See discussions, stats, and author profiles for this publication at: [Link]
net/publication/357988302
MikroTik Router Vulnerability Testing for Network Vulnerability Evaluation
using Penetration Testing Method
Article in International Journal of Computer Applications · January 2022
DOI: 10.5120/ijca2022921878
CITATIONS READS
3 849
2 authors, including:
Yasir Muin
Khairun University
5 PUBLICATIONS 5 CITATIONS
SEE PROFILE
All content following this page was uploaded by Yasir Muin on 31 December 2022.
The user has requested enhancement of the downloaded file.
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022
MikroTik Router Vulnerability Testing for Network
Vulnerability Evaluation using Penetration Testing
Method
Rosihan Yasir Muin
Khairun University Khairun University
Ternate Maluku Utara Ternate Maluku Utara
Indonesia Indonesia
ABSTRACT communication resource results, but to produce these
the improvement of information and communication resources requires network device security which needs to be
technology is very rapid with the progress of computer done by a sysadmin (system administrator) as a network
networks using network devices such as the MikroTik improvement so that avoid the threat of attacks both internally
[Link] security is needed to prevent threats or and externally.
attacks such as DDoS (Distributed Denial of Services). To
improve network security on the MikroTik Router, a study Threats or attacks often occur in the world of computer
was conducted that conducted vulnerability testing with networks, especially on the internet network. The number of
several penetration testing methods including Exploit, Brute attacks on internet networks has increased significantly in
Force, and DDoS. Penetration Testing is an activity where recent years. Many and varied targets and attack patterns. [2]
someone tries to simulate attacks that can be carried out on mentions that CVE (Common Vulnerability and Exposures) is
several organizational networks/agencies to find one of the vulnerabilities in software or hardware firmware,
vulnerabilities contained in the network system. The person one of which is on MikroTik devices. CVE is a catalog that
who performs this activity is known as penetration testing. provides a reference method regarding any publicly known
DDoS is a type of attack that floods internet traffic on a server information security vulnerabilities and exposures[3].CVE
or network. This DDoS attack usually occurs on MikroTik vulnerability data comes from the National Vulnerability
router servers which has a fairly large impact. The purpose of Database (NVD) XML source provided by the National
this research is to gain access to the MikroTik Router and to Institute of Standards and Technology (NIST). In addition to
test the performance of the MikroTik CPU Load from DDoS the NVD-CVE data, additional data was released from various
attacks while providing recommendations for improvements sources such as exploits [4], vendor inquiries, and additional
to the vulnerabilities found in these objects. This research is data provided by vendors through the Metasploit model.
expected to produce network security on MikroTik Router
devices that can prevent threats and attacks. The site [Link] is a website that records CVE
(Common Vulnerability and Exposures) vulnerability data. In
Keywords 2021, the cvedetails site noted the vulnerabilities that existed
Vulnerability Mikrotik, Penetration Testing, DDoS Attack, in MikroTik Router devices, allowing anyone to carry out
Exploit Mikrotik attackers through networks with various types of attackers
such as DDoS (Danial Distributed of Services), CSRF,
1. INTRODUCTION Execute Code, Overflow, Memory Corruption, and various
The computer network is one of the decision supportin the types. other attackers. From the cvedetails site, the most
development of the world of communication and information common type of attacker in 2021 is a DoS attack. This is
technology, where computer networks can connect. because DoS attacks are very common attacks, therefore
Togetherwith current technological developments, many many researchers simulate using this type of DoD attack, then
agencies or organizations are implementing computer prevent or mitigate DoS attacks on hardware sites and servers.
networks to support technological advances in providing
information and communication resources which have DDoS Attack is attacks against network sites, routers, and
become an unimportant need for food and clothing for servers that very often occur, including on MikroTik routers.
network technology users. By increasing the needs of network DDoS attacks aim to make the network down so that it is
users, various developments have emerged in the network by unable to serve requests from users who have valid access
utilizing network devices such as Mik Router devices. rights[5]. Bruteforce attacks are one of the practical attacks
used to break cryptographic security techniques [6].
MikroTik router is an operating system that can be used as a Bruteforce is a type of attack that attempts to access the
reliable network router and contains various wireless and network illegally by guessing the username and password by
network functions. In addition, MikroTik can also act as a trying the password combinations in the password list.
firewall for other computers, prioritizing other computers to The impact of DDoS attacks and Bruteforce attacks poses a
access internet data and local data. MikroTik aims to manage pretty big risk for companies or agencies, because they can
bandwidth and administer MikroTik Router devices [1]. find credential information in the form of administrator
usernames and passwords both on the server and on the
The utilization of the MikroTik Router device which has Mikrotik router, and also the impact of the DDoS attack
become one of the supporters of development in this network which causes the performance of the Mikrotik router to be
is expected to provide effective and efficient information and
33
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022
slow. even down because this attack flooded internet traffic a public Ip searcher from Mikrotik. The results of the
which overloaded MikroTik's CPU load and caused the research carried out are concluding and providing solutions on
internet network to be not optimal. how to overcome and prevent re-attacks on the security
problem of proxy router access from exploit attacks, in this
The Unkhair Informatics Engineering Network is a network case it can be a consideration for IT security agencies or
used for academic purposes, data such as lecturer usernames companies to secure the proxy router from exploit attacks.
and passwords become an awareness for network
administrators on how to secure the data on Mikrotik routers
from hacker attacks. However, the phenomenon of the current 3. METHODOLOGY
object is based on the information obtained that the network This research is applied research by conducting penetration
has not yet been tested to determine the vulnerability of the testing directly on the object to be studied, namely on the
device so that. Informatics Engineering campus of Khairun University in
This research will be tested to find vulnerabilities on order to solve the problems faced today. This research has
MikroTik devices with several pentest methods, namely several stages including:
Bruteforce, and DDoS Attack. The purpose of this research is
to gain access to MikroTik and also to test the CPU Load
performance of MikroTik from DDoS attacks as well as to
provide recommendations for repairs to the found loopholes.
2. RELATED LITERATURE
[7] discusses efforts to improve network security on Mikrotik
routers from penetration testing attacks. In his research,
preventive measures were carried out in securing the Mikrotik
network using the port knocking method, where the function
of this Port Knocking is to maintain Router device access
rights from users who are not authorized to access it. The Port
Knocking method is one of the network security methods that
is applied to the Mikrotik Router OS by working, that is, it
can open or close certain port access through the firewall on
the router according to the role built. The Port Knocking role
built on the firewall in this study utilizes four ports, namely
Port 8291 (Winbox), Port 23 (telnet), and Port 80 (Webfig).
And the access time of each port is 10 seconds.
[8] In his research, he explains about the analysis of the
Mikrotik router security system that has been applied to the
[Link] Warnet. The process of analyzing the security of the Fig 2: Research Flow
Mikrotik Router network is carried out using a case study-
based penetration testing method, namely testing using
simulations. his research shows that the network security
3.1 Information Gathering
owned by the [Link] internet cafe network still has many This stage is the information search stage to get more
loopholes to be exploited so that it shows serious things in information about the target of the attack on the Khairun
terms of exploitation such as getting the proxy router University Informatics Engineering network. This information
username and password. collection can be done by conducting interviews with network
administrators about network security and what important
[9]. discusses the analysis and implementation of the Mikrotik data is on the network. In addition, information collection is
router security system from winbox exploit attacks, brute also carried out with several additional applications such as
force, Dos On the network, the device that has the Nmap.
vulnerability is the computer. Router is the outermost device
that connects Local Area Network (LAN) to the internet so 3.2 Scanning Port
that it can be easily attacked by irresponsible parties. There This stage is the stage for performing vulnerability scanning
are lots of tools that can be used to carry out attacks on on MikroTik using the Nmap application. Nmap is an open-
Mikrotik routers such as Hping3 (DoS), Hydra (Brute-Force), source tool for exploring network security audits, the way
and Exploitation Script (Winbox Exploitation). To find out theseapplications works is by scanning to find information
the security loop on the Mikrotik router. his research uses such as type of information system, OS type, version, port,
penetration testing methods and attack techniques such as and other services [11]. This process aims to look for
Winbox Exploit, Brute-force, and DoS. After knowing the vulnerabilities on the target network through a scanning
security loophole. process in order to provide information in the form of active
ports that can be utilized.
[10] This study aims to analyze the security system for access
to the proxy router and to do mitigation or prevention and
security solutions from Exploit attacks. The method used in 3.3 Attack
this research is using experimental methods, literature study This stage is an important stage in research, where testing will
and simulation. In conducting trials, this study uses the be carried out on the information technology network using
Exploit Winbox critical vulnerability technique several penetration testing methods such as Bruteforce and
againstMikrotik devices which are known to still have DDoS Attack methods. Testing with the brute force attack
security holes by utilizing the Scada Shodan search engine as method aims to find the admin username and password from
34
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022
Mikrotik, while the DDoS attack test aims to test MikroTik or open status. This process can be seen in Figure 3.2 as
CPU Load performance against these attacks. follows.
3.4 Gain Access
This stage is the penetration testing stage with several
methods that successfully access the system or obtain
credential data in the form of a Mikrotik username and
password. The password can be used to access the Mikrotik
system as an administrator so that you can view the data
stored on the server such as lecturer and student account data.
3.5 Analysis
This stage is to analyze the results of penetration testing, the
analysis process is based on the type of attack that has an
impact on MikroTik, and provides recommendations to the
informatics study program so that it pays attention to the
existing network security system on the campus.
Fig 4: Scenning Port with nmap
4. RESULT In Figure 4 can be seen the process of port scanning results on
This section describes the results and discussion of the target network. The scanning results provide an output in
penetration testing using the brute force method and DDoS the form of information about the active port services on the
attacks. The object of the test is carried out on the Unkhair Mikrotik device, including port 21 FTP, port 53 Domain, port
Informatics Engineering network with the following network 80 HTTP, and port 443 is HTTPS. the information obtained
topology. can be used to carry out attacks through one of the active
service ports by trying attack methods such as DDoS Attack
and Brute Force to gain access to MikroTik.
4.3 Attack
At this stage, an attack will be carried out on the target
MikroTik device using two attack methods such as Brute
Force and DDoS Attack.
4.3.1 Brute Force
The attack with the brute force method is a technique used to
find the MikroTik admin password by trying all the password
combinations in the password list in the routersploit module.
The attack process starts by running the RouteSsploit
application using the Python command [Link].
Fig 3: Network Topology Khairun University
Figure 3.1 is the topology of the unkhair informatics
engineering network which will be tested for penetration
testing based on the following stages:
4.1 Information Gathering
This stage is the information search stage to get more
information regarding the target of the attack on the Khairun
University Informatics Engineering network. This information
collection can be done by conducting interviews with network
administrators about network security and what important
data is on the network. In addition, information collection is
also carried out with several additional applications such as
Nmap.
4.2 Scanning Tools Fig 5: Main Page RouterSploit
This stage is the stage of the scanning process which is carried In figure 3.3. is the main view of the RouterSploit application.
out after getting information from the previous stage. The To run this application, you can determine the module or
information obtained is in the form of the IP address of the package according to the type of attack used. in this case, the
target, which is [Link]. The IP is then used for scanning attack used is a brute force attack, to see the available
which aims to find information about ports that have an active modules on RouterSploit for FTP you can use the search
MikroTik command as shown in Figure 3.4 below.
35
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022
Fig 6 Module RouterSploit
Figure 6 shows the available modules on RouterSploit. This
module can be used to carry out attacks on several attacks on
certain ports. in this case, the attack was carried out on the
target proxy device, namely on FTP port 21 with the
creds/routers/MikroTik/ftp_default_creds module. after the
command is successfully activated, the next step is to
configure several dependencies, namely entering the IP
address of the target MikroTik on the brute force module as
shown in figure 7.
Fig 8: Main Page MikrotikSploit
Figure 3.8 is an initial view of RouterSploit which shows
several options that can be used for several types of attacks, in
this case, the type of attack used is a DDoS Attack. how to use
it, you can choose number three, namely DDoS Network, then
you will be asked to enter the Target URL URL link, namely
[Link], then you can execute the command by
pressing the enter button and the DDoS Attack is executed as
shown in Figure 9 below.
Fig 7 Settings IP address target in RouterSploit
In Figure 7 the configuration display for the brute force
module is set as a dependency. If seen in Figure 3.5 contains
important information that needs to be known such as target,
port, and password list. In the target section that must be
entered, the IP address of the target MikroTik is [Link].
After successfully added, the next step is to do brute force by
running the exploit command. RouterSploit will run
Bruteforce to Mikrotik and guess the MikroTik password as
shown in Figure 8 below.
Fig 9 impact of DDoS attacks
Figure 9 shows the process of the DDOS attack that was
carried out on MikroTik via port 80 with the target URL
[Link]. from these attacks the impact given to the
MikroTik CPU Load has increased to 50%.
4.4 Analysis
The results of the analysis were carried out to determine the
vulnerability of the Unkhair information technology network
security system. Based on the data from the test results, it is
known that some of the active ports on the MikroTik device
were found to be vulnerable so that during the test, credential
information such as the MikroTik username and password
Fig 8: Run Brute Force Attack were found using the brute force method. In addition, the
In Figure 8 it can be seen that the brute force process when DDoS Attack test also has a fairly large impact on MikroTik
executed tries to guess the password of the target MikroTik CPU Load because the attack floods network traffic which
device. In the brute force process successfully makes MikroTik performance increase and network
guessedMikroTik admin password is 101010###User28. performance becomes slow. From the results of the analysis, it
was concluded that the security of the Unkhair Informatics
4.3.2 DDoS Attack Engineering network needs to be an important concern for
DDoS Attack is a type of attack that is carried out by flooding network administrators, considering that there is a lot of
the traffic on the target network, making traffic-congested, important data stored in MikroTik, both lecturer, and student
resulting in slow internet speed, and can also overload the data, it is necessary to improve the network security system
MikroTik CPU Load. by installing a firewall and also deactivating the port if it is
not used for other needs because this can be a gap that can be
36
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022
used by attackers to infiltrate through these ports as this [3] “Apa Itu CVE? – TEGALSEC | BLOG.”
research has done. [Link] (accessed Nov. 19,
2021).
5. CONCLUSION
Based on the results and discussion, it can be concluded that [4] “MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12
penetration testing on the Khairun informatics engineering (long-term) - Firewall and NAT Bypass - Hardware
network still has a vulnerability found on port 21, namely remote Exploit.” [Link]
FTP. This port is usually intended to transfer files from a [Link]/exploits/46444 (accessed Nov. 19, 2021).
computer to a server via the internet. However, this
[5] B. Jaya, Y. Yuhandri, and S. Sumijan, “Peningkatan
vulnerability can be used to perform penetration testing via
Keamanan Router Mikrotik Terhadap Serangan Denial of
the FTP port using the brute force attack method. Testing with
Service (DoS),” J. Sistim Inf. dan Teknol., vol. 2, pp.
this brute force attack is carried out to find usernames and
115–123, 2020, doi: 10.37034/jsisfotekv2i4.32.
passwords by trying lift combinations on the Metasploit
password list. From the test results, they managed to find [6] Amarudin, A., & Ulum, F. (2018). Desain Keamanan
credential information in the form of a MikroTik username Jaringan Pada Mikrotik Router OS Menggunakan
and password so that researchers could log in to MikroTik to Metode Port Knocking. Jurnal Teknoinfo, 12(2), 72-75.
view lecturer and student accounts.
[7] Hidayat, A., & Saputra, I. P. (2018). Analisa Dan
Pada pengujian DDoS attack dilakukan dengan tujuan untuk Problem Solving Keamanan Router Mikrotik Rb750Ra
menguji dampak serangan DDoS terhadap performa MikroTik. Dan Rb750Gr3 Dengan Metode Penetration Testing
Hasil pengujian tersebut ternyata memberikan dampak yang (Studi Kasus: Warnet Aulia. Net, Tanjung Harapan
cukup signifikan, dilihat dari performa CPU Load MikroTik Lampung Timur). Jurnal RESISTOR (Rekayasa Sistem
yang meningkat mencapai 50% dari dampak serangan DDoS Komputer), 1(2), 118-124.
Attack, karena DDoS Attack akan membanjiri traffic data yang
membuat performa MikroTik menjadi menurun bahkan sampai [8] Haeruddin, H. (2021). Analisa dan Implementasi Sistem
down. Dari beberapa pengujian yang dilakukan, telah diketahui Keamanan Router Mikrotik dari Serangan Winbox
beberapa vulnarebility pada jaringan Informatika unkhair, hal ini Exploitation, Brute-Force, DoS. JURNAL MEDIA
menjadi perhatian bagi administrator jaringan untuk lebih aware INFORMATIKA BUDIDARMA, 5(3), 848-855.
terhadap sistem keamanan, untuk itu peneliti merekomendasikan [9] Haeruddin, H. (2021). Analisa dan Implementasi Sistem
sistem keamanan dengan mengimplmentasi firewall pada Keamanan Router Mikrotik dari Serangan Winbox
MikroTik dan juga menutup beberapa port yang tidak digunakan
Exploitation, Brute-Force, DoS. JURNAL MEDIA
karena bisa dimanfaatakan attacker untuk masuk kedalam sitem
MikroTik melalui port tersebut. INFORMATIKA BUDIDARMA, 5(3), 848-855.
[10] Sandromedo Christa Nugroho, “No Title,” Brute Force
6. REFERENCES Attack pada Algoritm. SHA-256, vol. Vol 2 No 2, no. Vol
[1] I. Riadi, “Optimalisasi Keamanan Jaringan 2 No 2 (2019): Talenta Conference Series: Science and
Menggunakan Pemfilteran Aplikasi Berbasis Mikrotik Technology (ST), [Link]
Pendahuluan Landasan Teori,” JUSI, Univ. Ahmad
Dahlan Yogyakarta, vol. 1, no. 1, pp. 71–80, 2011. [11] “Panduan Refensi Nmap (Man Page, bahasa Indonesia)
|.” [Link] description
[2] Haeruddin, “Analisa dan Implementasi Sistem (accessed Nov. 19, 2021).
Keamanan Router Mikrotik dari,” J. Media Inform.
Budidarma, vol. 5, no. 3, pp. 848–855, 2021, doi:
10.30865/mibv5i3.2979.
IJCATM : [Link] 37
View publication stats