dd-wrt patched against severe flaws in WPA2 / KRACK attack

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next
Author Message
Takv
DD-WRT User


Joined: 31 Aug 2010
Posts: 66
Location: Valparaiso, Chile

PostPosted: Tue Oct 17, 2017 17:53    Post subject: any news for the branch update containing the fixes? Reply with quote
So, when the branch will be updated?
_________________
WIFITxRx NetWorks
DD-WRT user from 2009 to date

Routers:
tp-link 740n v1.x to v5.x (60+)
tp-link 741nd v1.x to v5.x (80+)
tp-link 841nd v7 (5)
tp-link 841nd v8 v9 (10+)
tp-link 941nd v3.6 (2)
ubnt bullet m2hp (1)
ubnt airgrid m2hp m5hp (4)
rb450g-rb2011-rbX86-rb433uah-rb912
And many more each month coming!
Sponsor
Takv
DD-WRT User


Joined: 31 Aug 2010
Posts: 66
Location: Valparaiso, Chile

PostPosted: Tue Oct 17, 2017 18:20    Post subject: Reply with quote
I will answer myself:

ftp://ftp.dd-wrt.com/betas/2017/10-17-2017-r33525/

_________________
WIFITxRx NetWorks
DD-WRT user from 2009 to date

Routers:
tp-link 740n v1.x to v5.x (60+)
tp-link 741nd v1.x to v5.x (80+)
tp-link 841nd v7 (5)
tp-link 841nd v8 v9 (10+)
tp-link 941nd v3.6 (2)
ubnt bullet m2hp (1)
ubnt airgrid m2hp m5hp (4)
rb450g-rb2011-rbX86-rb433uah-rb912
And many more each month coming!
lovaduck
DD-WRT Novice


Joined: 29 May 2017
Posts: 2

PostPosted: Tue Oct 17, 2017 18:30    Post subject: Re: Krack CVE Reply with quote
Slobodan, are you using DD-WRT on your Asus RT-N16?
Which patched build works?
I have the same unit, running Merlin at the moment but it seems not patched yet.
Thanks!
imorven
DD-WRT Novice


Joined: 17 Oct 2017
Posts: 1

PostPosted: Tue Oct 17, 2017 18:38    Post subject: Reply with quote
It is not useless. Not all your client devices can get updated. Patching DD-WRT AP can secure your home or owned Wi-Fi environment. At least you won't need to have VPN connection at home to have more secure connections due to the vulnerability.

apacheguy wrote:
Yeah, my understanding is that the vulnerability only affects a router operating in client/repeater mode. If it is just a straight AP then he patch is pretty useless.
jc1685
DD-WRT Novice


Joined: 20 Sep 2017
Posts: 1

PostPosted: Tue Oct 17, 2017 19:52    Post subject: Reply with quote
33525 is in ftp://ftp.dd-wrt.com/betas/2017/ now. Has anyone tried it yet on Linksys WRT1900AC v1?
riahc3
DD-WRT User


Joined: 04 May 2007
Posts: 329

PostPosted: Tue Oct 17, 2017 21:47    Post subject: Reply with quote
This should have been released a lot sooner. FreeBSD I believe already had a patch out last week.
GregProtocol
DD-WRT Novice


Joined: 18 Oct 2017
Posts: 3

PostPosted: Wed Oct 18, 2017 0:42    Post subject: Reply with quote
Asus RT-ac68u B1 will not boot on the new 10/17 load. I can confirm 10/10 load boots no problem; its very stable. Anyone else experiencing issues with the new beta?
joseph805
DD-WRT Novice


Joined: 18 Oct 2017
Posts: 1

PostPosted: Wed Oct 18, 2017 0:49    Post subject: Reply with quote
I just patched my Linksys WRT1900AC V2 to the 10/17 build. Everything seems to be working okay thus far. GL.
slobodan
DD-WRT Guru


Joined: 03 Nov 2011
Posts: 1558
Location: Zwolle

PostPosted: Wed Oct 18, 2017 1:23    Post subject: Re: Krack CVE Reply with quote
lovaduck wrote:
Slobodan, are you using DD-WRT on your Asus RT-N16?
Which patched build works?
I have the same unit, running Merlin at the moment but it seems not patched yet.
Thanks!

I did not install 33525 yet on my RT-N16, I assume that it works fine, since it works fine on my E4200 V1 (pretty much the same specs).

_________________
2 times APU2 Opnsense 21.1 with Sensei

2 times RT-AC56U running DD-WRT 45493 (one as Gateway, the other as AP, both bridged with LAN cable)

3 times Asus RT-N16 shelved

E4200 V1 running freshtomato 2020.8 (bridged with LAN cable)

3 times Linksys WRT610N V2 converted to E3000 and 1 original E3000 running freshtomato 2020.8 (bridged with LAN cable)


apacheguy
DD-WRT User


Joined: 26 Jun 2008
Posts: 103

PostPosted: Wed Oct 18, 2017 1:54    Post subject: Reply with quote
imorven wrote:
It is not useless. Not all your client devices can get updated. Patching DD-WRT AP can secure your home or owned Wi-Fi environment. At least you won't need to have VPN connection at home to have more secure connections due to the vulnerability.


Patching the dd-wrt AP will NOT protect an unpatched client. The client will still be vulnerable.
Bib
DD-WRT Guru


Joined: 07 Jul 2008
Posts: 629
Location: France

PostPosted: Wed Oct 18, 2017 5:54    Post subject: Reply with quote
Let's wait these tools from Mathy Vanhoef to know if our devices are still vulnerable.
_________________
): FoReVeR nEwB Sad
cystal88
DD-WRT Novice


Joined: 18 Oct 2017
Posts: 3

PostPosted: Wed Oct 18, 2017 6:48    Post subject: Reply with quote
GregProtocol wrote:
Asus RT-ac68u B1 will not boot on the new 10/17 load. I can confirm 10/10 load boots no problem; its very stable. Anyone else experiencing issues with the new beta?


I can confirm here too that the newest firmware does not work on the AC68U. The 10/10 firmware is okay.

The 10/17 AC68U firmware that does not work:
MD5: 1CE8AD8488D0C2832D4D622AE238A9A0
SHA1: 1985F0B237EB8ABA473A1A7A36E9C51F915A3258
vfrjim
DD-WRT Novice


Joined: 10 Jul 2010
Posts: 5

PostPosted: Wed Oct 18, 2017 13:32    Post subject: Asus RT-N12 not listed for Krack Patch Reply with quote
I did not see the Asus RT-N12 Listed with the latest beta after 10/10. Do you think it will be updated? I have 3 of them in service. Thanks.
Dooremo
DD-WRT Novice


Joined: 15 Jun 2017
Posts: 3

PostPosted: Wed Oct 18, 2017 15:04    Post subject: Reply with quote
Here are list the fixes along with company's names and status:


Apple: Apple has ALREADY released a patch update in macOS 10.11.1 (beta only). The company will widely roll out an update for iOS and Mac users in a few days.

Windows: Windows reacted promptly and sent out an automatic update for Windows 7, 8, 8.1 & 1o users.

Linux: Linux worked swiftly and released KRACK Wi-Fi Patches updates for Ubuntu 14.04+, Arch, OpenBSD, Debian, Gentoo, and Linux upstream.

Intel chipsets: Intel released firmware updates for its various chipsets.

Raspberry Pi: Jessian, Stretch has been fixed. Wheezy and others will receive updates by October 17.

Android: Android will fix at patch level by November 6, 2017.

Lineage OS: Fixes have been merged and will be rolled out in next weekly release.

Samsung: Samsung’s flagship devices have received Google security patches, but older models have still not received KRACK Wi-Fi patches.

iOS: Apple will likely release the KRACK Wi-Fi patch in iOS 11.1 this week.

Google Wi-Fi: Google will release a patch soon.

Apple Airport: No news on the Apple Airport.

Netgear: No updates have been released. Expect updates soon.

UniFi: Firmware 3.9.3 solves the concern.

Microtik: RouterOS v6.39.3, v6.40.4, v6.41rc and up.

LEDE: Fixes available in night by night updates.

Eero: eerOS 3.5 and up is secure.

AVM: AVM is somewhat aware of the vulnerability but doesn’t feel an update is necessary.

DD-WRT: Fixed in core, waiting for an update.

Meraki: Fixed with Meraki 24.11 and 25.7.

Aruba: Updates are available across Aruba hardware.

FortiNet: FortiAP 5.6.1 and up are secure.

Cisco: Updates are now available on Cisco hardware.

TP-Link: The company, doesn't know much about the vulnerability.

Synology: KRACK Wi-Fi security fix is now available.

KPN (NL): No information on the fix.

Nest: Nest claims that their devices aren't affected.

Sonos: No information on Sonos.

Amazon: Amazon is still in the process of reviewing devices while there is no fix issued for Echo etc.

Belkin: Belkin is aware of the issue, yet there is no fix for Wemo/Linksys devices.

Source: https://www.purevpn.com/blog/krack-wifi-security-fixes/
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 13880
Location: Netherlands

PostPosted: Wed Oct 18, 2017 15:10    Post subject: Reply with quote
For those of you who are interested see: http://blog.mojonetworks.com/wpa2-vulnerability

The real solution is in the client side, clients must not install the retransmitted keys.

Only exception is of course if the router is used as a client and if the router can do handovers in roaming (802.11r)

However on the Router side measures can be taken to mititgate the problem by not retransmitting the key and then disconnecting the client. This can give you connectivity problems, so probably a switch will be implemented in the GUI to use this countermeasure (I hope)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next Display posts from previous:    Page 3 of 8
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum