Abusing container mount points on MikroTik's RouterOS to gain code execution
nns.ee
nns.ee
1. This was introduced in a beta. It was then removed from subsequent betas until a fix could be found.
2. Running docker on a router could be really helpful in some cases, especially for small ISPs such as mine. For example: being able to run a recursive DNS resolver at the broadcast tower (ie nearer the customer) without having to run an entire server would be great. Or running a Prometheus exporter on the router for metric collection. Or for local processing/archiving of netflow data.
There are some really helpful use cases for this, but they are not the normal devops reasons for using docker.
The attack area on a router should shrink, not grow!
Do you just not review the configuration of your networking equipment?
It is a convenient way to maximize hardware in SOHO deployments.
This pursuit of saving money has given us weak boundaries that are relatively easy to cross, which will ultimately cost substantially more given any successful attack. The risk of an attack is an existential threat to the business itself. Do you really want to risk your entire business because you are trying to save a few hundred for a separate device?
There are places to try to save money and consolidate workloads, but edge routers are not it.
I posted on mikrotik forums, even contacted support, all to no avail. Not what I expected from mikrotik and a device marketed as a "home router".
After installing openwrt, everything just worked as expected.
I like the idea of Mikrotik and understand that they are pretty powerful for the price, but as you said, they require a certain level of experience and knowledge to wrangle them to the users liking.
Eg: https://www.servethehome.com/dell-s5232f-on-hands-on-a-vastl...
Seriously considering replacing this with Mikrotik showing up so often
Edit: Any recommendations for 10GbE switches with ~8 ports would be appreciated, likely encouraging me to follow through