DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Was my router hacked ?

  • uklad
  • Topic Author
  • User
  • User
More
06 Nov 2017 12:34 #1 by uklad
Was my router hacked ? was created by uklad
I was just checking my router config today and happen to click on the Remote Dial-in and noticed a VPN connection that i had not created, i can not figure out where this has come from or how long its been there the user name was "hema" i have since deleted it and removed the remote admin settings has anyone seen this before ?

Firmware is 3.8.4.6_BT but was previously on 3.8.4.4 this was my last backup

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
06 Nov 2017 12:59 #2 by hornbyp
Replied by hornbyp on topic Re: Was my router hacked ?
I agree you are right to be concerned :cry:

I would do an integrity check of any connected PCs ... e.g. offline virus scans. Maybe change credentials for important sites like Internet Banking - possibly every password, if you've got the stamina.

The issue is, that you don't know what (if anything) this inbound connection has been used for.

Please Log in or Create an account to join the conversation.

  • uklad
  • Topic Author
  • User
  • User
More
06 Nov 2017 15:21 #3 by uklad
Replied by uklad on topic Re: Was my router hacked ?
I have setup a syslog server and going to see if it comes back or any wan based login attempts, im also going to load my last config backup to see if it was there then

Please Log in or Create an account to join the conversation.

More
07 Nov 2017 03:18 #4 by admin
Replied by admin on topic Re: Was my router hacked ?
You should also change your admin password. Perhaps you enabled remote access to the router and left it on default password. Even if that was for one day, hackers are always scanning...



Forum Administrator

Please Log in or Create an account to join the conversation.

  • uklad
  • Topic Author
  • User
  • User
More
11 Nov 2017 13:21 #5 by uklad
Replied by uklad on topic Re: Was my router hacked ?
Well the VPN came back :( i had the sys logs this time..

Looks like it was brute forced on 443 SSL login, i can see lots of unsuccessful login attempts, then soon as they get in, a connection was made from another address where a VPN called Hema was created within seconds so i suspect this is automated and targeted to this type of router, when the VPN connection was made from an IP in the Palestinian Area then this started hammering DNS servers with request and then many web SSL connections :(

So router password change remote admin locked and brute force protection on..

Any one care to take a look at the syslog database ?

Please Log in or Create an account to join the conversation.

  • uklad
  • Topic Author
  • User
  • User
More
11 Nov 2017 14:01 #6 by uklad
Replied by uklad on topic Re: Was my router hacked ?

admin wrote: You should also change your admin password. Perhaps you enabled remote access to the router and left it on default password. Even if that was for one day, hackers are always scanning...



Defo not defaulted

Please Log in or Create an account to join the conversation.