TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Abusing container mount points on MikroTik's RouterOS to gain code execution

54 pointsby xx_nsalmost 3 years ago

3 comments

adamcharnockalmost 3 years ago
I’m seeing a few unhappy comments about this, so I’ll just point out a couple of things:<p>1. This was introduced in a beta. It was then removed from subsequent betas until a fix could be found.<p>2. Running docker on a router could be really helpful in some cases, especially for small ISPs such as mine. For example: being able to run a recursive DNS resolver at the broadcast tower (ie nearer the customer) without having to run an entire server would be great. Or running a Prometheus exporter on the router for metric collection. Or for local processing&#x2F;archiving of netflow data.<p>There are some really helpful use cases for this, but they are not the normal devops reasons for using docker.
评论 #32362595 未加载
tmikaeldalmost 3 years ago
This is seriously the last straw for me, I&#x27;ll be switching away from Mikrotik to OpenWRT devices, a router should stay a router, not run containers!<p>The attack area on a router should shrink, not grow!
评论 #32360259 未加载
评论 #32359051 未加载
评论 #32360824 未加载
评论 #32362599 未加载
评论 #32362182 未加载
评论 #32362616 未加载
bravetraveleralmost 3 years ago
Oh boy, glad I moved mine to SwitchOS I guess. This being a beta means I would&#x27;ve ended up with this eventually, and Docker is just not something I want on a network device<p>Seriously considering replacing this with Mikrotik showing up so often<p>Edit: Any recommendations for 10GbE switches with ~8 ports would be appreciated, likely encouraging me to follow through