DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Possible hacked Draytek??

  • pops1000uk
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
14 Mar 2018 15:59 #1 by pops1000uk
Possible hacked Draytek?? was created by pops1000uk
Hi all, Ive been having problem both at home and work with 2 draytek 2860 modems. When ever I access secure banking / payment sites, basicly my banking app on my mobile doesnt work i get errors my banking with a different bank on my computers hard wired get blocked and reffered to fraud and ordering my car insurance resulted in the payment being blocked due to fraud. I have no viruses, ive checked. I use MAV and done alsorts of scans on the phones and computers. Changing the draytek at work to a Ubiquiti Edge router resolved the issue. Now I seem to have the problem at home. There not connected via VPN or nothing. Doing a GRC firewall scan shows PORT 0 to be Closed not stealthed. ? Very strange problem. Ive just had to call my bank now and unlock my banking because they blocked it due to fraud or something. They cant tell me what it is tho.
Anyone else having this issue with Draytek 2860 routers?

Please Log in or Create an account to join the conversation.

More
15 Mar 2018 10:30 #2 by admin3
Replied by admin3 on topic Re: Possible hacked Draytek??
Please contact support, they will be able to help with determining what has happened.



Forum Administrator

Please Log in or Create an account to join the conversation.

More
19 Mar 2018 11:59 #3 by admin
Replied by admin on topic Re: Possible hacked Draytek??
I'm not sure support will be able to diagnose - there's not enough information there and I'm not sure much more would be available.

my banking app on my mobile doesnt work i get errors my banking with a different bank



I can't see why you think this is a 'hack' - it might be an incompatibility that's triggering some
alert/false positive with the bank. Can you borrow a different router for home ?

I have no viruses, ive checked



Well, that just means your current AV software can't detect any known issues...but this necessarily doesn't sound like a virus anyway.



Forum Administrator

Please Log in or Create an account to join the conversation.

More
30 Mar 2018 08:51 #4 by admin
Replied by admin on topic Re: Possible hacked Draytek??
n.b. checkyour router's DNS settings.

A possibility is that remote mngt was enabled with weak credentials (e.g. default or weak password). This could result in the DNS setting being changed on the router. There are bots which automate this. The first thing any router owner should do is change the default password - the router warns you this every time you log in.



Forum Administrator

Please Log in or Create an account to join the conversation.