Thu May 24, 2018 12:54 am
Apprently it is not fixed in 6.43. I found logins as admin from different IPs allover the world to my CCRs1036 with 6.43rc11.
Moreover not only CCRs are affected as I found similar logins into my RB3011. These logins appears first time back in April 30 and was happening every few days until today.
What is common - is that VPN server (pptp and l2tp) was enabled and accessible from internet on all affected devices.
I do not use "admin" login at all but always change password for that account at the very beginning of configuration as well as creating separate account for myself.
Here is an example of log snippet from my RB3011:
AA.BB.CC.30/2018/04/30/user.log:2018-04-30T01:34:37.148169+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.220.101.4 via winbox
AA.BB.CC.30/2018/04/30/user.log:2018-04-30T01:34:37.613308+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.220.101.4 via winbox
AA.BB.CC.30/2018/05/04/user.log:2018-05-04T17:39:01.065674+03:00 AA.BB.CC.30 system,info,account user admin logged in from 93.115.95.201 via winbox
AA.BB.CC.30/2018/05/04/user.log:2018-05-04T17:39:01.745860+03:00 AA.BB.CC.30 system,info,account user admin logged in from 93.115.95.201 via telnet
AA.BB.CC.30/2018/05/04/user.log:2018-05-04T17:39:14.734529+03:00 AA.BB.CC.30 system,info,account user admin logged out from 93.115.95.201 via winbox
AA.BB.CC.30/2018/05/04/user.log:2018-05-04T17:39:14.736870+03:00 AA.BB.CC.30 system,info,account user admin logged out from 93.115.95.201 via telnet
AA.BB.CC.30/2018/05/09/user.log:2018-05-09T21:40:32.304240+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.220.101.15 via winbox
AA.BB.CC.30/2018/05/09/user.log:2018-05-09T21:40:32.775736+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.220.101.15 via winbox
AA.BB.CC.30/2018/05/10/user.log:2018-05-10T00:07:56.877298+03:00 AA.BB.CC.30 system,info,account user admin logged in from 93.115.95.207 via winbox
AA.BB.CC.30/2018/05/10/user.log:2018-05-10T00:07:57.382748+03:00 AA.BB.CC.30 system,info,account user admin logged out from 93.115.95.207 via winbox
AA.BB.CC.30/2018/05/10/user.log:2018-05-10T11:21:13.242989+03:00 AA.BB.CC.30 system,info,account user admin logged in from 37.220.35.202 via winbox
AA.BB.CC.30/2018/05/10/user.log:2018-05-10T11:21:13.825319+03:00 AA.BB.CC.30 system,info,account user admin logged out from 37.220.35.202 via winbox
AA.BB.CC.30/2018/05/11/user.log:2018-05-11T03:29:08.904707+03:00 AA.BB.CC.30 system,info,account user admin logged in from 93.115.95.206 via winbox
AA.BB.CC.30/2018/05/11/user.log:2018-05-11T03:29:09.359377+03:00 AA.BB.CC.30 system,info,account user admin logged out from 93.115.95.206 via winbox
AA.BB.CC.30/2018/05/11/user.log:2018-05-11T12:43:20.279635+03:00 AA.BB.CC.30 system,info,account user admin logged in from 85.248.227.165 via winbox
AA.BB.CC.30/2018/05/11/user.log:2018-05-11T12:43:20.742564+03:00 AA.BB.CC.30 system,info,account user admin logged out from 85.248.227.165 via winbox
AA.BB.CC.30/2018/05/12/user.log:2018-05-12T04:01:37.186571+03:00 AA.BB.CC.30 system,info,account user admin logged in from 77.247.181.162 via winbox
AA.BB.CC.30/2018/05/12/user.log:2018-05-12T04:01:37.618239+03:00 AA.BB.CC.30 system,info,account user admin logged out from 77.247.181.162 via winbox
AA.BB.CC.30/2018/05/12/user.log:2018-05-12T09:52:17.436537+03:00 AA.BB.CC.30 system,info,account user admin logged in from 163.172.214.8 via winbox
AA.BB.CC.30/2018/05/12/user.log:2018-05-12T09:52:17.848710+03:00 AA.BB.CC.30 system,info,account user admin logged out from 163.172.214.8 via winbox
AA.BB.CC.30/2018/05/14/user.log:2018-05-14T17:31:38.127266+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.220.101.4 via winbox
AA.BB.CC.30/2018/05/14/user.log:2018-05-14T17:31:38.719155+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.220.101.4 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T14:16:47.740781+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.220.101.0 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T14:16:48.282335+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.220.101.0 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T14:52:41.320130+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.220.101.4 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T14:52:41.754492+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.220.101.4 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T17:29:21.806512+03:00 AA.BB.CC.30 system,info,account user admin logged in from 204.8.156.142 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T17:29:22.434875+03:00 AA.BB.CC.30 system,info,account user admin logged out from 204.8.156.142 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T22:06:02.753890+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.220.101.21 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T22:06:03.410611+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.220.101.21 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T23:35:34.403232+03:00 AA.BB.CC.30 system,info,account user admin logged in from 77.247.181.165 via winbox
AA.BB.CC.30/2018/05/15/user.log:2018-05-15T23:35:34.865392+03:00 AA.BB.CC.30 system,info,account user admin logged out from 77.247.181.165 via winbox
AA.BB.CC.30/2018/05/16/user.log:2018-05-16T02:46:28.421722+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.100.84.250 via winbox
AA.BB.CC.30/2018/05/16/user.log:2018-05-16T02:46:28.865875+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.100.84.250 via winbox
AA.BB.CC.30/2018/05/16/user.log:2018-05-16T03:41:01.220939+03:00 AA.BB.CC.30 system,info,account user admin logged in from 93.115.95.205 via winbox
AA.BB.CC.30/2018/05/16/user.log:2018-05-16T03:41:01.690549+03:00 AA.BB.CC.30 system,info,account user admin logged out from 93.115.95.205 via winbox
AA.BB.CC.30/2018/05/16/user.log:2018-05-16T16:25:20.392325+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.107.47.215 via winbox
AA.BB.CC.30/2018/05/16/user.log:2018-05-16T16:25:21.021640+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.107.47.215 via winbox
AA.BB.CC.30/2018/05/17/user.log:2018-05-17T18:04:12.157033+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.56.80.242 via winbox
AA.BB.CC.30/2018/05/17/user.log:2018-05-17T18:04:12.723442+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.56.80.242 via winbox
AA.BB.CC.30/2018/05/18/user.log:2018-05-18T01:33:51.464257+03:00 AA.BB.CC.30 system,info,account user admin logged in from 51.15.64.212 via winbox
AA.BB.CC.30/2018/05/18/user.log:2018-05-18T01:33:51.917806+03:00 AA.BB.CC.30 system,info,account user admin logged out from 51.15.64.212 via winbox
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T02:26:26.427456+03:00 AA.BB.CC.30 system,info,account user admin logged in from 37.187.129.166 via winbox
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T02:26:26.888703+03:00 AA.BB.CC.30 system,info,account user admin logged out from 37.187.129.166 via winbox
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T03:04:24.643637+03:00 AA.BB.CC.30 system,info,account user admin logged in from 185.100.87.207 via winbox
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T03:04:25.316232+03:00 AA.BB.CC.30 system,info,account user admin logged out from 185.100.87.207 via winbox
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T13:48:48.605493+03:00 AA.BB.CC.30 system,info,account user admin logged in from 194.67.218.104 via web
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T13:48:48.896114+03:00 AA.BB.CC.30 system,info,account user admin logged in from 194.67.218.104 via web
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T13:50:09.902606+03:00 AA.BB.CC.30 system,info,account user admin logged out from 194.67.218.104 via web
AA.BB.CC.30/2018/05/20/user.log:2018-05-20T13:50:09.902606+03:00 AA.BB.CC.30 system,info,account user admin logged out from 194.67.218.104 via web
AA.BB.CC.30/2018/05/21/user.log:2018-05-21T02:46:04.527079+03:00 AA.BB.CC.30 system,info,account user admin logged in from 176.126.252.12 via winbox
AA.BB.CC.30/2018/05/21/user.log:2018-05-21T02:46:04.978765+03:00 AA.BB.CC.30 system,info,account user admin logged out from 176.126.252.12 via winbox