threat9 / routersploit

Exploitation Framework for Embedded Devices
Other
12.03k stars 2.31k forks source link

Mikrotik exploits #288

Open Wrench404 opened 6 years ago

Wrench404 commented 6 years ago

Please add exploits for mikrotik routers

0BuRner commented 6 years ago

Hi, can you share some links related to these exploits?

theleestarr commented 6 years ago

https://mkbrutusproject.github.io/MKBRUTUS/

0BuRner commented 6 years ago

@theleestarr the link you gave is about a brute-force which is not consedered as an exploit... Routersploit already contains some generic brute-force tools. So I don't think it's what @Wrench404 was talking about...

ghost commented 6 years ago

There is some exploits for MikroTik routers, check Exploit Db... image

Wrench404 commented 6 years ago

I am newbie, so I wanna you compile exploits for mikrotik routers.

sasatefa2009 commented 6 years ago

@0BuRner @Wrench404 @cipiricus this is a an extreme vulnerability http://seclists.org/fulldisclosure/2015/Mar/49 http://www.websecuritywatch.com/xsrf-vulnerability-in-mikrotik-routeros-before-v5-0/ video for it from the owner of it https://www.youtube.com/watch?v=FHrvHJeLjLA

also Wikileaks has some good vulnerabilities for routeros and other routers leaked from the CIA https://wikileaks.org/ciav7p1/cms/page_28049428.html https://wikileaks.org/ciav7p1/cms/page_16384512.html https://wikileaks.org/ciav7p1/cms/page_16384604.html

and this is the whole index of the whole vulnerabilities https://wikileaks.org/ciav7p1/index.html

BigNerd95 commented 6 years ago

https://github.com/BigNerd95/Chimay-Red

GH0st3rs commented 6 years ago

I added Chimay-Red module to routersploit... But i have some trouble with pwntools

sasatefa2009 commented 6 years ago

new exploits

https://www.exploit-db.com/exploits/44290/ https://www.exploit-db.com/exploits/44284/ https://www.exploit-db.com/exploits/44283/

halekan commented 6 years ago

I am Test all new exploit it is never not works works only with vmware for play only

BigNerd95 commented 6 years ago

@halekan it is not working because you are testing random architectures.

BigNerd95 commented 5 years ago

I added Chimay-Red module to routersploit... But i have some trouble with pwntools

I'm going to port chimayred to routersploit using a list of fixed addresses for the ropchain, do you still have your branch with chimayred? if we merge them we will do it faster