Community discussions

MikroTik App
 
Hoov
Member Candidate
Member Candidate
Topic Author
Posts: 114
Joined: Fri Mar 30, 2018 9:08 am
Location: NE Michigan

Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Mon Dec 23, 2019 7:21 am

https://fossbytes.com/notorious-lazarus ... x-malware/

This was an article that was forwarded to me by a friend who knows I use Mikrotik devices. I do try to keep everything updated to one of the last two releases. From what I understand of this, it is using a plugin that has already been dealt with several updates ago. Has anyone looked into this at all?
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Mon Dec 23, 2019 7:52 am

I guess we will find out, since its a new threat...
Just dont let 8291 open to public...
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11594
Joined: Thu Mar 03, 2016 10:23 pm

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Mon Dec 23, 2019 8:21 am

Just dont let 8291 open to public...

... or to a host running Atlassian which might be already compromised by the same exploit.
 
R1CH
Forum Guru
Forum Guru
Posts: 1101
Joined: Sun Oct 01, 2006 11:44 pm

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Wed Dec 25, 2019 1:12 am

This doesn't mention a specific exploit, just a port scan. So there is nothing you're really "vulnerable" to, but if your winbox port is reachable by random users you should expect that to change in the future.
 
r00t
Long time Member
Long time Member
Posts: 674
Joined: Tue Nov 28, 2017 2:14 am

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Wed Dec 25, 2019 1:52 am

It's best to use VPN to manage your routers from outside, but if you don't want to, at least do these simple steps:
1) do not use default admin account, create new one with unique name and strong password and disable the original admin
2) change winbox port to a new one
This will help you greatly against basic bots looking for default port open and also bruteforcing or common password testing using default admin user name.
You still might be vulnerable in case new zero-day exploit is discovered, but having changed the port number, you will probably not be that quickly pwned.
Or even better:
3) search for "port knocking" on this forum on how to setup it so winbox port is closed unless you send a specific sequence of packets to router to open it for that one IP only. It's not as good as VPN but helps a lot to hide the port
 
gotsprings
Forum Guru
Forum Guru
Posts: 2118
Joined: Mon May 14, 2012 9:30 pm

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Thu Dec 26, 2019 5:32 pm

Port knocking and address lists. Also add scanners to drop list.
 
Hoov
Member Candidate
Member Candidate
Topic Author
Posts: 114
Joined: Fri Mar 30, 2018 9:08 am
Location: NE Michigan

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Sat Dec 28, 2019 7:29 am

For now, it really doesn't matter. Our network is not accessible from the outside. Not that I have not tried, but we had a bit of a scare a year and a half ago, and I locked it down. I just wanted to being this up, just in case there was a vulnerability. Our network is finally running fairly smooth, and I want to keep it that way.
 
User avatar
ingdaka
Trainer
Trainer
Posts: 452
Joined: Thu Aug 30, 2012 3:06 pm
Location: Albania
Contact:

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Sat Dec 28, 2019 11:38 pm

This phrase on that post:
The report reads, “We are not sure why TCP 8291 is targeted, but we know that the Winbox protocol of the MikroTik Router device works on TCP / 8291 port and is exposed on the Internet.”

Is the group real from North Korea or is supported by Cisco / Unify with friends because Mikrotik is gaining his reputation and sales on the top of others... so they cannot beat Mikrotik in market and do those types to make people "think twice" before buy a Mikrotik device...
 
gotsprings
Forum Guru
Forum Guru
Posts: 2118
Joined: Mon May 14, 2012 9:30 pm

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Sun Dec 29, 2019 4:53 pm

I swear i remember an article more than a year ago, about holding the connection open to 8291 and using it to probe Tik Networks.

It was the next "big thing" after Slingshot.
 
Hoov
Member Candidate
Member Candidate
Topic Author
Posts: 114
Joined: Fri Mar 30, 2018 9:08 am
Location: NE Michigan

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

Thu Jan 02, 2020 7:17 am

If I remember correctly, there was a vulnerability in ROS. There were two ways of dealing with it. Update it, or close port 8291. I may be wrong about that though. But I do remember the port being vulnerable, and there was an update. But this is something new. At least as far as a I can find out.

Who is online

Users browsing this forum: dioeyandika, munimleo, tlamik and 104 guests