DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Draytek 2925 hacked

  • davsands
  • Topic Author
  • Offline
  • New Member
  • New Member
More
16 May 2018 14:45 #1 by davsands
Draytek 2925 hacked was created by davsands
I just wanted to post in here to ask people to check their DNS settings in their routers. One of our businesses uses a 2925 and found it on Friday (11/05/2018) had incorrect DNS server listed!

I Googled the IP address and reported it to this site on Monday. I looked back today and it's filling quickly with people with Drayteks!

https://www.abuseipdb.com/check/38.134.121.95

We were running v3.8.4 firmware, now I've updated it to v3.8.8. I've also disabled ALL remote management! We have more routers in a good number for home-based staff, we're about to start to manually check them but I do not want to have to turn off remote management, they are home-based staff after all!

Please Log in or Create an account to join the conversation.

More
16 May 2018 17:00 #2 by admin
Replied by admin on topic Re: Draytek 2925 hacked
It may be a remote management issue - possibly your user left it at default password (even for a moment - everythings constantly being scanned)
or it might be a LAN-side CSRF:

https://www.draytek.co.uk/support/guides/kb-avoiding-csrf-attacks



Forum Administrator

Please Log in or Create an account to join the conversation.

  • silverstreak_2006
  • User
  • User
More
16 May 2018 22:47 #3 by silverstreak_2006
Replied by silverstreak_2006 on topic Re: Draytek 2925 hacked
As Admin says, I use a 2925, and have no issues at all in that manner.

Please Log in or Create an account to join the conversation.

  • bookit
  • User
  • User
More
17 May 2018 07:59 #4 by bookit
Replied by bookit on topic Re: Draytek 2925 hacked
Perhaps DrayTek could add configuration change to Notification Object?

Please Log in or Create an account to join the conversation.

  • davsands
  • Topic Author
  • Offline
  • New Member
  • New Member
More
17 May 2018 11:29 #5 by davsands
Replied by davsands on topic Re: Draytek 2925 hacked

admin wrote: It may be a remote management issue - possibly your user left it at default password (even for a moment - everythings constantly being scanned)
or it might be a LAN-side CSRF:

https://www.draytek.co.uk/support/guides/kb-avoiding-csrf-attacks



The password was quite long and was only changed back in Feb.

Please Log in or Create an account to join the conversation.

More
17 May 2018 11:32 #6 by leegee333
Replied by leegee333 on topic Re: Draytek 2925 hacked
This is more widespread than it would seem see https://www.abuseipdb.com/check/38.134.121.95?page=2#report

I doubt this is down to a remote admin issue.

Please Log in or Create an account to join the conversation.