I'm wondering if - as you suggested/implied - non-patch older Asus router (so running a default older firmware) would be the only one affected. Asuswrt in its latest release seems to have a recent version of miniupnp, at least it should have the fix you mentioned.
Nmap is reporting for the WAN...
I wanted to do also some real test on my ASUS RT-AC68U which is part of the marked vulnerable routers. And before I finally found where the UPnP option was (I know I had deactivated it, so I needed to reactivate it to test it) I found out that:
1. Asus activated DDNS without me configuring it...
Hi RMerlin,
From reading their (Akamai) paper, I think they need that the Router (e.g. a vulnerable ASUS router) has already at least a UPnP service active (potentially several). So imagine, one has launched an application on your computer on the LAN (e.g. a video conferencing tool or game for...
It is not unrealistic, they have one platform to validate for an updated SDK. Then, the end-product manufacturer (e.g. Asus) can validate the 2-3 platforms based on the updated SDK. How does Microsoft do it for Windows?
In addition, take embedded devices like a Raspberry Pi, or a Turris Omnia...
Thanks RMerlin, that's what I fear. But I had some hope that in order to offer the new WiFi meshing features, they had to go back to Broadcom and get some kind of updated SDK, hence newer Kernel.
OK, then bye bye Asus and hello Turris!
I understand that your 382 branch is currently private, so not accessible. But what about the official GPL 382 code from Asus? Is it public?
I'm interested in looking at the code to see if they bumped the Kernel version for the RT-AC68U. The reason is if they bump it, then I'm willing to keep...
Does this new firmware by any chance update the Linux Kernel version to one that is still maintained? What would be the Kernel version for RT-AC68U?
Kernel 2.6.36 (the one on the RT-AC68U) is soon 7 years old (published Oct 2010). Kernel 3.0-3.10 got a lot of improvements esp. related to...
Those are reasons serious enough for me to consider buying the Turris Omnia router, or possibly a Unifi one, but my open source heart is preferring the former.
In the end, I did a trade-off...
I let my ASUS router taking care of DHCP and DNS, *BUT* I configured in the "WAN" part of the administration settings the DNS to point to my own maintained DNS (I want to build a recursive DNS in the end) inside my LAN. So the ASUS router is caching the DNS...
Sustaining download especially when done over TCP (e.g. HTTP/HTTPS or FTP) is something that clearly depends of many factor on the network: latency (and hence distance), packet loss, buffer sizes, congestion, and the TCP algorithms chosen on both end of the stream regarding flow and congestion...
I do not trust too much those speedtest websites. But if you have no other means, then try this one: http://www.dslreports.com/speedtest
This site is not too bad, it provides lots of control on the test and good feedback (including how the latency is impacted by the bandwidth, aka bufferbloat)...
Hi bartoszbruhn
Could you explain to me what you mean by "NAT off". NAT cannot be off unless you use public IP addresses on your LAN, but I doubt it. Do you mean that you disabled NAT acceleration?
How did you your benchmarking? Which tool did you use? Are you sure the drop in bandwidth is due...
I did some tests over the weekend to see the routing speed of my RT-AC68U. I've been using iperf3 with 2 machines: one on the WAN interface the other on the LAN interface. Previously I had measured when both machines where on the LAN and I could get around 950Mb/s in TCP or UDP. But when using...
Thank you for the information. Then I still need to find out why on my iPhone and iPad, I often lose the wifi for several tens of seconds. It doesn't happen on the android phone of my wife nor on her Mac. And it also doesn't happen on my laptop (Win7+Linux).
So a problem pure iOS-ish.
Is this option available on the official firmware also or only on your Merlin fork?
I'm asking because I don't find it in the professional tab and I'm asking myself if the feature was remove from newer firmware or was never there to begin with.