Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Disrespective

1926 posts

Uber Geek


#196234 24-May-2016 09:04
Send private message

I spent a bit of time last night having a play with my new Vodafone TC7210 cable modem and trying to figure out its nuances around static IPs, and later on some conflicting DHCP server settings I was encountering on my HTPC. (I'm wondering if this could have been the start of the hack) I also had my RT-AC68 wifi router active as it was what WAS doing the DHCP just fine.

 

Before the DHCP issues were noticed, I had decided to pick a random port to open and have a play and see how remote management of the HTPC would go. I picked port 9091 and apparently I should google these things as that's a common torrent port... Anyway I ended up opening the port on both the modem and the wifi router because I was playing with what I thought was doing the DHCP stuff at about 9pm.

 

I figured i'd just leave it for a while and let my wife watch some TV off the HTPC, and 10min later she starts complaining that i'm moving the mouse around and making "random menus pop up"... Eventually a notepad window appears and somebody writes something along the lines of "hi from cyber-somethingorother :)"

 

At this point I pulled the power from the modem and got a little worried... I have since malware checked the machine and can't find anything untoward so think it's clean.

 

I've also since reset and renamed almost everything, but what is more likely? That they got in through the open port (if so, does that mean my HTPC user account and password got hacked in less than 10 min?) Or that they got in through the wifi, and also hacked my different HTPC password? The HTPC has a username and password for accessing everything but I do have UnifiedRemote installed which lets me control it with my phone as it doesn't have a local keyboard or mouse I don't believe this is password protected, but would give someone control if on the network and they knew what was installed. They wouldn't be able to view the video output though unless they had a RDP connection I guess?

 

I'm wondering if they were on our network before the ports were opened and were causing the DHCP conflict that the HTPC was having. And I'm still unsure about was how they took control of the machine while we were also using it.

 

Either way, I still don't feel like i'm out of the woods, and will have to go through and edit all my account passwords today. It's a lesson I feel I may have been lucky enough to get away with, without too much pain, but worrying nonetheless.

 

I'll hang my head in shame in preparation for everyone who will come on board to tell me what I did wrong.

 

 

 

 


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
robjg63
4100 posts

Uber Geek

Subscriber

  #1558463 24-May-2016 09:36
Send private message

That sounds really scary.

 

Whoever it was announced themselves - so they were 'playing' with you - if they were really in the 'stealing' business they would have kept quiet. Hard to tell what the real motivation would be.

 

Hope someone may be able to advise you





Nothing is impossible for the man who doesn't have to do it himself - A. H. Weiler




Behodar
10518 posts

Uber Geek

Trusted
Lifetime subscriber

  #1558476 24-May-2016 09:45
Send private message

I'm aware of at least one copy of a popular TV show that has "menus" and a Notepad window encoded into the video for some reason. I'm not accusing you of anything, just stating facts in case it's the same thing :)


chevrolux
4962 posts

Uber Geek
Inactive user


  #1558478 24-May-2016 09:49
Send private message

That makes me think it was something to do with the UnifiedRemote software? Is that a screen sharing app? The only other way they could have opened notepad, menus etc would be with remote desktop.

 

I recognise 9091 as the default https port for the transmission torrent client web interface - i run this on my own server at home. I wonder if perhaps they tried to load their own torrents or something thinking it was actually a transmission client. Transmission has an api (maybe not a true api, but you can send commands to it on the https port) for other programs to interact with so maybe they tried but.

 

But it certainly isn't a screen sharing app!




Disrespective

1926 posts

Uber Geek


  #1558482 24-May-2016 09:55
Send private message

Behodar:

 

I'm aware of at least one copy of a popular TV show that has "menus" and a Notepad window encoded into the video for some reason. I'm not accusing you of anything, just stating facts in case it's the same thing :)

 

Ironically that's what a friend just asked me if it was. I didn't even consider it and didn't think to ask swmbo what she was watching (freeview or something from the NAS) so can't comment on that either. My knee jerk reaction may have been a little overzealous if that's true.


robjg63
4100 posts

Uber Geek

Subscriber

  #1558483 24-May-2016 10:00
Send private message

Behodar:

 

I'm aware of at least one copy of a popular TV show that has "menus" and a Notepad window encoded into the video for some reason. I'm not accusing you of anything, just stating facts in case it's the same thing :)

 

 

What show would that be? - just out of interest





Nothing is impossible for the man who doesn't have to do it himself - A. H. Weiler


JamesL
956 posts

Ultimate Geek
Inactive user


  #1558485 24-May-2016 10:02
Send private message

Doesn't really matter what port you use, or what the internet says it's used for, you'll often be constantly port scanned to determine what is open and what service is running

 

They're unlikely to have the username/password for your Windows machine, if they RDP'd onto it then the screen would've gone onto the lock screen whereas it sounds like they may have been using something like VNC or other remote software 


dan

dan
1134 posts

Uber Geek

Lifetime subscriber

  #1558496 24-May-2016 10:19
Send private message

robjg63:

 

Behodar:

 

I'm aware of at least one copy of a popular TV show that has "menus" and a Notepad window encoded into the video for some reason. I'm not accusing you of anything, just stating facts in case it's the same thing :)

 

 

What show would that be? - just out of interest

 

 

 

 

likely the GOT leaked episode,


 
 
 

Trade NZ and US shares and funds with Sharesies (affiliate link).
robjg63
4100 posts

Uber Geek

Subscriber

  #1558501 24-May-2016 10:30
Send private message

dan:

 

robjg63:

 

Behodar:

 

I'm aware of at least one copy of a popular TV show that has "menus" and a Notepad window encoded into the video for some reason. I'm not accusing you of anything, just stating facts in case it's the same thing :)

 

 

What show would that be? - just out of interest

 

 

 

 

likely the GOT leaked episode,

 

 

Just googled that and it sounds quite a bit like the OP reported - scared a few people in the middle of the episode....





Nothing is impossible for the man who doesn't have to do it himself - A. H. Weiler


Behodar
10518 posts

Uber Geek

Trusted
Lifetime subscriber

  #1558510 24-May-2016 10:43
Send private message

I can neither confirm nor deny this! tongue-out


JamesL
956 posts

Ultimate Geek
Inactive user


  #1558515 24-May-2016 10:53
Send private message

lol


garbonzai
315 posts

Ultimate Geek


  #1558517 24-May-2016 10:56
Send private message

Same thing happened to me last night, made me think what is going on here, I just rewind it a bit and it did it exactly the same again, so was part of the stream.





 

 

 

 

 

 

 


Disrespective

1926 posts

Uber Geek


  #1558518 24-May-2016 10:59
Send private message

Heh, sounds like I need to talk to her about what she was watching.

 

At the least it's kicked me in the bum to go and change some very old passwords, heh.


ghettomaster
387 posts

Ultimate Geek


  #1558521 24-May-2016 11:15
Send private message

We've had these discussions before. I personally think tools like Lastpass are awesome - just don't stick your banking passwords in there.

 

 

 

When dealing with an issue like this, Lastpass will tell you when each password was last changed, so it can be an easy way to be sure you've gone through all your passwords and changed them. Just be sure to make your lastpass password the first one you change, and be sure you've got a clean system before that.


Batman
Mad Scientist
29771 posts

Uber Geek

Trusted
Lifetime subscriber

  #1558557 24-May-2016 11:31
Send private message

garbonzai:

Same thing happened to me last night, made me think what is going on here, I just rewind it a bit and it did it exactly the same again, so was part of the stream.



Made my day!

nakedmolerat
4629 posts

Uber Geek

Trusted
Lifetime subscriber

  #1559259 25-May-2016 11:33
Send private message

@Disrespective:

Heh, sounds like I need to talk to her about what she was watching.


At the least it's kicked me in the bum to go and change some very old passwords, heh.



Did you ever find out the issue?

 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Gen Threat Report Reveals Rise in Crypto, Sextortion and Tech Support Scams
Posted 7-Aug-2025 13:09


Logitech G and McLaren Racing Sign New, Expanded Multi-Year Partnership
Posted 7-Aug-2025 13:00


A Third of New Zealanders Fall for Online Scams Says Trend Micro
Posted 7-Aug-2025 12:43


OPPO Releases Its Most Stylish and Compact Smartwatch Yet, the Watch X2 Mini.
Posted 7-Aug-2025 12:37


Epson Launches New High-End EH-LS9000B Home Theatre Laser Projector
Posted 7-Aug-2025 12:34


Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.