Jump to content

I think Emby may have hijacked my Shield?


Recommended Posts

crusher11
Posted

I tried to play a movie in a streaming app, but when I hit play it started up “Maroon” by Taylor Swift. Pressing play and pause causes the streaming app's play/pause icon to flash, but only plays and pauses the music. Exiting to the Android TV home screen shows no sign anything is playing. It's running through the entire Midnights album. It's gone way too long without an ad for it to be Spotify, and the only other source I can think of would be Emby. The Emby app doesn't show anything playing, but then neither does the Shield's home screen so that doesn't necessarily mean anything. I just have no idea what's going on here.

Posted

Shutting down your server would be an easy way to tell but what does the Emby dashboard show?  Log activity?

crusher11
Posted

I let it play out until the end of the album, because I was curious as to what would happen. It just stopped. Didn't think to check the dashboard.

The log...does appear to show playback. I booted the theater up at 17:06, and the searches for “sitting duck” and “la synd” are me looking up the movie I was about to watch to see what the correct aspect ratio was in order to put my projector on the correct preset; I would have attempted to start the movie in the streaming app within a minute or two of those searches.

embyserver (1).txt

Posted

Unless you can reproduce, I'm not sure what else to do here. It sounds like some sort of situation where Emby was still holding the media session in the background and so responded to your remote clicks.

crusher11
Posted
52 minutes ago, ebr said:

Unless you can reproduce, I'm not sure what else to do here. It sounds like some sort of situation where Emby was still holding the media session in the background and so responded to your remote clicks.

There was no media session to hold. I have never attempted, at least not recently, to play Midnights. It certainly wasn't the most recent thing I was doing with Emby. So I have no idea why it even started, or why the Emby app gave no indication anything was playing, or why my Shield gave no indication anything was playing.

  • 2 weeks later...
Posted
On 9/10/2026 at 11:13 PM, ebr said:

Unless you can reproduce, I'm not sure what else to do here.

It's happened again. Checked the dashboard this time and it is indeed playing through the universal Android app. Doesn't seem to be playing an album, this time...it started midway through “I Did Something Bad” from Reputation and has now moved on to “Love Story” from Fearless. Might be one of my music playlists, though, which was the last thing I was doing on Emby from a music playback perspective but I've watched a dozen movies since then so it doesn't make much sense.

This is also the first time I've used Beamafilm since the last time I had this issue, so it does seem to be some sort of interaction with Beamafilm specifically.

I rebooted the server. It was in the middle of “Love Story” when it shut down, and when it booted up it immediately started playing “no body, no crime.” I'm unable to control playback from the dashboard.

embyserver.txt embyserver-63925689323.txt

crusher11
Posted

@ebrWhere are we at with this? I see someone has downloaded the server logs, but you haven't downloaded the DM'd app logs, so I'm not sure where we stand.

Posted (edited)

2026-09-08 07:00:47.861 Info Server-0HNOCNNMM76IC:00000001: http/1.1 Response 404 to host17. Time: 0ms. GET http://host3/version. 
2026-09-08 07:00:48.958 Info Server-0HNOCNNMM76ID:00000001: http/1.1 Response 404 to host17. Time: 6ms. GET http://host3/api/v1/pods. 
2026-09-08 07:01:46.528 Info Server-0HNOCNNMM76IG:00000001: http/1.1 POST http://host3/v1/statement. Source Ip: host18, UserAgent: python-urllib3/2.7.0
2026-09-08 07:01:46.529 Info Server-0HNOCNNMM76IG:00000001: http/1.1 Response 404 to host18. Time: 1ms. POST http://host3/v1/statement. 
2026-09-08 07:02:09.291 Info Server-0HNOCNNMM76IH:00000001: http/1.1 Response 404 to host19. Time: 0ms. GET http://host3/dana-na/nc/nc_gina_ver.txt. 
2026-09-08 07:02:10.235 Info Server-0HNOCNNMM76II:00000001: http/1.1 Response 404 to host19. Time: 0ms. GET http://host3/dana-cached/hc/HostCheckerInstaller.osx. 
2026-09-08 07:02:11.264 Info Server-0HNOCNNMM76IJ:00000001: http/1.1 GET http://host3/dana-na/auth/url_default/welcome.cgi. Source Ip: host19, Host=115.70.108.233, User-Agent=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) 

Quote
The endpoint /dana-na/auth/url_default/welcome.cgi is associated with a critical remote code execution (RCE) and stack-based buffer overflow vulnerability tracked as CVE-2025-0282 in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways. [1, 2, 3]
 
Overview of CVE-2025-0282
 

Vulnerability Type: Stack-based Buffer Overflow (CWE-121, CWE-787) leading to Remote Code Execution. [1]

CVSS Score: 9.0 (Critical) [1]

Affected Products:
  • Ivanti Connect Secure versions prior to 22.7R2.5
  • Ivanti Policy Secure versions prior to 22.7R1.2
  • Ivanti Neurons for ZTA gateways prior to 22.7R2.3 [1]

Target Endpoint: Unauthenticated attackers target /dana-na/auth/url_default/welcome.cgi (a pre-exploitation version-check and welcome portal interface) to send crafted payloads over HTTPS (port 443) that overwrite return addresses in memory. [1, 2, 3]

It is this. Somebody is trying to hack you hoping you are running a reverse proxy, vpn, or something and take control. They are trying to run exploits against your server. It isn't coming from Emby but being shoveled down Emby's port you have opened facing the internet. It doesn't look like they can do anything. But they can likely send "casting" commands and cause incorrect media to play and other shenanigans. If they gain access to your correct user with admin they can delete things.

The IP shown on the one sending the welcome.cgi appears to be from Superloop (Australia) Pty Ltd.

Find the corresponding IP to match Host3 in your unsantized logs. You will have the offending IP. Ban it. Ban its subnet.

Edited by speechles
Posted (edited)

2026-09-08 07:02:27.786 Info Server-0HNOCNNMM76IL:00000001: http/1.1 Response 404 to host20. Time: 0ms. GET http://host3/RDWeb. 
2026-09-08 07:02:31.028 Info Server-0HNOCNNMM76IO:00000001: http/1.1 Response 404 to host20. Time: 0ms. GET http://host3/Remote. 
2026-09-08 07:02:32.100 Info Server-0HNOCNNMM76IP:00000001: http/1.1 Response 404 to host20. Time: 0ms. GET http://host3/RDWeb/Pages/en-US/login.aspx. 

2026-09-08 07:02:46.305 Info Server-0HNOCNNMM76IR:00000001: http/1.1 Response 404 to host21. Time: 0ms. POST http://host3/wsman. 
2026-09-08 07:04:06.867 Info Server-0HNOCNNMM76J1:00000001: http/1.1 GET http://host3/api/sonicos/auth. Source Ip: host22, Host=115.70.108.233, User-Agent=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36, Accept-Encoding=gzip, X-Real-IP=74.207.240.7, X-Forwarded-For=74.207.240.7
2026-09-08 07:07:17.412 Info Server-0HNOCNNMM76J9:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=+CSCOE+/portal_inc.lua. 
2026-09-08 07:07:44.435 Info SyncService-0HNOCNNMM76JB:00000002: http/1.1 POST http://192.168.0.2:8096/Sync/Data?TargetId=116f23d7-a0de-6360-ea5c-6686e8076f78. Source Ip: host1, UserAgent: EmbyMedia.13848C33ED80B/2.322.2.0
2026-09-08 07:07:44.435 Info SyncService-0HNOCNNMM76JB:00000002: http/1.1 Response 200 to host1. Time: 1ms. POST http://192.168.0.2:8096/Sync/Data?TargetId=116f23d7-a0de-6360-ea5c-6686e8076f78. 
2026-09-08 07:08:01.248 Info Server-0HNOCNNMM76JC:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/.env. 
2026-09-08 07:08:46.035 Info Server-0HNOCNNMM76JD:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/.ftpconfig. 
2026-09-08 07:09:27.432 Info Server-0HNOCNNMM76JE:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/.git/config. 
2026-09-08 07:10:07.256 Info Server-0HNOCNNMM76JF:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/.idea/WebServers.xml. 
2026-09-08 07:10:52.461 Info Server-0HNOCNNMM76JG:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/.remote-sync.json. 
2026-09-08 07:11:36.450 Info Server-0HNOCNNMM76JH:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/.vscode/ftp-sync.json. 
2026-09-08 07:12:13.134 Info Server-0HNOCNNMM76JI:00000001: http/1.1 Response 404 to host23. Time: 0ms. GET http://host3/.vscode/sftp.json. 

They were throwing everything but the kitchen sink at you.

Edited by speechles

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...