Hide-sensitive shows serial number

I had just a look at export with hide-sensitive and noticed that the serial number is stated. This can be used to indentify a member here in the forum with other information if present outside this forum.

This because, many times in replies to questions, the poster is asked to post an export and this heavy search engine indexed this information is indexed within seconds. And this information is for eternity available to most of the people on this earth and those who are in space.

So don’t make the mistake that this forum is seen as a select group. You are standing in the bright lights and every letter you type and any information given, is being recorded and made available world-wide and even outside the earth.


Users browsing this forum: …, > Baidu [Spider]> , …, > Bing [Bot]> , …, msatter, > Semrush [Bot] > and 31 guests

RIGHT.

lowercase_serial_number + .sn.mynetname.net and you are inside not-well-protected, or updated, router with cloud active…

Also login information on exported scheduler or script section (for example dyndns, no-ip, api keys, ftp passwords, etc.)…

also some tunnels ipsec password are exported (i do not remember exactly)

Is so easy “scan” *.sn.mynetname.net for find those devices…
Just search “# serial number =” on GoogIe:laughing:

Serial numbers exposed in exports is the lesser thing someone needs to worry about.
I don’t know if there are forum scrapers that look for serial numbers, but even if you don’t expose your serial number, if your device is left unprotected and vulnerable it’s just a matter of time until someone gets into it. Like all unprotected devices out there.
Sheesh.
Where will this stop?

Nice of Mikrotik to also provide, if used, the public IP of a router posting here in the forum their serial number.

Time to have someone with Mikrotik, to looks at these kind of leaking, vulnerabilities (like last, taking router hostage) from a neutral perspective and advise unasked on this.

Now we discover these things to late, while many devives are now high-jacked or taken over and/or never to be patched again.

I did search for my serial using goolge and found it once here on this forum.
Removed it.

+1
I agree Serial-Number shouldn’t be part of the /export hide-sensitive