Community discussions

MikroTik App
 
darkuek
just joined
Topic Author
Posts: 9
Joined: Wed Dec 05, 2018 6:16 pm

Hacked recently

Mon Jun 10, 2019 12:39 pm

Hello, some of my accounts got hacked i start enabling 2FA. i wonder if my Forwarding played a role and if the hacker could access my router and bridge settings and edit/add rules.
Ports 0-65535 TCP and UDP

Best regards.
You do not have the required permissions to view the files attached to this post.
 
User avatar
krafg
Forum Guru
Forum Guru
Posts: 1021
Joined: Sun Jun 28, 2015 7:36 pm

Re: Hacked recently

Wed Jun 12, 2019 7:42 pm

Update your ROS to latest version and change admin password.

Regards.
 
craigreilly
newbie
Posts: 46
Joined: Mon Jan 26, 2015 7:04 pm

Re: Hacked recently

Wed Jun 12, 2019 8:37 pm

change the username too...
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19372
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Hacked recently

Wed Jun 12, 2019 11:23 pm

Incorrect advice, first we dont know what firmware he had to begin with so its an assumption not fact if his firmware is or is not up to date.
Secondly, if there is hacked firmware the only 'safe' method for an update or reset is to dowload a clean copy of the latest firmware and apply it via netinstall!!

As to the setup, it appears you have attempted to create a "DMZ" to one of your PCs. Basically forwarded all ports to one device.
In general thats a urine poor idea for any config. Why was it necessary???
In addition it is not clear if you segmented that computer from accessing any Router Resources (input chain) or any other LAN devices (filter firewall).
Without seeing the whole config, it would just be more speculation which is teat useless.
 
darkuek
just joined
Topic Author
Posts: 9
Joined: Wed Dec 05, 2018 6:16 pm

Re: Hacked recently

Sat Jun 15, 2019 2:31 pm

Incorrect advice, first we dont know what firmware he had to begin with so its an assumption not fact if his firmware is or is not up to date.
Secondly, if there is hacked firmware the only 'safe' method for an update or reset is to dowload a clean copy of the latest firmware and apply it via netinstall!!

As to the setup, it appears you have attempted to create a "DMZ" to one of your PCs. Basically forwarded all ports to one device.
In general thats a urine poor idea for any config. Why was it necessary???
In addition it is not clear if you segmented that computer from accessing any Router Resources (input chain) or any other LAN devices (filter firewall).
Without seeing the whole config, it would just be more speculation which is teat useless.
You do not have the required permissions to view the files attached to this post.
 
darkuek
just joined
Topic Author
Posts: 9
Joined: Wed Dec 05, 2018 6:16 pm

Re: Hacked recently

Sat Jun 15, 2019 2:34 pm

Incorrect advice, first we dont know what firmware he had to begin with so its an assumption not fact if his firmware is or is not up to date.
Secondly, if there is hacked firmware the only 'safe' method for an update or reset is to dowload a clean copy of the latest firmware and apply it via netinstall!!

As to the setup, it appears you have attempted to create a "DMZ" to one of your PCs. Basically forwarded all ports to one device.
In general thats a urine poor idea for any config. Why was it necessary???
In addition it is not clear if you segmented that computer from accessing any Router Resources (input chain) or any other LAN devices (filter firewall).
Without seeing the whole config, it would just be more speculation which is teat useless.
I didnt dowload a clean copy but i closed trhe ports he cant log in i guess
 
Pea
Member Candidate
Member Candidate
Posts: 233
Joined: Fri Jul 17, 2015 11:07 pm
Location: Czech

Re: Hacked recently

Sat Jun 15, 2019 2:58 pm

Why do you think someone hacked in?
Your log shows only failed logins due to your poor firewall. You should rethink your firewall and running services.
 
User avatar
krafg
Forum Guru
Forum Guru
Posts: 1021
Joined: Sun Jun 28, 2015 7:36 pm

Re: Hacked recently  [SOLVED]

Sat Jun 15, 2019 7:56 pm

To not get anymore these logs, go to IP -> Services and limit the access to local network or disable that you don't need.

Regards.

Who is online

Users browsing this forum: No registered users and 106 guests