It was less than a month between the increased botnet http vuln (03/28) & the discovery of the winbox vuln (04/23)
Can someone confirm VPNfilter exclusively utilizing the http vuln ?
A post in the http vuln (03/28) thread: “Also via the winbox port … We think there is a circular second exploit that works in a similar way to this.”
- It was repeatedly stated the winbox port was getting hit only to identify the device as MT.
I don’t have a ton of time for forum searches, but i believe there were a few winbox vuln posts floating around between the http & winbox discoveries. The timeline feels fuzzy.
- Sorry about the edits