0% found this document useful (0 votes)
9 views6 pages

MikroTik Router Security Assessment

The document discusses a study on testing vulnerabilities in MikroTik routers using penetration testing methods to enhance network security against threats like DDoS attacks. It outlines various attack techniques, including Brute Force and DDoS, and emphasizes the importance of securing network devices to prevent unauthorized access. The research aims to provide recommendations for improving the security of MikroTik routers based on the findings from the penetration tests conducted on the Khairun University network.

Uploaded by

vetal04.vr
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views6 pages

MikroTik Router Security Assessment

The document discusses a study on testing vulnerabilities in MikroTik routers using penetration testing methods to enhance network security against threats like DDoS attacks. It outlines various attack techniques, including Brute Force and DDoS, and emphasizes the importance of securing network devices to prevent unauthorized access. The research aims to provide recommendations for improving the security of MikroTik routers based on the findings from the penetration tests conducted on the Khairun University network.

Uploaded by

vetal04.vr
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

See discussions, stats, and author profiles for this publication at: [Link]

net/publication/357988302

MikroTik Router Vulnerability Testing for Network Vulnerability Evaluation


using Penetration Testing Method

Article in International Journal of Computer Applications · January 2022


DOI: 10.5120/ijca2022921878

CITATIONS READS

3 849

2 authors, including:

Yasir Muin
Khairun University
5 PUBLICATIONS 5 CITATIONS

SEE PROFILE

All content following this page was uploaded by Yasir Muin on 31 December 2022.

The user has requested enhancement of the downloaded file.


International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022

MikroTik Router Vulnerability Testing for Network


Vulnerability Evaluation using Penetration Testing
Method

Rosihan Yasir Muin


Khairun University Khairun University
Ternate Maluku Utara Ternate Maluku Utara
Indonesia Indonesia

ABSTRACT communication resource results, but to produce these


the improvement of information and communication resources requires network device security which needs to be
technology is very rapid with the progress of computer done by a sysadmin (system administrator) as a network
networks using network devices such as the MikroTik improvement so that avoid the threat of attacks both internally
[Link] security is needed to prevent threats or and externally.
attacks such as DDoS (Distributed Denial of Services). To
improve network security on the MikroTik Router, a study Threats or attacks often occur in the world of computer
was conducted that conducted vulnerability testing with networks, especially on the internet network. The number of
several penetration testing methods including Exploit, Brute attacks on internet networks has increased significantly in
Force, and DDoS. Penetration Testing is an activity where recent years. Many and varied targets and attack patterns. [2]
someone tries to simulate attacks that can be carried out on mentions that CVE (Common Vulnerability and Exposures) is
several organizational networks/agencies to find one of the vulnerabilities in software or hardware firmware,
vulnerabilities contained in the network system. The person one of which is on MikroTik devices. CVE is a catalog that
who performs this activity is known as penetration testing. provides a reference method regarding any publicly known
DDoS is a type of attack that floods internet traffic on a server information security vulnerabilities and exposures[3].CVE
or network. This DDoS attack usually occurs on MikroTik vulnerability data comes from the National Vulnerability
router servers which has a fairly large impact. The purpose of Database (NVD) XML source provided by the National
this research is to gain access to the MikroTik Router and to Institute of Standards and Technology (NIST). In addition to
test the performance of the MikroTik CPU Load from DDoS the NVD-CVE data, additional data was released from various
attacks while providing recommendations for improvements sources such as exploits [4], vendor inquiries, and additional
to the vulnerabilities found in these objects. This research is data provided by vendors through the Metasploit model.
expected to produce network security on MikroTik Router
devices that can prevent threats and attacks. The site [Link] is a website that records CVE
(Common Vulnerability and Exposures) vulnerability data. In
Keywords 2021, the cvedetails site noted the vulnerabilities that existed
Vulnerability Mikrotik, Penetration Testing, DDoS Attack, in MikroTik Router devices, allowing anyone to carry out
Exploit Mikrotik attackers through networks with various types of attackers
such as DDoS (Danial Distributed of Services), CSRF,
1. INTRODUCTION Execute Code, Overflow, Memory Corruption, and various
The computer network is one of the decision supportin the types. other attackers. From the cvedetails site, the most
development of the world of communication and information common type of attacker in 2021 is a DoS attack. This is
technology, where computer networks can connect. because DoS attacks are very common attacks, therefore
Togetherwith current technological developments, many many researchers simulate using this type of DoD attack, then
agencies or organizations are implementing computer prevent or mitigate DoS attacks on hardware sites and servers.
networks to support technological advances in providing
information and communication resources which have DDoS Attack is attacks against network sites, routers, and
become an unimportant need for food and clothing for servers that very often occur, including on MikroTik routers.
network technology users. By increasing the needs of network DDoS attacks aim to make the network down so that it is
users, various developments have emerged in the network by unable to serve requests from users who have valid access
utilizing network devices such as Mik Router devices. rights[5]. Bruteforce attacks are one of the practical attacks
used to break cryptographic security techniques [6].
MikroTik router is an operating system that can be used as a Bruteforce is a type of attack that attempts to access the
reliable network router and contains various wireless and network illegally by guessing the username and password by
network functions. In addition, MikroTik can also act as a trying the password combinations in the password list.
firewall for other computers, prioritizing other computers to The impact of DDoS attacks and Bruteforce attacks poses a
access internet data and local data. MikroTik aims to manage pretty big risk for companies or agencies, because they can
bandwidth and administer MikroTik Router devices [1]. find credential information in the form of administrator
usernames and passwords both on the server and on the
The utilization of the MikroTik Router device which has Mikrotik router, and also the impact of the DDoS attack
become one of the supporters of development in this network which causes the performance of the Mikrotik router to be
is expected to provide effective and efficient information and

33
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022

slow. even down because this attack flooded internet traffic a public Ip searcher from Mikrotik. The results of the
which overloaded MikroTik's CPU load and caused the research carried out are concluding and providing solutions on
internet network to be not optimal. how to overcome and prevent re-attacks on the security
problem of proxy router access from exploit attacks, in this
The Unkhair Informatics Engineering Network is a network case it can be a consideration for IT security agencies or
used for academic purposes, data such as lecturer usernames companies to secure the proxy router from exploit attacks.
and passwords become an awareness for network
administrators on how to secure the data on Mikrotik routers
from hacker attacks. However, the phenomenon of the current 3. METHODOLOGY
object is based on the information obtained that the network This research is applied research by conducting penetration
has not yet been tested to determine the vulnerability of the testing directly on the object to be studied, namely on the
device so that. Informatics Engineering campus of Khairun University in
This research will be tested to find vulnerabilities on order to solve the problems faced today. This research has
MikroTik devices with several pentest methods, namely several stages including:
Bruteforce, and DDoS Attack. The purpose of this research is
to gain access to MikroTik and also to test the CPU Load
performance of MikroTik from DDoS attacks as well as to
provide recommendations for repairs to the found loopholes.

2. RELATED LITERATURE
[7] discusses efforts to improve network security on Mikrotik
routers from penetration testing attacks. In his research,
preventive measures were carried out in securing the Mikrotik
network using the port knocking method, where the function
of this Port Knocking is to maintain Router device access
rights from users who are not authorized to access it. The Port
Knocking method is one of the network security methods that
is applied to the Mikrotik Router OS by working, that is, it
can open or close certain port access through the firewall on
the router according to the role built. The Port Knocking role
built on the firewall in this study utilizes four ports, namely
Port 8291 (Winbox), Port 23 (telnet), and Port 80 (Webfig).
And the access time of each port is 10 seconds.

[8] In his research, he explains about the analysis of the


Mikrotik router security system that has been applied to the
[Link] Warnet. The process of analyzing the security of the Fig 2: Research Flow
Mikrotik Router network is carried out using a case study-
based penetration testing method, namely testing using
simulations. his research shows that the network security
3.1 Information Gathering
owned by the [Link] internet cafe network still has many This stage is the information search stage to get more
loopholes to be exploited so that it shows serious things in information about the target of the attack on the Khairun
terms of exploitation such as getting the proxy router University Informatics Engineering network. This information
username and password. collection can be done by conducting interviews with network
administrators about network security and what important
[9]. discusses the analysis and implementation of the Mikrotik data is on the network. In addition, information collection is
router security system from winbox exploit attacks, brute also carried out with several additional applications such as
force, Dos On the network, the device that has the Nmap.
vulnerability is the computer. Router is the outermost device
that connects Local Area Network (LAN) to the internet so 3.2 Scanning Port
that it can be easily attacked by irresponsible parties. There This stage is the stage for performing vulnerability scanning
are lots of tools that can be used to carry out attacks on on MikroTik using the Nmap application. Nmap is an open-
Mikrotik routers such as Hping3 (DoS), Hydra (Brute-Force), source tool for exploring network security audits, the way
and Exploitation Script (Winbox Exploitation). To find out theseapplications works is by scanning to find information
the security loop on the Mikrotik router. his research uses such as type of information system, OS type, version, port,
penetration testing methods and attack techniques such as and other services [11]. This process aims to look for
Winbox Exploit, Brute-force, and DoS. After knowing the vulnerabilities on the target network through a scanning
security loophole. process in order to provide information in the form of active
ports that can be utilized.
[10] This study aims to analyze the security system for access
to the proxy router and to do mitigation or prevention and
security solutions from Exploit attacks. The method used in 3.3 Attack
this research is using experimental methods, literature study This stage is an important stage in research, where testing will
and simulation. In conducting trials, this study uses the be carried out on the information technology network using
Exploit Winbox critical vulnerability technique several penetration testing methods such as Bruteforce and
againstMikrotik devices which are known to still have DDoS Attack methods. Testing with the brute force attack
security holes by utilizing the Scada Shodan search engine as method aims to find the admin username and password from

34
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022

Mikrotik, while the DDoS attack test aims to test MikroTik or open status. This process can be seen in Figure 3.2 as
CPU Load performance against these attacks. follows.

3.4 Gain Access


This stage is the penetration testing stage with several
methods that successfully access the system or obtain
credential data in the form of a Mikrotik username and
password. The password can be used to access the Mikrotik
system as an administrator so that you can view the data
stored on the server such as lecturer and student account data.

3.5 Analysis
This stage is to analyze the results of penetration testing, the
analysis process is based on the type of attack that has an
impact on MikroTik, and provides recommendations to the
informatics study program so that it pays attention to the
existing network security system on the campus.
Fig 4: Scenning Port with nmap
4. RESULT In Figure 4 can be seen the process of port scanning results on
This section describes the results and discussion of the target network. The scanning results provide an output in
penetration testing using the brute force method and DDoS the form of information about the active port services on the
attacks. The object of the test is carried out on the Unkhair Mikrotik device, including port 21 FTP, port 53 Domain, port
Informatics Engineering network with the following network 80 HTTP, and port 443 is HTTPS. the information obtained
topology. can be used to carry out attacks through one of the active
service ports by trying attack methods such as DDoS Attack
and Brute Force to gain access to MikroTik.

4.3 Attack
At this stage, an attack will be carried out on the target
MikroTik device using two attack methods such as Brute
Force and DDoS Attack.

4.3.1 Brute Force


The attack with the brute force method is a technique used to
find the MikroTik admin password by trying all the password
combinations in the password list in the routersploit module.
The attack process starts by running the RouteSsploit
application using the Python command [Link].

Fig 3: Network Topology Khairun University


Figure 3.1 is the topology of the unkhair informatics
engineering network which will be tested for penetration
testing based on the following stages:

4.1 Information Gathering


This stage is the information search stage to get more
information regarding the target of the attack on the Khairun
University Informatics Engineering network. This information
collection can be done by conducting interviews with network
administrators about network security and what important
data is on the network. In addition, information collection is
also carried out with several additional applications such as
Nmap.

4.2 Scanning Tools Fig 5: Main Page RouterSploit


This stage is the stage of the scanning process which is carried In figure 3.3. is the main view of the RouterSploit application.
out after getting information from the previous stage. The To run this application, you can determine the module or
information obtained is in the form of the IP address of the package according to the type of attack used. in this case, the
target, which is [Link]. The IP is then used for scanning attack used is a brute force attack, to see the available
which aims to find information about ports that have an active modules on RouterSploit for FTP you can use the search
MikroTik command as shown in Figure 3.4 below.

35
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022

Fig 6 Module RouterSploit


Figure 6 shows the available modules on RouterSploit. This
module can be used to carry out attacks on several attacks on
certain ports. in this case, the attack was carried out on the
target proxy device, namely on FTP port 21 with the
creds/routers/MikroTik/ftp_default_creds module. after the
command is successfully activated, the next step is to
configure several dependencies, namely entering the IP
address of the target MikroTik on the brute force module as
shown in figure 7.
Fig 8: Main Page MikrotikSploit
Figure 3.8 is an initial view of RouterSploit which shows
several options that can be used for several types of attacks, in
this case, the type of attack used is a DDoS Attack. how to use
it, you can choose number three, namely DDoS Network, then
you will be asked to enter the Target URL URL link, namely
[Link], then you can execute the command by
pressing the enter button and the DDoS Attack is executed as
shown in Figure 9 below.

Fig 7 Settings IP address target in RouterSploit


In Figure 7 the configuration display for the brute force
module is set as a dependency. If seen in Figure 3.5 contains
important information that needs to be known such as target,
port, and password list. In the target section that must be
entered, the IP address of the target MikroTik is [Link].
After successfully added, the next step is to do brute force by
running the exploit command. RouterSploit will run
Bruteforce to Mikrotik and guess the MikroTik password as
shown in Figure 8 below.

Fig 9 impact of DDoS attacks


Figure 9 shows the process of the DDOS attack that was
carried out on MikroTik via port 80 with the target URL
[Link]. from these attacks the impact given to the
MikroTik CPU Load has increased to 50%.

4.4 Analysis
The results of the analysis were carried out to determine the
vulnerability of the Unkhair information technology network
security system. Based on the data from the test results, it is
known that some of the active ports on the MikroTik device
were found to be vulnerable so that during the test, credential
information such as the MikroTik username and password
Fig 8: Run Brute Force Attack were found using the brute force method. In addition, the
In Figure 8 it can be seen that the brute force process when DDoS Attack test also has a fairly large impact on MikroTik
executed tries to guess the password of the target MikroTik CPU Load because the attack floods network traffic which
device. In the brute force process successfully makes MikroTik performance increase and network
guessedMikroTik admin password is 101010###User28. performance becomes slow. From the results of the analysis, it
was concluded that the security of the Unkhair Informatics
4.3.2 DDoS Attack Engineering network needs to be an important concern for
DDoS Attack is a type of attack that is carried out by flooding network administrators, considering that there is a lot of
the traffic on the target network, making traffic-congested, important data stored in MikroTik, both lecturer, and student
resulting in slow internet speed, and can also overload the data, it is necessary to improve the network security system
MikroTik CPU Load. by installing a firewall and also deactivating the port if it is
not used for other needs because this can be a gap that can be

36
International Journal of Computer Applications (0975 – 8887)
Volume 183 – No. 47, January 2022

used by attackers to infiltrate through these ports as this [3] “Apa Itu CVE? – TEGALSEC | BLOG.”
research has done. [Link] (accessed Nov. 19,
2021).
5. CONCLUSION
Based on the results and discussion, it can be concluded that [4] “MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12
penetration testing on the Khairun informatics engineering (long-term) - Firewall and NAT Bypass - Hardware
network still has a vulnerability found on port 21, namely remote Exploit.” [Link]
FTP. This port is usually intended to transfer files from a [Link]/exploits/46444 (accessed Nov. 19, 2021).
computer to a server via the internet. However, this
[5] B. Jaya, Y. Yuhandri, and S. Sumijan, “Peningkatan
vulnerability can be used to perform penetration testing via
Keamanan Router Mikrotik Terhadap Serangan Denial of
the FTP port using the brute force attack method. Testing with
Service (DoS),” J. Sistim Inf. dan Teknol., vol. 2, pp.
this brute force attack is carried out to find usernames and
115–123, 2020, doi: 10.37034/jsisfotekv2i4.32.
passwords by trying lift combinations on the Metasploit
password list. From the test results, they managed to find [6] Amarudin, A., & Ulum, F. (2018). Desain Keamanan
credential information in the form of a MikroTik username Jaringan Pada Mikrotik Router OS Menggunakan
and password so that researchers could log in to MikroTik to Metode Port Knocking. Jurnal Teknoinfo, 12(2), 72-75.
view lecturer and student accounts.
[7] Hidayat, A., & Saputra, I. P. (2018). Analisa Dan
Pada pengujian DDoS attack dilakukan dengan tujuan untuk Problem Solving Keamanan Router Mikrotik Rb750Ra
menguji dampak serangan DDoS terhadap performa MikroTik. Dan Rb750Gr3 Dengan Metode Penetration Testing
Hasil pengujian tersebut ternyata memberikan dampak yang (Studi Kasus: Warnet Aulia. Net, Tanjung Harapan
cukup signifikan, dilihat dari performa CPU Load MikroTik Lampung Timur). Jurnal RESISTOR (Rekayasa Sistem
yang meningkat mencapai 50% dari dampak serangan DDoS Komputer), 1(2), 118-124.
Attack, karena DDoS Attack akan membanjiri traffic data yang
membuat performa MikroTik menjadi menurun bahkan sampai [8] Haeruddin, H. (2021). Analisa dan Implementasi Sistem
down. Dari beberapa pengujian yang dilakukan, telah diketahui Keamanan Router Mikrotik dari Serangan Winbox
beberapa vulnarebility pada jaringan Informatika unkhair, hal ini Exploitation, Brute-Force, DoS. JURNAL MEDIA
menjadi perhatian bagi administrator jaringan untuk lebih aware INFORMATIKA BUDIDARMA, 5(3), 848-855.
terhadap sistem keamanan, untuk itu peneliti merekomendasikan [9] Haeruddin, H. (2021). Analisa dan Implementasi Sistem
sistem keamanan dengan mengimplmentasi firewall pada Keamanan Router Mikrotik dari Serangan Winbox
MikroTik dan juga menutup beberapa port yang tidak digunakan
Exploitation, Brute-Force, DoS. JURNAL MEDIA
karena bisa dimanfaatakan attacker untuk masuk kedalam sitem
MikroTik melalui port tersebut. INFORMATIKA BUDIDARMA, 5(3), 848-855.
[10] Sandromedo Christa Nugroho, “No Title,” Brute Force
6. REFERENCES Attack pada Algoritm. SHA-256, vol. Vol 2 No 2, no. Vol
[1] I. Riadi, “Optimalisasi Keamanan Jaringan 2 No 2 (2019): Talenta Conference Series: Science and
Menggunakan Pemfilteran Aplikasi Berbasis Mikrotik Technology (ST), [Link]
Pendahuluan Landasan Teori,” JUSI, Univ. Ahmad
Dahlan Yogyakarta, vol. 1, no. 1, pp. 71–80, 2011. [11] “Panduan Refensi Nmap (Man Page, bahasa Indonesia)
|.” [Link] description
[2] Haeruddin, “Analisa dan Implementasi Sistem (accessed Nov. 19, 2021).
Keamanan Router Mikrotik dari,” J. Media Inform.
Budidarma, vol. 5, no. 3, pp. 848–855, 2021, doi:
10.30865/mibv5i3.2979.

IJCATM : [Link] 37

View publication stats

Common questions

Powered by AI

DDoS attacks overload the MikroTik CPU load, causing extensive internet traffic that results in slower processing speeds and may lead to network downtime, impacting the router’s ability to serve legitimate user requests. Brute force attacks attempt to illegally access the network by systematically guessing passwords, potentially leading to unauthorized access if successful. Both attack types can severely impact performance and security, posing significant risks to organizations relying on these routers for network connectivity .

Tools like Nmap and RouterSploit significantly facilitate penetration testing procedures by providing functionalities that simplify the identification of vulnerabilities. Nmap is used to scan and identify open ports and services running on the MikroTik router, key information necessary for exploiting potential weaknesses. RouterSploit offers modules for various types of attacks, such as brute force attacks, which can be deployed based on the information gathered. Together, these tools streamline the testing process by automating the discovery and exploitation phases, thus making it more efficient to uncover and address security gaps .

Network topology significantly impacts penetration testing as it dictates the pathways and nodes that can be exploited during attacks. For educational institutions like those using MikroTik routers, understanding the topology helps testers recognize potential vulnerability points and routes that attackers might use. The implications include the need for comprehensive mapping to identify all reachable areas and endpoints on the network, allowing for targeted and efficient testing. Additionally, ensuring that penetration tests do not disrupt educational activities while maintaining realistic testing conditions is vital .

Information gathering, through interviews and digital tools, is pivotal as it provides detailed insights into the network environment and potential vulnerabilities. Interviews with network administrators can reveal undocumented or overlooked weaknesses specific to the institutional environment. Digital tools, like Nmap, provide data on active services and open ports, which are critical when planning effective penetration strategies. This combined approach ensures comprehensive understanding and preparedness, increasing the accuracy and success of penetration tests .

Findings from penetration tests can guide network security policy modifications at institutions like Khairun University by illustrating current vulnerabilities and risks within their network infrastructure. These insights can lead to implementing enhanced security measures, such as closing vulnerable ports, setting up firewalls, and enhancing password policies to prevent unauthorized access. Additionally, the institutional awareness of threats can drive investment in ongoing security training for IT staff and the adoption of advanced monitoring tools to detect and mitigate attacks proactively .

The primary methods used for evaluating MikroTik router vulnerabilities include penetration testing techniques such as Exploit, Brute Force, and DDoS attacks. These methods simulate real-world attacks to identify vulnerabilities in the network system. Penetration testing contributes to network security by exposing weaknesses that can then be addressed to prevent unauthorized access and ensure the network’s resilience against potential threats .

Penetration testing results can inform future IT security training programs by identifying specific weaknesses and attack patterns prevalent in MikroTik routers, highlighting areas where administrators lack expertise or understanding. Training can then be tailored to address these gaps, focusing on topics like advanced threat detection, response strategies, and the application of best practices in configuring and securing routers. This knowledge transfer ensures that administrators are better prepared to anticipate and mitigate potential risks, enhancing overall network security and resilience .

To enhance the security of MikroTik routers, administrators should implement a multi-layered security approach including: 1) stricter access controls and robust password policies to prevent brute force attacks; 2) regular updates of firmware to patch known vulnerabilities documented in CVE listings; 3) deployment of firewalls to filter and limit potentially harmful traffic; 4) disabling unused services and ports to minimize exposure to attacks; and 5) continuous network monitoring to quickly detect and respond to unusual activities and potential breaches. These strategies collectively reduce risks associated with exploitation and enhance overall network security .

CVE plays a critical role in managing MikroTik router vulnerabilities by providing a standardized catalog of known software vulnerabilities, which allows IT administrators to quickly identify and address security flaws within their systems. The effectiveness of the CVE system lies in its ability to offer an organized and accessible repository of vulnerability data sourced from various credible entities, thus enabling systematic tracking and response to potential threats. This aids organizations in prioritizing their security efforts and ensuring compliance with industry standards .

Administrators face several challenges when using brute force and DDoS simulations for network security improvements. These include the risk of creating network disturbances while performing tests, which can impact normal operations. Properly calibrating tools to avoid unintentional damage or open security loopholes is another challenge. Additionally, there's a necessity for continuous monitoring and accurate interpretation of test results to ensure they reflect real-world conditions and adapt security protocols accordingly without affecting service availability or network performance .

You might also like