Community discussions

MikroTik App
 
Darman
just joined
Topic Author
Posts: 3
Joined: Mon Jan 28, 2019 12:27 am

IP Socks causes 100%cpu

Mon Jan 28, 2019 2:41 am

After moving the vulnerable version i cleaned all suspicious setings in RoS (firewall filter, schedule, ip socks).
But now, ther are thousands entrys in IP-Socks-Access, and when you try to access IP Socks router stuck at 100% cpu,
Is there any chanse that Mikrotik make an upgrade version that will automaticly remowe that socks access entry?

What to do, routers are miles away?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12986
Joined: Thu Mar 03, 2016 10:23 pm

Re: IP Socks causes 100%cpu

Mon Jan 28, 2019 9:08 am

I'm afraid that only sure way to clean malware from hacked routerboard is to perform netinstall ... for that physical access is a must. And, after you do it, don't restore configuration from backup, malware might be hidden in it. Rather re-do configuration manually (output from /export command can be valuable reminder, just don't copy-paste any configuration commands you're not 120% sure you know what they're doing). In particular, default firewall is a really good starting point, build on it rather than replacing it with your own old firewall config as it might have been primary reason for your router being hacked in the first place.
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 914
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: IP Socks causes 100%cpu

Tue Jan 29, 2019 10:34 am

when you try to access IP Socks router stuck at 100% cpu,

How do you "access IP Socks"? Are you trying to use the IP socks service as a client? Are you opening the IP > Socks > Access window in WinBox? Are you printing the entries in Terminal?

The most simple command to remove all entries is, in CLI (WinBox/WebFig terminal, SSH or telnet):
/ip socks access remove [find]

And give it some time (minutes) to complete.

Please do not post your question in multiple topics.

Who is online

Users browsing this forum: Florian, jaclaz, MontyP and 23 guests