Главная
Study mode:
on
1
Intro
2
What is RouterOS?
3
RouterOS Release Trees
4
Previous Research
5
Developer Backdoor: Long Term Release
6
Creating a Backdoor (6.42+)
7
JSProxy Key Negotiation
8
Offline Brute Forcing
9
PCAP Decryption
10
JSON Protocol Description
11
System Number Mapping
12
Switch to Binary
13
Message Binary Format
14
WinBox Uses the Binary Message Protocol
15
Importance of the Message Protocol
16
CVE-2018-1156
17
Policy Discovery
18
CVE-2018-14847
19
By the way
Description:
Explore the intricacies of bug hunting in RouterOS with Jacob Baines in this 42-minute conference talk from Derbycon 2018. Delve into the world of RouterOS, examining its release trees and previous research. Uncover developer backdoors in long-term releases and learn techniques for creating backdoors in version 6.42 and beyond. Investigate JSProxy key negotiation, offline brute forcing, and PCAP decryption. Gain insights into the JSON protocol description, system number mapping, and the transition to binary message formats. Understand the significance of the message protocol in WinBox and its implications. Examine real-world vulnerabilities, including CVE-2018-1156 and CVE-2018-14847, while discovering the importance of policy discovery in RouterOS security.

Bug Hunting in RouterOS

Add to list