Page 1 of 1

Hacked or Forgotten Password

Posted: Mon Nov 26, 2018 3:33 pm
by squishio
Hi Guys,

I have two mikrotiks that I cant get access to. Completely independant of eachother, not linked in any way.
I havent had any need to login to either of them for around one year. But now, I cant get into them. They're online and winbox is listening. Functionally they're completely fine.

So either I'm crazy and have forgotten the passwords to them, or I'm wondering if they have been hacked with the winbox exploit.

There is no obvious impact to the LAN to suggest the devices have been compromised, but I'm wondering if there is any way to tell?
I've tried running the winbox exploit from GitHub against them and it does not work.

Thanks!

Re: Hacked or Forgotten Password

Posted: Mon Nov 26, 2018 3:42 pm
by Jotne
If you have not upgraded after april this year (i think it was) and you have Winbox open to public internet, you are hacked.
They do scan most of the internet to find system lisen on Winbox port, then hack it, if its not updated.

So only thing you can do, is a full reset, then restore a good working backup.

Re: Hacked or Forgotten Password

Posted: Mon Nov 26, 2018 4:01 pm
by victorsoares
Depending on the version that these mikrotiks are running, you might want to try an older version of winbox too.