Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 57 guests and 3 members online
You are here:
Home
Resources
Tutorials
Bypassing Mikrotik hotspot login page
EH-Net
May 18, 2013, 05:43:53 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Tutorials
(Moderator:
don
) >
Bypassing Mikrotik hotspot login page
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Bypassing Mikrotik hotspot login page (Read 56772 times)
0 Members and 2 Guests are viewing this topic.
software
Newbie
Offline
Posts: 2
Bypassing Mikrotik hotspot login page
«
on:
April 06, 2008, 02:14:06 AM »
Hi guys, pls i will like to know how to bypass a mikrotik hotspot login page.. I understand a little about the technology.. the Radius server authentification and the redirection to the gateway bla bla bla.. my question is i need more clues to bypassing the login page..
I presently manage an ISP, and someone not registered is always on my network.. Using the network for free.. Pls guys i need yourt help. I really want to know how he byepass it then i can improvoe on my security also.
my email adress is
adepetu2000@yahoo.co.uk
I await your response and assistance.
thanks
Engr Emmanuell
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Bypassing Mikrotik hotspot login page
«
Reply #1 on:
April 06, 2008, 03:32:55 AM »
software,
Welcome to EH-Net.
As I run a system similar to the one you describe, I can offer very precise information for this kind of issue. Contact the Mikrotik technical divison and request their assistance. I'm sure that they will be just as keen to improve their security also, I always am.
«
Last Edit: April 06, 2008, 07:03:24 AM by RoleReversal
»
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
software
Newbie
Offline
Posts: 2
Re: Bypassing Mikrotik hotspot login page
«
Reply #2 on:
April 06, 2008, 05:51:54 AM »
Quote from: RoleReversal on April 06, 2008, 03:32:55 AM
software,
Welcome to EH-Net.
As I run a system similar to the one you describe, I can offer very precise information for this kind of issue. Contact the Mikrotik technical divison and request their assistance. I'm sure that they will be just as keen to improve their security also as I always am.
Hi role Reversal
Thanks so much for your quick reply..
I have contacted them, and i was adviced to go for some more professional courses to learn more about Security..
What i really need to know right now is how its been done... and so doing,g i will be able to know the faults.. presently, some ports are open on my network.. 21,22,23,80,53
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Bypassing Mikrotik hotspot login page
«
Reply #3 on:
April 06, 2008, 06:54:28 AM »
Software,
looking at the port list, as I'm sure you're aware you've got FTP, Telnet, SSH, HTTP and DNS open to the source of your scan. I'm assuming the scan was actioned from an external source not local, if you performed the scan from the loca network then there may be false positives for services that are protected by firewalls etc.
Major advice would be to disable any services that you do not need. As you state that you are an ISP, all the services seem reasonable although I would question running all services from a single IP/server, although I know that this can be forced via budget/resource restraints etc.
First service that I would look at would be Telnet, as you are also running SSH then it is likely this service isn't needed for general administrative purposes. (Telnet transmits login/session details in cleartext whilst SSH is encrypted).
As your remote communication services (telnet/ssh) require valid credentials to access the server (I hope) then it is possible that an account on the server has been compromised, possibly through social engineering, or dictionary/bruteforce attempts. Only good staff awareness, training and policy can protect against the first, for the latter there are many tools designed to protect against brute-force attemtps, for example try
breakinguard.
Next step would be to ensure that all software and services are up to date. I know it's a chore but keeping patch levels up to date can save you some big headaches.
You also stated that a third party hotspot service was the source of the unidentified individual using your network. As from your response they appear to be fairly unhelpful, I would recommend if possible and within your authority finding a different service provider. If this is not possible then you could try to segregate the wireless connection from the core of your network, on a DMZ for example. What evidence do you have that has lead you to believe that this is the entry point being used to access your network?
Once your server is locked down then you need to attempt to determine how the unknown party has gained access to your network and what damage has been done. For this you need to be looking at logs and any information you can get. How were you alerted to the individual bypassing your systems in the first place?
If incident response is new to you then the SANs Intrusion Detection FAQ can be a good place to start,
HERE
.
Hopefully this should set you on your way to both determining what has occured and improving your systems security. Knowing the industry I appreciate that some of this information you may not want it public view, this being the case feel free to PM me if necessary. Good luck...
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Bogwitch
Jr. Member
Offline
Posts: 51
Senno Ekto Gamat
Re: Bypassing Mikrotik hotspot login page
«
Reply #4 on:
April 07, 2008, 09:32:12 AM »
If you are managing an ISP, you should inform your management that you have security issues and suggest they employ a security professional to secure the network. This is the first time I have heard of ANY ISP that does not have a dedicated security team although I have not dealt with small ISPs.
Are you sure you work for the ISP and you're not just trying to break in to their network?
Logged
CISSP, C|EH, C|HFI
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Bypassing Mikrotik hotspot login page
«
Reply #5 on:
April 07, 2008, 10:02:32 AM »
Quote from: Bogwitch on April 07, 2008, 09:32:12 AM
Are you sure you work for the ISP and you're not just trying to break in to their network?
Good question,
looks like EH-net-ers are friendlier than
TechRepublic
though
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
shawal
Jr. Member
Offline
Posts: 88
Re: Bypassing Mikrotik hotspot login page
«
Reply #6 on:
April 07, 2008, 11:05:52 AM »
several years ago I used to work for an ISP, actually it was a visp, where the modem banks are managed by the teleco, not us. I was the system admin, the accounting the security team, support line, and the kitchen sink.
ISP does not always mean big teams, nor big hardware. RR answer was spot on first time, and the Guy wanted to know more about securing a system, not attacking a system, give him a break. people with better defenseive skills are the best ethical hackers as they are preventing the attack from happening in first place.
Logged
RHCE, GIAC GCIH.
slimjim100
EH-Net Columnist
Sr. Member
Offline
Posts: 385
Re: Bypassing Mikrotik hotspot login page
«
Reply #7 on:
April 07, 2008, 01:55:08 PM »
I do work for an ISP (I see tons of phishing calls for help to the
Abuse@myisp.com
) and I would like to see an e-mail address from the real domain before offering too much help as Yahoo e-mail addresses are free. If you truly need help with security you might want to post a real e-mail address you can post it like bob.smith (at) Mikrotik (dot) com to avoid spam. But till you show a way to prove you do work for the ISP it would be hard for most of the members here to help you ethically.
Brian
Logged
CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
shawal
Jr. Member
Offline
Posts: 88
Re: Bypassing Mikrotik hotspot login page
«
Reply #8 on:
April 07, 2008, 02:19:31 PM »
SlimJim100,
The last thing this guy wants is to tell the whole internet world which isp have a wide open hole. that they can not close right now.
Asking in an open public forum regarding an issue that is currently active and exploited now by one may be not that harmless abuser! didn't we learn that the first step of attacks are gathering information from public forums. it is enough that he gave his yahoo email if it is the true one, one can correlate from his internet presence lots of information that can be used against him.
software,
google for system hardening, and invest some money in a security consultant to harden, and audit your systems, if you are making money of it , its only fair to your users to spend thier money wisely and protect thier privacy as you do not know the extent of the compromise most probably.
Logged
RHCE, GIAC GCIH.
geekyone
Full Member
Offline
Posts: 180
Re: Bypassing Mikrotik hotspot login page
«
Reply #9 on:
April 07, 2008, 03:34:29 PM »
Well the long and the short of it is that you aren't going to get much more then general help from an open forum about an active security issue that you can't disclose details about (for obvious reasons). If you do work for the ISP and need fix this security breach then your best bet is to tell management to pony up some cash and hire a security professional to take a look at your network. Now if you need help finding a security professional you came to the right place! Post your geographical location and ask for someone in your general area to send you a Private Message so you can make arrangements. Good Luck!
Logged
CISSP, CEH, GPEN, GCIH, GCFA
BillV
Hero Member
Offline
Posts: 1892
Re: Bypassing Mikrotik hotspot login page
«
Reply #10 on:
April 07, 2008, 04:53:20 PM »
shawal does make a good point in regards to posting the ISP in a public forum.
I personally choose not to respond to posts like this when they are not very well written (like the original post above). I would expect that a network administrator have a little more competence (as someone else mentioned too). Plus, in this case, he's not specific enough for me to believe that he's actually trying to protect something instead of break through it. Especially since he works for an ISP that offers this service, I'd expect him to have some more knowledge than "a little bit" on how his own system works.
Logged
Kev
Sr. Member
Offline
Posts: 428
Re: Bypassing Mikrotik hotspot login page
«
Reply #11 on:
April 07, 2008, 05:37:34 PM »
I tend to agree with Bill V on this and this does not seem like the kind of question an admin would be asking. The only way to bypass the Mikrotic login is if you have admin access. Its actually a simple technique. If someone is able to do this then it suggests they have owned the box and have admin access. If this is true then you have a serious issue that requires more immediate attention that trying to figure out how to bypass the login page remotely.
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: Bypassing Mikrotik hotspot login page
«
Reply #12 on:
April 07, 2008, 07:04:32 PM »
This thread has pretty much run its course.
Closed.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Ethical Hacktivism
: lulzsec in it for the money
(7) by
Georgydfea
News Items and General Discussion About EH-Net
: [Article]-Holiday 2012 Free Giveaway Sponsor - Rapid7
(20) by
Georgydfea
News Items and General Discussion About EH-Net
: Наконец то ра
(4) by
Georgydfea
Web Applications
: Nessus and Nikto
(4) by
Seen
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(4) by
impelse
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.