BS... not bad to update to this one 2.83, as lots of new holes will be patched...it seams 2.82 if plain used is open to vulnerabilities of cache poisoning and SAD DNS attacks...
the only way to mitigate those in 2.82 is using a DoT, DoH as well DNScrypt...but still prone to crc32 or sha-1 weakness in DNSSEC verification
I believe im not the first that have found the hot water today... _________________ Atheros
TP-Link WR740Nv1 -----DD-WRT 45928 BS AP,NAT
TP-Link WR740Nv4 -----DD-WRT 44251 BS WAP/Switch
TP-Link WR1043NDv2 ---DD-WRT 45849 BS AP,NAT,AP Isolation,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---DD-WRT 45928 BS AP,NAT,AD/Block,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---Gargoyle OS 1.12.0 AP,NAT,QoS,Quotas
Qualcomm/IPQ8065
Netgear R7800 -----DD-WRT 45928 BS AP,NAT,AD-Block,AP&Net Isolation,VLAN's,Firewall,Local DNS,DoT
Broadcom
Netgear R7000 -----DD-WRT 45928 BS AP,Wi-Fi OFF,NAT,AD-Block,Firewall,Local DNS,Forced DNS,VLAN's,DoT,VPN
-----------------------------------------------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 by mac913
Joined: 16 Nov 2015 Posts: 4177 Location: UK, London, just across the river..
Posted: Wed Jan 20, 2021 9:08 Post subject:
hmmm... the only thing i could see in SVN was regarding DHCP, ipv6 and some stuff about DNSSEC... + DNSmasq - UNKNOWN at the current builds...
Yes DNSSEC issues ware known, before those holes ware exposed to public...as well some others...so good move from BS side...patching those, in advance if so...
But DDWRT still needs the proper full version of it (2.83), as its has more complex approach...to the known issues..
https://svn.dd-wrt.com/changeset/45503
Thanks for letting us know egc and thanks to BS too...
p.s. im sorry if i opened an inappropriate thread, mods can delete it now... _________________ Atheros
TP-Link WR740Nv1 -----DD-WRT 45928 BS AP,NAT
TP-Link WR740Nv4 -----DD-WRT 44251 BS WAP/Switch
TP-Link WR1043NDv2 ---DD-WRT 45849 BS AP,NAT,AP Isolation,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---DD-WRT 45928 BS AP,NAT,AD/Block,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---Gargoyle OS 1.12.0 AP,NAT,QoS,Quotas
Qualcomm/IPQ8065
Netgear R7800 -----DD-WRT 45928 BS AP,NAT,AD-Block,AP&Net Isolation,VLAN's,Firewall,Local DNS,DoT
Broadcom
Netgear R7000 -----DD-WRT 45928 BS AP,Wi-Fi OFF,NAT,AD-Block,Firewall,Local DNS,Forced DNS,VLAN's,DoT,VPN
-----------------------------------------------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 by mac913