D-Link Forums

The Graveyard - Products No Longer Supported => D-Link Storage => DNS-320 => Topic started by: gcoxii on January 21, 2015, 07:49:07 AM

Title: new user on dns
Post by: gcoxii on January 21, 2015, 07:49:07 AM
I logged into my dns this morning and found a new user called remote. with rights to sudo,wheel,wheel. I am sure it wasn't trhere the last time i logged in. Basically, i have a ddns enabled and ftp. I turned off ftp. Not sure if this is something within the system or is someone in my dns
Title: Re: new user on dns
Post by: cable2 on January 22, 2015, 06:34:56 AM
Hi, check to see if you have the latest firmware. If not, download and install it.  After you update, login and change the admin password to something more secure.  Delete the user you are suspicious of, make sure to give all the users you want to keep a more secure password.  Go and change the password on your DDNS account.  Not sure how you are using your FTP, but lookin to using the SSL/TLS type of connection to access your DNS.  I maybe a bit paranoid, but better safe than sorry.
Title: Re: new user on dns
Post by: Talisman on September 05, 2016, 02:13:37 PM
Sorry to start up an old topic however I cannot find much information about this problem ANYWHERE except this post and I am seeing exactly the same accounts appearing.

Does anyone know what the "remote" account, "sudo" and "wheel" group accounts on a Dlink NAS with fun_plug installed relate to? Are they as sinister as they seem?
Every time I delete the "remote" account it appears again about a half hour later. Nothing in the log either. I have closed the firewall to the NAS so in theory is only accessible on the local network.
Please, if anyone has any knowledge of what these accounts are can they let me know.
Many thanks in advance!
Chris
Title: Re: new user on dns
Post by: ivan on September 06, 2016, 03:22:50 AM
Have you tried asking over on http://forum.dsmg600.info/viewforum.php?id=14 (http://forum.dsmg600.info/viewforum.php?id=14) where they deal with fun_plug and such things?
Title: Re: new user on dns
Post by: Talisman on September 06, 2016, 08:45:16 AM
Thanks, i will give that a try. Does anyone know if these accounts can appear as a result of using any of the built in applications on the Dlink NAS i.e. Ajaxplorer?
Title: Re: new user on dns
Post by: I am not a bot. on February 25, 2017, 11:35:36 AM
I first noticed something was wrong when I hadn't received my weekly SMART test emails for 3 weeks.  I couldn't login with any of the accounts I've set up.  Once I rebooted my DNS-320 I could login like normal and then found the remote user in the sudo and wheel groups.  Instead of deleting it, I updated the password, removed all groups, and denied access to all shares.  I then updated the firmware and finally deleted the remote user.  I was on firmware verison 2.0 dated 2010 and have since updated to 2.05 dated 2/2016.  I just installed the patch today so I can't confirm yet whether this was the issue I was experiencing.

EDIT: As soon as I posted this reply, I found this topic about the new firmware update: http://forums.dlink.com/index.php?topic=65608.0 (http://forums.dlink.com/index.php?topic=65608.0)  :P
Title: Re: new user on dns
Post by: FurryNutz on February 25, 2017, 03:10:37 PM
Let us know if the new version of FW works for you...

I first noticed something was wrong when I hadn't received my weekly SMART test emails for 3 weeks.  I couldn't login with any of the accounts I've set up.  Once I rebooted my DNS-320 I could login like normal and then found the remote user in the sudo and wheel groups.  Instead of deleting it, I updated the password, removed all groups, and denied access to all shares.  I then updated the firmware and finally deleted the remote user.  I was on firmware verison 2.0 dated 2010 and have since updated to 2.05 dated 2/2016.  I just installed the patch today so I can't confirm yet whether this was the issue I was experiencing.

EDIT: As soon as I posted this reply, I found this topic about the new firmware update: http://forums.dlink.com/index.php?topic=65608.0 (http://forums.dlink.com/index.php?topic=65608.0)  :P