Superb quality and spec AB-Com PULSe 4K SE. Crazy offer! Only £129! FREE UK DELIVERY! 4K UHD, Enigma 2, Multiboot 4 images & more!...
Superb quality and spec AB-Com PULSe 4K Rev II Twin Satellite tuner only £179! FREE UK DELIVERY! 4K UHD, Enigma 2, SATA HDD facility, Multiboot 4 images & more!...

[VU+ Ultimo] Tuner in use permanently even when in standby

Then it shouldn't be possible for me to access the box using the password from the original firmware but for some reason I can and I can also access it with the one that I have changed too. :confused:

Can anyone else try this on a gigablue and confirm if they can get access with two different passwords?
 
Last edited by a moderator:
I'm seeing problems accessing my own box via openwebif. I can telnet into the box using the root password I've set but openwebif is saying the password is incorrect. I thought the root password was used in openwebif too?
Is anyone else seeing this?
Gary
 
Gary I'm not seeing that. The default password doesn't allow me access to openwebif, so basically it works as it should on my end. Only the new password works on openwebif and flashxp as it should. So it works but how did they get my new password then?
 
A simple password provides no security at all. Especially HTTP-ports are under constant 'surveillance'.
And remember: once in a box, they're in your complete network.
You have any info on your lappy/PC/NAS/whatever you don't want strangers to have a look at (a bank account maybe :) ) ?
If so: never forward a port with only HTTP/Password.
 
A simple password provides no security at all. Especially HTTP-ports are under constant 'surveillance'.
And remember: once in a box, they're in your complete network.
You have any info on your lappy/PC/NAS/whatever you don't want strangers to have a look at (a bank account maybe :) ) ?
If so: never forward a port with only HTTP/Password.

So what your saying Rob is transcoding feature is a security risk? As the plugin uses http port 8002 .
If this is the case is there a secure option
 
No: transcoding is no risk at all. Forwarding a (any) port to a (any) device in your network is however accepting a severe security risk. Hence I'll never do that.
Although I'm far from an expert in this area, I would only use port-forwarding when using VPN. As far as I know that should be secure. And most mobile devices support that nowadays.
But maybe HttPS is also secure enough?
Anyway: don't ask me how to set it up :p The only thing I know is that I'll never ever use port-forwarding for HTTP/Password.
 
Hi guys,

I'm no expert either but obviously when you open any ports via http to the net then you are leaving yourself open to an attack, regardless of how obscure your specified port number is. These hackers run a port scan against your IP address to check what ports are opened and access your internal network from there.

If you are unsure what ports etc. you have opened then there are websites that can run a port scan etc. against your IP address to assess how secure your network is. ShieldsUp is one that I used a long time back, I'm sure there are better ones too but it does the job.

But as Rob says, at least go down the https route if you are going to open ports..

Cheers,
mcquaim
 
Hi guys,

Upgraded to zeus last week and this morning I turned on my duo to find that Tuner A has been occupied. Someone has been watching my tv again.

I ran the netstat command and the ip address I got was: 91.121.218.83:34698.

I then ran an ip-address.com search and found out that ip address is located in Belgium.

Now I think Ill have to go for the vpn server way to stop this happening (as Rob and mcquaim said).

Just thought Id point out that its happened again, so be aware. p.s: I changed my password via telnet shortly after zeus flash.
 
Hi guys,

Upgraded to zeus last week and this morning I turned on my duo to find that Tuner A has been occupied. Someone has been watching my tv again.

I ran the netstat command and the ip address I got was: 91.121.218.83:34698.

I then ran an ip-address.com search and found out that ip address is located in Belgium.

Now I think Ill have to go for the vpn server way to stop this happening (as Rob and mcquaim said).

Just thought Id point out that its happened again, so be aware. p.s: I changed my password via telnet shortly after zeus flash.

what about your router password etc ?.

once there in, its best to do a full clear out, just changing a password is often not enough.
 
Hi guys,

Upgraded to zeus last week and this morning I turned on my duo to find that Tuner A has been occupied. Someone has been watching my tv again.

I ran the netstat command and the ip address I got was: 91.121.218.83:34698.

I then ran an ip-address.com search and found out that ip address is located in Belgium.

Now I think Ill have to go for the vpn server way to stop this happening (as Rob and mcquaim said).

Just thought Id point out that its happened again, so be aware. p.s: I changed my password via telnet shortly after zeus flash.

As far as I'm aware, having a strong password will only help prevent people getting into your OpenWebIf interface. So that's port 80 covered. However, ports 8001 & 8002 don't require authentication to watch the stream, so someone from Belgium just needed to figure out a channel ID e.g. the serviceref, and append it to your public ip.

E.g.
Code:
 http:// yourpublicIP: 8001 / 1:0:19:F17:7F7:2:11A0000:0:0:0:

Did the full netstat command show that the stream was going out on port 8001?
 
what about your router password etc ?.

once there in, its best to do a full clear out, just changing a password is often not enough.

Yep I changed that again just to be on the safe side.
 
As far as I'm aware, having a strong password will only help prevent people getting into your OpenWebIf interface. So that's port 80 covered. However, ports 8001 & 8002 don't require authentication to watch the stream, so someone from Belgium just needed to figure out a channel ID e.g. the serviceref, and append it to your public ip.

E.g.
Code:
 http:// yourpublicIP: 8001 / 1:0:19:F17:7F7:2:11A0000:0:0:0:

Did the full netstat command show that the stream was going out on port 8001?

Ohhh right, that's really interesting actually. I think you might be right because last time it happened the guy was watching the same channel sky action.

Yes the netstat showed the ip under 8001. But then again that's the streaming port, so if anyone streams they're always going to use port 8001.
 
Exactly.

So my point is that the 'remote viewer' isn't necessarily someone who has hacked into your box or router. Could be just some kid that knows how to construct a URL...
 
Another question: When in deep standby, Vu+Ultimo also shuts the loop through antenna signal in internal DBV-T and DBV-T/T2 modules. I suppose it does it for the DVB-S signal, too. This can't be correct. Why so?
 
Another question: When in deep standby, Vu+Ultimo also shuts the loop through antenna signal in internal DBV-T and DBV-T/T2 modules. I suppose it does it for the DVB-S signal, too. This can't be correct. Why so?
Please ask about other issues in an other (your own?) thread.
 

OpenViX Feeds Status

Back
Top