Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
router seems to have been compromised
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Amity88
Apprentice
Apprentice


Joined: 03 Jul 2010
Posts: 265
Location: Third planet from the Sun

PostPosted: Mon Apr 11, 2011 8:07 am    Post subject: router seems to have been compromised Reply with quote

I have a beetel 450tc1 wireless router, which I secured with a resonably strong WPA and administration passwords. A couple of days ago I got locked out of my router (the wireless password and internet was working however), I called up customer care and they reset it remotely.

There are two things that bother me, first of all about the password itself, there was no way that I could have mistyped the password (I had written it down some place safe, no one could have seen it), it was not guessable (12+ random character).... besides I used it occasionally, how could it stop working all of a sudden?

Then, I had turned on the router's firewall and a web based port scan (www.grc.com) shows that that ports 1:1023 dropped incoming packets. Despite this the people at my ISP was able to reset the administration password, it was convinient (I was thinking that they would have to send someone over to manually reset and reconfigure the router) BUT it raises the question of security.... If they could do it, couldn't someone else do it as well..... I wan't even supposed to be locked out in the first place.....

Any help would be appreciated :)
_________________
Ant P. wrote:
The enterprise distros sell their binaries. Canonical sells their users.


Also... Be ignorant... Be happy! :)
Back to top
View user's profile Send private message
djinnZ
Advocate
Advocate


Joined: 02 Nov 2006
Posts: 4831
Location: somewhere in L.O.S.

PostPosted: Tue Apr 12, 2011 2:16 pm    Post subject: Re: router seems to have been compromised Reply with quote

Amity88 wrote:
I called up customer care and they reset it remotely
this is the problem and the question is very old. Look here.
The only reasonable solution is to use a router (openwrt?) without a documented backdoor password builtin.

A reasonable start will be reflash the firmware.
_________________
scita et risus abundant in ore stultorum sed etiam semper severi insani sunt:wink:
mala tempora currunt...mater stultorum semper pregna est :evil:
Murpy'sLaw:If anything can go wrong, it will - O'Toole's Corollary:Murphy was an optimist :wink:
Back to top
View user's profile Send private message
Amity88
Apprentice
Apprentice


Joined: 03 Jul 2010
Posts: 265
Location: Third planet from the Sun

PostPosted: Thu Apr 14, 2011 4:23 pm    Post subject: Reply with quote

That's what I'm most concerned about... a backdoor.... I've read a bit about the PsyB0t worm, but my ports (except ssh) were open to the internal network..... any chance I could tweak the settings of router in solve the problem?
_________________
Ant P. wrote:
The enterprise distros sell their binaries. Canonical sells their users.


Also... Be ignorant... Be happy! :)
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum