PDA

View Full Version : [VU+ Duo] Have I been hacked.



BobbyC
03-07-14, 22:33
Hey folks, I telnet into my box last after reading the default password on the box is blank. I set a password using a randomly generated string from lastpass,

I was able to cd through the directories, log in and out, everything was working fine.

Today I went to FTP some downloaded video files into /media/hdd/movie as I have done countless time over the last year and half since ive had the box. I wasnt able to acccess the directory, afaik root isnt allowed FTP on linux ??

anyway cut long story short, I can not log back into my duo via telnet or ssh, Im getting authentication error, its like I had an intruder and they changed the root password when they saw I had set one up. Then about 4 pm today, my entire /media/hdd/movie and sub directories with nearly 200gb of files were deleted, and my settings and image backups were deleted.

Sounds like I had an intruder with access to the box, frighting, I just hope they haven't been able to island hop on my network, I have quite a few devices on the network, windows and linux, all up to date tho.

Any thoughts, is a clean reflash the only way I can reset the root password, Id like to get into the box before wiping to investigate any logs

judge
03-07-14, 22:42
Then about 4 pm today, my entire /media/hdd/movie and sub directories with nearly 200gb of files were deleted, and my settings and image backups were deleted.

Are you sure they were deleted & not just the HDD losing its mount point?
Any plugins installed such as TSPanel that might interfere with mounts?
Original box or clone?

BobbyC
03-07-14, 22:46
Are you sure they were deleted & not just the HDD losing its mount point?
Any plugins installed such as TSPanel that might interfere with mounts?
Original box or clone?Hey,

Original box, cccam 2.3 is the only plugin installed. Nothing wrong with the mount, my hdd is showing its 94% free space, I can see the trash, thats it, it was at about 40% free yesterday :(

judge
03-07-14, 22:49
Can you take a screenshot of your Mount Manager screen & post it here?
Blue button -> ViX -> Mount Manager.

BobbyC
03-07-14, 22:53
Can you take a screenshot of your Mount Manager screen & post it here?
Blue button -> ViX -> Mount Manager.

http://imgur.com/6S4xLnX

Thanks for your time btw :)

judge
03-07-14, 23:03
Mounts look fine.
Can you take another screenshot of your movie button press? better to upload screen shots here rather than an external site.
Use the Go Advanced button, bottom right of the post area.

Have you any ports open on your router/modem that could be used externally?

BobbyC
04-07-14, 07:18
No mate, never port forwarded, never had the need.

35701

StuBFrost
04-07-14, 08:23
I occasionally get an issue with the box not letting me log onto it. A quick power off and back on again usually fixes it.

BobbyC
04-07-14, 08:25
Of course, Ive tried that :)

BobbyC
05-07-14, 10:02
as I thought...35715

zappahey
05-07-14, 11:05
That doesn't necessarily mean you've been hacked, you get that message the first time you use winscp to connect to a server.

Sent from my Nexus 7 using Tapatalk

BobbyC
05-07-14, 11:14
I know that, wasn't my first time using winscp.