D-Link Forums

The Graveyard - Products No Longer Supported => Routers / COVR => DIR-655 => Topic started by: nategrim on May 14, 2010, 12:12:01 PM

Title: DIR-655 compromised?
Post by: nategrim on May 14, 2010, 12:12:01 PM
Greetings,

I have been watching my logs and I am noticing that someone is trying to access the https on the router itself.  I have disabled this and set the rules to deny all connections from the internet for remote management of the router.  About 10 minutes later, the router was reset and https was enabled again.

After this happened, I looked at the logs.  They again started to access https.

I would appreciate any information.  Thank you for your time and patience.

Regards,

Nate
Title: Re: DIR-655 compromised?
Post by: EddieZ on May 15, 2010, 12:27:51 PM
Post some logs please.
Title: Re: DIR-655 compromised?
Post by: Sammydad1 on May 16, 2010, 12:19:54 AM
Hi,

Unplug your WAN connection and do a hard reset (or two) on the router.  Then re-do your settings by hand..do not re-use a saved file....

save all your settings and reboot as the router as instructed by the screen....

 DO change your admin password to something more complex and write it down.

DO set up your wireless encryption properly with WPA2 and AES !! And use a more complex wpa2 password.

Only once you are fully re-setup, should you reboot your ISP modem and reconnect it to your router.
Title: Re: DIR-655 compromised?
Post by: kthaddock on May 16, 2010, 12:29:19 AM
Use this password generator:
https://www.grc.com/passwords.htm (https://www.grc.com/passwords.htm)

choose 63 random printable ASCII characters:

good luck !
Title: Re: DIR-655 compromised?
Post by: nategrim on May 20, 2010, 10:28:08 PM
Greetings,

I have been watching my logs and I am noticing that someone is trying to access the https on the router itself.  I have disabled this and set the rules to deny all connections from the internet for remote management of the router.  About 10 minutes later, the router was reset and https was enabled again.

After this happened, I looked at the logs.  They again started to access https.

I would appreciate any information.  Thank you for your time and patience.

Regards,

Nate
Post some logs please.

Hi,

Unplug your WAN connection and do a hard reset (or two) on the router.  Then re-do your settings by hand..do not re-use a saved file....

save all your settings and reboot as the router as instructed by the screen....

 DO change your admin password to something more complex and write it down.

DO set up your wireless encryption properly with WPA2 and AES !! And use a more complex wpa2 password.

Only once you are fully re-setup, should you reboot your ISP modem and reconnect it to your router.

I apologize for no update.  It seems to have stop resetting itself and the changes finally committed.  It took a full reset and password change.  Thank you for your suggestions. I will be watching the logs to see if it continues when we have less traffic.  Right now they are getting filled with other things.

Thank you again.

Nate