View Single Post
  #1 (permalink)  
Old 07-04-2007, 08:37 AM
Debbie Hurley
Guest
 
Posts: n/a
Default Help my Linksys WRT54G router was broken into using the "curl" command

It's way too easy to break into the Linksys WRT54G router!

Instantly bypassing the administrator password, my fifteen-year old
neighbor broke into my Linksys WRT54G router (firmware revision v1.0.0.6)
in ten seconds simply by sending this one "curl" command to it via the
Internet from his home next door!

c:\> curl -d "SecurityMode=0&layout=en" http://192.168.0.1/Security.tri

This kid was kind enough to knock on my door today to tell me to fix it.

I invited him in, and from inside my own house, he showed me the Linksys
WRT54G command above which immediately disabled all my wireless security
WITHOUT him having to enter any password!

He showed me how to disable remote administration but he said the
vulnerability still exists until I get a new router. I can't believe
everyone with a Linksys WRT54G router is throwing it in the garbage.

Where/how can I find a firmware update that protects me from this
vulnerability?






Reply With Quote