Dear MTik,
Been a very long time user, etc. I'm used to things not being implemented perfectly in ROS from time to time, but now I have kind of a bigger issue. There's a sea o RBs we installed at various locations, some of those we manage directly, some locations we jump in when needed.
At one site it happened. ROS was not updated, also Winbox was made available to the Internet-facing interface. Great. So now it got hacked. So ok, we resolved that. Upgraded, changed password, restored the proper config, etc. But before restoring the config I looked around to see what the attacker did with the device. So I discovered that the attacker:
- brought up a web proxy
- brought up SOCKS
- looks like it tried something with IPSEC, but that didn't look functional
- enabled DDNS, under ip/cloud
- changed a few firewall rules to make proxy work for users on the net
So the purpose was, I guess, to redirect traffic through - to use it as a cloak for... attacks ? spam ? I don't really know.
The reason I'm writing all this is that I can't get traffic to stop coming in. All that traffic is now dropped, of course, but the reason we are still receiving all this traffic is the damn DDNS record that won't go away. ROS manual for ip/cloud states that when you disable DDNS, ROS will send a message to your servers to REMOVE the DNS record. Only it doesn't really do that. Tried quite a few times. Tried checking with geo DNS query later - and well, the record is still alive and doing well. That's 1 day after it's supposed deletion took place.
Dear MTik, I want to stop packets coming to that router. While I'm fully aware you can't do much to stop Internet traffic reaching that router, you should be able to help me remove the DNS record from sn.mynetname.net ! Please just tell me how, now that I've found the built-in functionality doesn't work, and there's no other way that I know of, to delete it manually. At least not from my side. The problem is this router is on a static IP, that address won't ever change, so... I have an interesting situation.
Kind regards,
Lucius