Router Security configurations for worm attacks

Source: Internet
Author: User

Network security is a matter of special concern to users, but there are still many problems. It does not matter if many people do not know how to configure Router Security for worm attacks. After reading this article, you will certainly have a lot of GAINS, I hope this article will teach you more things. A few days ago, security researchers discovered a botnet worm called psyb0t, which can attack DSL modem and router security configurations. This worm can search for and exploit specific devices with open ports. The attacked device also has a weak password.

Once a worm enters a vro, it can do whatever it wants, block the port, leak sensitive information, and attack other networks. In this article, I will analyze the router security configuration types that are vulnerable to such specific worms, and then discuss how to prevent such and other types of router worms from being infected. Finally, we will discuss how to clear worms infected with routers.

How do worms enter the vro

The router worm enters the router through the port used to remotely manage the router. However, the router security configuration does not open these ports by default. It must be manually enabled on the configuration program of the router security configuration Web interface. In addition, a larger vulnerability lies in weak passwords. In other words, remote management is secure if defense measures are taken. According to media research, the latest worm attacks basically need to meet the following standards:

1. These devices are generally devices using MIPS processors, which run the simple version of The Endian mode (mipsel. This includes about 30 Linksys devices, 10 Netgear devices, and many other devices. In addition, routers that load other firmware replacements, such as DD-WRT and OpenWRT, are also vulnerable to attacks.

2. enable some remote management devices, such as telnet, SSH, or Web-based access. It is not easy to provide local access.

3. The combination of user names and passwords for remote access management is not strong enough to be easily cracked. Or its firmware is easily exploited by the Vulnerability exploitation program.

Ensures the security of WAN services

Since vro worms invade through remote management ports, ensuring the security of these ports becomes the key to preventing infection. In addition, it is the best solution to disable remote management and disable these ports because worms are inaccessible. However, if remote access is required, follow the following guidelines to prevent worms from intruding:

1. Use a strong and secure password

You know, the router worm relies on powerful dictionary attacks (constantly trying to guess the password), so we should use a password that is not easy to guess. Do not use any "admin", "router", or "12345" as vro Security Configuration passwords, but use a combination, such as rDF4m9Es0yQ3ha. It must contain at least uppercase and lowercase letters and contain numbers and letters. Although this password is hard to remember, we can store it in a certain file (such as a text file), and use TrueCrypt, Cryptainer LE and other software to encrypt various files that save the password.

2. Secure Remote Connection Encryption

For example, try not to use HTTP because it uses plain text transmission. You can use HTTPS to transmit Web-based access. You can enable the remote access settings of the vro security configuration program and select the "https" option. If you need command lines to access the vro, you can use SSH. Because SSH is an encrypted protocol. Encrypted connections are not necessary to prevent router worms, but they can enhance the overall security of router security configurations. If the vro is infected, some incredible things will happen. For example, it is reported that Psyb0t will block communication between port 22, port 23, and port 80.

To clear the worm, the most thorough solution is to restore the router security configuration to the factory default value, so as to ensure that the worm is cleared. Press the reset button on the back of the vro Security Configuration and wait a few seconds (different vendors have different requirements. For example, if my vro requires more than 30 seconds), it can be restored to the factory status. Once the worm is cleared, remember to use the method described in this article.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.