VPNfilter official statement

I understand … but we need assume that Mikrotik is doing their best and try to deliver software without bugs. If we/they have no proof that something is “broken” then they always could say “YES, it is safe”.

  1. If you are running any open ports on your router, then you are unsecured and implicitly accepting ALL the associated risks of remote exploits. That is regardless of the manufacturer. The device and service you choose to run is irrelevant.

  2. Scans against any ports, specific or otherwise, mean nothing by themselves from a security perspective, i.e. this provides no new information of any kind since they are trivial to do.

  3. If you are asking in this thread whether there is a 0-day exploit for Mikrotik routers and your only evidence for that are port scans, then please stop wasting everyone’s time. How on Earth would anyone know that?

If your target audience is the vendor, they would not release information of a 0-day to you without going through private channels, for obvious reasons. If your target audience are hackers, they would say nothing on public forum, regardless of whether they are black hats or white hats. If your target is everyone else, ask in a completely separate thread with your specific evidence or concerns, not piggybacking on the official statement for a known attack.

Many people watch these official threads for very specific topic information or official information, not for general discussion. Thank you.

A new technical update was published, which expands the compromised device list to include almost all Mikrotik boards (CCR1009 (new), CCR1016, CCR1036, CCR1072, CRS109 (new), CRS112 (new), CRS125 (new), RB411 (new), RB450 (new), RB750 (new), RB911 (new), RB921 (new), RB941 (new), RB951 (new), RB952 (new), RB960 (new), RB962 (new), RB1100 (new), RB1200 (new), RB2011 (new), RB3011 (new), RB Groove (new), RB Omnitik (new), STX5 (new)).

https://blog.talosintelligence.com/2018/06/vpnfilter-update.html

The new version of VPNfilter intercepts HTTP traffic and rewrites HTTPS to HTTP. This makes it possible to detect signs of compromise externally, as it modifies the HTTP request, but at this time it isn’t possible to know what domains it is targeting.

Since the remote exploit targets previously known RouterOS vulnerabilities, then naturally it would have included all RouterOS devices anyway.

These Affected Devices lists are more informational than containing any new warnings because they simply show what devices they are seeing being targeted in the wild.

It may be more serious for other vendors if it is using a host of different vulnerabilities to span architectures (because different platforms may be updated differently), or worst of all, if it is using zero-day exploits (not as far as anyone knows).

If your have no open ports on your WAN interface, then you are completely safe from remote wired exploits of any kind. This is the default state for all Mikrotik SOHO devices, afaik.

w 0 w the problem it`s more bigger.

https://www.theregister.co.uk/2018/06/07/vpnfilter_is_much_worse_than_everyone_thought/

Actually I have always found it ridiculous that MikroTik people made remarks on this forum that RouterOS is safe because there were no known security problems and there had been no major problems in the past.
Results obtained in the past are no guarantee for the future, and when software has no known problems it usually means there has been no adquate search for problems.

Now that the bad guys have discovered MikroTik, problems appear everywhere. That was only to be expected. It happened with all the other manufacturers as well.
This means there was no safety to begin with, it was only imagined. In fact we are lucky that up to now all the discovered problems are in services that you can quite easily firewall, but again: there is no guarantee that it will remain that way.

Unfortunately that is not true at all. You are safe from the exploits as they are seen now. You could still have problems e.g. when there turns out to be a problem in some obscure firewall rule type like L7 matching or when there is a problem in some client that you have to run (e.g. DHCP client).

Hi folks,
now are more mikrotik devices affected…

https://blog.talosintelligence.com/2018/06/vpnfilter-update.html
Also my RB3011…
Any solution from Mikrotik?

regards

Alex

No more devices affected, just an updated announcement after the announcers better researched the MikroTik product gamma.
(the original announcment where it was said it affected CCR1016 1036 and 1072 but not 1009 was of course hogwash)

Solution was mentioned already in the first post, please don’t append questions without reading the topic.

ALL devices are affected which has OLD RouterOS. Cisco doesn’t know that many devices can have the same firmware. And they’re not able to write affected firmware versions. So just upgrade to the current of bugfix version.

The fact that Mikrotik is still on the list due to them seeing Mikrotik routers still being hit by this means one thing only for Mikrotik users. They have failed to keep their routers current and are still running over a YEAR OLD (plus) version of ROS. Regardless of this virus attack, that is just bad practices all around.

Hi to all
I think my router has been hacked i can’t login to my router (CCR-1036-12G-4S) and i don’t have backup to reset and restore backup, i have more data inside :frowning:

Of course. Just like those people that post “I am locked out of my router and I don’t have a backup”. Just bad practices.
But that happens to all manufacturers, there is always a certain percentage of customers that do not update, do not backup, etc.
That is also the reason why the whole “internet of things security” is such a hot topic now. Millions of devices with poor default
security in the hands of unknowing users. That is just a disaster waiting to happen. (actually: a disaster already happening)

It’s also bad practice on the part of Mikrotik when it comes to information, it took them over a year to email about the httpd vulnerability, and I still have not yet received an email advisory about the winbox vulnerability. You cannot expect all Mikrotik users to be checking forum and changelog constantly.

There is a lot of information here, how to protect router, how to deal with infection, how we should always upgrade and few overconfident statement about how were routers infected. But one crucial information is missing: how to determine if my router is infected?
And I know you already typing “Just upgrade your…” before you even finish reading this, but please bear with me and read on first.

Yes, we have some routers without latest upgrades, yes we should upgrade them and yes, it is not MikroTiks fault it is logistic nightmare to always upgrade all routers in our specific situation. We took every precaution to minimize the risk - we disabled every service except ssh and winbox and even then only from one of internal networks, created robust firewall rules etc. Now we want to determine IF router is infected or not. We want to determine it BEFORE we upgrade and therefore eliminate potential infection. If we are infected, that means it had to come from inside the network and therefore our network is not safe. That would mean some device in our network is spreading infection. And to not trying to get that information, I would be a terrible network administrator. Saying that we should upgrade is therefore not satisfactory.

And before you jump into conclusion that our router is not infected, because we disabled webserver etc., I don’t buy this at all. Although it is most likely, that this particular vulnerability was exploited by VPNfilter, it is yet to be confirmed. And until it is confirmed that no other 0-day vulnerabilities were exploited too, we all are at potential risk. Just dismissing it by “upgrading and don’t asking questions” is unprofessional and irresponsible, it gives you false sense of security.

Also, with security threats constantly on the rise, it would be nice if there was a dedicated Security sub-forum or more some kind of channel / RSS / mailing list which would discuss only security and which we could subscribe to be notified of things like this.

There is unfortunately no easy way to tell, since Mikrotik doesn’t allow us shell access to our routers to perform this kind of examination. Lack of shell access also makes it hard to tell if upgrading a compromised device actually removes the compromise, advanced malware could easily persist after an upgrade. If you think a device may be infected, netinstall is by far the safest option.

For now the best indicator of compromise would be to watch your outbound traffic at an upstream device, eg looking for suspicious traffic or traffic to known IPs associated with the malware. You can’t trust monitoring the firewall table or torch etc since malware could hide itself from these lists (no indication VPNfilter does this yet, but certainly possible).

There is a “check installation” feature but unfortunately it does not check if there are files on the router that are unaccounted for, even though this has been claimed.

Back in the Urgent security advisory, it was said that upgrading your RouterOS version would remove “the bad files” on the device.
I have not heard anywhere that this is not the case for all RouterOS upgrades, so I would assume that it remove all unknown files when upgrading even now.
While a confirmation from MikroTik would be nice, I see no need to panic before otherwise is proven. Not like I can do much about it until then anyway.

Just upgrade your routers to RouterOS bugfix >6.40.8 or stable >6.42.1, and possibly secure your routers. Once that is done, just wait for further information.

http://forum.mikrotik.com/t/urgent-security-advisory/117944/1

If the malware is already on the device with root level privileges, it can easily hide itself from a filesystem check.