commit 1c989ecb5e3e74b5c676f8a1284f2db8ab936e59 Author: Mikhail Grebenkin Date: Sun Aug 5 12:36:44 2018 +0300 Первый коммит + добавил скрипт для проверки микрота на уязвимость winbox diff --git a/README.md b/README.md new file mode 100644 index 0000000..e69de29 diff --git a/check_mikrotik_socks.mikrotik b/check_mikrotik_socks.mikrotik new file mode 100644 index 0000000..25726bb --- /dev/null +++ b/check_mikrotik_socks.mikrotik @@ -0,0 +1,5 @@ +:if ([/ip socks get port] = 1080) do={:log info "Socks port is still Default."} else={:log info "Socks Port changed Possible infection!"} +:if ([/ip socks get enabled] = false) do={:log info "Socks is not on."} else={:log info "Socks is enabled... that could be bad!"} +:if ([:len [/file find name="mikrotik.php"]] > 0) do={:log info "!!!mikrotik.php!!! File Detected!"} else={:log info "mikrotik.php not found."} +:if ([:len [/file find name="Mikrotik.php"]] > 0) do={:log info "!!!Mikrotik.php!!! File Detected!"} else={:log info "Mikrotik.php not found."} +:if ([:len [/user find name="service"]] > 0) do={:log info "!!!YOU WERE BREACHED!!!"} else={:log info "No sign of the service user."}