South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
The beauty of Mikrotiks... those RB2011s are not exactly new but they still get the latest updates.4x RB2011 no issues
Now if this was an apple device, it would be slowed down with firmware and no new updatesThe beauty of Mikrotiks... those RB2011s are not exactly new but they still get the latest updates.
No need to artificially do it, they do slow down all depending on what’s enabled and being used.Now if this was an apple device, it would be slowed down with firmware and no new updates
thehackernews.com
Related: https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/![]()
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers gain full administrative control of MikroTik routers through internet-exposed SSH without authentication, CERT Polska says.thehackernews.com
MikroTik reminding us they push insecure garbage... again...
My SSH protocol is disabled. I never use it to access my RB![]()
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers gain full administrative control of MikroTik routers through internet-exposed SSH without authentication, CERT Polska says.thehackernews.com
MikroTik reminding us they push insecure garbage... again...
MikroTik is a hot mess and underpins some of the largest botnets out there. It's a terrible product.Its a very cute name MikroTrick. Its obviously serious, but not sure how many people this would affect. At a guess well over 90% will never enable SSH, and the ones who do, would likely limit the access.
So its just users who enabled not perhaps knowing what they were doing, users who enabled and forgot to disable, or users who are happy SSH is secure enough in itself.
Terrible product is stretching it. It exposes a lot of configuration / functionality and if you don't know what you're doing it can be a security risk.MikroTik is a hot mess and underpins some of the largest botnets out there. It's a terrible product.
Agree to disagree. It's garbage. Always has been.Terrible product is stretching it.
The issue is it is enabled by default and ive seen so many peeps using the default config on the tikIts a very cute name MikroTrick. Its obviously serious, but not sure how many people this would affect. At a guess well over 90% will never enable SSH, and the ones who do, would likely limit the access.
So its just users who enabled not perhaps knowing what they were doing, users who enabled and forgot to disable, or users who are happy SSH is secure enough in itself.
That default config is what I believe keeps over 90% safe as it blocks SSH on the input chain. So let me rather say allow or implement SSH not enable.The issue is it is enabled by default and ive seen so many peeps using the default config on the tik
I remember this as well.The issue is it is enabled by default and ive seen so many peeps using the default config on the tik
| RouterOS era | Default firewall behaviour | SSH from WAN? |
|---|---|---|
| Very old RouterOS | Some default configurations had little/no IP firewall protection | Could be accessible |
| Pre-6.43 | Default configurations generally had a WAN-interface drop protecting the router | Normally NO |
| 6.43 onward | Default configuration moved toward interface lists (LAN/WAN) and eventually the !LAN input protection | NO |
| 6.47.x | drop all not coming from LAN was clearly part of the default configuration | NO |
| RouterOS 7.x current | Default firewall protects router input by allowing LAN and dropping non-LAN | NO |