GhostDNS: 70+ different types of home routers (100,000+) are being hijacked

Published by

Click here to post a comment for GhostDNS: 70+ different types of home routers (100,000+) are being hijacked on our message forum
https://forums.guru3d.com/data/avatars/m/232/232349.jpg
What a day we live in today..... So many hardware/software vulnerabilities out there its simply amazing anything is up and running ATM. Anything...... Just crazy.....!!
data/avatar/default/avatar14.webp
DeskStar:

What a day we live in today..... So many hardware/software vulnerabilities out there its simply amazing anything is up and running ATM. Anything...... Just crazy.....!!
well ATM basically LAN (enclosed-wan) that only connect to banking-network which separate them from internet-open-world thats why they not effected much by real-world vulnerabilites... even though probably they share same vulnerabilites
https://forums.guru3d.com/data/avatars/m/130/130603.jpg
Think he ment 'At The Moment' xD
https://forums.guru3d.com/data/avatars/m/235/235398.jpg
Steppzor:

Think he ment 'At The Moment' xD
Thanks Ron Burgundy! now i know why you're the most trusted name in San Diego!
data/avatar/default/avatar28.webp
and lo ~ I have a router update! thnx for the heads up! (even updated just a month ago). if anyone needs help do this: open file explorer (the folder icon on the taskbar) click "network" on the left in windows 10, my wifi router appears under "network infrastructure" as "R7000 (Gateway)" right click that > "view device webpage" if it's netgear, The user name is admin, and the password is password you may see a flag to update firmware at the top of that main page, if not, click "advanced" tab > click "administration" on the left > "router update" again, you should see update firmware, but if not click "check" let it take the time to update and reset your router (no internet for a minute while it resets) as for your cable modem, google your device model number. if it's like mine, it says that firmware updates are pushed by your ISP so no worries there 🙂 other tips to maximize security: - there may be an option to auto update on your router page (expect to be kicked offline sometimes but who knows maybe it's smarter and knows your idle time like windows 10 updates now) - keep windows up to date (type 'check for updates' on windows 10 search bar) > click "check now" if they don't appear already - keep your pc up to date w/ manufacturer software (for me it's the "Lenovo vantage" windows 10 app. this pc updates its bios etc a lot) - use a wired connection directly from your cable modem to your newest PC (a new chipset that's designed to not have spectre and meltdown vulnerabilities etc).
https://forums.guru3d.com/data/avatars/m/243/243702.jpg
DeskStar:

What a day we live in today..... So many hardware/software vulnerabilities out there its simply amazing anything is up and running ATM. Anything...... Just crazy.....!!
There is no gain from taking infected device down. Gain comes from many sources, like: - pushing users content hijacker wants - knowing what victim does - having access to their data - coordinated blackout when someone pays for it - ...
data/avatar/default/avatar16.webp
Maybe some people overlooked the key factor here "change the default password."
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
seeing as the DNS on this Sagemcom router I have are locked to Spectrum and cant be changed even by me even if I wanted to, let alone fact that it hasnt had FW in years not much I can do with this router I have less, alot people really do need to change there defualt passwords though
https://forums.guru3d.com/data/avatars/m/232/232130.jpg
So it's not attack on router from outside, but from inside (client side)? From what I understand, user run JS on compromised website, which find router IP in internal network. Browser then accesses users router via HTTP and changes its settings? Damn, browsers are scary.
data/avatar/default/avatar40.webp
Makes me happy to A. have an Asus Router, B have Asus Merlin which is regular updated FW. Now go give that guy a donation =)
https://forums.guru3d.com/data/avatars/m/232/232349.jpg
Makes me feel good that I never was a person to use default garbage settings just because. Because if that is why these issues are taking place.....then by all means it is the consumers fault through and through. I am about to buy a newer router, but I think ill stick out my WNDR4500 for a bit longer until the new....new drops some time next year. Since they're in the mode of changing the standard naming of all routers "capabilities" on their throughput. Maybe something new will come in the way of a hardware mitigation toward any of these types of vulnerabilities of today.... Maybe??
https://forums.guru3d.com/data/avatars/m/232/232349.jpg
Mateja:

and lo ~ I have a router update! thnx for the heads up! (even updated just a month ago). if anyone needs help do this: open file explorer (the folder icon on the taskbar) click "network" on the left in windows 10, my wifi router appears under "network infrastructure" as "R7000 (Gateway)" right click that > "view device webpage" if it's netgear, The user name is admin, and the password is password you may see a flag to update firmware at the top of that main page, if not, click "advanced" tab > click "administration" on the left > "router update" again, you should see update firmware, but if not click "check" let it take the time to update and reset your router (no internet for a minute while it resets) as for your cable modem, google your device model number. if it's like mine, it says that firmware updates are pushed by your ISP so no worries there 🙂 other tips to maximize security: - there may be an option to auto update on your router page (expect to be kicked offline sometimes but who knows maybe it's smarter and knows your idle time like windows 10 updates now) - keep windows up to date (type 'check for updates' on windows 10 search bar) > click "check now" if they don't appear already - keep your pc up to date w/ manufacturer software (for me it's the "Lenovo vantage" windows 10 app. this pc updates its bios etc a lot) - use a wired connection directly from your cable modem to your newest PC (a new chipset that's designed to not have spectre and meltdown vulnerabilities etc).
Are you serious about your user name and password.....?!?!?
https://forums.guru3d.com/data/avatars/m/232/232349.jpg
tsunami231:

seeing as the DNS on this Sagemcom router I have are locked to Spectrum and cant be changed even by me even if I wanted to, let alone fact that it hasnt had FW in years not much I can do with this router I have less, alot people really do need to change there defualt passwords though
Buy your own router/modem. You are not locked into using their shtuff at all.
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
DeskStar:

Buy your own router/modem. You are not locked into using their shtuff at all.
yah i know I want to get the asus 86u but i have not done so yet, what is probably gona happen is I just gone use the asus 66u that currently being used at the house in nj though
https://forums.guru3d.com/data/avatars/m/232/232349.jpg
tsunami231:

yah i know I want to get the asus 86u but i have not done so yet, what is probably gona happen is I just gone use the asus 66u that currently being used at the house in nj though
Right on. I'm in the realm of looking also, but want to let his crazy dust settle before buying into these routers that have been on the market for a few years already. Trying to hold out, but this N900 is starting to show its lack of throughput at its age.
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
yah this sagemcom is utter trash, 1 connection doing something it can do it just fine, but if 2 people are trying to do something other then web browsing, the whole network come to a crawl. my 66U doesnt have this issue. and seeing as it really just me using the interent here replacing the router is low on list of things to do