Community discussions

MikroTik App
 
mmorelie
just joined
Topic Author
Posts: 18
Joined: Thu Jul 28, 2016 4:04 pm

Unexpected start message

Tue Jul 31, 2018 5:55 pm

When i restart my RB2011, sometimes those messages appear

cp: /nova/store/user/aaa.idx: No such file or directory
cp: /nova/store/user/aaa.dat: No such file or directory
cp: /ram/reset/aaa.idx: No such file or directory
cp: /ram/reset/aaa.dat: No such file or directory


Is it normal ?
 
msatter
Forum Guru
Forum Guru
Posts: 1875
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: Unexpected start message

Tue Jul 31, 2018 6:40 pm

Maybe it covered by the blog: viewtopic.php?f=21&t=137284
One RB4011 (cooled) and a RB760iGS (hEX S) in series. The 4011 Does PPPoE/IKEv2.
The cooler: viewtopic.php?f=3&t=138613&start=300#p799879
Running:
RouterOS 6.48beta35 / Winbox 3.27 64bits / MikroTik APP 1.3.15
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 24713
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: Unexpected start message

Wed Aug 01, 2018 11:28 am

Upgrade -> Change password -> Implement a firewall
No answer to your question? How to write posts
 
mmorelie
just joined
Topic Author
Posts: 18
Joined: Thu Jul 28, 2016 4:04 pm

Re: Unexpected start message

Wed Aug 01, 2018 6:19 pm

Yes, ok is the device compromise ?

because i have upgrade and it steel pop the message.

Regards
 
sindy
Forum Guru
Forum Guru
Posts: 5654
Joined: Mon Dec 04, 2017 9:19 pm

Re: Unexpected start message

Wed Aug 01, 2018 6:41 pm

Seems it is infected by something that can protect itself against a regular upgrade. So a netinstall seems to be necessary (and after you finish it and the messages do not appear, change the passwords one more time before connecting it to the net). Also bear in mind that once the malware could get in in the past, the device may be infected from the internal network as well if the malware has managed to install itself on something in the internal network.
Instead of writing novels, post /export hide-sensitive. Use find&replace in your favourite text editor to systematically replace all occurrences of each public IP address potentially identifying you by a distinctive pattern such as my.public.ip.1.
 
R1CH
Forum Veteran
Forum Veteran
Posts: 930
Joined: Sun Oct 01, 2006 11:44 pm

Re: Unexpected start message

Wed Aug 01, 2018 8:11 pm

How would malware get access to run arbitrary cp commands? This looks more like a bug in RouterOS, unless there is a new exploit available to elevate winbox to shell access (which is rumored to be possible).
 
mmorelie
just joined
Topic Author
Posts: 18
Joined: Thu Jul 28, 2016 4:04 pm

Re: Unexpected start message

Thu Aug 02, 2018 10:35 am

Even after netinstall i have the same message :(
Pretty scary

Who is online

Users browsing this forum: Baidu [Spider] and 61 guests