Get Paid to Participate     Twitter     Facebook     Google+
Hosting Discussion
 

forgot password?


Reply


Old
  Post #1 (permalink)   12-23-2010, 10:16 AM
HD Wizard
 
SenseiSteve's Avatar
 
Join Date: Mar 2009
Location: Saint Louis
Posts: 3,777
Send a message via MSN to SenseiSteve

Status: SenseiSteve is offline
I had to tackle result5.google last August, and what I thought at first was a virus was actually a re-direct to Eastern Europe. One of my friends was having problems searching, as his results were constantly being re-directed to advertising pages. He was running a small three computer network in his home with a Linksys wireless router.

Trying to access or download any type of anti-virus program was fruitless and scans with Microsoft Security Essentials and StopZilla turned up other viruses, but didn’t kill off result5.google. Neither did Malwarebytes.

Searches on Bing and Google returned plenty of posts on how to eliminate this problem, but only one helped – and that was to log onto the router, correct the DNS and change the password, then empty his computers’ history, temp pages and cookies. Seems his router’s DNS had been changed to 213.109.67.169 and 213.109.73.170, which a traceroute revealed pointed to Eastern Europe. When he installed his network, he neglected to change the router’s password from the vendor’s default, leaving himself open to exploits.

Typically, routers are marked with their serial numbers and MAC addresses, and from there you can search the vendors online support pages to determine its IP and how to log on to the router to change its password and settings.

I hope this helps anyone out there who is experiencing this problem.
__________________
Hands-On Web Hosting
cPanel Web Hosting, Domain Registration, Managed VPS Servers
Infusing Markets LLC - A Digital Interactive Marketing Firm
 
 
 


Old
  Post #2 (permalink)   12-23-2010, 02:27 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,003

Status: handsonhosting is offline
Great post. Another reason why DEFAULT PASSWORDS should always be changed, and passwords in general should be updated every 30-90 days.

I remember that type of exploit earlier this year too. I thought it was router specific, but can't remember the actual details on it. Similar type event though. Not fun to troubleshoot as people always forget about the router!
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #3 (permalink)   12-23-2010, 06:10 PM
HD Guru
 
HostMantis's Avatar
 
Join Date: Feb 2010
Posts: 539

Status: HostMantis is offline
I can't count how many times I was working on a networking issues for a business, family or friend and said "I'll need your login info for your router to check your configuration" and being told "Umm... I'm not sure what it would be. I didn't set a password".

Security is always an afterthought for the average person.
__________________
HostMantis Affordable Web Hosting
Shared • Reseller • 24/7/365 Support • Instant Activation
CloudLinux • Softaculous • Fantastico • FFMpeg • PHP 5.3
HostMantis on: FacebookTwitter
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Sponsored By: