How do these external connections work from third party bots?

talisman2208

Getting the hang of it
Joined
Aug 13, 2022
Messages
71
Reaction score
34
Location
Ohio
So playing around with a different camera system I have set up and opened up my port, my camera is just laying in my closet because I'm not actually using this system, but I noticed that someone managed to log into my BI using my username, and evidently my password which is VERY obscure.

Does this mean what I think it means? They spent 6 minutes and 42 seconds looking at camera footage? Or is that seconds?

How would it connect through my user name and password? Is there a vulnerability?

I don't have my main system open, but plan to open behind a VPN like suggested in various places through this forum.

1683762849446.png
 

wittaj

IPCT Contributor
Joined
Apr 28, 2019
Messages
25,270
Reaction score
49,211
Location
USA
I am assuming the 174 IP is you?

The 143 IP is a VPN that hides users IP - are you running one of those and is that you?
 

talisman2208

Getting the hang of it
Joined
Aug 13, 2022
Messages
71
Reaction score
34
Location
Ohio
The 174 is not me, it seems like just your typical roaming bot.

The 143 though, I think you're right - that makes sense. I did have a VPN on through my browser when I was testing connection. Now that makes sense! Thanks
 

talisman2208

Getting the hang of it
Joined
Aug 13, 2022
Messages
71
Reaction score
34
Location
Ohio
I do have verizon yes - but when I log in through my phone it says Zfold4
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,907
Reaction score
21,287
So playing around with a different camera system I have set up and opened up my port, my camera is just laying in my closet because I'm not actually using this system, but I noticed that someone managed to log into my BI using my username, and evidently my password which is VERY obscure.

Does this mean what I think it means? They spent 6 minutes and 42 seconds looking at camera footage? Or is that seconds?

How would it connect through my user name and password? Is there a vulnerability?

I don't have my main system open, but plan to open behind a VPN like suggested in various places through this forum.

View attachment 162519
The 174 connections were just that, connections, not data was transferred because they didnt have the correct username and password. You can see that in the log, Regardless stop port forwarding.
 
Top