• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

I have unautorised acces to my router/modem. i need help fast please !

Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Hi,

I live in morocco my ISP is "Maroc Telecom" (incase its important). and i have a fiber to home connection (100 Mb/s down 50 Mb/s up).
I have a Huawei HG8245H. (from my ISP).

Yesterday i had some internet problems (slowdowns and desconnects). so i went to my router config and changed some stuff (no problems here).

then i went to user logs, and then ohhh boy. there was a spam of connection attempts (like one every 3 min or so, until router block them for too much password errors. then they come back later). some even got the good password (WTF!)
FYI : the only password i can change is the root (i did change it some time ago). but there is an other one its like an ISP password or something (probably used in case you call them for a problem). but this one i can't change (at least i can't find where to change it). and its the same for all ISP clients that have this router (the login is "telecomadmin" very hard indeed lol)

plus my IP changes every time i restart my router. so i have no idea how this is possible (they must have somthing sending back the new ip)?

i tried to desable all web / telnet acces from WAN or WIFI (only local network should have acces). but in logs it says the acces was via CLI (command line interface ?).

Screenshot_2021-02-20 HG8245H(1).png

moreover and this is what worrying me the most. is that the one who got acces seem to have changed my DNS or somthing (so i guss i can be rederected to a fake paypal or somthing like that) (but in my PC i changed DNS to google / openDNS so i guss im ok but not any one that uses the router DNS ?)

Screenshot_1.png


so is there something i can do to stop this (any way to get even higher previlige to see maybe more settings to block this, because basic settings seem to have no effect) ?
i rather not have to change my router or contact my ISP (they are bad, and im sure 100% the help service poeple will not understand the problem (I speak knowingly))

PS: attached are the log files. (all connections from this ip "192.168.100.114" are mine (PC local IP).

thanks for your time.
 

Attachments

  • HG8245H.txt
    64.7 KB · Views: 446
Joined
Oct 17, 2012
Messages
9,781 (2.18/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
if possible disable Web management, or Web access. that way the only way to manage the router is from the LAN/WAN
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
if possible disable Web management, or Web access. that way the only way to manage the router is from the LAN/WAN

WAN Service
Enable the WAN-Side PC to Access the ONT Through FTP:
Enable the WAN-Side PC to Access the ONT Through HTTP:
Enable the WAN-Side PC to Access the ONT Through Telnet:
Enable the WAN-Side PC to Access the ONT Through SSH

are all desabled, plus in the logs it says acces using CLI
 
Joined
Oct 15, 2011
Messages
2,568 (0.53/day)
Location
Springfield, Vermont
System Name KHR-1
Processor Ryzen 9 5900X
Motherboard ASRock B550 PG Velocita (UEFI-BIOS P3.40)
Memory 32 GB G.Skill RipJawsV F4-3200C16D-32GVR
Video Card(s) Sparkle Titan Arc A770 16 GB
Storage Western Digital Black SN850 1 TB NVMe SSD
Display(s) Alienware AW3423DWF OLED-ASRock PG27Q15R2A (backup)
Case Corsair 275R
Audio Device(s) Technics SA-EX140 receiver with Polk VT60 speakers
Power Supply eVGA Supernova G3 750W
Mouse Logitech G Pro (Hero)
Software Windows 11 Pro x64 23H2
Is that a router-and-ONT-all-in-one?! If true, I dislike that setup. (not directed at you)
 
Joined
Oct 17, 2012
Messages
9,781 (2.18/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
are all desabled, plus in the logs it says acces using CLI
look through all options & tabs & see if there is another setting for web or remote management.
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Is that a router-and-ONT-all-in-one?! If true, I dislike that setup. (not directed at you)
YES all in one

like this one


sorry for the shitty picture.

yeah i know its bad but they dont give you a choice when you get a subscription. so im stuck with this.
 
Joined
Oct 15, 2011
Messages
2,568 (0.53/day)
Location
Springfield, Vermont
System Name KHR-1
Processor Ryzen 9 5900X
Motherboard ASRock B550 PG Velocita (UEFI-BIOS P3.40)
Memory 32 GB G.Skill RipJawsV F4-3200C16D-32GVR
Video Card(s) Sparkle Titan Arc A770 16 GB
Storage Western Digital Black SN850 1 TB NVMe SSD
Display(s) Alienware AW3423DWF OLED-ASRock PG27Q15R2A (backup)
Case Corsair 275R
Audio Device(s) Technics SA-EX140 receiver with Polk VT60 speakers
Power Supply eVGA Supernova G3 750W
Mouse Logitech G Pro (Hero)
Software Windows 11 Pro x64 23H2
YES all in one

like this one


sorry for the shitty picture.

yeah i know its bad but they dont give you a choice when you get a subscription. so im stuck with this.
Well, I like it when I can unplug the separate router for troubleshooting.
 
Joined
Sep 28, 2005
Messages
3,403 (0.48/day)
Location
Canada
System Name PCGR
Processor 12400f
Motherboard Asus ROG STRIX B660-I
Cooling Stock Intel Cooler
Memory 2x16GB DDR5 5600 Corsair
Video Card(s) Dell RTX 3080
Storage 1x 512GB Mmoment PCIe 3 NVME 1x 2TB Corsair S70
Display(s) LG 32" 1440p
Case Phanteks Evolve itx
Audio Device(s) Onboard
Power Supply 750W Cooler Master sfx
Software Windows 11
very curious about this myself.

I am not really strong in the network field so I will stay limited.

But can you adjust your DNS? Change it to google's or something. As well, also mentioned about web remote access, see if you can disable any kind of telnet or remote accessing within the router itself. You can also try to hide your WiFi signal as well, at least with most routers. I am not sure with yours. If it does have the option, try that.
 
Joined
Oct 17, 2012
Messages
9,781 (2.18/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
look through all options & tabs & see if there is another setting for web or remote management.
i only found this two, but they seem desabled

Screenshot_2021-02-20 HG8245H.png


Screenshot_2021-02-20 HG8245H(1).png


Hmm... Huawai, Xi Jinping knocking on your door.
exactly what i was thinking. maybe it some integrated spy system from the factory :tin foil hat:
 

OneMoar

There is Always Moar
Joined
Apr 9, 2010
Messages
8,802 (1.63/day)
Location
Rochester area
System Name RPC MK2.5
Processor Ryzen 5800x
Motherboard Gigabyte Aorus Pro V2
Cooling Thermalright Phantom Spirit SE
Memory CL16 BL2K16G36C16U4RL 3600 1:1 micron e-die
Video Card(s) GIGABYTE RTX 3070 Ti GAMING OC
Storage Nextorage NE1N 2TB ADATA SX8200PRO NVME 512GB, Intel 545s 500GBSSD, ADATA SU800 SSD, 3TB Spinner
Display(s) LG Ultra Gear 32 1440p 165hz Dell 1440p 75hz
Case Phanteks P300 /w 300A front panel conversion
Audio Device(s) onboard
Power Supply SeaSonic Focus+ Platinum 750W
Mouse Kone burst Pro
Keyboard SteelSeries Apex 7
Software Windows 11 +startisallback
Last edited:
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
change the password for telecomadmin
how ? i can't find anywhere to change it

Screenshot_2021-02-20 HG8245H(2).png


can't change it its stuck in root (but im connected using telecomadmin)
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
18,072 (2.45/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
thanks i will look into this

Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
Screenshot_2021-02-20 HG8245H.png


desabled it, will see if it changes anything
 
Joined
Aug 20, 2007
Messages
21,688 (3.40/day)
Location
Olympia, WA
System Name Pioneer
Processor Ryzen 9 9950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon, Phanteks and Corsair Maglev blower fans...
Memory 64GB (2x 32GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage Intel 5800X Optane 800GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64 / Windows 11 Enterprise IoT 2024
Hmm... Huawai, Xi Jinping knocking on your door.
Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.
 

OneMoar

There is Always Moar
Joined
Apr 9, 2010
Messages
8,802 (1.63/day)
Location
Rochester area
System Name RPC MK2.5
Processor Ryzen 5800x
Motherboard Gigabyte Aorus Pro V2
Cooling Thermalright Phantom Spirit SE
Memory CL16 BL2K16G36C16U4RL 3600 1:1 micron e-die
Video Card(s) GIGABYTE RTX 3070 Ti GAMING OC
Storage Nextorage NE1N 2TB ADATA SX8200PRO NVME 512GB, Intel 545s 500GBSSD, ADATA SU800 SSD, 3TB Spinner
Display(s) LG Ultra Gear 32 1440p 165hz Dell 1440p 75hz
Case Phanteks P300 /w 300A front panel conversion
Audio Device(s) onboard
Power Supply SeaSonic Focus+ Platinum 750W
Mouse Kone burst Pro
Keyboard SteelSeries Apex 7
Software Windows 11 +startisallback
the ip address the access is coming from is a static ip owned by digital ocean there is also a unconfigured apache server running on p80
 
Joined
Mar 20, 2019
Messages
556 (0.26/day)
Processor 9600k
Motherboard MSI Z390I Gaming EDGE AC
Cooling Scythe Mugen 5
Memory 32GB of G.Skill Ripjaws V 3600MHz CL16
Video Card(s) MSI 3080 Ventus OC
Storage 2x Intel 660p 1TB
Display(s) Acer CG437KP
Case Streacom BC1 mini
Audio Device(s) Topping MX3
Power Supply Corsair RM750
Mouse R.A.T. DWS
Keyboard HAVIT KB487L / AKKO 3098 / Logitech G19
VR HMD HTC Vive
Benchmark Scores What's a "benchmark"?
Well, you seem to have some botnets calling your horrible, horrible ONT with a list of default login/passwords left unchanged by many horrible, horrible ISPs. Change ACS password to something ridiculous, disable telnet for WAN if you can. Use this horrible thing as a bridge and get a proper router - in the web interface go to "LAN" -> LAN port work mode, check the LAN1. Then connect with telnet and type port vlan eth 1 transparent this will make the ONT work as a transparent bridge on LAN1 port to which you should connect a proper router and forget this rubbish ONT exists.
At the very least for now, in the LAN -> "DHCP server configuration" manually type a reasonably trustworthy DNS like 1.1.1.1
 
Joined
Jan 5, 2006
Messages
18,584 (2.67/day)
System Name AlderLake
Processor Intel i7 12700K P-Cores @ 5Ghz
Motherboard Gigabyte Z690 Aorus Master
Cooling Noctua NH-U12A 2 fans + Thermal Grizzly Kryonaut Extreme + 5 case fans
Memory 32GB DDR5 Corsair Dominator Platinum RGB 6000MT/s CL36
Video Card(s) MSI RTX 2070 Super Gaming X Trio
Storage Samsung 980 Pro 1TB + 970 Evo 500GB + 850 Pro 512GB + 860 Evo 1TB x2
Display(s) 23.8" Dell S2417DG 165Hz G-Sync 1440p
Case Be quiet! Silent Base 600 - Window
Audio Device(s) Panasonic SA-PMX94 / Realtek onboard + B&O speaker system / Harman Kardon Go + Play / Logitech G533
Power Supply Seasonic Focus Plus Gold 750W
Mouse Logitech MX Anywhere 2 Laser wireless
Keyboard RAPOO E9270P Black 5GHz wireless
Software Windows 11
Benchmark Scores Cinebench R23 (Single Core) 1936 @ stock Cinebench R23 (Multi Core) 23006 @ stock
I'm absolutely no expert in this but I've used to allow devices access by their specific MAC addresses but I think that works only for the devices connected by wifi.
 
Last edited:
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
so, desabling TR-069 didn't totaly stoped the probleme (i think it just stoped my ISP (or who ever was doing it) from changing my DNS)

so then i found that my firewall was on desabled, i changed it to normal (high stoped all trafic even web pages stoped working). so now 1 day later no attack yet. so i guss its working.

thanks you all for the help, you probably saved me.

Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.
yep i think it was the firewall.

Well, you seem to have some botnets calling your horrible, horrible ONT with a list of default login/passwords left unchanged by many horrible, horrible ISPs. Change ACS password to something ridiculous, disable telnet for WAN if you can. Use this horrible thing as a bridge and get a proper router - in the web interface go to "LAN" -> LAN port work mode, check the LAN1. Then connect with telnet and type port vlan eth 1 transparent this will make the ONT work as a transparent bridge on LAN1 port to which you should connect a proper router and forget this rubbish ONT exists.
At the very least for now, in the LAN -> "DHCP server configuration" manually type a reasonably trustworthy DNS like 1.1.1.1
yes i did change the ACS on the TR-069 to a random hard pass.

yes i will try to get a new proper router at some point.

and for the DNS i have it changed on my pc and thi shit router to 1.1.1.1

Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.
the huawei website is broken no firmware found, but there was some links in the forums i did download one but for need the problem seem to be fixed so i will avoid any new problems caused by non official links :)
 
Joined
Aug 20, 2007
Messages
21,688 (3.40/day)
Location
Olympia, WA
System Name Pioneer
Processor Ryzen 9 9950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon, Phanteks and Corsair Maglev blower fans...
Memory 64GB (2x 32GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage Intel 5800X Optane 800GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64 / Windows 11 Enterprise IoT 2024
huawei website is broken no firmware found, but there was some links in the forums i did download one but for need the problem seem to be fixed so i will avoid any new problems caused by non official links :)
Sounds best. Keep an eye on it and best of luck.
 

ASghostKI

New Member
Joined
Apr 25, 2021
Messages
2 (0.00/day)
I'm having the same issue, we're from the same country and we have the same ISP.

Any updates on the situation and the steps you did beside the ones you mentioned ?


In my case the DNS was redirecting to this page: http://heartoftech.club/author/hamza/page/6/+
1619372800783.png


and those where that DNS addresses that I found
1619372888387.png

and this is the user access log:
1619372923449.png



He's using servers from AWS I think
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M

ASghostKI


so here is what i did and it works fine (for me at least)

1-in "LAN" then "DHCP" change DNS to google or open DNS "1.1.1.1" . like in picture
Screenshot_2021-04-25 HG8245H.png


2- in "security" then "firewall" put it to "user-defined"

Screenshot_2021-04-25 HG8245H(1).png


3- in "security" then "ONT acces" desable all "WAN" and "WLAN" acces (i desabled also telnet from LAN just to be sure. because i only use HTTP from LAN)

Screenshot_2021-04-25 HG8245H(3).png


4- in "system tool" then "TR-069" i changed the logins and passwords with random stuff then i desabled it.

Screenshot_2021-04-25 HG8245H(2).png



This is all i think , i hope it helps you. GL.
 

ASghostKI

New Member
Joined
Apr 25, 2021
Messages
2 (0.00/day)
Thank you for the recap. I hope it prevent this from happening again.

I also got the IPs from the logs also the DNS servers IPs I found out that there are from AWS, so I filled an AWS abuse Report, maybe amazon can shut this down.
 
Joined
Sep 2, 2020
Messages
1,491 (0.92/day)
System Name Chip
Processor Amd 5600X
Motherboard MSI B450M Mortar Max
Cooling Hyper 212
Memory 2x 16g ddr4 3200mz
Video Card(s) RX 6700
Storage 5.5 tb hd 220 g ssd
Display(s) Normal moniter
Case something cheap
VR HMD Vive
idk if its possible but when i had a similar thing to this
when this happend i made the router only talk to mac addresses i set
 

AsRock

TPU addict
Joined
Jun 23, 2007
Messages
19,166 (2.98/day)
Location
UK\USA
Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.

Yeah should of been the 1st thing to do.

Maybe consider a separate modem\router that support your ISP.
 
Top