VPNfilter official statement

Hi, after the the linked news/thread back in March (http://forum.mikrotik.com/t/urgent-security-advisory/117944/1) I checked patch levels - or at least thought I had.

On rechecking with the latest set of news today, it became clear to me that I’ve been applying upgrades incorrectly for a long time - I have only been upgrading the RouterOS packages (bang up to date now, and never far behind), not the Routerboard firmware, which was really old (3.x).

1/ Would this partial upgrade have potentially left me open to this attack? I’m hoping not, and that the firmware is basically just a bootloader.

2/ Particularly if the answer to the above is ‘yes’, it would be great to have reassurance that upgrading the firmware (which I have now done) as well as the packages would definitely clear the malware. I know Mikrotik has said ‘yes’ to this before. However, it would be good to have confirmation that - as far as Mikrotik is aware - the malware has not evolved the ability to protect itself against removal, given that we appear to be talking about a state actor that has had since March to develop this defence.

3/ (Unrelated to this thread, really) What level of general exposure would I have had from not updating firmware over a long period of time?

I have had a pretty restrictive set of firewall rules applied - there should be no access from the Internet for anything except L2TP VPN connections. Hopefully that would have mitigated the attack on its own. But it would be great to have an answer to 1/ that would apply even if I had made a mistake in those firewall rules, as it appears I’m incapable of applying an update :frowning:

Cheers,

Martin