 jandar
join:2006-01-16 Middleburg, FL | reply to Oligarchy Re: 2Wire Cross Site Request Forgery Vulnerability
2Wire 2701HG-B Software: 5.29.109.11
With a system password set, none of those exploits work. It always prompts me to enter my current pass.
Simple enough fix. |
|
 sasparilla
join:2008-04-09 Round Lake, IL
| said by jandar :2Wire 2701HG-B Software: 5.29.109.11 With a system password set, none of those exploits work. It always prompts me to enter my current pass. Simple enough fix. This sounds nice but 2Wire/AT&T must be rolling it out slowly - its apparantly only available to some people so far.
If I go to "View Available System Upgrades" on my AT&T/2Wire 2701HG-B, which has never been updated since it came from AT&T, it shows none available....Software version is 5.29.109.5. :-(
So, while a fix is supposedly out there, its apparantly not out there for everyone yet.  |
|
  left_out
@sbcglobal.net
| said by sasparilla :This sounds nice but 2Wire/AT&T must be rolling it out slowly - its apparantly only available to some people so far. AT&T claims they've already rolled it out to the majority of its customers. »tech.slashdot.org/tech/08/04/08/···14.shtml
None of this helps us poor HomePortal 1xxx users, since we can't use 5.xx firmwares. No update for us, it seems. My 1701HG remains very hackable. »AT&T claims this is fixed??? |
|
 koolkid1563 Premium,MVM join:2005-11-06 Powell, WY clubs:
·Bresnan Online
·AT&T U-Verse
edit: April 9th, @04:15PM
| reply to sasparilla Note that the fix may not be in the form of a firmware upgrade. AT&T first fixed this issue on the 3800 series with a UI Hotfix that got applied. The firmware upgrade included the hotfix in it's code so the hotfix was no longer needed.
It might take awhile, but at least they are trying. |
|
 sasparilla
join:2008-04-09 Round Lake, IL
edit: April 12th, @10:25AM
| reply to jandar said by jandar :2Wire 2701HG-B Software: 5.29.109.11 With a system password set, none of those exploits work. It always prompts me to enter my current pass. Hey Jandar, as an interested owner of another 2701GH-B that is susceptible to the exploits (got the 2701 from AT&T this week, v5.29.109.5), how did you get the updated firware?
As my 2701 is telling me no updates available when checking for firmware updates. And AT&T support site and 2Wire website do not have updates listed either.
Scott |
|