In my history I noticed this, "Web Attack: CCTV-DVR Remote Code Execution". Norton said I did not have to do any further action, but I am very concerned on what is going on.
Alright
Hi, aren. Stick with the expert on the qmalware forum. He will fix any problems.
So, I've ran Norton and Malwarebytes scans. (im coming back to this) I can be pretty sure I am safe correct? and I also have a qmalware forum.
Hello aren
That is why you signed up with 1 of the free malware removal sites. The site you signed up with will determine if your computer is clean or infected If it is infected, they will help you to clean it up.
Have a Good Night and
Thanks.
So, what shall I do? Am I good?
Hello
Ahhh, that's what I thought when you mentioned NAV.
Have a Good Night and
Thanks.
Just a router, only Norton product I have is the Norton Antivirus. I do not have any CCTV camera, etc.. so I was not 100% sure why it was in my history. :/
I am not using a Core router. I am only using the Norton Antivirus.
Hello aren
Are you using a Core Router? I am asking since you mention that you are using NAV.
Have a Good Night and
Thanks.
aren3000 You haven't answered the most important question thus far. Is this CCTV-DVR directly connected to your Core router or connected to a LAN port on your ISP device? I am assuming you have it connected to your ISP device vice the Core since it would not be discoverable connected to the Core as it protects iOT devices if directly connected to it.
Cheers
Im using the regular paid version of Norton Antivirus, I was not sure what to put there. Should I be concerned?
Hello aren3000
Welcome to the Norton Core
Your best bet would be to contact Customer Support. I had the remaining time on my NIS subscription added onto the Core Subscription. They would be the ones who handle subscription issues. Perhaps you can get the days from your antivirus added back on.
Have a Good Night and
Thanks.
Hi, I am currently using a paid subscription of the regular Norton Antivirus. May I ask how to remove my device from the network? I am not really sure..
Thank you!
Hello aren3000, since the tag for the thread is Core I ask are these are connected downstream on the Core router, IE connected to the core via Ethernet? Or connected to a router in the network BEFORE Core? Although NAV has prevented this exploit and attack the fact that is was attempted presents its own issue in that the device was discoverable. These are known exploits using the vulnerabilities within the device firmware to compromise the device for use in DDos attacks. This is the only write-up I can find regarding the issue from a Symantec/Norton standpoint: https://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=29627
Another article although older lists vendor names of products affected. If your device manufacturer name in on the list in the below article my best advice is remove it from your network due to the manufacturers not providing updates for their firmware: http://news.softpedia.com/news/remote-code-execution-flaw-found-in-firmware-of-70-different-cctv-dvr-vendors-502096.shtml
Cheers