Home > Ask the Information Security Experts > Questions & Answers > How to prevent hackers from accessing your router security password
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

How to prevent hackers from accessing your router security password

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 November 2007
How do I change my router's password? What are best practices to protect against router security password compromise?

>
There are two basic rules for protecting router passwords: always change the default password that comes with the router out of the box and only log on to the router via a secure and encrypted connection.

Hackers not only know all the default passwords of routers commonly on the market, they also have posted these passwords on Web sites. If you don't think they try this as a first step to break into a router, then don't change the default password and see what happens.

Along with this, of course, use a strong password -- no dictionary words, at least eight characters long and mix of upper and lower case letters and numbers. Also, make sure to use different passwords on each system. If the same password is used throughout the network, and it's compromised, guess what? The whole network is now compromised.

As for an encrypted connection, only use protocols like SSH, which creates a secure connection with the router. Protocols and services like Telnet and TFTP are unencrypted, and therefore, weak. Routers are notorious for allowing the transmission of user IDs and passwords in clear text, which can be easily sniffed.

Cisco IOS, on the other hand, has two ways to encrypt passwords in the configuration file where they're stored on the router. Cisco can store passwords in the configuration file in one of three ways: clear text, Vignere encryption and the MD5 hash algorithm. Vignere is an encryption algorithm that is weaker than MD5, and unlike MD5, it's reversible, meaning it can be cracked.

There are three commands for encrypting passwords on Cisco routers: service password-encryption, enable password and enable secret. The first command uses Vignere encryption, while the other two use the MD5 hash. The enable secret command is a newer feature of Cisco routers and is stronger than enable password. The enable password command is only kept for backwards compatibility, while service password-encryption, though weak, is still needed for compatibility with some older network protocols.

These commands also allow passwords to be set and encrypted at different access level privileges, depending on the rights granted to staff by administrators.

Wherever possible, use the Cisco encryption commands to protect router passwords. There is extensive and detailed documentation on Cisco's Web site. If you're using another brand of router, stick with SSH or another encrypted connection.

For more information:

  • Network security expert Mike Chapple discusses if Snort can be configured with a FreeBSD router.
  • Learn if it is necessary for a router to be placed between an enterprise firewall and DMZ.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Endpoint and NAC Protection
    Considering two-factor authentication? Do cost, risk analysis
    Look into SIEM services to cut costs, comply with PCI DSS, HIPAA
    Voice data security risks on the rise, say experts
    The value of booting from a VHD in Windows 7
    Thin-client technologies surge thanks to easier security, says Deloitte
    A closer look at Internet Explorer 8 security features
    USB drive security best practices and processes
    First step in forensics: Create a bootable Windows environment CD
    Protecting enterprise networks from new mobile application downloads
    Four things to remember about server virtualization security concerns

    User Password Security
    Microsoft, security firms warn of password meltdown
    Single sign-on system removes password chaos at East Kent NHS Trust
    Brute force attacks target Yahoo email accounts
    The consequences of poor Microsoft SharePoint security permissions policies
    Unpatched vulnerability discovered in Microsoft SQL Server
    Supplier's problems with passwords solved by single sign-on technology
    Social networks and spear phishing attacks
    How effective are password hack tools?
    How to protect employees' personal information and passwords
    Gartner: How to succeed at identity and access management

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Centre for the Protection of National Infrastructure  (SearchSecurityUK.com)
    Computer Misuse Act 1990  (SearchSecurityUK.com)
    Regulation of Investigatory Powers Act  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Access Management: Authentication, Biometrics, Password Security
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts