DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Draytek 2925 hacked

More
29 May 2018 20:21 #37 by irksome
Replied by irksome on topic Re: Draytek 2925 hacked
I've been rather busy over the last few days so am late to the conversation ... but tonight I found a 2760 running 3.5.x which had been compromised with no remote access services enabled - am I missing something - my understanding is that only devices with some sort of remote access have been compromised, but this one definitely did not have any remote access enabled (I had to access it via a local device)?

MTIA etc ...

Please Log in or Create an account to join the conversation.

  • davsands
  • Topic Author
  • Offline
  • New Member
  • New Member
More
29 May 2018 20:34 #38 by davsands
Replied by davsands on topic Re: Draytek 2925 hacked
Thats worrying but not too different to what we have heard already. Did you have SSL VPN active?

Please Log in or Create an account to join the conversation.

More
29 May 2018 21:01 #39 by admin
Replied by admin on topic Re: Draytek 2925 hacked
The Vigor 2760/62 shares the same codebase so would need updating - SSL being actually in use is not necessary.



Forum Administrator

Please Log in or Create an account to join the conversation.

More
29 May 2018 21:06 #40 by irksome
Replied by irksome on topic Re: Draytek 2925 hacked
SSL VPN not enabled.

Please Log in or Create an account to join the conversation.

More
29 May 2018 21:34 #41 by admin
Replied by admin on topic Re: Draytek 2925 hacked

Irksome wrote: SSL VPN not enabled.



Does it have a specific checkbox to disable?



Forum Administrator

Please Log in or Create an account to join the conversation.

More
29 May 2018 22:37 #42 by irksome
Replied by irksome on topic Re: Draytek 2925 hacked
No remote access to that device ... however I suspect somewhere in my portfolio of devices there will be similar device unpatched. I shall consult my records and gain access and report back.

Please Log in or Create an account to join the conversation.