TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Critical vulnerabilities in numerous ASUS routers

61 点作者 Kilo-byte将近 12 年前

9 条评论

zdw将近 12 年前
If you haven&#x27;t already, go replace your firmware with OpenWRT:<p><a href="http://wiki.openwrt.org/toh/start#asus" rel="nofollow">http:&#x2F;&#x2F;wiki.openwrt.org&#x2F;toh&#x2F;start#asus</a><p>It&#x27;s a much better UI experience, performs better, and with better stability than most OEM firmwares, and it&#x27;s open source so you can inspect&#x2F;recompile the code as needed to satiate your security concerns, install arbitrary software, etc.<p>This is literally the first thing I do with every router I pull out of the box.<p>Unfortunately, ASUS&#x27;s devices tend to use the Broadcom 47xx series chipsets in general, which tend to be not as well supported as newer chipset like the Atheros 7k and 9k variants, which are in most of the recommended devices these days.
评论 #6052548 未加载
评论 #6051891 未加载
评论 #6051707 未加载
评论 #6051694 未加载
gecko将近 12 年前
The first vulnerability listed isn&#x27;t a huge deal; it only applies when AiCloud is activated, which I suspect most people don&#x27;t.<p>On the other hand, the second vulnerability listed--that UPnP is <i>available on the @#%( WAN port</i>--should have people incredibly upset.
评论 #6052954 未加载
mikevm将近 12 年前
Given the recent NSA revelations, and the various posts discussing software and hardware backdoors, this vulnerability sent me into full-blown paranoia mode.<p>You can&#x27;t trust web service providers, you can&#x27;t trust your ISP, you can&#x27;t trust your gov&#x27;t, you can&#x27;t trust hardware providers. Jesus H. Christ, is there anything left to trust?<p>I&#x27;m starting to feel that by the simple act of connecting a device to the Internet I&#x27;m already compromised which makes me feel dirty.<p>I guess Richard Stallman isn&#x27;t so crazy after all for demanding open source hardware (well, he&#x27;s actually demanding &#x27;free&#x27; hardware). I know that DD-WRT is an open source router firmware, but I&#x27;m not sure whether high-end routers support it.
评论 #6051463 未加载
评论 #6051629 未加载
评论 #6052261 未加载
评论 #6051475 未加载
fulafel将近 12 年前
This kind of consumer NAT boxes have a history of being like swiss cheese. Only use them in bridge mode!
diminoten将近 12 年前
Oh neat, I&#x27;ve got one of these!<p>But I&#x27;ve got DD-WRT on there, so I&#x27;m... good to go?<p>uPNP has been a no-go security wise for a while now though, hasn&#x27;t it?
zokier将近 12 年前
I have RT-N12, it&#x27;s not on the list. Am I safe, is there some kind of test that would indicate if I&#x27;m vulnerable?
leeoniya将近 12 年前
toastman builds have been solid for me: <a href="http://www.4shared.com/dir/v1BuINP3/Toastman_Builds.html" rel="nofollow">http:&#x2F;&#x2F;www.4shared.com&#x2F;dir&#x2F;v1BuINP3&#x2F;Toastman_Builds.html</a><p>also great: <a href="http://tomato.groov.pl/download/" rel="nofollow">http:&#x2F;&#x2F;tomato.groov.pl&#x2F;download&#x2F;</a>
评论 #6052488 未加载
sramov将近 12 年前
OpenBSD on either Soekris or ALIX and you are done.
评论 #6052112 未加载
joshSimms将近 12 年前
Thanks for this post. I am installing ddwrt today!