{"id":89,"date":"2018-10-21T22:51:24","date_gmt":"2018-10-21T20:51:24","guid":{"rendered":"https:\/\/leeryanrs.com\/?p=89"},"modified":"2018-10-21T22:51:24","modified_gmt":"2018-10-21T20:51:24","slug":"mikrotik-router-hijack-fix","status":"publish","type":"post","link":"https:\/\/leeryanrs.com\/?p=89","title":{"rendered":"Mikrotik Router hijack fix"},"content":{"rendered":"\n<p>Mikrotik routers recently came under attack some time ago. An exploit was found to gain administrative access to them and would link them to a larger botnet network. The below will potentially help in removing the intruder and disable the security hole used by them to gain access. You should also upgrade the router to the latest available firmware<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">\/sys backup save<br>\/ip socks set enabled=no<br>\/sys scheduler remove rsched1_<br>\/sys scheduler remove schedule3_<br>\/sys script remove script3_<br>\/sys script remove rscript1_<br>\/file remove mikrotik.php<br><br>Disable the services which are not required, only winbox allowed<br>\/ip service<br>set telnet disabled=yes<br>set ftp disabled=yes<br>set www disabled=yes<br>set ssh disabled=yes<br>set api disabled=yes<br>set api-ssl disabled=yes<br><\/pre>\n\n\n\n<p>Commands explained &#8211;\u00a0<\/p>\n\n\n\n<p>First we take a backup, then disable the ip socks feature. We remove the maliciously scheduled tasks and scripts and also remove the un-needed mikrotik.php file. Lastly we are disabling all the services which shouldn&#8217;t need to be activated on the firewall\/router.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mikrotik routers recently came under attack some time ago. An exploit was found to gain administrative access to them and would link them to a larger botnet network. The below will potentially help in removing the intruder and disable the security hole used by them to gain access. You should also upgrade the router to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[32,36,41],"class_list":["post-89","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-firewall","tag-mikrotik","tag-router"],"_links":{"self":[{"href":"https:\/\/leeryanrs.com\/index.php?rest_route=\/wp\/v2\/posts\/89","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/leeryanrs.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/leeryanrs.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/leeryanrs.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/leeryanrs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=89"}],"version-history":[{"count":0,"href":"https:\/\/leeryanrs.com\/index.php?rest_route=\/wp\/v2\/posts\/89\/revisions"}],"wp:attachment":[{"href":"https:\/\/leeryanrs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=89"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/leeryanrs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=89"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/leeryanrs.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=89"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}