• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
  • Search
  • Member List
  • Calendar
  • Help

Current time: 11-22-2008, 09:37 PM Hello There, Guest! (Login — Register)


Warp2Search - Your Daily Tech News Service / General Discussion / Submit News / Linksys Wi-Fi router vulnerability discovered/and Fixed!!!!

Post Reply  Post Thread 
Threaded Mode | Linear Mode
Linksys Wi-Fi router vulnerability discovered/and Fixed!!!!
Author Message
.
Account not Activated


Posts: 131
Group: Awaiting Activation
Joined: Apr 2004
Status: Offline
Post: #1
Linksys Wi-Fi router vulnerability discovered/and Fixed!!!!

Quelle: CNetNews.com

Quote:
Cisco Systems has issued a patch for a security flaw in one of its Linksys routers that could give hackers access to consumers' home networks.

Alan Rateliff II, an independent security consultant, on Friday said he discovered a vulnerability in the Linksys WRTS54G 802.11g wireless router. The flaw gives hackers a free pass into the Web-based configuration page of the router when the firewall function is turned off. When Rateliff originally tested the devices in March, he discovered that this vulnerability existed on two Linksys routers straight from the store. The default configuration on the products he tested used version 2.02.7 of the firmware, and they enabled access to the configuration page via ports 80 and 443.

When he tested new Linksys routers, using both firmware versions 2.02.7 and 2.02.2 earlier this week, he did not find the same flaw on routers that use the standard configuration settings. But he noticed that when the firewall is turned off on the devices, ports 80 and 443 are still open, allowing the configuration page to be easily accessed. Allowing easy access to configuration settings on a router is a security risk. Hackers could change settings of the router to launch spam and virus attacks, without the victim ever realizing what is going on. Attackers could also gain access to devices attached to the router, such as laptops and PCs. With an open door into the network, attackers could target unprotected individual machines and infect them with worms and viruses.





And here the Fix?!:

Quote:
Linksys have also released a new BETA version for the WRT54G (2.02.8_BETA)

very little is shown in the changelog however they have shown this:

- Resolved security issue where remote management is enabled on port 80 and 443 when firewall is disabled
- Additional features are under development and are not supported in this beta release.


Download:

http://www.linksysinfo.org/modules.php?n...etit&lid=5

06-05-2004 08:06 AM
Find all posts by this user Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply  Post Thread 

View a Printable Version
Send this Thread to a Friend
Subscribe to this Thread | Add Thread to Favorites

Forum Jump:

Contact Us | Warp2Search.Net | Return to Top | Return to Content | RSS Syndication

Powered By MyBB
Copyright © 2002-2008 MyBB Group