While setting up my new router (CCR1009..) I left it exposed for some hours to the internet with default user and password and telnet and ssh services enabled.
I found several successful logins in the log and command history in Terminal contained commands like ts; /bin/BusyBox XYZD.
I have now reset configuration (/system reset-configuration), changed login credentials and disabled telnet and ssh. Is this sufficient or is it likely that malicious software have been installed?
Hi, I don’t understand how does someone know when a router is exposed to the internet?
Are they constantly scanning standard ports on all IP addresses around the world?
I’ve configured couple of MikroTik devices and they are connected to the internet for remote access, didn’t ever see anyone trying to connect.
Although I’ve disabled all standard services and ports. Only opened is winbox on a specific port, default admin users deleted and new ones created, I believe it’s more complicated to guess the username than password
The default firewall in the default configuration protects the router if you connect to the internet via the default port (ether1). However, if you are playing with your own custom configurations or firewall rules, and hook up through an unprotected port, your router is visible to hackers who indeed are constantly scanning for anything they can get their hooks into. If you log rejected traffic on your (protected) router, you will see how prevalent this is. It’s unsettling, like your first view of pond water through a microscope.
It’s necessary to add: default firewall on pro line of devices (CCR, RB1xxx, possibly some others) is empty (it is assumed that experienced admins who know their jobs will be configuring those devices) and it’s pretty easy to expose unprotected router to internet. OP has a CCR.