Community discussions

MikroTik App
 
smith5golf
just joined
Topic Author
Posts: 3
Joined: Fri Sep 13, 2019 9:51 pm

Laptops are trying to hack my router

Fri Sep 13, 2019 10:07 pm

I have a large guest network (Wi-Fi), that consists of Unifi APs and a Mikrotik Router as the gateway.

Recently I was alerted to winbox login attempts to the router from 3-4 Laptops on the network. Now I have the router setup to only accept logins from my IP on a management port, and have the firewall set to reject any attempts from the guest network, so I am not to worried about them getting in.

I got my hands on one of the laptops that has the virus(?), and after running several AV scans on it, I was unable to locating the program causing it.

I was able to see the logs roll in on the router while I had the laptop, and at that time I could hear the HDD in the laptop running, but by the time I got to resource monitor it had stopped.

Anyone know what is causing this? I tried searching, but maybe I was using the wrong terms. Let me know if you need more details.

Also if this is in the wrong section of the forum please let me know.
 
User avatar
karlisi
Member
Member
Posts: 438
Joined: Mon May 31, 2004 8:09 am
Location: Latvia

Re: Laptops are trying to hack my router

Mon Sep 16, 2019 9:24 am

Start with this
https://wiki.mikrotik.com/wiki/Manual:S ... our_Router
If you want to block access to router from guest network, block in firewall input chain all from this interface or IP range, allowing only needed services, i.e. DHCP, DNS, etc.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11585
Joined: Thu Mar 03, 2016 10:23 pm

Re: Laptops are trying to hack my router

Mon Sep 16, 2019 11:33 am

Start with this
https://wiki.mikrotik.com/wiki/Manual:S ... our_Router
If you want to block access to router from guest network, block in firewall input chain all from this interface or IP range, allowing only needed services, i.e. DHCP, DNS, etc.

I don't think this is answer to OPs question (he wrote: "I am not to worried about them getting in."). He's interested in knowing what kind of malware can be running on laptops which tries to get into ROS.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10216
Joined: Mon Jun 08, 2015 12:09 pm

Re: Laptops are trying to hack my router

Mon Sep 16, 2019 11:59 am

Are you sure it was winbox login attempts and not some other service like webfig or SMB?
It is quite common for guest devices to do all kinds of attempts to connect services that they have available at home, and where the owner has installed software or has made configuration for it.
The best way is to just allow only what you need to allow (likely only TCP and UDP port 53) and just reject or drop everything else without log.
 
smith5golf
just joined
Topic Author
Posts: 3
Joined: Fri Sep 13, 2019 9:51 pm

Re: Laptops are trying to hack my router

Thu Sep 26, 2019 11:19 pm

Sorry for the slow reply. It appears to be winbox/dude traffic, as they are using port 8291.

After my last post, I did set up a HoneyPot (T-Pot) on the network and opened it up to the network. The same laptops that attempt port 8291 on the router, attempts to access the honey pot via ssh and a couple other protocols.

I know that no one at the laptop is doing it, as I have one of them here with me.
 
R1CH
Forum Guru
Forum Guru
Posts: 1101
Joined: Sun Oct 01, 2006 11:44 pm

Re: Laptops are trying to hack my router

Thu Sep 26, 2019 11:49 pm

Time to format it, clearly infected with malware.
 
ivicask
Member
Member
Posts: 425
Joined: Tue Jul 07, 2015 2:40 pm
Location: Croatia, Zagreb

Re: Laptops are trying to hack my router

Fri Sep 27, 2019 8:33 am

What AV you used to scan?
 
smith5golf
just joined
Topic Author
Posts: 3
Joined: Fri Sep 13, 2019 9:51 pm

Re: Laptops are trying to hack my router

Fri Sep 27, 2019 3:18 pm

Avast Premium was installed on it when it got infected, Scanning with that didn't yield any results. I uninstalled it and tried AVG and it found nothing. I also ran scans with Malwarebytes, CCleaner, and a Bot scanner from Avast.
 
markos222
just joined
Posts: 24
Joined: Tue Dec 15, 2015 9:15 pm

Re: Laptops are trying to hack my router

Sun Sep 29, 2019 12:08 am

Hi

As I know avast does a test for know if network is secure , And it tries to connect to the gateway , and does this attemps to.router (ssh,ftp...)try to uninstall avast and try onli.malwarebytes or eset for serveral days and see if the problem.persist

M.BP

Who is online

Users browsing this forum: chindo, emzdev404, NGiannis, pants6000, unhuzpt and 69 guests