What I Found Poking Around My Own Router After Friday

What I Found Poking Around My Own Router After Friday

Tutorials home network iot security mirai passwords router

So Friday happened. If you were trying to use Twitter, Netflix, Spotify, Reddit, or about a dozen other sites around midday and again in the evening and got nothing but spinners, that wasn't your wifi, it was Dyn (the DNS company a huge chunk of the internet quietly depends on) getting hammered by a distributed denial of service attack that by evening was being described as one of the biggest ever. I'm not going to walk through the whole timeline here, every tech site on earth already did that better than I could, with better sources than "a guy on his couch." What I want to write about is what happened after I read the one detail that actually stuck with me: a lot of the traffic hitting Dyn wasn't coming from hacked laptops. It was coming from things like DVRs and security cameras, ordinary internet-connected junk that got roped into a botnet because it shipped with a default username and password nobody ever bothered to change.

That detail bugged me all weekend, because I own some of that junk.

Sunday afternoon, instead of doing literally any of the things on my actual to-do list, I logged into my router's admin panel (192.168.1.1, if you've never had to look, though check the sticker on the bottom of the box if that doesn't work) and just started clicking around. First thing I found: the admin password was still whatever came printed on that same sticker. I've had this router for something like two and a half years. Two and a half years of "I'll get to that."

Then I remembered I've also got a cheap Foscam camera pointed at the garage, bought off Amazon for about forty bucks back when I had a brief and expensive idea about starting a woodworking hobby. Same story. Default login, port forwarded straight out to the internet because that's how the setup wizard told me to do it, and I never touched it again after the first ten minutes. That thing has been sitting there for over a year, reachable from anywhere, with credentials you could find in the manual PDF with about four seconds of googling. I don't even know for sure it wasn't already part of somebody's botnet before this weekend. There's no clean way to check that after the fact, which is its own kind of unsettling.

Anyway, here's roughly what I actually did, in case anyone else is having the same Sunday I did:

  • Logged into the router and changed the admin password to something long and stupid, not the wifi password, the actual admin login, which is a separate thing a shocking number of people don't realize exists.
  • Turned off remote/WAN administration on the router entirely. I don't need to log into my router from a coffee shop in another state. Nobody does, really.
  • Went into the Foscam app, found the change-password option buried two menus deeper than it should be, and set a real one.
  • Turned off UPnP on the router. This is the setting that lets devices on your network punch their own holes in your firewall without asking you first, which is convenient right up until it's the whole problem.
  • Went looking for anything else on the network I'd forgotten about. Found an ancient Slingbox in a closet that I'm fairly sure hasn't been powered on since 2013. Unplugged it out of spite more than security.

None of this took very long, maybe forty-five minutes total, and that's honestly the annoying part. It's not hard. It's just that nothing about setting these devices up nudges you toward doing it. The Foscam setup wizard walks you through port forwarding like it's the most natural thing in the world and never once suggests you might want a password that isn't printed on a sticker. That seems like the actual design failure here, not that some botnet operator found a list of default logins and used it. Of course they used it. It was sitting right there.

I don't think I'm going to notice any difference day to day from having done this. That's kind of the point, and also kind of the frustrating thing about security work in general, you do the work and the reward is that nothing happens. Still beats being one of the anonymous IP addresses in somebody's incident report.

Also, small unrelated note: Microsoft's got some kind of event tomorrow that's supposedly hardware-heavy. Guessing new Surface stuff. We'll see.