6.42 attacked??

Hi, since last update to v6.42 severals SXT on our network, was infected/modified creating PPPoE server itself, and now our pppoe-clients are connected to “false” servers with http redirects to “Your Internet Connecion has been Hacked”!!

If i make a PPPoE scan on a CPE client, i can see several PPPoE servers called “server”

Any suggestion/help?

Thanks!

Maybe you are victim of http://forum.mikrotik.com/t/winbox-vulnerable-unusual-login-to-routers/118695/1

Hi BartoszP, may be the problem was the same, but in my case, all infected CPE are now PPPoE server with AC-NAME=Mikrotik and service name=server.

When i try to log in to CPE i get invalid username/password..

If you need additional info, please tell me.

Thanks.

You might want to follow this thread: http://forum.mikrotik.com/t/winbox-vulnerable-unusual-login-to-routers/118695/1