DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Was my router hacked ?
- uklad
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank yous received: 0
06 Nov 2017 12:34 #89975
by uklad
Was my router hacked ? was created by uklad
I was just checking my router config today and happen to click on the Remote Dial-in and noticed a VPN connection that i had not created, i can not figure out where this has come from or how long its been there the user name was "hema" i have since deleted it and removed the remote admin settings has anyone seen this before ?
Firmware is 3.8.4.6_BT but was previously on 3.8.4.4 this was my last backup
Firmware is 3.8.4.6_BT but was previously on 3.8.4.4 this was my last backup
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank yous received: 0
06 Nov 2017 12:59 #89976
by hornbyp
Replied by hornbyp on topic Re: Was my router hacked ?
I agree you are right to be concerned
I would do an integrity check of any connected PCs ... e.g. offline virus scans. Maybe change credentials for important sites like Internet Banking - possibly every password, if you've got the stamina.
The issue is, that you don't know what (if anything) this inbound connection has been used for.
I would do an integrity check of any connected PCs ... e.g. offline
The issue is, that you don't know what (if anything) this inbound connection has been used for.
Please Log in or Create an account to join the conversation.
- uklad
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank yous received: 0
06 Nov 2017 15:21 #89979
by uklad
Replied by uklad on topic Re: Was my router hacked ?
I have setup a syslog server and going to see if it comes back or any wan based login attempts, im also going to load my last config backup to see if it was there then
Please Log in or Create an account to join the conversation.
- admin
- Offline
- Site Admin
Less
More
- Posts: 1723
- Thank yous received: 0
07 Nov 2017 03:18 #89988
by admin
Forum Administrator
Replied by admin on topic Re: Was my router hacked ?
You should also change your admin password. Perhaps you enabled remote access to the router and left it on default password. Even if that was for one day, hackers are always scanning...
Forum Administrator
Please Log in or Create an account to join the conversation.
- uklad
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank yous received: 0
11 Nov 2017 13:21 #90008
by uklad
Replied by uklad on topic Re: Was my router hacked ?
Well the VPN came back i had the sys logs this time..
Looks like it was brute forced on 443 SSL login, i can see lots of unsuccessful login attempts, then soon as they get in, a connection was made from another address where a VPN called Hema was created within seconds so i suspect this is automated and targeted to this type of router, when the VPN connection was made from an IP in the Palestinian Area then this started hammering DNS servers with request and then many web SSL connections
So router password change remote admin locked and brute force protection on..
Any one care to take a look at the syslog database ?
Looks like it was brute forced on 443 SSL login, i can see lots of unsuccessful login attempts, then soon as they get in, a connection was made from another address where a VPN called Hema was created within seconds so i suspect this is automated and targeted to this type of router, when the VPN connection was made from an IP in the Palestinian Area then this started hammering DNS servers with request and then many web SSL connections
So router password change remote admin locked and brute force protection on..
Any one care to take a look at the syslog database ?
Please Log in or Create an account to join the conversation.
- uklad
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank yous received: 0
11 Nov 2017 14:01 #90010
by uklad
Defo not defaulted
Replied by uklad on topic Re: Was my router hacked ?
You should also change your admin password. Perhaps you enabled remote access to the router and left it on default password. Even if that was for one day, hackers are always scanning...admin wrote:
Defo not defaulted
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek