Accessibility Resource Center Skip to main content
Have a phone you love? Get up to $500 when you switch and bring your phone.

WBM User Unknown - firewall config change

SOLVED
Reply
Kei897
Contributor
Contributor
Posts: 1
Registered: ‎08-26-2010

WBM User Unknown - firewall config change

Message 1 of 14
(40,948 Views)

In my Security Log I have been seeing a strange message that keeps appearing, see below.

 

I have no idea what this is or if this is someone hacking my router or if a virus is on my computer.  It has appeared even during times when my computer has been turned off.  I have my firewall set at max security and changed my password.  Even after changing my password this appeared.  Not sure what this is or what to do about it but I am very concerned.

 

Firewall Setup Configuration change

WBM user Unknown (0.0.0.0) has changed security settings[repeated 5 times, last time on Aug 25 03:00:26 2010]

1 ACCEPTED SOLUTION

Accepted Solutions
cobe
Contributor
Contributor
Posts: 1
Registered: ‎09-21-2013

Re: WBM User Unknown - firewall config change

Message 12 of 14
(10,878 Views)

I found this thread while looking for information about the "WBM user Unknown (0.0.0.0) has changed security settings"event that is logged in these FIOS routers on business networks.

 

So far I have seen no definitive answers but the various clues in all the messages here and on DSLREPORTS has caused me to think this message is likely due to something like antivirus definition updates.  It might also include any internal changes that are reactions to some self (the router) initiated event.

 

I'm going to go with that and consider it harmless since I can find not visible settings changes.

 

0.0.0.0 can translate to HERE in some networking speak.  Just like 127.0.0.1

In other situations 0.0.0.0 translates to any interface or all interfaces.  We also use it to mean any address that is not on the LAN side of a router.  Just depends on where it is seen. 

 

So it seems to me it is something inside the web management system that is updating something and since I can see no changes it is likely rules updates for firewall or other threat mitigation systems rules and possibly even firmware inside the router/firewall  On mine I doubt firmware because my uptime is months and I think firmware requires a reboot.

 

My other business networks use various other routers that perform these updates as needed. Sometimes many times a day and other times less frequently.

 

Those other devices typically check some remote server and based on my subscriptions (antivirus, website category definitions etc.) they then check the list of updates to any paid subscription definition and download and install it into the rules system and SEND ME AN EMAIL STATING WHICH DEFINITIONS HAVE BEEN UPDATED. On some days this might consist of many updated rules and others only 1.    Those cost $1000s and did not come free with an account and we pay a subscription fee for security definition updates so it makes sense that they provide a bit more functionality to detail what we get for the money and that the Verizon device just takes care of it and logs a security change.

 

 

 

 

View solution in original post

13 REPLIES 13
Hubrisnxs
Platinum Contributor III
Platinum Contributor III
Posts: 5,881
Registered: ‎07-22-2009

Re: WBM User Unknown - firewall config change

Message 2 of 14
(40,892 Views)

I don't know what it is for sure, but there are users at another forum asking about it.   not sure if it means anything. 

 

One guy reset the log, and disconnected physically from the net, and then factory restored his router, and he still got the message, so he was thinking it might be just a bug in the firmware,    

 

you can see their discussion here.

Hubrisnxs
Platinum Contributor III
Platinum Contributor III
Posts: 5,881
Registered: ‎07-22-2009

Re: WBM User Unknown - firewall config change

Message 3 of 14
(40,889 Views)

a user on the other forum mentions this.    

 

kinda makes sense.

 

 

"I believe the default config for the router is to query for updated firmware at specified intervals."

 

 

WBM means web based management, and 0.0.0.0 means the request did not come from outside your home.  it was internal. 

 

 

VSurfn
Contributor
Contributor
Posts: 1
Registered: ‎12-26-2012

Re: WBM User Unknown - firewall config change

Message 4 of 14
(33,635 Views)

This explanation was given by Actiontec (they build the router for Verizon)

 

 

Product:MI424WR (Rev. I) - Wireless Broadband Router

Incident Summary
=========================
Since Verizon can't answer this question I would like to know for the
people who built this router. 

Verizon Actiontec MI242WR (not sure of Rev) 
firmware 40.19.36

 

Why do I get this log security event every day?

 

mmm dd hh:mm:ss yyyy
Firewall Setup Configuration change WBM user Unknown (0.0.0.0) has
changed security settings
=========================

Resolution:
=========================
Each and every day, Verizon has a server that makes contact with your
router to check its firmware.

No changes are made to your router however, it simply checks the router

to make sure the firmware is up to date and this generates a log entry.
=========================

abern01
Contributor
Contributor
Posts: 2
Registered: ‎02-10-2011

Re: WBM User Unknown - firewall config change

Message 5 of 14
(33,043 Views)

VSurfn:

 

Although that sounds like a viable explanation from Actiontec...I just don't buy it!  You say you get that log entry every day?  I received just one entry in my log showing the identical message.  That issue took place 27 times between January 22 and January 30, 2013.  My log goes back to December 14, 2007 and that entry has never, ever appeared prior to last week.

 

If you ask me...Actiontec is just blowing smoke up your skirt!

 

Apparently neither Verizon nor Actiontec has a viable answer!

lfish43
Contributor
Contributor
Posts: 2
Registered: ‎02-09-2013

Re: WBM User Unknown - firewall config change

Message 6 of 14
(32,873 Views)

I dont buy it either. I have been having the same issue - the thing is it that it seems to happen right after I log into the router and make changes. The ither night I logged in at 3AM and changed some settings because I was having issues with my android phone transfering files. The next  day I logged in and one hour after I had logged in, I had this message:

 

WBM user admin (192.168.1.7) has changed security settings [repeated 2 times, last time on Feb 6 03:55:21 2013]

 

Why would I have a login 1 hour after I did? So the last few days, I have been regularly logging in and changing things just to see what happens. EVERY TIME I login, shortly after I get the same log as above. Why does it have to check for firmware updates several times a day, right after I login? I also chaged the general settings to allow only 1 session at a time, so If I am logged in, nobody else can. Well, several times I have tried to login and I get a message saying that I have to wait for the current session to end. Meaning that somebody else is logged in.

I am not liking this at all. I think it is a back door, and there is more going on than firmware checks. I am going to keep researching this and to the bottom of it. 

Hubrisnxs
Platinum Contributor III
Platinum Contributor III
Posts: 5,881
Registered: ‎07-22-2009

Re: WBM User Unknown - firewall config change

Message 7 of 14
(32,862 Views)

"WBM" is Web Based Management and the ip address 0.0.0.0 is known as the default route, so it's unlikely these are external events.

 

 

There are backdoors to that router, but they don't come from WBM.

 

 

lfish43
Contributor
Contributor
Posts: 2
Registered: ‎02-09-2013

Re: WBM User Unknown - firewall config change

Message 8 of 14
(32,847 Views)

Thanks for the info..

 

Are you pretty savvy with networking? There are some other logs that concern me. Here is one:

 

Its the bittorrent part that I was wondering about.. I dont have that on my machine. I double checked ( at one time my son installed utorrent, but it was uninstalled over a year ago)

 

Thanks.

Peace,
elPhish

 

Inbound TrafficAccepted Traffic - Service

BitTorrent (TCP): TCP 120.192.95.36:43092->192.168.1.7:32701 on clink1

 

 

Hubrisnxs
Platinum Contributor III
Platinum Contributor III
Posts: 5,881
Registered: ‎07-22-2009

Re: WBM User Unknown - firewall config change

Message 9 of 14
(32,843 Views)

That IP '120.192.95.36' is from china so that log entry is telling you that a machine at your location (192.168.1.7) has a torrent program and is downloading from that other ip.  

 

So you want to do an ipconfig on each of your machines to see which has the .7 address

 

 

Deciphering the Information

To get to ipconfig, we have to get to the command line.

  • Click Start, click Run, type in “cmd” & hit enter.
  • Type in ipconfig & hit enter. (you can use ipconfig /all for detailed information)

You will get a screen that looks like this.

ipconfig windows

 

 

 

stamina1914
Contributor
Contributor
Posts: 2
Registered: ‎03-20-2013

Re: WBM User Unknown - firewall config change

Message 10 of 14
(32,146 Views)

For what it is worth guys and I am no techy here, but I have gotten that message several times.  I actually got 13 today. However, the caveat is, I have been trying to unsuccesul to wake my pc via a mobile phone today with the Ceton media Center App.  the 13 events that the security log documented was in fact me trying to get into my system.

 

The irony here for me is that my port forwarding should be working, but I router kung fu is still to strong.

How-To Videos
 
The following videos were produced by users like you!
   
Videos are subject to the Verizon Fios Community Terms of Service and User Guidelines and contains content that is not created by Verizon.
Have a spare Fios-G1100?Learn how to bridge it into your network
Get Started


Covid19

Browse Categories
Categories:
Posts

Verizon Troubleshooters
Unable to find your answer here? Try searching Verizon Troubleshooters for more options.
Modal Dialogue Title