Jump to content

Had some kind of break of security today so I installed Malware Anti-bytes. It detected Emby related things.


Recommended Posts

Uncle_Frank
Posted

NEVER open ports for any reason not ever

  • Disagree 3
Uncle_Frank
Posted
3 minutes ago, crusher11 said:

Opening ports is how you allow remote connections. Opening a port is not, in and of itself, a problem. And if there's malware or something on the machine closing the port will do nothing to remove it.

Stop giving bad advice, stop abusing other users.

Stop TROLLING just go back to irc and troll there

  • Disagree 1
Lessaj
Posted

Port 8096 open towards Emby Server is a very low surface attack area for privilege escalation and I don't believe it's an actual attack vector barring undiscovered/unreported vulnerabilities. At most an attacker could capture the unencrypted HTTP traffic and jack user credentials upon auth, or grab an API key from the address, which can grant them access to Emby Server, but not to the server machine itself. They would still need to be in a position to capture that traffic outside the network. Ideally, HTTPS should be used if you're going to open ports to encrypt communications, but nothing inherently wrong with opening 8096 and using HTTP.

Based on what was provided by the OP, the executable for Emby Theater was flagged and whether that is false or not it's still unrelated to the details provided - though my comment of Emby Theater running with old vulnerable code still stands, and hence recommending to use Emby for Windows instead. The further details provided indicated an attempt from that IP to connect to their Emby Server and was blocked by Malware Bytes. There are scanners all over the internet that will try to probe for open ports, so I would say Malware Bytes did its job to block it - it's essentially a type of NID (network intrusion detection). Yes, you can get around opening ports by using something like Tailscale but it's not inherently bad to open ports.

However the further details indicating Discord being hacked/CC charges, that can indicate that the system has some kind of keylogger, or was cookie-jacked - depending on if you're using MFA with Discord or not. That could have been some other malicious website or link you clicked on. Closing 8096 is unrelated to that.

  • Disagree 1
  • Agree 2
crusher11
Posted
12 minutes ago, Lessaj said:

Based on what was provided by the OP, the executable for Emby Theater was flagged and whether that is false or not it's still unrelated to the details provided

I contacted Malwarebytes about it some time ago when I got hit with the same thing, and they looked into it and confirmed it was a false positive. They said they'd removed it from their database, but evidently not.

I really need to get around to uninstalling Emby Theater. I've been ignoring malware warnings from Malwarebytes for way too long at this point, under the assumption this false positive is all it is.

  • Disagree 1
  • Thanks 2
Lessaj
Posted
6 minutes ago, Uncle_Frank said:

Wow what a dummy, you care to test me? Ima fire up a linux os inside ram only with NO hard drive run from ram only. I'm trying not to let you idiots push me to the point ima do bad stuff your not worth it, you are losers the people that are good are not you losers.  Emby team is my friends so stop pissing me off

Good luck in your endeavors.

  • Haha 2
Neminem
Posted

Hmm how many posts did Uncle_Frank just write in this thread 🤔

Guess Frank is the irc you flood

  • Disagree 1
Uncle_Frank
Posted

Neminem have a good day 

pwhodges
Posted

You too - enjoy using extra software to avoid opening ports.

I will stick with opening ports which connect to known and trusted software only, which is basically how the Internet works.  

Paul

  • Like 1
sh0rty
Posted (edited)
1 hour ago, Lessaj said:

Port 8096 open towards Emby Server is a very low surface attack area for privilege escalation and I don't believe it's an actual attack vector barring undiscovered/unreported vulnerabilities. At most an attacker could capture the unencrypted HTTP traffic and jack user credentials upon auth, or grab an API key from the address, which can grant them access to Emby Server, but not to the server machine itself. They would still need to be in a position to capture that traffic outside the network. Ideally, HTTPS should be used if you're going to open ports to encrypt communications, but nothing inherently wrong with opening 8096 and using HTTP.

Based on what was provided by the OP, the executable for Emby Theater was flagged and whether that is false or not it's still unrelated to the details provided - though my comment of Emby Theater running with old vulnerable code still stands, and hence recommending to use Emby for Windows instead. The further details provided indicated an attempt from that IP to connect to their Emby Server and was blocked by Malware Bytes. There are scanners all over the internet that will try to probe for open ports, so I would say Malware Bytes did its job to block it - it's essentially a type of NID (network intrusion detection). Yes, you can get around opening ports by using something like Tailscale but it's not inherently bad to open ports.

However the further details indicating Discord being hacked/CC charges, that can indicate that the system has some kind of keylogger, or was cookie-jacked - depending on if you're using MFA with Discord or not. That could have been some other malicious website or link you clicked on. Closing 8096 is unrelated to that.

E.g. Cisco scanned their firmwares (router, firewalls, switches) recently with Mythos before attackers will do it resulting in a shitload of CVEs no one found for years. I would not in the slightest way believe that an open http port is or will be no big attack vector, specially for attackers/spoofers that use AI to search for vulnerabilities. In 2026 running any port with unencrypted traffic inbound to a service without proper restrictions like WAF etc. is a big no no. Simply no.

Edited by sh0rty
Posted
24 minutes ago, sh0rty said:

E.g. Cisco scanned their firmwares (router, firewalls, switches) recently with Mythos before attackers will do it resulting in a shitload of CVEs no one found for years. I would not in the slightest way believe that an open http port is or will be no big attack vector, specially for attackers/spoofers that use AI to search for vulnerabilities. In 2026 running any port with unencrypted traffic inbound to a service without proper restrictions like WAF etc. is a big no no. Simply no.

I don't disagree, HTTPS should be used when possible, but I don't think it has anything to do with what's being discussed in this thread RE: other services like their Discord having been hacked. Looks like the connection to their server was a bog standard port scan that was being blocked by Malware Bytes.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...