Recent content by Zuultroet

  1. Z

    Security bug : Administration reachable over WAN

    I have been able to test the WAN side in 3 different ways, I am quite certain this is no loopback related issue; besides, problematic rules have already observed in the previous posts. Hence my conclusion.
  2. Z

    Security bug : Administration reachable over WAN

    I finally was able to take the time to try just that, and am sad to tell you that I have done just the above, and that port 80 and the administration pages were immediately available from the wan after : -NVRAM clear (wps + on) -flashing Shibby's tomato -wiping with Shibby's -flashing...
  3. Z

    Security bug : Administration reachable over WAN

    I am currently at work and will test as soon as I can. I did reboot the Asus several times, flash and clear the NVRAM without any changes to the behavior : I will attempt more severe resetting, possibly by flashing Shibby's, using its thorough NVRAM wipe, and reflash back your firmware...
  4. Z

    Security bug : Administration reachable over WAN

    My goal it to set OpenVPN to port 80 : It was set on port 80 on the first iptables -L -v. I set it back to 1194 and posted the result from http://forums.smallnetbuilder.com/showpost.php?p=106956&postcount=45 : Admin is still accessible from the WAN side. I'm afraid this is not crucial to...
  5. Z

    Security bug : Administration reachable over WAN

    ...continued - was too long for one post /jffs/syslog.log-1:Jan 1 01:00:12 kernel: eth1: Broadcom BCM4331 802.11 Wireless Controller 6.30.163.2002 (r382208) /jffs/syslog.log-1:Jan 1 01:00:12 kernel: eth2: Broadcom BCM4360 802.11 Wireless Controller 6.30.163.2002 (r382208)...
  6. Z

    Security bug : Administration reachable over WAN

    /jffs/syslog.log-1:Feb 20 22:46:12 kernel: usbcore: deregistering interface driver net1080 /jffs/syslog.log-1:Jan 1 01:00:11 kernel: memory: 08000000 @ 87fff000 (usable) /jffs/syslog.log-1:Jan 1 01:00:12 kernel: eth1: Broadcom BCM4331 802.11 Wireless Controller 6.30.163.2002 (r382208)...
  7. Z

    Security bug : Administration reachable over WAN

    wl0_rxchain_pwrsave_quiet_time=1800 wl_acs_dfsr_deferred=604800 5 wan_gateway=78.217.80.254 qos_rulelist=<Web Surf>>80>tcp>0~512>0<HTTPS>>443>tcp>0~512>0<File Transfer>>80>tcp>512~>3<File Transfer>>443>tcp>512~>3 login_port=80 wl0_acs_dfsr_deferred=604800 5...
  8. Z

    Security bug : Administration reachable over WAN

    Alas the router's version of netstat does not know -p :-( It understands : -r Routing table -a All sockets -l Listening sockets Else: connected sockets -t TCP sockets -u UDP sockets -w Raw sockets -x Unix sockets Else: all socket types -e Other/more information -n Don't...
  9. Z

    Security bug : Administration reachable over WAN

    To be more complete, I tested the behavior : - both Merlin's 3.0.0.4_374.39_0 and Asus's 3.0.0.4_374_4561 firmwares, - both with my current settings and right after a NVRAM clear (On+WPS), which I did after each flashing. Each time the bug was present.
  10. Z

    Security bug : Administration reachable over WAN

    This was the setup I originally wanted, port 80 being able to go through most restrictive connections, and TAP being my favorite. The problem occurs even when OpenVPN is on its default port, 1194 : port 80 still gives you access to the Asus's Admin page, not an OpenVPN related port. The...
  11. Z

    Security bug : Administration reachable over WAN

    The ISP is called "Free" (it is not ! ;-) ), and the modem, called Freebox, is proprietary to it.
  12. Z

    Security bug : Administration reachable over WAN

    Sorry, I'll try to be more clear : my initial configuration was : [ISP's router] -> 192.168.0.x -> [ASUS] -> 192.168.1.x -> LAN I did this for testing purposes, to be able to configure the Asus without exposing it to the Internet. Then a few posts later, to be able to scan the Asus from...
  13. Z

    Security bug : Administration reachable over WAN

    yep, here my ISP's router can be configured as a bridge (hands the external IP to one single device), or as a full NAT router. This way I can test both configurations :-)
  14. Z

    Security bug : Administration reachable over WAN

    Sorry, I'll try to be more clear : my initial configuration was : [ISP's router] -> 192.168.0.x -> [ASUS] -> 192.168.1.x -> LAN I did this for testing purposes, to be able to configure the Asus without exposing it to the Internet. Then a few posts later, to be able to scan the Asus from...
  15. Z

    Security bug : Administration reachable over WAN

    - On my ISP's modem/router, NAT is disabled. It justs hands my external IP to he WAN side of the ASUS. - On the Asus, NAT is enabled, the PC I'm on is currently plugged on the LAN port of the Asus, with an IP of 192.168.x.X the setup is currently : [ISP's Modem] Lan port -> WAN port...
Back
Top