Gentoo Archives: gentoo-user

From: walt <w41ter@×××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: ADSL+WiFi modem router possibly compromised
Date: Mon, 03 Feb 2014 20:02:08
Message-Id: 52EFF5B6.7030601@gmail.com
In Reply to: [gentoo-user] re: ADSL+WiFi modem router possibly compromised by Alexander Kapshuk
1 On 02/03/2014 10:25 AM, Alexander Kapshuk wrote:
2 > Howdy,
3 >
4 > I connect to the Internet via a TP-LINK TD-W8101G Wireles ADSL2+ model
5 > router. It has been set up to acquire IP addresses via DHCP. My
6 > '/etc/resolve.conf' has been getting populated like so from the word go:
7 > cat /etc/resolv.conf
8 > # Generated by dhcpcd from enp4s0
9 > # /etc/resolv.conf.head can replace this line
10 > nameserver 192.168.1.1
11 > # /etc/resolv.conf.tail can replace this line
12 >
13 > This morning, I discovered that the nameserver IP address in my
14 > '/etc/resolve.conf' had changed:
15 > cat /etc/resolv.conf
16 > # Generated by dhcpcd from enp4s0
17 > # /etc/resolv.conf.head can replace this line
18 > nameserver 5.45.75.11
19 > # /etc/resolv.conf.tail can replace this line
20 >
21 > I contacted my ISP about it. They said the nameserver in question was
22 > not theirs.
23 >
24 > The whole thing began to smell fishy.
25 >
26 > What I've done so far is, I've reset my router to the default settings
27 > and set it up again.
28 > I've also changed the admin console password, as well as the WiFi access
29 > point password.
30 >
31 > As a result, my nameserver IP address has been defined as 192.168.1.1.
32 >
33 > Anything else I can do to ensure my system has not been compromised?
34
35 Google the number 32764 and you'll find a lot of info on a particular
36 router bug. You'll see a link to Steve Gibson's grc.com, where you can
37 scan for port 32764 on your router to see if it's listening.

Replies

Subject Author
Re: [gentoo-user] Re: ADSL+WiFi modem router possibly compromised Alexander Kapshuk <alexander.kapshuk@×××××.com>