Superb quality and spec AB-Com PULSe 4K SE. Crazy offer! Only £99! FREE UK DELIVERY! 4K UHD, Enigma 2, Multiboot 4 images & more!...
Superb quality and spec AB-Com PULSe 4K Rev II Twin Satellite tuner only £149! FREE UK DELIVERY! 4K UHD, Enigma 2, SATA HDD facility, Multiboot 4 images & more!...

[VU+ Duo] Sorry feeds are down for maintenance, please try again later!!

  • Thread starter Thread starter sherry
  • Start date Start date
Oh damn!! Today after just 2 days after the fix via ftp DUO A showed again the "feed are down..." message.
And you know what?
I Used FTP to check /usr/bin and there's no trace of wget at all!!! Yes neither -wget is there.

This is the content of /usr/bin
Code:
[
[[
alsamixer
ar
awk
basename
bdpoll
bunzip2
bzcat
chage
cheetah
cheetah-analyze
cheetah-compile
chfn
chfn.shadow
chrt
chsh
chsh.shadow
chvt
clear
cmp
crontab
cut
dbclient
dbus-cleanup-sockets
dbus-daemon
dbus-monitor
dbus-send
dbus-uuidgen
dc
deallocvt
diff
dirname
dlist_test
dos2unix
du
eject
enigma2
enigma2.sh
env
ether-wake
event_rpcgen.py
expiry
expr
faillog
fgconsole
find
flock
free
fuser
get_device
get_driver
get_module
gpasswd
grab
groups
groups.shadow
gst-feedback
gst-feedback-0.10
gst-inspect
gst-inspect-0.10
gst-launch
gst-launch-0.10
gst-typefind
gst-typefind-0.10
gst-xmlinspect
gst-xmlinspect-0.10
gst-xmllaunch
gst-xmllaunch-0.10
head
hotplug_e2_helper
id
kbd_mode
killall
last
last.sysvinit
lastb
lastlog
less
logger
logname
lspci
lsusb
manhole
md5sum
mesg
mesg.sysvinit
mkfifo
nc
newgrp
newgrp.shadow
nmap
nmeter
nohup
nslookup
ntpdate
od
openssl
openvt
opkg
opkg-cl
opkg-key
passwd
passwd.shadow
patch
pcap-config
pgrep
pilconvert.py
pildriver.py
pilfile.py
pilfont.py
pilprint.py
printf
pyhtmlizer
python
python-config
python2.7
python2.7-config
readlink
realpath
renice
reset
run-parts
scp
sdparm
seq
setkeycodes
setsid
sg
sha1sum
sha256sum
sha512sum
showiframe
showkey
smemcap
sort
ssh
strings
su
systool
tail
tap2deb
tap2rpm
tapconvert
taskset
tee
telnet
test
time
timeout
top
tr
traceroute
traceroute6
trial
tty
turnoff_power
twistd
uniq
unix2dos
unxz
unzip
update-alternatives
uptime
users
utmpdump
volname
wall
wall.sysvinit
watch
wc
wg
which
who
whoami
whois
wpa_passphrase
xargs
xml2-config
xmlcatalog
xmllint
xzcat
yes

as you can notice now wget is renamed to wg (between wc and which)
 
Last edited:
Oh damn!! Today after just 2 days after the fix via ftp DUO A showed again the "feed are down..." message.
And you know what?
I Used FTP to check /usr/bin and there's no trace of wget at all!!! Yes neither -wget is there.

This is the content of /usr/bin
Code:
[
[[
alsamixer
ar
awk
basename
bdpoll
bunzip2
bzcat
chage
cheetah
cheetah-analyze
cheetah-compile
chfn
chfn.shadow
chrt
chsh
chsh.shadow
chvt
clear
cmp
crontab
cut
dbclient
dbus-cleanup-sockets
dbus-daemon
dbus-monitor
dbus-send
dbus-uuidgen
dc
deallocvt
diff
dirname
dlist_test
dos2unix
du
eject
enigma2
enigma2.sh
env
ether-wake
event_rpcgen.py
expiry
expr
faillog
fgconsole
find
flock
free
fuser
get_device
get_driver
get_module
gpasswd
grab
groups
groups.shadow
gst-feedback
gst-feedback-0.10
gst-inspect
gst-inspect-0.10
gst-launch
gst-launch-0.10
gst-typefind
gst-typefind-0.10
gst-xmlinspect
gst-xmlinspect-0.10
gst-xmllaunch
gst-xmllaunch-0.10
head
hotplug_e2_helper
id
kbd_mode
killall
last
last.sysvinit
lastb
lastlog
less
logger
logname
lspci
lsusb
manhole
md5sum
mesg
mesg.sysvinit
mkfifo
nc
newgrp
newgrp.shadow
nmap
nmeter
nohup
nslookup
ntpdate
od
openssl
openvt
opkg
opkg-cl
opkg-key
passwd
passwd.shadow
patch
pcap-config
pgrep
pilconvert.py
pildriver.py
pilfile.py
pilfont.py
pilprint.py
printf
pyhtmlizer
python
python-config
python2.7
python2.7-config
readlink
realpath
renice
reset
run-parts
scp
sdparm
seq
setkeycodes
setsid
sg
sha1sum
sha256sum
sha512sum
showiframe
showkey
smemcap
sort
ssh
strings
su
systool
tail
tap2deb
tap2rpm
tapconvert
taskset
tee
telnet
test
time
timeout
top
tr
traceroute
traceroute6
trial
tty
turnoff_power
twistd
uniq
unix2dos
unxz
unzip
update-alternatives
uptime
users
utmpdump
volname
wall
wall.sysvinit
watch
wc
wg
which
who
whoami
whois
wpa_passphrase
xargs
xml2-config
xmlcatalog
xmllint
xzcat
yes

as you can notice now wget is renamed to wg (between wc and which)

ok then something is messing with system files.
 
hi andy
some more feedback:
1- once again tried to rename wg back to wget.
At that point since a new update is on air I tried to perform the onair update via config menu, but got the error that a system process was ongoing...

2-This morning before starting from scratch by reflashing I wanted to try via Telnet to perform the update but the receiver refused me the access with this message:
Code:
Connection closed by foreign host.


*************** SESSION CLOSED **************

3- before flashing I went back to receiver to write down the error message reported at the above point 1. You know what, the receiver is updating itself without errors...
 
Have a look at
Code:
http://vierko.org/tech/lightaidra-0x2012/

Very interesting read rob, just goes to show why people should always enable authentication protocols on any Internet connected device and especially not to use default passwords or login details.


Sent from my iPad using Tapatalk HD
 
Have a look at
Code:
http://vierko.org/tech/lightaidra-0x2012/
Ok, and this should be interesting for DUO issue?
I mean, how should I check if my device is infected?
Assuming that I'm infected, I'm wondering why only 1 DUO is actually affected.

Second thing I'm using an Adsl router, all the devices in the LAN (computers and STBs) have static IPs.
The port for FTP, telent and web access are customized. Isn't this enough?
 
Last edited:
Robs, thank to your discovery I checked thoroughly my router forwarding rules and discovered that had one duplicated rule forwarding the plain 23 port to the wget affected DUO.
Fixed it.

Now. (forgive my poor linux knowledge in advance, I may be writing bullshit now on...) Since I'm only able to ftp and telent is refused, is there a way to access the "configuration" where the telnet password is stored and edit that file?

****************
I've to admit that I'm guilty since till this discovery I never thought about customizing telnet password. And so I'm wondering: if I customize that once performing a restore of the backed up setting the custom telnet password will be retained?
****************
 
Robs, thank to your discovery I checked thoroughly my router forwarding rules and discovered that had one duplicated rule forwarding the plain 23 port to the wget affected DUO.
Fixed it.

Now. (forgive my poor linux knowledge in advance, I may be writing bullshit now on...) Since I'm only able to ftp and telent is refused, is there a way to access the "configuration" where the telnet password is stored and edit that file?

****************
I've to admit that I'm guilty since till this discovery I never thought about customizing telnet password. And so I'm wondering: if I customize that once performing a restore of the backed up setting the custom telnet password will be retained?
****************


yes, login to telnet and type.


passwd root

and type in your new password, this wil be for both FTP and Telnet.
 
yes, login to telnet and type.


passwd root

and type in your new password, this wil be for both FTP and Telnet.
Actually, if your read back my post I was asking something else. Anyway never mind about that.

********************
I'd like to inform you that yesterday night I've reflashed the DUO-A (wget affected) and fixed all the firewall rules to block port 23 forwarding to it. I've customized the root password. And now on I'll let you know how it'll behave.
 
Ok, have a look in your /usr/bin, you may find the wget has been renamed to -wget. Rename it back to wget and all should be back to normal :) I have no idea why/how this rename occurs though. Thanks Google you have saved me many a reflash :p

It does seem to go back to -wget every now and then though, just FTP back in and rename again. 10 second job. I'm happy with that until the devs manage to identify the issue.

Great Find Star Wolf!!! :thumbsup:
I have been having the ''Sorry feeds are down for maintenance, please try again later'' issue crop up regularly and always resorted to a USB flash to update.
Thanks to your bit of advice, I find my own wget file is renamed at random intervals to ~wget...
a quick rename of the file and online update works a treat!
Thanks again!
 
Great Find Star Wolf!!! :thumbsup:
I have been having the ''Sorry feeds are down for maintenance, please try again later'' issue crop up regularly and always resorted to a USB flash to update.
Thanks to your bit of advice, I find my own wget file is renamed at random intervals to ~wget...
a quick rename of the file and online update works a treat!
Thanks again!

I'd be thanking Rob & getting your network in order rather than renaming a binary...
 
Great Find Star Wolf!!! :thumbsup:
I have been having the ''Sorry feeds are down for maintenance, please try again later'' issue crop up regularly and always resorted to a USB flash to update.
Thanks to your bit of advice, I find my own wget file is renamed at random intervals to ~wget...
a quick rename of the file and online update works a treat!
Thanks again!

Did you read post 44 in this thread ??.


http://www.world-of-satellite.com/s...-again-later!!&p=210902&viewfull=1#post210902
 
I'd be thanking Rob & getting your network in order rather than renaming a binary...


From reading the post Rob linked and checking out the suggested binary/files along with having fairly good firewall settings,(I hope....Nothing connected is ever 100% secure of course) prior to renaming the binary in question and still having the issue randomly crop up even after reflashing, I used Starred wolfs suggestion and it allowed me an online update.
But I will go through my network settings/firewall and also recheck \var and \etc for any of the obvious anamolies
 
From reading the post Rob linked and checking out the suggested binary/files along with having fairly good firewall settings,(I hope....Nothing connected is ever 100% secure of course) prior to renaming the binary in question and still having the issue randomly crop up even after reflashing, I used Starred wolfs suggestion and it allowed me an online update.
But I will go through my network settings/firewall and also recheck \var and \etc for any of the obvious anamolies
Pretty sure that if your box still suffers from the 'wget-renaming-'issue you have an 'aidra' infected device in your network.
Be aware it is aimed at devices running embedded Linux, so most routers and many STB's will be a target.
Or can you think of any other reason for your files to be spontaneous renamed?
 
So to be clear if I reboot my Duo it will remove any evidence of Aidra from that machine?
In my case I'm guessing my router is the issue though (running DD-WRT). Would my router being infected cause issues on my Duo?
 
So to be clear if I reboot my Duo it will remove any evidence of Aidra from that machine?
If you reflash I would say yes, because the flash will be completely erased.
Only worry might be a connected storage device.
In my case I'm guessing my router is the issue though (running DD-WRT). Would my router being infected cause issues on my Duo?
I presume so, but I'm far from an expert in this area. Anyway: make sure not to forward any port and to personalise the routers password.
 
OK reset router to default and set new password. Also reflashed duo and set new root password and telnet is now working. Will see how my wget issue goes...

Sent from my MID using Tapatalk HD
 

OpenViX Feeds Status

Back
Top