Thoughts Media.com

 


Windows Phone Thoughts

Loading feed...

Digital Home Thoughts

Loading feed...

Apple Thoughts

Loading feed...




Go Back   Thoughts Media Forums > Thoughts Media Off Topic

Reply
 
Thread Tools Display Modes
  #1  
Old 06-08-2004, 07:50 PM
Jonathon Watkins
Swami
Join Date: Feb 2004
Posts: 4,303
Default Linksys Patch Available

url=http://www.theinquirer.net/?article=16416

Ed posted last week that Linksys Routers were open to vulnerability when subject to a buffer overflow attack. The Inquirer has just put up a story about the patches being available. There's more than just a fix for the BOOTP issue and the full list of fixes is shown below:

  • Fixed CGI string attacks issue
    Fixed UPnP on Windows XP SP2 issue
    Fixed One way audio issue
    Fixed NAT-T issue for some VPN connection
    Fixed DHCP server revision, fill the siaddr to the server address
    Fixed DHCP (BOOTP) vulnerability issue
    Added Filter IDENT(port 113) to appear stealth when scanned
    Added DHCP option 55 support
    Fixed buffer leakage bug
    Modified TCP Support RFC 3360 standard
    Modified PPPoE/L2TP/PPTP fragmentation supports fragmenting 1 packet into more than 3.
    Modified MTU/MRU function for better handling

Firmware upgrades for the following devices: BEFSR11, BEFSR41, BEFSR81, BEFSRU31, BEFW11S4 (except Version 1), can be found here. Still, better late than never eh! :wink:
 
Reply With Quote
  #2  
Old 06-08-2004, 08:00 PM
GoldKey
Pontificator
Join Date: Jul 2003
Posts: 1,264

Interestingly, according to this slashdot story - http://slashdot.org/articles/04/06/0...id=126&tid=172 the backdoor password was not removed, just changed, and the new one is already out.
 
Reply With Quote
  #3  
Old 06-08-2004, 08:02 PM
Jonathon Watkins
Swami
Join Date: Feb 2004
Posts: 4,303

:roll: It never ends? :?
 
Reply With Quote
  #4  
Old 06-08-2004, 08:22 PM
psyfactor
Pupil
Join Date: Aug 2005
Posts: 26

Slashdot thread is about a security hole in NetGear router not Linksys
 
Reply With Quote
  #5  
Old 06-08-2004, 08:41 PM
GoldKey
Pontificator
Join Date: Jul 2003
Posts: 1,264

Quote:
Originally Posted by PsyFactor
Slashdot thread is about a security hole in NetGear router not Linksys
Sorry, that will teach me to link back to something I read earlier today without double checking the article. It is still funny though.
 
Reply With Quote
  #6  
Old 06-08-2004, 09:02 PM
brianchris
Philosopher
brianchris's Avatar
Join Date: Sep 2006
Posts: 533

We can't all celebrate yet. A number of Linksys Routers were implicated in the original article (http://www.theinquirer.net/?article=16298), yet the only router to have a firmware upgrade so far that addresses the issue is the BEFSR41.

Granted the BEFSR41 is extremely popular and widley adopted, but the fact remains many other Linksys routers are apparently affected and are still waiting to be patched.
 
Reply With Quote
  #7  
Old 06-08-2004, 09:59 PM
Jason Dunn
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 29,160

Makes me happy that I have a now-discontinued and obscure MN-700 router from that little Microsoft company. :lol:
__________________
Want to contact me personally? Use this. Want to read my personal blog? Check it out. Want to follow me on Twitter? Here you go.
 
Reply With Quote
  #8  
Old 06-08-2004, 10:17 PM
Brian Johnson
Pupil
Join Date: Jun 2002
Posts: 22

The link below takes you to Linksys Knowledgebase that links to firmware upgrades for BEFSR11, BEFSR41, BEFSR81, BEFSRU31, BEFW11S4(except Version 1)

Jonathon: your front page post should reflect these devices in the link also, not just the BEFSR41.

http://linksys.custhelp.com/cgi-bin/...user/entry.php
 
Reply With Quote
  #9  
Old 06-08-2004, 10:57 PM
Jonathon Watkins
Swami
Join Date: Feb 2004
Posts: 4,303

Thanks for that Brian - a good point. I have updated the post with this info. Cheers.
 
Reply With Quote
  #10  
Old 06-08-2004, 10:57 PM
Jonathon Watkins
Swami
Join Date: Feb 2004
Posts: 4,303

Quote:
Originally Posted by Jason Dunn
Makes me happy that I have a now-discontinued and obscure MN-700 router from that little Microsoft company. :lol:
A silver lining to every cloud eh Jason? :wink:
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 09:05 PM.


Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2019, vBulletin Solutions, Inc.
Copyright Thoughts Media Inc. 2009