Urgent security advisory

not really - go for latest 6.41. due to smb exploit for 6.40.x https://github.com/BigNerd95/Chimay-Blue
original “chimay red” exploit had persistence option - check wikileaks files.

Hello, good morning, in case of mass update, more than 320 equipments, is there any script?

Thank you

@normis… Ok so now I am really confused… People above point out how to see infection via a simple “ls” on the /rw directory but the ability to perform the “ls” is not available. So how the heck are we supposed to check to see if a machine is infected? And please don’t point at another post because I looked at all the other posts and nothing was pointed out as “Here this is what you see if you are infected” EXCEPT the results of a tool we can’t have. And yes all my ports are filtered, but that is not good enough to verify not infected… And upgrading some of these machines may not work due to legacy hardware.

Those are not “people” but one person who has already hacked his device himself. You can ignore him, his instructions can’t be done by others.
There is only one thing needed to determine if you are vulnerable = upgrade RouterOS. Read the first post, the questions are answered there.

“Here this is what you see if you are infected”

There is no such test. Upgrade is mandatory. There is no other way to clean this tool from your device.

I suggest you edit the very first message in the thread and write that only 6.41.X has all required fixes.

\

This is why upgrading to LATEST version is important.

What is the “LATEST version”. Do you mean LATEST released version of maybe LATEST RC versions?
We are on the internet, as you may notice, use https links to point the version what you are talking about.

\

Currently this botnet only spreads and scans

Why do you think so? The vulnerability allows to load some random code to Mikrotik and run it, why you are sure that it “only spreads and scans”?

I can see completely different picture here: ESTABLISHED ssh connections to some hosts from our Mikrotik, attempts to connect over ssh to internal hosts.

Sometimes nmap utility shows Mikrotik devices on the other side, sometimes not.

Please at least read carefully before spreading your misleading things. Even your own posts are conflicting!

carefully compare these sentences:

Currently this botnet only spreads and scans

Why do you think so? The vulnerability allows

You are mixing up two different topics! Botnet is discussed here. Your device shows unrelated file, possibly injected by the SMB vulnerability that was closed in v6.41 like I said before. This has nothing to do with the botnet. Also, if you have installed command line shell access, who can know where you got this package from, what other stuff you accidentally installed and what other intrusion points you opened by installing this stuff

My personal recommendation to you is reinstall your device with Netinstall.

As you may understand it was done because we could get a proper answer from support.


There is only one thing needed to determine if you are vulnerable = upgrade RouterOS. Read the first post, the questions are answered there.

You are changing clothes on the go. Now you say that upgrade to 6.41.3 is mandatory.


There is no such test. Upgrade is mandatory. There is no other way to clean this tool from your device.

We tried to perform an upgrade from 6.40.5 to 6.41.3 for 2 infected devices remotely.
Both upgrades were unsuccessful (one device was reset to defaults, another one is not responding and we are waiting for someone in the remote office to have a look at the device).

There is this page with some info on how to do that:
https://wiki.mikrotik.com/wiki/Manual:Upgrading_RouterOS#RouterOS_massive_auto-upgrade

However, it still is something that could have further clarification.
There is the “/system package update” command which has the same functionality as in the system->packages screen,
i.e. check for upgrades on the MikroTik servers and decide to install them and reboot.

There is also the “/system upgrade” command which allows downloads from local location, but it is not clear to me if
this is a recommended mechanism for new use, as it is mentioned very little. Is it part of the Dude update mechanism?

It would be nice when a mechanism can be established and configured by default in our routers to automatically update
to minimally some pre-established version. I.e on some central server a version could be stored for different architectures
and all routers will make sure their software version is at least that version. It would be possible to individually upgrade
routers to higher versions and they would not downgrade themselves to that centrally stored version, but when a router
has a lower version it would auto-upgrade itself, e.g. once a day.

Such a config would allow us to keep the network safe (e.g. in cases like this worm), without all routers automatically
tracking whatever MikroTik releases in current or bug-fix. So testing can be done and tested versions put on that
central server. In this case, the routers could use some predetermined password of the central service, but it should
not be obligatory that the central service knows all the admin passwords of the routers (as is the case with Dude).

Would it be advisable to build something like this using “/system upgrade” and a scheduled job? Is there an example?

Keep calm and don’t use exclamation signs while talking to the customer.

It’s more than related: since “the botnet issue” has started we detected malicious activity on our Mikrotiks.

@random12

Not judging anyone … but how do you have access to internals of Mikrotik? Is it official way or not?

If not, then I should agrre with Normis that you device is not the representative example for the problem.
I could agree that maybe you have example of other malicious activity but are you sure that you are not responsible for opening any “door” to your device?

It’s 100% official. No hacking at all. That’s all that I can say for now.


If not, then I should agrre with Normis that you device is not the representative example for the problem.
I could agree that maybe you have example of other malicious activity but are you sure that you are not responsible for opening any “door” to your device?

Seems that you are trying to tell me that if shell access is unofficial - then it leads to “all doors open” issue?

I really think that Mikrotik should publish an extended post with details and explanations of what was fixed and how to be sure that my device is not affected.

Hello!
How we can check if the MKT is compromised and the running processes?
As reported by other users also newer versions may be affected!

Seems that you are trying to tell me that if shell access is unofficial

Yes, that is what I am saying. There is no official way to do it, sorry, this is again misinformation.

You are changing clothes on the go. Now you say that upgrade to 6.41.3 is mandatory.

OK, maybe I can say it in some other way.

  1. Upgrade to 6.38.5 fixes the botnet scanner and removes it.
  2. Upgrade to 6.41.3 fixes SMB vulnerability.

This topic is about #1, but you don’t seem to have this issue at all, you have some other files in your system. Since you have shell access, I can’t say how you got those files in your system. I suggested clean Netinstall to restore system to defaults.

Normis thanks for this thread.


We have been dillgently upgrading all devices to 6.40.6 , locking down all http/winbox access for time being both from internal and external networks.SSH Access is only allowed from management IT management subnets for time being.
Will the 6.41.3 fixes for the SMB vulnerability be backported to the BugFix only code base any time soon ?

We’d have to do a mountain of tests before we are able to move to the Current stable.

We had a DOS attack last night for the first time in awhile. I have some firewall rules that normally shuts these attacks down but didn’t last night for some reason. Could this have been the cause of this? When I was touching the interface I saw all the traffic from different IPs but no ports were showing with them.

Hello,

I followed the instructions , but how I can find I my routers affected with this vulnerability.

Thank you

It dates from before the Internet-enabled /system package update facility. MikroTik would much rather you always update to their newest releases to make it easier on their support staff, so the newer one is the one they promote heaviest. Conversely, their customers who run networks and are interested in testing and certification often prefer the older one because they can test a specific release and then ensure that only that release gets distributed to their network devices.

We have done precisely what you describe. It’s a rather complicated script, because the MikroTik-supplied facility breaks down when the connection fails for any reason in mid transfer, etc., but the scripts we have written take care of all that and do run nightly. If you contact me off list, I’ll send you a copy that you can work from.

I wrote one in perl that can do this sort of thing. There are some example methods on the wiki for how to automate a bunch of this as well.

Thanks for replying, I could make it available because WIKI has nothing specific, API ports, API-SSL, Telnet, SSH and 80 clients are deactivated, I need to bulk update via Mac-Telnet.

I wrote one in perl that can do this sort of thing. There are some example methods on the wiki for how to automate a bunch of this as well.
[/quote]

Thanks for replying, I could make it available because WIKI has nothing specific, API ports, API-SSL, Telnet, SSH and 80 clients are deactivated, I need to bulk update via Mac-Telnet.