Community discussions

MikroTik App
 
nozz
just joined
Topic Author
Posts: 5
Joined: Tue Sep 24, 2019 3:25 pm

CRS125-24G-1S-RM brick

Tue Sep 24, 2019 3:28 pm

Hello. The devicewas hacked by a known vulnerability. The admin was given - read, the new admin full. Protected bootloader is set and reformat-hold-button - 4:59.
After resetting by reset, fell into a cyclic reboot at the loading kernel stage (on LCD)
NetInstall is not detected. A console-COM connection gives the following:

RouterBOOT backup booter 3.33
CRS125-24G-1S-RM
CPU frequency: 600 MHz
Memory speed: 220 MHz
Memory size: 128 MB

loading kernel ... kernel not found

That's all. There is no timing for entering bios settings; frantic keystrokes do nothing.
When you hold the reset for 5 minutes and turn on the device, it displays the following:

RouterOS... cleanup
writing settings to flash...writing settings to flash...

and then reboot again

HELP
Last edited by nozz on Wed Sep 25, 2019 3:51 pm, edited 3 times in total.
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: CRS125-24G-1S-RM brick

Tue Sep 24, 2019 4:09 pm

What is the port you use to perform netinstall?
Did you try again?
 
nozz
just joined
Topic Author
Posts: 5
Joined: Tue Sep 24, 2019 3:25 pm

Re: CRS125-24G-1S-RM brick

Wed Sep 25, 2019 12:58 am

What is the port you use to perform netinstall?
Did you try again?
I use all the ports. The port indicator is active on mikrotik, but the network card on the computer shows 0 packets received
 
Miracle
Member Candidate
Member Candidate
Posts: 106
Joined: Fri Sep 11, 2015 9:04 am

Re: CRS125-24G-1S-RM brick

Wed Sep 25, 2019 3:42 am

Disconnect console before install
 
nozz
just joined
Topic Author
Posts: 5
Joined: Tue Sep 24, 2019 3:25 pm

Re: CRS125-24G-1S-RM brick

Wed Sep 25, 2019 7:37 am

Disconnect console before install
of course disconnected
 
peson
Trainer
Trainer
Posts: 202
Joined: Tue Jul 20, 2004 10:33 am
Location: Sweden

Re: CRS125-24G-1S-RM brick

Wed Sep 25, 2019 10:48 am

Disconnect console before install
of course disconnected
Have you tried this 20s reset?
"Release the button after LED is no longer lit (~20 seconds) to cause a device to look for Netinstall servers "
Use a switch in between the CRS and the Netinstall PC and disabled firewall on the PC.
Follow the guide:
https://wiki.mikrotik.com/wiki/Manual:Netinstall
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: CRS125-24G-1S-RM brick

Wed Sep 25, 2019 1:36 pm

Ethernet boot for netinstall is supported only on Port Number 1... You cant perform netinstall using the other ports.
 
nozz
just joined
Topic Author
Posts: 5
Joined: Tue Sep 24, 2019 3:25 pm

Re: CRS125-24G-1S-RM brick

Wed Sep 25, 2019 3:50 pm

Disconnect console before install
of course disconnected
Have you tried this 20s reset?
"Release the button after LED is no longer lit (~20 seconds) to cause a device to look for Netinstall servers "
Use a switch in between the CRS and the Netinstall PC and disabled firewall on the PC.
Follow the guide:
https://wiki.mikrotik.com/wiki/Manual:Netinstall

the firewall is off, there is no antivirus. I think the thing is
"Warning: If you have set up Protected bootloader, then the reset button's behaviour is changed. Make sure you remember the settings you used to set up the Protected bootloader, otherwise you will not be able to use Eterboot mode and will not be able to reset your device."
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: CRS125-24G-1S-RM brick

Wed Sep 25, 2019 7:08 pm

Try to perform netinstall on another Mikrotik without problem so you can be sure you do it right....
Also check inside the wiki how we netinstall a device because since you said you tried every port then am not sure you do it correctly....
 
nozz
just joined
Topic Author
Posts: 5
Joined: Tue Sep 24, 2019 3:25 pm

Re: CRS125-24G-1S-RM brick

Thu Sep 26, 2019 1:55 am

Try to perform netinstall on another Mikrotik without problem so you can be sure you do it right....
Also check inside the wiki how we netinstall a device because since you said you tried every port then am not sure you do it correctly....
On the PC where Netinstall installed, I previously restored another device, so the problem with firewalls disappears. Why does it respond to a reset within 4:55, does the CleanUP and flash process begin, and is everything reset? So somewhere there is info about the Protected Bootloader.
By the way, there is another same patient with exactly the same hack, it works, but there are no admin rights, so I can’t do anything, just read. I'm afraid to reset it so far so as not to get another brick. The only thing that comes to mind while he is alive is to try to enter the BIOS through the console and put it into Etherboot mode. But the description on the wiki, Protected Boootloader disables the ability to run from the console and NetInstall.

Who is online

Users browsing this forum: No registered users and 75 guests