• April 26, 2024, 04:45:32 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: new user on dns  (Read 6737 times)

gcoxii

  • Level 1 Member
  • *
  • Posts: 15
new user on dns
« on: January 21, 2015, 07:49:07 AM »

I logged into my dns this morning and found a new user called remote. with rights to sudo,wheel,wheel. I am sure it wasn't trhere the last time i logged in. Basically, i have a ddns enabled and ftp. I turned off ftp. Not sure if this is something within the system or is someone in my dns
Logged

cable2

  • Level 3 Member
  • ***
  • Posts: 299
Re: new user on dns
« Reply #1 on: January 22, 2015, 06:34:56 AM »

Hi, check to see if you have the latest firmware. If not, download and install it.  After you update, login and change the admin password to something more secure.  Delete the user you are suspicious of, make sure to give all the users you want to keep a more secure password.  Go and change the password on your DDNS account.  Not sure how you are using your FTP, but lookin to using the SSL/TLS type of connection to access your DNS.  I maybe a bit paranoid, but better safe than sorry.
Logged

Talisman

  • Level 1 Member
  • *
  • Posts: 2
Re: new user on dns
« Reply #2 on: September 05, 2016, 02:13:37 PM »

Sorry to start up an old topic however I cannot find much information about this problem ANYWHERE except this post and I am seeing exactly the same accounts appearing.

Does anyone know what the "remote" account, "sudo" and "wheel" group accounts on a Dlink NAS with fun_plug installed relate to? Are they as sinister as they seem?
Every time I delete the "remote" account it appears again about a half hour later. Nothing in the log either. I have closed the firewall to the NAS so in theory is only accessible on the local network.
Please, if anyone has any knowledge of what these accounts are can they let me know.
Many thanks in advance!
Chris
Logged

ivan

  • Level 8 Member
  • ***
  • Posts: 1480
Re: new user on dns
« Reply #3 on: September 06, 2016, 03:22:50 AM »

Have you tried asking over on http://forum.dsmg600.info/viewforum.php?id=14 where they deal with fun_plug and such things?
Logged

Talisman

  • Level 1 Member
  • *
  • Posts: 2
Re: new user on dns
« Reply #4 on: September 06, 2016, 08:45:16 AM »

Thanks, i will give that a try. Does anyone know if these accounts can appear as a result of using any of the built in applications on the Dlink NAS i.e. Ajaxplorer?
Logged

I am not a bot.

  • Level 1 Member
  • *
  • Posts: 1
Re: new user on dns
« Reply #5 on: February 25, 2017, 11:35:36 AM »

I first noticed something was wrong when I hadn't received my weekly SMART test emails for 3 weeks.  I couldn't login with any of the accounts I've set up.  Once I rebooted my DNS-320 I could login like normal and then found the remote user in the sudo and wheel groups.  Instead of deleting it, I updated the password, removed all groups, and denied access to all shares.  I then updated the firmware and finally deleted the remote user.  I was on firmware verison 2.0 dated 2010 and have since updated to 2.05 dated 2/2016.  I just installed the patch today so I can't confirm yet whether this was the issue I was experiencing.

EDIT: As soon as I posted this reply, I found this topic about the new firmware update: http://forums.dlink.com/index.php?topic=65608.0  :P
« Last Edit: February 25, 2017, 03:10:04 PM by FurryNutz »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: new user on dns
« Reply #6 on: February 25, 2017, 03:10:37 PM »

Let us know if the new version of FW works for you...

I first noticed something was wrong when I hadn't received my weekly SMART test emails for 3 weeks.  I couldn't login with any of the accounts I've set up.  Once I rebooted my DNS-320 I could login like normal and then found the remote user in the sudo and wheel groups.  Instead of deleting it, I updated the password, removed all groups, and denied access to all shares.  I then updated the firmware and finally deleted the remote user.  I was on firmware verison 2.0 dated 2010 and have since updated to 2.05 dated 2/2016.  I just installed the patch today so I can't confirm yet whether this was the issue I was experiencing.

EDIT: As soon as I posted this reply, I found this topic about the new firmware update: http://forums.dlink.com/index.php?topic=65608.0  :P
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.