{"id":119,"date":"2012-04-06T08:52:20","date_gmt":"2012-04-06T13:52:20","guid":{"rendered":"http:\/\/triplescomputers.com\/blog\/?p=119"},"modified":"2012-07-29T22:21:27","modified_gmt":"2012-07-30T03:21:27","slug":"change-your-routers-login-information","status":"publish","type":"post","link":"https:\/\/www.triplescomputers.com\/blog\/casestudies\/change-your-routers-login-information\/","title":{"rendered":"Change your router&#8217;s login information"},"content":{"rendered":"<p>As a bit of an extension from <a title=\"Infected routers threaten death by DNS\" href=\"http:\/\/triplescomputers.com\/blog\/?p=57\" target=\"_blank\">an earlier post<\/a>, I&#8217;d just like to reiterate the importance of changing the default login information for your router (or your customers&#8217; routers). \u00a0I&#8217;ve seen another uptick in DNS-Changer\/DNS Hijack activity which includes the modification of router DNS settings to include malicious IP addresses, most of which hail from within the Russian Federation.<\/p>\n<p>There is an easy way to correct this. \u00a0For starters, obviously, you need to ensure your router isn&#8217;t infected. \u00a0If the DNS settings have been changed, blank them out, then follow it up with a new username\/password for your router. \u00a0It doesn&#8217;t need to be anything complex; even simply changing it to <em>anything\u00a0<\/em>else will do the trick. \u00a0The malware responsible aren&#8217;t brute forcing the passwords or anything like that; they&#8217;re simply leveraging knowledge of the default login info for each router model to weasel their way into the settings and add their own DNS information.<\/p>\n<p>It also goes without saying that <em>all <\/em>client PCs need to be clean before making the change, lest the settings will be reversed by any active malware on the network after you change them. \u00a0It is possible to change the login info <em>first<\/em>, and <em>then <\/em>blank out the DNS settings if you&#8217;re unsure which machine is causing problems and you just wish to prevent propagation of the malware\/further information theft. \u00a0But this must be done from a clean machine.<\/p>\n<p>Many ISPs will warn users if they&#8217;re affected by such DNSChanger infections. \u00a0By cleaning the malware off the PCs and checking the routers, you can ensure the problem is resolved. \u00a0However, there is one final setting to check:<\/p>\n<blockquote><p><strong>HKLM\\System\\ControlSet001\\Services\\Tcpip\\Parameters\\\\DhcpNameServer<\/strong><\/p><\/blockquote>\n<p>This registry value will often be modified to include the same malicious DNS servers. \u00a0Be sure to check it on each machine, lest a clean machine can quickly become infected once again!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As a bit of an extension from an earlier post, I&#8217;d just like to reiterate the importance of changing the default login information for your router (or your customers&#8217; routers). \u00a0I&#8217;ve seen another uptick in DNS-Changer\/DNS Hijack activity which includes &hellip; <a href=\"https:\/\/www.triplescomputers.com\/blog\/casestudies\/change-your-routers-login-information\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4],"tags":[105,11,51],"class_list":["post-119","post","type-post","status-publish","format-standard","hentry","category-casestudies","category-security","tag-dnschanger","tag-malware","tag-router"],"_links":{"self":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/comments?post=119"}],"version-history":[{"count":0,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/119\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/media?parent=119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/categories?post=119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/tags?post=119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}