September 16th, 2005, 10:36 AM
|
#1 (permalink)
| | Real gangstas sip on Yacc
Join Date: Oct 2001 Location: Suckas-ville
Posts: 4,549
|
Six vulnerabilities have been found in this quite popular router. These are tested against the linksys firmware, but may be found in third party firmware as well. Please check with your firmware provider.
Some of these are quite serious! http://isc.sans.org/diary.php?storyid=674
Jkrohn
__________________
Signatures blow hard
If your signature contains an ad of any kind, congratulations, you're on my ignore list.
|
| |
September 20th, 2005, 02:19 PM
|
#2 (permalink)
| | Cerca, trova
Join Date: May 1999 Location: USA
Posts: 10,679
| |
| |
September 20th, 2005, 02:32 PM
|
#3 (permalink)
| | Ultimate Member
Join Date: Oct 2001
Posts: 2,503
|
Nice, I have that router, but it's just sitting in a box.
__________________ How come Sour Cream can expire? |
| |
September 20th, 2005, 02:38 PM
|
#4 (permalink)
| | A hero in training
Join Date: Oct 2001 Location: Norfolk, VA
Posts: 22,773
| |
| |
September 20th, 2005, 02:44 PM
|
#5 (permalink)
| | Best To Avoid Me
Join Date: Mar 2002 Location: Under Your Bed
Posts: 8,596
|
Thanks for the info, I'm a WRT54G user.
It seems that 4 of the 5 workarounds are simply having wireless security in place and having the latest firmware. Quote: WORKAROUND
In order to mitigate exposure of the router and internal network to
outside attackers, ensure encryption is enabled on the wireless
interface. The exact settings to use are dependent on your wireless
deployment policies. VENDOR RESPONSE
This vulnerability is addressed in firmware version 4.20.7 available for
download...
| The other is simply disabling the web access from wireless users. Quote:
In order to prevent exposure of this vulnerability from wireless clients,
disable wireless access to the web interface:
• Connect to the web interface, typically at http://192.168.1.1/
• Go to the Administration page
• Select 'Disable' next to the 'Wireless Access Web'
• Click the 'Save Settings' button.
Please note that this will only prevent wireless access, and not access
from one of the physical ports. Additionally, other vulnerabilities in
the httpd may allow exploitation of the router, even with this setting
enabled. | |
| |
September 20th, 2005, 02:47 PM
|
#6 (permalink)
| | A hero in training
Join Date: Oct 2001 Location: Norfolk, VA
Posts: 22,773
|
Disabling access to the wireless clients should be off by default. (One of the first things i turned off) No one should ever have that on. They are just asking for trouble. |
| |
September 20th, 2005, 02:49 PM
|
#7 (permalink)
| | Best To Avoid Me
Join Date: Mar 2002 Location: Under Your Bed
Posts: 8,596
|
Agreed, but how many router users even log into the dang thing? They just plug it all in, get on the internet, and surf away on multiple PC's. 75% of the router users I talk to look at me funny when I mention wireless security. |
| |
September 20th, 2005, 03:01 PM
|
#8 (permalink)
| | Cerca, trova
Join Date: May 1999 Location: USA
Posts: 10,679
| Quote: |
75% of the router users I talk to look at me funny when I mention wireless security.
| You sure it's not the mask?  |
| |
September 26th, 2005, 02:43 PM
|
#9 (permalink)
| | A hero in training
Join Date: Oct 2001 Location: Norfolk, VA
Posts: 22,773
| |
| |
October 1st, 2005, 07:58 PM
|
#10 (permalink)
| | A hero in training
Join Date: Oct 2001 Location: Norfolk, VA
Posts: 22,773
| Quote:
Although it seems like the WRT54GS has been getting all the love lately, there's been a new rash of updates to the HyperWRT firmware for the venerable WRT54G.
Both a newcomer, Tofu, and the originator of this storm, Rupan, have taken to their keyboards to keep HyperWRT alive while Avenger2.0 is away from his.
Common to both releases is integration of the HyperWRT 2.1b1 code with Linksys' updated 4.20.7 codebase, upgrades to BusyBox 1.01, and the addition of static DHCP, ala Thibor's latest release for the WRT54GS. Although implemented differently, Tofu through the web GUI with a 5 client limitation and Rupan through Telnet, this has got to be one of the most requested additional features for the HyperWRT crowd. Other differences do exist and you can find them int he changelogs that follow. KaiStation is not included in either of these releases.
If you'd like to pick up either of these release follow the links:
Rupan's 09-26-05 release for the WRT54G: binary and source changes.
Tofu's TOFU5 release for the WRT54G: binary and source changes.
More complete changelogs can be found after Read More....
Rupan's 09-26-05 release changelog
o dnsmasq v2.23
o rewrite uptime() function to display actual uptime and load average
o support libresolv (+2kb) for various external software (a la Net-SNMP)
o iptables 1.2.9*
o Linksys codebase 4.20.7
in addition, the usual complement of features:
o edns and etherwake
o Busybox 1.01
o HyperWRT 2.1b1
o kai is *not* included (but may be in the future)
o static DHCP leases, but NOT from the web gui -- only from telnet
Tofu's TOFU5 release changelog:
o added static dhcp lease, 5 clients GUI interface
o udhcp* is now up to 0.9.9-pre
o included busybox 1.01.
o Incoming/outgoing logs have been updated to show denied and accepted connections.
o Syslog now works. Enter 0.0.0.0 to disable it. (By default it will load klogd to give you kernel messages, but if for some reason you want it disabled, you can do this by setting klogd=0 in nvram.)
o Linksys 4.20.7 codebase
o HyperWRT 2.1b1
| from http://www.linksysinfo.org/modules.p...rticle&sid=410
BTW Wallwatcher works with the WRT54G with the hyper/seasoft firmware! |
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |
Posting Rules
| You may post new threads You may post replies You may not post attachments You may not edit your posts HTML code is Off | | |
Similar Threads | | Thread | Thread Starter | Forum | Replies | Last Post | | WRT54G Low response | washe | Networking and Internet | 4 | August 17th, 2005 11:18 PM | | Help on WRT54G | zheshi | Webmastering and Programming | 2 | July 26th, 2005 07:00 AM | | Linksys WRT54G issue | washe | Networking and Internet | 1 | June 26th, 2005 05:31 PM | | wrt54g firmware | sr71000 | Networking and Internet | 5 | April 16th, 2005 01:46 PM | | New WRT54G and WPC54G | EvilRick | Networking and Internet | 8 | March 10th, 2004 05:23 PM | | Most Active Discussions | | | | | Recent Discussions  | | | | | |