DATA DOCTORS

How can I protect my router from the attack the FBI is warning about?

May 31, 2018, 1:00 PM

(Flickr/DeclanTM)...

(Flickr/DeclanTM)

(Flickr/DeclanTM)

Q: What exactly do I need to do to protect my router against the attack the FBI is warning about?

A: The recent warning sent out by the FBI about hackers compromising hundreds of thousands of routers commonly used in homes and small businesses is an indication of how important this particular threat is to many.


The threat

The exploit can silently capture everything you’re doing on your various devices, including stealing usernames and passwords and limit or completely shut down your Internet connection altogether.

The FBI’s reference to ‘small office and home office routers’ generally refers to inexpensive consumer grade routers that typically lack the level of security and management available in expensive business class routers.

Who’s at risk?

The brands known to be vulnerable include Linksys, Netgear, QNAP, MicroTik and TP-Link but my advice is that everyone with a consumer router should assume that it may be vulnerable and update it anyway.  The older your router is, the more likely that it’s vulnerable.

VPNFilter

The malware that‘s threatening routers and some QNAP network-attached storage (NAS) devices is known as VPNFilter.  It’s particularly pervasive because it can remain even if an infected device is rebooted.

The malware authors also focused on intercepting industrial control system communications that control large-scale systems such as gas pipelines, power transmission and water distribution, which is another reason for the FBI to be concerned.

How it infects

The most likely methods of infection are possible because most consumer routers are still using the default admin username and password and haven’t patched known security exploits after they were initially setup.

Protection steps

The steps to protect your router from this and many other router specific security threats is pretty straightforward.

Before you perform any of these steps, read them all so you don’t get stuck in the middle of the process without something you’ll need.  It’s also critical that you document any of the settings that you’re currently using such as level of encryption, SSID and passwords so you can re-enter them when the reset and update are complete.

If you don’t use the exact same SSID and password when you’re done, you’ll have to reset each device that connects to your Wi-Fi network with the new credentials, which can be a bit of a hassle if you have lots of home automation or IOT devices in your home.

You’ll also need to make sure you have an Ethernet cable to connect your computer directly to your router before you get started.

The first step is to find out the exact model of router you own (usually stamped on the bottom or side) and download the most current firmware from the manufacturer’s support website (If you have a newer router that has the automatic update feature built-in, you can skip this step).

Since there’s no simple way to know if your device is infected, performing a hard reset, which wipes out the malware and all your settings is the next step.

Once your router has restarted and your connected computer is able access it, carefully follow the installation instructions for updating the firmware.

Finally, make sure you change the default username and password for the administrative interface to something only you will know and re-enter all the connection settings you documented prior to resetting.

Data Doctors

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

7 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

14 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

21 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

28 days ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

(Photo by Michael Bocchieri/Getty Images)...

Ken Colburn, Data Doctors

Here’s how to calculate your bandwidth needs

When searching for an alternative internet service provider, here are some tips on how to know how much bandwidth is needed.

1 month ago

Sponsored Articles

...

DESERT INSTITUTE FOR SPINE CARE

Desert Institute for Spine Care is the place for weekend warriors to fix their back pain

Spring has sprung and nothing is better than March in Arizona. The temperatures are perfect and with the beautiful weather, Arizona has become a hotbed for hikers, runners, golfers, pickleball players and all types of weekend warriors.

...

COLLINS COMFORT MASTERS

Here are 5 things Arizona residents need to know about their HVAC system

It's warming back up in the Valley, which means it's time to think about your air conditioning system's preparedness for summer.

...

DISC Desert Institute for Spine Care

Sciatica pain is treatable but surgery may be required

Sciatica pain is one of the most common ailments a person can face, and if not taken seriously, it could become one of the most harmful.

How can I protect my router from the attack the FBI is warning about?