Author | Message |
---|---|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
to be clear ... when i talk about Redmond education, this is not about the product, but the policy of "assistance" (i'm not sure about the correct english tranlation). I mean User is treat a ... | |
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
this typical from Redmond education "Openned mouth waiting for food to come in without doing anything Hm... I may have something to say about that "Redmond education"; I'm not a &quo ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
Anyway, mailing list could be a good idea, if you read it. A better idea may be having some kind of built-in mechanism into DD-WRT to check from time to time for updates; fetch some kind of "up ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
Anyway, mailing list could be a good idea, if you read it. A better idea may be having some kind of built-in mechanism into DD-WRT to check from time to time for updates; fetch some kind of "up ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
I think a better way might be to have a session token passed by a cookie that must be included as part of the URL for any subsequent communication http://SERVER_IP/normalstuff&SESSION=66a934bbf ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
Sorry guys, no time right now to comb through all the 12 pages of this discussion (maybe somebody already has reported about this). I just read about this issue and wanted to inform, that the bug is ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
Yeah I think such a GUI option would be good. I can't see how quitting and restarting the httpd daemon could be permanent on reboot. Right now a more realistic option is probably just to change you ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
ports, you've got to do it as described killall httpd cd /www httpd -p 81 -h /www cd /jffs httpd -h /jffs Will that work across boots? you won't need the second part (that is the "jffs&quo ... |
|
![]() |
|
![]() |
|
OB1 Replies: 6 Views: 9445 |
![]() |
just read the news dd-wrt.com sounds like you didn't follow the "vuln" thread on THIS forum, did you <eg> ? |
|
![]() |
|
![]() |
|
OB1 Replies: 6 Views: 9445 |
![]() |
Thanks for the headsup drjay. While we wait for a firmware update to address this vulnerability, does anyone know how to protect against a "Cross Site Reference Forgery Exploit"? Disable ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
If I remember right, last years' exploit was something like this... if you'd previously authorized to the control panel with the browser and then visited an evil site without first logging out, your ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
Hello, all. What about spawning a shell at port tcp/11111 by using ROFL...that's something I tried to enforce, but apparently ... I did hit deaf ears :P anyways... that isn't "sorry for the m ... |
|
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
No. Because the same thing happens to many people's computers in a day. Eventually, they figure out they have a virus and the get someone to fix the problem. Those who actually *keep* up with their ... | |
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
Yeah this was already discussed way back in the thread by myself and others. Band-aid fix is right. Not a good feeling knowing your ddwrt devices are a URL away from crash/hack no matter where you h ... | |
![]() |
|
![]() |
|
OB1 Replies: 221 Views: 307560 |
![]() |
One idea that would mitigate automated CSRF attacks like this is for everyone to use a unique IP address range - there is the whole of 10.x.x.x to use, and 172.16.something, and of course 192.168.N.x ... | |
![]() |
|
All times are GMT |