Did you use the same credentials that you had on the router before you upgraded to 6.40.9? Attackers were harvesting router credentials for months before the vulnerability was discovered in April of 2018. If you configured the same credentials in use prior to upgrading to 6.40.9, your credentials are probably compromised.RB3011 running 6.40.9, 2 days ago recieved "wrong username or password" in winbox. User is not "admin", password is strong enough. LCD touch was disabled.
A crack - i think, than netinstall, 6.43, total reconfig (had no backups)... and today i recived the same message "wrong username or password". All services, exept winbox, are disabled. Winbox is allowed from internal network and for 1 external IP (my work). LCD is workind, i can reset config, but what a hell is going on?
Is it a issue or open gate for hack?
I'm not a mikrotik master, but i have enough brains to change my credentials after hacking.Did you use the same credentials that you had on the router before you upgraded to 6.40.9? Attackers were harvesting router credentials for months before the vulnerability was discovered in April of 2018. If you configured the same credentials in use prior to upgrading to 6.40.9, your credentials are probably compromised.
Have you tried Winbox 3.18? There's a potential fix there. I just realized you aren't the OP. The OP tried 3.18, but you haven't said you tried it.I'm not a mikrotik master, but i have enough brains to change my credentials after hacking.
I have same issue, and also RB951Any news? I've got the same issue also ....
Upgraded to 6.40.9 two weeks ago (was attacked by mining scrypt), next days logon was successful, last successful connect was Sep 11, but now "Wrong user or password .."
Tried Winbox 3.11, 3.14, 3.18 - all negative.
Unfortunately - all impacted routers are on remote sites ...
Any ideas ? How to restore access to routers without send it from remote to local office ?
As far as I saw - in 6.40.9 also has fixes for security issues ....As i've got understood, versions below 6.43 are compromised for attack. I've had to upgrade to 6.43 and total reconfig (because backup files aslo send message about wrong password, btw they were written without any password at all).
Netinstall 6.43.2 on the device with no configuration and start from scratch. Do no copy paste old backup or export lines as the virus changed many things.Good day!
hacking being asked, but (unfortunately)
installed 6.43, got " wrongusername..."
've reset the configuration, restore configuration,
entered a new user and password.
Set a limit on the connection "winbox" by IP
it took 5 days
I try to connect "winbox".... getting " wrongusername..."
winbox version 3.18 also does not help.
To restore all of course not for long.... the question is for how long...
Besides changing passwords, are there any other recommendations?