Community discussions

MUM Europe 2020
 
yuridee
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 92
Joined: Wed Jun 27, 2012 5:32 am

pptp, info - TCP connection established from

Sat Jan 17, 2015 6:27 am

Hello everybody,

I have PPTP server enabled with a few user name set.

In the log I see the following at random time and random IP (mostly from china):
Log pptp, info - TCP connection established from <IP>
And here is the list of IPs for last 24 hours
112.193.88.167
175.184.153.152
110.241.68.223
183.69.220.53
183.60.48.25
99.229.71.133

There is no indication of usual authentication, encoding, connected, etc. from those IP

Do I have to worry about it?

Thank you,
Yuri
 
farilson
just joined
Posts: 1
Joined: Fri Jun 13, 2008 11:41 pm

Re: pptp, info - TCP connection established from

Sat Jan 17, 2015 12:52 pm

This happening the same.
But I do not have active service.

Tracking. :o
 
User avatar
satman1w
Member Candidate
Member Candidate
Posts: 106
Joined: Mon Oct 02, 2006 11:47 am
Location: Croatia

Re: pptp, info - TCP connection established from

Sun Jan 18, 2015 1:49 am

Hello everybody,

I have PPTP server enabled with a few user name set.

In the log I see the following at random time and random IP (mostly from china):
Log pptp, info - TCP connection established from <IP>
And here is the list of IPs for last 24 hours
112.193.88.167
175.184.153.152
110.241.68.223
183.69.220.53
183.60.48.25
99.229.71.133

There is no indication of usual authentication, encoding, connected, etc. from those IP

Do I have to worry about it?

Thank you,
Yuri

You can copy list of all Chinese IP addresses ( http://www.ipdeny.com/ipblocks/data/countries/cn.zone ) create address list "Hit List" in Mikrotik and add a following firewall rule:
/ip firewall filter
add action=drop chain=input comment="Drop China" protocol=tcp src-address-list=HitList
All the traffic from chinese IP addresses will be dropped !! It is not nice and neat, but it works !!

regards
 
User avatar
mousa1983
Frequent Visitor
Frequent Visitor
Posts: 79
Joined: Mon Apr 21, 2014 2:36 pm
Location: ilam-iran

Re: pptp, info - TCP connection established from

Wed Aug 05, 2015 10:52 am

I Have This problem too!!
 
ithelp
just joined
Posts: 2
Joined: Sun Aug 16, 2015 9:41 pm

Re: pptp, info - TCP connection established from

Sun Aug 16, 2015 9:44 pm

I have the same situation.
See the attached file, is the IP list a solution?
What about new IP's ?
You do not have the required permissions to view the files attached to this post.
 
User avatar
berry2012
newbie
Posts: 38
Joined: Thu Apr 25, 2013 4:07 pm
Location: Nigeria
Contact:

Re: pptp, info - TCP connection established from

Mon Oct 12, 2015 11:21 am

All,

Please this security threat issues needs to be given serious attention.
Is there a bug that Mikrotik tech team needs to fix?

I am having thesame issues and I don't believe so many of us will be doing thesame thing wrong.


The strange thing is that you can see a trace of these IP addresses activities on your network.
I can only see a lot of packets out of my network.


How do we stop this security threat.

Thanks
--
Regards,
Olawale
MTCNA, MTCTCE, MTCRE, MTCUME
 
User avatar
cdiedrich
Forum Veteran
Forum Veteran
Posts: 929
Joined: Thu Feb 13, 2014 2:03 pm
Location: Basel, Switzerland // Bremen, Germany
Contact:

Re: pptp, info - TCP connection established from

Mon Oct 12, 2015 2:43 pm

This is not a bug.
The router accepts a connection - and the PPTP server logs this connection. (And frankly, there are way more connections coming in - not every one of which is logged. Here at work I have about 450k foreign and unwanted connection attemps a day (we have two /28 and one /27 subnets facing outside) - and about 10k a day at home).

So the only thing you can do about this is harden your router and lock it down against your WAN side(s).

Just my 2 cents,
-Chris
Christopher Diedrich
MTCNA, MTCUME, MTCWE
Basel, Switzerland
Bremen, Germany

There are 10 types of people: Those who understand binary and those who don't.
There are two types of people: Those who can extrapolate from incomplete data

Who is online

Users browsing this forum: No registered users and 43 guests