Community discussions

MikroTik App
 
User avatar
SoundGuyFYI
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 74
Joined: Wed Jun 05, 2013 12:43 am

Winbox Vulnerability Changes

Tue Aug 07, 2018 10:35 pm

I wanted to see if anyone had compiled the affects of the winbox vulnerability found in versions 6.29 - 6.42.

I am cleaning up some of the affects and am hoping that other have collected changes in there equipment so I can compare against what I am finding to see if I have found everything.

I have just noticed that it apears to have created interface lists that I'm guessing would be used to start collecting or forwarding information.

I have been collecting changes in my configuration that I have found to hopefully help others resolve any issues they are having, however I'm not sure it is best to post them all on the forums to prevent workarounds for what I have found.

Anyone have any records of what was changed when they were affected by this?
 
R1CH
Forum Guru
Forum Guru
Posts: 1108
Joined: Sun Oct 01, 2006 11:44 pm

Re: Winbox Vulnerability Changes

Wed Aug 08, 2018 1:18 am

The vulnerability allows someone full admin access to the router, so they could change anything and everything. Mikrotik seem to suggest that winbox can even be elevated to shell access, in which case undetectable backdoors could be installed. The safest way to restore a router is export the config, manually check it, netinstall then import the clean config.

Who is online

Users browsing this forum: Jivcheg, marquetry, patrikg, profinetasmb, vic3apex and 66 guests