• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

I have unautorised acces to my router/modem. i need help fast please !

Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Hi,

I live in morocco my ISP is "Maroc Telecom" (incase its important). and i have a fiber to home connection (100 Mb/s down 50 Mb/s up).
I have a Huawei HG8245H. (from my ISP).

Yesterday i had some internet problems (slowdowns and desconnects). so i went to my router config and changed some stuff (no problems here).

then i went to user logs, and then ohhh boy. there was a spam of connection attempts (like one every 3 min or so, until router block them for too much password errors. then they come back later). some even got the good password (WTF!)
FYI : the only password i can change is the root (i did change it some time ago). but there is an other one its like an ISP password or something (probably used in case you call them for a problem). but this one i can't change (at least i can't find where to change it). and its the same for all ISP clients that have this router (the login is "telecomadmin" very hard indeed lol)

plus my IP changes every time i restart my router. so i have no idea how this is possible (they must have somthing sending back the new ip)?

i tried to desable all web / telnet acces from WAN or WIFI (only local network should have acces). but in logs it says the acces was via CLI (command line interface ?).

Screenshot_2021-02-20 HG8245H(1).png

moreover and this is what worrying me the most. is that the one who got acces seem to have changed my DNS or somthing (so i guss i can be rederected to a fake paypal or somthing like that) (but in my PC i changed DNS to google / openDNS so i guss im ok but not any one that uses the router DNS ?)

Screenshot_1.png


so is there something i can do to stop this (any way to get even higher previlige to see maybe more settings to block this, because basic settings seem to have no effect) ?
i rather not have to change my router or contact my ISP (they are bad, and im sure 100% the help service poeple will not understand the problem (I speak knowingly))

PS: attached are the log files. (all connections from this ip "192.168.100.114" are mine (PC local IP).

thanks for your time.
 

Attachments

  • HG8245H.txt
    64.7 KB · Views: 383
Joined
Oct 17, 2012
Messages
9,781 (2.32/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
if possible disable Web management, or Web access. that way the only way to manage the router is from the LAN/WAN
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
if possible disable Web management, or Web access. that way the only way to manage the router is from the LAN/WAN

WAN Service
Enable the WAN-Side PC to Access the ONT Through FTP:
Enable the WAN-Side PC to Access the ONT Through HTTP:
Enable the WAN-Side PC to Access the ONT Through Telnet:
Enable the WAN-Side PC to Access the ONT Through SSH

are all desabled, plus in the logs it says acces using CLI
 
Joined
Oct 15, 2011
Messages
1,974 (0.43/day)
Location
Springfield, Vermont
System Name KHR-1
Processor Ryzen 9 5900X
Motherboard ASRock B550 PG Velocita (UEFI-BIOS P3.40)
Memory 32 GB G.Skill RipJawsV F4-3200C16D-32GVR
Video Card(s) Sapphire Nitro+ Radeon RX 6750 XT
Storage Western Digital Black SN850 1 TB NVMe SSD
Display(s) Alienware AW3423DWF OLED-ASRock PG27Q15R2A (backup)
Case Corsair 275R
Audio Device(s) Technics SA-EX140 receiver with Polk VT60 speakers
Power Supply eVGA Supernova G3 750W
Mouse Logitech G Pro (Hero)
Software Windows 11 Pro x64 23H2
Is that a router-and-ONT-all-in-one?! If true, I dislike that setup. (not directed at you)
 
Joined
Oct 17, 2012
Messages
9,781 (2.32/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
are all desabled, plus in the logs it says acces using CLI
look through all options & tabs & see if there is another setting for web or remote management.
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Is that a router-and-ONT-all-in-one?! If true, I dislike that setup. (not directed at you)
YES all in one

like this one


sorry for the shitty picture.

yeah i know its bad but they dont give you a choice when you get a subscription. so im stuck with this.
 
Joined
Oct 15, 2011
Messages
1,974 (0.43/day)
Location
Springfield, Vermont
System Name KHR-1
Processor Ryzen 9 5900X
Motherboard ASRock B550 PG Velocita (UEFI-BIOS P3.40)
Memory 32 GB G.Skill RipJawsV F4-3200C16D-32GVR
Video Card(s) Sapphire Nitro+ Radeon RX 6750 XT
Storage Western Digital Black SN850 1 TB NVMe SSD
Display(s) Alienware AW3423DWF OLED-ASRock PG27Q15R2A (backup)
Case Corsair 275R
Audio Device(s) Technics SA-EX140 receiver with Polk VT60 speakers
Power Supply eVGA Supernova G3 750W
Mouse Logitech G Pro (Hero)
Software Windows 11 Pro x64 23H2
YES all in one

like this one


sorry for the shitty picture.

yeah i know its bad but they dont give you a choice when you get a subscription. so im stuck with this.
Well, I like it when I can unplug the separate router for troubleshooting.
 
Joined
Sep 28, 2005
Messages
3,160 (0.47/day)
Location
Canada
System Name PCGR
Processor 12400f
Motherboard Asus ROG STRIX B660-I
Cooling Stock Intel Cooler
Memory 2x16GB DDR5 5600 Corsair
Video Card(s) Dell RTX 3080
Storage 1x 512GB Mmoment PCIe 3 NVME 1x 2TB Corsair S70
Display(s) LG 32" 1440p
Case Phanteks Evolve itx
Audio Device(s) Onboard
Power Supply 750W Cooler Master sfx
Software Windows 11
very curious about this myself.

I am not really strong in the network field so I will stay limited.

But can you adjust your DNS? Change it to google's or something. As well, also mentioned about web remote access, see if you can disable any kind of telnet or remote accessing within the router itself. You can also try to hide your WiFi signal as well, at least with most routers. I am not sure with yours. If it does have the option, try that.
 
Joined
Oct 17, 2012
Messages
9,781 (2.32/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
look through all options & tabs & see if there is another setting for web or remote management.
i only found this two, but they seem desabled

Screenshot_2021-02-20 HG8245H.png


Screenshot_2021-02-20 HG8245H(1).png


Hmm... Huawai, Xi Jinping knocking on your door.
exactly what i was thinking. maybe it some integrated spy system from the factory :tin foil hat:
 

OneMoar

There is Always Moar
Joined
Apr 9, 2010
Messages
8,746 (1.71/day)
Location
Rochester area
System Name RPC MK2.5
Processor Ryzen 5800x
Motherboard Gigabyte Aorus Pro V2
Cooling Enermax ETX-T50RGB
Memory CL16 BL2K16G36C16U4RL 3600 1:1 micron e-die
Video Card(s) GIGABYTE RTX 3070 Ti GAMING OC
Storage ADATA SX8200PRO NVME 512GB, Intel 545s 500GBSSD, ADATA SU800 SSD, 3TB Spinner
Display(s) LG Ultra Gear 32 1440p 165hz Dell 1440p 75hz
Case Phanteks P300 /w 300A front panel conversion
Audio Device(s) onboard
Power Supply SeaSonic Focus+ Platinum 750W
Mouse Kone burst Pro
Keyboard EVGA Z15
Software Windows 11 +startisallback
Last edited:
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
change the password for telecomadmin
how ? i can't find anywhere to change it

Screenshot_2021-02-20 HG8245H(2).png


can't change it its stuck in root (but im connected using telecomadmin)
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
16,064 (2.26/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/5za05v
Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
thanks i will look into this

Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
Screenshot_2021-02-20 HG8245H.png


desabled it, will see if it changes anything
 
Joined
Aug 20, 2007
Messages
20,784 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Hmm... Huawai, Xi Jinping knocking on your door.
Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.
 

OneMoar

There is Always Moar
Joined
Apr 9, 2010
Messages
8,746 (1.71/day)
Location
Rochester area
System Name RPC MK2.5
Processor Ryzen 5800x
Motherboard Gigabyte Aorus Pro V2
Cooling Enermax ETX-T50RGB
Memory CL16 BL2K16G36C16U4RL 3600 1:1 micron e-die
Video Card(s) GIGABYTE RTX 3070 Ti GAMING OC
Storage ADATA SX8200PRO NVME 512GB, Intel 545s 500GBSSD, ADATA SU800 SSD, 3TB Spinner
Display(s) LG Ultra Gear 32 1440p 165hz Dell 1440p 75hz
Case Phanteks P300 /w 300A front panel conversion
Audio Device(s) onboard
Power Supply SeaSonic Focus+ Platinum 750W
Mouse Kone burst Pro
Keyboard EVGA Z15
Software Windows 11 +startisallback
the ip address the access is coming from is a static ip owned by digital ocean there is also a unconfigured apache server running on p80
 
Joined
Mar 20, 2019
Messages
556 (0.30/day)
Processor 9600k
Motherboard MSI Z390I Gaming EDGE AC
Cooling Scythe Mugen 5
Memory 32GB of G.Skill Ripjaws V 3600MHz CL16
Video Card(s) MSI 3080 Ventus OC
Storage 2x Intel 660p 1TB
Display(s) Acer CG437KP
Case Streacom BC1 mini
Audio Device(s) Topping MX3
Power Supply Corsair RM750
Mouse R.A.T. DWS
Keyboard HAVIT KB487L / AKKO 3098 / Logitech G19
VR HMD HTC Vive
Benchmark Scores What's a "benchmark"?
Well, you seem to have some botnets calling your horrible, horrible ONT with a list of default login/passwords left unchanged by many horrible, horrible ISPs. Change ACS password to something ridiculous, disable telnet for WAN if you can. Use this horrible thing as a bridge and get a proper router - in the web interface go to "LAN" -> LAN port work mode, check the LAN1. Then connect with telnet and type port vlan eth 1 transparent this will make the ONT work as a transparent bridge on LAN1 port to which you should connect a proper router and forget this rubbish ONT exists.
At the very least for now, in the LAN -> "DHCP server configuration" manually type a reasonably trustworthy DNS like 1.1.1.1
 
Joined
Jan 5, 2006
Messages
17,825 (2.67/day)
System Name AlderLake / Laptop
Processor Intel i7 12700K P-Cores @ 5Ghz / Intel i3 7100U
Motherboard Gigabyte Z690 Aorus Master / HP 83A3 (U3E1)
Cooling Noctua NH-U12A 2 fans + Thermal Grizzly Kryonaut Extreme + 5 case fans / Fan
Memory 32GB DDR5 Corsair Dominator Platinum RGB 6000MHz CL36 / 8GB DDR4 HyperX CL13
Video Card(s) MSI RTX 2070 Super Gaming X Trio / Intel HD620
Storage Samsung 980 Pro 1TB + 970 Evo 500GB + 850 Pro 512GB + 860 Evo 1TB x2 / Samsung 256GB M.2 SSD
Display(s) 23.8" Dell S2417DG 165Hz G-Sync 1440p / 14" 1080p IPS Glossy
Case Be quiet! Silent Base 600 - Window / HP Pavilion
Audio Device(s) Panasonic SA-PMX94 / Realtek onboard + B&O speaker system / Harman Kardon Go + Play / Logitech G533
Power Supply Seasonic Focus Plus Gold 750W / Powerbrick
Mouse Logitech MX Anywhere 2 Laser wireless / Logitech M330 wireless
Keyboard RAPOO E9270P Black 5GHz wireless / HP backlit
Software Windows 11 / Windows 10
Benchmark Scores Cinebench R23 (Single Core) 1936 @ stock Cinebench R23 (Multi Core) 23006 @ stock
I'm absolutely no expert in this but I've used to allow devices access by their specific MAC addresses but I think that works only for the devices connected by wifi.
 
Last edited:
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M
Maybe read up on TR-069, it's what your service provider uses to access your router when they have to, which this seems to be a case of.
Could also be that they have a "backdoor" as many telco's do, which is bad, as those passwords tend to leak and they're usually the same for all of the same model of router.
Was a big drama about it in Sweden a few years ago, so the service providers were forced to swap out a lot of older gear.
so, desabling TR-069 didn't totaly stoped the probleme (i think it just stoped my ISP (or who ever was doing it) from changing my DNS)

so then i found that my firewall was on desabled, i changed it to normal (high stoped all trafic even web pages stoped working). so now 1 day later no attack yet. so i guss its working.

thanks you all for the help, you probably saved me.

Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.
yep i think it was the firewall.

Well, you seem to have some botnets calling your horrible, horrible ONT with a list of default login/passwords left unchanged by many horrible, horrible ISPs. Change ACS password to something ridiculous, disable telnet for WAN if you can. Use this horrible thing as a bridge and get a proper router - in the web interface go to "LAN" -> LAN port work mode, check the LAN1. Then connect with telnet and type port vlan eth 1 transparent this will make the ONT work as a transparent bridge on LAN1 port to which you should connect a proper router and forget this rubbish ONT exists.
At the very least for now, in the LAN -> "DHCP server configuration" manually type a reasonably trustworthy DNS like 1.1.1.1
yes i did change the ACS on the TR-069 to a random hard pass.

yes i will try to get a new proper router at some point.

and for the DNS i have it changed on my pc and thi shit router to 1.1.1.1

Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.
the huawei website is broken no firmware found, but there was some links in the forums i did download one but for need the problem seem to be fixed so i will avoid any new problems caused by non official links :)
 
Joined
Aug 20, 2007
Messages
20,784 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
huawei website is broken no firmware found, but there was some links in the forums i did download one but for need the problem seem to be fixed so i will avoid any new problems caused by non official links :)
Sounds best. Keep an eye on it and best of luck.
 

ASghostKI

New Member
Joined
Apr 25, 2021
Messages
2 (0.00/day)
I'm having the same issue, we're from the same country and we have the same ISP.

Any updates on the situation and the steps you did beside the ones you mentioned ?


In my case the DNS was redirecting to this page: http://heartoftech.club/author/hamza/page/6/+
1619372800783.png


and those where that DNS addresses that I found
1619372888387.png

and this is the user access log:
1619372923449.png



He's using servers from AWS I think
 
Joined
Sep 23, 2013
Messages
34 (0.01/day)
Location
Morocco
System Name Windows 7 64Bit
Processor Intel E5300 2.6Ghz
Motherboard Asus P5KPL-AM SE
Cooling NQ-3360A
Memory 2GB Kingston PC2-6400 + 2GB Kingston PC2-5300
Video Card(s) Sapphire HD5770 Vapor-x 1GB
Storage 4x80GB (2xSATA + 2xATA) :(
Display(s) CRT
Case Who need it ;)
Audio Device(s) Realtek ALC662
Power Supply NQ-4775-850-flex Black Magic
Benchmark Scores FSB (200Mhz) OC 270MHz CPU (2.6Ghz) OC 3.51GHz / Vcore 1.3v RAM (667Mhz) OC 900MHz / 2v GPU (860M

ASghostKI


so here is what i did and it works fine (for me at least)

1-in "LAN" then "DHCP" change DNS to google or open DNS "1.1.1.1" . like in picture
Screenshot_2021-04-25 HG8245H.png


2- in "security" then "firewall" put it to "user-defined"

Screenshot_2021-04-25 HG8245H(1).png


3- in "security" then "ONT acces" desable all "WAN" and "WLAN" acces (i desabled also telnet from LAN just to be sure. because i only use HTTP from LAN)

Screenshot_2021-04-25 HG8245H(3).png


4- in "system tool" then "TR-069" i changed the logins and passwords with random stuff then i desabled it.

Screenshot_2021-04-25 HG8245H(2).png



This is all i think , i hope it helps you. GL.
 

ASghostKI

New Member
Joined
Apr 25, 2021
Messages
2 (0.00/day)
Thank you for the recap. I hope it prevent this from happening again.

I also got the IPs from the logs also the DNS servers IPs I found out that there are from AWS, so I filled an AWS abuse Report, maybe amazon can shut this down.
 
Joined
Sep 2, 2020
Messages
1,478 (1.11/day)
System Name Chip
Processor Amd 5600X
Motherboard MSI B450M Mortar Max
Cooling Hyper 212
Memory 2x 16g ddr4 3200mz
Video Card(s) RX 6700
Storage 5.5 tb hd 220 g ssd
Display(s) Normal moniter
Case something cheap
VR HMD Vive
idk if its possible but when i had a similar thing to this
when this happend i made the router only talk to mac addresses i set
 

AsRock

TPU addict
Joined
Jun 23, 2007
Messages
18,874 (3.07/day)
Location
UK\USA
Processor AMD 3900X \ AMD 7700X
Motherboard ASRock AM4 X570 Pro 4 \ ASUS X670Xe TUF
Cooling D15
Memory Patriot 2x16GB PVS432G320C6K \ G.Skill Flare X5 F5-6000J3238F 2x16GB
Video Card(s) eVga GTX1060 SSC \ XFX RX 6950XT RX-695XATBD9
Storage Sammy 860, MX500, Sabrent Rocket 4 Sammy Evo 980 \ 1xSabrent Rocket 4+, Sammy 2x990 Pro
Display(s) Samsung 1080P \ LG 43UN700
Case Fractal Design Pop Air 2x140mm fans from Torrent \ Fractal Design Torrent 2 SilverStone FHP141x2
Audio Device(s) Yamaha RX-V677 \ Yamaha CX-830+Yamaha MX-630 Infinity RS4000\Paradigm P Studio 20, Blue Yeti
Power Supply Seasonic Prime TX-750 \ Corsair RM1000X Shift
Mouse Steelseries Sensei wireless \ Steelseries Sensei wireless
Keyboard Logitech K120 \ Wooting Two HE
Benchmark Scores Meh benchmarks.
Unlikely they'd be so blunt.

Op, have you checked if there is newer firmware for this router? Is it ISP provided? If so, contact ISP asap.

Yeah should of been the 1st thing to do.

Maybe consider a separate modem\router that support your ISP.
 
Top