Page 1 of 1

Hi traffic from Mikrotic, ISP complains on DDOS

Posted: Wed Dec 25, 2024 1:17 pm
by csqwipik
Hi, I'm quite newby user with Mikrotik hAP ^2. Today my internet speed has been reduced and ISP complains that DDOS traffic is going out from the router. I disconntect all devices, but outbound traffic is still there.
Is there any way to help me? It seems I opened too many ports (but it is just gut feeling). What I need is to keep remote access to the router and vpn through the router.

I cannot make
export compact hide-sensitive
from the terminal as the access is limited (I am not near the router) and only through winbox.
On top I cannot even open terminal via winbox and see the following error message:
Terminal <1> - not permitted (9)
.
Is there any way how to resolve my case via Winbox?

Re: Hi traffic from Mikrotic, ISP complains on DDOS

Posted: Wed Dec 25, 2024 1:37 pm
by csqwipik
It seems I found something strange: there is another user with name System. I have never add this user. I as Admin user now have less rights and I cannot add telnet connection to unlock terminal. Any suggestions?

Re: Hi traffic from Mikrotic, ISP complains on DDOS

Posted: Wed Dec 25, 2024 2:29 pm
by holvoetn
Your router has been hacked.

Disconnect router from network
NETINSTALL asap.

Re: Hi traffic from Mikrotic, ISP complains on DDOS

Posted: Wed Dec 25, 2024 5:06 pm
by csqwipik
Thanks! Yes, it seems the routere was hacket. Strange, that I never share the password with anyone.
Just did hard reset and start settings from the beginning.

Re: Hi traffic from Mikrotic, ISP complains on DDOS

Posted: Wed Dec 25, 2024 5:45 pm
by optio