Quantcast
Channel: MikroTik
Viewing all articles
Browse latest Browse all 15394

The Dude • Security bug Report

$
0
0
Hello All.

Since Mikrotik removed Winbox from Dude packages , and add the command in tools menu and copy file into dude folder. by mistake the Winbox.exe name was Winbox64.exe and I found big surprise.

YOU CAN SHOW ADMIN OR ANY USER PASSWORD STORED IN DUDE.

just add any wrong command using tools with ip + user + password.
Code:
111.exe [Device.FirstAddress] [Device.UserName] "[Device.Password]"

then see below attached.
:?
Screenshot 2024-02-24 at 18.33.32.png

please Mikrotik there is some request.
use encryption for tools or any other password API request.
add winbox on dude setup folder and update it automatically from host machine.

Statistics: Posted by ahmedramze — Sat Feb 24, 2024 5:42 pm



Viewing all articles
Browse latest Browse all 15394

Trending Articles