Community discussions

MikroTik App
 
User avatar
Pearse
just joined
Topic Author
Posts: 4
Joined: Wed Feb 16, 2011 5:33 pm

FTP Attack causes 100% CPU - ROS 5.7

Tue Oct 25, 2011 10:47 pm

Hello I have noticed this kind of attack a few times but lately they cause the CPU to max out
Attached is a screen shot showing the FTP service off and the log. I know it is easy to firewall this and it can be found here
http://wiki.mikrotik.com/wiki/Bruteforc ... %26_SSH%29

Is this a bug because different routers all over my network keep getting attacked like this with the FTP service off. I don't have this firewall rule an all my routers as there are too many. You would imagine with the FTP service disabled that is enough. When I firewall the IP the CPU is normal

I also made a supout.rif when the attack was in progress if that is any help
You do not have the required permissions to view the files attached to this post.
 
Toiletbowl
Member Candidate
Member Candidate
Posts: 169
Joined: Fri Jun 03, 2011 6:49 am
Location: Boracay Philippines

Re: FTP Attack causes 100% CPU - ROS 5.7

Wed Oct 26, 2011 12:14 pm

Hello I have noticed this kind of attack a few times but lately they cause the CPU to max out
Attached is a screen shot showing the FTP service off and the log. I know it is easy to firewall this and it can be found here
http://wiki.mikrotik.com/wiki/Bruteforc ... %26_SSH%29

Is this a bug because different routers all over my network keep getting attacked like this with the FTP service off. I don't have this firewall rule an all my routers as there are too many. You would imagine with the FTP service disabled that is enough. When I firewall the IP the CPU is normal

I also made a supout.rif when the attack was in progress if that is any help
i think that's is a bug if you setup a brute-force login properly the attacker will ban immediately, even in you ip/service the ftp port is disable but the bruteforce still attack.
 
jandafields
Forum Guru
Forum Guru
Posts: 1515
Joined: Mon Sep 19, 2005 6:12 pm

Re: FTP Attack causes 100% CPU - ROS 5.7

Wed Oct 26, 2011 3:07 pm

If FTP is disabled, how is it possible to have a bruteforce attack? The mikrotik shouldn't even be tryint to authenticate FTP if it is disabled.

If it is still showing FTP failures in the log while the FTP service is disabled, that is a definate bug.

Who is online

Users browsing this forum: Kanzler and 190 guests