• April 18, 2024, 12:51:05 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Pages: [1] 2

Author Topic: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.  (Read 13180 times)

cvearl

  • Level 1 Member
  • *
  • Posts: 6
SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« on: August 23, 2019, 10:25:02 AM »

Hello...

I have owned an AV2 1000 Powerline Kit for a year. I understand how it works and have had mostly no issues. Until last night. In the middle of using my computer I had a sudden loss of network performance. Youtube was poor. Speedtest was below 10Mb/s (Normally I get about 60 mb/s - 70 mb/s. Also the ping was 35 and would normally be 11.

Checked IPCONFIG and I was no longer on my subnet. Rebooted my computer and my router as well as my ISP's router several times... Still on the wrong network. Could not ping my router! Yet I had Internet. Albiet sloooowwww internet. All other devices in the house were on the correct network and could ping my router. Only my PC on the Powerline adaptor was behaving this way. It was late so I shut down my PC and went to bed.

Next day tested further. Unplugged the main Powerline unit next to my router from the wall. Ran upstairs and wow... The second unit for my PC was still working and I STILL had network!

I enabled network discovery on Win 10 and immediately could see someone elses network devices. I installed thier printer and, with notepad, printed a message to them with my phone number and name. They called 30 minutes later and it turns out it's my next door neighbor. Last night they plugged in thier new AV2 2000 right when my side got slow.

Turn out, without my permission or knowledge, my adaptor in my office joined THIER adaptors over power. I should not have to explain why this is a very bad thing and all the nasty reprecussions this presents.

Of course I was able to pair my units again after talking to dlink support. They seemed to feel this was impossible but I assure you as a Senior IT person in the field for over 20 years this happend right in front of my eyes. I never touched anything when it happened. I was on Discord with a buddy and watching youtube video right as it happened. I will have to pay to have a line pulled to my office from the core as I no longer trust this device.

Be warned.

C.
« Last Edit: August 23, 2019, 10:30:10 AM by cvearl »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #1 on: August 23, 2019, 10:45:45 AM »

Are there default PWs on these PLs and if so, are they changeable?

Very interesting that two different sets in close proximity got connected to a different network that's not even on your network or on same circuit. These don't have any wireless function and only use a button press to sync the two PLs together through the power circuit. Unless your house and the other persons house is on the same circuit, I would presume that this should not be happening.

This tow houses or a apartment? Whats the distance between your home and theirs?

« Last Edit: August 23, 2019, 10:49:58 AM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

GreenBay42

  • Administrator
  • Level 11 Member
  • *
  • Posts: 2752
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #2 on: August 23, 2019, 11:20:53 AM »

Please explain your environment. Obviously you and your neighbor are on the same circuit. It is impossible if they are on different circuits.  Did you press the encryption button (Simple Connect) on your adapters? That should lock out your neighbor's adapters.

I will forward this to the security team to investigate.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #3 on: August 23, 2019, 11:37:47 AM »

Your neighbor should be encrypting there PLs as well. Something to let them know about. ;)
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

cvearl

  • Level 1 Member
  • *
  • Posts: 6
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #4 on: August 23, 2019, 03:20:39 PM »

Are there default PWs on these PLs and if so, are they changeable?

Very interesting that two different sets in close proximity got connected to a different network that's not even on your network or on same circuit. These don't have any wireless function and only use a button press to sync the two PLs together through the power circuit. Unless your house and the other persons house is on the same circuit, I would presume that this should not be happening.

This tow houses or a apartment? Whats the distance between your home and theirs?

Two separate houses.

C.
Logged

cvearl

  • Level 1 Member
  • *
  • Posts: 6
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #5 on: August 23, 2019, 03:24:17 PM »

Please explain your environment. Obviously you and your neighbor are on the same circuit. It is impossible if they are on different circuits.  Did you press the encryption button (Simple Connect) on your adapters? That should lock out your neighbor's adapters.

I will forward this to the security team to investigate.

Two houses side by side. I did push the bottons when initially installed. Been paired since. Up until when they plugged thiers in next door that is.

The shock to me was how it decided to join theirs without the button being pressed. It just hopped on over. I no longer trust it.

C.
Logged

cvearl

  • Level 1 Member
  • *
  • Posts: 6
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #6 on: August 23, 2019, 03:25:25 PM »

Your neighbor should be encrypting there PLs as well. Something to let them know about. ;)

So they just connect without clicking that? I do remember a year ago pressing it on one and running fast upstairs to press the other. Can it just drop the relationship?

Will new units just talk without it out of the box?

C.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #7 on: August 23, 2019, 03:59:28 PM »

Honestly don't know. I haven't experienced D-Link PLs. I did once years ago but that was a different mfr. Theoretically they should only pair when on the same power circuit as if on a different, there is no route to the different circuit. I presume it's possible that you could add say another set to the same household and circuit. Which maybe one reason why yours joined, however yours shouldn't automatically disconnect or unsecure themselves to go connect to a new set that just comes online. I presume this is something that D-Link should test for.

You might factory reset yours, make sure the FW is up to date and setup from scratch and then have your neighbor do the same. Both of you watch them and see if anything happens.

I would have a electrician come out and check to see if there is any form on a power connection between your two houses. Technically there should not be and each house should be isolated from each other. It's possible that maybe the PL is finding a route out thru the main box to the power box or pole outside which your neighbor might be also tied to. Just an idea here is all.

Is is a odd issue and haven't seen this. Hopefully we can help you narrow down whats happening and get you confidence in using them again.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

cvearl

  • Level 1 Member
  • *
  • Posts: 6
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #8 on: August 24, 2019, 08:05:13 PM »

Please explain your environment. Obviously you and your neighbor are on the same circuit. It is impossible if they are on different circuits.  Did you press the encryption button (Simple Connect) on your adapters? That should lock out your neighbor's adapters.

I will forward this to the security team to investigate.

Just found out today talking to the neighbor. This was not another Dlink kit next door that mine connected to. It was NETGEAR 2000. That's even stranger.

C.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #9 on: August 25, 2019, 11:51:43 AM »

These?
https://www.netgear.com/support/product/PLP2000.aspx

Need to find out if there is any form of power connection or a common connection with a power box between your two houses. This would be the only thing that could possibly allow the two circuits to connect.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

cvearl

  • Level 1 Member
  • *
  • Posts: 6
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #10 on: August 26, 2019, 05:41:12 AM »

These?
https://www.netgear.com/support/product/PLP2000.aspx

Need to find out if there is any form of power connection or a common connection with a power box between your two houses. This would be the only thing that could possibly allow the two circuits to connect.

If Dlink asks me the exact model I could look into it better.

I paid a master electrician to come and check my house. Did a bunch of tests and said my panel/wiring was fine. My Meter was not cross-metered or anything. He said we go out to the same pole but that's it. We are not wired together.

That's all I know.

C.
Logged

GreenBay42

  • Administrator
  • Level 11 Member
  • *
  • Posts: 2752
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #11 on: August 26, 2019, 06:27:55 AM »

If you and your neighbor are not on the same electrical circuit, it is IMPOSSIBLE for them to connect. Are they connected to your wifi?

It is like saying a neighbor is connecting to your Ethernet switch without an Ethernet cable being plugged in from their house to your switch.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #12 on: August 26, 2019, 09:06:41 AM »

Wondering if there finding a path way to each other if on same power pole. Shouldn't be happening though... ::)
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

GreenBay42

  • Administrator
  • Level 11 Member
  • *
  • Posts: 2752
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #13 on: August 27, 2019, 06:58:40 AM »

It must be but I don't think that is possible either. People have issues in their own home with powerline adapters. It is hard to believe that this power outlet is somehow able to send data to another house via power pole, but happens with phone lines that get crossed so i guess it is possible.

Need the complete topology.

But the real issue may in fact be the "security" issue. If the 2 adapters have been properly "encrypted", other powerline adapters should not be able to talk to them.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: SECURITY ALERT! AV2 HUGE Security Flaw!!!!! Be warned.
« Reply #14 on: August 27, 2019, 07:18:06 AM »

Even from different Mfrs though the HW maybe similar internally.

Ya something isn't right about this... ???
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.
Pages: [1] 2