Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » 2Wire » DNS Hijack on 2wire routers?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
2701HG-B Frequent loss of Internet light, and now rebooting »
« Block MSN Messenger in the company  
AuthorAll Replies

muiredised
ESSE QUAM VIDERI

join:2007-06-11
Tacoma, WA

reply to bjparker
Re: DNS Hijack on 2wire routers?

You can implement a temporary fix yourself. The first post in the following thread describes how to protect yourself until 2wire fixes the issue »2Wire Cross Site Request Forgery Vulnerability .

Here is a short summary:

First, change the IP scheme that the 2wire is using for your home network. Specifically, change the IP address of the 2wire router itself. This will prevent attacks against 192.168.1.254.

Next you have to prevent attacks against the domains "home" and "gateway.2wire.net". You can do this a couple of ways. You can modify your hosts file and point those domains to 127.0.0.1... or you can hardcode the dns settings into your computer so that your computer is not using the 2wire to resolve domain names.

Of course the bottom line is 2wire needs to plug this hole. When will that happen? Who knows.
--
Assiduus usus uni rei deditus et ingenium et artem saepe vincit

bjparker

join:2004-09-13
England

reply to jr9730
said by jr9730 See Profile :

The fix is under way..
When? My router got attacked today, for the second time in a month, fortunately I had a partial fix in place that just meant the DNS stopped working (presumably they block OpenDNS).

These exploits have been talked of for 1 year and in the wild for about 3 months!

Does 2wire actually do anything?
Forums » Equipment Support » Hardware By Brand » 2Wire2701HG-B Frequent loss of Internet light, and now rebooting »
« Block MSN Messenger in the company  


Saturday, 05-Dec 06:18:16 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [90] The Bandwidth Hog Does Not Exist
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [77] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Farewell [Bell Canada]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· DNS options, what are YOU using? [TekSavvy]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· ZR1 VS The USN Blue Angels! [56k Lookout (Broadband Heavy)]