microtik xploit

2
During an audit the Mikrotik RouterOS sshd (ROSSSH) has been identified to have a remote previous to authentication heap corruption in its sshd component. Exploitation of this vulnerability will allow full access to the router device. This analysis describes the bug and includes a way to get developer access to re cent versions of Mikrotik RouterOS using the /etc/devel-login file. This is done by forging a modified NPK file usi ng a correct signature and logging into the device with username â develâ and the password of the administrator. This will d rop into a busybox shell for further researching the sshd vulnerability using gdb and strace tools that have been compiled for the Mikrotik busybox platform. Shodanhq.com shows >290.000 entries for the ROSSSH search term. The 50 megs Mikrotik package including the all research items can be downloaded here: http://www.farlight.org/mikropackage.zip https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sp loits/28056.zip

Upload: antonio-otero

Post on 10-Mar-2016

25 views

Category:

Documents


3 download

DESCRIPTION

xploit microtik os

TRANSCRIPT

Page 1: Microtik xploit

 

During an audit the Mikrotik RouterOS sshd (ROSSSH) has been identified to havea remote previous to authentication heap corruption in its sshd component.

Exploitation of this vulnerability will allow full access to the router device.

This analysis describes the bug and includes a way to get developer access to recent versions of Mikrotik RouterOSusing the /etc/devel-login file. This is done by forging a modified NPK file using a correct signature and logginginto the device with username âdevelâ and the password of the administrator. This will drop into a busybox shell forfurther researching the sshd vulnerability using gdb and strace tools that havebeen compiled for the Mikrotik busyboxplatform.

Shodanhq.com shows >290.000 entries for the ROSSSH search term.

The 50 megs Mikrotik package including the all research items can be downloadedhere:

http://www.farlight.org/mikropackage.ziphttps://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/28056.zip

Page 2: Microtik xploit