cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

FBI warns people to reboot your router due to Russian malware

14 REPLIES 14

FBI warns people to reboot your router due to Russian malware

That's why I am not making sales on Ebay - It's the Russians! open_mouth

Message 2 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

Actually, the Russians are the only people buying from me.  

Message 3 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

Another source of info - Consumer Reports

 

https://www.consumerreports.org/wireless-routers/why-you-need-to-reboot-a-router/

 

Because the Russians just haven't got the time to spend with us on a personal basis.

"Fly the Big Ones"
Message 4 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

Honestly, I think if I hear the words Russians or Russia

one more time I'm going to barf, LOL.:smileyvery-happy:

I feel like we're back in the Cold War days.

The next thing you know we'll be doing the air raid drills

under the desks in schools again !

Message 5 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

I remember them, Duck and Cover!

 

Think about that, though, if nuclear war broke out, I doubt hiding under  your desk and covering your head is going to help!

Message 6 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

NEVER EVER use Russian salad dressing.  Ebay will know and act accordingly.  I live in very rural America.  My internet goes down a couple of times a day.  I found that rebooting the router has no effect on getting anything up and running.  The internet resumes when the internet resumes.   

Message 7 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

According to South Park, duck and cover is the response to volcanoes.

https://www.youtube.com/watch?v=v6prK716ssM
Message 8 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

>>rebooting the router has no effect on getting anything up and running.

Maybe not for your rural internet issues, but router reboots are a valid fix for some issues. Routers are little microcomputers mostly running Linux, and they crash and burn like any other system. Some, like my old Linksys WRT54GL tended to get confused after months of heavy use and required a reboot.


As far as the OP router reboot warning goes: everyone should probably do it just to be sure to flush any lurking in memory instance of the VPNFilter stage 2 malware. The odds of anybody having that infestation are low, but a reboot takes only a minute.

The reboot works by flushing any VPNFilter stage 2 infestation from the router memory. If the router is infected with the persistent stage 1 infestation, after reboot that code will try to contact the main server that the FBI sinkholed to locate a server to download the actual malicious stage 2 code again. That tells the FBI who is infected, so they can notify ISPs, who can then notify the users who, then need to do a full factory reset to eliminate the stage 1 infection.

Because the FBI sinkholed that Russian server, which was the backup method the malware uses to obtain the stage 2 malware, and I assume, also took out the Photobucket image primary method of obtaining an IP address for a server to download stage 2 from, a VPNFilter stage 1 infected router can no longer obtain the actual stage 2 malicious code UNLESS contacted by the blackhats directly (which is probably unlikely unless router belongs to a juicy target)

So rebooting the router flushes any stage 2 or stage 3 infection, but does not actually remove the stage 1 infection. That requires a factory reset or flashing with new firmware. However, unless method 3 is used (direct contact by miscreants), a stage 1 infected router presumably can't do anything but futilely try to download stage 2 and fail doing so.

At this point it appears to be only a limited, small set of router models that could be infected, but as that is uncertain, doing the reboot is worth taking a minute or two. And disabling remote admin, And changing the router password.

https://arstechnica.com/information-technology/2018/05/fbi-tells-router-users-to-reboot-now-to-kill-...
Message 9 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

I reboot my router regularly and check for upgrades at least monthly. Rebooting works wonders if you have lots of devices connected. My desktop is directly connected, but we have two phones, five tablets, one laptop and three Rokus connected wirelessly.  It really helps, especially when you already have slow DSL like we do. (2.3 mbps on a good day going downhill with the wind at our back)

The easier you are to offend the easier you are to control.


We seem to be getting closer and closer to a situation where nobody is responsible for what they did but we are all responsible for what somebody else did. - Thomas Sowell
Message 10 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

Lots of devices mean lots of connections. Routers suffer from something akin to memory leaks keeping track of those connections, the built in NAT firewall doing its thing, DHCP server issuing IPs on the local network as devices connect, etc - a reboot flushes everything and starts fresh.

Flashing the router with something like DD-WRT firmware (if possible for that router) might help. Aftermarket firmware often works better than the junk the manufacturers install. I used HyperWrt Thibor 15c on my old Linksys for a decade (before it died) and got away with sometimes 4-6 months of operation with 3 desktops, 2 laptops, and a half dozen phones and tablets without issues. Using DD-WRT on a newer Linksys/Cisco that seems to be working as well as HyperWRT did.
Message 11 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

But I love that Russian dressing!
Message 12 of 15
latest reply

FBI warns people to reboot your router due to Russian malware

NSA and the FBI/CIA must have done something stupid on the Hillary Servers and so now the NY Times has to blame Russians on their software debacle.  The internet just gets weirder and weirder each day - but good thing we have Russians to blame for it all - DARN those Russians are Smart - surpassing all the the Asian cultures on Spying and Software hacks.

Message 13 of 15
latest reply

FBI warns people to reboot your router due to Russian malware


@berserkerplanet wrote:
Flashing the router with something like DD-WRT firmware (if possible for that router) might help. Aftermarket firmware often works better than the junk the manufacturers install. I used HyperWrt Thibor 15c on my old Linksys for a decade (before it died) and got away with sometimes 4-6 months of operation with 3 desktops, 2 laptops, and a half dozen phones and tablets without issues. Using DD-WRT on a newer Linksys/Cisco that seems to be working as well as HyperWRT did.

Yes, OEM firmware typically is terribly limited.  I myself run routers on Gargoyle, and the ability to run it is what determines my choice when I upgrade.

 

PS.  My router automatically reboots every day at 5 am.

Message 14 of 15
latest reply

FBI warns people to reboot your router due to Russian malware


@ittybitnot wrote:

NEVER EVER use Russian salad dressing.  Ebay will know and act accordingly.  I live in very rural America.  My internet goes down a couple of times a day.  I found that rebooting the router has no effect on getting anything up and running.  The internet resumes when the internet resumes.   


No worries.  I don't eat salad thus no salad dressing involved, LOL.

Message 15 of 15
latest reply