Page 1 of 1

security issue winbox attack

Posted: Thu Mar 16, 2006 12:42 am
by aitsecurity
Hi i have 4 Mikrotik server, work very great.

but look this

16:17:34 system,error,critical login failure for user 68.148.82.16:18762\r Remote-IP: via winbox
16:17:37 system,error,critical login failure for user 70.146.162.3:25069\r Remote-IP: via winbox
16:17:44 system,error,critical login failure for user 66.141.184.124:39566\r Remote-IP\03 via winbox


no give me the login, and the IP is very diferents, look the time is only in seconds, is a brute force attack, ?? why no see the

"for user admin blablabla, for user joe blalbabla, for user melisa blablabla, etc


no see the user only the ip,

i now thinking wake up the VPN server, and close port for TCP sockets for winbox

What you think

Best Regards
Daniel W
Venezuela

Posted: Fri Mar 17, 2006 9:43 am
by sergejs
Username of the person accessing router goes after 'failure for user |username|'.

I suppose, you have to allow access to the router only for trust hosts/networks,
you may look for firewall documentation to see some configuration examples.