routersploit icon indicating copy to clipboard operation
routersploit copied to clipboard

Mikrotik exploits

Open Wrench404 opened this issue 7 years ago • 12 comments

Please add exploits for mikrotik routers

Wrench404 avatar Aug 08 '17 17:08 Wrench404

Hi, can you share some links related to these exploits?

0BuRner avatar Aug 09 '17 17:08 0BuRner

https://mkbrutusproject.github.io/MKBRUTUS/

theleestarr avatar Aug 11 '17 04:08 theleestarr

@theleestarr the link you gave is about a brute-force which is not consedered as an exploit... Routersploit already contains some generic brute-force tools. So I don't think it's what @Wrench404 was talking about...

0BuRner avatar Aug 11 '17 20:08 0BuRner

There is some exploits for MikroTik routers, check Exploit Db... image

ghost avatar Aug 13 '17 06:08 ghost

I am newbie, so I wanna you compile exploits for mikrotik routers.

Wrench404 avatar Aug 13 '17 18:08 Wrench404

@0BuRner @Wrench404 @cipiricus this is a an extreme vulnerability http://seclists.org/fulldisclosure/2015/Mar/49 http://www.websecuritywatch.com/xsrf-vulnerability-in-mikrotik-routeros-before-v5-0/ video for it from the owner of it https://www.youtube.com/watch?v=FHrvHJeLjLA

also Wikileaks has some good vulnerabilities for routeros and other routers leaked from the CIA https://wikileaks.org/ciav7p1/cms/page_28049428.html https://wikileaks.org/ciav7p1/cms/page_16384512.html https://wikileaks.org/ciav7p1/cms/page_16384604.html

and this is the whole index of the whole vulnerabilities https://wikileaks.org/ciav7p1/index.html

sasatefa2009 avatar Aug 30 '17 08:08 sasatefa2009

https://github.com/BigNerd95/Chimay-Red

BigNerd95 avatar Nov 11 '17 02:11 BigNerd95

I added Chimay-Red module to routersploit... But i have some trouble with pwntools

GH0st3rs avatar Mar 15 '18 16:03 GH0st3rs

new exploits

https://www.exploit-db.com/exploits/44290/ https://www.exploit-db.com/exploits/44284/ https://www.exploit-db.com/exploits/44283/

sasatefa2009 avatar Mar 17 '18 01:03 sasatefa2009

I am Test all new exploit it is never not works works only with vmware for play only

halekan avatar Mar 25 '18 09:03 halekan

@halekan it is not working because you are testing random architectures.

BigNerd95 avatar Mar 25 '18 09:03 BigNerd95

I added Chimay-Red module to routersploit... But i have some trouble with pwntools

I'm going to port chimayred to routersploit using a list of fixed addresses for the ropchain, do you still have your branch with chimayred? if we merge them we will do it faster

BigNerd95 avatar May 02 '19 18:05 BigNerd95