home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 3493
Discussions: 188,440, Posts: 2,243,947, Members: 232,691
Old September 16th, 2005, 10:36 AM   Digg it!   #1 (permalink)
Real gangstas sip on Yacc
 
jkrohn's Avatar
 
Join Date: Oct 2001
Location: Suckas-ville
Posts: 4,549
Send a message via ICQ to jkrohn Send a message via AIM to jkrohn Send a message via Yahoo to jkrohn
WRT54G Vulerabilities!

Six vulnerabilities have been found in this quite popular router. These are tested against the linksys firmware, but may be found in third party firmware as well. Please check with your firmware provider.

Some of these are quite serious!

http://isc.sans.org/diary.php?storyid=674

Jkrohn
__________________
Signatures blow hard
If your signature contains an ad of any kind, congratulations, you're on my ignore list.

jkrohn is offline   Reply With Quote
Old September 20th, 2005, 02:19 PM     #2 (permalink)
Cerca, trova
 
Socalgal's Avatar
 
Join Date: May 1999
Location: USA
Posts: 10,679
Thumbs up

Thanks!

Socalgal is offline   Reply With Quote
Old September 20th, 2005, 02:32 PM     #3 (permalink)
Ultimate Member
 
batmeat's Avatar
 
Join Date: Oct 2001
Posts: 2,503
Nice, I have that router, but it's just sitting in a box.
__________________
How come Sour Cream can expire?

batmeat is offline   Reply With Quote
Old September 20th, 2005, 02:38 PM     #4 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,773
Blog Entries: 5
hahahahaha awsome
GroundZero3 is online now   Reply With Quote
Old September 20th, 2005, 02:44 PM     #5 (permalink)
Best To Avoid Me
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Under Your Bed
Posts: 8,596
Thanks for the info, I'm a WRT54G user.

It seems that 4 of the 5 workarounds are simply having wireless security in place and having the latest firmware.

Quote:
WORKAROUND
In order to mitigate exposure of the router and internal network to
outside attackers, ensure encryption is enabled on the wireless
interface. The exact settings to use are dependent on your wireless
deployment policies.

VENDOR RESPONSE
This vulnerability is addressed in firmware version 4.20.7 available for
download...
The other is simply disabling the web access from wireless users.
Quote:
In order to prevent exposure of this vulnerability from wireless clients,
disable wireless access to the web interface:

• Connect to the web interface, typically at http://192.168.1.1/
• Go to the Administration page
• Select 'Disable' next to the 'Wireless Access Web'
• Click the 'Save Settings' button.

Please note that this will only prevent wireless access, and not access
from one of the physical ports. Additionally, other vulnerabilities in
the httpd may allow exploitation of the router, even with this setting
enabled.

Martoch is online now   Reply With Quote
Old September 20th, 2005, 02:47 PM     #6 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,773
Blog Entries: 5
Disabling access to the wireless clients should be off by default. (One of the first things i turned off) No one should ever have that on. They are just asking for trouble.
GroundZero3 is online now   Reply With Quote
Old September 20th, 2005, 02:49 PM     #7 (permalink)
Best To Avoid Me
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Under Your Bed
Posts: 8,596
Agreed, but how many router users even log into the dang thing? They just plug it all in, get on the internet, and surf away on multiple PC's. 75% of the router users I talk to look at me funny when I mention wireless security.
Martoch is online now   Reply With Quote
Old September 20th, 2005, 03:01 PM     #8 (permalink)
Cerca, trova
 
Socalgal's Avatar
 
Join Date: May 1999
Location: USA
Posts: 10,679
Quote:
75% of the router users I talk to look at me funny when I mention wireless security.
You sure it's not the mask?
Socalgal is offline   Reply With Quote
Old September 26th, 2005, 02:43 PM     #9 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,773
Blog Entries: 5
http://www.hyperwrt.org/forum/viewtopic.php?id=485

For those who want to keep HyperWRT!


err nevermind just noticed they modified the .6 and not .7

poop
GroundZero3 is online now   Reply With Quote
Old October 1st, 2005, 07:58 PM     #10 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,773
Blog Entries: 5
Quote:
Although it seems like the WRT54GS has been getting all the love lately, there's been a new rash of updates to the HyperWRT firmware for the venerable WRT54G.

Both a newcomer, Tofu, and the originator of this storm, Rupan, have taken to their keyboards to keep HyperWRT alive while Avenger2.0 is away from his.

Common to both releases is integration of the HyperWRT 2.1b1 code with Linksys' updated 4.20.7 codebase, upgrades to BusyBox 1.01, and the addition of static DHCP, ala Thibor's latest release for the WRT54GS. Although implemented differently, Tofu through the web GUI with a 5 client limitation and Rupan through Telnet, this has got to be one of the most requested additional features for the HyperWRT crowd. Other differences do exist and you can find them int he changelogs that follow. KaiStation is not included in either of these releases.

If you'd like to pick up either of these release follow the links:

Rupan's 09-26-05 release for the WRT54G: binary and source changes.

Tofu's TOFU5 release for the WRT54G: binary and source changes.

More complete changelogs can be found after Read More....



Rupan's 09-26-05 release changelog
o dnsmasq v2.23
o rewrite uptime() function to display actual uptime and load average
o support libresolv (+2kb) for various external software (a la Net-SNMP)
o iptables 1.2.9*
o Linksys codebase 4.20.7

in addition, the usual complement of features:

o edns and etherwake
o Busybox 1.01
o HyperWRT 2.1b1
o kai is *not* included (but may be in the future)
o static DHCP leases, but NOT from the web gui -- only from telnet


Tofu's TOFU5 release changelog:
o added static dhcp lease, 5 clients GUI interface
o udhcp* is now up to 0.9.9-pre
o included busybox 1.01.
o Incoming/outgoing logs have been updated to show denied and accepted connections.
o Syslog now works. Enter 0.0.0.0 to disable it. (By default it will load klogd to give you kernel messages, but if for some reason you want it disabled, you can do this by setting klogd=0 in nvram.)
o Linksys 4.20.7 codebase
o HyperWRT 2.1b1
from

http://www.linksysinfo.org/modules.p...rticle&sid=410



BTW Wallwatcher works with the WRT54G with the hyper/seasoft firmware!
GroundZero3 is online now   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
WRT54G Low response washe Networking and Internet 4 August 17th, 2005 11:18 PM
Help on WRT54G zheshi Webmastering and Programming 2 July 26th, 2005 07:00 AM
Linksys WRT54G issue washe Networking and Internet 1 June 26th, 2005 05:31 PM
wrt54g firmware sr71000 Networking and Internet 5 April 16th, 2005 01:46 PM
New WRT54G and WPC54G EvilRick Networking and Internet 8 March 10th, 2004 05:23 PM

Most Active Discussions
"mastermind" of London at.. (59)
Is It Just Me? (2973)
9/11 commission final report right .. (26)
can anyone help me? (5)
building a gaming computer, input p.. (13)
Windows 7 Beta To Be Released On Ja.. (5)
I think I just killed my computer w.. (24)
How to increase my ram? (14)
Folderchat Weekday thread (444)
Recent Discussions
Please help! (0)
New Build i7 920 gaming rig (0)
Windows 7 Beta To Be Released O.. (5)
get this error, "res://C:\.. (75)
nVidia GTX 295 now available (6)
AMD Phenom II X4 940 Black Edit.. (0)
New Build ( Finally ) (9)
MS to offer free Windows 7 upgr.. (4)
Computer will not boot(powers o.. (1)
Blackberry Storm, Gears of War .. (1)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 06:15 PM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28