Home > Ask the Information Security Experts > Questions & Answers > How to prevent hackers from accessing your router security password
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

How to prevent hackers from accessing your router security password

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 November 2007
How do I change my router's password? What are best practices to protect against router security password compromise?

>
EXPERT RESPONSE
There are two basic rules for protecting router passwords: always change the default password that comes with the router out of the box and only log on to the router via a secure and encrypted connection.

Hackers not only know all the default passwords of routers commonly on the market, they also have posted these passwords on Web sites. If you don't think they try this as a first step to break into a router, then don't change the default password and see what happens.

Along with this, of course, use a strong password -- no dictionary words, at least eight characters long and mix of upper and lower case letters and numbers. Also, make sure to use different passwords on each system. If the same password is used throughout the network, and it's compromised, guess what? The whole network is now compromised.

As for an encrypted connection, only use protocols like SSH, which creates a secure connection with the router. Protocols and services like Telnet and TFTP are unencrypted, and therefore, weak. Routers are notorious for allowing the transmission of user IDs and passwords in clear text, which can be easily sniffed.

Cisco IOS, on the other hand, has two ways to encrypt passwords in the configuration file where they're stored on the router. Cisco can store passwords in the configuration file in one of three ways: clear text, Vignere encryption and the MD5 hash algorithm. Vignere is an encryption algorithm that is weaker than MD5, and unlike MD5, it's reversible, meaning it can be cracked.

There are three commands for encrypting passwords on Cisco routers: service password-encryption, enable password and enable secret. The first command uses Vignere encryption, while the other two use the MD5 hash. The enable secret command is a newer feature of Cisco routers and is stronger than enable password. The enable password command is only kept for backwards compatibility, while service password-encryption, though weak, is still needed for compatibility with some older network protocols.

These commands also allow passwords to be set and encrypted at different access level privileges, depending on the rights granted to staff by administrators.

Wherever possible, use the Cisco encryption commands to protect router passwords. There is extensive and detailed documentation on Cisco's Web site. If you're using another brand of router, stick with SSH or another encrypted connection.

For more information:

  • Network security expert Mike Chapple discusses if Snort can be configured with a FreeBSD router.
  • Learn if it is necessary for a router to be placed between an enterprise firewall and DMZ.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Endpoint Protection
    Network security basics: How to prevent common attacks
    Cybercrime reports: Security not broken, but breaking at the seams
    Screencast: How to gather host-level data with Network Miner
    Appliance provides network access protection on school campus
    Market Harborough Building Society finds way to monitor users' network traffic
    Key defense features of a firewall
    Local council finds better way to track lost laptops
    Marshal and 8e6 combine to control Web and mail communications
    Securing Windows services to prevent hacker attacks
    Client-server LAN security issues

    Password Security
    Windows password security: System tools and policy
    Identity management still eludes most companies
    Understanding multifactor authentication features in IAM suites
    Worst practices: Exposing IAM blunders
    John Lewis dumps RSA tokens for phones
    EU crypto project Suphice mired in red tape
    IBM releases simplified Tivoli Identity Manager
    Top 10 access-related controls for PCI compliance
    What is the best way to securely change the local administrator password in a domain?
    What type of protections should security question and answer authentication credentials have?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Centre for the Protection of National Infrastructure  (SearchSecurityUK.com)
    Computer Misuse Act 1990  (SearchSecurityUK.com)
    Regulation of Investigatory Powers Act  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts