Community discussions

MikroTik App
 
FabFab10
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Mon Jul 14, 2008 2:17 pm

I Tink i got hacked

Wed Dec 27, 2023 11:17 am

Hello,
i found my admin user belongin to a new "admin" group and i can't any longer open a terminal window (telnet and SSH have been disabled for this group). I also found a new "Ssytem" user which has all privilegs.
Is there any way to recover full access without having to fully reset the router?

thanks
 
elbob2002
Member Candidate
Member Candidate
Posts: 270
Joined: Tue May 15, 2018 8:15 pm
Location: Ireland

Re: I Tink i got hacked

Wed Dec 27, 2023 11:54 am

You should netinsall to factory reset the router. It's the only way to be certain that the compromise has been completely removed:

https://help.mikrotik.com/docs/display/ROS/Netinstall

That won't prevent you from future hacks though so likely you have an issue with your firewall rules or services open to the internet. You should resolve these too once it's reinstalled.
 
FabFab10
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Mon Jul 14, 2008 2:17 pm

Re: I Tink i got hacked

Wed Dec 27, 2023 11:58 am

Thanks for your reply.
I'm pretty sure there was just a user modification, so if there is a way to regain group control of my user that will be fine.
I know Netinstall would replace everything but if there is a way to modify group belongin for my user that would fix it.
It happened with API service.

I'm running version 7.6 , also tried the Netwatch trick, but either not working or i'm doing something wrong
 
erlinden
Forum Guru
Forum Guru
Posts: 2614
Joined: Wed Jun 12, 2013 1:59 pm
Location: Netherlands

Re: I Tink i got hacked

Wed Dec 27, 2023 12:38 pm

Sounds like you know what happened...were you hacked or not? If this situation is caused by a known user (like yourself), you might want to resolve it. If it's not, you really really should use netinstall.
 
FabFab10
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Mon Jul 14, 2008 2:17 pm

Re: I Tink i got hacked

Wed Dec 27, 2023 12:44 pm

Honestly i'd rather prefer trying to resolve it (if possible) and I have already disabled some unnecessary services.
But i need to regain full access to the system
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1464
Joined: Thu Nov 12, 2020 12:07 pm

Re: I Tink i got hacked

Wed Dec 27, 2023 1:00 pm

If there was a legal and official way to gain admin privileges again.....lol? Then everyone could make themselves admin? to be honest: what answer did you expect to hear? "yes sure, just press the reset button according to the notes of Beethoven's 5th symphony and you have all privileges again"
 
FabFab10
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Mon Jul 14, 2008 2:17 pm

Re: I Tink i got hacked

Wed Dec 27, 2023 4:20 pm

@infabo
some devices let you connect to a console port and make some recovery procedures.........
I hoped there was one using a different connection
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21879
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: I Tink i got hacked

Wed Dec 27, 2023 4:37 pm

Why did you have unsecure API enabled and running.
Perhaps you need to take some courses before being allowed to setup a router?

Netinstall, stop arguing do it, you wont get any other advice, stop wasting our time.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1464
Joined: Thu Nov 12, 2020 12:07 pm

Re: I Tink i got hacked

Wed Dec 27, 2023 7:03 pm

There is the Woobm USB Stick that emulates a serial console port. but still you need to login with a valid user/password.
 
holvoetn
Forum Guru
Forum Guru
Posts: 6738
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: I Tink i got hacked

Wed Dec 27, 2023 7:57 pm

And... woobm has been discontinued.
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1464
Joined: Thu Nov 12, 2020 12:07 pm

Re: I Tink i got hacked

Wed Dec 27, 2023 10:10 pm

And... woobm has been discontinued.
😭
 
User avatar
infabo
Forum Guru
Forum Guru
Posts: 1464
Joined: Thu Nov 12, 2020 12:07 pm

Re: I Tink i got hacked

Wed Dec 27, 2023 11:23 pm

Thanks, I already have one myself. But to discontinue such a helpful device makes me sad
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12550
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: I Tink i got hacked

Thu Dec 28, 2023 11:29 am

"just press the reset button according to the notes of Beethoven's 5th symphony and you have all privileges again"
But what are you talking about? I tried and it didn't work...
 
holvoetn
Forum Guru
Forum Guru
Posts: 6738
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: I Tink i got hacked

Thu Dec 28, 2023 11:47 am

That was a joke which you may have missed.
(but your comment was one too :lol: )
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12550
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: I Tink i got hacked

Thu Dec 28, 2023 1:06 pm

That was a joke which you may have missed.
(sure?)
ah, I thought I had choice the wrong timing 2/4 (is 3/8) :lol:
Image

Who is online

Users browsing this forum: No registered users and 41 guests