Superb quality and spec AB-Com PULSe 4K SE. Crazy offer! Only £129! FREE UK DELIVERY! 4K UHD, Enigma 2, Multiboot 4 images & more!...
Superb quality and spec AB-Com PULSe 4K Rev II Twin Satellite tuner only £179! FREE UK DELIVERY! 4K UHD, Enigma 2, SATA HDD facility, Multiboot 4 images & more!...

Menus remotely accessed

  • Thread starter Thread starter magichew
  • Start date Start date
M

magichew

Guest
My Vu Duo 2 Box seemed to have menus accessed remotely this morning. Details are vague as it was my wife relaying the information but the Menu moved on screen by itself. Anyone else seen this? Apparently it rebooted, the on screen headed to Transponder settings and rebooted again. Not sure if anything else was accessed as I say my wife gave me the details.

The box is on the network with a public IP to access recordings and such remotely. I find it strange that if someone was trying to tinker with my settings remotely they wouldn't just use WEBIF and change the settings there.

Anyone seen this before?
 
The box is on the network with a public IP to access recordings and such remotely.
Well, that's the reason then. And you're not the first one who experiences this.
But let's be honest: do you also leave your kitchen door open day and night? And if you do, would you really be surprised to find a stranger in your home?
So in this case would you be surprised to find your device being part of an IPTV-network? Or worse: a stranger logging into the shell of your box and entering all your network-devices? And using the banking-account services of your PC for his personal benefit?

We've warned against this over and over again: never open any device to the outside world. At least not without using SSH or VPN.
 
Thanks for the reply. I do understand that perils of opening a device up to the world but I do have VPN set up but I've found that it doesn't always reconnect at after coming out of standby or after a reboot even though the setting to restart is on. This must be the case this time.
 
You are lucky the hacker didn't delete all your recordings.
Also when you have mounted devices (like a NAS) , they also can delete files on the mounted devices.
 
I asked the wife to turn it off and I'll have to take a look when I'm at home. Is there any way to force VPN to run on start up other than the menu option as it seems unreliable.
 
Is there anyway to implement basic auth on the webif interface? Having to implement VPN/proxy server solution is overkill for me as everything else on my network (NAS, router, web apps on my NAS, etc) can be accessed through basic auth or in-app auth.
 
I've often wondered that about WEBIF. Just type the address and then BOOM. Full access.
 
Nope. Bear in mind that E2 has never been designed with safety in mind. A proper safety implementation would require E2 to be build from scratch.
But as long as you don't open any ports, and use either VPN or SSH you'll be fine.
 
Thanks for the reply. I do understand that perils of opening a device up to the world but I do have VPN set up but I've found that it doesn't always reconnect at after coming out of standby or after a reboot even though the setting to restart is on. This must be the case this time.
Do you mean you have VPN setup on the STB? If so, you see the result; VPN should really be active on your router.
 
Yes. I have it set up on the box. I don't have a VPN compatible router at the moment. This episode has made me look for one.
 
Yes. I'm looking at the DD-WRT firmware as we speak. Have to find a router suitable now. Thank you for your advice.
 
That thread is over 3 years old. And using user/pass for the WEB_IF isn't going to help you.

I appreciate your replies but could you tell me why the thread being 3 years old is a problem and why adding a user name and password to WEBIF won't help? I'm not being awkward, just want to know more.
 
Because since then we've learned that user/pass gives no (or hardly any) added value. And also since then a second 'security' has been added (authenticate HTTP-streams).

Only VPN or SSH will give you security.
 
I don't see how adding a password would not give any added value? Yes its not the most secure but I would have thought any scanners would be checking/testing for any systems that either had no password set or used the default password?

I would say the vast majority of users have not changed their passwords or even set one up. I would also think that the percentage of users who have even tried to setup a VPN is less than 0.001% Yes that small!

So I can't imagine that hackers are even going to bother trying to hack a box that does have a password setup?
 
It's completely up to you.
I mean: believe what you want to believe: it's your box, your network, your security and your bank account. If you're happy sleeper with the door ajar, it's fine with me.
But never say you haven't been warned about the risk of a break in.

But also remeber that your STB is a Linux PC, with root-access rights to every one who comes in. And from there your whole network can be reached.
 

OpenViX Feeds Status

Back
Top