Networking Forums

Networking Forums > Computer Networking > Broadband > cannot access ebay....

Reply
Thread Tools Display Modes

cannot access ebay....

 
 
Tired
Guest
Posts: n/a

 
      11-24-2011, 09:52 PM
Tired wrote:
> A problem on a friends bt broadband. I cannot access www.ebay.co.uk.
> All other sites seem to be ok. Just this one site. Tried changing mtu
> values, tried changing wireless dongle (this seemed to have worked,
> but problem back).


Thanks for the help. Tracked the problem down. Some kind of trojan had
accessed the router (dlink router with admin admin as user /password) and
had changed the dns server settings.

Put them back to automatic and flushed dns cache, problem solved......


 
Reply With Quote
 
 
 
 
The Natural Philosopher
Guest
Posts: n/a

 
      11-24-2011, 10:10 PM
Tired wrote:
> Tired wrote:
>> A problem on a friends bt broadband. I cannot access www.ebay.co.uk.
>> All other sites seem to be ok. Just this one site. Tried changing mtu
>> values, tried changing wireless dongle (this seemed to have worked,
>> but problem back).

>
> Thanks for the help. Tracked the problem down. Some kind of trojan had
> accessed the router (dlink router with admin admin as user /password) and
> had changed the dns server settings.
>
> Put them back to automatic and flushed dns cache, problem solved......
>
>

i've logged into at least three routers like that, that had been used to
launch DOS attacks.. and shut them down HOPING that whoever owned them
would notice and rejig the password...

 
Reply With Quote
 
TGH
Guest
Posts: n/a

 
      11-25-2011, 06:40 AM
On 24/11/2011 23:10, The Natural Philosopher wrote:
> Tired wrote:
>> Tired wrote:
>>> A problem on a friends bt broadband. I cannot access www.ebay.co.uk.
>>> All other sites seem to be ok. Just this one site. Tried changing mtu
>>> values, tried changing wireless dongle (this seemed to have worked,
>>> but problem back).

>>
>> Thanks for the help. Tracked the problem down. Some kind of trojan had
>> accessed the router (dlink router with admin admin as user /password)
>> and had changed the dns server settings.
>>
>> Put them back to automatic and flushed dns cache, problem solved......
>>

> i've logged into at least three routers like that, that had been used to
> launch DOS attacks.. and shut them down HOPING that whoever owned them
> would notice and rejig the password...
>

At least it is sorted now, first thing to do when setting up a router is
to change the default username/password of it IMHO.
TGH
 
Reply With Quote
 
The Natural Philosopher
Guest
Posts: n/a

 
      11-25-2011, 10:31 AM
TGH wrote:
> On 24/11/2011 23:10, The Natural Philosopher wrote:
>> Tired wrote:
>>> Tired wrote:
>>>> A problem on a friends bt broadband. I cannot access www.ebay.co.uk.
>>>> All other sites seem to be ok. Just this one site. Tried changing mtu
>>>> values, tried changing wireless dongle (this seemed to have worked,
>>>> but problem back).
>>>
>>> Thanks for the help. Tracked the problem down. Some kind of trojan had
>>> accessed the router (dlink router with admin admin as user /password)
>>> and had changed the dns server settings.
>>>
>>> Put them back to automatic and flushed dns cache, problem solved......
>>>

>> i've logged into at least three routers like that, that had been used to
>> launch DOS attacks.. and shut them down HOPING that whoever owned them
>> would notice and rejig the password...
>>

> At least it is sorted now, first thing to do when setting up a router is
> to change the default username/password of it IMHO.
> TGH

And unless you are a total noob, remove access to its admin pages from
the internet at large. At the worsts, make sure only a range
corresponding to your ISP can access it.


 
Reply With Quote
 
Mike Tomlinson
Guest
Posts: n/a

 
      11-25-2011, 12:08 PM
In article <jangpt$pe8$(E-Mail Removed)>, TGH <(E-Mail Removed)>
writes

>At least it is sorted now, first thing to do when setting up a router is
>to change the default username/password of it IMHO.


Then untick the option that exposes the management interface to the
internet!

--
(\__/)
(='.'=)
(")_(")
 
Reply With Quote
 
Tired
Guest
Posts: n/a

 
      11-25-2011, 12:52 PM
TGH wrote:
> On 24/11/2011 23:10, The Natural Philosopher wrote:
>> Tired wrote:
>>> Tired wrote:
>>>> A problem on a friends bt broadband. I cannot access
>>>> www.ebay.co.uk. All other sites seem to be ok. Just this one site.
>>>> Tried changing mtu values, tried changing wireless dongle (this
>>>> seemed to have worked, but problem back).
>>>
>>> Thanks for the help. Tracked the problem down. Some kind of trojan
>>> had accessed the router (dlink router with admin admin as user
>>> /password) and had changed the dns server settings.
>>>
>>> Put them back to automatic and flushed dns cache, problem
>>> solved......

>> i've logged into at least three routers like that, that had been
>> used to launch DOS attacks.. and shut them down HOPING that whoever
>> owned them would notice and rejig the password...
>>

> At least it is sorted now, first thing to do when setting up a router
> is to change the default username/password of it IMHO.
> TGH


changed his password.

As i understand it though changing the password isnt good enough. The trojan
doesnt just rely on default passwords, but on users 'remembering' the
password in Internet Explorer, and then using that to access.

I would imagine that each router type would need a sophisticated script to
work. I have come across netgears with screwed up dns settings, but never a
dlink.


 
Reply With Quote
 
Tired
Guest
Posts: n/a

 
      11-25-2011, 12:52 PM
The Natural Philosopher wrote:
> TGH wrote:
>> On 24/11/2011 23:10, The Natural Philosopher wrote:
>>> Tired wrote:
>>>> Tired wrote:
>>>>> A problem on a friends bt broadband. I cannot access
>>>>> www.ebay.co.uk. All other sites seem to be ok. Just this one
>>>>> site. Tried changing mtu values, tried changing wireless dongle
>>>>> (this seemed to have worked, but problem back).
>>>>
>>>> Thanks for the help. Tracked the problem down. Some kind of trojan
>>>> had accessed the router (dlink router with admin admin as user
>>>> /password) and had changed the dns server settings.
>>>>
>>>> Put them back to automatic and flushed dns cache, problem
>>>> solved......
>>> i've logged into at least three routers like that, that had been
>>> used to launch DOS attacks.. and shut them down HOPING that whoever
>>> owned them would notice and rejig the password...
>>>

>> At least it is sorted now, first thing to do when setting up a
>> router is to change the default username/password of it IMHO.
>> TGH

> And unless you are a total noob, remove access to its admin pages from
> the internet at large. At the worsts, make sure only a range
> corresponding to your ISP can access it.


I dont think i have come across a router that has external access enabled by
default.


 
Reply With Quote
 
Monsieur Merde
Guest
Posts: n/a

 
      11-25-2011, 03:20 PM
On Fri, 25 Nov 2011 13:52:02 +0000, Tired texted:

> TGH wrote:
>> On 24/11/2011 23:10, The Natural Philosopher wrote:
>>> Tired wrote:
>>>> Tired wrote:
>>>>> A problem on a friends bt broadband. I cannot access www.ebay.co.uk.
>>>>> All other sites seem to be ok. Just this one site. Tried changing
>>>>> mtu values, tried changing wireless dongle (this seemed to have
>>>>> worked, but problem back).
>>>>
>>>> Thanks for the help. Tracked the problem down. Some kind of trojan
>>>> had accessed the router (dlink router with admin admin as user
>>>> /password) and had changed the dns server settings.
>>>>
>>>> Put them back to automatic and flushed dns cache, problem
>>>> solved......
>>> i've logged into at least three routers like that, that had been used
>>> to launch DOS attacks.. and shut them down HOPING that whoever owned
>>> them would notice and rejig the password...
>>>

>> At least it is sorted now, first thing to do when setting up a router
>> is to change the default username/password of it IMHO. TGH

>
> changed his password.
>
> As i understand it though changing the password isnt good enough. The
> trojan doesnt just rely on default passwords, but on users 'remembering'
> the password in Internet Explorer, and then using that to access.
>

CSRF - common as fuck. Easy to scan given customer ranges belonging to
certain telco's where vulnerable routers live - especially if they have
certain default ports open.
 
Reply With Quote
 
The Natural Philosopher
Guest
Posts: n/a

 
      11-25-2011, 03:28 PM
Tired wrote:
> The Natural Philosopher wrote:
>> TGH wrote:
>>> On 24/11/2011 23:10, The Natural Philosopher wrote:
>>>> Tired wrote:
>>>>> Tired wrote:
>>>>>> A problem on a friends bt broadband. I cannot access
>>>>>> www.ebay.co.uk. All other sites seem to be ok. Just this one
>>>>>> site. Tried changing mtu values, tried changing wireless dongle
>>>>>> (this seemed to have worked, but problem back).
>>>>> Thanks for the help. Tracked the problem down. Some kind of trojan
>>>>> had accessed the router (dlink router with admin admin as user
>>>>> /password) and had changed the dns server settings.
>>>>>
>>>>> Put them back to automatic and flushed dns cache, problem
>>>>> solved......
>>>> i've logged into at least three routers like that, that had been
>>>> used to launch DOS attacks.. and shut them down HOPING that whoever
>>>> owned them would notice and rejig the password...
>>>>
>>> At least it is sorted now, first thing to do when setting up a
>>> router is to change the default username/password of it IMHO.
>>> TGH

>> And unless you are a total noob, remove access to its admin pages from
>> the internet at large. At the worsts, make sure only a range
>> corresponding to your ISP can access it.

>
> I dont think i have come across a router that has external access enabled by
> default.
>
>

depends on which ISP supplies it.

Some come that way for 'remote support by the ISP'
 
Reply With Quote
 
Phil W Lee
Guest
Posts: n/a

 
      11-25-2011, 05:20 PM
TGH <(E-Mail Removed)> considered Fri, 25 Nov 2011 07:40:41 +0000
the perfect time to write:

>On 24/11/2011 23:10, The Natural Philosopher wrote:
>> Tired wrote:
>>> Tired wrote:
>>>> A problem on a friends bt broadband. I cannot access www.ebay.co.uk.
>>>> All other sites seem to be ok. Just this one site. Tried changing mtu
>>>> values, tried changing wireless dongle (this seemed to have worked,
>>>> but problem back).
>>>
>>> Thanks for the help. Tracked the problem down. Some kind of trojan had
>>> accessed the router (dlink router with admin admin as user /password)
>>> and had changed the dns server settings.
>>>
>>> Put them back to automatic and flushed dns cache, problem solved......
>>>

>> i've logged into at least three routers like that, that had been used to
>> launch DOS attacks.. and shut them down HOPING that whoever owned them
>> would notice and rejig the password...
>>

>At least it is sorted now, first thing to do when setting up a router is
>to change the default username/password of it IMHO.
>TGH

I hope most (if not all) of us on here realise that.
The problems are the ones who don't.

A few years ago I came across one that was such a mess that I was able
to find the email addresses for all the users on the network it was
connecting, and emailed their "network admin", MD, and HR department
offering my services as security consultant with an explanation of why
they needed one, and the new, secure, admin names and passwords for
their router and email server (it was self defence - they were
mail-bombing a server on a network I was asked to sort out after it
got bogged down dealing with the consequences of the malware on their
unsecured systems).

A couple of weeks later I built and installed a firewall for them -
their "network admin" had been the supposedly computer literate son of
one of the directors, setting it up in his school holidays.
Needless to say, the router and firewalling weren't the only things
that needed fixing.

They were a business contact of the place I was originally sorting
out, so simply blocking them wasn't an option.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
cantennas on ebay sillyputty Wireless Internet 1 08-25-2007 08:50 PM
ebay buy Skype Sunil Sood Broadband 0 09-12-2005 11:33 AM
DG834G and eBay? Paul D Smith Broadband 2 02-20-2005 05:52 PM
Problems with eBay Warthog Broadband 2 05-24-2004 10:03 PM
Ebay Scam SOGGY Wireless Internet 0 02-18-2004 06:50 PM



1 2 3 4 5 6 7 8 9 10 11