{"id":112,"date":"2010-06-21T21:11:43","date_gmt":"2010-06-21T19:11:43","guid":{"rendered":"http:\/\/lunatic.no\/?p=112"},"modified":"2010-06-21T21:11:43","modified_gmt":"2010-06-21T19:11:43","slug":"dissecting-mikrotiks-mac-telnet-packets","status":"publish","type":"post","link":"http:\/\/130.61.186.249\/index.php\/2010\/06\/21\/dissecting-mikrotiks-mac-telnet-packets\/","title":{"rendered":"Dissecting Mikrotiks Mac-Telnet packets"},"content":{"rendered":"<p><div id=\"attachment_117\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/130.61.186.249\/wp-content\/uploads\/2010\/06\/Screenshot-mactelnet-test.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-117\" class=\"size-medium wp-image-117\" title=\"Screenshot of Mac-Telnet dissecter\" src=\"http:\/\/130.61.186.249\/wp-content\/uploads\/2010\/06\/Screenshot-mactelnet-test-300x205.png\" alt=\"Screenshot of Mac-Telnet dissecter\" width=\"300\" height=\"205\" \/><\/a><p id=\"caption-attachment-117\" class=\"wp-caption-text\">Mac-Telnet traffic in Wireshark<\/p><\/div><br \/>\nI was searching on the Internet if there were any MAC-Telnet clients for linux\/posix, since using terminal.exe in wine is problematic sometimes, as wine gives it access to only one of the NICs in your computer.<br \/>\nI didn&#8217;t find any clients, but I found this nice reverse engineering of the protocol, which interested me, because I&#8217;ve always wondered how it was made, just not enough to check myself. But this guy has done his homework and then some in reverse engineering of Mikrotiks protocol.<br \/>\nYou can find his page here: <a href=\"http:\/\/www.omniflux.com\/devel\/\" target=\"_blank\" rel=\"noopener\">http:\/\/www.omniflux.com\/devel\/<\/a><br \/>\nThis gave me an Idea to create a MAC-Telnet client myself, and I started some testing with perl to check if I was able to send the correct packets to my mikrotik router. At first you might think; thats easy! All packets via the mac-telnet protocol uses UDP packets, with both source- and destintation port: 20561.<br \/>\nBut you can&#8217;t send these packets with your normal socket wrapper library, because you need to set the mac-addresses in the network frame to something other than the source\/destination IPs corresponding ARP entry. To go into details: When you send Mac-Telnet packets as a client, you need to send your packets going from your ip to ip 255.255.255.255, but with the router you want to telnet as the destination mac address in the ethernet frame. (even though the ip is set to 255.255.255.255).<br \/>\nTo test this in perl, I used Net::RawIP from CPAN, which worked just like I wanted to. The only problem is that you need to have root access to be able to do raw packets.<br \/>\nAnyways, I looked at the packet I sent with my test script, and the response from the RouterBoard with Wireshark. Even though I got it to work, I felt I was having problems reading the packets very easily: Reading omniflux&#8217;s protocol description, and then looking at the hex dump of the packet. So I decided to make a dissector plugin for Wireshark (ethereal), so I could debug the packets easier.<br \/>\nHere is the finished source code for the Wireshark plugin (GPLv2): <a href=\"http:\/\/lunatic.no\/wp-content\/uploads\/2010\/06\/mactelnet.diff_.txt\">mactelnet.diff<\/a><br \/>\nJust patch this in from the root of the wireshark sources.<br \/>\n[Update: It is now added in the wireshark svn trunk]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was searching on the Internet if there were any MAC-Telnet clients for linux\/posix, since using terminal.exe in wine is problematic sometimes, as wine gives it access to only one of the NICs in your computer. I didn&#8217;t find any clients, but I found this nice reverse engineering of the protocol, which interested me, because [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,27],"tags":[],"class_list":["post-112","post","type-post","status-publish","format-standard","hentry","category-cprogramming","category-routeros"],"_links":{"self":[{"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/posts\/112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/comments?post=112"}],"version-history":[{"count":0,"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/posts\/112\/revisions"}],"wp:attachment":[{"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/media?parent=112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/categories?post=112"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/130.61.186.249\/index.php\/wp-json\/wp\/v2\/tags?post=112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}