Community discussions

MikroTik App
 
nikola033
just joined
Topic Author
Posts: 14
Joined: Wed Jan 03, 2018 9:42 pm

Password bug with The Dude maps v6 (we can read XML)

Thu Jan 11, 2018 5:52 pm

Hi everyone,

On The Dude maps version 6, when copying element from the map into Notepad, we get xml, and we can read all data related to that element and also password.

Does anyone have this problem?

Image
 
eriitguy
Member Candidate
Member Candidate
Posts: 197
Joined: Thu Jan 26, 2017 1:16 pm

Re: Password bug with The Dude maps v6 (we can read XML)

Thu Jan 11, 2018 6:23 pm

Hello, nikola033!

It seems that we have similar situation:
Dude-v6-Device-xml.png

Thank you!
You do not have the required permissions to view the files attached to this post.
 
nikola033
just joined
Topic Author
Posts: 14
Joined: Wed Jan 03, 2018 9:42 pm

Re: Password bug with The Dude maps v6 (we can read XML)

Sun Jan 14, 2018 3:19 pm

Hi eriitguy,

I am pleased to you have joined on this topic, and that I helped you with this information.

ps. Sorry for my English
 
nikola033
just joined
Topic Author
Posts: 14
Joined: Wed Jan 03, 2018 9:42 pm

Re: Password bug with The Dude maps v6 (we can read XML)

Mon Jan 15, 2018 8:04 pm

Also, if you do not have a winbox file on your computer, but winbox tool is runned on some device, you can also see the user / pass.

Image
 
HaQs
Member Candidate
Member Candidate
Posts: 153
Joined: Sat Oct 20, 2007 3:26 pm
Location: POLAND

Re: Password bug with The Dude maps v6 (we can read XML)

Tue Jan 16, 2018 12:14 pm

MT know this :-) very long.
And nothind do with this.
 
nikola033
just joined
Topic Author
Posts: 14
Joined: Wed Jan 03, 2018 9:42 pm

Re: Password bug with The Dude maps v6 (we can read XML)

Wed Jun 06, 2018 6:20 pm

Hi,

Do you have new information for us?
update 6.43rc23 did not fix the problem.

Thanks a lot
Best regards
Nikola
 
jdtins
just joined
Posts: 5
Joined: Wed May 13, 2015 8:27 pm

Re: Password bug with The Dude maps v6 (we can read XML)

Tue Jun 19, 2018 7:16 pm

This would be a great thing to fix. We had a penetration tester use this as a way to gain access to our routers. It has caused management to consider ripping out Mikrotik in favor of something we can manage in a secure manner.

Any response would be appreciated!

Thanks,

Jonathan
 
nikc
Member Candidate
Member Candidate
Posts: 208
Joined: Wed Jul 13, 2016 6:05 pm

Re: Password bug with The Dude maps v6 (we can read XML)

Tue Jun 19, 2018 7:42 pm

This would be a great thing to fix. We had a penetration tester use this as a way to gain access to our routers. It has caused management to consider ripping out Mikrotik in favor of something we can manage in a secure manner.

Any response would be appreciated!

Thanks,

Jonathan
Surely changing the management tool would be a far less drastic approach ?

That said ... it needs fixing !
 
tibobo
newbie
Posts: 41
Joined: Tue Sep 27, 2016 8:54 am

Re: Password bug with The Dude maps v6 (we can read XML)

Wed Jul 04, 2018 4:27 pm

Guys, let's be reasonnable.

I can create my own tools and use [Device.Password] which is nice since I do not have to type it the whole day long.

Event if MT guys were to cypher the password in the DB and in the XML and wherever you can see it, what will prevent me from creating this tool :
cmd /c "echo [Device.Password] && pause"
Or any other tool where I show/store the password ?

So what's the point ?
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: Password bug with The Dude maps v6 (we can read XML)

Wed Jul 04, 2018 6:55 pm

what will prevent me from creating this tool :
cmd /c "echo [Device.Password] && pause"
Huh... Readonly rights? :)
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26367
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: Password bug with The Dude maps v6 (we can read XML)

Thu Jul 05, 2018 7:36 am

Not about the initial question, but ... why would you save passwords on a machine you don't trust? Encrypt your disk and use a strong login password for the user of this device.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2875
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Password bug with The Dude maps v6 (we can read XML)

Thu Jul 05, 2018 9:46 am

Normis ... you answer resembles me the quotation of Polish Nobel's prize receiver: "If you have fever do shutter a thermometer." :lol: :lol: :lol:
 
tibobo
newbie
Posts: 41
Joined: Tue Sep 27, 2016 8:54 am

Re: Password bug with The Dude maps v6 (we can read XML)

Thu Jul 12, 2018 2:34 pm

what will prevent me from creating this tool :
cmd /c "echo [Device.Password] && pause"
Huh... Readonly rights? :)
OK, agreed :)

Who is online

Users browsing this forum: stmx38 and 9 guests