Hi everyone,
This morning I started experiencing problems with the https certificates of various websites such as google, msn etc. In the beginning i thought there is a temporary problem maybe with google but after surfing some more I realised it wasn't just google but other sites as well. After upgrading my routers to 6.42.3 from 6.40.4 (main ones are a 1036 and a 1100 used as a load balancer) I started looking into the devices and I found out that there were two entries in the DNS settings 128.14.6.12 and 13 as DNS servers on the 1100 (load balancing). I removed the entries and all is back to normal. I obviously was hacked. I had all services disabled except www and winbox on which I changed the default ports (www was changed from day one but decided to change it again). My bad that I used the default admin account with an 8 digit password (although letters+symbols+numbers), so I've changed the username and the password as well and disabled the admin account. So my question is
1. What else should I do to further secure my devices and if there is anything else I should look for in them
2. Is there anything I can do about reporting these IPs to someone? From what I found the 128.14.0.0/17 subnet belongs to zenlayer.com (some chinese-usa ISP?)
Thanks everyone!