HI there,
Q - How can I catagorically show a 3rd party + my client that the 3rd party was NOT able to log into one of my routers ?
Background:
An onsite 3rd party (instructed by client for non MT work) recently told a client of mine that via WinBox he can log into their (large) ISP provided, managed MT router, running the latest LTS from 2022 for the model in question.
This person said they could not explain to me how they did it over the phone (Red flag 1) ... They did not have any screenshots either (RD 2)... They state that they could login via the default MT login details (Admin ; blank password). I immediatly tried this, and failed. I tried the 2nd MT at that site - same thing. I tried this a few times just incase.
I contacted the ISP to check the logs - they could not find any sign of a user logging in. The default Admin username is not even in the User list...
My theory:
1) They had a previous Winbox session cached. Is this possible? I may have read about people experiancing this over time.
2) Their laptop had connected to the closest OpenWifi (coffee shops all around) and they had an insecure MT.