Hi!
I just installed my new DCS-2121 and enabled upnp to be able to watch the feed from my mobile.
While being on vacation I noticed that the feed redirected to some strange Russian site, lovebak.com
Back home now, I noticed that the /m/m/index.html file contains an iframe at the bottom, that redirects there. So SOMEONE (not me) has been able to alter the index on the wap site and add that at the end some way or the other.
While Googling I found only one reference on a French forum, and other than the lack of newer firmware for the camera no direct reactions to this.
I tried with a simple PUT to put the original file back, without the iframe at the bottom, but there I get a 403.
My questions:
- Anyone else seen this problem?
- When can we expect new firmware to fix this HUGE security problem?
- How to restore the original (and yes, I tried a factory reset, but that doesn't restore the html files it seems)
- How did they manage?
It seems from the config db that it's an OEM'ed alphanetworks.com camera with a lot more options that d-link put in there (like SIP! And SSL, which would certainly have helped here). Any input from them maybe, it seems they are writing the firmware?
/Robni