Networking Forums

Networking Forums > Computer Networking > Broadband > Netgear DG834 - Vulnerabilities

Reply
Thread Tools Display Modes

Netgear DG834 - Vulnerabilities

 
 
Anonymous
Guest
Posts: n/a

 
      09-03-2006, 03:22 PM
From my own experience many Netgear DG834-series devices
leave ports OPEN and "UNSTEALTHED" by default.

I believe i've easily fixed this in my DG834.

Can any using DG834-series devices test these known ports
and post what their models , firmware-versions (if known) ,
and results are?

I'm more than happy to share my fix , if any have need of it.

Please test/scan TCP ports 1863 , 1864 , 4443 , 5190 , 5566 ,
and the range 40000 - 40099 AND the UDP port-range 40000 - 40100.

On my Netgear DG834v2 (wired-ethernet) , the above ports were
OPEN and/or "UNSTEALTHED" by the DEFAULT firewall-rules. The
administrative web-interface lied.

I'm not exactly sure how many Netgear models and/or firmware-versions
are affected , given the increasing popularity of these devices ,
such as most recently with Sky Broadband , it would seem scandalous
if many are being put at risk and have not been warned.

There are many sites that provide testing:



https://www.grc.com/x/ne.dll?bh0bkyd2


http://www.pcflank.com/


http://www.linux-sec.net/Audit/nmap.test.gwif.html



Be sure to TEMPORARILY disable your DG834's "DOS/Attack"
feature before testing , otherwise if you scan too many
ports at once your device will probably not allow all of
your requested ports to be tested properly.
 
Reply With Quote
 
 
 
 
PeterD
Guest
Posts: n/a

 
      09-03-2006, 03:32 PM
Anonymous <(E-Mail Removed)> wrote:

> Please test/scan TCP ports 1863 , 1864 , 4443 , 5190 , 5566


Nope, all stealth on my Netgear DG834v2, default rules.

--
Pd
 
Reply With Quote
 
Peter R Cook
Guest
Posts: n/a

 
      09-03-2006, 06:50 PM
In message <(E-Mail Removed) ixmin.net>,
Anonymous <(E-Mail Removed)> writes
>From my own experience many Netgear DG834-series devices
>leave ports OPEN and "UNSTEALTHED" by default.
>
>I believe i've easily fixed this in my DG834.
>
>Can any using DG834-series devices test these known ports
>and post what their models , firmware-versions (if known) ,
>and results are?
>
>I'm more than happy to share my fix , if any have need of it.
>
>Please test/scan TCP ports 1863 , 1864 , 4443 , 5190 , 5566 ,
>and the range 40000 - 40099 AND the UDP port-range 40000 - 40100.
>
>On my Netgear DG834v2 (wired-ethernet) , the above ports were
>OPEN and/or "UNSTEALTHED" by the DEFAULT firewall-rules. The
>administrative web-interface lied.
>
>I'm not exactly sure how many Netgear models and/or firmware-versions
>are affected , given the increasing popularity of these devices ,
>such as most recently with Sky Broadband , it would seem scandalous
>if many are being put at risk and have not been warned.
>
>There are many sites that provide testing:
>
>
>
>https://www.grc.com/x/ne.dll?bh0bkyd2
>
>
>http://www.pcflank.com/
>
>
>http://www.linux-sec.net/Audit/nmap.test.gwif.html
>
>
>
>Be sure to TEMPORARILY disable your DG834's "DOS/Attack"
>feature before testing , otherwise if you scan too many
>ports at once your device will probably not allow all of
>your requested ports to be tested properly.

This has been an ongoing issue with various releases of the firmware.

The latest release from Netgear (DG834G V1) V3.01.25 does not exhibit
the vulnerabilities
--
Peter R Cook
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Netgear DG834 Ted B Broadband 9 01-16-2007 04:10 PM
Netgear DG834 NickNike Broadband 5 06-28-2005 09:24 PM
Netgear DG834 Max Power Home Networking 1 06-17-2004 11:19 PM
Netgear DG834 Neil Raffan Broadband 6 06-07-2004 08:32 PM
Netgear DG834 CJ Windows Networking 6 01-23-2004 10:03 PM



1 2 3 4 5 6 7 8 9 10 11