Correct me if I’m wrong, but isn’t something missing here? Now we know how they got passwords to log in, but what about those files (script and binary) uploaded to router and (probably) executed by RouterOS? Is it some other hidden functionality of WinBox we know nothing about?
When the tool gets your password, it has full access and installs some kind of tools. This is secondary. Most importantly is to close access to your device so this is impossible.
Maybe, but this is strange. Web interface indeed is available from Internet, but I changed default port from 80 to something else, and there was 5 attemps in 2 seconds, possible attack ?
Although I understand the decission not to make the vulnerability information public, we need to know if a exposed winbox port with “Available From” address list is vulnerable or not.
We’ve some devices with disabled conntrack, so we can’t protect it by firewall. For now we’ve completely disabled winbox service.
By the way, as it uses the same user database… can BTest Server be vulnerable? We’ve also deactivated it in all the routers…
Any Informations on how to use this exploit?
I’ve inherited a wide-range setup with unknown password and resetting will need a crane or something like this
On MT specific hardware and using WINBOX – winbox – gains root access and if a vulnerability exists in Winbox code then root access can be had once that code is exploited but no one has yet proven that Winbox has that vulnerability .. so are there multiple faults here ---- like a special provision for Auctoritas?
The point being is that it appears there are folks out there that seem to understand how this router is coded from the ground up. So either the entire code has been compromised (stolen) or a former employee is disgruntled and is enacting revenge or a current employee is a criminal. I favour the latter scenario seeing as its based on recent work of 6.39…
However, as I noted before for the Wireless Issues, a lack of communication strategy will lead to speculation which I am quite guilty of…
To state hey don’t worry (its just a secondary issue) about super sophisticated tools, that allow the hacker more granularity than you do as an admin, is the wrong approach with this group.
As for Auctoritas-what? Mozerd. Is this the title of the next book in the Dan Brown’s Robert Langdon Series?
Normis (or other MikroTik people here) - can you, please, share the very important info: Is there a known attack / exploit you were informed about? Did you learn about this vulnerability from your own studies or from a “friendly” user? Or was someone already attacked, and it came during the analysis?
Or - simpler - is there a known exploit scanning the internet right now? Is there a group of people having detailed knowledge about this vulnerability? Or was it caught in advance, before anyone started exploiting it?
Where do you see shifting blame on the users? It is information for users to know that routers are safe against this vulnerability if winbox port was protected.