Author |
Message |
|
Post subject: RE: UBNT virus
Posted: 05.06.2016 - 21:13 #111183
|
|
Basic
Joined: Nov 11, 2009
Posts: 195
|
|
Tak viem si predstavit ze by to preliezlo aj cez nat v pohode. |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 05.06.2016 - 21:15 #111184
|
|
Basic
Joined: Jan 21, 2005
Posts: 180
Location: Bratislava
|
|
vo firewalli to uz blokujem a vidim tam divne spojenia z vonku kde port na strane sukromnej ip je 80, neviem ci je zvonka nadviazany alebo zvnutra |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 05.06.2016 - 22:55 #111185
|
|
Majster
Joined: Feb 14, 2011
Posts: 2544
|
|
dajte si pravidlo na drop IP: 78.24.191.177
a odlogujte si IP ktore sa pokusaju pripojit na tuto IP.
tie zariadenia su infikovne |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 05.06.2016 - 23:29 #111186
|
|
Basic
Joined: Apr 05, 2012
Posts: 22
|
|
To pravidlo som mal na firewale aj tak sa to nejako dostalo do siete. dufam za zatial nevypne zariadenia a len odmietne pristup. stihol som hlavne radia prehodit ale asi 10 to odnieslo. dokonca ked som sa do jedneho prihlasil a nahraval som novy firware tak ma to vykoplo a zmenilo pristupove hesla. takze bolo to v tom zariadeni akurat cerstvo. Budete skusat niekto to prelomit a nejako odstranit alebo bude len rucna práca z restartovaním ?
Dik za info. |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 05.06.2016 - 23:39 #111188
|
|
Basic
Joined: Apr 05, 2012
Posts: 22
|
|
Tak pozeram na trafic a vidim ze sa hodne zmensil. Takze virus odstavuje komunikáciu. |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 06.06.2016 - 08:16 #111189
|
|
Basic
Joined: Okt 21, 2007
Posts: 305
|
|
A robi vam to aj na zariadeniach s 5.6.5 a 5.6.6 ? |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 06.06.2016 - 21:23 #111193
|
|
Majster
Joined: Aug 31, 2005
Posts: 2295
Location: Hájske
|
|
Ahojte, tak ako to je postihuje to vsetky UBNT zariadenia alebo len radia? |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 07.06.2016 - 06:30 #111194
|
|
Basic
Joined: Apr 05, 2012
Posts: 22
|
|
Viem ze je to nevhodne ale ak ma niekto hesla do poslednej vlny alebo nejaky postup ako to nadialku opravit mozete to sem hodit ?
Dakujem vopred Gaspo. |
|
|
|
|
|
|
Post subject: RE: UBNT virus
Posted: 07.06.2016 - 08:05 #111195
|
|
Basic
Joined: Nov 11, 2009
Posts: 195
|
|
user wrote: ›Viem ze je to nevhodne ale ak ma niekto hesla do poslednej vlny alebo nejaky postup ako to nadialku opravit mozete to sem hodit ?
Dakujem vopred Gaspo.
Ten exploit si skusal co som posielal link??? |
|
|
|
|
|
|
Post subject: UBNT virus
Posted: 07.06.2016 - 14:01 #111199
|
|
Basic
Joined: Máj 25, 2003
Posts: 264
|
|
pokial funguje SSH
killall mother
killall search
killall infect
rm /etc/persistent/rc.poststart
rm /etc/persistent/mf.tar
rm -R /etc/persistent/.mf/
ln -s /dev/null /etc/persistent/.mf
cfgmtd -w -p /etc/
reboot |
|
|
|
|
|
|
Post subject: UBNT virus
Posted: 07.06.2016 - 14:12 #111200
|
|
Basic
Joined: Nov 11, 2009
Posts: 195
|
|
bob wrote: ›pokial funguje SSH
.
.
.
reboot
Ved vravi ze sa tam nevie dostat. |
|
|
|
|
|
|
Post subject: UBNT virus
Posted: 07.06.2016 - 17:16 #111201
|
|
Basic
Joined: Máj 25, 2003
Posts: 264
|
|
bob wrote: ›pokial funguje SSH
killall mother
killall search
killall infect
rm /etc/persistent/rc.poststart
rm /etc/persistent/mf.tar
rm -R /etc/persistent/.mf/
ln -s /dev/null /etc/persistent/.mf
cfgmtd -w -p /etc/
reboot
2 vlna meno/heslo:
moth3/fuck.3r |
|
|
|
|
|
|
Post subject: 5.6.4
Posted: 07.06.2016 - 17:20 #111202
|
|
Ucen
Joined: Aug 09, 2004
Posts: 753
|
|
Ked mam dajme tomu 5.6.4 a nemam virus, naco tam davat 5.6.5 a vyssie? |
|
|
|
|
|
|
Post subject: 5.6.4
Posted: 07.06.2016 - 17:35 #111203
|
|
Basic
Joined: Máj 25, 2003
Posts: 264
|
|
neos wrote: ›Ked mam dajme tomu 5.6.4 a nemam virus, naco tam davat 5.6.5 a vyssie?
aby si ho nedostal |
|
|
|
|
|
|
Post subject: 5.6.4
Posted: 07.06.2016 - 17:42 #111205
|
|
Ucen
Joined: Aug 09, 2004
Posts: 753
|
|
bob wrote: › neos wrote: ›Ked mam dajme tomu 5.6.4 a nemam virus, naco tam davat 5.6.5 a vyssie?
aby si ho nedostal
Tak ked od 5.6.2 vyssie nemaju dieru, ktorou sa da prihlasit bez znalosti hesla, tak ako ho mozem dostat? |
|
|
|
|
|
|
Powered by PNphpBB2 © 2003-2005 The PNphpBB Group Credits |