January 04, 2022, 08:24:05 am *
Welcome, Guest. Please login or register.
News:
 
   Forum Home   Search Login Register OBiTALK  
Pages: [1]
  Print  
Author Topic: Obi110 Hacked? Attempting to Send NTP Packets to Ukraine  (Read 4598 times)
Busthead
Newbie
*
Posts: 17


« on: April 05, 2018, 10:59:20 am »

Why is my Obi110 attempting to send NTP packets to Ukraine?

Date Time   Country blocked    UDP         
192.168.0.202:55573   → 91.236.251.5:123
     
https://www.obitalk.com/forum/index.php?topic=8984.0

indicates that the latest firmware version is 2877. My device appears to be running 2886:

SoftwareVersion   1.3.0 (Build: 2886)

Interestingly, I still have the 2886 firmware file:

> certutil -hashfile OBi110-1-3-0-2886.fw SHA256
SHA256 hash of file OBi110-1-3-0-2886.fw:
7d 59 fa 2d 71 8f 14 c7 86 bd 87 7b 1e 1e af 23 30 77 f0 07 0d cb 7c a8 67 bc f9 08 5c 54 56 bd

Any ideas?
« Last Edit: April 05, 2018, 11:24:36 am by Busthead » Logged
drgeoff
Hero Member & Beta Tester
*****
Posts: 5539


« Reply #1 on: April 05, 2018, 12:04:35 pm »

1.  The OBI110 has a user-configurable field to set the address of the NTP server.  The default is pool.ntp.org.  Is yours still set to that?  If yes or if set to some other legitimate NTP server URL then look to your DNS server (which is not part of the OBi110) to see why it might be returning the 91.236.251.5 dotted quad.

2.  The latest firmware for OBi100 and OBi110 is 2886.
Logged
Lavarock7
Hero Member
*****
Posts: 613



« Reply #2 on: April 05, 2018, 12:08:16 pm »

The country code for the Ukraine is similar for the US (UA vrs US) although I don't see where it would be obvious to set it based upon country code.

Also, Ukraine is close to United States in the drop down of countries.

The country code ofr UA is 804 and US is 840 (very similar).

Could this be a fat finger choice in some manual setting for time zone or NTP server choice or with automatic setup via ISP?
« Last Edit: April 05, 2018, 12:10:07 pm by Lavarock7 » Logged

My websites: Kona Coffee: http://ItsKona.Com and Web Hosting: http://PlanetAloha.Info
A simplified Voip explanation: http://voip.planet-aloha.com
SteveInWA
Hero Member & Beta Tester
*****
Posts: 6445



« Reply #3 on: April 05, 2018, 01:17:15 pm »

Change the NTP server to:  us.pool.ntp.org

This screenshot is from a OBi 202, but there's a similar setting in the 110.


* screenshot-www.obitalk.com-2018.04.05-13-14-55.png (246.02 KB, 1028x717 - viewed 403 times.)
Logged

Pages: [1]
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Advertisement
Advertisement