Files

43 lines
1.3 KiB
Markdown
Raw Permalink Normal View History

2024-12-19 01:28:55 +01:00
## Hardening Mikrotik con Sara
2024-12-19 01:23:32 +01:00
2024-12-19 01:28:55 +01:00
### Fai il backup del mikrotik e installa sara
#### Fai il backup verbose del mikrotik in modo da generare un .rsc invece di un .backup
2024-12-19 01:23:32 +01:00
```
/export verbose file=mybackup
```
2024-12-19 01:28:55 +01:00
#### Scarica il backup da webgui
2024-12-19 01:23:32 +01:00
"File" (nel menu a sx) > "Download" in corrispondenza del backup salvato
2024-12-19 01:28:55 +01:00
#### Installa sara
2024-12-19 01:23:32 +01:00
```
# kali (e parrot?):
sudo apt update && sudo apt install sara -y
# altri:
via python3 https://github.com/casterbyte/sara
```
2024-12-19 01:28:55 +01:00
#### Testa la configurazione del mikrotik con sara
2024-12-19 01:23:32 +01:00
```
sara --config-file /home/$USER/Downloads/mybackup.rsc
```
2024-12-19 01:28:55 +01:00
### ESEMPI:
#### Disabilita i servizi inutili
2024-12-19 01:23:32 +01:00
```
/ip service set telnet disabled=yes
/ip service set ftp disabled=yes
#/ip service set www disabled=no (la 80 รจ da tenere aperta per l'accesso remoto default e non chiuderci fuori)
/ip service set www-ssl disabled=yes
/ip service set api disabled=yes
/ip service set api-ssl disabled=yes
#/ip service set winbox disabled=no (l'accesso via ethernet l2 potremmo volerlo tenere abilitato per evitarci l'hard reset)
```
2024-12-19 01:28:55 +01:00
#### Impedisci attacchi al bootloader...
2024-12-19 01:23:32 +01:00
```
/system routerboard upgrade #(se non hai >=6.49.17)
/system reboot #(se non hai >=6.49.17)
/system routerboard settings set protected-routerboot=enabled
```
#### ... quindi verifica
```
/system routerboard settings print
```