- Feb 9, 2017
- 19
- 10
System hacked, help reading blue iris logs
I have big problems and need some big help please! My computer was hacked, 2 or more of 4, but it’s a little more complicated than just that.
Here’s the story and time line. 2 weeks ago I installed a demo of Blue iris onto a VM, thought it may be something I can use, I have an old computer that I’m willing to do some further testing with. All computers are on the same network, all logged in with my username and password (windows user and PW)
Last weekend I installed a new drive and windows onto SPARE, installed demo of blue iris, added cameras, working good, but now I want to add more cameras to see if the PC can handle it. I have 7 cameras on there now, looks promising, so now I want to test remote access.
Saturday 1-9-21
I went through the wizard, opened port 81 to allow access to SPARE that runs BI, all is working well, I am starting to like the software.
FF to this AM (1-13-21).
My main PC is off, I had a bunch of notes and websites open (including this one) from looking around on how to setup VLAN and just tweaking the software… so I’m annoyed. Start it back up, it’s all looking normal PC1 is working fine. My sick cat had an accident and I wanted to look at the camera to see what happened.. funny, the camera is not pointed where it was last night… long story short, a couple others are also not pointed correctly. I go into BI logs and find out there is a user (that was not there) named “anonymous” go into devices, there is an android device that I do not own… so now I know I have been hacked! The SPARE PC seems to be normal, it was on like it was before… however now I look into my router logs and see that PC1 tried to communicate to an ip in Germany now I know PC1 was hacked, or did they get into blue iris and then into the network… PC2 was on and PC3… they are both on screen saver now, and PC2 rebooted. I have image backups of the PC1, PC2, and PC3 and hopefully the image restore will get rid of what’s there….
HERE IS WHERE I NEEED HELP / ADVICE PLEASE!!!
I need to find PC-0 Patient Zero, did BI allow the attack, or did port 81 allow attacks from another PC? How do I read the logs to see when this “anonymous” user was created?
How do I read logs to see log ins and times logged in by users?
Any other logs I should look at? Any other advice would also be greatly appreciated.
I’m not blaming blue iris here, but opening that port 81 was a HUGE MISTAKE and I am trying to establish a timeline on activity that was not created from my use via the logs and information I can get from my PC in event viewer. Thanks in advance, and if some of you pummel me with lack of security measures and I told you so… that too will not offend me, I deserve it at my level of knowledge (not that I know how to prevent it completely, but to know better…. ) Just please, after slapping me in the head, please offer some help.
I have big problems and need some big help please! My computer was hacked, 2 or more of 4, but it’s a little more complicated than just that.
Here’s the story and time line. 2 weeks ago I installed a demo of Blue iris onto a VM, thought it may be something I can use, I have an old computer that I’m willing to do some further testing with. All computers are on the same network, all logged in with my username and password (windows user and PW)
Last weekend I installed a new drive and windows onto SPARE, installed demo of blue iris, added cameras, working good, but now I want to add more cameras to see if the PC can handle it. I have 7 cameras on there now, looks promising, so now I want to test remote access.
Saturday 1-9-21
I went through the wizard, opened port 81 to allow access to SPARE that runs BI, all is working well, I am starting to like the software.
FF to this AM (1-13-21).
My main PC is off, I had a bunch of notes and websites open (including this one) from looking around on how to setup VLAN and just tweaking the software… so I’m annoyed. Start it back up, it’s all looking normal PC1 is working fine. My sick cat had an accident and I wanted to look at the camera to see what happened.. funny, the camera is not pointed where it was last night… long story short, a couple others are also not pointed correctly. I go into BI logs and find out there is a user (that was not there) named “anonymous” go into devices, there is an android device that I do not own… so now I know I have been hacked! The SPARE PC seems to be normal, it was on like it was before… however now I look into my router logs and see that PC1 tried to communicate to an ip in Germany now I know PC1 was hacked, or did they get into blue iris and then into the network… PC2 was on and PC3… they are both on screen saver now, and PC2 rebooted. I have image backups of the PC1, PC2, and PC3 and hopefully the image restore will get rid of what’s there….
HERE IS WHERE I NEEED HELP / ADVICE PLEASE!!!
I need to find PC-0 Patient Zero, did BI allow the attack, or did port 81 allow attacks from another PC? How do I read the logs to see when this “anonymous” user was created?
How do I read logs to see log ins and times logged in by users?
Any other logs I should look at? Any other advice would also be greatly appreciated.
I’m not blaming blue iris here, but opening that port 81 was a HUGE MISTAKE and I am trying to establish a timeline on activity that was not created from my use via the logs and information I can get from my PC in event viewer. Thanks in advance, and if some of you pummel me with lack of security measures and I told you so… that too will not offend me, I deserve it at my level of knowledge (not that I know how to prevent it completely, but to know better…. ) Just please, after slapping me in the head, please offer some help.