Community discussions

MikroTik App
 
stuartkoh
newbie
Topic Author
Posts: 30
Joined: Tue Apr 09, 2019 2:16 pm
Location: USA

password suddenly stopped working

Fri Nov 26, 2021 3:19 pm

I have an hEX running ROS 6.49.1. I had disabled the default "admin" user and created another user with the same privileges - as is best practice.

It's been working fine for quite a while, but this morning I found that I wasn't able to login to the web UI. I use a password manager, so it wasn't a problem with my CAPS Lock key being on or my having made a typo. I tried it several times and then tried ssh, but that didn't work either. I had last logged in yesterday, so it worked recently. I didn't make any changes to it recently, although all users say that. :-)

The router seemed to be working normally other than this. I finally power-cycled it and tried again. It still didn't let me login.

I swapped in another router (not Mikrotik) and will see if I can investigate further later. (It will be a couple of days before I can really devote any time to it, and that's why I swapped in a different router). I don't know if I was hacked somehow and someone reset the credentials, etc. or if this was a bug of some sort. I've got the standard setup of new incoming traffic from the public network blocked, outgoing traffic from the LAN allowed, and then return traffic allowed from outside when the socket has been initiated from inside. The only thing new allowed from outside is ICMP, so the WAN interface can be pinged (which is the default behavior AFAIK).

I'm leaning towards the issue being a bug or some other, internal to the router, problem, but swapped out the router with something else for the time being just in case.

I guess that, if the issue doesn't magically resolve itself when I take a laptop and run a cable between it and the LAN port of the router and try logging in (without it being connected to the WAN), I'll have to do a reset and try it again.

I realize that I haven't really given much to work with, but I was wondering if anyone has any insight into this?
 
ConnyMercier
Forum Veteran
Forum Veteran
Posts: 725
Joined: Tue Dec 17, 2019 1:08 pm

Re: password suddenly stopped working

Mon Nov 29, 2021 3:37 am

You did the right thing!!
Try connecting directly to the Router , and see what happens...

If you are where using the "Default-Config" you can try using Telnet (IP & MAC) ,Winbox (IP & MAC), SSH, WEB (HTTP)


If the Router is unresponsive and we assume you didnt do anything =)
There is always a possibility that the Device has been hacked.
Maybe in the Past and/or recently ....

a small mistake in the Firewall or even
a local PC, that may be infected with Malware


In both cases, to regain thrust in the Device, simply reinstall ROuterOS via Netintall
 
stuartkoh
newbie
Topic Author
Posts: 30
Joined: Tue Apr 09, 2019 2:16 pm
Location: USA

Re: password suddenly stopped working

Mon Nov 29, 2021 12:50 pm

You did the right thing!!
Try connecting directly to the Router , and see what happens...

If you are where using the "Default-Config" you can try using Telnet (IP & MAC) ,Winbox (IP & MAC), SSH, WEB (HTTP)


If the Router is unresponsive and we assume you didnt do anything =)
There is always a possibility that the Device has been hacked.
Maybe in the Past and/or recently ....

a small mistake in the Firewall or even
a local PC, that may be infected with Malware


In both cases, to regain thrust in the Device, simply reinstall ROuterOS via Netintall

Thanks!

I had disabled the non-encrypted services, and had enabled strong encryption on SSH, plus generated a 4096-bit host key. The only way to access it is SSH or HTTPS. The passphrase was 30 characters and I wasn't using the default "admin" account. I think if it was brute-forced the bad actors had to be really lucky.

I looked at it last night and was able to login. I didn't see anything obviously wrong, so I did do a Netinstall to get a fresh install of ROS. I'll probably put it back in service at some point.

Who is online

Users browsing this forum: Benzebub and 72 guests