- 1 week ago
Secure home routers against hacking with these seven quick fixes. Protect your network from compromise and stop unauthorized access today.
Recent reports confirm that thousands of devices are vulnerable to outside interference. This tutorial is designed for anyone concerned about their internet safety who wants to lock down their home network settings without spending money on new hardware. I walk you through the specific steps to harden your device, ensuring you are not part of the next wave of compromises.
We focus on essential router security measures, including how to properly configure your WAN settings and why you must immediately disable WPS mode. You will also learn to implement WPA with integrity checks to add a necessary layer of encryption to your traffic. By performing these router configuration adjustments, you significantly reduce the chance of your device being targeted by malicious units.
⚠️ Visual source note:
This video may include a mix of original footage, custom visuals, stock media, public-domain material, and occasional brief third-party visual clips used only to support original commentary, instruction, and educational storytelling. All narration, editing, music, and overall presentation are original to this channel.
Recent reports confirm that thousands of devices are vulnerable to outside interference. This tutorial is designed for anyone concerned about their internet safety who wants to lock down their home network settings without spending money on new hardware. I walk you through the specific steps to harden your device, ensuring you are not part of the next wave of compromises.
We focus on essential router security measures, including how to properly configure your WAN settings and why you must immediately disable WPS mode. You will also learn to implement WPA with integrity checks to add a necessary layer of encryption to your traffic. By performing these router configuration adjustments, you significantly reduce the chance of your device being targeted by malicious units.
⚠️ Visual source note:
This video may include a mix of original footage, custom visuals, stock media, public-domain material, and occasional brief third-party visual clips used only to support original commentary, instruction, and educational storytelling. All narration, editing, music, and overall presentation are original to this channel.
Category
🤖
TechTranscript
00:0018,000 home routers, hijacked quietly over the last two years by the same Russian military unit,
00:05and the FBI says most of them are still sitting in kitchens and living rooms right now,
00:09owners totally unaware. Today I'm going to show you how to make your own router essentially
00:13unhackable with seven fixes that cost nothing. Take under a minute each and permanently close
00:18the exact doors they walked through. One of those fixes is a single toggle. The FBI and NSA told
00:24everyone to flip after they reset thousands of infected devices in April. Once you see what it
00:29does, you'll wonder why it's been on this whole time. And I've had my entire network locked down
00:34this way for two years. After what happened to a friend last month, I'm never going back.
00:38My buddy lives 20 minutes away. Normal house, normal internet. Pays his bill on time, he called me three
00:42weeks ago. Because his bank login started redirecting to a page that looked exactly right, but the URL
00:48was off by one letter. He hadn't clicked anything weird. No phishing email, no weird download,
00:53no neighbor guessing his Wi-Fi password. What happened is his router itself got hijacked without
00:58anyone ever joining his Wi-Fi at all. A bot scanning the internet found his public IP, tried admin
01:04and admin and got in because he'd never changed the factory login, slipped in through remote management
01:09that his provider left open, and silently rewrote his DNS settings to point to a server overseas.
01:15From that second on every site, he typed. His bank, his email, even Google could be quietly rerouted
01:21through a perfect fake copy that skimmed whatever he typed, and he had no clue for almost a month. That
01:25is not a freak story.
01:27In April, the FBI and NSA published an advisory that a GRU unit called Fancy Bear, also called Forest
01:34Blizzard and APT28, had been doing exactly this to small office and home routers across 23 U.S. states
01:40since at least 2024. Microsoft counted more than 5,000 consumer devices caught in it. CISA had warned
01:47manufacturers in January 2024 to fix this by design, and the devices they actually named weren't fancy
01:53enterprise boxes. They were old TP links like the WR841N from 2007, the Archer C7, the WR740N, 23 models,
02:04and the UK advisory alone. The kind people buy once, shove in a closet, and never touch again.
02:10E, Set, and Kaspersky both flag the same pattern. Routers run for years untouched, which is why attackers
02:15love them. They sit between every device you own and the internet, so one win gives them everything.
02:19You don't need to buy anything to fix this, and you definitely don't need some $9.99 a month
02:24security subscription that can't even see a router level hijack. I'm giving you seven specific changes
02:29in the exact order I'd do them tonight, if this were my house. Halfway through, I'll show you a 30
02:33second check that tells you if you're already DNS hijacked or if someone left a back door port forward
02:38in your settings. I'll also take apart three myths that make people feel safe while leaving the front door
02:43wide open. And the extra habit the NSA says actually wipes these memory-only implants out,
02:48even the nation-state ones. And once we get through the first one, you'll understand why his strong
02:53wi-fi password didn't help him at all. First, kill the factory credentials, because that sticker on the
02:58bottom of your router is not a password, it's a public invitation. Every model ships with something
03:04like admin and admin or admin and password printed right there, and there are searchable databases of
03:09every default combo ever made. A bot doesn't sit in a car cracking your wi-fi, it just hammers admin
03:14slash admin against millions of public ips per hour for free. And when you leave it, you've handed them
03:19a key to the whole house from anywhere on the planet. Open your browser, type 192.168.1.1 or
03:26192.168.0.1.
03:31It's on that same sticker, log in, and immediately change the admin username. If it lets you and the admin
03:36password to something long and random, you store in your password manager, not your head. This is
03:42not the wi-fi password, it's the router admin password, two different things. And while you're
03:47there, change your network name to something boring that doesn't scream your model. So not
03:51tp-link-841n, or bell-home, hub-500, or rogers-5, g-8472, just call it house-5 or something
04:02generic.
04:04Broadcasting your exact model tells an attacker which exploit to try first. My friend's router
04:08still said admin slash admin after six years, which alone was enough to let them in from another
04:14continent without ever being near his house. That one change would have stopped his entire incident
04:20cold. Second, fix your firmware, or throw the router out. And I mean that literally. Manufacturers
04:26release firmware updates to patch holes they find, and if you never install them, you're running with the
04:31whole open on purpose. The FBI went a step further in 2025, and said if your router no longer receives
04:38updates, retire it, don't keep using it, because those end-of-life devices were exactly what got
04:44swept into the KAV botnet, built from dead small office routers, and the Raptor train botnet of more
04:50than 200,000 routers and cameras that got disrupted in September 2024. Go to the manufacturer's support page,
04:57type your exact model, compare the latest firmware date to what's shown in your admin panel under
05:03system or administration or firmware update, and if the last update was more than two or three years
05:09ago, or the page says end of life, end of service, end of support, that router is done. No setting
05:15will
05:15save it. Keeping it is like triple locking your windows while the foundation is cracked. If it does
05:21still get updates, turn on automatic firmware updates. Most decent routers now hide it under administration or
05:26system, and if it doesn't have that toggle, put a reminder in your calendar for every three months
05:31to check manually. It takes 60 seconds. A solid mesh system that actually gets automatic updates is about
05:38$175. Once and lasts five years. The median identity theft lost the FTC tracks when banking credentials
05:47leak is over $1,300 plus weeks on the phone, and professional cleanup after a DNS skim bills
05:54$2 to $400 per incident, so this free check saves you more than seven times the cost of a replacement
06:00before you even buy one. My friend's TP-Link hadn't been updated since 2020. Four years of known holes
06:07sitting open. Third, turned WPS off completely. Not just the button, the whole thing. Because this is the
06:14myth that feels safest and is the weakest. WPS was supposed to be convenient. Press a button or type an
06:21eight-digit PIN and connect without typing a long password. Cute idea. Except the PIN is not eight
06:27real digits. The last digit is a checksum, so there are only about 11,000 real guesses. And a $20
06:34tool can
06:35brute force it in two to six hours while sitting outside in a parked car. And here's the catch that
06:40burns people. Pressing the button doesn't disable the PIN. The PIN stays listening in the background,
06:46even if you never use it. Forever, silently answering. In your settings, look for WPS, or
06:52Wi-Fi Protected Setup, sometimes under Wireless Advanced, and switch it to Off or Disabled on both
06:57bands if you have 2.4 and 5GHz. There is no downside unless you actually use that button daily, which
07:04almost nobody does. You type the password once per device and you're done forever. I had mine on for a
07:10year thinking the button was harmless. Same trap. Turning it off closes a door that was designed
07:16to be easy to open. If you're still with me here that tells me you actually care if your network
07:21is
07:21leaking right now, so tap subscribe. It's free, and it helps this channel keep making these breakdowns.
07:27And if you want the extended live tests where I tear this stuff down step by step, the membership
07:31gives you those members-only videos. And back to it, the next one is the toggle that let that Russian
07:37DNS hijack spread to thousands of houses without cracking a single Wi-Fi password. And it's probably
07:43on in your house right now. Fourth, disable two features you almost certainly don't need, and one
07:49acronym most people have never heard of. UPNP, Universal Plug and Play, lets devices inside your
07:55network automatically open ports to the outside without asking you. Sounds helpful for a game console
08:01until you realize any compromised light bulb or phone app can also punch a hole straight through your
08:06firewall and keep it open. And your router will never tell you. Security folks have been saying
08:11to turn it off for years because reducing the surface attackers can touch Beats convenience every
08:16time. Find it under advanced or NAT or forwarding and switch it to disabled. Next is remote management,
08:23sometimes called remote access or web access from WAN or remote administration. This lets you log into
08:30your router from the internet, not just from your couch, which is exactly how that bot reached my friend from
08:36overseas without ever joining his Wi-Fi. It logged in over his public IP on port 8080 or 443 and
08:43rewrote
08:43his settings. Unless you actually managed your parents router from another city every week, you don't need
08:48it. So go to administration or system or remote management and switch it to disabled or allow local
08:53access only. While you're there, if you see TR-069 or CWMP or a remote config from provider, leave it
09:02enabled only
09:02if your ISP requires it for updates. Otherwise, disable it. And also turn off respond to ping on WAN.
09:10That just makes your router loudly announce, I'm here, scan me to every bot on the internet.
09:15Quieter is safer. You might be thinking my router is new, so I'm fine, but that's exactly the
09:21misunderstanding that makes newer mesh owners ignore this. My friend's router wasn't ancient because it
09:26was cheap. It was ancient because nobody told him a router ages like milk, not like a fridge.
09:31Fifth, lock your actual Wi-Fi encryption the right way, because this is where the second and third
09:36myths get expensive. A lot of people think a 10 character clever password and hiding the network
09:41name makes them invisible. Hiding your SSID does not hide you at all. Your phones and laptops shout
09:47that hidden name everywhere they go, constantly probing, are you there, hidden network? So you're
09:52actually broadcasting it more. And any laptop with free software sees it in two seconds. It's theater
09:57that makes you harder to find for your own family and easier to track for everyone else. Same with
10:02MAC address filtering, which sounds strict until you remember a MAC address is broadcast in plain text
10:07with every single packet. You can sniff it and spoof it in 30 seconds. It stops zero attackers and
10:13creates busy work where you have to manually approve every new bulb while thinking you're secure.
10:17What actually works is WPA3, if your router offers it, otherwise WPA2AES explicitly, not WPA slash WPA,
10:28to mixed mode, and definitely not TKIP. TKIP has been broken for years, and mixed mode keeps it alive
10:35for compatibility. Make your Wi-Fi passphrase at least 20 characters, random words with a number tucked in,
10:41like Correct Lantern Bicycle 24 River. Easy to type once, brutally hard to crack, even if someone
10:47captures your four-way handshake outside your window. And if you see a toggle for protected
10:51management frames, PMF, set it to capable or required, that stops the deauth attack where they
10:57kick you off for a half second to capture that handshake in the first place. My friend's Wi-Fi
11:01password was actually decent, 12 characters, mixed case, didn't matter, they never needed it. Which
11:07tells you why the admin login and this encryption choice matter more than cleverness. Look, I know
11:12this sounds like a lot, but three of these take 10 seconds each and you never touch them again?
11:16That's the trade. Sixth, lock your DNS and split your network so one cheap gadget can't sink the
11:22whole house. DNS is the phone book that turns google.com into an IP address, and when my friend's
11:28router got hijacked, the attacker just rewrote that phone book. He typed his bank's real name, the router
11:33lied, and sent him to a perfect clone at an IP overseas that harvested his login. The URL bar
11:39looked almost right, because the lie happened before his browser even left the house. Antivirus
11:44on his laptop never saw it, because antivirus watches the laptop, not the router lying underneath
11:49it, which is why $100 a year for a suite that can't see a router. Level hijack is money you
11:54don't
11:55need to spend. Go to internet, or WAN, or DHCP settings. Find DNS. Change it from automatic to manual,
12:02set primary to 1.1.1.1 and secondary to 1.0.0.1 or 8.8.8.8 and
12:118.8.4.4. Those are Cloudflare and Google.
12:16Both support DNS over HTTPS, which encrypts the lookup so your ISP and any eavesdropper can't
12:23silently rewrite it, save, and if your router offers DNS over HTTPS or DNS over TLS, turn that on too.
12:34Then, in that same admin panel, create a separate guest network, and if you have it,
12:38a separate IoT network. Put the cheap smart plugs, cameras, bulbs, even the kid's tablet on that
12:45isolated guest. Not your main network where your laptops and phones live. Isolation, sometimes
12:51called V-L-A-N, or wireless isolation, or AP isolation, means if that $15 bulb from the big
12:59box store gets hijacked, it can talk to the internet, but not sideways to your computer to steal files.
13:04This costs nothing, takes two minutes, and it fire breaks the exact lateral movement those botnets rely
13:10on to turn one. Weak bulb into a whole house foothold. The last one is the dumbest and the most
13:16powerful,
13:16and almost nobody does it, even though it's the one the NSA actually wrote down. Seventh,
13:21reboot your router every week and audit what it let in. This sounds too simple to matter,
13:26which is why it's so effective. Most of these implants, including the ones Fancy Bear and Volt
13:30Typhoon dropped into those 23 states, live only in memory, they don't survive a reboot, they have to
13:36reinfect, and if you've already closed the doors with the first six fixes, they can't get back in
13:41after you kick them out. The NSA guidance after that. April takedown literally said, reboot your
13:47router, your smartphone, and your computer. At least once a week, regular reboots help remove implants
13:53and ensure security. Just pull the power for 60 seconds and plug it back in. 60 seconds, that's it.
13:59While it comes back up, make it a two-minute habit to open the admin panel and check two things.
14:04First, connect to devices. Look for names or MAC addresses that you don't recognize. A generic
14:10android dash, one F4B, or a vendor you don't own is a red flag. Geasset's own checklist says unknown
14:17devices is one of the strongest signs you've been had. Second, port forwarding or virtual server,
14:23or NAT rules. There should be zero entries. Unless you personally created them for game server,
14:29any rule you didn't create is a spare key someone added to let themselves back in delete it.
14:34If your router has an outbound firewall log or access control or system log,
14:38glance at what tried to phone home at 3am when everyone was asleep,
14:42steady blinking when every device is off, or a warm router at idle is the clue,
14:46both Kaspersky and ESET flag as infection chatter. You're not looking for perfection,
14:51you're looking for the thing that never sleeps. Here's the 30-second test I promised to tell if
14:56you're already compromised before you change anything else. Log in, find the status page, confirm your admin
15:01password still works. If it suddenly doesn't, and nobody in the house changed it, you've been locked
15:06out. Compare the DNS numbers on that page to what you just set, or to 1.1.1.1 and
15:128.8.8.8. If there are
15:16random numbers pointing somewhere you didn't choose, that's hijack. Scroll to port forwarding,
15:21if you see any IP you don't recognize, that's someone's back door. Screenshot it, then do a proper
15:27factory reset with the pinhole button for 10 seconds, update firmware before you reconnect
15:31to the internet, and then change every password that matters in this order. Router admin, Wi-Fi,
15:36ISP portal, email, bank. Do it wired if you can, not over Wi-Fi, while you're still hijacked.
15:43Let's actually do the money because free fixes sound cheap until you price the alternative. A decent
15:48replacement that actually gets automatic updates is about $175 once, and lasts five years. That's $35 a
15:55year. A year of a big brand security suite that still can't see a router-level DNS hijack is about
16:02$100 a year, $500 over that same period. Professional cleanup after a DNS skim, or ransomware scare bills,
16:09$200 to $400 per incident. And the median identity theft loss when banking credentials leak is over $1,000
16:16plus weeks of calls, and my friend lost two days on the phone and had to replace his cards. So
16:22those
16:22seven toggles that cost $0 and maybe 10 minutes total save you roughly $600 in subscriptions you
16:27don't need, plus the one-time $1,000 plus hit you never take. If you do need to replace an
16:33end-of-life
16:33box, that $175 still saves you the $1,000 plus. It's not close. Go do this tonight. In order. Admin,
16:40login, firmware, WPS off, UPnP, and remote management off, WPA3 or WPA2, A-E-I-S with a 20-character
16:50phrase,
16:50and PMF on, DNS locked, and guest network split, then weekly reboot, and device audit. I've run
16:56this exact stack for two years since I watched my friend unwind his. It's boring. It's quiet. It
17:01just works. And that's the point. Thanks for watching. If this locked your network down a notch,
17:07share it with someone still running admin slash admin and hit, like, and I'll see you in the next one.
Comments