Re: [AFMUG] mikrotik hacked.....again

2018-08-06 Thread Mike Hammett
, August 5, 2018 1:10:51 PM Subject: [AFMUG] mikrotik hacked.again Looking through all of our routers, most running the latest firmware, most running non-standard winbox ports, i still see the following today: * accept rule in firewall (for port 10438 i think, same port enabled on ip

Re: [AFMUG] mikrotik hacked.....again

2018-08-06 Thread David M
Brothers WISP <http://www.thebrotherswisp.com/> <https://www.facebook.com/thebrotherswisp> <https://www.youtube.com/channel/UCXSdfxQv7SpoRQYNyLwntZg> *From: *"CBB - Jay Fuller" *To: *af@af.afmu

Re: [AFMUG] mikrotik hacked.....again

2018-08-06 Thread David M
+1 I have always done this. We do have some customer facing routers that had this compromise. Fixed by doing the same to them. Does anyone have a source for these HAXORS ? If so Share :) On 8/5/2018 2:32 PM, Lewis Bergman wrote: It can be inconvenient, but we only allow connections from

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread Mike Hammett
https://youtu.be/yEO1qbAp2NE ;-) - Mike Hammett Intelligent Computing Solutions Midwest Internet Exchange The Brothers WISP - Original Message - From: "CBB - Jay Fuller" To: af@af.afmug.com Sent: Sunday, August 5, 2018 1:10:51 PM Subject: [AFMUG] mikro

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread Mike Hammett
Exchange The Brothers WISP - Original Message - From: "CBB - Jay Fuller" To: "AnimalFarm Microwave Users Group" Sent: Sunday, August 5, 2018 9:27:06 PM Subject: Re: [AFMUG] mikrotik hacked.again So yes I have followed this and our network has bee

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread CBB - Jay Fuller
We are also seeing something new that I don't think anyone else has seen...may wind up submitting that to mikrotik. Sent from my smartphone - Reply message - From: "CBB - Jay Fuller" To: "AnimalFarm Microwave Users Group" Subject: [AFMUG]mikrotik hacked.ag

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread CBB - Jay Fuller
and think we have a plan... Sent from my smartphone - Reply message - From: "CBB - Jay Fuller" To: "AnimalFarm Microwave Users Group" Subject: [AFMUG]mikrotik hacked.again Date: Sun, Aug 5, 2018 9:23 PM Off and onwith the socks proxy? Sent from my smartphone

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread Mike Hammett
t 5, 2018 7:06:40 PM Subject: Re: [AFMUG] mikrotik hacked.again Againanyone know what the hackers are doing? Sent from my smartphone - Reply message - From: "Josh Baird" To: "AnimalFarm Microwave Users Group" Subject: [AFMUG] mikrotik hacked..

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread Mike Hammett
quot; Sent: Sunday, August 5, 2018 3:00:19 PM Subject: Re: [AFMUG] mikrotik hacked.again just wondering: a) who else is seeing this b) what are they doing? - Original Message - From: Lewis Bergman To: AnimalFarm Microwave Users Group Sent: Sunday, August 5, 2018 2:32 PM

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread CBB - Jay Fuller
Againanyone know what the hackers are doing? Sent from my smartphone - Reply message - From: "Josh Baird" To: "AnimalFarm Microwave Users Group" Subject: [AFMUG] mikrotik hacked.again Date: Sun, Aug 5, 2018 6:12 PM This. It really should be a no-bra

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread Josh Baird
This. It really should be a no-brainer to protect your devices by only allowing management from specific management networks. If you don’t, you are asking for trouble. > On Aug 5, 2018, at 1:06 PM, Jesse DuPont > wrote: > > Exactly what Lewis said. We take an "allow specific things, block

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread CBB - Jay Fuller
just wondering: a) who else is seeing this b) what are they doing? - Original Message - From: Lewis Bergman To: AnimalFarm Microwave Users Group Sent: Sunday, August 5, 2018 2:32 PM Subject: Re: [AFMUG] mikrotik hacked.again It can be inconvenient, but we only

Re: [AFMUG] mikrotik hacked.....again

2018-08-05 Thread Lewis Bergman
It can be inconvenient, but we only allow connections from our ip at work. If you want in, you have to VPN there first. On Sun, Aug 5, 2018, 1:12 PM CBB - Jay Fuller wrote: > > Looking through all of our routers, most running the latest firmware, most > running non-standard winbox ports, i