6 ms·
Just calling out the good guys at Microtik. They patched their router a year before being notified by Cisco.
by el-y0y0s 8y ago
Just calling out the good guys at Microtik. They patched their router a year before being notified by Cisco.
- tarellel 8y agoAs a Mikrotik devote, I love the active development and patches being pushed for their Packages and RouterBoard. If anyone maintains a Mikrotik router and/or switches and hasn't heard about the vulnerability and actively patched their systems, then they're completely at fault and putting themselves and possibly they're companies at risk.
- dboreham 8y agoIt's also extremely easy to update RouterOS these days : a couple of clicks in winbox and reboot, for example.
- jlgaddis 8y agoJust make sure that you don't end up downloading a few DLLs you weren't expecting. https://securelist.com/apt-slingshot/84312/ https://securelist.com/apt-slingshot/84312/
- jlgaddis 8y agoHonest question: how's their GPL compliance these days?
- severine 8y agoSome info here: https://forum.lede-project.org/t/mikrotik-gpl-source/6750/12 https://forum.lede-project.org/t/mikrotik-gpl-source/6750/12 Which led to this repo: https://github.com/robimarko/routeros-GPL https://github.com/robimarko/routeros-GPL
- dboreham 8y agoIs this posted somewhere? I read the CERT release, TFA, and the MT forums and can't see any reference to a known fixed version. Thanks.
- el-y0y0s 8y agoI can't say definitively, but I couldn't find a public posting on this by MicroTik at the time Cisco made their information public on Cisco's Talos bolg. So I contacted MT support through email and was told that they were notified of the vulnerability May 18, 2018 but had already patched it March of 2017. I looked at the changelog on MTs RouterOS and several vulnerabilities were patched back at the time.
- ComodoHacker 8y agohttps://forum.mikrotik.com/viewtopic.php?t=134776 https://forum.mikrotik.com/viewtopic.php?t=134776