Orbi WiFi 7 RBE973
Reply

netgear cold you explain this

netgear cold you explain this

i dont know is some one or a haker is trying to acess to my modem but he cant so  i have this logs 

 

the name that  i have for the user is admin  not thos rare names wtf is going 

 

i think some one is attaking me and sending attack because this is rare 

 

i dont have nothing to share on the pc 

 

this is why i request netgear make a strong security for login and for all 

 

 

here the log wtf 

[user login failure] from source 192.168.0.113Sat Sep 10 22:41:50 20160.0.0.0:0192.168.0.11:0
[sysadm login failure] from source 192.168.0.111Sat Sep 10 22:41:49 20160.0.0.0:0192.168.0.11:0
[support login failure] from source 192.168.0.111Sat Sep 10 22:41:49 20160.0.0.0:0192.168.0.11:0
[smc login failure] from source 192.168.0.111Sat Sep 10 22:41:49 20160.0.0.0:0192.168.0.11:0
[root login failure] from source 192.168.0.113Sat Sep 10 22:41:49 20160.0.0.0:0192.168.0.11:0
[manager login failure] from source 192.168.0.111Sat Sep 10 22:41:49 20160.0.0.0:0192.168.0.11:0
[login login failure] from source 192.168.0.113Sat Sep 10 22:41:49 20160.0.0.0:0192.168.0.11:0
[customer login failure] from source 192.168.0.111Sat Sep 10 22:41:48 20160.0.0.0:0192.168.0.11:0
[comcast login failure] from source 192.168.0.111Sat Sep 10 22:41:48 20160.0.0.0:0192.168.0.11:0
[ADSL login failure] from source 192.168.0.111Sat Sep 10 22:41:48 20160.0.0.0:0192.168.0.11:0
[DXDSL login failure] from source 192.168.0.111Sat Sep 10 22:41:48 20160.0.0.0:0192.168.0.11:0
[ZXDSL login failure] from source 192.168.0.111Sat Sep 10 22:41:48 20160.0.0.0:0192.168.0.11:0
[TMARDLKT93319 login failure] from source 192.168.0.111Sat Sep 10 22:41:48 20160.0.0.0:0192.168.0.11:0
[admin login failure] from source 192.168.0.1121Sat Sep 10 22:41:48 20160.0.0.0:0192.168.0.11:0
[admin2 login failure] from source 192.168.0.112Sat Sep 10 22:41:45 20160.0.0.0:0192.168.0.11:0
[admim login failure] from source 192.168.0.111Sat Sep 10 22:41:45 20160.0.0.0:0192.168.0.11:0
[adm login failure] from source 192.168.0.111Sat Sep 10 22:41:45 20160.0.0.0:0192.168.0.11:0
[ login failure] from source 192.168.0.115Sat Sep 10 22:41:45 20160.0.0.0:0192.168.0.11:0
[Username login failure] from source 192.168.0.111Sat Sep 10 22:41:44 20160.0.0.0:0192.168.0.11:0
[User login failure] from source 192.168.0.112Sat Sep 10 22:41:44 20160.0.0.0:0192.168.0.11:0
[Administrator login failure] from source 192.168.0.112Sat Sep 10 22:41:44 20160.0.0.0:0192.168.0.11:0
[Admin login failure] from source 192.168.0.112Sat Sep 10 22:41:43 20160.0.0.0:0192.168.0.11:0
[superuser login failure] from source 192.168.0.111Sat Sep 10 22:41:43 20160.0.0.0:0192.168.0.11:0
[superman login failure] from source 192.168.0.111Sat Sep 10 22:41:43 20160.0.0.0:0192.168.0.11:0
[super login failure] from source 192.168.0.111Sat Sep 10 22:41:43 20160.0.0.0:0192.168.0.11:0
[cusadmin login failure] from source 192.168.0.111Sat Sep 10 22:41:43 20160.0.0.0:0192.168.0.11:0
[admin login failure] from source 192.168.0.117Sat Sep 10 22:41:43 20160.0.0.0:0192.168.0.11:0
[Gearguy login failure] from source 192.168.0.111Sat Sep 10 22:41:42 20160.0.0.0:0192.168.0.11:0

 

 

Message 1 of 4
robtheone
Star

Re: netgear cold you explain this

Model: C3700-100NAS

Firmware Version: V2.02.08

OS: Win10 Pro

Cable Provider: Comast

 

I see that you have NO replies on this issue, and when I logged into my router today, I saw the EXACT same things!  I also have NO idea what it is.  Makes me feel paranoid that I either have a trojan (anti-virus can't seem to find any) or something else weird happening.  

 

Does ANYONE have any idea what this might be??  It is ODD that the same usernames are being used to attempt to login: sysadm, smc, root, customer, comcast, ADSL, DXDSL, ZXDSL and TMARDLKT93319!!! 

 

Here is my log today:

[user login failure] from source 192.168.0.112Wed Dec 07 14:12:39 20160.0.0.0:0192.168.0.11:0
[sysadm login failure] from source 192.168.0.111Wed Dec 07 14:12:39 20160.0.0.0:0192.168.0.11:0
[support login failure] from source 192.168.0.111Wed Dec 07 14:12:39 20160.0.0.0:0192.168.0.11:0
[smc login failure] from source 192.168.0.111Wed Dec 07 14:12:39 20160.0.0.0:0192.168.0.11:0
[root login failure] from source 192.168.0.113Wed Dec 07 14:12:39 20160.0.0.0:0192.168.0.11:0
[manager login failure] from source 192.168.0.111Wed Dec 07 14:12:39 20160.0.0.0:0192.168.0.11:0
[login login failure] from source 192.168.0.113Wed Dec 07 14:12:39 20160.0.0.0:0192.168.0.11:0
[customer login failure] from source 192.168.0.111Wed Dec 07 14:12:38 20160.0.0.0:0192.168.0.11:0
[comcast login failure] from source 192.168.0.111Wed Dec 07 14:12:38 20160.0.0.0:0192.168.0.11:0
[ADSL login failure] from source 192.168.0.111Wed Dec 07 14:12:38 20160.0.0.0:0192.168.0.11:0
[ZXDSL login failure] from source 192.168.0.111Wed Dec 07 14:12:38 20160.0.0.0:0192.168.0.11:0
[TMARDLKT93319 login failure] from source 192.168.0.111Wed Dec 07 14:12:38 20160.0.0.0:0192.168.0.11:0
[admin login failure] from source 192.168.0.1115Wed Dec 07 14:12:38 20160.0.0.0:0192.168.0.11:0
[admin2 login failure] from source 192.168.0.112Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0
[admim login failure] from source 192.168.0.111Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0
[adm login failure] from source 192.168.0.111Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0
[ login failure] from source 192.168.0.115Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0
[Username login failure] from source 192.168.0.111Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0
[User login failure] from source 192.168.0.112Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0
[Administrator login failure] from source 192.168.0.112Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0
[Admin login failure] from source 192.168.0.112Wed Dec 07 14:12:37 20160.0.0.0:0192.168.0.11:0

 

There were a LOT more attempts, but I am limited to character count here, so this was just a sample.

 

I have never seen anything in the Logs other than the "admin" logging in.  HELP?!?

Model: C3700|N600 Cable Gateway Docsis 3.0
Message 2 of 4
DarrenM
Sr. NETGEAR Moderator

Re: netgear cold you explain this

Hello Robtheone

 

It says its coming from a local Ip are you able to go to your attached devices and see if anything shows up with those ips 111-115?

 

DarrenM

Message 3 of 4
robtheone
Star

Re: netgear cold you explain this

Yes, you are correct.  The logs show the Router Login attempts coming from my main PC connected to the Router via ethernet.  This is why it scared me.  I though perhaps a trojan was on my PC, doing who knows what kind of damage, perhaps a keylogger, or data and credit card stealer.

 

HOWEVER, after looking into it and researching, I determined exactly what happened.  I had just installed a free version of Avast Anti-Virus program a couple days before this, and never put anti-virus software and someone trying to log into my router as being connected.  I realized the program has a feature (perhaps it is only for 30 days, because I have the FREE Version, and not what I thought I had downloaded), which will check your network for vulnerabilities.  I clicked run "Smart Scan" which I assumed was a simple Anti-Virus check, but actually also includes the network check for threats.  So it turns out that Avast was attempting to use some basic, generic logins from many different Router companies that have default username and passwords to see if they can gain access to my network, if the default logins were never changed.  Hence the odd usernames, which I found from googling some of them, which helped put the puzzle pieces together.  So, I re-ran just the network test portion of the software and confirmed that was exactly what happened.  I saw the same exact router login attempts in my logs and confirmed this was the issue.

 

So anyone else seeing these weird random logins, I hope you find this information useful.  If you are running any network testing software, that is the likely culprit for what is showing on the logs.  I appreciate you answering and trying to help determine the problem.

 

Mystery solved!  Phew, do I feel better!

Message 4 of 4
Top Contributors
Discussion stats
  • 3 replies
  • 3955 views
  • 1 kudo
  • 3 in conversation
Announcements

Orbi WiFi 7