Security announcement blog

Add me to this. I should have gotten an email instead of having to find out the hard way. Now we have 40-50 user CPE’s, many mounted in trees that are probably unusable. Can’t log into them to fix them. What a disaster!

Getting down to fixing this cluster. Is the reset button disabled? Or can a person go to each router site, hit the reset button and put an upgraded OS on it, and the new setup? Or is the hardware now trash?

Is there a way to log into these compromised devices remotely? The devices that were compromised today are not reachable using telnet, ssh, or winbox. They are still running, presumably performing their Internet access function, but I’ve lost control of them. Maybe MT, having seriously dropped the ball in not informing a customer of 18 years that this was a problem, could suggest a comeback path?

npyoung, just make sure you have not removed your mikrotik.com account or put mikrotik.com in some spam filter, because MikroTik did send mails about this and other vulnerabilities.
Also, since the issue was patched back in april, I suggest to also check our communication channels more often (social networks, forum).

Ok, I’m glad to hear that, but I’m pretty screwed now that I didn’t get it.

Now that I have 40 infected Dynadishes, what can be done? They seem to still be functioning, but I cannot get into them from Winbox. Port 80 sort of works, the login page comes up, but then it shuts down after entering user/pass. Any ideas? Does the exploit allow for a hard reset of the dish, or are they now scrap?

Having been through this sort of thing with UBNT before, I have to say there’s a world of difference in the response. UBNT almost immediately had a fix for infected devices, followed by improvement in their excellent NMS tool, AirControl, which allows an operator to keep all the devices up on their FW. (The Dude is a pale shadow of this software.) None of this, “well, you should have been brushing your teeth after each meal” and blaming the customer. I’ve been a customer of MT for 18 years now, and I’ve been impressed by how solid a product it is. But, I’m thinking at this point, after this very expensive fiasco, it’s time to part ways, especially as it appears from the silence on a fix that I’d need to purchase new hardware. I’ll be purchasing new hardware all right, but just not from MT!

This is a public user forum, official support is not provided here, but we do try to post useful responses.
Have you tried contacting support@mikrotik.com?

You only mention that you can’t access these devices. This could be because of any number of reasons. At least you should try to connect from both interfaces, not only ethernet, but also from the wireless side.

Doesn’t always work Normis.

Please provide an itemized breakdown including disclosure on the blog of what these exploits entailed.

+2

https://forum.mikrotik.com/posting.php?mode=quote&f=21&p=682067

@npyoung

Telnet?! (You’re kidding, right?) :wink:
or winbox from WAN?!

I think you should read basic about the security configuration of your router.
Here is a very good introduction:
https://www.manitonetworks.com/networking/2017/7/25/mikrotik-router-hardening#router-configuration

Take the time to read. Winbox or Web service vulnerability can not harm your routers then.

I think you’ll have to visit your routers local if they’re really compromised.
Make a factory reset and play your backup.
Do not forget to create a backup after each upgrade!

Hint:
No SSH login via password only with ssh key.

CVE-2018-14847 - https://thehackernews.com/2018/09/mikrotik-router-hacking.html

Is the above a new vulnerability, tried searching the blog for the CVE Article number, but can’t find it on the Mikrotik Security Blog or change logs

same old. we did not assign that CVE, so we don’t mention it:
https://blog.mikrotik.com/security/winbox-vulnerability.html

Thought so, thx Normis

[quote=carlajiji post_id=684058 time=1536100711 user_id=128125]
ite is quite slow here because it has an IPv6 address in DNS but IPv6 does not actually work for this server.

can you see if this works now?
[/quote]

blog works fine over ipv6, make sure your ipv6 is configured correctly and you can ping 2a02:610:7501:1000::195

[quote=normis post_id=684097 time=1536127628 user_id=5]
[quote=carlajiji post_id=684058 time=1536100711 user_id=128125]
ite is quite slow here because it has an IPv6 address in DNS but IPv6 does not actually work for this server.

can you see if this works now?
[/quote]

blog works fine over ipv6, make sure your ipv6 is configured correctly and you can ping 2a02:610:7501:1000::195
[/quote]

It is a copy/paste of an earlier exchange in this topic (page 1) between you and me. No idea why!

That IPv6 problem was solved immediately back then.

[quote=pe1chl post_id=684110 time=1536133640 user_id=80589]
[quote=normis post_id=684097 time=1536127628 user_id=5]
[quote=carlajiji post_id=684058 time=1536100711 user_id=128125]
ite is quite slow here because it has an IPv6 address in DNS but IPv6 does not actually work for this server.

can you see if this works now?
[/quote]

blog works fine over ipv6, make sure your ipv6 is configured correctly and you can ping 2a02:610:7501:1000::195
[/quote]

It is a copy/paste of an earlier exchange in this topic (page 1) between you and me. No idea why!

That IPv6 problem was solved immediately back then.
[/quote]

probably spammer

I think so, I now notice the same behaviour in another topic. Better ban that user.

:slight_smile:

That blog is so freaking awesome!

BUGFIX UPDATE 6.40.9 RELEASED – https://blog.mikrotik.com/software/bugfix-update-6-40-9-released.html

Well, that was the first and last blog entry about a release…

We really need an email subscription list for all new releases/bugfixes/secvulns. Is that really so hard to do??? Isn’t security the core of your business???

I used to get some emails from you guys about new releases, but then from one day to another they ceased to be sent out / reach me.

RouterOS v6.34 RC (The Dude and CHR) from 12/9/2015 was the last one which I received.

BTW, today you got a lot of bad reputation at Security Now from Steve Gibson. Rightly so!