Community discussions

MikroTik App
 
GilbelyLiza
just joined
Topic Author
Posts: 2
Joined: Wed Feb 08, 2023 6:03 am

login failure messages for various users attempting to access my Mikrotik devices

Mon Mar 13, 2023 6:38 am

Periodically, I encounter login failure messages for various users attempting to access my Mikrotik devices (router and access points) via ssh, ftp, and telnet. I have configured logging of these ports and can see connection details from hosts on the local network. Brute-force attacks seem to come from different Windows hosts every time, sometimes even at night when no one is present. I have scanned the last two hosts with multiple antivirus tools, but nothing dangerous was found. Could the malicious code be using address spoofing? How can I identify any potential malware?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11593
Joined: Thu Mar 03, 2016 10:23 pm

Re: login failure messages for various users attempting to access my Mikrotik devices

Mon Mar 13, 2023 8:55 am

Did you verify also the "trusted" applications? AWG antivirus is known to have a "feature" to detect vulnerable devices on LAN so that it can alert user about them. The feature is a recent addition and user is not prompted to enable it.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26376
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: login failure messages for various users attempting to access my Mikrotik devices

Mon Mar 13, 2023 8:56 am

The first and most obvious thing to note - you have administrative ports open to untrusted networks. This is not good.

Who is online

Users browsing this forum: boocko, korbanpinjol, sbert, stralis and 107 guests