Has there been a large scale hacking on SOHO routers and modems recently?

KonfuSed

Disciple
Hi All,

Today while checking an issue with my home network (not my current place but at my natives), I found that the DNS address looked kind of suspicious. The DNS IP Address was 5.45.75.11(Primary.) and 5.45.75.36(Secondary.) and these addresses kinda seemed phony to me. So I ran a Google search and found out that there has been reports of a very recent Cyber attack on modems/routers where the DNS server address has been forcefully changed to these addresses. What this means that all your sensitive data/information probably are being compromised. Here are couple of references for this attack which google has shown:

http://www.ispreview.co.uk/index.ph...0000-home-broadband-routers-major-brands.html

http://www.pcworld.com/article/2104...-300000-home-routers-alters-dns-settings.html

The report can be found here :
https://www.team-cymru.com/ReadingRoom/Whitepapers/2013/TeamCymruSOHOPharming.pdf

Also it seems that these phony DNS servers are not exactly responding well and most of the time you would not be even able to connect to network or it'll be very slow net conn (which is what was happening at my folk's place). So if you are suddenly facing such issues and getting DNS response errors then it might be the case that your modem/router has been compromised. Even if you are not facing disconnection or slow network issues, it would be better if you check your DNS configs just to be sure.

The modem and router used in my home are DLink but it seems many other brands also facing the same issue.
The service provider is BSNL at my natives.

Note : As of now, I'll force my modem to point to either google DNS or some other openDNS now but that probably is not the permanent solution (or not even a solution). Permanent solution would probably be an upgraded firmware without this vulnerability for such attacks. Also if the network is compromised that would also mean that the computers and other devices are also been compromised. Probably I will also have to get the machines at my home scanned properly for virus/maleware?

If anyone out there have more info then please do share. Also please let us know if this attack is for real (from the readings it does look real) and what should be steps need to be taken for remedy and also for protection.
Regards,
 
it sounds like they hacked the ISP's DNS server rather than the customers modem.

How elegant, now everybody that pulls a dns list at modem startup off their ISP will get the chosen servers :D

I've always used google's because it meant a faster modem startup to get online. No need to do that dns list request to the ISP.

cymru btw means wales in welsh.
 
From the links in his post it looks like the modems and routers having admin pages accessible from net were hacked with some exploit. I don't think the ISP servers were hacked.
 
Doesn't seem like it is happening at the ISP side. The change was done at the modem (DLink 2520). By default the DNS settings used to be Enable Obtain DNS automatically but this got changed to the phony DNS addresses. I've changed those addresses to that of Google DNS and also changed the password and LAN addresses. Now the network is working and my folks are able to use the internet now. Hope this will keep on working for some time. Luckily no one at home use net-banking and so that way kinda safe.
 
Dear, not everyone is tech savvy and probably 80% of internet users are not even aware of what DNS server is. So I feel this kind of attack/threat is very real and can cause damage.
 
Back
Top