Router exposed to internet over night

While setting up my new router (CCR1009..) I left it exposed for some hours to the internet with default user and password and telnet and ssh services enabled.
I found several successful logins in the log and command history in Terminal contained commands like ts; /bin/BusyBox XYZD.
I have now reset configuration (/system reset-configuration), changed login credentials and disabled telnet and ssh. Is this sufficient or is it likely that malicious software have been installed?

Any recommended actions?

You don’t say what version of ROS it was running… to be safest, you should netinstall unit entirely.

Absolutely suspect the router is infected and as noted netinstall is the only way redo this safely.

Thank’s for the advice.

It was running 6.46.4 at the time and I will reinstall with Netinstall ASAP.

Hi, I don’t understand how does someone know when a router is exposed to the internet?
Are they constantly scanning standard ports on all IP addresses around the world?

I’ve configured couple of MikroTik devices and they are connected to the internet for remote access, didn’t ever see anyone trying to connect.
Although I’ve disabled all standard services and ports. Only opened is winbox on a specific port, default admin users deleted and new ones created, I believe it’s more complicated to guess the username than password :slight_smile:

The default firewall in the default configuration protects the router if you connect to the internet via the default port (ether1). However, if you are playing with your own custom configurations or firewall rules, and hook up through an unprotected port, your router is visible to hackers who indeed are constantly scanning for anything they can get their hooks into. If you log rejected traffic on your (protected) router, you will see how prevalent this is. It’s unsettling, like your first view of pond water through a microscope.

It’s necessary to add: default firewall on pro line of devices (CCR, RB1xxx, possibly some others) is empty (it is assumed that experienced admins who know their jobs will be configuring those devices) and it’s pretty easy to expose unprotected router to internet. OP has a CCR.