Helping my friend close the backdoor

So as I mentioned before, I was able to set up OpenVPN/dns2tcp to work on a MikroTik Router. I never mentioned how I actually got access to that MikroTik Router. Well, the way I got access to it was because the guy in charge of the network didn't bother updating it and BigNerd95's Exploit worked. I went to him the first time I found out about this and told him to update it and he said sure. A couple of days later, I go open WinBox and notice it hasn't been updated. I go back to him and told him to make sure he updates it, he says "I don't need to worry. Most Yemenis (I'm in Yemen now) don't know how to do stuff like this." I replied "Yeah, but what if someone evil (aka me :)) comes through and gives himself free internet or ruins your router." He says "ok don't worry, I'll update it." 3 days later, still no update. At this point, I just give up and just log in, give myself a bunch of codes I can use to log in, set up OpenVPN/dns2tcp, bypass my random MAC, etc...

So I'm leaving Yemen next week and decided to help this guy (who at this point we're friends considering how much times we talked together.) I go to him today after 2PM with my laptop and show him how the exploit worked and I explained to him some stuff. He got a call and had to leave, so we decided to meet after 6PM. I left to go shopping (a Pringles can cost 1250YR can you believe that (2.50$)) and got a cool USB and MicroUSB USB Storage device (64GB).

Came back home, relaxed til 6:10, then went to meet the guy. I got there, pulled out my laptop, and started researching about updating whether it was going to mess up user manager or not(all the codes are in the use manager and if it messes up, then none of the codes will work and there will be a lot of pissed customers.) After a while I back up the User Manager database (this came really handy later on), then I transfer it from the MikroTik Router to the guy's laptop. After that we spend a bit more time (like an hour and a half) looking up about MikroTik updating and if there's any negatives (more like I was the only one looking up cause I'm the only one who was able to read English.) Then I decided to wing it. I clicked the "Download&Install" button. The download was going slow (like 1% every 8-9 seconds) and my heart was beating loudly. I was hoping it wouldn't mess with anything. After a while, it was done and we heard the MikroTik Router beeping (it was restarting.) We waited for 10-15 secs before trying to log back on to WinBox, then it worked. I went to check on the scheduler, hotspot, firewall, and some other stuff. Then I went to check on the User Manager. My heart was beating fast as I hoped nothing happened to it. I went to log in, then it worked. All the users were still there. I then told him to change his User Manager account and password as having the password be blank and the account be called "admin" wasn't gonna be hard to break. I did something stupid and removed the admin account. He then added his own username and password. I left and thought that was the end of it.

Sike. He called me and told me the User Manager was messed up. I told him I'll be right there and left my home. Once I arrived, I took a look. The User Manager was completely empty. I panicked for a second, but I remembered we backed it up before we updated it. I went on the MikroTik Router through SSH and ran the command to restore it, and thank god it worked. I then let him change the account "admin"'s password. Now everything is working fine, the script I left in the scheduler to run every 5 mins to add my mac to the bypassed list is working, and now no one else can break through the MikroTik Router.

I found out that the other connection next to me uses MikroTik and he didn't update his router. I might hit him up later and ask him if he wants to update his router for better protection.

Also, I keep referring to him as "guy" because I actually don't know his name lol.

EDIT: Forgot to mention, but before I went to him to update it, I added a script to scheduler that adds a Random MAC Address I made up to the bypassed list so I can spoof my laptop's MAC for free Internet speed with 2mb/s. The script runs every 5 minutes, so even if he blocks it, it'll automatically change to bypassed after 5 min.

Comments

Now no one else can break through the MikroTik Router" Nice backdoor you left there :rofl:
Interesting read, I have no idea who MicroTik is but I figure it's some business oriented brand?
 
  • Like
Reactions: 1 person
So, TL;DRAOI:

You're in Yemen. You're helping a guy, but you can't remember his name. He doesn't believe updates will prevent people like you from hacking into the network, though you're dedicated and sneaky.

After you show him that you've hacked him, you offer to help him out. You bought some Pringles afterward. Later, he calls you regarding User Manager not working properly, but you made a backup, which fixed the issue.

You're leaving Yemen in one week, but you made a friend....and the guy next door to your new friend has a router susceptible to hacking.

pokemonfacts-01-credits-56d3df7a5f9b5879cc8dab64.jpg
 
  • Like
Reactions: 1 person
@The Real jdbye MikroTik is a company that sells routers that sets up a captive portal + other stuff.

@HB1BEsquire I actually never asked for his name. Also, he knew updating would block the hack, but he said no one in Yemen would probably figure that out (which is most likely true since I can't find any tutorial in Arabic about the MikroTik Exploit.) I actually wasn't sneaky cause he actually knew I'd log on (I think the system tells him when someone else logs on.) The other guy isn't next door per se. I actually met him before when I came to Yemen the first time (around 2014/15.) I was trying to hack and get free internet at the time, but all my efforts were futile. Also, I'm leaving Yemen in 6 days.

@Hells Malice I prefer the term "Chaotic good".
 
  • Like
Reactions: 1 person

Blog entry information

Author
Coolsonickirby
Views
175
Comments
8
Last update

More entries in Personal Blogs

More entries from Coolsonickirby

General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    Hope they made lots of spaget
  • K3N1 @ K3N1:
    Chill dog
  • SylverReZ @ SylverReZ:
    Chilli dog
  • Skelletonike @ Skelletonike:
    Damn, I'm loving the new zelda.
  • xtremegamer @ xtremegamer:
    loving the new zelda, i started a game, it was so fucking good, so i
    am waiting on my friend to get home so we can start a new one together
  • Skelletonike @ Skelletonike:
    I just dislike that they don't let me choose the voices before the game starts. Happened with botw as well, had to change to japanese and restart.
  • K3N1 @ K3N1:
    But the important question is can you choose gender
  • Skelletonike @ Skelletonike:
    Same way you can choose Gerald's gender.
  • Skelletonike @ Skelletonike:
    *Geralt, damn autocorrect.
  • Psionic Roshambo @ Psionic Roshambo:
    But can he be trans? Lol
  • K3N1 @ K3N1:
    Zelda transforms into link
  • Psionic Roshambo @ Psionic Roshambo:
    Link I'm not the princess your looking for.... *Pulls a crying game*
  • K3N1 @ K3N1:
    *skirt up* it's exactly what I always wanted
  • Skelletonike @ Skelletonike:
    Just scanned all my zelda amiibos, took a while but didn't get anything that cool, did get the lon lon ranch hylian fabrics though.
  • Skelletonike @ Skelletonike:
    It was pretty funny when I scanned wolf link and got a shit load of meat.
  • K3N1 @ K3N1:
    @Skelletonike, btw I ran that custom for mgs4 on the deck I'm amazed it got that far in game
  • K3N1 @ K3N1:
    Plug in*
  • K3N1 @ K3N1:
    Your favorite activity
  • BentlyMods @ BentlyMods:
    My fav actvity is:

    mario-dancing.gif
  • Psionic Roshambo @ Psionic Roshambo:
    Do the Mario lol
  • K3N1 @ K3N1:
    🍑
    K3N1 @ K3N1: 🍑