So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.
https://blog.mikrotik.com/security/new-exploit-for-mikrotik-... "Regardless of version used, all RouterOS versions that have the default firewall enabled, are not vulnerable" I don't believe all MK devices OOTB had the WAN interface firewall'd (they do now though their wAP's run same license level 4 of RouterOS and do not have fw enabled on the ethernet port) though I do recall that being made very clear in both the…
200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
51–60 of 76 posts
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#52Earlier quoted context omitted.
Try doing it through the web interface, you'll be unpleasantly surprised. I just upgraded my last hAP ac from 6.39.2 to 6.42.9 through the web interface, entered the bootloop, then did the Netinstall of the system package only, then manually restored the configuration.
This is why we do backups :) I always assume something will go wrong, but make sure to have a backup of any critical device that is being updated (mikrotik or not). Did your hAP run out of flash disk space? I notice that it only has 16MB.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#53I have several hAP ac Mikrotik routers and upgrading them is a pain. You can not just download an image from their website, flash and reboot. If you do so, your router will likely be locked in a bootloop. I managed to have consistent upgrades by using only the main package and Netinstall, but it is still a huge pain in the ass. Mikrotik makes stable routers, but they messed up the upgrade process completely.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#54So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#55Earlier quoted context omitted.
https://blog.mikrotik.com/security/new-exploit-for-mikrotik-... "Regardless of version used, all RouterOS versions that have the default firewall enabled, are not vulnerable" I don't believe all MK devices OOTB had the WAN interface firewall'd (they do now though their wAP's run same license level 4 of RouterOS and do not have fw enabled on the ethernet port) though I do recall that being made very clear in both the…
They've sent emails about this, posted to Twitter and Facebook, the software shows that there is an update available. If you've bought their device from a third party, and they don't have your contact information, how do you expect them to communicate with you?
Edit: I see...*notification via email is what I thought I had written in top post.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#56Earlier quoted context omitted.
Mikrotik is trustworthy enough. The update that fixed this was released in April, the first exploit appeared a few months later but this story gets regurgitated every couple of weeks because so many people use insecure configurations and don't bother upgrading their routers. As to their update availability - I'm fairly certain I could take something they manufactured 15 years ago and update it to the current version,…
I wonder how networking equipment manufacturers can motivate regular users to update their equipment more regularly? Auto update would seems like a logical one but plenty of people have reasons to not update and don't want there router going down at times they cannot control.
But as the first comment says - introducing breaking changes is not acceptable and they should appear only in major releases. And then those security bugfixes should be backported on all major versions which were released at least 5 years back. Yesterday I upgraded mikrotik from 6.14 to 6.42 and it took me 30minutes of additional configuration to make everything working again.
Also mikrotik collets a lot of network stats so implementing an algorithm which would restart the router when there's usually the least amount of traffic should be feasible - those updates take less than a minute so it's not like windows 10.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#57IMHO Mikrotik are being sloppy by introducing breaking changes to their stable channel. Hence ISPs are reluctant to update automatically, fearing some subtle bridge/VLAN change which is sadly set to happen again (6.43 -> 6.44!). Also doesn't help that the underlying Linux stable kernel updates more than once a week. Every Internet connected device needs some automatic update functionality by default. It's tricky for…
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#58I have several hAP ac Mikrotik routers and upgrading them is a pain. You can not just download an image from their website, flash and reboot. If you do so, your router will likely be locked in a bootloop. I managed to have consistent upgrades by using only the main package and Netinstall, but it is still a huge pain in the ass. Mikrotik makes stable routers, but they messed up the upgrade process completely.
The only method I have ever used is dropping the .npk packages into the root of the filesystem via sftp or ftp, and rebooting. No Netinstall required.
I've done this something like 50 times, on multiple models covering multiple architectures (Mips, PPC, x86, Arm), and never once had any issues.
Uploading them one-by-one via the web interface or Winbox (via the Files section) and rebooting also works just fine, but why bother when you can do them in one shot as above?
And if you have to upgrade a large number of routers, best of all is write your own script that pulls firmware from your own private repository on your management VLAN, and reboots. And seriously, anyone who is managing a large number of routers and is not bothering to test image upgrades in a testing environment before deploying to live deserves any trouble they get.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#59http://pcengines.ch/ APU2 plus debian. Be secure. Maybe I'll tidy up the ansible I use for this and publish it.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#60So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.
Germany (or rather DACH) has AVM, a German manufacturer that is making the "Fritz!Box" product line and supplied security updates to all affected routers they ever sold after somebody discovered and exploited a bug in the firmware to remotely call premium numbers via VoIP in various countries. Their routers were also not affected by the KRACK WPA2 exploit last year. AVM products cost a lot more than their competitors…