blueirissoftware.com website down (2023.07.07)

I'm hoping I don't get hit by this. Right now, my seventeen cameras are still working fine with my BI machine. So I will not remotely access the PC unless it stops working or comes up in evaluation mode.
 
  • Like
Reactions: compulen
Mine is currently running normally fingers crossed hopefully it remains that way. I put a wildcard domain block in my Pihole DNS server for blueirissoftware.com, blueiris.pro and blueiris.software; my OS also resolves the AAAA records along with the A records but so far there haven't been any valid responses of the AAAA records so it appears Blue Iris was NOT running IPv6 on their sites. Those sites are now inaccessible from my network which hopefully means my BI instance is isolated but if there are any hardcoded IP addresses within BI to check for updates it could still get through. I am on a much older version, I have current maintenance through 2024 but I have been lazy and haven't updated my instance mostly because it was working fine and I didn't need any of the new features. I am on 5.4.9.14 x64 (7/23/2021) if anyone was curious. My BI machine does much more than just BI and so I was really hoping NOT to have to totally isolate the machine entirely. I also leave my BI console open at all times on the machine, it seems to check when I open the console after a reboot, I already had "no automatic updates" set and my system shows it last checked for News & Updates last night (7/7/23) just after 10:30pm.
 
  • Like
Reactions: benpage
Couldn't use the app yesterday. Eval just came up on screen a few moments ago. Just renewed last month.
If you are using the built in DDNS option then you wont be able to connect because the server cant update your ip address. Enter your actual ip or use another DDNS provider and it will work.
 
  • Like
Reactions: Smilingreen
Mine is currently running normally fingers crossed hopefully it remains that way. I put a wildcard domain block in my Pihole DNS server for blueirissoftware.com, blueiris.pro and blueiris.software...

Not sure since it's been a while but I don't think that it looks there. I think that it's an Amazon-hosted IP that it goes to. I remember long ago wondering why it was phoning out and that's my recollection.

Check your Pi Hole logs for traffic coming from the BI server IP and you may see it.
 
Not sure since it's been a while but I don't think that it looks there. I think that it's an Amazon-hosted IP that it goes to. I remember long ago wondering why it was phoning out and that's my recollection.

Check your Pi Hole logs for traffic coming from the BI server IP and you may see it.
are you saying it goes direct to an ip or uses some other domain? i’ve also blocked blueirissoftware.com at my dns server and haven’t had issues yet. i haven’t seen other suspicious queries yet
 
...Check your Pi Hole logs for traffic coming from the BI server IP and you may see it...

I would but I have multiple VMs sharing the same IP and I can't tell which is requesting what from where. This is also why I was hoping not to totally isolate that machine.
 
Reentered my serial and maintenance numbers and things returned to normal. Noticed my camera groups are missing. Did this happen to anyone else?
 
are you saying it goes direct to an ip or uses some other domain? i’ve also blocked blueirissoftware.com at my dns server and haven’t had issues yet. i haven’t seen other suspicious queries yet

I don't recall now whether it was to an IP or to a domain hosted at Amazon. I'm not at home where I can check my logs easily. Also, was long ago when I noticed it so it could be done completely differently now. I just blocked everything out to the WAN from that host. Can still get there via my VPN the way that mine is set up.
 
I don't recall now whether it was to an IP or to a domain hosted at Amazon. I'm not at home where I can check my logs easily. Also, was long ago when I noticed it so it could be done completely differently now. I just blocked everything out to the WAN from that host. Can still get there via my VPN the way that mine is set up.
I did a check for updates after blocking blueirissoftware.com and see a query for blueirissoftware.com, but nothing else that stands out. I don't have detailed netflow logs to see what other traffic may have been sent.
 
Yesterday I posted a question asking if I was the only one having problems getting to their web site. I didn't read all of the replys to this thread but I did get a response back from tech support stating that "we are experiencing some technical difficulties with out server". Its currently being worked on, but their is no indication as to when it will be back up. But they state, "it should be back up and running soon".
Since I haven't installed it yet I can't say how this outage impacts all of you.
 
  • Like
Reactions: looney2ns
Just an FYI:
I would suggest that you DO NOT download anything from the BI website during it's current downtime.
It's possible it is a malicious payload a bad actor placed there.
It is not malicious. It was placed there by Ken. It is 100 percent safe. VirusTotal
It would be silly for a malicious actor to do it this way rather than simply upload to a working website.
 
That's Funny. Well not really. I just downloaded it and was thinking the same thing. But just because it doesn't trip any malware flags doesn't necessarily mean it's not a bad actor! Takes a while for malware to be discovered, then a malware identifier to be sent out to all of the AV programs...... by then too late....
 
That's Funny. Well not really. I just downloaded it and was thinking the same thing. But just because it doesn't trip any malware flags doesn't necessarily mean it's not a bad actor! Takes a while for malware to be discovered, then a malware identifier to be sent out to all of the AV programs...... by then too late....
The developer has already replied to emails and posted on their facebook page indicating that their server is down and the file has been uploaded. The malware engines can detect viruses new viruses based on code using AI among other techniques.. Again what kind of foolish malicious actor would take down a site then upload a malicious file rather than simply uploading the file to the working site. Why would you then even download any file from the BI website or any site- even its working fine...if you dont trust it move on to an alternative product you can trust.