MikroTik security findings, explained
Every finding the audit can report has its own page: what it means, why it matters, what it looks like in Winbox, and the exact RouterOS commands that fix it. Written for people who run a MikroTik router, not only for security specialists.
Packet sniffer is streaming your traffic to a remote host
The built-in packet sniffer on your MikroTik is configured to stream a copy of network traffic to another machine. Unless you set this up yourself for troubleshooting, somebody else is intercepting what passes through your router.
A scheduler script downloads and runs remote code
A scheduler entry or script on your router fetches a file from a remote server and then executes it or changes users and services. If you did not set this up yourself, it is the classic footprint of a MikroTik botnet.
SOCKS proxy enabled on a MikroTik: the classic sign of a hacked router
Almost nobody turns on the RouterOS SOCKS proxy on purpose. Botnets do, to relay their traffic through your router. If you did not enable it yourself, treat the device as compromised and rebuild it rather than just switching the proxy off.
Web proxy enabled: when your router becomes an open proxy
The RouterOS web proxy is almost never needed today, but malware routinely switches it on to relay traffic or inject content. If it is reachable from the internet your router is an open proxy. Check who enabled it, then turn it off.
New article every other day · RSS