Results 1 to 10 of 10

Thread: DD-WRT router, broken?     submit to reddit submit to twitter

  1. #1
    Resident Moogle
    Join Date
    Mar 2007
    Posts
    13,170
    BG Level
    9
    FFXI Server
    Asura

    DD-WRT router, broken?

    /////////// Problem solved, typical case of ISP doesn't know wtf they're doing. /////////////

    Not sure what's been up, but around noon today my router decide to shit on itself.

    Tried to see what was the issue, and it didn't want to connect to my cable modem to my net. Used my backup router, connected fine and everything.

    Figured the config file may have corrupted itself so I resetted back to factory settings, but after doing that, I can't change anything on the router itself, can't even restore my backup. (whenever it goes to 'apply' a setting, my browser just prompts me with a page error)

    At this point I was considering reflashing it (if I can even do that as it stands), but apparently the DD-WRT site is down also, so I can't download the firmware, convenient. ;/

    Anyone got any experience with this at all?

    [EDIT] Of course the site comes back up after I post this, going to try reflashing it....

  2. #2
    The Mizzle Fizzle of Nikkei's Haremizzle

    Join Date
    Feb 2006
    Posts
    22,049
    BG Level
    10
    FFXI Server
    Bismarck

    Good deal, let us know how the reflash goes.

  3. #3
    Resident Moogle
    Join Date
    Mar 2007
    Posts
    13,170
    BG Level
    9
    FFXI Server
    Asura

    Manage to let it save stuff again by manually telling it to delete nvram via telnet (felt kinda old-school doing that >.>), currently in the process of trying to remember which bloody version of dd-wrt I needed for my particular router. It's still unable to connect unfortunately.

    Ffs, this isn't my day, damn dd-wrt site being crap again.

    Makes me wonder if I got hit by that vulnerability that was announced last week.

    Testing (trying out said exploit to simply reboot router) :


    [EDIT] Things seem good now, ISP had to phone back a couple hours later to announce to me everything apparently wasn't a-OK on their end. Just weird that it affected my DD-WRT router and not the backup factory-firmware router.

    At any rate, least this problem brought my saving-issue to my attention and got fixed, as well as protecting it from that one exploit.

  4. #4
    Bagel
    Join Date
    Jan 2009
    Posts
    1,412
    BG Level
    6

    Glad you got the problem resolved, but I still can't see whatever is in what you spoilered. Routers tend to be rather finicky though... wouldn't be the first time I've had massive troubles with one for seemingly no reason at all and when you come back to it a few hours (days) later it works just fine. Major headaches.

  5. #5
    Resident Moogle
    Join Date
    Mar 2007
    Posts
    13,170
    BG Level
    9
    FFXI Server
    Asura

    If you're on a DD-WRT router with your IP set to 192.168.1.1 (default), opening the spoiler should make your router reboot (or potentially reboot the second the page loads, I'm unsure if spoilers load with the page, or load as its clicked open). Was just testing to see if the vulnerability fix (detailed/described here) was working, which it was when I entered it manually into a separate tab.

    I'm actually surprised at how long it took for that to discover, that's a major exploit that could easily be abused by malicious users.

  6. #6
    Relic Shield
    Join Date
    Aug 2006
    Posts
    1,807
    BG Level
    6

    Yup the exploit works, but it requires you to be using default addresses etc. I could reboot my router using the exploit, changed to reflect the specific settings I've set to the router (such as different default IP and port for the HTTP GUI)

    Such a ghetto exploit, lol. I'm guessing given that you basically have command line access to the router that you could in theory uninstall DD-WRT from a web address, or even execute an externally downloaded script? Router botnets ahoy?

  7. #7
    Resident Moogle
    Join Date
    Mar 2007
    Posts
    13,170
    BG Level
    9
    FFXI Server
    Asura

    All it would take is a simple iframe injection (to the lovely users of IE) filled with 100s of instances of typical local IP addresses to start wrecking some havoc.

    Exploit can give the user root access, so I'm under the assumption they could do whatever the fuck they wanted with the router, modify settings, lock users out, firmware it to make it a bot as you mentioned, or use it as an easier means to scout out local networks remotely for unprotected PCs to infect. Only drawback (I'm assuming) is that your average user doesn't have DD-WRT, so those that do should actually know how to protect their friggen PC.

  8. #8
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    I thought you needed remote access enabled on the router for that DD-WRT exploit to work, and almost no one leaves their router configuration open to outside access...

  9. #9
    Relic Shield
    Join Date
    Aug 2006
    Posts
    1,807
    BG Level
    6

    Newp, I don't have remote access on for that very reason, and it was still vulnerable till I applied the fixes.

  10. #10
    E. Body
    Join Date
    Jun 2007
    Posts
    2,065
    BG Level
    7
    FFXI Server
    Phoenix

    Has DD-WRT update in a while? The last time I flashed was maybe 2 years ago. I know if it's not broken, dont try to fix it... but new stuff rawr!

Similar Threads

  1. DD-WRT Standard v24 Beta
    By SephYuyX in forum Tech
    Replies: 17
    Last Post: 2011-05-21, 16:14
  2. DD-WRT Internet Throughput Issues
    By Kohan in forum Tech
    Replies: 10
    Last Post: 2011-05-03, 12:38
  3. Buying a router for dd-wrt
    By octopus in forum Tech
    Replies: 9
    Last Post: 2010-12-11, 05:42
  4. DD-WRT Issue
    By Tythera in forum Tech
    Replies: 3
    Last Post: 2010-06-13, 15:25
  5. easy DD-WRT walkthough?
    By Kenshiin in forum Tech
    Replies: 1
    Last Post: 2009-12-30, 16:58