Router hijacking

From: Nick (kewlest_at_yahoo.com)
Date: 09/09/04


Date: Wed, 08 Sep 2004 15:24:41 -0700

Hi
I had a belkin's router with a simple packet filtering firewall. I had
switch off remote access/configuration - that is, it won't(shouldn't)
allow any connections to port 80 that comes from the external interface.

One day, I found a open TCP port (Virtual Server/port forwarding) to my
housemate's machine that we hadn't set up! I checked my housemate's
machine for any process listening on that port...none!

I closed the port / changed the password and it didn't happen again. But
I wonder how it happened in the first place? Any ideas?
My router also used to get a couple of port scans that it used to log.
But that's it!
I recently came across a similar complaint at some other newsgroup too.

Only way that I can think of, is that my friend downloaded some spyware
with a keylogger - got the login/passwd info ( though I doubt it since
he hardly used to login himself) and tried to login and add the entry (
the author must know exact http packets that were exchanged with the
router). Or a bug in belkin's router that I am not aware of!
-N



Relevant Pages

  • Re: Using Remote Desktop From an SBS Domain
    ... when you tried to RDP while attached directly to a port on your router? ... So if 3389 needs forwarded on the client end too then that is what the ... Hopefully next week I can attempt a connection while my ISP watches the ...
    (microsoft.public.windows.server.sbs)
  • Re: Firewall HELP
    ... When you say that you get the "login to the firewall"... ... would try deactivating all remote login options in the router (or at least ... changing them to another port). ... >>> Does tell me that your router is blocking port 25. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cost of setting up a network
    ... A router capable of acting as a VPN endpoint for more than one user simultaneously with four Ethernet ports or a switch to suit. ... The rationale for using a server here is basically that the router doesn't need to be able to decide which PC to route the connection to. ... If you are using a router which supports it, you can set up a port-forwarding inbound rule which also _translates_ the port supplied to the receiving port. ... You can use several of these connections to different machines simultaneously. ...
    (uk.comp.homebuilt)
  • Re: Block ssh login prompt for *.kr *.jp etc.
    ... >to be PROMPTED for a login. ... You probably want your whole machine to be invisible, not just the SSH ... Block as much as you can at the router. ... Consider running SSH on a non-standard port. ...
    (comp.security.ssh)
  • Cant Connect to XP
    ... wrt54g router, I cannot connect anymore and receive 'Generic Platform ... Web 0' login box, I've tried typing in router login, PC admin, even ... I've forwarded the port to 3389 using the url 1 below, ...
    (microsoft.public.windowsxp.work_remotely)