Advisory: Vulnerability exploiting the Winbox port [SOLVED]

This is from Web. Most likely unrelated.

but should still be firewalled :slight_smile:

Correct me if I’m wrong, but isn’t something missing here? Now we know how they got passwords to log in, but what about those files (script and binary) uploaded to router and (probably) executed by RouterOS? Is it some other hidden functionality of WinBox we know nothing about?

When the tool gets your password, it has full access and installs some kind of tools. This is secondary. Most importantly is to close access to your device so this is impossible.

Maybe, but this is strange. Web interface indeed is available from Internet, but I changed default port from 80 to something else, and there was 5 attemps in 2 seconds, possible attack ?

Although I understand the decission not to make the vulnerability information public, we need to know if a exposed winbox port with “Available From” address list is vulnerable or not.

We’ve some devices with disabled conntrack, so we can’t protect it by firewall. For now we’ve completely disabled winbox service.

By the way, as it uses the same user database… can BTest Server be vulnerable? We’ve also deactivated it in all the routers…

Regards

Any Informations on how to use this exploit?
I’ve inherited a wide-range setup with unknown password and resetting will need a crane or something like this :slight_smile:

scanning for the new port isn’t hard to do.
firewalling that port (and others) will make sure they can’t try to brute force it

That is kind of strange, because when I know the password of my router I still cannot install that kind of tools!
So there are multiple faults here.

I have the admin password of my own router, how can I upload shell scripts and ELF binaries to be executed?

Like I said, this issue is secondary. It exists yes.

On MT specific hardware and using WINBOX – winbox – gains root access and if a vulnerability exists in Winbox code then root access can be had once that code is exploited but no one has yet proven that Winbox has that vulnerability .. so are there multiple faults here ---- like a special provision for Auctoritas?

I just installed it again with netinstall … I do not want hidden visitors in my system…

Is that now fixed in the latest release? Or are we waiting for an exploit for that one once a new way to enter access has been discovered?

Like a special provision for Auctoritas?

!) winbox - fixed vulnerability that allowed to gain access to an unsecured router;

Shifting of the blame onto users… what else are we supposed to use for remote management?

The point being is that it appears there are folks out there that seem to understand how this router is coded from the ground up. So either the entire code has been compromised (stolen) or a former employee is disgruntled and is enacting revenge or a current employee is a criminal. I favour the latter scenario seeing as its based on recent work of 6.39…
However, as I noted before for the Wireless Issues, a lack of communication strategy will lead to speculation which I am quite guilty of…

To state hey don’t worry (its just a secondary issue) about super sophisticated tools, that allow the hacker more granularity than you do as an admin, is the wrong approach with this group.
As for Auctoritas-what? Mozerd. Is this the title of the next book in the Dan Brown’s Robert Langdon Series? :stuck_out_tongue_winking_eye:

Just finished moving the entire network to 6.40.7 on Sunday and I was so proud :slight_smile:
And this now :frowning:


Hopefully a new Bugfix will be rolled out very soon

Normis (or other MikroTik people here) - can you, please, share the very important info: Is there a known attack / exploit you were informed about? Did you learn about this vulnerability from your own studies or from a “friendly” user? Or was someone already attacked, and it came during the analysis?
Or - simpler - is there a known exploit scanning the internet right now? Is there a group of people having detailed knowledge about this vulnerability? Or was it caught in advance, before anyone started exploiting it?

Where do you see shifting blame on the users? It is information for users to know that routers are safe against this vulnerability if winbox port was protected.