{"id":79489,"date":"2020-04-27T19:41:58","date_gmt":"2020-04-27T17:41:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/legkij-sposob-zashhitit-svoj-mikrotik-ot-atak"},"modified":"2020-04-27T19:41:58","modified_gmt":"2020-04-27T17:41:58","slug":"legkij-sposob-zashhitit-svoj-mikrotik-ot-atak","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/legkij-sposob-zashhitit-svoj-mikrotik-ot-atak","title":{"rendered":"Nj\u00eb m\u00ebnyr\u00eb e leht\u00eb p\u00ebr t\u00eb mbrojtur Mikrotik-un tuaj nga sulmet.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dua t\u00eb ndaj me komunitetin nj\u00eb m\u00ebnyr\u00eb t\u00eb thjesht\u00eb dhe funksionale se si me ndihm\u00ebn e Mikrotik t\u00eb mbrojm\u00eb rrjetin ton\u00eb dhe sh\u00ebrbimet \"shikues\" nga sulmet e jashtme. Dometh\u00ebn\u00eb, t'i organizojm\u00eb tre rregulla p\u00ebr t\u00eb vendosur nj\u00eb honeypot n\u00eb Mikrotik. <\/p>\n<p>Le t\u00eb paraqesim nj\u00eb skenar ku kemi nj\u00eb zyr\u00eb t\u00eb vog\u00ebl, nj\u00eb IP t\u00eb jashtme p\u00ebr t\u00eb cilin q\u00ebndron nj\u00eb server RDP, p\u00ebr pun\u00ebn e punonj\u00ebsve nga distanca. Rregulli i par\u00eb \u00ebsht\u00eb natyrisht t\u00eb ndryshohet porta 3389 n\u00eb nd\u00ebrfaqen e jashtme me nj\u00eb tjet\u00ebr. Por kjo nuk do t\u00eb zgjas\u00eb, pas disa dit\u00ebsh, regjistri i auditimit t\u00eb serverit t\u00eb terminalit do t\u00eb filloj\u00eb t\u00eb tregoj\u00eb disa autorizime t\u00eb pasuksesshme n\u00eb sekond\u00eb nga klient\u00eb t\u00eb panjohur. <\/p>\n<p>Nj\u00eb situat\u00eb tjet\u00ebr \u00ebsht\u00eb se pas Mikrotik \u00ebsht\u00eb i fshehur nj\u00eb asterisk, natyrisht jo n\u00eb portin 5060 udp, dhe pas disa dit\u00ebsh gjithashtu fillon t\u00eb b\u00ebhet nj\u00eb prov\u00eb p\u00ebr fjal\u00ebkalimet... po, e di, fail2ban \u00ebsht\u00eb zgjidhja jon\u00eb, por do t\u00eb kemi nevoj\u00eb t\u00eb punojm\u00eb pak mbi t\u00eb... p\u00ebr shembull, un\u00eb sapo e kam ngritur at\u00eb n\u00eb ubuntu 18.04 dhe u befasova kur zbulova se nga kutia fail2ban nuk p\u00ebrmban cil\u00ebsimet aktuale p\u00ebr asterisk nga e nj\u00ebjta kutia t\u00eb nj\u00ebjtit distribucion ubuntu... dhe nuk mund t\u00eb gjej shpejt rregullime p\u00ebr \"recetat\" e gatshme, numrat e l\u00ebshimeve rriten me kalimin e viteve, artikujt me \"recetat\" p\u00ebr versionet e vjetra nuk funksionojn\u00eb m\u00eb, dhe t\u00eb rinjt\u00eb pothuajse nuk shfaqen... Por po, po m\u00eb shp\u00ebton nga tema...<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nPra, \u00e7far\u00eb \u00ebsht\u00eb honeypot n\u00eb dy fjal\u00eb \u2014 \u00ebsht\u00eb nj\u00eb kurth, n\u00eb rastin ton\u00eb ndonj\u00eb port popullor n\u00eb IP-n\u00eb e jashtme, \u00e7do k\u00ebrkes\u00eb p\u00ebr k\u00ebt\u00eb port nga nj\u00eb klient i jasht\u00ebm d\u00ebrgon adres\u00ebn src n\u00eb list\u00ebn e zez\u00eb. E gjitha.<\/p>\n<pre><code class=\"plaintext\">\/ip firewall filter\nadd action=add-src-to-address-list address-list=&quot;Honeypot Hacker&quot; \n    address-list-timeout=30d0h0m chain=input comment=&quot;block honeypot ssh rdp winbox&quot; \n    connection-state=new dst-port=22,3389,8291 in-interface=\n    ether4-wan protocol=tcp\nadd action=add-src-to-address-list address-list=&quot;Honeypot Hacker&quot; \n    address-list-timeout=30d0h0m chain=input comment=\n    &quot;block honeypot asterisk&quot; connection-state=new dst-port=5060 \n    in-interface=ether4-wan protocol=udp \n\/ip firewall raw\nadd action=drop chain=prerouting in-interface=ether4-wan src-address-list=\n    &quot;Honeypot Hacker&quot;\n<\/code><\/pre>\n<p>\nRregulli i par\u00eb mbi portat popullore TCP 22, 3389, 8291 t\u00eb nd\u00ebrfaqes s\u00eb jashtme ether4-wan d\u00ebrgon IP-n\u00eb e \"mysafir\u00ebve\" n\u00eb list\u00ebn \"Honeypot Hacker\" (portat p\u00ebr ssh, rdp dhe winbox jan\u00eb \u00e7aktivizuar paraprakisht ose ndryshuar me t\u00eb tjera). Tjet\u00ebr, rregulli i dyt\u00eb b\u00ebn t\u00eb nj\u00ebjt\u00ebn gj\u00eb p\u00ebr UDP 5060 t\u00eb njohur.<\/p>\n<p>Rregulli i tret\u00eb n\u00eb faz\u00ebn e pararoutimit bllokon paketat e \"mysafir\u00ebve\" t\u00eb cil\u00ebt adresa srs e t\u00eb cil\u00ebve \u00ebsht\u00eb futur n\u00eb \"Honeypot Hacker\".<\/p>\n<p>Pas dy jav\u00ebsh funksionimi t\u00eb Mikrotik tim n\u00eb sht\u00ebpi, lista \"Honeypot Hacker\" p\u00ebrfshinte rreth nj\u00eb mij\u00eb e pes\u00ebqind IP adresa t\u00eb adhuruesve t\u00eb \"t\u00eb mbajturit p\u00ebr thithk\u00eb\" burimet e mia n\u00eb rrjet (n\u00eb sht\u00ebpi kam telefonin\u00eb time, emailin, nextcloud, rdp). Sulmet e Brute-force pushuan nd\u00ebrpriten, erdhi qet\u00ebsia. <\/p>\n<p>N\u00eb pun\u00eb nuk ishte aq e thjesht\u00eb, atje serveri rdp vazhdon t\u00eb thyhet nga p\u00ebrpjekjet p\u00ebr fjal\u00ebkalimet.<\/p>\n<p>Duket se numri i portit u p\u00ebrcaktua nga skanuesi shum\u00eb para aktivizimit t\u00eb honeypot, dhe gjat\u00eb karantin\u00ebs nuk \u00ebsht\u00eb shum\u00eb e leht\u00eb t\u00eb rilidhesh me mbi 100 p\u00ebrdorues, nga t\u00eb cil\u00ebt 20% jan\u00eb mbi 65 vje\u00e7. N\u00eb rastin kur porti nuk mund t\u00eb ndryshohet, ekziston nj\u00eb recet\u00eb e vog\u00ebl e pun\u00ebs. Kam par\u00eb di\u00e7ka t\u00eb till\u00eb n\u00eb internet, por k\u00ebtu ka shtes\u00eb dhe finesa n\u00eb cil\u00ebsim: <\/p>\n<p>                        <b class=\"spoiler_title\">Rregullat p\u00ebr konfigurimin e Port Knocking<\/b><\/p>\n<pre><code class=\"plaintext\"> \/ip firewall filter\nadd action=add-src-to-address-list address-list=rdp_blacklist \n    address-list-timeout=15m chain=forward comment=rdp_to_blacklist \n    connection-state=new dst-port=3389 protocol=tcp src-address-list=\n    rdp_stage12\nadd action=add-src-to-address-list address-list=rdp_stage12 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage11\nadd action=add-src-to-address-list address-list=rdp_stage11 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage10\nadd action=add-src-to-address-list address-list=rdp_stage10 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage9\nadd action=add-src-to-address-list address-list=rdp_stage9 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage8\nadd action=add-src-to-address-list address-list=rdp_stage8 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage4\nadd action=add-src-to-address-list address-list=rdp_stage7 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage6\nadd action=add-src-to-address-list address-list=rdp_stage6 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage5\nadd action=add-src-to-address-list address-list=rdp_stage5 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=\n    3389 protocol=tcp src-address-list=rdp_stage4\nadd action=add-src-to-address-list address-list=rdp_stage4 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=\n    3389 protocol=tcp src-address-list=rdp_stage3\nadd action=add-src-to-address-list address-list=rdp_stage3 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage2\nadd action=add-src-to-address-list address-list=rdp_stage2 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp src-address-list=rdp_stage1\nadd action=add-src-to-address-list address-list=rdp_stage1 \n    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 \n    protocol=tcp \n\/ip firewall raw\nadd action=drop chain=prerouting in-interface=ether4-wan src-address-list=\nrdp_blacklist\n<\/code><\/pre>\n<p>\nBrenda 4 minutash klientit t\u00eb larg\u00ebt i lejohet t\u00eb b\u00ebj\u00eb vet\u00ebm 12 \"k\u00ebrkesa\" t\u00eb reja p\u00ebr RDP. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/dts-shicago\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2877\">server<\/a>. Nj\u00eb p\u00ebrpjekje hyrje \u2014 \u00ebsht\u00eb nga 1 deri n\u00eb 4 \"k\u00ebrkesa\". N\u00eb k\u00ebrkes\u00ebn e 12-t\u00eb \u2014 bllokim p\u00ebr 15 minuta. N\u00eb rastin tim, keqb\u00ebr\u00ebsit nuk e ndal\u00ebn thyerjen e serverit, ata u p\u00ebrshtat\u00ebn me timerat dhe tani e b\u00ebjn\u00eb shum\u00eb ngadal\u00eb, kjo shpejt\u00ebsi shkat\u00ebrrimi e redukton efikasitetin e sulmit n\u00eb zero. Punonj\u00ebsit e nd\u00ebrmarrjes nuk ndjehen fare t\u00eb shqet\u00ebsuar nga masat e marra. <\/p>\n<p>                        <b class=\"spoiler_title\">Nj\u00eb tjet\u00ebr truk i vog\u00ebl<\/b><br \/>\n                         Ky rregull aktivizohet sipas orarit n\u00eb or\u00ebn nj\u00eb t\u00eb nat\u00ebs dhe \u00e7aktivizohet n\u00eb or\u00ebn pes\u00eb, kur njer\u00ebzit e gjall\u00eb jan\u00eb me siguri t\u00eb fjetur, kurse skanuesit automatizuar vazhdojn\u00eb t\u00eb mbesin zgjuar.<\/p>\n<pre><code class=\"plaintext\">\/ip firewall filter \nadd action=add-src-to-address-list address-list=rdp_blacklist \n    address-list-timeout=1w0d0h0m chain=forward comment=\n    &quot;night_rdp_blacklist&quot; connection-state=new disabled=\n    yes dst-port=3389 protocol=tcp src-address-list=rdp_stage8<\/code><\/pre>\n<p>\nTani, me lidhjen e 8-t\u00eb, IP e keqb\u00ebr\u00ebsit d\u00ebrgohet n\u00eb list\u00ebn e zez\u00eb p\u00ebr nj\u00eb jav\u00eb. Bukuri!<\/p>\n<p>P\u00ebr m\u00eb shum\u00eb, do t\u00eb shtoja nj\u00eb lidhje p\u00ebr artikullin Wiki, me konfigurimin funksional t\u00eb mbrojtjes s\u00eb Mikrotik nga skanuesit e rrjetit. <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.mikrotik.com\/wiki\/Drop_port_scanners\">wiki.mikrotik.com\/wiki\/Drop_port_scanners<\/a><\/noindex><\/p>\n<p>N\u00eb pajisjet e mia, ky konfigurim funksionon s\u00eb bashku me rregullat e honeypot t\u00eb p\u00ebrshkruara m\u00eb sip\u00ebr, duke i plot\u00ebsuar ato mir\u00eb.<\/p>\n<p>UPD: Si\u00e7 u sugjerua n\u00eb komentet, rregulli i bllokimit t\u00eb paketimeve \u00ebsht\u00eb zhvendosur n\u00eb RAW, p\u00ebr t\u00eb reduktuar ngarkes\u00ebn n\u00eb router.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/499146\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0425\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u044b\u043c \u0438 \u0440\u0430\u0431\u043e\u0447\u0438\u043c \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u043c, \u043a\u0430\u043a \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 Mikrotik \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u044e \u0441\u0435\u0442\u044c \u0438 \u00ab\u0432\u044b\u0433\u043b\u044f\u0434\u044b\u0432\u0430\u044e\u0449\u0438\u0435\u00bb \u0438\u0437-\u0437\u0430 \u043d\u0435\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043e\u0442 \u0432\u043d\u0435\u0448\u043d\u0438\u0445 \u0430\u0442\u0430\u043a. \u0410 \u0438\u043c\u0435\u043d\u043d\u043e \u0432\u0441\u0435\u0433\u043e \u0442\u0440\u0435\u043c\u044f \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u041c\u0438\u043a\u0440\u043e\u0442\u0438\u043a\u0435 honeypot. \u0418\u0442\u0430\u043a, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043c, \u0447\u0442\u043e \u0443 \u043d\u0430\u0441 \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043e\u0444\u0438\u0441, \u0432\u043d\u0435\u0448\u043d\u0438\u0439 IP \u0437\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0441\u0442\u043e\u0438\u0442 RDP \u0441\u0435\u0440\u0432\u0435\u0440, \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u043e\u0432 \u043f\u043e \u0443\u0434\u0430\u043b\u0435\u043d\u043a\u0435. \u041f\u0435\u0440\u0432\u043e\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u044d\u0442\u043e \u043a\u043e\u043d\u0435\u0447\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-79489","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0425\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u044b\u043c \u0438 \u0440\u0430\u0431\u043e\u0447\u0438\u043c \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u043c, \u043a\u0430\u043a \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 Mikrotik \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u044e \u0441\u0435\u0442\u044c \u0438 \u00ab\u0432\u044b\u0433\u043b\u044f\u0434\u044b\u0432\u0430\u044e\u0449\u0438\u0435\u00bb \u0438\u0437-\u0437\u0430 \u043d\u0435\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043e\u0442 \u0432\u043d\u0435\u0448\u043d\u0438\u0445 \u0430\u0442\u0430\u043a. \u0410 \u0438\u043c\u0435\u043d\u043d\u043e \u0432\u0441\u0435\u0433\u043e \u0442\u0440\u0435\u043c\u044f \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u041c\u0438\u043a\u0440\u043e\u0442\u0438\u043a\u0435 honeypot. \u0418\u0442\u0430\u043a, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043c, \u0447\u0442\u043e \u0443 \u043d\u0430\u0441 \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043e\u0444\u0438\u0441, \u0432\u043d\u0435\u0448\u043d\u0438\u0439 IP \u0437\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0441\u0442\u043e\u0438\u0442 RDP \u0441\u0435\u0440\u0432\u0435\u0440, \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u043e\u0432 \u043f\u043e \u0443\u0434\u0430\u043b\u0435\u043d\u043a\u0435. \u041f\u0435\u0440\u0432\u043e\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u044d\u0442\u043e \u043a\u043e\u043d\u0435\u0447\u043d\u043e\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/legkij-sposob-zashhitit-svoj-mikrotik-ot-atak\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041b\u0435\u0433\u043a\u0438\u0439 \u0441\u043f\u043e\u0441\u043e\u0431 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u0439 Mikrotik \u043e\u0442 \u0430\u0442\u0430\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0425\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u044b\u043c \u0438 \u0440\u0430\u0431\u043e\u0447\u0438\u043c \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u043c, \u043a\u0430\u043a \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 Mikrotik \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u044e \u0441\u0435\u0442\u044c \u0438 \u00ab\u0432\u044b\u0433\u043b\u044f\u0434\u044b\u0432\u0430\u044e\u0449\u0438\u0435\u00bb \u0438\u0437-\u0437\u0430 \u043d\u0435\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043e\u0442 \u0432\u043d\u0435\u0448\u043d\u0438\u0445 \u0430\u0442\u0430\u043a. \u0410 \u0438\u043c\u0435\u043d\u043d\u043e \u0432\u0441\u0435\u0433\u043e \u0442\u0440\u0435\u043c\u044f \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u041c\u0438\u043a\u0440\u043e\u0442\u0438\u043a\u0435 honeypot. \u0418\u0442\u0430\u043a, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043c, \u0447\u0442\u043e \u0443 \u043d\u0430\u0441 \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043e\u0444\u0438\u0441, \u0432\u043d\u0435\u0448\u043d\u0438\u0439 IP \u0437\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0441\u0442\u043e\u0438\u0442 RDP \u0441\u0435\u0440\u0432\u0435\u0440, \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u043e\u0432 \u043f\u043e \u0443\u0434\u0430\u043b\u0435\u043d\u043a\u0435. \u041f\u0435\u0440\u0432\u043e\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u044d\u0442\u043e \u043a\u043e\u043d\u0435\u0447\u043d\u043e\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/legkij-sposob-zashhitit-svoj-mikrotik-ot-atak\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-27T17:41:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-27T17:41:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47M\u00ebnyra e leht\u00eb p\u00ebr t\u00eb mbrojtur Mikrotik tuaj nga sulmet | ProHoster","description":"Dua t\u00eb ndaj me komunitetin nj\u00eb m\u00ebnyr\u00eb t\u00eb thjesht\u00eb dhe funksionale se si me ndihm\u00ebn e Mikrotik t\u00eb mbrojm\u00eb rrjetin ton\u00eb dhe sh\u00ebrbimet \"shikues\" nga sulmet e jashtme. Dometh\u00ebn\u00eb, t'i organizojm\u00eb tre rregulla p\u00ebr t\u00eb vendosur nj\u00eb honeypot n\u00eb Mikrotik. Le t\u00eb paraqesim nj\u00eb skenar ku kemi nj\u00eb zyr\u00eb t\u00eb vog\u00ebl, nj\u00eb IP t\u00eb jashtme p\u00ebr t\u00eb cilin q\u00ebndron nj\u00eb server RDP, p\u00ebr pun\u00ebn e punonj\u00ebsve nga distanca. Rregulli i par\u00eb \u00ebsht\u00eb natyrisht","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/legkij-sposob-zashhitit-svoj-mikrotik-ot-atak","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041b\u0435\u0433\u043a\u0438\u0439 \u0441\u043f\u043e\u0441\u043e\u0431 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u0439 Mikrotik \u043e\u0442 \u0430\u0442\u0430\u043a | ProHoster","og:description":"\u0425\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441 \u0441\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u044b\u043c \u0438 \u0440\u0430\u0431\u043e\u0447\u0438\u043c \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u043c, \u043a\u0430\u043a \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 Mikrotik \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u044e \u0441\u0435\u0442\u044c \u0438 \u00ab\u0432\u044b\u0433\u043b\u044f\u0434\u044b\u0432\u0430\u044e\u0449\u0438\u0435\u00bb \u0438\u0437-\u0437\u0430 \u043d\u0435\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u043e\u0442 \u0432\u043d\u0435\u0448\u043d\u0438\u0445 \u0430\u0442\u0430\u043a. \u0410 \u0438\u043c\u0435\u043d\u043d\u043e \u0432\u0441\u0435\u0433\u043e \u0442\u0440\u0435\u043c\u044f \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u041c\u0438\u043a\u0440\u043e\u0442\u0438\u043a\u0435 honeypot. \u0418\u0442\u0430\u043a, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043c, \u0447\u0442\u043e \u0443 \u043d\u0430\u0441 \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043e\u0444\u0438\u0441, \u0432\u043d\u0435\u0448\u043d\u0438\u0439 IP \u0437\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0441\u0442\u043e\u0438\u0442 RDP \u0441\u0435\u0440\u0432\u0435\u0440, \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u043e\u0432 \u043f\u043e \u0443\u0434\u0430\u043b\u0435\u043d\u043a\u0435. \u041f\u0435\u0440\u0432\u043e\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u044d\u0442\u043e \u043a\u043e\u043d\u0435\u0447\u043d\u043e","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/legkij-sposob-zashhitit-svoj-mikrotik-ot-atak","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-27T17:41:58+00:00","article:modified_time":"2020-04-27T17:41:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"79489","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:37:23","updated":"2026-02-09 21:41:53"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/79489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=79489"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/79489\/revisions"}],"predecessor-version":[{"id":160157,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/79489\/revisions\/160157"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=79489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=79489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=79489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}