Community discussions

MikroTik App
 
campa4bt
newbie
Topic Author
Posts: 32
Joined: Mon Jul 21, 2014 12:49 pm

Web Proxy Hacked

Tue Jul 03, 2018 1:28 pm

I am founding a lot of CPE (SXT) that has 100% cpu, and i found web proxy enabled in port 41258 anonymous.

Is there a kind of hack attack that can activate that?

Thanks.
 
Samot
Member Candidate
Member Candidate
Posts: 113
Joined: Sat Nov 25, 2017 10:01 pm

Re: Web Proxy Hacked

Tue Jul 03, 2018 2:30 pm

What version of ROS are you running on the SXT's? That will determine the answer to your question as there are older versions with vulnerabilities known to them.
 
campa4bt
newbie
Topic Author
Posts: 32
Joined: Mon Jul 21, 2014 12:49 pm

Re: Web Proxy Hacked

Tue Jul 03, 2018 5:33 pm

6.41.3 and 6.42.1
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: Web Proxy Hacked

Tue Jul 03, 2018 5:40 pm

6.41.3 is able to leak passwords on WinBox port:

viewtopic.php?f=21&t=133533
 
campa4bt
newbie
Topic Author
Posts: 32
Joined: Mon Jul 21, 2014 12:49 pm

Re: Web Proxy Hacked

Wed Jul 04, 2018 5:27 pm

Update to 6.42.5 and changed passwords and today hacked. Is there a solution?
 
whatever
Member
Member
Posts: 366
Joined: Thu Jun 21, 2018 9:29 pm

Re: Web Proxy Hacked

Wed Jul 04, 2018 10:25 pm

Don't expose the mgmt interface to the internet? If you have to: use additional security features like port knocking and vpn.
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 914
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: Web Proxy Hacked

Wed Jul 04, 2018 10:54 pm

Have you checked your entire configuration for remaining malware? E.g. scheduler and scripts?
 
R1CH
Forum Guru
Forum Guru
Posts: 1108
Joined: Sun Oct 01, 2006 11:44 pm

Re: Web Proxy Hacked

Thu Jul 05, 2018 12:17 am

You should format and netinstall after being compromised. Winbox access can supposedly be escalated to shell access, where all kinds of malware could be lurking with no way to detect.
 
Ubiifere
just joined
Posts: 9
Joined: Thu Jul 12, 2018 3:28 pm

Re: Web Proxy Hacked

Thu Jul 12, 2018 3:43 pm

Hello guys,
Please, i'm having a similar issue with MikroTik RouterBOARD RB951Ui 2nD. After few days of installation with passwords, I can't log in in again with the password I used. I also notice that the identity changed to "HACKED". Please, what might be the cause?

Who is online

Users browsing this forum: bmatic, ias, meetriks2 and 33 guests