Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » 2Wire » DNS Hijack on 2wire routers?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
2701HG-B Frequent loss of Internet light, and now rebooting »
« Block MSN Messenger in the company  
AuthorAll Replies


jr9730

join:2000-11-22
Torrance, CA
reply to no_fix_4me
Re: U-verse isn't the universe

All older gateways should be almost done now too I think - send me a message and dont be anon so we can commuicate with you..


no_fix_4me

@sbcglobal.net
reply to jr9730
See above - from me and others who haven't been updated.


jr9730

join:2000-11-22
Torrance, CA
reply to no_fix_4me
What version gateway do you have? The fix has hit a majority of ATT users at this time?


no_fix_4me

@sbcglobal.net

reply to yes_fix_4u
Ok, I understand that on a 2Wire forum, some fanboys will come out in defense, but it's foolish to claim that everything's hunky-dory because a very small subset - U-verse and a select few others - have the hotfix.

Yes, I've checked the MDC. I don't have the hotfix, my mother doesn't have it, and the neighbors I've checked with don't have it. Therefore a reasonable conclusion is that a large number of AT&T users remain unpatched.

I'm happy for you U-verse customers who have the fix, but the reality is that U-verse is new and represents the minority of users.


yes_fix_4u

@sbcglobal.net

reply to no_fix_4U
Re: AT&T claims this is fixed???

It's a hotfix, not a firmware change. I have U-verse and they first pushed out a hotfix then they updated the firmware fixing some other things. look at your MDC page: »home/mdc at the bottom of the System Settings page and look for hotfix or uihotfix. My brother has normal adsl and he has the patch and I believe it says hotfix. Oh, he has a 2701(?) and the firmware didn't change, just a component was added.

»New Firmware for 3800 Series


ctceo
Premium
join:2001-04-26
South Bend, IN
clubs:
·magicjack.com
·AT&T U-Verse
·Comcast
·AT&T Midwest
·HughesNet Satellit..

reply to no_fix_4U
I've been on several hundred BETA lists in the last 15 years, Games, Hardware, Software, MMO's, and I actually have to turn down some that I otherwise would love to participate in. As for the 2Wire, I was chosen based on a questionaire that I got when I subscribed for at&t DSL back in early 2000. Since then I've had the pleasure of being part of the test groups. For a couple models and about 2 or 3 firmwares, Including the latest 4.25.19 .

They've been hush hush about the vulnerability, so I'm sure based on that and my experience with other earlier problems that the hardware had, they're working on it. Due to that pretty pink sheet of paper that I have labeled Non-Disclosure Agreement blah blah, blah blah; in BOLD and UNDERLINE, I cannot comment any further.


no_fix_4U

@sbcglobal.net

reply to ctceo
said by ctceo See Profile :

I'm running in the BETA pool 4.25.19 on a 1000HG

Exploit 1 brings up the "Page not Found" screen.
Exploit 2 brings up the "Enter the Password" Screen.

If your passwords were set to "admin", you'd definitely have a problem on your hands
So it sounds like there's a fixed beta 4.25.19 out there, or perhaps you have the UI hotfix that was mentioned. How did you get your beta version? My 4.25.19 is still vulnerable:

For me, the exploit works regardless of the password I have set. I've always had a strong password (8 characters, with numbers/punctuation), but the first exploit resets the password to "admin".

Apparently AT&T has not deployed the hotfix to me. Wish I could get updated - my 1701HG always tells me I have the latest version.

sasparilla

join:2008-04-09
Round Lake, IL

reply to no_fix_4U
said by no_fix_4U :

So is AT&T just feeding us a line?
It definately makes me wonder if this just wasn't spin control on AT&T's part. Suposedly, 2Wire's/AT&T's fixes have been out in the wild for my 2701 for several days, but checking for a firmware update shows no updates available.

The v5.29.109.5 software on my AT&T 2701 (that I got this last week) is fully exploitable (just verified that the exploits work on it). (Supposedly another user's v5.29.109.11 is the fixed version)

Seems like spin control to me, at this point.


ctceo
Premium
join:2001-04-26
South Bend, IN
clubs:
·magicjack.com
·AT&T U-Verse
·Comcast
·AT&T Midwest
·HughesNet Satellit..


3 edits
reply to no_fix_4U
I'm running in the BETA pool 4.25.19 on a 1000HG

Exploit 1 brings up the "Page not Found" screen.
Exploit 2 brings up the "Enter the Password" Screen.

If your passwords were set to "admin", you'd definitely have a problem on your hands, and as for the first one if you have no password set, You might have an issue as this SETS your password to whatever the attacker wants. He's then free to run exploit #2 assuming that the host site used is ready for the embed.

I recommend that everyone who uses a vulnerable 2Wire SET A SYSTEM PASSWORD other than "admin". I use 5 letters & 5 Numbers caps & lowercase, no spaces or characters is ok.


no_fix_4U

@sbcglobal.net

reply to evad123
So this story shows up on slashdot »tech.slashdot.org/tech/08/04/08/···14.shtml
and AT&T responds by claiming they've already fixed this problem for most all their users. But my 1701HG has 4.25.19 and it's still easily hijacked. It seems some of the 5.xx firmwares are fixed, but that doesn't work on older homeportals.

This exploit still works on my box:

First URL sets my password without asking for confirmation. Second URL hijacks www.example.com to 127.0.0.1

So is AT&T just feeding us a line?
Forums » Equipment Support » Hardware By Brand » 2Wire2701HG-B Frequent loss of Internet light, and now rebooting »
« Block MSN Messenger in the company  


Sunday, 29-Nov 10:15:07 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [74] Verizon CEO: Hulu Will Be Dead Soon
· [74] Weekend Open Thread
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· [WIN7] Let's See Your Win 7 Desktop [Microsoft Help]
· Anyone have a problem [Software]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]