LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-22-2014, 06:46 PM   #1
catatom
LQ Newbie
 
Registered: Oct 2014
Posts: 23

Rep: Reputation: Disabled
locked out of router settings! ... by a spoofer?


I recently started suspecting an attack. Now I find that I can't access http://routerlogin.net, where I would go to adjust the settings. The connection times out immediately. I tried disabling my firewall, allowing netBIOS traffic through the modem, and I checked the hosts file.

Could a spoofer do this to hide and protect their changes? Is it good evidence of spoofing?

Last edited by catatom; 10-22-2014 at 06:49 PM.
 
Old 10-22-2014, 07:02 PM   #2
coralfang
Member
 
Registered: Nov 2010
Location: Bristol, UK
Distribution: Slackware, FreeBSD
Posts: 836
Blog Entries: 3

Rep: Reputation: 297Reputation: 297Reputation: 297
Have you tried accessing the gateway directly. eg; 192.168.0.1
It may be a different subnet depending on the device.

Could be that your dns has gone funky, where it is unable to resolve routerlogin.net to an address.
Just a possibility.
 
Old 10-24-2014, 06:47 AM   #3
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
u should google ur router model and check if there are any exploits to it, or if its web configuration page is reachable from the internet etc.
 
Old 10-24-2014, 03:52 PM   #4
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
http://kb.netgear.com/app/answers/de...fault-settings
 
Old 10-24-2014, 09:32 PM   #5
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,980

Rep: Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624
Yes a crook or automated crook could have taken control.

Reset to factory settings.

Be sure to consider latest updates if they suggest security.

Be sure to disable any outside access and limit times and ports and protocols.
 
Old 10-26-2014, 06:56 PM   #6
catatom
LQ Newbie
 
Registered: Oct 2014
Posts: 23

Original Poster
Rep: Reputation: Disabled
Every site is fine except routerlogin. Apparently I can try entering the router's IP address too. WIll try at home.

ALthough our model seems fine, the model you get if you subtract the "v3" is at its end of life and has four vulnerabilities.

I'm trying to get a reinstall image because my cursor was going berzerk when I connected to any network.

Last edited by catatom; 10-26-2014 at 07:21 PM.
 
Old 10-27-2014, 02:49 PM   #7
catatom
LQ Newbie
 
Registered: Oct 2014
Posts: 23

Original Poster
Rep: Reputation: Disabled
I'm not sure which was the router IP, but I entered "route -n" and none of those addresses loaded a page.
I can access the modem through its IP just fine.
 
Old 10-27-2014, 10:10 PM   #8
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,980

Rep: Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624
That domain name is a stub. Basically if you have a new windows computer the computer will use the router as dns. Router will convert that name to it's ip address.

So, just access router by ip forever instead of some dns name.
 
Old 10-28-2014, 05:06 PM   #9
catatom
LQ Newbie
 
Registered: Oct 2014
Posts: 23

Original Poster
Rep: Reputation: Disabled
How do I find the router IP address? I tried all the IPs I could find through terminal command lines, but all I got was the modem page and Google (tcpdump).

Last edited by catatom; 10-28-2014 at 05:07 PM.
 
Old 10-28-2014, 06:33 PM   #10
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
http://192.168.1.1
 
Old 10-28-2014, 09:29 PM   #11
michaelk
Moderator
 
Registered: Aug 2002
Posts: 25,700

Rep: Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895Reputation: 5895
Please post the make/model of your MODEM. What do you mean my MODEM page? What is the IP of the MODEM? How is your network physically configured?

Please post the model number of your router.

As stated Netgear SOHO routers typically have a default IP address of 192.168.1.1. The output of the route -n command will show a UG under flags. The address in the same line under gateway should be the LAN IP of your router.

Last edited by michaelk; 10-28-2014 at 09:31 PM.
 
Old 10-28-2014, 10:10 PM   #12
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,980

Rep: Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624
Get the mac address and use arp to make a temporary static arp entry. Then make a default ip for that mac in the range of your current subnet.

No matter what the real ip, your static arp would point to the one you set.
 
Old 10-30-2014, 04:30 PM   #13
catatom
LQ Newbie
 
Registered: Oct 2014
Posts: 23

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by michaelk View Post
Please post the make/model of your MODEM. What do you mean my MODEM page? What is the IP of the MODEM? How is your network physically configured?

Please post the model number of your router.

As stated Netgear SOHO routers typically have a default IP address of 192.168.1.1. The output of the route -n command will show a UG under flags. The address in the same line under gateway should be the LAN IP of your router.
That address was 192.168.1.254. It was called "home portal" in the unmodified route output. Another output was "link-local" but that IP led nowhere too.

I don't have the model number with me ATM, but the make is
N300 Wireless ADSL2 + Modem Router DGN2200v3

Last edited by catatom; 10-30-2014 at 04:45 PM.
 
Old 10-30-2014, 05:53 PM   #14
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
n/m. michaelk already mentioned NetGear.

Last edited by Habitual; 10-30-2014 at 05:54 PM.
 
Old 10-30-2014, 05:53 PM   #15
catatom
LQ Newbie
 
Registered: Oct 2014
Posts: 23

Original Poster
Rep: Reputation: Disabled
It is netgear.

Jefro, I'll try that. btw, how could I turn off ARP replies to limit my connections to those established manually?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
dconf and locked settings Chris.Bristol Linux - Desktop 1 05-18-2014 03:47 AM
cannot ping wireless router or access router settings. wireless works, wired doesn't mattca Linux - Networking 1 06-09-2010 09:28 PM
Locked out of Time and Network settings GUI mirror_man Debian 8 06-24-2009 06:54 PM
Proftpd Locked Behind Router discrepant Linux - Networking 1 02-01-2005 05:53 PM
Proftpd Locked Behind Router discrepant Linux - Newbie 1 02-01-2005 03:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration