Receive new posts as email.
RSS 0.91 | RSS 2.0
RDF | Atom
Podcast only feed (RSS 2.0 format)
Get an RSS reader
Get a Podcast receiver
| Sun | Mon | Tues | Wed | Thurs | Fri | Sat |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | 6 | |
| 7 | 8 | 9 | 10 | 11 | 12 | 13 |
| 14 | 15 | 16 | 17 | 18 | 19 | 20 |
| 21 | 22 | 23 | 24 | 25 | 26 | 27 |
| 28 | 29 | 30 | 31 |
This site operates as an independent editorial operation. Advertising, sponsorships, and other non-editorial materials represent the opinions and messages of their respective origins, and not of the site operator or JiWire, Inc.
Entire site and all contents except otherwise noted © Copyright 2001-2006 by Glenn Fleishman. Some images ©2006 Jupiterimages Corporation. All rights reserved. Please contact us for reprint rights. Linking is, of course, free and encouraged.
Powered by
Movable Type
« Alvarion Releases "WiMax" Platform | Main | McCaw Stays Mum on Clearwire »
Tech consultant discovers that Linksys WRT54G allows remote, over-the-Internet administration login even when remote management is turned off: Because all broadband gateway vendors ship their equipment with default passwords like public or admin, this vulnerability is moderately critical according to the Secunia security consultants. An automated attack could scan millions of home broadband network addresses and feed them the WRT54G Web login sequence.
With remote administrative access, the most that could happen is vandalism: the Linksys doesn’t provide tools via its Web interface for packet sniffing, but someone could corrupt the setup and lock a user out by changing the password, requiring a hard reset. Also, Linksys’ Web form appears to send the WEP or WPA password as hidden password text in a Web form, but that text is unencrypted in the HTML source, which can easily be viewed.
Posted by Glennf at June 2, 2004 10:15 AM
TrackBack URL for this entry:
https://db.isbn.nu/mt3/mt-tb.pl/1993
Listed below are links to weblogs that reference Change Your Linksys WRT54G Admin Password Right Now!:
» Security Consultants Urge Linksys WRT54G Owners to Change Configuration from Default from Operation Gadget
Wi-Fi Networking News reports that a consultant has discovered a "moderately critical" security vulnerability in the Linksys WRT54G router. According to the report, the Linksys WRT54G "allows remote, over-the-Internet administration login even when rem... [Read More]
Tracked on June 2, 2004 12:26 PM
» Linksys Problems from Full Speed
Wi-Fi Net News made me aware of a security hole in the Linksys WRT54G wireless router yesterday. They say that the admin website can be accessed remotely even if remote admin is disabled. Through my personal testing, I have not... [Read More]
Tracked on November 3, 2004 6:16 PM