering major and not a programmer.</p> <p align=left>I wanted to know what I could do to protect myself from this sort of thing. </p> <p align=left> </p> <p align=left> </p> <p align=left> </p> <p align=left> </p>© 2009 Microsoft Corporation. All rights reserved.Tue, 02 Sep 2008 21:36:21 Z2106cb94-3e15-4e08-a181-ead7a2c09346http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#2106cb94-3e15-4e08-a181-ead7a2c09346http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#2106cb94-3e15-4e08-a181-ead7a2c09346Sketchahhttp://social.microsoft.com/Profile/en-US/?user=SketchahRouter hacked? How can I avoid this?<p align=left><font face=Arial size=2></font> </p> <p>Background info of incident:</p> <p align=left> </p> <p align=left>I was trying out windows home server and went to DYNDNS.ORG for their free domain name service.</p> <p align=left>My internet connection is dynamic so I thought to use that.</p> <p align=left>The ports on my router that i opened at first were 443,4125 and 80 on tcp.</p> <p align=left>The router I was using was the BEFSX41 router form linksys.</p> <p align=left>The router's firmware was not at first updated.</p> <p align=left> </p> <p align=left>What happened:</p> <p align=left> </p> <p align=left>I had enabled the ports listed above (80,4125 and 443). At first I had issues with connection over the internet. So I disabled all the firewall options except for the SPI. Then enabled each one by one while checking on another connection to see if I still could connect to the home server (also had UPNP enabled).</p> <p align=left> </p> <p align=left>It got hacked, I could not chose anything on the gui for changes, my logs were all gone, time zone, date were changed and everything was select to open (it was as if my router was not even there). This was not too long after I had signed on to the DDNS through the router and after I made a free account there. The only way to reset the router was manually.</p> <p align=left> </p> <p align=left>So I went to linksys's site and saw there was a recent update (pathing a upnp vulnerability.. upgraded the firmware and it took. </p> <p align=left> </p> <p align=left>So I changed modems around, made a new account with dyndns and watched the connections for a bit the next day using a different connection.</p> <p align=left>a few hits came (this time I only set up 443 and 4125 and closed 80) in then I looked at the security for firewall and saw 113 was open (it was closed before). Noted the IP and moved on. a few minutes later I checked and it was completely toasted again (the linksys router). Wide OPEN to the internet.</p> <p align=left> </p> <p align=left>Needless to say I am not sure what to do. I am a engineering major and not a programmer.</p> <p align=left>I wanted to know what I could do to protect myself from this sort of thing. </p> <p align=left> </p> <p align=left> </p> <p align=left> </p> <p align=left> </p>Thu, 21 Aug 2008 23:37:32 Z2008-08-22T23:28:51Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#9375a577-be09-4e1c-9e71-c0a02f12bf37http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#9375a577-be09-4e1c-9e71-c0a02f12bf37Chris Cuplerhttp://social.microsoft.com/Profile/en-US/?user=Chris%20CuplerRouter hacked? How can I avoid this?<p align=left><font face=Arial size=2> <div class=quote> <table width="85%"> <tbody> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%">I wanted to know what I could do to protect myself from this sort of thing. </td></tr></tbody></table></td></tr></tbody></table></div>Very strong admin password for the router.  And, for the love of God, disable remote admin (AKA WAN admin access.)  There is really no reason that you should leave that enabled.</font> <p></p>Fri, 22 Aug 2008 00:31:25 Z2008-08-22T00:31:25Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#de713cd8-0079-4ff9-8f24-f9424f5f9e78http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#de713cd8-0079-4ff9-8f24-f9424f5f9e78Ken Warrenhttp://social.microsoft.com/Profile/en-US/?user=Ken%20WarrenRouter hacked? How can I avoid this?Turn off remote administration and change the password. Those are the two things you should do immediately. I would also turn off UPnP and configure port forwarding manually.<br><br>But in the longer term, someone has figured out that you're vulnerable to attack, and they're trying to set up a mail relay through your router (port 113). Perhaps replacing the router would be a better option. I think highly of DLink (except the DIR-655, which a lot of people here have had problems with) and Netgear. I have a SonicWall myself, but that's a SOHO router, not a consumer/home router.<br>Fri, 22 Aug 2008 00:42:52 Z2008-08-22T00:42:52Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#31b23692-5072-47f2-98ae-d77169b4504bhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#31b23692-5072-47f2-98ae-d77169b4504bSketchahhttp://social.microsoft.com/Profile/en-US/?user=SketchahRouter hacked? How can I avoid this?<p> <div class=quote> <table width="85%"> <tbody> <tr> <td class=txt4> <strong>Ken Warren wrote:</strong></td></tr> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%">Turn off remote administration and change the password. Those are the two things you should do immediately. I would also turn off UPnP and configure port forwarding manually.<br><br>But in the longer term, someone has figured out that you're vulnerable to attack, and they're trying to set up a mail relay through your router (port 113). Perhaps replacing the router would be a better option. I think highly of DLink (except the DIR-655, which a lot of people here have had problems with) and Netgear. I have a SonicWall myself, but that's a SOHO router, not a consumer/home router.<br></td></tr></tbody></table></td></tr></tbody></table></div> <p></p> <p align=left> </p> <p align=left>The remote was off.</p> <p align=left>2nd time I manually did all of that.</p> <p align=left>I am thinking someone has an exploit for the router.</p> <p align=left>The router since has been removed from that service and I no longer have the server up and running.</p> <p align=left>It's doing fine now. It was jsut getting killed when I was using the DDNS feature on it.</p> <p align=left> </p> <p align=left>DYNDNS gives a list of routers here:</p> <p align=left><a title="http://www.dyndns.com/support/clients/hardware/" href="http://www.dyndns.com/support/clients/hardware/">http://www.dyndns.com/support/clients/hardware/</a></p> <p align=left> </p> <p align=left>I would replace the router but seeing how easily that one was taken down, I wonder how hard it would be for whoever that is to hit other home-based routers.</p> <p align=left> </p> <p align=left>I really could use some good suggestions for safer services that are free or cheap.</p> <p align=left><img height=19 alt=Sad src="http://forums.microsoft.com/MSDN/emoticons/emotion-6.gif" width=19></p> <p align=left>I'd love to use windows home server and have been aching to buy it on new3gg.</p> <p align=left>I am tryng to set it up for study groups at school so we can share files easily and quickly.</p> <p align=left> </p>Fri, 22 Aug 2008 03:01:06 Z2008-08-22T03:01:06Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#018d2946-0cfd-4621-9f1c-a28a906df06dhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#018d2946-0cfd-4621-9f1c-a28a906df06dSketchahhttp://social.microsoft.com/Profile/en-US/?user=SketchahRouter hacked? How can I avoid this?<div class=quote> <table width="85%"> <tbody> <tr> <td class=txt4> <strong>cuppie wrote:</strong></td></tr> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%"> <p align=left><font face=Arial size=2> <div class=quote> <table width="85%"> <tbody> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%">I wanted to know what I could do to protect myself from this sort of thing. </td></tr></tbody></table></td></tr></tbody></table></div>Very strong admin password for the router.  And, for the love of God, disable remote admin (AKA WAN admin access.)  There is really no reason that you should leave that enabled.</font> <p></p> <p></p></td></tr></tbody></table></td></tr></tbody></table></div> <p></p> <p align=left> </p> <p align=left>remote was off the 2nd time. </p> <p align=left>I had updated the firmware as well.</p> <p align=left> </p> <p align=left>example of complexity and length of passwords I use for the router:</p> <p align=left> </p> <p align=left>#bxns7479*ncbGs43&amp;jebcns7te3b^dbc43n19t</p> <p> </p> <p align=left>the actual ones I do use I have memorized.</p> <p align=left>It didnt help me in this situation... and having long passwords memorized that did nothing for me makes me feel.</p> <p align=left><img alt=Crying src="http://forums.microsoft.com/MSDN/emoticons/emotion-9.gif"></p>Fri, 22 Aug 2008 03:06:48 Z2008-08-22T03:06:48Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#1674b155-47c3-4571-a0e6-fc057abdd29dhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#1674b155-47c3-4571-a0e6-fc057abdd29dbrubberhttp://social.microsoft.com/Profile/en-US/?user=brubberRouter hacked? How can I avoid this?<p align=left><font face=Arial size=2>Some routers also have a backdoor which allows telnet entry, in some cases even with some default password thus bypassing your strong password. So close the telnet port, or forward all WAN requests on the telnet port to some fake private IP address, for example if your clients have IP addresses in the 192.168.1.1 range you can forward telnet requests to 192.168.21.25</font></p> <p align=left> </p> <p align=left>Also please note that running a (web) server (opening http port) is more or less an invitation for hackers.</p>Fri, 22 Aug 2008 07:40:24 Z2008-08-22T07:40:24Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#c5188113-bfe8-4541-a637-83a5fd566db5http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#c5188113-bfe8-4541-a637-83a5fd566db5hughojarhttp://social.microsoft.com/Profile/en-US/?user=hughojarRouter hacked? How can I avoid this?<p align=left><font face=Arial size=2>The previous suggestions are all good security measures to take with consumer routers. But, I find building your own upnp router works best when done right with a linux kernel...Way more secure, and very customizable. A lot harder to hack as well.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>This may be new to most of you, building your own gigabyte ethernet router. But there are plenty of resources to use from the linux website or you can google for resources. You can download any distro you feel comfortable with and give it a try. If you want to purchase a distro instead, you can get one from ebay website (seller: deepspace6auctions). These days you can download a liveCD version that can be run directly from CD or DVD ROM (no need for a hard drive or anything else that will generate heat), and you certainly don't need a monitor either. </font><font face=Arial size=2>You can also run from a floppy disk using coyote linux. The best part, you get to take that old pc from out of the closet or basement to put to use once again.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>If you wish to attempt this, please note that a fast computer is not required. I am using an old 486 intel 266MHZ system, with 512MB memory module. I use a kernel from <a title="http://www.gibraltar.at/" href="http://www.gibraltar.at/">http://www.gibraltar.at/</a>. and it works fine. </font><font face=Arial size=2>If you want wifi router instead, try the kernel from <a title="http://www.wifislax.com/descargas.php" href="http://www.wifislax.com/descargas.php">http://www.wifislax.com/descargas.php</a>, works best with wifi tech.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>If you're squimish about linux or you want to use an old Windows system as a router, I would suggest you go hear instead <a title="http://www.mikrotik.com/index.html" href="http://www.mikrotik.com/index.html">http://www.mikrotik.com/index.html</a></font>, this is a Windows Router OS, and easy to install and administer.</p> <p align=left> </p> <p align=left><font face=Arial size=2>Hardware is cheaper these days as well, but some of you may already have spare hardware lying around, if not, get this <font size=2>&quot;Sabrent PCI-G802 PCI Wireless Card - 54Mbps, 802.11g, Windows/Mac/Linux Compatible&quot;. This is very compatable with linux OS and under $20US.</font></font></p> <p align=left><font face=Arial size=2><font size=2></font></font> </p> <p align=left><font face=Arial size=2><font size=2>If you are not technically incline like most people, then I suggest getting this router instead &quot;</font></font><font face=Arial size=2>Linksys WRT54GL Wireless Router - 54Mbps, 802.11g, 4-Port, Open Source Linux Version&quot;, for more on this wrt router please visit <a title="http://www.wrtrouters.com/router/wrt54gl/" href="http://www.wrtrouters.com/router/wrt54gl/">http://www.wrtrouters.com/router/wrt54gl/</a>. </font><font face=Arial size=2>The good thing about this router, you can setup a hotspot area in your home for a radious of 300m, cool right?! Visit <a title="http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html" href="http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html">http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html</a>, for more information on hotspot project.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>Goodluck to everyone who will attempt this project on their own. Please post back if you have any question, or just google it if you want an answer immediately.</font></p>Fri, 22 Aug 2008 07:40:35 Z2008-08-22T07:40:35Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#c2960515-ec5f-43c7-bdf8-d27346fcc90ehttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#c2960515-ec5f-43c7-bdf8-d27346fcc90ehughojarhttp://social.microsoft.com/Profile/en-US/?user=hughojarRouter hacked? How can I avoid this?<div class=quote> <table width="85%"> <tbody> <tr> <td class=txt4> <strong>Sketchah wrote:</strong></td></tr> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%"> <p> <div class=quote> <table width="85%"> <tbody> <tr> <td class=txt4> <strong>Ken Warren wrote:</strong></td></tr> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%">Turn off remote administration and change the password. Those are the two things you should do immediately. I would also turn off UPnP and configure port forwarding manually.<br><br>But in the longer term, someone has figured out that you're vulnerable to attack, and they're trying to set up a mail relay through your router (port 113). Perhaps replacing the router would be a better option. I think highly of DLink (except the DIR-655, which a lot of people here have had problems with) and Netgear. I have a SonicWall myself, but that's a SOHO router, not a consumer/home router.<br></td></tr></tbody></table></td></tr></tbody></table></div> <p></p> <p align=left> </p> <p align=left>The remote was off.</p> <p align=left>2nd time I manually did all of that.</p> <p align=left>I am thinking someone has an exploit for the router.</p> <p align=left>The router since has been removed from that service and I no longer have the server up and running.</p> <p align=left>It's doing fine now. It was jsut getting killed when I was using the DDNS feature on it.</p> <p align=left> </p> <p align=left>DYNDNS gives a list of routers here:</p> <p align=left><a title="http://www.dyndns.com/support/clients/hardware/" href="http://www.dyndns.com/support/clients/hardware/">http://www.dyndns.com/support/clients/hardware/</a></p> <p align=left> </p> <p align=left>I would replace the router but seeing how easily that one was taken down, I wonder how hard it would be for whoever that is to hit other home-based routers.</p> <p align=left> </p> <p align=left>I really could use some good suggestions for safer services that are free or cheap.</p> <p align=left></p> <p align=left>I'd love to use windows home server and have been aching to buy it on new3gg.</p> <p align=left>I am tryng to set it up for study groups at school so we can share files easily and quickly.</p> <p align=left> </p> <p></p></td></tr></tbody></table></td></tr></tbody></table></div> <p></p> <p align=left> </p> <p align=left>If you are willing to try a linux kernel, then try this fw router instead <a title="http://www.smoothwall.org/" href="http://www.smoothwall.org/">http://www.smoothwall.org/</a>, download a copy of this distro. and install it on an old 386 pc if you have any, you can get a cheap pc for about $50US, just and an extra wifi adapter to make it wireless, or a regular wired adapter works better with protecting your router, plus, it helps if your router credential is not the same or close to your dynamic services' credentials.</p> <p align=left> </p> <p align=left>Goodluck.</p>Fri, 22 Aug 2008 08:04:37 Z2008-08-22T08:04:37Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#41d0eb18-b2f5-4d05-bfd0-a8dd36ae622dhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#41d0eb18-b2f5-4d05-bfd0-a8dd36ae622dOlaf Engelkehttp://social.microsoft.com/Profile/en-US/?user=Olaf%20EngelkeRouter hacked? How can I avoid this?<p align=left>Could be something like this:</p> <p align=left><a title="http://www.juniper.net/security/auto/vulnerabilities/vuln6201.html" href="http://www.juniper.net/security/auto/vulnerabilities/vuln6201.html">http://www.juniper.net/security/auto/vulnerabilities/vuln6201.html</a></p> <p align=left>&quot;Linksys Router Unauthorized Management Access Vulnerability&quot;</p> <p align=left> </p> <p>Best greetings from Germany</p> <p align=left>Olaf</p>Fri, 22 Aug 2008 08:07:56 Z2008-08-22T08:07:56Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#d37565d3-1d88-4a92-aaf1-5fc44576c4e9http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#d37565d3-1d88-4a92-aaf1-5fc44576c4e9hughojarhttp://social.microsoft.com/Profile/en-US/?user=hughojarRouter hacked? How can I avoid this?<p align=left><font face=Arial size=2></font> </p>Yes, that is why a hacker is able to access the linksys router. Which is why I suggest getting the WRT router from linksys instead, the WRT I suggested can be updated with a linux firmware to prevent such hacks. If you're not a (Linux) power user there's little point in enduring the cost of this version over the standard ''G'' model. However, if you're like me, you bought it for the modded firmware and the features that come along with it. I've added an SD slot to mine, with a 1GB SD card supporting web and ftp servers in a DMZ, and also run the VoIP mods. Performance for me has been awesome! It's been 6 months in service with no issues thus far. This router is the bomb - if for no other reason than the ability to bump the radio power! I get far better signal in the top portion of my house than I ever did with my prior D-Link. For info, see Google, and start here: <a title="http://www.wrtrouters.com/router/wrt54gl/" href="http://www.wrtrouters.com/router/wrt54gl/">http://www.wrtrouters.com/router/wrt54gl/</a>. If there's a fault to find with this router it may be that it can do _too much_. Plus the option to setup a wifi hotspot in your home is a bonus.Fri, 22 Aug 2008 08:28:05 Z2008-08-22T08:28:05Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#c4a41a13-e7ed-4157-b7d0-6cf12b9251fchttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#c4a41a13-e7ed-4157-b7d0-6cf12b9251fcSketchahhttp://social.microsoft.com/Profile/en-US/?user=SketchahRouter hacked? How can I avoid this?<div class=quote> <table width="85%"> <tbody> <tr> <td class=txt4> <strong>hughojar wrote:</strong></td></tr> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%"> <p align=left><font face=Arial size=2>The previous suggestions are all good security measures to take with consumer routers. But, I find building your own upnp router works best when done right with a linux kernel...Way more secure, and very customizable. A lot harder to hack as well.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>This may be new to most of you, building your own gigabyte ethernet router. But there are plenty of resources to use from the linux website or you can google for resources. You can download any distro you feel comfortable with and give it a try. If you want to purchase a distro instead, you can get one from ebay website (seller: deepspace6auctions). These days you can download a liveCD version that can be run directly from CD or DVD ROM (no need for a hard drive or anything else that will generate heat), and you certainly don't need a monitor either. </font><font face=Arial size=2>You can also run from a floppy disk using coyote linux. The best part, you get to take that old pc from out of the closet or basement to put to use once again.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>If you wish to attempt this, please note that a fast computer is not required. I am using an old 486 intel 266MHZ system, with 512MB memory module. I use a kernel from <a title="http://www.gibraltar.at/" href="http://www.gibraltar.at/">http://www.gibraltar.at/</a>. and it works fine. </font><font face=Arial size=2>If you want wifi router instead, try the kernel from <a title="http://www.wifislax.com/descargas.php" href="http://www.wifislax.com/descargas.php">http://www.wifislax.com/descargas.php</a>, works best with wifi tech.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>If you're squimish about linux or you want to use an old Windows system as a router, I would suggest you go hear instead <a title="http://www.mikrotik.com/index.html" href="http://www.mikrotik.com/index.html">http://www.mikrotik.com/index.html</a></font>, this is a Windows Router OS, and easy to install and administer.</p> <p align=left> </p> <p align=left><font face=Arial size=2>Hardware is cheaper these days as well, but some of you may already have spare hardware lying around, if not, get this <font size=2>&quot;Sabrent PCI-G802 PCI Wireless Card - 54Mbps, 802.11g, Windows/Mac/Linux Compatible&quot;. This is very compatable with linux OS and under $20US.</font></font></p> <p align=left><font face=Arial size=2><font size=2></font></font> </p> <p align=left><font face=Arial size=2><font size=2>If you are not technically incline like most people, then I suggest getting this router instead &quot;</font></font><font face=Arial size=2>Linksys WRT54GL Wireless Router - 54Mbps, 802.11g, 4-Port, Open Source Linux Version&quot;, for more on this wrt router please visit <a title="http://www.wrtrouters.com/router/wrt54gl/" href="http://www.wrtrouters.com/router/wrt54gl/">http://www.wrtrouters.com/router/wrt54gl/</a>. </font><font face=Arial size=2>The good thing about this router, you can setup a hotspot area in your home for a radious of 300m, cool right?! Visit <a title="http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html" href="http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html">http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html</a>, for more information on hotspot project.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>Goodluck to everyone who will attempt this project on their own. Please post back if you have any question, or just google it if you want an answer immediately.</font></p> <p></p></td></tr></tbody></table></td></tr></tbody></table></div> <p></p> <p align=left> </p> <p align=left> <div class=quote> <table width="85%"> <tbody> <tr> <td class=txt4> <strong>hughojar wrote:</strong></td></tr> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%"> <p></p> <p align=left><font face=Arial size=2>The previous suggestions are all good security measures to take with consumer routers. But, I find building your own upnp router works best when done right with a linux kernel...Way more secure, and very customizable. A lot harder to hack as well.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>This may be new to most of you, building your own gigabyte ethernet router. But there are plenty of resources to use from the linux website or you can google for resources. You can download any distro you feel comfortable with and give it a try. If you want to purchase a distro instead, you can get one from ebay website (seller: deepspace6auctions). These days you can download a liveCD version that can be run directly from CD or DVD ROM (no need for a hard drive or anything else that will generate heat), and you certainly don't need a monitor either. </font><font face=Arial size=2>You can also run from a floppy disk using coyote linux. The best part, you get to take that old pc from out of the closet or basement to put to use once again.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>If you wish to attempt this, please note that a fast computer is not required. I am using an old 486 intel 266MHZ system, with 512MB memory module. I use a kernel from <a title="http://www.gibraltar.at/" href="http://www.gibraltar.at/">http://www.gibraltar.at/</a>. and it works fine. </font><font face=Arial size=2>If you want wifi router instead, try the kernel from <a title="http://www.wifislax.com/descargas.php" href="http://www.wifislax.com/descargas.php">http://www.wifislax.com/descargas.php</a>, works best with wifi tech.</font></p> <p align=left><font face=Arial size=2></font> </p> <p align=left><font face=Arial size=2>If you're squimish about linux or you want to use an old Windows system as a router, I would suggest you go hear instead <a title="http://www.mikrotik.com/index.html" href="http://www.mikrotik.com/index.html">http://www.mikrotik.com/index.html</a></font>, this is a Windows Router OS, and easy to install and administer.</p> <p align=left> </p> <p align=left><font face=Arial size=2>Hardware is cheaper these days as well, but some of you may already have spare hardware lying around, if not, get this <font size=2>&quot;Sabrent PCI-G802 PCI Wireless Card - 54Mbps, 802.11g, Windows/Mac/Linux Compatible&quot;. This is very compatable with linux OS and under $20US.</font></font></p> <p align=left><font face=Arial size=2><font size=2></font></font> </p> <p align=left><font face=Arial size=2><font size=2>If you are not technically incline like most people, then I suggest getting this router instead &quot;</font></font><font face=Arial size=2>Linksys WRT54GL Wireless Router - 54Mbps, 802.11g, 4-Port, Open Source Linux Version&quot;, for more on this wrt router please visit <a title="http://www.wrtrouters.com/router/wrt54gl/" href="http://www.wrtrouters.com/router/wrt54gl/">http://www.wrtrouters.com/router/wrt54gl/</a>. </font><font face=Arial size=2>The good thing about this router, you can setup a hotspot area in your home for a radious of 300m, cool right?! Visit <a title="http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html" href="http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html">http://www.hotspotsystem.com/en/hotspot/wifi_hotspot.html</a>, for more information on hotspot project.</font></p> <p align=left> </p> <p align=left> </p> <p align=left>Thanks for your help, I have 3 distros of linux here that I have been looking into. I have played with ubuntu from 6.06 to 8.04 thus far. I even bought a book &quot;Hacking Ubuntu&quot; published by extremetech. I do have several old computers and spare parts + a few other network cards. </p> <p align=left>I am pretty interested ino running a machine as a router and if this wold give me better security I am all for  it.</p> <p align=left>My level of experience= n00b when it comes to linux. I had also looked at the WRT firmwares before posting on here.</p> <p align=left>I saw the one router I had was not listed as supported (I understand which model you are talkign about as to it is one of the most popular ones.)</p> <p align=left> </p> <p align=left>Also, how hard would it be to set up WHS through multile routers and would that only be a speed bump (and not a wall) to a bot with exploits?</p> <p align=left> </p> <p align=left> </p> <p align=left> </p> <p align=left>Also I would like to thank the poster who talked about the backdoor through telnet. I had not thought about that and had done something like that before to a router to send requests to an invalid IP.</p> <p align=left> </p> <p align=left>I found this last night concerning my router (I do see it says 2004)</p> <p align=left> <table cellspacing=1 cellpadding=3 width="100%" border=0> <tbody> <tr> <td bgcolor="#cccccc"><b><font size=2><a class=pn-title href="http://www.hackinthebox.org/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=13329&amp;mode=thread&amp;order=0&amp;thold=0">Linksys routers may be open to remote sniffing</a></b></font><br><font size=1>Posted by <a title="http://www.hackinthebox.org/user.php?op=userinfo&amp;uname=L33tdawg" href="http://www.hackinthebox.org/user.php?op=userinfo&amp;uname=L33tdawg">L33tdawg</a> on Friday, June 04, 2004 - 06:32 PM (Reads: 4559)</font><br><span class=pn-sub></span></td></tr> <tr> <td bgcolor="#ffffff">Source: <a title="http://www.hackinthebox.org/url.php?url=13329" href="http://www.hackinthebox.org/url.php?url=13329">The Inquirer</a> <p> <p> <p> <hr> <p></p> <p><br><font size=2>FOLKS AT security portal SecuriTeam published on May 17 an exploit that could allow hackers and other nasty people to remotely sniff traffic passing through the <a class=kLink id=KonaLink0 style="position:static;text-decoration:underline! important" href="http://www.hackinthebox.org/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=13329&amp;mode=thread&amp;order=0&amp;thold=0#"><font style="font-weight:400;color:black! important;font-family:Tahoma;position:static" color=black size=2><span class=kLink style="font-weight:400;color:black! important;font-family:Tahoma;position:relative">router</span></font></a>, and also crash the device. The article says it all comes down to a &quot;memory leak&quot;, causing a flaw in the way the Linksys routers' DHCP <a class=kLink id=KonaLink1 style="position:static;text-decoration:underline! important" href="http://www.hackinthebox.org/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=13329&amp;mode=thread&amp;order=0&amp;thold=0#"><font style="font-weight:400;color:black! important;font-family:Tahoma;position:static" color=black size=2><span class=kLink style="font-weight:400;color:black! important;font-family:Tahoma;position:relative">server</span></font></a> returns BOOTP protocol packets. This exploit is currently listed at position #3 in the SecuriTeam.com <a class=kLink id=KonaLink2 style="position:static;text-decoration:underline! important" href="http://www.hackinthebox.org/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=13329&amp;mode=thread&amp;order=0&amp;thold=0#"><font style="font-weight:400;color:black! important;font-family:Tahoma;position:static" color=black size=2><span class=kLink style="font-weight:400;color:black! important;font-family:Tahoma;position:relative">front </span><span class=kLink style="font-weight:400;color:black! important;font-family:Tahoma;position:relative">page</span></font></a>, so expect lots of script kiddies to be playing with it as we write (and you read) this. The site says: &quot;Instead of returning legitimate BOOTP responses, (the linksys units) return BOOTP responses with the BOOTP fields filled in with portions of memory. This allows you to do cool things like the equivalent of sniffing all the traffic to/from the device&quot;. It continues: &quot;I have successfully used this technique to steal the admin username and password from an innocent third party who recently configured the device, and I watched someone's traffic as they browsed ebay for a new Ti-Book&quot;. The exploit code indicates the vulnerability has been tested &quot;on a fully updated Linksys BEFSR41 and BEFW11S4&quot; but the author of this exploit, who signs his code under the name Jon Hart, hints that all other Linksys routers which have a dhcp server could be vulnerable &quot;Currently, this looks to include at least the BEFN2PS4, BEFSR41, BEFSR81, BEFSX41, RV082, BEFCMU10, BEFSR11, BEFSR41W, BEFSRU31, BEFVP41, WRT55AG, WRV54G, WRT51AB&quot;, he writes. </font></p> <p align=left><font size=2></font> </p> <p align=left><font size=2>^^^ that was a bit troubling^^^ I am begining to think my BEFSX41 and my DI-604 are only good for in-house  use for gaming.</font></p> <p align=left><font size=2></font> </p> <p align=left><font size=2>I am going to give this another shot though w/ school starting moday I am anxious to get this working.</font></p> <p align=left><font size=2>Thank you all and I will keep reading this thread. I will try out these suggestions and test them.</font></p> <p align=left><font size=2></font> </p> <p align=left><font size=2>I wish I knew where the exploit was because I would try and reproduce the problem to find the best fix.</font></p></td></tr></tbody></table></p></td></tr></tbody></table></td></tr></tbody></table></div>Fri, 22 Aug 2008 14:45:39 Z2008-08-22T14:45:39Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#cc4f53b4-2c36-4b56-84c9-457376a7407bhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#cc4f53b4-2c36-4b56-84c9-457376a7407bColin Hodgsonhttp://social.microsoft.com/Profile/en-US/?user=Colin%20HodgsonRouter hacked? How can I avoid this?<p>Just to note to the OP: There is no reason to use DynDNS for WHS. If you take advantage of the homeserver domain and certificate, you automatically get re-direction for your dynamic IP.</p> <p align=left>I believe that the HP unit also has the option of using TZO, which also has the same facility.</p> <p align=left> </p> <p align=left>Also, just to note that I now have about 18 customers all using the D-Link DIR-655, which are all pleased with.</p> <p align=left> </p> <p align=left>Colin</p> <p align=left><font face=Arial size=2></font> </p>Fri, 22 Aug 2008 14:51:37 Z2008-08-22T14:51:37Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#e771b2a6-e603-44dd-9a6e-4e3af0104450http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#e771b2a6-e603-44dd-9a6e-4e3af0104450sorranohttp://social.microsoft.com/Profile/en-US/?user=sorranoRouter hacked? How can I avoid this?I found out today this exploit was used on my linksys router. I logged into it and its an open hole with a crippled interface.<br>Fri, 22 Aug 2008 17:13:06 Z2008-08-22T17:13:06Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#64ea6ba6-201b-459b-a0ac-60878d489e66http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#64ea6ba6-201b-459b-a0ac-60878d489e66Olaf Engelkehttp://social.microsoft.com/Profile/en-US/?user=Olaf%20EngelkeRouter hacked? How can I avoid this?<div class=quote> <table width="85%"> <tbody> <tr> <td class=txt4> <strong>Colin Hodgson wrote:</strong></td></tr> <tr> <td class=quoteTable> <table width="100%"> <tbody> <tr> <td class=txt4 valign=top width="100%"> <p>Just to note to the OP: There is no reason to use DynDNS for WHS. <font face=Arial size=2></font></p> <p></p></td></tr></tbody></table></td></tr></tbody></table></div> <p></p> <p align=left> </p> <p align=left>Note to Colin:</p> <p align=left>Sometimes in the real world it happens, that the domain homeserver.com points to the wrong (old, whatever) IP address. (Maybe if the router lost the connection to ISP for a short time or whatever the reasons are.)</p> <p align=left>Of course always, if you need the connection urgently.</p> <p align=left>In such situations a second way in via dyndns.org is for sure helpful.</p> <p align=left>Best greetings from Germany</p> <p align=left>Olaf</p>Fri, 22 Aug 2008 19:34:11 Z2008-08-22T19:34:11Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#5fa85b6d-178b-4388-8bdf-433ce7a6c942http://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#5fa85b6d-178b-4388-8bdf-433ce7a6c942hughojarhttp://social.microsoft.com/Profile/en-US/?user=hughojarRouter hacked? How can I avoid this?<p align=left><font face=Arial size=2>One major way of securing my network, is to put my linksys router behind my linux firewall. This is the setup I am currently using for my WRT model.</font></p> <p align=left> </p> <p align=left>linksys setup:</p> <ol> <li> <div align=left>Linux firewall with DMZ ported directly to my linksys WRT router (router setup is disabled for DHCP, instead I use one of my server to create and supply NAT, <br>DNS and DHCP addresses) to my DMZ network.</div> <li> <div align=left>Routing is also disabled on router, it is only supplying basic connectivity for DMZ network.</div> <li> <div align=left>Remote access is disabled. You get the idea.</div></li></ol> <p align=left>As for my linux fw router:</p> <p align=left> </p> <ol> <li>The basic is connectivity for upnp and direct port to and from my internal network, with port forwarding to and from the net. SSH and remote access is disabled. <li> <div align=left>dhcp is disabled on linux router (internal DNS, DHCP, and WEB is supplied from inside my network).</div></li></ol> <p align=left><strong>If any of you ever checked the connection map of your adapter, a basic setup from your ISP is like this:</strong></p> <p align=left><strong></strong> </p> <p align=left><strong>from external net:</strong></p> <ol> <li> <div align=left><strong>ISP dhcp enabled</strong></div> <li> <div align=left><strong>ip address from ISP = 1.1.1.2, with submask</strong></div></li></ol> <p align=left><strong>ISP network setup:</strong></p> <ol> <li><strong>ISP gateway = 1.1.1.1</strong><strong> (this is on the same network as your external ip address)</strong> <li> <div align=left><strong>ISP DHCp = 1.1.1.1 ( this is same as isp gateway)</strong></div> <li> <div align=left><strong>DNS = 2.2.2.2 for primary, and 5.5.5.5 for secondary (this setup is to further protect the internal network from the outside, by supplying dns and nat from two different network)</strong></div></li></ol> <p align=left>However, you can further protect the network by turning off DHCP, DNS, and ROUTING on the fw router facing the wan. It is safer to provide these service from your internal network behind the firewall, or even the DMZ itself.</p> <p align=left> </p> <p align=left>I hope this helps. Good luck.</p> <p align=left> </p> <p align=left>Hugh</p>Fri, 22 Aug 2008 20:38:01 Z2008-08-22T23:28:51Zhttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#49150ee3-b7a3-4f52-a209-e7c2e25e3f3ehttp://social.microsoft.com/Forums/en-US/whssoftware/thread/2106cb94-3e15-4e08-a181-ead7a2c09346#49150ee3-b7a3-4f52-a209-e7c2e25e3f3eSketchahhttp://social.microsoft.com/Profile/en-US/?user=SketchahRouter hacked? How can I avoid this?<p>Thx I will give this a few go arounds.</p> <p align=left><img height=19 alt=Smile src="http://forums.microsoft.com/MSDN/emoticons/emotion-1.gif" width=19></p> <p align=left><font face=Arial size=2></font> </p>Fri, 22 Aug 2008 23:29:27 Z2008-08-22T23:29:27Z