What to do in case of a vulnerable MikroTik router

DroneBL has historically seen, and continues to see, excessive numbers of exploited/vulnerable MikroTik router devices. The vast majority of these are due to since-fixed software vulnerabilities in MikroTik's firmware, as well as common misconfigurations (e.g. exposing the configuration ports to the internet). Attackers can activate various proxy options on these devices to obscure their true IP address (using your MikroTik device's IP address) to attack and spam websites and other services on the Internet. If you've been directed to this page regarding a DroneBL listing, this is probably what has happened to you.

Here's what to do if your router is vulnerable:

  1. Upgrade your router to the latest security patches provided by MikroTik. Instructions are provided on MikroTik's website here:
  2. Ensure that you recognize all user accounts present on the router, and that all users have secure passwords. Here's MikroTik's documentation for managing user accounts:
  3. Ensure that you recognize all of the configuration options applied to your router, especially the proxy-related options:
    1. HTTP proxy:
    2. SOCKS proxy:
    3. PPTP server:
    4. L2TP server:
    5. SSTP server:
  4. If possible, ensure that all MikroTik IP services only accept connections from the local network, using the address= syntax:
  5. Protect access to the MikroTik router with firewall rules:

If you've been directed here due to a DroneBL listing, please reply to your ticket email once you've followed these instructions to secure your MikroTik device, and we'll check whether the problem still exists.

