Router Compromised - Security flaw ?

So, router was accessed using it’s private IP, right? That means he knows port forwarding of core router.
I bet he knows password too, how he does it’s another story.

In ten years I have worked with mikrotik, since ROS 2.9.x , I have never encountered a case where routerboard was compromised with just two attempts (never seen any compromised for what is worth). Changing default user, like you have done later, and good password will never let any gain access on to it, more so when presumed hacker can not access the router physically.

I am 99.9% convinced this is not a bug in ROS security, but rather who gained access knows user and password. I am not saying ROS is unbreakable, there is no such thing, but in this case I am almost sure the “hacker” knew credentials.

no, and there is not a port forward to this router (dstnat)

A small extract from yesterdays log for attempted 8291 access:

/var/log/2017/08/15/x.x.x.x/log:16077:Aug 15 00:51:08 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (ACK,RST), 216.59.251.67:19441->y.y.y.y:8291, len 40
/var/log/2017/08/15/x.x.x.x/log:16087:Aug 15 00:51:11 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (ACK,RST), 216.59.251.67:19441->y.y.y.y:8291, len 40
/var/log/2017/08/15/x.x.x.x/log:16102:Aug 15 00:51:17 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (ACK,RST), 216.59.251.67:19441->y.y.y.y:8291, len 40
/var/log/2017/08/15/x.x.x.x/log:32290:Aug 15 01:55:26 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether3, src-mac mac.mac.mac, proto TCP (SYN,ACK), 158.69.122.195:10110->z.z.z.z:8291, len 40
/var/log/2017/08/15/x.x.x.x/log:33642:Aug 15 01:59:19 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33649:Aug 15 01:59:21 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33653:Aug 15 01:59:22 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33661:Aug 15 01:59:25 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33664:Aug 15 01:59:25 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33672:Aug 15 01:59:28 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33683:Aug 15 01:59:31 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33691:Aug 15 01:59:34 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33697:Aug 15 01:59:37 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33711:Aug 15 01:59:42 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33736:Aug 15 01:59:49 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:33776:Aug 15 02:00:06 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:73135:Aug 15 04:40:03 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether4, src-mac mac.mac.mac, proto TCP (RST), 45.77.69.175:80->w.w.w.w:8291, len 40
/var/log/2017/08/15/x.x.x.x/log:122499:Aug 15 07:47:58 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122501:Aug 15 07:47:59 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122510:Aug 15 07:48:01 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122516:Aug 15 07:48:03 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122518:Aug 15 07:48:04 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122527:Aug 15 07:48:07 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122543:Aug 15 07:48:10 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122565:Aug 15 07:48:13 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122573:Aug 15 07:48:16 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122586:Aug 15 07:48:20 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122602:Aug 15 07:48:29 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:122646:Aug 15 07:48:45 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 51.254.120.95:33111->v.v.v.v:8291, len 44
/var/log/2017/08/15/x.x.x.x/log:144585:Aug 15 09:12:41 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 2.98.37.184:53094->t.t.t.t:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:144596:Aug 15 09:12:44 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 2.98.37.184:53094->t.t.t.t:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:145079:Aug 15 09:12:51 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (SYN,ACK), 2.98.37.184:53094->t.t.t.t:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:145106:Aug 15 09:13:03 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether12, src-mac mac.mac.mac, proto TCP (RST), 2.98.37.184:53094->t.t.t.t:8291, len 40
/var/log/2017/08/15/x.x.x.x/log:146253:Aug 15 09:18:28 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether6, src-mac mac.mac.mac, proto TCP (SYN,ACK), 84.53.132.200:80->u.u.u.u:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:146254:Aug 15 09:18:28 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether6, src-mac mac.mac.mac, proto TCP (SYN,ACK), 84.53.132.200:80->u.u.u.u:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:146259:Aug 15 09:18:30 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether6, src-mac mac.mac.mac, proto TCP (SYN,ACK), 84.53.132.200:80->u.u.u.u:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:146265:Aug 15 09:18:31 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether6, src-mac mac.mac.mac, proto TCP (SYN,ACK), 84.53.132.200:80->u.u.u.u:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:146280:Aug 15 09:18:35 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether6, src-mac mac.mac.mac, proto TCP (SYN,ACK), 84.53.132.200:80->u.u.u.u:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:146305:Aug 15 09:18:43 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether6, src-mac mac.mac.mac, proto TCP (SYN,ACK), 84.53.132.200:80->u.u.u.u:8291, len 52
/var/log/2017/08/15/x.x.x.x/log:146339:Aug 15 09:18:59 x.x.x.x firewall,info wbox8291 forward: in:bond1 out:ether6, src-mac mac.mac.mac, proto TCP (SYN,ACK), 84.53.132.200:80->u.u.u.u:8291, len 52

I do usually add these rules on firewall filter, got them from wiki:

add action=drop chain=forward comment="Drop invalid packets" \
    connection-state=invalid disabled=no
add action=drop chain=input comment="" connection-state=invalid disabled=no
add action=drop chain=output comment="" connection-state=invalid disabled=no
add action=drop chain=input comment="drop ssh brute force login" disabled=no \
    dst-port=22 protocol=tcp src-address-list=ssh_blaclist
add action=add-src-to-address-list address-list=ssh_blaclist \
    address-list-timeout=1w3d chain=input comment="" connection-state=new \
    disabled=no dst-port=22 protocol=tcp src-address-list=ssh_stage3
add action=add-src-to-address-list address-list=ssh_stage3 \
    address-list-timeout=5m chain=input comment="" connection-state=new \
    disabled=no dst-port=22 protocol=tcp src-address-list=ssh_stage2
add action=add-src-to-address-list address-list=ssh_stage2 \
    address-list-timeout=1m chain=input comment="" connection-state=new \
    disabled=no dst-port=22 protocol=tcp src-address-list=ssh_stage1
add action=add-src-to-address-list address-list=ssh_stage1 \
    address-list-timeout=1m chain=input comment="" connection-state=new \
    disabled=no dst-port=22 protocol=tcp
add action=drop chain=input comment="drop ftp brute forcers" disabled=no \
    dst-port=21 protocol=tcp src-address-list=ftp_blacklist
add action=accept chain=output comment="" content="530 Login incorrect" \
    disabled=no dst-limit=1/1m,9,dst-address/1m protocol=tcp
add action=add-dst-to-address-list address-list=ftp_blacklist \
    address-list-timeout=3h chain=output comment="" content=\
    "530 Login incorrect" disabled=no protocol=tcp
add action=drop chain=input comment="drop Winbox brute force login" disabled=\
    no dst-port=8291 protocol=tcp src-address-list=winbox_blaclist
add action=add-src-to-address-list address-list=winbox_blaclist \
    address-list-timeout=1d chain=input comment="" connection-state=new \
    disabled=no dst-port=8291 protocol=tcp src-address-list=winbox_stage3
add action=add-src-to-address-list address-list=winbox_stage3 \
    address-list-timeout=5m chain=input comment="" connection-state=new \
    disabled=no dst-port=8291 protocol=tcp src-address-list=winbox_stage2
add action=add-src-to-address-list address-list=winbox_stage2 \
    address-list-timeout=1m chain=input comment="" connection-state=new \
    disabled=no dst-port=8291 protocol=tcp src-address-list=winbox_stage1
add action=add-src-to-address-list address-list=winbox_stage1 \
    address-list-timeout=1m chain=input comment="" connection-state=new \
    disabled=no dst-port=8291 protocol=tcp
add action=drop chain=input comment="drop Telnet brute force login" disabled=\
    no dst-port=23 protocol=tcp src-address-list=telnet_blaclist
add action=add-src-to-address-list address-list=telnet_blaclist \
    address-list-timeout=1w3d chain=input comment="" connection-state=new \
    disabled=no dst-port=23 protocol=tcp src-address-list=telnet_stage3
add action=add-src-to-address-list address-list=telnet_stage3 \
    address-list-timeout=5m chain=input comment="" connection-state=new \
    disabled=no dst-port=23 protocol=tcp src-address-list=telnet_stage2
add action=add-src-to-address-list address-list=telnet_stage2 \
    address-list-timeout=1m chain=input comment="" connection-state=new \
    disabled=no dst-port=23 protocol=tcp src-address-list=telnet_stage1
add action=add-src-to-address-list address-list=telnet_stage1 \
    address-list-timeout=1m chain=input comment="" connection-state=new \
    disabled=no dst-port=23 protocol=tcp
add action=drop chain=input comment="Drop DNS Requests from outside" \
    dst-port=53 in-interface=ether1 protocol=udp
add action=drop chain=input dst-port=53 in-interface=ether1 protocol=tcp

Change time and in-interface accordingly. Beware though, that you might left yourself out of the router after three failed attempts

Those are NOT attempts to access your router! I have filtered such packets from my trace before I said there were no connects, I had about 4300 packets in my trace before that.

What you see there is replies to outgoing traffic that happens to have source port number 8291 at your side (the source port number is random), or backscatter from
traffic send by others that spoof your external address as their source address for DDoS attacks etc. This traffic is not to be counted for this purpose.

You need to look for lines like this:

11.22.33.44 → x.x.x.x TCP 66 39246→8291 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1

Note only the SYN and no other flags (such as ACK or RST).

ok thanks, can I stop them appearing in my log ?

Maybe filter them in the syslog server or do a selective search (e.g. using “grep”) on the resulting logfile.

When you use a firewall, you can limit the output by logging only “new” connections.
I did not use a firewall rule with logging, but a trace on a mirrored switchport using wireshark on a PC.