Community discussions

MikroTik App
 
msatter
Forum Guru
Forum Guru
Topic Author
Posts: 2897
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Hide-sensitive shows serial number

Wed Nov 17, 2021 12:51 pm

I had just a look at export with hide-sensitive and noticed that the serial number is stated. This can be used to indentify a member here in the forum with other information if present outside this forum.

This because, many times in replies to questions, the poster is asked to post an export and this heavy search engine indexed this information is indexed within seconds. And this information is for eternity available to most of the people on this earth and those who are in space.

So don't make the mistake that this forum is seen as a select group. You are standing in the bright lights and every letter you type and any information given, is being recorded and made available world-wide and even outside the earth.

Users browsing this forum: ...., Baidu [Spider], ..., Bing [Bot], ..., msatter, Semrush [Bot] and 31 guests
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 11982
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: Hide-sensitive shows serial number

Wed Nov 17, 2021 1:01 pm

RIGHT.

lowercase_serial_number + .sn.mynetname.net and you are inside not-well-protected, or updated, router with cloud active...

Also login information on exported scheduler or script section (for example dyndns, no-ip, api keys, ftp passwords, etc.)...

also some tunnels ipsec password are exported (i do not remember exactly)

Is so easy "scan" *.sn.mynetname.net for find those devices...
Just search "# serial number =" on GoogIe... :lol:
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1347
Joined: Mon Sep 23, 2019 1:04 pm

Re: Hide-sensitive shows serial number

Wed Nov 17, 2021 1:18 pm

Serial numbers exposed in exports is the lesser thing someone needs to worry about.
I don't know if there are forum scrapers that look for serial numbers, but even if you don't expose your serial number, if your device is left unprotected and vulnerable it's just a matter of time until someone gets into it. Like all unprotected devices out there.
Sheesh.
Where will this stop?
 
msatter
Forum Guru
Forum Guru
Topic Author
Posts: 2897
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: Hide-sensitive shows serial number

Wed Nov 17, 2021 2:28 pm

Nice of Mikrotik to also provide, if used, the public IP of a router posting here in the forum their serial number.

Time to have someone with Mikrotik, to looks at these kind of leaking, vulnerabilities (like last, taking router hostage) from a neutral perspective and advise unasked on this.

Now we discover these things to late, while many devives are now high-jacked or taken over and/or never to be patched again.
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3292
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: Hide-sensitive shows serial number

Wed Nov 17, 2021 3:28 pm

I did search for my serial using goolge and found it once here on this forum.
Removed it.
 
ConnyMercier
Forum Veteran
Forum Veteran
Posts: 724
Joined: Tue Dec 17, 2019 1:08 pm

Re: Hide-sensitive shows serial number

Wed Nov 17, 2021 3:32 pm

+1
I agree Serial-Number shouldn't be part of the /export hide-sensitive

Who is online

Users browsing this forum: saajid, yosmithy and 52 guests