<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Ouch!  Security problem in linksys routers in Wireless Security</title>
<link>http://www.dslreports.com/forum/r14141344</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 17:09:35 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 17:09:35 EDT</lastBuildDate>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14259591</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : <div class="bquote"><SMALL>said by  Yoofer <A HREF="/useremail/u/118802"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>So am I correct that the consensus is this is an issue related to old settings not being purged after a firmware update?</DIV>Yes, you are correct.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14259591</guid>
<pubDate>Wed, 31 Aug 2005 06:46:33 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14257053</link>
<description><![CDATA[<A HREF="/useremail/u/118802"><b>Yoofer</b></A> : Quick update to my settings:  just switched to WPA-AES.<br><SMALL>--<br>Ken S.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14257053</guid>
<pubDate>Tue, 30 Aug 2005 21:23:19 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14256920</link>
<description><![CDATA[<A HREF="/useremail/u/118802"><b>Yoofer</b></A> : Okay, I'm not new to networking, but extremely new to wireless (under 1 week with the Linky WRT54G, firmware 3.03.6).  So am I correct that the consensus is this is an issue related to old settings not being purged after a firmware update?  Has anyone been able to confirm this behavior in the G?  Or only the GS?  Am I okay with my currently installed firmware?  How does MAC filtering figure in?  Mine is currently set to permit only, with just the MAC of my notebook's built-in wireless adapter entered.  Sorry for all the questions, still learning...<br><br>Some (relevant?) settings:<br>SSID broadcast disabled<br>Firewall enabled<br>WPA-TKIP enabled<br>MAC filtering (permit only) enabled<br><br>I have a friend coming over to the house in a couple of days - I'll have him bring his wireless notebook (it's never seen my router) and see if he can connect.  I'll post back with the results...<br><SMALL>--<br>Ken S.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14256920</guid>
<pubDate>Tue, 30 Aug 2005 21:09:50 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14164154</link>
<description><![CDATA[<A HREF="/useremail/u/894458"><b>Glen T</b></A> : Well here are the results of my test:<br><br>1. I saved a config file from firmware v3.03.6 on my WRT54G v1.1 router.<br>2. I used the HTML interface to apply the firmware update to v4.20.6.<br>3. Tried logging on from my laptop using a Linksys WUSB11 v2.6 adapter on my neighbour's laptop (which has seen my secure connection in the past). I could not log on. However, he is running WinXP without SP2, so it saw my connection as WEP (not WPA).<br>4. I brought his WUSB11 v2.6 connector to my laptop, installed it, and set it up. It identified my connection as secure, but I could not log on.<br>5. My other wireless PC which was on and connected throughout the upgrade, remained connected.<br>6. I did a factory reset on the WRT54G. All settings including password for log on were purged.<br>7. I successfully logged onto the newly unsecured connection from my laptop.<br>8. I then applied the saved config file made from firmware v3.03.6. My settings appear to be completely restored with no problems. The router never complained or warned in any way about the different version of the config file.<br><br>Conclusions:<br><br>1. This was not a clean test for reproducing the problems with unsecured logon following the firmware upgrade. I didn't have access to a clean client that had not previously seen my router. However, the router did end up in a state where I could not log on from my laptop prior to do a factory reset.<br><br>2. My test showed that it is at least feasible to save your config to file prior to upgrading the firmware, and then restoring your settings after a factory reset. On the WRT54G, this could be a recommended work around. Linksys support confirmed this (for what that's worth).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14164154</guid>
<pubDate>Thu, 18 Aug 2005 15:12:50 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14162414</link>
<description><![CDATA[<A HREF="/useremail/u/894458"><b>Glen T</b></A> : Here is the question that I asked Linksys support:<br><br><BLOCKQUOTE><B>Thanks for your reply. I just want to confirm your answer: <br><br>I can use the Config Managment tool to restore a previously saved config file, saved before I did a firmware upgrade. In other words, the following: <br>1. My router is using firmware version X. I create a back up config file from version X.<br>2. I upgrade my router to firmware Y.<br>3. I do a factory reset following the firmware upgrade.<br>4. I do a restore of my config file to restore my settings.<br>This will work?</B></BLOCKQUOTE><br><br>Here is the response:<br><br><BLOCKQUOTE><B>Yes. It is the configuration or the settings that you need to save and not the firmware. Create a back up first then restore it after.</B></BLOCKQUOTE><br><br>I have not had time to try this yet, but I plan to do the entire procedure on my WRT54G -- hopefully today. After all, who wouldn't want to miss the opportunity of turning their router into a doorstop?<br><br>I'll post my findings when I'm done. Please allow time for me to run to the store and by a new WRX router! <br><br>My objective is to establish whether or not I can reproduce the reported conditions, and whether or not you can restore a saved config file after an upgrade of firmware. This would at least provide a decent workaround.<br><br>Note that I am using an access restriction table on router which limits access to the Internet for several computers based on their MAC numbers and time of day. Should be interesting to see if that survives the restore, along with other settings.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14162414</guid>
<pubDate>Thu, 18 Aug 2005 11:41:03 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14155597</link>
<description><![CDATA[<A HREF="/useremail/u/894458"><b>Glen T</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>It gives me something to do until school starts again :p<br><br> Greg_Z <A HREF="/useremail/u/447260"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, I'm also interested in seeing which other WRT's this applies to.  If I had another WRT54G, or WRT54GS, I'd test it out :(.<br> </DIV>I'm still waiting for he definitive response from Linksys support regarding the feasibility of using the save/restore settings after a a firmware upgrade/reset. <br><br>If I get the green light from Linksys, I'd like to try the whole process along with restoring from a saved conf file on my WRT54G v1.1. I'll be upgrading the firmware from v3.03.6 to v4.20.6. I don't have a 'virgin' client, though, so I'd have to wipe one to give this a try. I may also be able to grab my nextdoor neighbour's laptop.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14155597</guid>
<pubDate>Wed, 17 Aug 2005 15:07:09 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14154999</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : It gives me something to do until school starts again :p<br><br> Greg_Z <A HREF="/useremail/u/447260"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, I'm also interested in seeing which other WRT's this applies to.  If I had another WRT54G, or WRT54GS, I'd test it out :(.<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14154999</guid>
<pubDate>Wed, 17 Aug 2005 13:58:29 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14154632</link>
<description><![CDATA[<A HREF="/useremail/u/447260"><b>Greg_Z</b></A> : Definitely he is doing something that is going to help everyone out in the long run. I am wondering how far into the WRT line this problem goes..<br><SMALL>--<br>One man's customer loyalty is another man's misguided arrogance.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14154632</guid>
<pubDate>Wed, 17 Aug 2005 13:14:43 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14152419</link>
<description><![CDATA[<A HREF="/useremail/u/633186"><b>jebz</b></A> : <div class="bquote"><SMALL>said by  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>With WPA Personal/TKIP authentication enabled, the unit allows both clients using encryption with the correct settings and key, and clients not using any encryption.<br> </DIV>This happened to me on my WRT54G v2.2 when upgrading from 4.00.7 to 4.20.6 . <br><br>I checked all my security settings and they were in place after the upgrade and the wireless network was operating well. I tried to connect a second laptop but it developed a wireless hardware fault. I substituted another card and it reported the wireless network was insecure. This was quite a surprise. This was confirmed by Netstumbler.<br><br>I looked at the security settings again and found the latest version of the firmware has a button icon with a lock in it in the Wireless/Basic Wireless Settings. The button showed an open lock. I clicked on the lock and all hell broke loose. It changed all my security settings. I then re-entered my security settings to restore operation. The network then indicated secure on the clients and all operations continued as per the old firmware version.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14152419</guid>
<pubDate>Wed, 17 Aug 2005 06:54:13 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14151649</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : Isn't  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> the best for putting in the time on this one? <br><br>Great job!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14151649</guid>
<pubDate>Wed, 17 Aug 2005 01:12:07 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14150964</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : I was able to produce this problem on both Linksys 4.50.6 and DD-WRT v22.<br><br>I'm not sure which Linksys version DD-WRT v22 is based on.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14150964</guid>
<pubDate>Tue, 16 Aug 2005 23:22:07 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14150451</link>
<description><![CDATA[<A HREF="/useremail/u/772729"><b>Nerdtalker</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>&#8226;Flash from Linksys 4.50.6 to DD-WRT.</LI><br>&#8226;I looked in the web GUI after the flash and the WPA settings from my previous Linksys firmware were still in there.</LI><br>&#8226;I set my wireless card to "Disabled" for security settings</LI><br><br>I was able to connect right up (see attached image).<br><br>I'm guessing that even though the WRT54GS web config is reporting WPA is enabled, it's not really enabled.<br> </DIV>Wow, interesting vulnerability.<br><br>Are 3rd party firmware distros built on the 4.50.6 linux-GPL code also affected?<br><SMALL>--<br>"Some people never see the light till it shines thru bullet holes." -Bruce Cockburn<BR><BR>I'm testing Gmail's spam filters: Broadbandreports1@gmail.com<BR><B>Spam: 8800+</B> messages currently using 268 MB (11%) of my 2442 MB</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14150451</guid>
<pubDate>Tue, 16 Aug 2005 22:19:37 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14148315</link>
<description><![CDATA[<A HREF="/useremail/u/447260"><b>Greg_Z</b></A> : If you are just changing the Wifi A/P MAC, are you changing the MAC on the NIC at the time of reboot.  MAC address scheming can work both ways, and if the A/P is still associating the MAC of the NIC at the time of reboot, then you may still have problems.<br><br>The problem lies that the A/P still remembers the MAC of the NIC at the time of the reboot along with the Key that it has to send to confirm the key on the A/P and the MAC of the A/P.  Unless the IPTables is being flushed at the time of reboot, everything stays in the memory of the A/P.<br><br>There is going to defiantly be a good White paper out of this.<br><SMALL>--<br>One man's customer loyalty is another man's misguided arrogance.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14148315</guid>
<pubDate>Tue, 16 Aug 2005 17:38:00 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14148214</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : Still letting me on after a reboot, SSID change, wireless MAC change.<br><br>See picture.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14148214?c=876331&ret=L2ZvcnVtL3IxNDE0MTM0NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="73772 bytes" WIDTH=600 HEIGHT=311 SRC="/r0/download/876331.thumb600~f44407f7717911f4b9f191db04c5269b/new.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14148214</guid>
<pubDate>Tue, 16 Aug 2005 17:25:59 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147917</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>I should have been more specific; I cloned the wireless APs MAC address, not the wireless card.  That should make a difference, right? </DIV>It will only make a difference one way.<br><br>WPA authenticates both sides:  STA auth's the AP, AP auth's the STA<br><br>If I were you, I'd repeat your previous steps, but power-cycle the router and reboot the laptop after that point I mentioned above.  That way any prior auths or lockouts are forgotten.<br><SMALL>--<br>Robb Topolski ;) <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> :D Hillsboro, Oregon USA<BR><I>Dear Anonymous, Thank you!!! Thank you!!!</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147917</guid>
<pubDate>Tue, 16 Aug 2005 16:44:11 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147884</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : I should have been more specific; I cloned the wireless APs MAC address, not the wireless card.  That should make a difference, right?<br><br>I can try it with my Linux laptop and see what happens.<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147884</guid>
<pubDate>Tue, 16 Aug 2005 16:39:13 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147669</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>&#8226;I set my wireless card to "Disabled" for security settings</LI> </DIV>"Greg Z" mentioned this above -- <div class="bquote">Just changing the SSID and Wireless NIC MAC address will not do it. The machine that is being used still remembers the MAC address of the device that you are connecting to. </DIV>...and I just want to back him up on this fact...<br><br>If you started with an EAP protocol, then switched the card to disabled, the EAPOL authenitcation service continues to run -- perhaps stupidly, but it does.<br><br>And as long as that MAC address is out there, it will enforce its last instructions.<br><br>I agree -- we need to test this with a reboot after the above step mentioned in &raquo;<A HREF="/forum/remark,14142758">Re: Ouch!  Security problem in linksys routers</A><br><SMALL>--<br>Robb Topolski ;) <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> :D Hillsboro, Oregon USA<BR><I>Dear Anonymous, Thank you!!! Thank you!!!</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147669</guid>
<pubDate>Tue, 16 Aug 2005 16:09:47 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147526</link>
<description><![CDATA[<A HREF="/useremail/u/596526"><b>justageek</b></A> : Ask SW Bill and you shall receive<br><br>I can't recreate the issue on the G... <br>using 4.00.7 = No issue<br>using 4.20.6 = No issue<br><br>Dare I speculate that this bug is confined to the GS routers or am I just not testing things right??<br><br>Equipment Tested<br>1 Dell C600 <br>1 Linksys WPC54G version 2 with no firmware updates and standard Linksys drivers<br>1 Linksys WRT54G version 3<br><br>1.) Flashy Flashy to 4.20.6<br>2.) Run Netstumbler<br>3.) Found other networks, mine was "missing".<br>4.) Flashy Flashy to 4.00.7<br>5>) See step 2<br>6.) See step 3<br>7.) Flashy Flashy to 4.20.6<br>8.) Router cranky at first, but works fine now.<br><br>Laptop is a unit that I took out of work and has never been wireless.  <br>XP installed on it from ground zero (No slipstreamed SP2)<br>After I got all the fun fun stuff on it (at the office), I popped in the NIC and gave it the drivers.<br><br>Maybe I have a sooper router???]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147526</guid>
<pubDate>Tue, 16 Aug 2005 15:50:48 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147518</link>
<description><![CDATA[<A HREF="/useremail/u/447260"><b>Greg_Z</b></A> : Just changing the SSID and Wireless NIC MAC address will not do it.  The machine that is being used still remembers the MAC address of the device that you are connecting to.  You really have to use something like Knoppix or another machine in order to see if there is a vulnerbility out there.<br><SMALL>--<br>One man's customer loyalty is another man's misguided arrogance.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147518</guid>
<pubDate>Tue, 16 Aug 2005 15:49:40 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147472</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : I only have one machine with wireless.<br><br>I changed the SSID and wireless MAC address on the router prior to connect to it with my laptop, so that <I>should</I> make it like the computer has never seen it before, hopefully.<br><br>If anyone else has a WRT54GSv1, or even a regular WRT54G, I'd be interested in seeing what results you get.<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147472</guid>
<pubDate>Tue, 16 Aug 2005 15:42:55 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147412</link>
<description><![CDATA[<A HREF="/useremail/u/447260"><b>Greg_Z</b></A> : What gets me is that you are reproducing the error on a machine that has already been connected to the router that is supposedly connected prior to the upgrade.<br><br>In order to do a real world test, you have to use a machine that has never been connected via wifi to the router in order to see if there is a true claim in this possible security hole.<br><SMALL>--<br>One man's customer loyalty is another man's misguided arrogance.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147412</guid>
<pubDate>Tue, 16 Aug 2005 15:33:33 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14147046</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : Thanks  Glen T <A HREF="/useremail/u/894458"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :)<br><br>Hopefully we'll get an answer in this thread, or via your email.  At the least, Linksys has been notified of this problem and hopefully will fix it :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14147046</guid>
<pubDate>Tue, 16 Aug 2005 14:47:39 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14146789</link>
<description><![CDATA[<A HREF="/useremail/u/894458"><b>Glen T</b></A> : I just had a 'live' chat with Linksys support, which wasn't very helpful. He sort-of confirmed that you might want to do a factory reset after flashing a new firmware version. He had no knowledge of what the configuation management tools were used for.<br><br>I've e-mailed my question to Linksys support, including a link to this topic. We'll see what they come back with. I've asked for a definitive statement on when you would use the Configuration Managment save/restore.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14146789</guid>
<pubDate>Tue, 16 Aug 2005 14:14:21 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14146510</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : With the D-Link DI-5xx/6xx/7xx routers, and the Netgear WGT/WGU-624, you generally cannot apply settings saved from a previous version to an upgraded version.<br><br>We have found a few exceptions to this rule, but we've also found that a higher rate of success is obtained my hand-entering these settings over restoring them from a file -- even under the same firmware version!<br><SMALL>--<br>Robb Topolski ;) <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> :D Hillsboro, Oregon USA<BR><I>Dear Anonymous, Thank you!!! Thank you!!!</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14146510</guid>
<pubDate>Tue, 16 Aug 2005 13:41:12 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14146476</link>
<description><![CDATA[<A HREF="/useremail/u/894458"><b>Glen T</b></A> : I'm going to look into this a bit more -- will check with Linksys support. You would think that Save/Restore would be meant for exactly this kind of scenario. Also, it does not necessarily follow that restoring a saved firmware set is the same as flashing over top of an existing set without resetting.<br><br>I'll see what I can find out.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14146476</guid>
<pubDate>Tue, 16 Aug 2005 13:37:39 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14146403</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : Mine does have a "Backup" option, but I do not know if the settings can be transferred between different firmware versions.  <br><br>It warns me about using it on different firmwares/models.<br><br>I'm not willing to test out "Restore" from a different firmware version because there is a possibility it could turn my router into a paperweight.<br><br>Also, I do not know if the "backup" from a previous firmware would do any good.  If you upgrade the firmware, without a reset, wouldn't that essentially be doing the same thing as flashing, resetting, then using the backup file?  We've already found out settings aren't successfully transferred from one to the other, so it seems like it would be the same.<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14146403</guid>
<pubDate>Tue, 16 Aug 2005 13:28:58 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14146285</link>
<description><![CDATA[<A HREF="/useremail/u/894458"><b>Glen T</b></A> : Does this router not have the admin function to save/restore a configuration file, like the WRT54G has?<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14146285?c=876196&ret=L2ZvcnVtL3IxNDE0MTM0NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="44467 bytes" WIDTH=600 HEIGHT=389 SRC="/r0/download/876196.thumb600~e368d99f0b7cd3cbb143949cce5a6574/wrt54g.png/thumb.jpg" ALT="Click for full size"></A><br>WRT54G config save/restore</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14146285</guid>
<pubDate>Tue, 16 Aug 2005 13:10:07 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14145667</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : I used the "Factory Defaults" option in the firmware upgrade menu (see attached image).<br><br>I prefer not to do a hard-reset.  The only time I'll do a hard-reset (use the reset button) is if I can't get into the web config.<br><br>There's also a stand-alone "Factory Defaults" option inside most of the Linksys firmwares, which will allow you to restore all settings to "Factory Defaults", without upgrading your firmware.<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14145667?c=876157&ret=L2ZvcnVtL3IxNDE0MTM0NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="9011 bytes" WIDTH=600 HEIGHT=214 SRC="/r0/download/876157.thumb600~a197e77e392cfc8c75c8d264568c4f7a/untitled.bmp/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14145667</guid>
<pubDate>Tue, 16 Aug 2005 11:44:46 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14145603</link>
<description><![CDATA[<A HREF="/useremail/u/818279"><b>WALL_E</b></A> : When you say that it is necessary to restore factory defaults after upgrading the firmware, does that mean restoring defaults by pressing and holding the recessed button on the back of the router, or by restoring defaults through the router's web interface, or does that not make a difference?  I have always restored the router by pressing and holding the button until the power light began to flash.<br><br>Thanks in advance.<br><br>I also believe that this is a pretty good bug, but as Linksys does highly recommend resetting after a firmware upgrade, it is not as big of an issue as I had originally thought.  Perhaps in the future, Linksys can have their upgrade utility display a warning box after the firmware upgrade completes, which urges the user to reset the router, with several scolding warning messages if the user decides not to.  Or they could even make the upgrade utility reset the router without asking after a firmware upgrade.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14145603</guid>
<pubDate>Tue, 16 Aug 2005 11:36:46 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14144905</link>
<description><![CDATA[<A HREF="/useremail/u/136163"><b>avantare</b></A> : I just purchased a WRT54G from CompUSA hw is v4 and the first thing I did was check the firmware. It's the latest.<br><br>Chuck<br><SMALL>--<br>A computer is not a tool. When was the last time you had to do maintenance on your screwdriver?</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14144905</guid>
<pubDate>Tue, 16 Aug 2005 09:42:38 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14144622</link>
<description><![CDATA[<A HREF="/useremail/u/651054"><b>kpr92400</b></A> : <div class="bquote">This is a good bug.  Although it is security related, it's not likely going to be exploited.</DIV>Not likely that it's going to be exploited?!?  Unless this particular firmware upgrade scenario is unlikely, it's going to happen, and it's going to get wardriven and exploited someday.<br><br>n.b. I just bought a WRT54G from newegg, and while it was hardware v4, it had some pretty ancient firmware on it...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14144622</guid>
<pubDate>Tue, 16 Aug 2005 08:48:45 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14143878</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>It's definitely a problem, but I'm not sure if it can be addressed and fixed by Linksys or the third-party providers.<br><br>Obviously, people don't want to "Restore to Factory Defaults" because they'll loose their settings and have to re-enter them, but it may have to be done to prevent this security problem.<br> </DIV>Yes, but OTOH, there's no guarantee that one firmware version is going to use the same keywords or values as the other.  <br><br>Something like that is probably what's happening here.  Between version x and y, something got flipped or skipped.<br><br>This is a good bug.  Although it is security related, it's not likely going to be exploited.<br><SMALL>--<br>Robb Topolski ;) <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> :D Hillsboro, Oregon USA<BR><I>Dear Anonymous, Thank you!!! Thank you!!!</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14143878</guid>
<pubDate>Tue, 16 Aug 2005 02:18:34 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14143781</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : It's definitely a problem, but I'm not sure if it can be addressed and fixed by Linksys or the third-party providers.<br><br>Obviously, people don't want to "Restore to Factory Defaults" because they'll loose their settings and have to re-enter them, but it may have to be done to prevent this security problem.<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14143781</guid>
<pubDate>Tue, 16 Aug 2005 01:49:48 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14143639</link>
<description><![CDATA[<A HREF="/useremail/u/318634"><b>dad123</b></A> : I always wondered if you restore factory defaults can you reapply your previously saved configuration file and not mess up the settings ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14143639</guid>
<pubDate>Tue, 16 Aug 2005 01:14:08 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14143325</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Thanks to the people who have been testing this, particularly  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and  scherf <A HREF="/useremail/u/1248656"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.<br><br>Even if this is a configuration/update issue, I see it as still a problem.  But it isn't as serious a problem as it might have been.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14143325</guid>
<pubDate>Tue, 16 Aug 2005 00:18:59 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14143265</link>
<description><![CDATA[<A HREF="/useremail/u/1248656"><b>scherf</b></A> : Good job reproducing this! I guess it actually is an issue with updating. I don't agree about WPA actually being disabled, though, because password validation is functioning. If your password is wrong, you can't connect. Also, my computer reports that it is connected with WPA. The bug is that WPA is "optional". :)<BR><br>As for whether it is expected for this unit to keep config after updating, I'm not sure what the vendor advertises. But the unit does seem to keep config and report it exactly as it was before the update. But apparently what it reports doesn't necessarily match what's going on inside.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14143265</guid>
<pubDate>Tue, 16 Aug 2005 00:08:55 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14143054</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : Anyone else out there with a WRT54GSv1 able to get the same results as me?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14143054</guid>
<pubDate>Mon, 15 Aug 2005 23:30:32 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142941</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : I don't know much about the internal workings of this router, but I do know they act weird when they aren't "Restoring" after updates.  I am not sure why the web config is reporting inaccurate data.<br><br>As an update, I got the same results when flashing from DD-WRT to Linksys 4.50.6, without "Restoring".  When I did the flash, with "Restoring", everything worked fine (no WPA problem).<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142941</guid>
<pubDate>Mon, 15 Aug 2005 23:09:40 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142913</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : Is it expected that this router would retain its memory across firmware updates?  <br><br> -- Robb (not a Linksys router user)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142913</guid>
<pubDate>Mon, 15 Aug 2005 23:06:19 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142758</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : Ok, I was able to recreate this problem.  Here's what I did:<br><br>&#8226;Flash from Linksys 4.50.6 to DD-WRT.</LI><br>&#8226;I looked in the web GUI after the flash and the WPA settings from my previous Linksys firmware were still in there.</LI><br>&#8226;I set my wireless card to "Disabled" for security settings</LI><br><br>I was able to connect right up (see attached image).<br><br>I'm guessing that even though the WRT54GS web config is reporting WPA is enabled, it's not really enabled.<br><br>One more reason to be sure to "Restore Factory Defaults" after firmware upgrades :D<br><br>Edit: Fixed picture<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14142758?c=875912&ret=L2ZvcnVtL3IxNDE0MTM0NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="101981 bytes" WIDTH=600 HEIGHT=287 SRC="/r0/download/875912.thumb600~63f52a6bdc5c7293e1ad65c0360c4d15/untitled.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142758</guid>
<pubDate>Mon, 15 Aug 2005 22:48:10 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142722</link>
<description><![CDATA[<A HREF="/useremail/u/421043"><b>Kabanos</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>...Maybe I'm doing something wrong?<br> </DIV>Do not use the newest Firmware Version: <B>4.70.6</B>; try it with the old one (Firmware Version: 4.50.6)<br><SMALL>--<br><I>non nova, sed nove</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142722</guid>
<pubDate>Mon, 15 Aug 2005 22:42:32 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142701</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : When you upgraded the firmware from the previous version, did you "Restore Factory Defaults" after the upgrade? <br><br>If you didn't it is possible it was in a "weird state".  <br><br>I upgraded a few months ago from Alchemy to DD-WRT and since I didn't "Restore Factory Defaults" some settings would not take and I was getting random errors in the web GUI.  It's like random garbage was stored in memory instead of the values I tried setting.<br><br>I will try flashing to DD-WRT, then back to Linksys, without restoring defaults and see what happens.<br><br>Thanks<br>Bill.<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142701</guid>
<pubDate>Mon, 15 Aug 2005 22:39:54 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142662</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hi, I'm the original poster to Bugtraq. I wouldn't be surprised if this was a hard one to reproduce. To recount what I did in the hopes that someone else will be able to make it happen: I set the AP to use WPA personal/TKIP with a very long and random password (generated with /dev/random). At the time I was using an older firmware, perhaps a year old. I don't recall what version. I was not getting great reception, so I installed two aftermarket directional antennas. Not a lot of improvement, but not surprising given that there are something like 10 networks in my neighborhood. So I upgraded the firmware in the hope that perhaps they improved some of the connectivity issues. I upgraded through the usual web browser interface without changing any settings before or after. It all seemed to work fine, and I ran with it for a month until a friend noted that my network seemed to be open. His Win XP box showed my net as open, and he connected without a password. I cranked up Macstumbler, and it showed the network as open as well, even though my 4 Macs are configured to use TKIP and were working just fine that way. The Linksys AP was definitely configured to use TKIP, no question, but the network still showed up as open in the scans I ran. The original post tells the rest of the details. I wonder if the firmware update process put the unit into a weird state or something?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142662</guid>
<pubDate>Mon, 15 Aug 2005 22:35:42 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142609</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : My read of the test cases are this:<br><br>&#8226;Router configured for WPA-PSK TKIP<br>&#8226;Client profile configured for same SSID, no encryption<br>REPORTED RESULT: Access granted<br>EXPECTED: Access denied<br><br>&#8226;Router configured for WPA-PSK TKIP<br>&#8226;Client not configured with a profile<br>REPORTED RESULT: Router is listed in a site survey as an AP with no encryption enabled<br>EXPECTED:  Router is listed in a site survey with encryption<br>NOTE:  Macstumbler was used by the original observer<br><SMALL>--<br>Robb Topolski ;) <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> :D Hillsboro, Oregon USA<BR><I>Dear Anonymous, Thank you!!! Thank you!!!</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142609</guid>
<pubDate>Mon, 15 Aug 2005 22:27:41 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142536</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : I don't see it...<br><br>I tried setting up the wireless card with a blank WPA-PSK key.  I tried setting the wireless card with no security.<br><br>Nothing.<br><br>Maybe I'm doing something wrong?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142536</guid>
<pubDate>Mon, 15 Aug 2005 22:17:49 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142251</link>
<description><![CDATA[<A HREF="/useremail/u/421841"><b>seezar</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I gave it about 2 seconds of thought, then decided to do it :D<br><br>Downloading the Linksys stuff right now.  Will report back..<br> </DIV>{patiently sits by and awaits the results}]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142251</guid>
<pubDate>Mon, 15 Aug 2005 21:38:49 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142245</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : Just to clarify, Sw Bill, it seems from reading the bugtraq report that the fw is allowing a blank key in the supplicant.  A wrong key seems to be rejected.  <br><br>Suggest you take a look at the report.  The bugtraq poster also seemed to be confused as to what to expect from Auto mode.<br><SMALL>--<br>Robb Topolski ;) <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> :D Hillsboro, Oregon USA<BR><I>Dear Anonymous, Thank you!!! Thank you!!!</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142245</guid>
<pubDate>Mon, 15 Aug 2005 21:38:10 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142235</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : <div class="bquote"><SMALL>said by  funchords <A HREF="/useremail/u/340409"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br><div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Are you guys gonna make me flash the Linksys firmware onto my WRT54GS to test this? ;):p<br> </DIV>C'mon, you can't tell me you're not curious.  ;)<br> </DIV>I gave it about 2 seconds of thought, then decided to do it :D<br><br>Downloading the Linksys stuff right now.  Will report back..<br><SMALL>--<br><A HREF="http://www.bsnyder.net/folding">Folding Monitor</A><BR><A HREF="http://www.bsnyder.net/stats">Network Status</A><BR><A HREF="http://www.bsnyder.net/weather">Weather Stats</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142235</guid>
<pubDate>Mon, 15 Aug 2005 21:35:55 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142232</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : <div class="bquote"><SMALL>said by  Bill <A HREF="/useremail/u/535085"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Are you guys gonna make me flash the Linksys firmware onto my WRT54GS to test this? ;):p<br> </DIV>C'mon, you can't tell me you're not curious.  ;)<br><SMALL>--<br>Robb Topolski ;) <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> :D Hillsboro, Oregon USA<BR><I>Dear Anonymous, Thank you!!! Thank you!!!</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142232</guid>
<pubDate>Mon, 15 Aug 2005 21:35:20 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142221</link>
<description><![CDATA[<A HREF="/useremail/u/535085"><b>Bill</b></A> : Are you guys gonna make me flash the Linksys firmware onto my WRT54GS to test this? ;):p]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142221</guid>
<pubDate>Mon, 15 Aug 2005 21:34:25 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142127</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : &raquo;<A HREF="http://msgs.securepoint.com/cgi-bin/get/bugtraq0508/164.html" >msgs.securepoint.com/cgi-bin/get&middot;&middot;&middot;164.html</A><br><br>I'd sure like to see this verified by a second party before we spread any alarm.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142127</guid>
<pubDate>Mon, 15 Aug 2005 21:22:01 EDT</pubDate>
</item>

<item>
<title>Re: Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14142006</link>
<description><![CDATA[<A HREF="/useremail/u/660738"><b>Techless</b></A> : A link ???]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14142006</guid>
<pubDate>Mon, 15 Aug 2005 21:06:13 EDT</pubDate>
</item>

<item>
<title>Ouch!  Security problem in linksys routers</title>
<link>http://www.dslreports.com/forum/remark,14141344</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Quoting from a recent bugtraq message (from Steve Scherf):<br><br>Subject: Serious flaw in Linksys wireless AP password security<br><br>It appears that firmware version 4.50.6 for the Linksys WRT54GS (hardware version 1) wireless router allows wireless clients to connect and use the network without actually authenticating. With WPA Personal/TKIP authentication enabled, the unit allows both clients using encryption with the correct settings and key, and clients not using any encryption. It disallows clients attempting to use encryption with the wrong settings and/or key.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14141344</guid>
<pubDate>Mon, 15 Aug 2005 19:39:08 EDT</pubDate>
</item>

</channel>
</rss>
