Something NEEDS to be done about the default passwords

Brecht as in north of Antwerp ? That’s 40km from where my spare is sitting (Kontich). If REALLY needed, you can collect it tomorrow (I’m not there but I can instruct the colleagues to fetch it from my desk).
Just let me know AT gmail DOT com

Or Brecht, Germany ? That’s a bit further away :laughing:
(160km from where I live)

Thinking out of the box here. When the board is not matching the case then you have this problem. Did you check if the replied MAC is still as the one on the box, after a reset?

Last edited by bpwl on Wed Apr 19, 2023 8:13 pm, edited 2 times in total.

Be careful with that assumption.
I have recently taken 11 cAP AX devices in service and those MAC addresses are really close to each other.

Last edited by bpwl on Wed Apr 19, 2023 8:13 pm, edited 2 times in total.

Last edited by bpwl on Wed Apr 19, 2023 8:13 pm, edited 2 times in total.

Reset to factory settings then.

That would be correct for port 3

Hi,

how to do netinstall to get rid of default password?

  1. I would like to keep the option when I reset the router it will ask me if I want to keep the default/basic configuration but without the default password. How to do this?
  2. If the option 1 is not possible I set up the device to a some basic setup and do the netinstall and tick keep default config?

Thank you

With the CLI version, it’s the -r flag. That tells netinstall to erase the existing config and reapply the default config. Along with this, you upload a new RSC file with -s to define a new “full” capability user with whatever password you like. You can make this script delete the default one in the same step, but I just add a new one and then manually delete it once I get logged in with my new user.

I’ve documented my procedure here. I find it considerably simpler than the Windows GUI instructions.

If you must use the not-actually-easier GUI version, I’m not going to be much more help than the docs.

Last edited by bpwl on Wed Apr 19, 2023 8:13 pm, edited 2 times in total.

Dear MikroTik:

It’s been well over a year, you have improved this process, but for the love of god please include barcodes and/or QR codes with your devices that includes the devices password and stick it on the outside of the box

It’s still painful to onboard MikroTik devices
If we have a barcode to scan then

  1. the absolute most important thing is zero spelling mistakes the barcode will be an exact match
  2. speed of processing, hundreds of devices can be ‘onboarded’ in a few minutes (whether that be inventory management or actual provisioning with custom scripted systems)
  3. it’s adaptable to anyone in a company, any trainee can be taught in 30 seconds how to use a barcode scanner and never needs to know anything about winbox or netinstall. The entire lifeline process can extend from the barcode itself

You can already kind-of use barcodes to get the passwords

Ask for the CSV file from the distributor, that includes your devices (they have password files).
Make some script that looks up the password based on the serial number.
Scan barcode and it will spit out the password

Please consider also this:
http://forum.mikrotik.com/t/feature-request-on-new-devices-set-the-admin-username-to-the-same-as-the-password-on-the-label/182059/1

+1

Perhaps the username should get randomized too? Since stickers are not going away.. a radmon username would aid some in a branding/netinstall defconf script IMO. For example, in some cases it be nice for the end-user to use the sticker and be prompted by RouterOS to change the password. My objection to the sticker is that I think "admin" as username is really dumb — so forcing a password change on default "admin" isn't actually helpful in RouterOS "built in" first-time login - so my defconf has to remove it and add new users, all of which must then be communicated/stored/etc. While, in some cases, being able to have my custom config, but still let the user change the password at first-login would be useful.

And this lead to the 2nd problem is unchangeable default "admin" in webfig — which since I never "admin" as username in a decade, it be wrong for just as long. But from usability POV to an end-user, they might [incorrectly] assume the username is actually "admin", given it's pre-populated and on sticker.

Basically the stickers lead into "admin" being the default username still, which is so easily re-used as a 2nd-factor (of sorts) since an attackers do guess "admin".

See thats missing the point. There’s a reason why barcode’s are still used absolutely everywhere in almost every industry from shipping to assembly and installers
You have that specific product in front of you, you match it with the barcode as its processed. You don’t do it in advance and go looking up CSV files
Barcode goes on box, box is scanned in. Product is now verified and proceeds to next step
Reaching out to vendors is double/triple handling at least. Just stick the barcode directly on the product & box themselves then even the work-experience kid can be assured its matching the right product because the scanner went ‘beep’

I’d be more than happy to send you a video of the onboarding process we use with other vendors demonstrating this marvel of ingenuity, it’d be about 3 seconds long and has had a 100% accuracy rating over thousands of devices. As well as a 10 minute long MikroTik one for contrast, where the operator is ready to throw the device against a wall and needs some anger management therapy afterwards