DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

DNS Attacks - Criticial Firmware Due (puzzled?)

  • osldraytek
  • Topic Author
  • User
  • User
More
10 Jul 2018 15:12 #1 by osldraytek
We have a 3220 series and our router was compromised during the latest DNS attack described here:
https://www.draytek.co.uk/support/security-advisories/kb-advisory-csrf-and-dns-dhcp-web-attacks

However we do have the latest firmware 3.8.8.2 already installed which was supposed to fix this!

I guess its not fixed!!

Please Log in or Create an account to join the conversation.

  • anaglypta
  • User
  • User
More
10 Jul 2018 17:59 #2 by anaglypta

Please Log in or Create an account to join the conversation.

  • macavity
  • User
  • User
More
11 Jul 2018 12:02 #3 by macavity
Is it possible the DNS was changed prior to the firmware being updated?

Please Log in or Create an account to join the conversation.

More
11 Jul 2018 12:44 #4 by admin
Yes, likely changed before the update and not spotted.... but what IP addres wa ther DNS changed to ?



Forum Administrator

Please Log in or Create an account to join the conversation.

  • osldraytek
  • Topic Author
  • User
  • User
More
11 Jul 2018 13:09 #5 by osldraytek
Thanks for the replies

the DNS was changed to: 38.134.121.95

Strangely we have just checked and the firmware 3.8.8.2 was released on the 18th May 2018. However we have not upgraded the firmware on this router for some time

Could it be possible that our Draytek is reporting the wrong firmware version?

screenshot of our current system information below

Please Log in or Create an account to join the conversation.

  • admin2
  • Site Admin
  • Site Admin
More
11 Jul 2018 13:35 #6 by admin2
It seem pretty unlikely, web browser caches can sometimes cause confusion. If you want to double-check then you could look at the firmware version via the CLI using the command 'sys ver'

If you click the Web Console (it's an icon in the top right that looks a bit like an abacus) then you type type the cmd sys ver.

Please Log in or Create an account to join the conversation.