Password bug with The Dude maps v6 (we can read XML)

Hi everyone,

On The Dude maps version 6, when copying element from the map into Notepad, we get xml, and we can read all data related to that element and also password.

Does anyone have this problem?

Hello, nikola033!

It seems that we have similar situation:
Dude-v6-Device-xml.png
Thank you!

Hi eriitguy,

I am pleased to you have joined on this topic, and that I helped you with this information.

ps. Sorry for my English

Also, if you do not have a winbox file on your computer, but winbox tool is runned on some device, you can also see the user / pass.

MT know this :slight_smile: very long.
And nothind do with this.

Hi,

Do you have new information for us?
update 6.43rc23 did not fix the problem.

Thanks a lot
Best regards
Nikola

This would be a great thing to fix. We had a penetration tester use this as a way to gain access to our routers. It has caused management to consider ripping out Mikrotik in favor of something we can manage in a secure manner.

Any response would be appreciated!

Thanks,

Jonathan

Surely changing the management tool would be a far less drastic approach ?

That said … it needs fixing !

Guys, let’s be reasonnable.

I can create my own tools and use [Device.Password] which is nice since I do not have to type it the whole day long.

Event if MT guys were to cypher the password in the DB and in the XML and wherever you can see it, what will prevent me from creating this tool :
cmd /c “echo [Device.Password] && pause”
Or any other tool where I show/store the password ?

So what’s the point ?

Huh… Readonly rights? :slight_smile:

Not about the initial question, but … why would you save passwords on a machine you don’t trust? Encrypt your disk and use a strong login password for the user of this device.

Normis … you answer resembles me the quotation of Polish Nobel’s prize receiver: “If you have fever do shutter a thermometer.” :laughing: :laughing: :laughing:

OK, agreed :slight_smile: