Monday, April 20, 2020

Draytek 2960 hacked?

The syslog have this following. Is it hacked ?

<141>Apr 20 05:20:30 Vigor: pptpd[12538]: accept client 141.98.81.42, socket[5]...

<141>Apr 20 05:20:30 Vigor: pptpd[12538]: MGR: check initial connection socket: 5 OK...

<141>Apr 20 05:20:30 Vigor: pptpd[12538]: CTRL: inetaddr[0]: 58.152.89.118

<141>Apr 20 05:20:30 Vigor: pptpd[12538]: CTRL: inetaddr[1]: 141.98.81.42

<141>Apr 20 05:20:30 Vigor: pptpd[12538]: CTRL: Client 141.98.81.42 control connection started

<141>Apr 20 05:20:30 Vigor: pptpd[12538]: CTRL: Made a START CTRL CONN RPLY packet

<141>Apr 20 05:20:31 Vigor: pptpd[12538]: CTRL: Asked to allocate call id when call open, not handled well

<141>Apr 20 05:20:31 Vigor: pptpd[12538]: CTRL: Set parameters to 10000000 maxbps, 3 window size

<141>Apr 20 05:20:31 Vigor: pptpd[12538]: CTRL: Made a OUT CALL RPLY packet

<141>Apr 20 05:20:31 Vigor: pptpd[12538]: CTRL: Starting call (launching pppd, opening GRE)

<141>Apr 20 05:20:31 Vigor: pptpd[7902]: CTRL (PPPD Launcher): program binary = /usr/sbin/pppd

<30>Apr 20 05:20:31 Vigor: pppd[7902]: Plugin /usr/lib/pppd/2.4.3/localip.so loaded.

<30>Apr 20 05:20:31 Vigor: pppd[7902]: LOCALIP: plugin initialized

<30>Apr 20 05:20:31 Vigor: pppd[7902]: MOTP: plugin initialized

<30>Apr 20 05:20:31 Vigor: pppd[7902]: Plugin /usr/lib/pppd/2.4.3/dhcpc.so loaded.

<30>Apr 20 05:20:31 Vigor: pppd[7902]: DHCPC: plugin initialized

<29>Apr 20 05:20:31 Vigor: pppd[7902]: Init buildin plugin /usr/lib/pppd/2.4.3/connect_status.so

<141>Apr 20 05:20:31 Vigor: pptp[7902]: Plugin /usr/lib/pppd/2.4.3/pptp.so loaded.

<141>Apr 20 05:20:31 Vigor: pptp[7902]: PPTP plugin version 2.4.3 compiled for pppd-2.4.3, linux-2.6.23.5

<141>Apr 20 05:20:31 Vigor: pptp[7902]: The remote system is required to authenticate itself

<141>Apr 20 05:20:31 Vigor: pptp[7902]: but I couldn't find any suitable secret (password) for it to use to do so.

<141>Apr 20 05:20:31 Vigor: pptpd[12538]: pppd[7902] process is not there ?? clear this call.



No comments:

Post a Comment