D-Link Forums

The Graveyard - Products No Longer Supported => IP Cameras => DCS-2630L => Topic started by: user100 on January 02, 2019, 03:30:32 AM

Title: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: user100 on January 02, 2019, 03:30:32 AM
DCS-2630L
Firmware Version: 1.05.02

I recent changed my router to TP Deco router. I used their build-in antivirus tool (TrendMicro). As soon as I started the protection, I received notice, from time to time, that my DSC-2630L was being attached from XXX.XXX.XX.XXX Classification: "WEB Remote Command".

Is it some security loophole for this product? What should I do?

Thank you.
Title: Re: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: GreenBay42 on January 02, 2019, 08:28:17 AM
i will forward this to the security team to see if this is an issue. The camera will send and receive data from the mydlink servers so the router may be detecting that.
Title: Re: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: FurryNutz on January 02, 2019, 11:11:54 AM
What is this number? XXX.XXX.XX.XXX


DCS-2630L
Firmware Version: 1.05.02

I recent changed my router to TP Deco router. I used their build-in antivirus tool (TrendMicro). As soon as I started the protection, I received notice, from time to time, that my DSC-2630L was being attached from XXX.XXX.XX.XXX Classification: "WEB Remote Command".

Is it some security loophole for this product? What should I do?

Thank you.
Title: Re: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: user100 on January 02, 2019, 01:02:37 PM
The numbers include:
205.185.113.123
119.23.68.83
104.248.161.171
37.53.77.129
183.233.238.67
209.141.57.239
205.185.115.94

These numbers do not appear at the same time (ie Each time the attack is from different addresses)
Title: Re: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: GreenBay42 on January 02, 2019, 01:11:29 PM
Try resetting the camera and setup again. Reflash the firmware - Make sure you get the firmware from support.dlink.com/dcs-2630L or tsd.dlink.com.tw.

Are any other devices on your network getting similar "attacks"?
Title: Re: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: FurryNutz on January 02, 2019, 02:29:07 PM
You can see who these IPs belong to at https://whois.domaintools.com (https://whois.domaintools.com)

The numbers include:
205.185.113.123
119.23.68.83
104.248.161.171
37.53.77.129
183.233.238.67
209.141.57.239
205.185.115.94

These numbers do not appear at the same time (ie Each time the attack is from different addresses)
Title: Re: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: user100 on January 03, 2019, 12:05:27 AM
Try resetting the camera and setup again. Reflash the firmware - Make sure you get the firmware from support.dlink.com/dcs-2630L or tsd.dlink.com.tw.

Are any other devices on your network getting similar "attacks"?

On my network, I also have a NAS, an Edimax IP cam, Compro IP cam, TP link Smart plug, WIFI printer. However, they did not receive any attacks notification. Yes, the latest firmware is from the official website of Dlink.
Title: Re: DSC-2630L attacked from XXX.XXX.XX.XXX Classification: "WEB Remote Command"
Post by: user100 on January 03, 2019, 12:29:27 AM
I just checked. All IP is from a company which I don't know.
Further, I read the Antivirus History again and found several entry on the attack of my DSC-2630L is "Classification: WEB D-Link DSL-2750B". Just want to know whether there are any security issue for DSC-2630L generally?


You can see who these IPs belong to at https://whois.domaintools.com (https://whois.domaintools.com)

The numbers include:
205.185.113.123
119.23.68.83
104.248.161.171
37.53.77.129
183.233.238.67
209.141.57.239
205.185.115.94

These numbers do not appear at the same time (ie Each time the attack is from different addresses)