<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Атакуют наш MT роутер?]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Атакуют наш MT роутер? форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Sun, 16 Aug 2026 12:25:00 -0400</pubDate>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276203">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я тут новенький в RouterOS и у меня вопрос. Если я хочу добавить список "http://www.spamhaus.org/drop/drop.txt", как это лучше сделать? <br />
			<i>17.03.2014 22:15:00, francisuk24.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276203</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276203</guid>
			<pubDate>Mon, 17 Mar 2014 22:15:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276202">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я тоже пробовал использовать подобные правила, но они выдают слишком много информации, которая мне не нужна. Мне просто нужно видеть IP-адрес и количество попыток. Вот что я обычно вижу с упомянутым правилом:<br />Sep/13/2012 16:08:37 route,ospf,debug ssh_blacklist (input): RECV: Hello &lt;- 172.16.0.1 on ether2 (172.16.0.200)<br />Sep/13/2012 16:08:37 route,ospf,debug,raw ssh_blacklist (input): PACKET:<br />Sep/13/2012 16:08:37 route,ospf,debug,raw ssh_blacklist (input): &nbsp; &nbsp; 45 C0 00 54 20 97 00 00 01 59 0B E4 AC 10 00 01<br />Sep/13/2012 16:08:37 route,ospf,debug,raw ssh_blacklist (input): &nbsp; &nbsp; E0 00 00 05 02 01 00 30 0A 00 00 01 AC 10 00 00<br />Sep/13/2012 16:08:37 route,ospf,debug,raw ssh_blacklist (input): &nbsp; &nbsp; 00 00 00 02 00 00 01 10 00 00 0B 77 FF FF FF 00<br />Sep/13/2012 16:08:37 route,ospf,debug,raw ssh_blacklist (input): &nbsp; &nbsp; 00 0A 02 01 00 00 00 28 00 00 00 00 00 00 00 00<br />Sep/13/2012 16:08:37 route,ospf,debug,raw ssh_blacklist (input): &nbsp; &nbsp; AC 10 00 C8 B0 6E EF 95 5C 8B 55 2B EE CD 0F 49<br />Sep/13/2012 16:08:37 route,ospf,debug,raw ssh_blacklist (input): &nbsp; &nbsp; 70 B1 8B 29<br />Sep/13/2012 16:08:37 route,ospf,debug ssh_blacklist (input): &nbsp; received options: E<br />Sep/13/2012 16:08:38 pptp,debug,packet ssh_blacklist (input): rcvd Echo-Request from 10.0.0.2<br />Sep/13/2012 16:08:38 pptp,debug,packet ssh_blacklist (input): &nbsp; &nbsp; identifier=15<br />Sep/13/2012 16:08:38 pptp,debug,packet ssh_blacklist (input): sent Echo-Reply to 10.0.0.2<br />Sep/13/2012 16:08:38 pptp,debug,packet ssh_blacklist (input): &nbsp; &nbsp; identifier=15<br />Sep/13/2012 16:08:38 pptp,debug,packet ssh_blacklist (input): &nbsp; &nbsp; result-code=1<br />Sep/13/2012 16:08:38 pptp,debug,packet ssh_blacklist (input): &nbsp; &nbsp; error-code=0 <br />
			<i>13.09.2012 14:16:00, kameelperdza.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276202</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276202</guid>
			<pubDate>Thu, 13 Sep 2012 14:16:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276201">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Если хочешь логировать все последующие попытки входа с заблокированных адресов, поставь это выше правила "action=drop": /ip firewall filter<br />add chain=input protocol=tcp dst-port=22 src-address-list=ssh_blacklisted action=log log-prefix=SSH-blacklisted comment="log blacklisted ssh brute forcers" disabled=no <br />
			<i>13.09.2012 13:35:00, Hotz1.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276201</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276201</guid>
			<pubDate>Thu, 13 Sep 2012 13:35:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276200">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я кое-что сделал: заменил критическое логирование с `echo` на запись в файл. Так мне проще отслеживать, сколько раз конкретный IP-адрес пытается подключиться. <br />
			<i>13.09.2012 08:13:00, kameelperdza.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276200</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276200</guid>
			<pubDate>Thu, 13 Sep 2012 08:13:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276199">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Обычно просто случайное сканирование портов. Местная кабельная компания получала мощную атаку, а мой подсеть отличается всего на пару цифр, и вскоре меня тоже затронуло. <br />
			<i>06.08.2008 02:26:00, 0ldman.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276199</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276199</guid>
			<pubDate>Wed, 06 Aug 2008 02:26:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276198">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Как они вообще узнают, что я только что установил новую копию RouterOS? Они ищут во всем интернете? Или мой сервер отправляет какие-то пакеты? Или они узнают это с форумов??? <br />
			<i>05.08.2008 22:45:00, Repla.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276198</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276198</guid>
			<pubDate>Tue, 05 Aug 2008 22:45:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276197">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, проверь вот это: <noindex><a href="http://joshaven.com/resources/tricks/mikrotik-automatically-updated-address-list/" target="_blank" rel="nofollow" >http://joshaven.com/resources/tricks/mikrotik-automatically-updated-address-list/</a></noindex> <br />
			<i>01.07.2016 10:15:00, amt.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276197</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276197</guid>
			<pubDate>Fri, 01 Jul 2016 10:15:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Атакуют наш MT роутер?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276196">Атакуют наш MT роутер?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, последние несколько дней каждый раз, когда я открываю новый терминал, я вижу список критических неудач входа для несуществующих имен пользователей. Иногда кажется, что там тысячи таких сообщений (не показано). Это какая-то атака? Что мне делать? Смотри ниже:<br /><br />MMM &nbsp; &nbsp; &nbsp;MMM &nbsp; &nbsp; &nbsp; KKK &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TTTTTTTTTTT &nbsp; &nbsp; &nbsp;KKK<br />MMMM &nbsp; &nbsp;MMMM &nbsp; &nbsp; &nbsp; KKK &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TTTTTTTTTTT &nbsp; &nbsp; &nbsp;KKK<br />MMM MMMM MMM &nbsp;III &nbsp;KKK &nbsp;KKK &nbsp;RRRRRR &nbsp; &nbsp; OOOOOO &nbsp; &nbsp; &nbsp;TTT &nbsp; &nbsp; III &nbsp;KKK &nbsp;KKK<br />MMM &nbsp;MM &nbsp;MMM &nbsp;III &nbsp;KKKKK &nbsp; &nbsp; RRR &nbsp;RRR &nbsp;OOO &nbsp;OOO &nbsp; &nbsp; TTT &nbsp; &nbsp; III &nbsp;KKKKK<br />MMM &nbsp; &nbsp; &nbsp;MMM &nbsp;III &nbsp;KKK KKK &nbsp; RRRRRR &nbsp; &nbsp;OOO &nbsp;OOO &nbsp; &nbsp; TTT &nbsp; &nbsp; III &nbsp;KKK KKK<br />MMM &nbsp; &nbsp; &nbsp;MMM &nbsp;III &nbsp;KKK &nbsp;KKK &nbsp;RRR &nbsp;RRR &nbsp; OOOOOO &nbsp; &nbsp; &nbsp;TTT &nbsp; &nbsp; III &nbsp;KKK &nbsp;KKK<br /><br />MikroTik RouterOS 3.0rc6 &#169; 1999-2007 <noindex><a href="http://www.mikrotik.com/" target="_blank" rel="nofollow" >http://www.mikrotik.com/</a></noindex><br />(3124 messages not shown)<br />oct/07/2007 06:23:51 system,error,critical login failure for user httpd from 213.21.208.164 via ssh<br />oct/07/2007 06:23:55 system,error,critical login failure for user pop from 213.2 1.208.164 via ssh<br />oct/07/2007 06:24:00 system,error,critical login failure for user nobody from 213.21.208.164 via ssh<br />oct/07/2007 06:24:03 system,error,critical login failure for user root from 213. 21.208.164 via ssh<br />oct/07/2007 06:24:12 system,error,critical login failure for user backup from 213.21.208.164 via ssh<br />oct/07/2007 06:24:17 system,error,critical login failure for user info from 213. 21.208.164 via ssh<br />oct/07/2007 06:24:20 system,error,critical login failure for user shop from 213. 21.208.164 via ssh<br />oct/07/2007 06:24:24 system,error,critical login failure for user sales from 213 .21.208.164 via ssh<br /><br />Terminal vt102 detected, using multiline input mode<br />[admin@MikroTik] &gt; <br />
			<i>06.10.2007 21:38:00, kvan64.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276196</link>
			<guid>http://mikrotik.moscow/forum/forum57/69856-atakuyut-nash-mt-router/message276196</guid>
			<pubDate>Sat, 06 Oct 2007 21:38:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
