Community discussions

MikroTik App
 
zriah
just joined
Topic Author
Posts: 4
Joined: Sat Jun 02, 2018 8:11 pm

Blocking Virus from Mikrotik

Sat Jun 02, 2018 8:29 pm

There is a web-based virus on mikrotik. When clients type address, it says "your connection is not hidden" NET:ERR_CERT_AUTHORITY_INVALID"
Then try to reload, it redirected to sohu.com address. Anyone else had trouble with this? Or how can i fix these?
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2880
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 10:23 pm

Are you sure taht it is Mikrotik problem? Have you tried other router?
 
msatter
Forum Guru
Forum Guru
Posts: 2912
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 10:28 pm

When I search for sohu.com I find this:

viewtopic.php?f=2&t=68290&hilit=Sohu.com
 
R1CH
Forum Guru
Forum Guru
Posts: 1101
Joined: Sun Oct 01, 2006 11:44 pm

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 10:47 pm

Perhaps your router was compromised and an attacker is intercepting your DNS.
 
zriah
just joined
Topic Author
Posts: 4
Joined: Sat Jun 02, 2018 8:11 pm

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 10:49 pm

Are you sure taht it is Mikrotik problem? Have you tried other router?
Totally sure, other router has no problem like this. Only mikrotik connections are being effected.
 
zriah
just joined
Topic Author
Posts: 4
Joined: Sat Jun 02, 2018 8:11 pm

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 10:58 pm

Perhaps your router was compromised and an attacker is intercepting your DNS.
I can connect couple websites, not all of them. Also, on Apple devices, it redirects to a fake apple security (apple id) page.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2880
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 11:21 pm

What is DNS setting for these clients?
What is DHCP server setting in Mikrotik?
Are you sure that router redirects pages?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19380
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 11:23 pm

If you let the web into your mikrotik, anything is possible!

Follow these instructions................
https://wiki.mikrotik.com/wiki/Manual:S ... our_Router
 
zriah
just joined
Topic Author
Posts: 4
Joined: Sat Jun 02, 2018 8:11 pm

Re: Blocking Virus from Mikrotik

Sat Jun 02, 2018 11:46 pm

What is DNS setting for these clients?
What is DHCP server setting in Mikrotik?
Are you sure that router redirects pages?
Clients uses Google DNS (8.8.8.8 and 8.8.4.4) Also, changed to another DNS but still same issue.
DHCP Settings: 10.10.24.0/20

I don't sure about mikrotik redirects pages. But it's being affected by only mikrotik clients on the WAN. The other networks are not affecting. Clients can uses instagram, whatsapp,youtube etc. applications on their devices. Only most of HTTP and HTTPS redirects.
 
henry81
just joined
Posts: 3
Joined: Sun Jun 03, 2018 4:42 pm

Re: Blocking Virus from Mikrotik

Sun Jun 03, 2018 4:48 pm

Is this issue address? I have same issue like this and i keep resetting the device which is not good.
 
henry81
just joined
Posts: 3
Joined: Sun Jun 03, 2018 4:42 pm

Re: Blocking Virus from Mikrotik

Thu Jun 21, 2018 12:37 am

Any update on this issue? this is so prostrating. Mikrotik need to address this issue.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2880
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Blocking Virus from Mikrotik

Thu Jun 21, 2018 1:25 am

Check this: viewtopic.php?f=21&t=134776
Do you have updated ROS?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19380
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Blocking Virus from Mikrotik

Thu Jun 21, 2018 4:48 am

Download the software upgrade for the OS. Remove your router from the internet, Upgrade your OS to the latest version, change all your passwords, do not use the same ones you used before and change the admin name as well.
And use the links provided to better secure the router. Dont allow external connections to the router itself and if you have to use VPN tunnels.
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1120
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: Blocking Virus from Mikrotik

Thu Jun 21, 2018 4:33 pm

OP please post your current running config. This may be something such as a DNS hijack but could be significantly worse if your router is genuinely compromised.
 
henry81
just joined
Posts: 3
Joined: Sun Jun 03, 2018 4:42 pm

Re: Blocking Virus from Mikrotik

Sun Jun 24, 2018 3:46 pm

So this means Mikrotik is easy to hack than other router devices. I only experience this one in mikrotik device, and how come when resetting it will fix the problem and back again after a month? fyi password has been change already.
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 897
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: Blocking Virus from Mikrotik

Sun Jun 24, 2018 3:52 pm

MikroTik already addressed this issue in all release channels. Just upgrade to the latest version, set a new password and check your configuration to be sure.

If you continue having problems despite upgrading, send supout.rif to support.

Who is online

Users browsing this forum: No registered users and 60 guests