Thoughts Media.com

 




  #1 (permalink)  
Old 06-08-2004, 07:50 PM
Swami
Join Date: Feb 2004
Posts: 4,371
Default Linksys Patch Available

url=http://www.theinquirer.net/?article=16416

Ed posted last week that Linksys Routers were open to vulnerability when subject to a buffer overflow attack. The Inquirer has just put up a story about the patches being available. There's more than just a fix for the BOOTP issue and the full list of fixes is shown below:

  • Fixed CGI string attacks issue
    Fixed UPnP on Windows XP SP2 issue
    Fixed One way audio issue
    Fixed NAT-T issue for some VPN connection
    Fixed DHCP server revision, fill the siaddr to the server address
    Fixed DHCP (BOOTP) vulnerability issue
    Added Filter IDENT(port 113) to appear stealth when scanned
    Added DHCP option 55 support
    Fixed buffer leakage bug
    Modified TCP Support RFC 3360 standard
    Modified PPPoE/L2TP/PPTP fragmentation supports fragmenting 1 packet into more than 3.
    Modified MTU/MRU function for better handling

Firmware upgrades for the following devices: BEFSR11, BEFSR41, BEFSR81, BEFSRU31, BEFW11S4 (except Version 1), can be found here. Still, better late than never eh! :wink:
 
Reply With Quote
  #2 (permalink)  
Old 06-08-2004, 08:00 PM
Pontificator
Join Date: Jul 2003
Posts: 1,329

Interestingly, according to this slashdot story - http://slashdot.org/articles/04/06/0...id=126&tid=172 the backdoor password was not removed, just changed, and the new one is already out.
 
Reply With Quote
  #3 (permalink)  
Old 06-08-2004, 08:02 PM
Swami
Join Date: Feb 2004
Posts: 4,371

:roll: It never ends? :?
 
Reply With Quote
  #4 (permalink)  
Old 06-08-2004, 08:22 PM
Pupil
Join Date: Aug 2005
Posts: 30

Slashdot thread is about a security hole in NetGear router not Linksys
 
Reply With Quote
  #5 (permalink)  
Old 06-08-2004, 08:41 PM
Pontificator
Join Date: Jul 2003
Posts: 1,329

Quote:
Originally Posted by PsyFactor
Slashdot thread is about a security hole in NetGear router not Linksys
Sorry, that will teach me to link back to something I read earlier today without double checking the article. It is still funny though.
 
Reply With Quote
  #6 (permalink)  
Old 06-08-2004, 09:02 PM
Philosopher
brianchris's Avatar
Join Date: Sep 2006
Posts: 510

We can't all celebrate yet. A number of Linksys Routers were implicated in the original article (http://www.theinquirer.net/?article=16298), yet the only router to have a firmware upgrade so far that addresses the issue is the BEFSR41.

Granted the BEFSR41 is extremely popular and widley adopted, but the fact remains many other Linksys routers are apparently affected and are still waiting to be patched.
 
Reply With Quote
  #7 (permalink)  
Old 06-08-2004, 09:59 PM
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 23,595

Makes me happy that I have a now-discontinued and obscure MN-700 router from that little Microsoft company. :lol:
__________________
Thanks for visiting our forums!
 
Reply With Quote
  #8 (permalink)  
Old 06-08-2004, 10:17 PM
Pupil
Join Date: Jun 2002
Posts: 48

The link below takes you to Linksys Knowledgebase that links to firmware upgrades for BEFSR11, BEFSR41, BEFSR81, BEFSRU31, BEFW11S4(except Version 1)

Jonathon: your front page post should reflect these devices in the link also, not just the BEFSR41.

http://linksys.custhelp.com/cgi-bin/...user/entry.php
 
Reply With Quote
  #9 (permalink)  
Old 06-08-2004, 10:57 PM
Swami
Join Date: Feb 2004
Posts: 4,371

Thanks for that Brian - a good point. I have updated the post with this info. Cheers.
 
Reply With Quote
  #10 (permalink)  
Old 06-08-2004, 10:57 PM
Swami
Join Date: Feb 2004
Posts: 4,371

Quote:
Originally Posted by Jason Dunn
Makes me happy that I have a now-discontinued and obscure MN-700 router from that little Microsoft company. :lol:
A silver lining to every cloud eh Jason? :wink:
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 12:02 AM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC7
Copyright Thoughts Media Inc. 2007