Community discussions

MikroTik App

Search found 5 matches

by c0nstantine
Tue Apr 17, 2018 2:24 pm
Forum: General
Topic: MikroTik 6.41.4 - FTP daemon Denial of Service PoC
Replies: 25
Views: 4678

Re: MikroTik 6.41.4 - FTP daemon Denial of Service PoC

We did check it. Firewall stops it, like it was written above. I didn't talk about firewall, It's about FTP service and it's clear the firewalls can block any connection, as you know this service has a vulnerability on parsing function, you can fix that easily. I will not continue this conversation...
by c0nstantine
Tue Apr 17, 2018 1:04 pm
Forum: General
Topic: MikroTik 6.41.4 - FTP daemon Denial of Service PoC
Replies: 25
Views: 4678

Re: MikroTik 6.41.4 - FTP daemon Denial of Service PoC

The Email is sent at Fri, Apr 13, 2018 to support@mikrotik.com Unfortunately I think the security is not important for your company. That is only 1.5 work day ago! In a company, such mails need to be categorized, the issue investigated, and a reply be made and verified. You cannot expect that to ha...
by c0nstantine
Tue Apr 17, 2018 12:21 pm
Forum: General
Topic: MikroTik 6.41.4 - FTP daemon Denial of Service PoC
Replies: 25
Views: 4678

Re: MikroTik 6.41.4 - FTP daemon Denial of Service PoC

I sent the report to your company before I publish the vulnerability and you didn't answer. We answer all emails. Make sure you are not filtering ours, or post the ticket number, so I can check what was answered. The Email is sent at Fri, Apr 13, 2018 to support@mikrotik.com Unfortunately I think t...
by c0nstantine
Mon Apr 16, 2018 7:19 pm
Forum: General
Topic: MikroTik 6.41.4 - FTP daemon Denial of Service PoC
Replies: 25
Views: 4678

Re: MikroTik 6.41.4 - FTP daemon Denial of Service PoC

Guys. Any service can be overloaded when it is polled enough times. How is this a vulnerability? This is simple DoS. If you set a simple firewall rule to limit number of connections per IP, in your input chain, this will not work at all. Why would anyone keep FTP open to the public, no firewall and...
by c0nstantine
Thu Dec 14, 2017 7:20 am
Forum: General
Topic: [exploit-db.com] MikroTik 6.40.5 ICMP - Denial of Service
Replies: 16
Views: 6882

Re: [exploit-db.com] MikroTik 6.40.5 ICMP - Denial of Service

Description: This could allow attacker(in your lan) to exhaust all available CPU and crash the kernel via a flood of ICMP packets with forged source IP addresses associated with the public Internet without fast connection. If you launch the exploit with local IP addresses, the router can handle the ...