<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Dangerous remote Linksys 0-day root exploit discovered!&#x27; in forum &#x27;Linksys&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Dangerous-remote-Linksys-0day-root-exploit-discovered-27911193</link>
<description></description>
<language>en</language>
<pubDate>Tue, 21 May 2013 09:15:17 EDT</pubDate>
<lastBuildDate>Tue, 21 May 2013 09:15:17 EDT</lastBuildDate>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27965393</link>
<description><![CDATA[Bill_MI posted : DefenseCode finally released their findings.  It's related to the uPnP abomination (see &raquo;<A HREF="/forum/r27958088-Security-Flaws-in-Universal-Plug-n-Play-Unplug-Don-t-Play">Security Flaws in Universal Plug-n-Play: Unplug, Don't Play</A>) but specific to Broadcom devices.<br><br>&raquo;<A HREF="http://blog.defensecode.com/2013/01/broadcom-upnp-remote-preauth-root-code.html" >blog.defensecode.com/2013/01/bro&middot;&middot;&middot;ode.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27965393</guid>
<pubDate>Thu, 31 Jan 2013 12:49:08 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27942993</link>
<description><![CDATA[jbob posted : <div class="bquote"><said>said by <a href="/profile/510041" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=510041');">planet</a>:</said><p><div class="bquote"><said>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</said><p><div class="bquote"><said>said by <a href="/profile/996768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=996768');">jbob</a>:</said><p>Does anyone actually run the Linksys firmware on these routers?  I think many hear, at least they should, are running a third party firmware.<br> </p></div>I do. The problem is its complex instructions and easy to brick. I don't want to try it until I have a spare wireless router to use in case something goes wrong. ;)<br> </p></div>What antdude said:<br>&raquo;<A HREF="/forum/r26771591-Linksys-E1000-Is-it-bricked-">Linksys E1000: Is it bricked?</A><br><br>My E1000 is now a paperweight.<br> </p></div>To be clear my comment about not using the Linksys firmware was for the router in question.   The 54GL.  <br><br>I'm not sure what is so hard about flashing the GL series router.  It is so user friendly.  Flashing this thing couldn't get any easier.  Just pick DD-WRT or Tomato and flash away.  There are so many more options available via these two third party firmwares that it makes not using them foolish.  lol  But I also understand if one doesn't really want to.  If the stock firmware works what more can you ask for!   Oh another exploit!  ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27942993</guid>
<pubDate>Thu, 24 Jan 2013 12:10:56 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27942279</link>
<description><![CDATA[planet posted : <div class="bquote"><said>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</said><p><div class="bquote"><said>said by <a href="/profile/996768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=996768');">jbob</a>:</said><p>Does anyone actually run the Linksys firmware on these routers?  I think many hear, at least they should, are running a third party firmware.<br> </p></div>I do. The problem is its complex instructions and easy to brick. I don't want to try it until I have a spare wireless router to use in case something goes wrong. ;)<br> </p></div>What antdude said:<br>&raquo;<A HREF="/forum/r26771591-Linksys-E1000-Is-it-bricked-">Linksys E1000: Is it bricked?</A><br><br>My E1000 is now a paperweight.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27942279</guid>
<pubDate>Thu, 24 Jan 2013 08:26:08 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27937738</link>
<description><![CDATA[Bill_MI posted : <div class="bquote"><said>said by <a href="/profile/1030204" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1030204');">NetFixer</a>:</said><p>Of course, if the Linksys router(s) in question have a default backdoor password, that might not help.</p></div>Absolutely! :-)<br><br>I know it's a Linux environment but do I recall logging in can use a (BLANK) or any username?  Or do you have to sign in with user "root"?  I vaguely recall, like other Linksys routers, they may have hacked in that compatibility.  It's just that kind of change that can open a vulnerability if it's done wrong.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27937738</guid>
<pubDate>Tue, 22 Jan 2013 20:52:52 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27937188</link>
<description><![CDATA[NetFixer posted : <div class="bquote"><said>said by <a href="/profile/277471" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=277471');">Bill_MI</a>:</said><p>I'll do some speculation just to see how close I am...<br><br>Many of you may have noticed when you try to access your own public IP you get the router web page.  Still true?  My speculation is that this rule is made advantage of.  It's not your LAN IP it's a public IP (that happens to be your own) so it'll get by a lot of security fixes against local addressing.  Cross-Site Scripting (XSS) had exploits to access local LAN addresses but this Linksys quirk is sort of an invitation.<br><br>IF that's all it is... securing your password off default would be #1.  But everyone here should already know THAT, anyway. :-)<br> </p></div>Of course, if the Linksys router(s) in question have a default backdoor password, that might not help. My Netgear WNR1000v2-VC (running stock Netgear firmware) has such a hidden "root" password, and I take advantage of it when I occasionally need to look at something that the html admin pages don't show me by running a Netgear utility called "TelnetEnable". That utility does exactly what the POC seems to be doing, it opens up a Linux command line interface (with "root" privileges) to the router (and the "admin" password I have setup is irrelevant to this process). <br><small>--<br>A well-regulated militia, being necessary to the security of a free State, the right of the people to keep and bear arms shall not be infringed.<br><br>When governments fear people, there is liberty. When the people fear the government, there is tyranny.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27937188</guid>
<pubDate>Tue, 22 Jan 2013 17:58:22 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27936788</link>
<description><![CDATA[Bill_MI posted : I'll do some speculation just to see how close I am...<br><br>Many of you may have noticed when you try to access your own public IP you get the router web page.  Still true?  My speculation is that this rule is made advantage of.  It's not your LAN IP it's a public IP (that happens to be your own) so it'll get by a lot of security fixes against local addressing.  Cross-Site Scripting (XSS) had exploits to access local LAN addresses but this Linksys quirk is sort of an invitation.<br><br>IF that's all it is... securing your password off default would be #1.  But everyone here should already know THAT, anyway. :-)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27936788</guid>
<pubDate>Tue, 22 Jan 2013 16:02:25 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27936733</link>
<description><![CDATA[CylonRed posted : <div class="bquote"><said>said by <a href="/profile/996768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=996768');">jbob</a>:</said><p>Does anyone actually run the Linksys firmware on these routers?  I think many here, at least they should, are running a third party firmware.<br> </p></div>Yes - I do - thought about using 3rd party but the Linksys firmware works perfectly fine for me.<br><small>--<br>Brian<br><br>"It drops into your stomach like a Abrams's tank....  driven by Rosanne Barr..."  A. Bourdain</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27936733</guid>
<pubDate>Tue, 22 Jan 2013 15:46:13 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27936674</link>
<description><![CDATA[Bill_MI posted : Here's the source of all this:<br>&raquo;<A HREF="http://www.defensecode.com/article/upcoming_cisco_linksys_remote_preauth_root_exploit-33" >www.defensecode.com/article/upco&middot;&middot;&middot;ploit-33</A><br><br>You can try to read between the lines all day with speculation.  For example, XSS is the process of inserting code to run as trusted in web pages and the demo EXE may simply represent that code that could come from a webpage but run locally.  But public demos giving away much detail wouldn't be in their best interest, too.<br><br>DefenseCode does say they tested WRT54GL 4.30.14 which is earlier than the 4.30.16 which is dated the same day as the DefenseCode announcement.  Kinda strange. :-)<br><br>Conclusion: No way to know.  Just speculate.  We have 2 days before they say they will disclose.  At that time we'll learn much more.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27936674</guid>
<pubDate>Tue, 22 Jan 2013 15:32:47 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27935477</link>
<description><![CDATA[unknvoip posted : <div class="bquote"><said>said by <a href="/profile/996768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=996768');">jbob</a>:</said><p>Does anyone actually run the Linksys firmware on these routers?  I think many hear, at least they should, are running a third party firmware.<br> </p></div>Based on the number of times I see wireless ssid's of LYNKSYS, yes many people are running that firmware. A fair number of them have the default password  I am guessing. Most of those people don't read dslreports and don't know anything about 3rd party firmware.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27935477</guid>
<pubDate>Tue, 22 Jan 2013 10:20:38 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27935297</link>
<description><![CDATA[antdude posted : <div class="bquote"><said>said by <a href="/profile/996768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=996768');">jbob</a>:</said><p>Does anyone actually run the Linksys firmware on these routers?  I think many hear, at least they should, are running a third party firmware.<br> </p></div>I do. The problem is its complex instructions and easy to brick. I don't want to try it until I have a spare wireless router to use in case something goes wrong. ;)<br><small>--<br>Ant @ AQFL.net and AntFarm.ma.cx. Please do not IM/e-mail me for technical support. Use this forum or better, &raquo;<A HREF="http://community.norton.com" >community.norton.com</A> ! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27935297</guid>
<pubDate>Tue, 22 Jan 2013 09:31:35 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27935265</link>
<description><![CDATA[jbob posted : Does anyone actually run the Linksys firmware on these routers?  I think many here, at least they should, are running a third party firmware.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27935265</guid>
<pubDate>Tue, 22 Jan 2013 09:22:11 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27917502</link>
<description><![CDATA[hardly posted : Anyone know if this works properly on at WRT54G v4 ? (supposedly identical to WRT54GL v1)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27917502</guid>
<pubDate>Wed, 16 Jan 2013 12:54:26 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27915084</link>
<description><![CDATA[BoToMaTiC posted : <div class="bquote"><said>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</said><p><div class="bquote"><said>said by <a href="/profile/892808" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=892808');">BoToMaTiC</a>:</said><p>Cisco/Linksys just released new firmware for the WRT54GL, don't know about other routers.<br><br>&raquo;<A HREF="http://homesupport.cisco.com/en-us/support/routers/WRT54GL" >homesupport.cisco.com/en-us/supp&middot;&middot;&middot;/WRT54GL</A><br><br>Firmware<br>01/10/2013<br><br>Firmware 4.30.16 (build 4)<br>- Resolves XSS issue.<br> </p></div>I will try it over the weekend or so. You guys go first. :P<br><br>XSS - Cross site scripting?<br> </p></div>I have already upgraded, did 30-30-30 reset, redid my settings and everything seems fine.<br><br>XSS - Cross site scripting?<br>That's what it looks like.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27915084</guid>
<pubDate>Tue, 15 Jan 2013 18:28:37 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27915020</link>
<description><![CDATA[antdude posted : <div class="bquote"><said>said by <a href="/profile/892808" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=892808');">BoToMaTiC</a>:</said><p>Cisco/Linksys just released new firmware for the WRT54GL, don't know about other routers.<br><br>&raquo;<A HREF="http://homesupport.cisco.com/en-us/support/routers/WRT54GL" >homesupport.cisco.com/en-us/supp&middot;&middot;&middot;/WRT54GL</A><br><br>Firmware<br>01/10/2013<br><br>Firmware 4.30.16 (build 4)<br>- Resolves XSS issue.<br> </p></div>I will try it over the weekend or so. You guys go first. :P<br><br>XSS - Cross site scripting?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27915020</guid>
<pubDate>Tue, 15 Jan 2013 18:14:05 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27914952</link>
<description><![CDATA[BoToMaTiC posted : Cisco/Linksys just released new firmware for the WRT54GL, don't know about other routers.<br><br>&raquo;<A HREF="http://homesupport.cisco.com/en-us/support/routers/WRT54GL" >homesupport.cisco.com/en-us/supp&middot;&middot;&middot;/WRT54GL</A><br><br>Firmware<br>01/10/2013<br><br>Firmware 4.30.16 (build 4)<br>- Resolves XSS issue.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27914952</guid>
<pubDate>Tue, 15 Jan 2013 17:54:45 EDT</pubDate>
</item>

<item>
<title>Re: Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27911917</link>
<description><![CDATA[NetFixer posted : <div class="bquote"><said>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</said><p>1:51PM <grifter> &raquo;<A HREF="http://www.net-security.org/secworld.php?id=14234" >www.net-security.org/secworld.php?id=14234</A><br><br>Uh oh. I have that old router too! :(<br> </p></div>What is being demonstrated in their video is <B>not</B> a remote exploit. Launching an application targeting 192.168.1.1 is not going to access a remote router.  :uhh:<br><br>Perhaps they have more that they are not showing in the video, but accessing a router from its LAN interface is not necessarily the same as accessing it from its WAN interface (which would be a requirement to be called a remote exploit). If an intruder already has access to your LAN, it is not your network anymore (whether they get root access to your perimeter router or not).<br><small>--<br>A well-regulated militia, being necessary to the security of a free State, the right of the people to keep and bear arms shall not be infringed.<br><br>When governments fear people, there is liberty. When the people fear the government, there is tyranny.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Dangerous-remote-Linksys-0day-root-exploit-discovered-27911917</guid>
<pubDate>Mon, 14 Jan 2013 20:53:23 EDT</pubDate>
</item>

<item>
<title>Dangerous remote Linksys 0-day root exploit discovered!</title>
<link>http://www.dslreports.com/forum/Dangerous-remote-Linksys-0day-root-exploit-discovered-27911193</link>
<description><![CDATA[antdude posted : 1:51PM <grifter> &raquo;<A HREF="http://www.net-security.org/secworld.php?id=14234" >www.net-security.org/secworld.php?id=14234</A><br><br>Uh oh. I have that old router too! :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Dangerous-remote-Linksys-0day-root-exploit-discovered-27911193</guid>
<pubDate>Mon, 14 Jan 2013 16:57:06 EDT</pubDate>
</item>

</channel>
</rss>
