Community discussions

MikroTik App
 
Marktime87
newbie
Topic Author
Posts: 38
Joined: Sat Feb 25, 2017 11:49 am

Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 11:25 am

Hi guys

I first posted over on the UBNT forums: https://community.ubnt.com/t5/airOS-Sof ... 484#M48642

I noticed this when setting up my new UNMS server for AirMax monitoring. After some Torch analysis I say that a lot of the random ports listed in the other post were to do with DNS but there were also a couple of SSH entries.

All the traffic is coming from the management subnets default gateway, namely the CCR1009. There's no port forwarding rules going to any nanostations, and there is a block rule for intervlan chatter as well as as rule to block vlan traffic from the management subnet.

Can anyone identify what is going on here? Happy to post extra info at your request.

Cheers
 
p3rad0x
Long time Member
Long time Member
Posts: 640
Joined: Fri Sep 18, 2015 5:42 pm
Location: South Africa
Contact:

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 11:36 am

Hi,

Can you maybe post a screenshot of that strange traffic you see when running torch?
 
Marktime87
newbie
Topic Author
Posts: 38
Joined: Sat Feb 25, 2017 11:49 am

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 11:40 am

Sure, here you go:
unms dropbear.PNG
You do not have the required permissions to view the files attached to this post.
 
Marktime87
newbie
Topic Author
Posts: 38
Joined: Sat Feb 25, 2017 11:49 am

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 11:42 am

Although that image seems to think the nanostation is trying to establish SSH with the router :-|
 
pe1chl
Forum Guru
Forum Guru
Posts: 10544
Joined: Mon Jun 08, 2015 12:09 pm

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 11:47 am

Your Ubiquiti has been hacked? There are worms for those devices that spread through your network.
 
Marktime87
newbie
Topic Author
Posts: 38
Joined: Sat Feb 25, 2017 11:49 am

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 12:01 pm

Thanks

The firmware is already up to date, I changed the password but the logs persisted, then I changed the default SSH port and the logs stopped.

Does that tell me that it was something externally trying to get in or is it still likely an infected radio?

Just to test the router I disabled all but my admin account and reset the password, then set SSH on the nanostation back to 22. Logs started again.
 
Marktime87
newbie
Topic Author
Posts: 38
Joined: Sat Feb 25, 2017 11:49 am

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 12:04 pm

Here's torch running on management subnet looking for SSH connections

mikrotik ssh.PNG
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10544
Joined: Mon Jun 08, 2015 12:09 pm

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 12:35 pm

I think it is an infected radio attempting to spread the worm to others.
I don't know how you can repair that, info should be on the UBNT forums.
(I only read about this problem and the many attempts UBNT have made to secure their radios, every time still not fixing it completely)
 
Marktime87
newbie
Topic Author
Posts: 38
Joined: Sat Feb 25, 2017 11:49 am

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Thu Nov 23, 2017 12:48 pm

Thanks, I've asked on the other UBNT thread what they think.

The latest news I can see of a UBNT worm was early last year, and these points were installed well after that so hopefully it's not a worm. I'm not ruling anything out though.
 
Marktime87
newbie
Topic Author
Posts: 38
Joined: Sat Feb 25, 2017 11:49 am

Re: Lots of weird traffic from CCR1009 to UBNT Nanostation

Tue Nov 28, 2017 6:57 pm

***UPDATE***

It was The Dude Server! I'm an idiot.