Live data from Hacker News

Backdoor found in Linksys, Netgear Routers

github.com

121–130 of 144 posts

Re: Backdoor found in Linksys, Netgear Routers

#121

Earlier quoted context omitted.

Time Warner wants nothing to do with my (own purchased) cable modem beyond allowing me to use it. The vendor will only provide firmware patches to cable operators, and Time Warner won't touch my modem to help get the firmware upgraded.

I've always had naked DSL because of not wanting to pay for cable TV or another line. For DSL and similar services, BYOE tends to be hand-off. With cable modems, does/can the provider push firmware?

With DOCSIS cable modems only the provider can update the firmware. And end user doesn't have the ability to update the firmware, even if they own the modem. That is part of the DOCSIS standard.

Re: Backdoor found in Linksys, Netgear Routers

#122
post #79
post #44

Earlier quoted context omitted.

Tell me, either way a Soekris box or an OpenWRT compatible router, how this brings a solution to the masses.

There is no purely technological solution for the masses. Actually solving the problem requires either a political revolution to make shipping backdoors like this criminal rather than a favor to the government, or educating users enough that they can protect themselves with the existing technological methods that are easy to deploy given basic computer literacy. It's not really clear which one is less impossible.

Even making it criminal won't work - don't you know the NSA and the government are above the law. They have government endorsed hackers who are known to be actively exploiting these systems... but if you, Joe Public, are caught doing this, you're thrown in jail under the Computer Fraud and Abuse Act. So even if it is made criminal, it'll only be criminal for you... if it's government mandated, however, it's fine.

Re: Backdoor found in Linksys, Netgear Routers

#123
post #92
post #58

Earlier quoted context omitted.

do you have a write up with more details about those exploits?

Yea I wrote it up on my blog here. Just didn't want to risk spamming heh. http://earlz.net/view/2012/06/07/0026/rooting-the-nvg510-fro...

Very neat trick. what does "errrr" do?

Re: Backdoor found in Linksys, Netgear Routers

#124

Earlier quoted context omitted.

Time Warner wants nothing to do with my (own purchased) cable modem beyond allowing me to use it. The vendor will only provide firmware patches to cable operators, and Time Warner won't touch my modem to help get the firmware upgraded.

I've always had naked DSL because of not wanting to pay for cable TV or another line. For DSL and similar services, BYOE tends to be hand-off. With cable modems, does/can the provider push firmware?

All the cable modems I've used (UK) have always downloaded a an image over TFTP on boot. As I understand it they can come up with a very minimal loader and reach out for their config to the local "node" for configuration, and this can include new firmware. On the support line they're adamant that you reboot the things before proceeding past the IVR. Which makes sense.

The last I heard about it the different levels of service (bronze/silver/gold they were at the time, 5/10/20Mbit/s) are just based on the MAC the modem sends on this initial config/handshake. When I moved from 20 to 50 I was told to reboot the modem and it came up will an all new shiny more craptastic than ever web interface as well as setting it's WAN port to 50Mbit/s

Re: Backdoor found in Linksys, Netgear Routers

#125
post #73

ScMM = SerComm, perhaps? Many of Linksys' old DSL modems were manufactured by them, AFAIK.. and it seems many of the noted 'probably affected' models have a SerComm manuf'ed device for at least one revision of that model line More probable SerComm manuf'ed devices are visible at the WD query link below.. http://wikidevi.com/w/index.php?title=Special%3AAsk&q=[[Manu...

No nothing about code ... I like research and the constitutional issues interest me. ScMM is also the NASDAQ symbol for Identive Group - working in secure ID for government and other institutions.

Re: Backdoor found in Linksys, Netgear Routers

#129

Does anyone have a recommendation for nice, configurable, reliable wireless router now a days? My Linksys E2000 is on the fritz and didn't last near as long as my old WRT54G.

I bought a buffalo router pre-loaded with dd-wrt on it that I like and gives you most of the options that the stock dd-wrt build does. Otherwise I just buy anything that is dd-wrt compatible and flash it.

Re: Backdoor found in Linksys, Netgear Routers

#130
post #62
post #45

"And the Chinese have probably known about this back door since 2008." http://www.microsofttranslator.com/bv.aspx?from=&to=en&a=htt... That's a pretty scary prospect. If its been 'known' and exploited since at least 2008. Poor form Netgear/Linksys.

Probably not Netgear or Linksys' choice. The Treasonous Act, aka, the Patriot Act has a black version that forces such companies to do as they're told and shut up about it.

If you have any citations for that, they'd be interesting reading.
Post reply on HN