×

Warning

JUser: :_load: Unable to load user with ID: 43

JUser: :_load: Unable to load user with ID: 40

UBIQUITI - Security bug

Detecting and removing

router ubnt
Reacting to the revealed vulnerability, we released ISPadmin, version 4.20, which included a utility for detecting and curing infected Ubiquiti units. Due to the emergency situation we released the very first version of the utility quickly.

Now we are presenting the utility with enhanced functionalities.

alert icon Run the utility from ISPadmin console (connected via SSH) under root user, ISPadmin does not detect anything automatically!

/usr/local/script/ispadmin/ubnt_vulnerability_test.pl

 

When running the utility without any parameter, help is displayed.

terminal help

 

Check devices from ISP admin bookmark ROUTERS
/usr/local/script/ispadmin/ubnt_vulnerability_test.pl check <username> <username2> <username3> <username4> <username5> - show ONLY vulnerable and infected ROUTERS ( AP )


Tests all Ubiquiti units inserted in Hardware Routers. If you run this command, the system tries to attack the unit, and if it succeeds, the console displays information with IP address and firmware version. If the system succeeds in connecting to Ubiquiti unit, it tries to determine whether there is the virus or not. If yes, it displays such information in the console. Nothing else. When 10 units are tested, a dot appears on the screen to show you that the script is still running and testing other units.


Check devices like AP ....( may take a long time )
/usr/local/script/ispadmin/ubnt_vulnerability_test.pl checkdevices <username> <username2> <username3> <username4> <username5>
  - show ONLY vulnerable and infected devices ( Acces points )


Tests all devices inserted as “Device attached to device” in Hardware Routers. In this case, the utility doesn´t care about device type since such information might not be available here. The utility tries to attack all IP addresses. If there are a lot of devices in your system, this might take a long time.

Check END USER devices ....( may take a long time )
/usr/local/script/ispadmin/ubnt_vulnerability_test.pl checkusers <username> <username2> <username3> <username4> <username5>
    - show ONLY vulnerable and infected client end device


Tests all IP addresses assigned to clients. The system tests all client-assigned IP addresses for it does not know whether a client has Ubiquiti device, or not. This operation might take a long time, since all IP addresses in the system are tested.

Clean INFECTED devices ( from previous check )
/usr/local/script/ispadmin/ubnt_vulnerability_test.pl cleaninfected
   - show vulnerable and infected devices and  REMOVE infection


If an infected unit is detected in the previous step, you may clean it this way. This operation connects to and cleans just those units, which are marked as infected. It means that prior to this step you have to run the utility with parameters check, checkdevices, or checkusers. Failing this no units are marked as infected and using parameter “cleaninfected” makes no difference.

 

terminal

A mandatory parameters are: check, checkdevices, checkusers, or cleaninfected. You may use user names, which you use for login to Ubiquiti units as an optional parameter. This is needed in cases when a key is stored in Ubiquiti unit after being attacked to enable login via ssh without password. You need to know the user name with which you connect to the system. If unknown, you won´t be able to connect. While running the vulnerability test, a default user name ubnt and user admin are tested. If you use neither of these, the script won´t be able to test vulnerability hence the need for entering a different username used for accessing the unit (no need for password). Then the system will try using these usernames.

 

Listing of UBNT units in ISPadmin

When you log into ISPadmin, you will see information about Vulnerability of UBNT devices:

ubnt upozorneni

 

In Other Tools > Vulnerability of UBNT devices, you will find a tool for displaying vulnerable devices as detected by the utility - see above.

ubnt seznam

 

alert icon Check the box at the end of each row (or check all, or you may use reversed selection) to select those devices, for which you want the system to update firmware - by clicking on on the bottom.

Creating a standalone invoice

Read more ... (index.php?option=com_content&view=article&id=1159&...

Removing records from ISPadmin

Delete client Deleted client is not deleted from the system, instead its rec...

Add new / Edit existing Service

If you have added a new client, it just a contact which is not linked to any ac...

System Variables

Read more ... (index.php?option=com_content&view=article&id=1380&...

Accepting Cash Payment

overpayments (index.php?option=com_content view=article id=1088:overpaymen...

Edit invoice

Modify an invoice changing the following: Title Item description ...

No permission for adding overpayment into client´s credit

If you are trying to add overpayment, and see Permission denied message you h...

Limited data consumed / Traffic graphs are high

If you experience one/both of the following problems Limited data gets consum...

Suspension of service

The function of suspending a client serves to temporarily block the service with...

How to display client portal login credentials on an invoice

In Invoicing Settings Invoice Groups, while adding a new group (+ Add new group)...

Creation of client number

While adding a new contact to the system, you will be offered first unused clien...

Add New Contact

a requested service in Client card (index.php?option=com_content view=article...

Return of overpayment

Bulk order (index.php?option=com_content view=article id=628:returned catid=488:...

Send invoices by email

Invoices get sent in PDF automatically upon their issuing. Sending via both, reg...

Entering an address

You have the following options to enter address: Fill in respective fields: S...

More than 1 item in email or phone number fields

You will be able to add more items in every field in the system designed for ema...

PING to client does not work

PING to client function is off by default. It is to reduce network load which in...

Charging clients for tariff changes

You might want to charge clients, for example, when they decide to change to ...

One-time invoice for a service provided in a certain time period

If you want to issue a one-time invoice for a certain service that is provide...

How to give a discount

Options for discount of regular service rate are as follows: Tariff rate dis...

VAT missing on a cash receipt

If the client pays for the invoice in cash, VAT tax is not stated on the cash re...

How to send a client an email containing all of their unpaid invoices

If you want to send a particular client an email containing all of their unpaid ...

How to issue an expenditure cash slip

The system issues an expenditure cash slip when overpayments are refunded in ...

How to assign an IP address pool to a client

When editing/adding the Internet service (index.php?option=com_content view=arti...

Filtering clients base on their invoicing

Invoicing is related to services, not clients. A client can have e.g. 2 active s...

Displaced invoice margin

If invoice margins are printed incorrectly you have to check print settings of P...

Use of IP address

To find out, which client used a certain IP address in specified time, go to ...

Lookup by phone number

You can use http://ISPadmindomain.com/new/www/find-client-by-phone-number/?numbe...

How to increase internet speed in off-peak hours

If you want to increase a client&rsquo;s Internet speed in off-peak hours...

Is it possible to set an installation fee discount anywhere in the system?

No, it is not. You cannot enter such a discount to the system at the moment. ...

How to add a NAT IP address

A NAT IP address can be added in the Client card. When you are editing the In...

Suspension of the internet service at the client's request

If your client contacts you and wants you to temporarily suspend the Internet...

Is it possible to set a specific speed for IPTV service?

No, it is not possible. You cannot set up special speed profiles for the IPTV...

How to add supplementary information to contact emails and phone numbers

If you need to add supplementary information to a client's email address and ...

Is it possible to export/print out all the contracts of a client at once?

No, it is not possible. Each contract is unique. It is a single file and it i...

«
»

CONTACT

NET service solution, s.r.o.
Žerotínova 3056/81a
787 01 Šumperk
Czech Republic