How to stop illegal openwebif streaming from hacked enigma2 box

There are 48 replies in this Thread which was already clicked 7,640 times. The last Post () by acypaczom.

  • I have this problem.

    Someone just stream from my box.

    I have no idea how to check for bug's in OSCAM.

    I use new oscam.

    My router not supporting blocking external IP

    How to add "hostname" to block this user (he use same address).

    Thankls.

    Edited once, last by master G: moved from "Failban oscam" thread ().

    • Official Post

    How to add "hostname" to block this user (he use same address).

    Delete the [account] that is being used to illegally login. If it happens again your server login and port has been exposed. You`ll need to shutdown whatever ports you`ve opened in the router and change your login details.

  • goralpm


    I don't understand exactly where the problem is.


    Anyone streaming video and audio ? In this case, just password your set-top box (root user) or maybe in the case of many Enigma2 distributions it is also necessary to activate a password request - to stream audio / video from your set-top box.


    Or do you mean just Oscam sharing ? The correct configuration of Oscam should be enough here. But you still have to describe your problem exactly.


    Of course, this can also be solved by completely blocking the external IP address in the WiFi router communication settings (if you use a quality and expensive router, not cheap and ordinary).

  • I use OSCAM for sharing with me. I often away from home, so I stream my tv to my self and my family (1 member).

    To easy access for me I use Dynamic DNS.

    I set "enable HTTP authentication" in OpenWebIf.

    And from few days I see unauthorizing client streaming from my box.

    I change password - no effect.

    Is looks like he bypass any passwords or settings.

    My router not supporting blocking external addressees (it was my first call).

    So, is any chance to kick out strimming clients or setting oscam to blok him access?

    I hope now is more understanding;)

    Edited once, last by master G: moved from "Failban oscam" thread ().

    • Official Post

    I use OSCAM for sharing with me.

    Now that we know you only share to yourself within your own network it can safely be said its not an oscam problem and it cannot be used to block access.

    I have moved your post and responses away from the "Failban oscam" thread back to here.


    Open OpenWebif configuration:

    HTTP port - don`t use the default port 80. Change this immediately and close this port in the router.

    Enable Authentication for streaming - default is no, change it to yes

    Disable remote access for user root - default is no, change it to yes

    Streaming port - don`t use the default port 8001. Change this immediately and close this port in the router.


    Telnet / ssh to your box, paste in this command then press enter:

    adduser admin -h /dev/null -H -s /bin/false -G root

    You will be prompted for a new password. Enter your password x2.


    Restart GUI.. Now try to login with the user = admin and your new password. You can change admin on the command to any username you want.

    The idea behind this is to disable root access which we did in OpenWebif configuration, then give access to only the users you create.


    Once the new ports have been configured and opened in the router, login with the new user & pass.

  • Does the IP address of the unwanted user always change (in OscamWebif LOG) or is it always the same ?

    If it is the same, then it is easy to block it.


    Do you also use a VPN network in the set-top box ? Through this virtual private network, the intruder could connect to your set-top box at any time and from anywhere. So... if you use a VPN, try to restrict access to the VPN or modify the network policy in your VPN... you check the network interfaces with the command: ifconfig (network interface lo means loop-back or local network, inside the Linux OS, and then there will be one more wired ethernet interface like ehtX and if you use WIFI, there will probably be one extra WIFI interface, usualy marked as wlX) ... try to identify if you don't have a VPN network added there.


    Try changing all passwords:

    • root password (administrator access to Linux) in your set-top box : ideally connect to the set-top box via SSH / telnet protocol and then enter the command passwd to change the root password
    • also activate the password login for the Enigma2 Open-Webif (via the MENU - with the helping of RCU)
    • then change the password for Oscam-Webif... you will find the password for Webif access in the file "oscam.conf" (then it is necessary to restart the Oscam)... but... in this file "oscam.conf" it would be appropriate to also limit the connection only from your scope, for your IP groups / addresses: https://wiki.streamboard.tv/wi…ig/oscam.conf#httpallowed (add the local IP 127.0.0.1 + then add the range of IP addresses what you use)
    • also check / change the passwords of Oscam users (clients) as they have their passwords set (in the "oscam.user" file)
  • I not use VPN on my box.

    - I always change password via SSH telnet, and I recently (yesterday) done this.

    - password for Enigma2 / OpenWebif - is different? Then root password? How to change this password?

    - same as OscamWebif - how to change password and how it will be used?

    If I using root password for streaming via internet using dDNS I use only one password.

    I like options with address range but it will be working if I don't have oscam server - I just using lines.

    Thanks.

    ps. Can someone, who give me lines can access my box for streaming (ip streaming are different from lines one)?

    • Official Post

    - password for Enigma2 / OpenWebif - is different? Then root password? How to change this password?

    - same as OscamWebif - how to change password and how it will be used?

    Password for Enigma2 / OpenWeif / SSH / FTP are all the same. When you changed it via SSH / Telnet it affects them all.

    If I using root password for streaming via internet using dDNS I use only one password.

    I like options with address range but it will be working if I don't have oscam server - I just using lines.

    Thanks.

    ps. Can someone, who give me lines can access my box for streaming (ip streaming are different from lines one)?

    Its clear to me you don`t have an oscam server and the illegal streaming is coming from the OpenWebif plugin.

    oscam sharing / lines isn`t streaming, don`t confuse the wording of the two, OpenWebif is streaming.

    Whoever gave you the lines won`t be able to access your box for streaming.


    Follow post #7 to make your box more secure and forget about oscam.

  • Sorry, I meant not to change, but to activate the password, to connect to the Enigma2 web-interface (OpenWebif plugin). This is setting in the Enigma2 configuration - via the GUI MENU, using the RCU (Remote-Control-Unit). My mistake, sorry.


    On some Enigma2 distributions, the OpenWebif password login is not enabled by default, so you must activate it. Otherwise, it is possible to connect to OpenWebif without a password.

  • Any one that knows how to use a search engine for 'internet of things'. I wont menion which ones, can easily find insecure openwebif pages. You can also do it in google if you know what to search for ;)
    They cannot then only access your streams, they can use file explorer plugins to search your entire box files to steal cs lines, iptv lines. passwords etc etc.


    So as instructed above. Add a good password and change the default ports. Then check it via your IP address outside your own network to see if it is actually password protected.


    And if they still getting around it, are your family and friends sharing the info with someone else?

    ** A person who feels appreciated will always do more than what is expected **

  • It is best to disable for OpenWebif and for set-top box, access to the internet, and allow them to communicate over the network only within their own home LAN. However, every WiFi router can handle this as by default (+ especially without the use of a VPN).


    I forgot to write before that the problem could also be Oscam, which is downloaded from an untrustworthy source. If it is not the original Oscam, then its source code may contain a back door - for attackers.

  • I don't want to hijack this thread but I have the same exact problem. Someone is streaming thought my openwebif for months. When I click menu 3 - 3 (streaming client info, I can see channel name and ip address outside my network) . I've changed my password and Ip ports and that would work for a while, and then again I've would notice someone is streaming.


    Now I did exactly everything what user "master G" said in post #7 and post #8


    Now I don't see any streamer , stealing my stream. (1 day in total, will see)

    But there is one unbelievable thing I noticed. which gives me conclusion that Vu+ Duo 4k SE or just its software (Open PLI 8.2) is compromised to its core.


    Here it is:


    - I am using on Android TV, " Dream Player for Android TV" to stream from my vu+ when I am traveling of course.

    - I did open that app on TV and , all channels were still there (old setting) , no epg, and could not refresh, because I changed all my password s and ports and disabled access to root user BUT

    old channels list was available and I could click on one of the channels and STREAM from my box like there is no any any protection (even so as I said I've changed all my password s and ports and disabled access to root use)

    -how is that possible, ? Well I think LIVE streaming , UN- ENCODED is compromised because it used port 8001 for that. You can't change that port, whatever port I put in webif, it would not work until I have open port 8001 in my router.


    So for un-encoded live streaming thief don't need anything except url (ip adress) of user box, nothing else. He can stream it without problems. it sounds unbelievable, but it works, and I think he needs to know channel parameters too from your settings.

    Edited once, last by maraxft ().

  • Friends

    I have a problem here.

    I have an Octagon sf8008 box with OpenATV multiboot. (6.4, 7.2)

    About two days ago, someone is entering my box and activating the channel list, changing channels, etc. I can't watch tv. How can I lock this?

    I already changed the password, I changed the IP. I switched from LAN to WLAN and nothing.

    Help is welcome.

Your hub for IPTV & streaming support.

Get help with Android apps, Smart TV setup, m3u playlists, channel lists, and finding reliable live streaming websites. Master IPTV streaming on all devices. Find downloads, setup tutorials, and community support for apps, Smart TVs, and m3u channel lists.