BleepingComputer.com: Router hijacking and Redirect issues

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Router hijacking and Redirect issues Is there a protocol we could follow?

#1 User is offline   jaredmcdonnell 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 18-November 10

Posted 21 November 2010 - 11:58 AM

I have a log posted for action and, following the rules, I am changing nothing until a volunteer helps me. Thank you for having that service!

But in reading through some other log reslution theads, I am pretty sure we are going ot find out we have an issue with the router; in particular, the problem now (mildly) also affects my work-issued laptop, but only when I am using it at home. I have waited at work for it to happen so my IT person can look at it, but it never happens there.

So the home router is suspect.

And a lot of similar theads are acattered through the log threads and I see the volunteers over and over going through steps and ending up suspecting the router.

Would a generic protocol for resetting the router and then implementing a set of anti-malware actions be appropriate? I am not sure which to do first. Does setting a user name and password on the router essentially stop getting it rerouted and it no longer needs to be considered?

#2 User is offline   MrBruce1959 

  • My cat Oreo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 5,328
  • Joined: 15-November 09
  • Gender:Male
  • Location:Norwich, Connecticut. in the USA

Posted 21 November 2010 - 03:08 PM

View Postjaredmcdonnell, on 21 November 2010 - 11:58 AM, said:

Does setting a user name and password on the router essentially stop getting it rerouted and it no longer needs to be considered?


Hello and welcome to Bleepingcomputer.

The answer to your question is YES.

Now depending on your router and what security protocol it has, you should use a different passphrase for wireless as often as every 30 days at the very least.

The wireless N routers are the best and latest routers out there.

G is Okay as well.

If your router is a B router, I would recommend an upgrade, most of those routers only use WEP as their best defense. WEP is very easy to crack.

WPA is the best.

There are two types of WPA.

WPA-PSK [TKIP]

WPA2-PSK [AES]

Both options above can be implemented at the same time.

Such as WPA-PSK & WPA2-PSK.

The passphrase should be at the very least 30 characters long and can be set to as many as 63.

Use a random passphrase rather than names or birth dates.

Here is an example of a very secure passphrase.

2wnY9$In3@hRbW8&m3Wo%f2NaW8$mME2IwZ$Lq0%

This passphrase would take quite some time to crack just as it is. But by some standards it is still considered rather weak.

Newer routers also have a feature built in, that ignores an access attempt, even if the correct passphrase is compromised or used.

Under Advance settings for Wireless you can use the wireless card access list option.

This option will have to be accessed through the routers firmware, then you have to click the wireless setup access list button, here, you can see a computer or wireless device that is attempting access to your router's wireless access. It lists it by computer name and MAC address. You have to add that computer's MAC address to the list and click apply.

If a device with an un-familure MAC address tries to gain access, it is denyed.

Hope this helps.

Bruce.
Please take notice. Oreo and I will not be available until June of 2012.
Thank you for understanding my absence, it is job and college related, so all is good. If I do not answer your PMs this is the reason why. See you all soon!

Bruce.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users