Orbi WiFi 7 RBE973
Reply

Am I getting hacked?

01dav
Aspirant

Am I getting hacked?

Hello, 

Today I saw strange logs on ma Orbi:

[LAN access from remote] from 217.153.58.129 port 20396 to 10.0.0.41 port 8123 Wednesday, Feb 21,2024 20:25:12
[LAN access from remote] from 217.153.58.129 port 20397 to 10.0.0.41 port 8123 Wednesday, Feb 21,2024 20:25:12
[LAN access from remote] from 217.153.58.129 port 20399 to 10.0.0.41 port 8123 Wednesday, Feb 21,2024 20:25:12
[LAN access from remote] from 217.153.58.129 port 20398 to 10.0.0.41 port 8123 Wednesday, Feb 21,2024 20:25:12
[LAN access from remote] from 217.153.58.129 port 20400 to 10.0.0.41 port 8123 Wednesday, Feb 21,2024 20:25:12

 

Am I getting hacked or something like that? Is it scanning all the ports on my router?

Message 1 of 8
FURRYe38
Guru

Re: Am I getting hacked?

Do a whois look up on that IP address to see where thats coming from. 

Log is just reporting the attempted log in. Not getting in. 

 

What model Orbi do you have? 
Firmware version loaded? 

What is the Mfr and model# of the Internet Service Providers modem/ONT the NG router is connected too?

Message 2 of 8
01dav
Aspirant

Re: Am I getting hacked?

Thank you for quick reply. My router is RBR750 and the firmware is V4.6.14.3_2.3.12 and it shows that no new firmware is available. I also have Netgear Armor subscription. I got notification that there was a DoS attack attempt on my iPhone as well.

Message 3 of 8
FURRYe38
Guru
01dav
Aspirant

Re: Am I getting hacked?

Thank you. Does it mean I could get hacked? Why I didn't get info that no new firmware is available on my orbi dashboard?

 

Should I change all my passwords? What can I do after updating router?

 

I've checked that one of the adresess is from my internet provider, the other one is from my country but it shows that it's T-Mobile

Message 5 of 8
FURRYe38
Guru

Re: Am I getting hacked?


@01dav wrote:

Thank you. Does it mean I could get hacked? No.

Why I didn't get info that no new firmware is available on my orbi dashboard?

NG doesn't auto update systems anymore unless it's some major version of FW or users allow the system to update. NG put in the ability to disable auto updates. So users have control now. So if you don't see it, and something is on the download site or mentioned here in the forums, user can manually update, if they wish too. 

 

Should I change all my passwords? What can I do after updating router?

Up to you, was an attempt is all, wasn't successful. 

Do you have a ISP service from T-Mobile? 
What ISP brand and model modem do you have connected to the Orbi system? 

 

I've checked that one of the adresess is from my internet provider, the other one is from my country but it shows that it's T-Mobile

Are you by chance connected to this T-Mobile service with a phone or pad to the system? 


 

Message 6 of 8
01dav
Aspirant

Re: Am I getting hacked?

Now everything is clear to me. So at this time I connected to my company VPN which has two internet providers, one of them is T-Mobile and both of IP adresses are from my company office.

 

Today I saw on my logs something like this:

[DoS attack: DoSPortScan] from source 10.0.0.18, port 62090

 

It's internal IP of my iPhone 14 Pro - mobile has the newest update. Is it something I should be concerned?

Message 7 of 8
FURRYe38
Guru

Re: Am I getting hacked?

Probably not. Just the system reporting what's happening. If VPN and all that is involved and is known then you'll be ok. 

 

Message 8 of 8
Top Contributors
Discussion stats
  • 7 replies
  • 1280 views
  • 1 kudo
  • 2 in conversation
Announcements

Orbi 770 Series