PoC Attack Escalates MikroTik Router Bug to ‘As Bad as It Gets’
threatpost.com
threatpost.com
The printf family is responsible for so many problems. Few people seem to know how to use it safely, or when to use something else.
> only approximately 30 percent of vulnerable modems have been patched, which leaves approximately 200,000 routers...
Welcome to the botnet. Combining the two bugs gives root, and that's a large enough collection of devices to target.
I was taught printf should only be used for quick n dirty debugging.
Another entry point could be other devices in your network that have been taken over to some extend (or maybe even an app on your phone).
And further, there are Mikrotiks for nearly any use case, from <100M to 10G. These things have speed ratings for a reason. I run a quadcore ARM unit now, and it's blazing fast, way overpowered for what I use it for. Before that I ran a dual-core PowerPC unit, that easily did 1G (unless you were throwing IPSec at it), for around $100.
GET /ssl_conn.php?usrname=%s&passwd=%s&softid=%s&level=%d&pay_typ'e=%d&board=%d HTTP/1.0
Attackers will not be able to use that, nor will they care. There are already plenty of routers vulnerable to RCE on the Internet.