Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-25-2005, 08:00 PM
RZ
Guest
 
Posts: n/a
Default Is this weird?? (hacking a router)

We are a small broadband ISP. We have one customer that
could not get DNS to resolve. We found that he was using a
DNS server in China/Taiwan, 168.95.192.1 (hntp1.hinet.net)
We have our own DNS servers and this router had our DNS
in its DNS field.
The reason he failed is that the above DNS failed for several
hours yesterday. We checked our server logs and found that
he has been using this DNS since early July. He is behind a
DI-604 router. As it turns out, the router redirects any request
on port 53 to this hntp1.hinet.net Today we replaced the router
and it's all back to normal, all DNS requests are going to our server.
We also checked the settings in the DI-604, they are correct.
In fact, if we use the DI-604's internal ping test, it uses our DNS.
Is it possible to hack a router?? Anyone heard of this?
Thanks,

-
R



Reply With Quote
  #2 (permalink)  
Old 08-25-2005, 09:27 PM
Duane Arnold
Guest
 
Posts: n/a
Default Re: Is this weird?? (hacking a router)

"RZ" <rz@dev.invalid> wrote in news:11gs8rja8u18u11@news.supernews.com:

> We are a small broadband ISP. We have one customer that
> could not get DNS to resolve. We found that he was using a
> DNS server in China/Taiwan, 168.95.192.1 (hntp1.hinet.net)
> We have our own DNS servers and this router had our DNS
> in its DNS field.
> The reason he failed is that the above DNS failed for several
> hours yesterday. We checked our server logs and found that
> he has been using this DNS since early July. He is behind a
> DI-604 router. As it turns out, the router redirects any request
> on port 53 to this hntp1.hinet.net Today we replaced the router
> and it's all back to normal, all DNS requests are going to our server.
> We also checked the settings in the DI-604, they are correct.
> In fact, if we use the DI-604's internal ping test, it uses our DNS.
> Is it possible to hack a router?? Anyone heard of this?
> Thanks,
>


Yeah a router can be hacked if the router is left in its out of the box
default state such as leaving the router's Admin user-id and PSW as is out
of the box and most *clueless* home users will do just that. It could
happen if the *clueless* user with happy fingers that clicked on unknown
links in an email or a Web site that deployed a backdoor Trojan or root
tool kit to a computer that gave the hacker full remote control of the
machine. The hacker could easily go to the router's admin screens and
configure the router.

If the router is wireless and was not secured wirelessly even a wireless
hacker that could attach a machine wirelessly to the LAN on the router
could access the router's Admin screens and configure the router with the
router being left in its out of the box default state.

Duane ;)

Reply With Quote
  #3 (permalink)  
Old 08-27-2005, 03:06 PM
Cantankerous Old Git
Guest
 
Posts: n/a
Default Re: Is this weird?? (hacking a router)

RZ wrote:
> We are a small broadband ISP. We have one customer that
> could not get DNS to resolve. We found that he was using a
> DNS server in China/Taiwan, 168.95.192.1 (hntp1.hinet.net)
> We have our own DNS servers and this router had our DNS
> in its DNS field.
> The reason he failed is that the above DNS failed for several
> hours yesterday. We checked our server logs and found that
> he has been using this DNS since early July. He is behind a
> DI-604 router. As it turns out, the router redirects any request
> on port 53 to this hntp1.hinet.net Today we replaced the router
> and it's all back to normal, all DNS requests are going to our server.
> We also checked the settings in the DI-604, they are correct.
> In fact, if we use the DI-604's internal ping test, it uses our DNS.
> Is it possible to hack a router?? Anyone heard of this?
> Thanks,
>


I have not heard of this before, but it certainly sounds like the
router has been hacked somehow. As for why - the most likely
reason is to be able to direct the user to a fake financial web
site, e.g. a mock-up of a home banking site, where thay can then
get him to give them his username and pasword, thinking he's
loggin into his usual home banking web site.

You should inform the user that any sites where he used passwords
could have been fakes, to change his passwords and to check all
his bank accounts. You should also look for other users similarly
compromised and inform them.

Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
wireless network / ethernet bridge question Pete alt.comp.hardware 13 03-19-2007 06:19 PM
Wireless router is no longer a router? Ikke alt.internet.wireless 7 02-01-2007 10:23 PM
HACKING LESSONS 1-17, HACKING, 24 CDs, WINDOWS XP ( X64 ) PRO CORP SP2, WINDOWS VISTA, OFFICE 2007, PROJECT 2007, PUBLISHER 2007, VISIO 2007, BRITANNICA 2007, other 2006-Dec-10 atarax alt.computer.security 0 12-11-2006 12:11 PM
Review: DLink WBR-1310 Wireless Router dennispublic@hotmail.com alt.internet.wireless 5 08-24-2006 04:27 PM
So, I don't need a new router -- my current one is just weird Cyde Weys alt.comp.hardware 1 09-28-2005 01:06 AM


All times are GMT. The time now is 09:11 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45