HNS-DNS-HIJACK and HNS-WEAK-WIFI-PASSWORD

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract:

Detailed description:

Product & version number:

OS details:

What is the error message you are seeing?

If you have any supporting screenshots, please add them:

@Ashish_Jain Hello. Running a Smart Scan generally always results in issues that are not present. The fix is most times a sell-up to correct the issues reported. Given this is a wifi issue, here is my best advice going forward:

AI Overview

To check your Wi-Fi for evidence of hijacking, immediately review your router’s connected devices, check for altered DNS settings, and monitor for sudden data spikes. Signs of a compromised network include unauthorized devices on your client list, sluggish speeds, or being locked out of your admin panel. [1, 2, 3]

  1. Check for Unauthorized Devices

The most common way to check if your network is hijacked is by auditing who is using it. [1]

  • Via Router: Log in to your router’s administrative console (e.g., 192.168.1.1 or 192.168.0.1) using the credentials usually printed on the physical device or that you previously set. [1, 2]
  • Via Network Scanner: Download a network scanner app like Fing on your mobile device to get a clear list of all connected gadgets. [1]
  • Identify Unknowns: Look closely at the list of connected IP and MAC addresses. Disconnect all your known devices, and if you still see unfamiliar phones, smart TVs, or computers on your list, your network may be compromised. [1, 2]
  1. Inspect Router Settings

If someone has hijacked your actual router, they may have altered your core configurations. [1, 2]

  • Admin Login: If your normal username and password no longer work, an attacker may have logged in and locked you out by changing your credentials. [1]
  • DNS Settings: Hackers often change DNS addresses so your web traffic gets routed through malicious servers. Check your router’s WAN or DNS settings; if they are set manually to strange IPs instead of your ISP or trusted providers like Google (8.8.8.8) or Cloudflare (1.1.1.1), it is a red flag. [1, 2, 3, 4]
  • Remote Management: Ensure “Remote Management” or “Remote Administration” is disabled. If enabled, it allows attackers to change your router settings from outside your home. [1, 2, 3]
  1. Review Network Traffic & Browser Behavior
  • Traffic Spikes: If your data activity LEDs are wildly flickering when all your computers and phones are completely turned off or idle, an unauthorized device is likely using your bandwidth. [1]
  • Redirects & Pop-ups: If your browser frequently redirects you to strange websites or you are flooded with unexpected pop-ups on a clean device, your DNS or Wi-Fi gateway may have been intercepted. [1, 2, 3]

IF, you have not had any prior notifications that may suggest an infection, your internet speeds suddenly dropped for no reason the above suggestions are the first steps. Conversely here are a few things you can do right now:

  • IF you are using the factory default logins and passwords, immediately change those. IF, you cannot log into your router FACTORY RESET IT and start from scratch.
    - IF you have never set unique WiFi passwords and they are still factory defaults also change these.

SA