Forum Discussion

Doug9's avatar
Doug9
Friendly Neighbour
25 days ago
Solved

Massive reported network traffic on MyTelus?

I have fibre service with an NH20A in bridge mode to my own modem. I have nothing plugged into the other NH20A ports. I am seeing massive internet usage when I log into MyTelus, much higher than the activity reported by my router.

At first, I thought that my router had picked up a botnet, as it was an ASUS RT-AX88U Pro that was part of the vulnerability discussed at:

https://www.tomsguide.com/news/arcadyan-router-malware

... so I did the factory reset on my ASUS, and rebooted it daily, but the problem reappeared. 

So recently, I got fed up and purchased an Ubiquity UCG Ultra to replace the ASUS.

I still see the massive data transfers on the Telus web site. For example, I show total usage so far today of 3924.27 GB on the telus web site, but only 14.8 GB for the last 24 hours on my Unify dashboard.

I'd like to update the firmware on the NH20A and maybe do a factory reset. Are there any risks to doing this? Will the admin password printed on the NH20A still be in effect?

Any other ideas on what could be causing this would be most welcome.

Thanks for reading.

 

 

  • Just an update. I didn't do a factory reset, but I rebooted the NH20A and things look good ever since. HOWEVER, this is interesting: I went back onto the MyTelus site today and the big usage numbers shown above for Nov 6 to 10 are no longer shown AT ALL, THOSE DATES ARE COMPLETELY MISSING missing from the usage report. I suspect that Telus discovered that their system was reporting bogus usage numbers and got rid of the erroneous data.

9 Replies

  • Doug9's avatar
    Doug9
    Friendly Neighbour

    Just an update. I didn't do a factory reset, but I rebooted the NH20A and things look good ever since. HOWEVER, this is interesting: I went back onto the MyTelus site today and the big usage numbers shown above for Nov 6 to 10 are no longer shown AT ALL, THOSE DATES ARE COMPLETELY MISSING missing from the usage report. I suspect that Telus discovered that their system was reporting bogus usage numbers and got rid of the erroneous data.

  • Doug9's avatar
    Doug9
    Friendly Neighbour

    It is on the My Telus Web page under usage details, a list, not a graph. I posted a picture, but it might not show because I'm new here. Not using peer-to-peer file sharing.

    • FuzzyLogic's avatar
      FuzzyLogic
      Icon for Community Power User rankCommunity Power User

      Very strange. Not sure what else to suggest unless you see some patter in the usage details.

      • Doug9's avatar
        Doug9
        Friendly Neighbour

        Rebooting the NH20A seems to have helped.

         

  • Doug9's avatar
    Doug9
    Friendly Neighbour

    I see it on My Telus Web, see attached image. I can only see the daily usage if I select the Past Cycle usage first. Not peer to peer or file sharing.  

     

  • Doug9's avatar
    Doug9
    Friendly Neighbour

    Oh, forgot to mention that the NH20A was also identified in the botnet vulnerable devices on the TomsGuide link shown above, which leads me to suspect it is the problem.

    • FuzzyLogic's avatar
      FuzzyLogic
      Icon for Community Power User rankCommunity Power User

      I don't have a NH20A to confirm but since this vulnerability was reported in 2021 I would suspect that Telus has rolled out and update to the firmware long ago.

      You normally don't need to do anything as this would be pushed out by Telus.

      Doing a factory reset should not cause any issues. If you have any customizations they will be lost. The password should be on the router unless you have changed it.

      I believe a factory reset will restore the password to the one listed on the router.

      Where exactly are you seeing this large data transfers? Are you referring to the Data Usage graph that Telus provides? Are you running any form of peer-to-peer file sharing?