Path: blob/master/documentation/modules/post/windows/gather/credentials/winbox_settings.md
28210 views
Vulnerable Application
Any Windows host with a meterpreter session and Mikrotik Winbox installed.
Winbox can be downloaded here
Installation Steps
Download and open Mikrotik Winbox
Enter a RouterOS device address into
Connect to, username intoLogin, password intoPasswordand check the flagKeep PasswordClick Connect
Verification Steps
Get a
meterpretersession on a Windows host.Do:
run post/windows/gather/credentials/winbox_settingsIf any users in the system has a
Keep Passwordenabled in Winbox, the credentials will be printed out.
Options
VERBOSE
By default verbose is turned off. When turned on, the module will show the HexDump of
settings.cfg.viwfiles.