• Unfortunately, we have experienced significant hard drive damage that requires urgent maintenance and rebuilding. The forum will be a state of read only until we install our new drives and rebuild all the configurations needed. Please follow our Facebook page for updates, we will be back up shortly! (The forum could go offline at any given time due to the nature of the failed drives whilst awaiting the upgrades.) When you see an Incapsula error, you know we are in the process of migration.

Very impurrtant linksys /tplink routers!

CATMAGEDDON
Loyal Member
Joined
Aug 17, 2014
Messages
1,669
Reaction score
294
theres a damn thingie named The Moon
it infects ROUTERS and makes them donwload an ELF file
redirect connections to 5.104.175.150 8.8.8.8 port 80 and consumes tons of bandwidth
also spams popups in browsers(i have firefox and IE 11)
ANTIVIRUS AND ANTISPYWARE DONT DETECT IT SINCE IT INFECTS ROUTER NOT THE PC

to fix...for now:
reset to factory settings
upgrade firmware
enabled router firewall
change router admin pass
closed remote control(why the fk is that active on routers?)
must be like this in tplink
ACL
Activated Secure IP Address 0.0.0.0 interface LAN
DNS Relay use discovered only

on Linksys go to administration/remote management and disable it
and setup a trusted DNS (DONT USE THE GOOGLE ONES)


for now its working but i need some help from any of you to stop this little thing to spread
and more data about that ip adress its from bulgaria
linksys already "patched" this but thou said theres a botnet involved
i was infected for 1 entire day now i think im clean :glare: but im still not sure
 
Pessimistic butt@%&!
Loyal Member
Joined
Jan 18, 2008
Messages
2,057
Reaction score
487
It only affects these models of routers.

E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000, E900, E300, WAG320N, WAP300N, WAP610N, WES610N, WET610N, WRT610N, WRT600N, WRT400N, WRT320N, WRT160N and WRT150N.
 
Back
Top