Has there been a large scale hacking on SOHO routers and modems recently?

KonfuSed

Disciple
Jun 11, 2009
62
4
72
45
Hi All,

Today while checking an issue with my home network (not my current place but at my natives), I found that the DNS address looked kind of suspicious. The DNS IP Address was 5.45.75.11(Primary.) and 5.45.75.36(Secondary.) and these addresses kinda seemed phony to me. So I ran a Google search and found out that there has been reports of a very recent Cyber attack on modems/routers where the DNS server address has been forcefully changed to these addresses. What this means that all your sensitive data/information probably are being compromised. Here are couple of references for this attack which google has shown:

http://www.ispreview.co.uk/index.ph...0000-home-broadband-routers-major-brands.html

http://www.pcworld.com/article/2104...-300000-home-routers-alters-dns-settings.html

The report can be found here :
https://www.team-cymru.com/ReadingRoom/Whitepapers/2013/TeamCymruSOHOPharming.pdf

Also it seems that these phony DNS servers are not exactly responding well and most of the time you would not be even able to connect to network or it'll be very slow net conn (which is what was happening at my folk's place). So if you are suddenly facing such issues and getting DNS response errors then it might be the case that your modem/router has been compromised. Even if you are not facing disconnection or slow network issues, it would be better if you check your DNS configs just to be sure.

The modem and router used in my home are DLink but it seems many other brands also facing the same issue.
The service provider is BSNL at my natives.

Note : As of now, I'll force my modem to point to either google DNS or some other openDNS now but that probably is not the permanent solution (or not even a solution). Permanent solution would probably be an upgraded firmware without this vulnerability for such attacks. Also if the network is compromised that would also mean that the computers and other devices are also been compromised. Probably I will also have to get the machines at my home scanned properly for virus/maleware?

If anyone out there have more info then please do share. Also please let us know if this attack is for real (from the readings it does look real) and what should be steps need to be taken for remedy and also for protection.
Regards,
 

blr_p

Skilled
Apr 11, 2007
8,739
1
3,049
376
it sounds like they hacked the ISP's DNS server rather than the customers modem.

How elegant, now everybody that pulls a dns list at modem startup off their ISP will get the chosen servers :D

I've always used google's because it meant a faster modem startup to get online. No need to do that dns list request to the ISP.

cymru btw means wales in welsh.
 

6pack

ex-Mod
Sep 19, 2005
8,589
2,699
378
From the links in his post it looks like the modems and routers having admin pages accessible from net were hacked with some exploit. I don't think the ISP servers were hacked.
 

blr_p

Skilled
Apr 11, 2007
8,739
1
3,049
376
If you enable serving on the router and retain default user/pass no exploit is needed.
 

KonfuSed

Disciple
Jun 11, 2009
62
4
72
45
Doesn't seem like it is happening at the ISP side. The change was done at the modem (DLink 2520). By default the DNS settings used to be Enable Obtain DNS automatically but this got changed to the phony DNS addresses. I've changed those addresses to that of Google DNS and also changed the password and LAN addresses. Now the network is working and my folks are able to use the internet now. Hope this will keep on working for some time. Luckily no one at home use net-banking and so that way kinda safe.
 

KonfuSed

Disciple
Jun 11, 2009
62
4
72
45
Dear, not everyone is tech savvy and probably 80% of internet users are not even aware of what DNS server is. So I feel this kind of attack/threat is very real and can cause damage.