hello rulers of Mikrotik planet just wondering here if there is a method or script to block any range of mac addresses by vendors let say i want to block all tp-link or all d-link or all belkin mac addresses to lower the risk of anyone connecting with these devices to my network,is it possible ? can...
hello rulers of Mikrotik planet just wondering here if there is a method or script to block any range of mac addresses by vendors let say i want to block all tp-link or all d-link or all belkin mac addresses to lower the risk of anyone connecting with these devices to my network,is it possible ? can...
Quote "we bounced the user off their own AP, and now when they re-authenticate, airodump-ng will attempt to grab their password in the new 4-way handshake."
what to do to stop users on my network from getting bounced and get the deauth ?
my router ip range is 100.0.0.0/24 this ip 192.168.15.1 is over a maximum of 30 hops it means it is not on my network ! did i mention that my public ip starts with 41.xx.xx.xx and i use opendns ips for dns which are Primary DNS 208.67.222.222 Secondary DNS 208.67.220.220 i checked the router log 100...
check this out guys i ran a traceroute from my 3com router's GUI and recieved this Tracing route to 192.168.15.1:33435 over a maximum of 30 hops, waiting timeout 5000 ms: 1 100 ms 100 ms 100 ms 163.121.170.34 2 * * * Request timed out. 3 * * * Request timed out. 4 100 ms 100 ms 100 ms 10.37.243.185 ...
i use 3Com router code 3CRWDR101A-75 Software version 1.12.04.A (10 Sep 2010 17:19:34) the router has 4 ports and a wifi ,i use 2 ports for 2 mikrotik servers and the wifi for a belkin with ddwrt firmware and an LG smart TV now forget all that and focus there is a weird IP that doesn't belong to any...
i have mikrotik 3.30 with 2 tp-link wireless cards dhcp server is runing with range 10.0.0.0/24 i made a logical bridge from the bridge menu then added the 2 wireless interfaces in ports menu i made first and second tp-link cards with different ssid names i have a web server runing and connected to ...
yeah! smart idea to block by ip but what if it is a secure link for some ads on youtube.com....you think if i block by ip my users will be able to access youtube.com ?
and for Chupaka i say to him when i said i know how to bock regular http links, i mean "it is a hint"
in simple words : i want to block these links ....how? https://www.youtube.com/subscribe_widget?adformat=2_2_1&p=SpKWMSmL8m-0XXqaPGtQKw&render=video_wall_companion it will be perfect to block anything under "https://www.youtube.com/subscribe_widget?adformat=" also https://ads.ak.fa...
how to send warning ads messages to users infected with pseudo-random domains that is blocked by names in the mikrotik's webproxy? if a random user's pc on the network keeps connecting to a well known infected website that is blocked by mikrotik sever's webproxy ,why not block that website from the ...
The Conficker worm can also disable important services on your computer. Blocking Conficker Domain Names: Will It Work? One important effort to try and stop the Conficker worm from being activated by its creators on April 1 and beyond is blocking the domain names that it may use for… Read full vers...
thanks richinuk for the good info some networks have some careless users and therefor i intend to blacklist these domains on mikrotik website you said 50 000 domain names ,can you provide me with a link to the list? the question is how the hackers registered all of these domain names and where are t...
well... what about normal people not expert people?! i mean comon how can you block a conficker worm and protect your users on a the local network even when you ask them to block the well known ports for it too? i have seen people with closed ports getting it too,it just changes it self everday and ...
here is a Second Shot with different servers /ip proxy access add action=deny comment="" disabled=no dst-host=*hcpckvlo.info* redirect-to=127.0.0.1 add action=deny comment="" disabled=no dst-host=*grpdkzm.info* redirect-to=127.0.0.1 add action=deny comment="" disabled=n...
how to force your users to watch youtube in 240p? is it a script or a layer7 + mangle ? i want my users when they go to watch anything on youtube to watch it at 240p then they can choose from the youtube drop down menu button any other quality ! or just redirect every high quality videos on youtube ...
Impact in Europe Intramar, the French Navy computer network, was infected with Conficker on 15 January 2009. The network was subsequently quarantined, forcing aircraft at several airbases to be grounded because their flight plans could not be downloaded. The United Kingdom Ministry of Defence report...
"Now, if you want to force ALL PAGES to be HTTPS... then you can do that in the facebook settings for each individual facebook user. Then, EVERYTHING is SSL."
okay!
so can it be done from mikrotik proxy by redirecting some facebook links or any other way?
is there any way or even a scheduled mikrotik script to reset the mac address of all joined users by returning its values to factory defaults,and not related to dhcp scripts? is there an html script that can be run as ads in the mikrotik server to reset the mac address of all joined users by returni...
i mean how to be able to run exe files located in the mikrotik server cache,open cached jpeg ,watch cached movies or copy entire mikrotik cache folder to my local pc?
So much lols zomg BTW that youtube vid of WPA hacking.. is a joke, lmao have you used backtrack or cain correctly? this is just the simple use for users with simple passwords,there are more methods but kept for self use http://www.irongeek.com/videos/airpcap-cain-wpa-cracking.swf just learned 6 mon...
the script is correct which is # DNSoMatic automatic DNS updates # User account info of DNSoMatic :global maticuser "user" :global maticpass "password" :global matichost "Yourhost" # No more changes need :global previousIP # Print values for debug :log info "DNSoMa...
suddenly my dnsomatic stopped working 2 days ago,as i investigated the issue i found that the script depending on dnsomatic to update opendns failed for some reasons one of them is because of the line checkip.dyndns.org requests checkip.dyndns.org shows local ip instead of the public ip i need an ad...
may be in Brazil there are lots of criminals ,but in our situation we need that option to limit users that are not on our network from trying get the identity of the network runing in the air.
/ip firewall layer7 add name=ip regexp="your Real IP" /ip firewall filter add action=drop layer7-protocol=ip But this code have problen, not all browser can open websites content your ip firewall chain is forward correct? can i use the true static ip address"bla.bla.bla.bla" ins...
i am sure that a script can do the job ,just remember guys everything is possible in the pc world,just how to do it,or how it can be done? i am thinking to redirect codes that include the the word "your ip address" into a local page with some scary words about safety! can it be done? http:...
how to hide the public ip address from network users so if any user visited google or any websites like let say "whatismyip.com" he gets his local ip on the network. i don't know how to do it and not sure if it can be done by a script or the proxy of the mikrotik server. in simple english ...
thank you fewi "I HAVE DONE IT!" just came back to tell you and without too much talking and in short words steps are: 1- a full working primary mikrotik hotspot server to handle all http requests from a slave mikrotik server with enabled (ap bridge) b/g mode wireless cards with automatic ...
why not leave the hotspot but instead of it redirecting people to the mikrotik ftp's login page it redirect them to an external html page on a local webserver ?
is it possible for anyone to be able to connect to my wireless mikrotik hotspot without seeing the login page and automatically gets connected to the internet without me using a bypassing command since the users will be with unknown mac and dunamic ips? without even using the trial hotspot in plan t...
can it be done without the existence of external router or external dns? i mean dhcp can use pool range 10.0.0.0/24 only ,also static dns can be used and no need to creat a hotspot login pages i guess only a redirect html page of free trial with direct link to to 10.0.0.10 in mikrotik's ftp what do ...
all i want is when people join my network via wireless access that is controlled by mikrotik server,when they open there browser mikrotik direct them to the webserver with or without a login page
while eating my dinner i asked myself a question "is it possible to let mikrotik be a gateway for an internal webserver only?" in simple words i want to broadcast a webserver as a hotspot in my area without offering internet access....so if it is possible then how? the webserver ip is 10.0...
that is true it blocks some ad webpages known for infecting people with viruses and spywares and on some porn websites it injects trojans. you should read more about doubleclick ,rad.msn and macromedia flash injections if you need help just go to: http://www.youtube.com/watch?feature=player_embedded...
on the wireless adaptor only ,MFP is to protect RouterOS to RouterOS from deauth attack but not to protect RouterOS to end users from MAC address cloning issue or deauth attack.
Hacker can use same MAC address as legitimate user, so blocking by MAC address is not very good solution. i agree with you ,same as the mikrotik hotspot user account too it uses mac auth +username+pass+ip address by the way.. any good news on the mac duplications issue as you call it "MAC addr...
but still 00:00:00:00:00:00 mac address is a risk for being not able to block it from attacking the network! at least you can block any other macs...correct? just remember running a hotspot with a log in page will be useless this way! i am with you that using WPA-EAP is a way arround the problem i l...
Dear kirshteins 00:00:00:00:00:00 mac address is a security hole in Mikrotik exactly when someone trys to take it either to do an ip scan on the network to get mac addresses of all users or to lunch a dns poisoning attack,you guys should add an option to be able to block any single user from taking ...
oh boy oh boy! MikroTik Support asking me how to block by mac i will tell you how i do it on the wireless network as a beginning from the access list of the wlan adapter add by mac then uncheck both forwarding and Authentication then create any fake private keys this will block any unwanted visitors...
as we all know when we try to change our ip address to use a static ip address in microsoft windows we go for the network connection properties,we also know that entering a new ip address is under some rules and conditions. microsoft windows will refuse letting you put in the first octet any number ...
lol radar detection you mean ? wrong answer DFS with radar detect will change the frequency only when it identify a military radar in it's frequency but not another AP in first case scenario the AP continues searching for the next available channel which is with the lowest so imagine you are in the ...
i chose the broadcast solution i allowed the igmp service from the firewall and the udp protocol too. i went into igmp proxy and chose the nic card that is hooked to the pc with the satellite card as upstream with alternative subnet as 0.0.0.0/0,then i entered the second nic card connected to the se...
i think using a dns service like Opendns.com is a solution,the paid for membership not the free one which allow to add a big list of websites to be blocked or to be reported or to use a 3com officeconnect router with updated spyware and parasites/hijackers/adware/spyware list.
RouterOS only supports ATHEROS wireless chipsets. So, no. does it means that alpha usb wifi adaptor model AWUS036NHA with AR9271 chipset will work ? http://www.alfa.com.tw/in/front/bin/ptdetail.phtml?Part=AWUS036NHA&Category=0 i took a look in http://wiki.mikrotik.com/wiki/Supported_Hardware it...
you should read this to understand what i am trying to do http://www.bestsupertech.com/2010/04/lan-how-to-stream-using-dvb-dream-and.html after reading that how to make mikrotik passes broadcast stream from a regular pc with ip 10.0.0.1 to ip 10.0.0.255 on a small local area network which is control...
i finished reading and became more confused! igmp asm 239.0.0.0/8 ssm 232.0.0.0/8 PIM-SM Sender -- (subnet I) --> Router A -- (subnet II) --> Router B -- (subnet III) --> Receiver yukkkkkkkkkkkkkk sorry for that but all i need is Sender with dvbdream--> 1 Mikrotik Router --> Receiver with vlc client...
thanks but i am kinda confused please give me some commands to put it directly in new terminal so i can understand our network config is: 10.0.0.0/24 our mikrotik dhcp server ip is 10.0.0.254 our subnet is 255.255.255.0 our default gateway is 192.168.100.1 our dns servers are 192.168.100.2 and 192.1...
we have a working satellite dish card connected to a pc in our network that is controlled by mikrotik pc server the pc is using a program called dvbdream to navigate between satellite channels which also include an option to stream live to the local network using a protocol called UDP ts on port 123...
every time i try to stream a video to all my network members throught ip 10.0.0.255 using vlc player's streaming option my pc gets blocked from internet access!
how to allow vlc player's rstp protocol to work without issues?
dear mikrotik staff a week ago many people on my wireless network started to suffer from a power surge windows warning messages other people complained too that their laptop wireless network cards became very very hot as soon as they connect to my network one female user on my wireless network calle...