New Build - 01/19/2023 - r51440

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Goto page Previous  1, 2, 3, 4, 5  Next
Author Message
ramblin
DD-WRT User


Joined: 03 Nov 2015
Posts: 317
Location: Florida, USA

PostPosted: Thu Jan 19, 2023 15:14    Post subject: Reply with quote
Router: Linksys ea8500 ..WDS AP
Firmware: DD-WRT v3.0-r51440 std (01/19/23)
Kernel: Linux 4.9.337 #1490 SMP Mon Jan 16 04:19:44 +07 2023 armv7l
Reset: NO...GUI upgrade from r50841
Mode: 2.4 GHz only ....Firmware type .. DD-WRT
Errors: NONE

Router: Linksys ea8500 ..WDS Stations ... X (2)
Firmware: DD-WRT v3.0-r51440 std (01/19/23)
Kernel: Linux 4.9.337 #1490 SMP Mon Jan 16 04:19:44 +07 2023 armv7l
Reset: NO...GUI upgrade from r50841
Mode: 2.4 GHz only ....Firmware type .. DD-WRT
Errors: NONE

Upgrades successful !! Seems all my "self inflicted" issues have been worked out..THANKS BS and all !

_________________
......All GOOD here... Just Handshakes and Time Stamps !......
Sponsor
mac913
DD-WRT Guru


Joined: 02 May 2008
Posts: 1848
Location: Canada

PostPosted: Thu Jan 19, 2023 16:14    Post subject: Reply with quote
dale_gribble39 wrote:
Alozaros wrote:
errors: For some odd reason...I keep seen remote_mgt_https=1 comes enabled by default on all my routers...and its not enabled in the GUI...by default ...so check yours :P

This might be a glitch in ssh remote being enabled. Or not. Just a guess. I haven't reviewed any code.


Just loaded up 51440 and I have ssh enabled and all good...

Quote:
size: 48398 bytes (82674 left)
remote_mgt_ssh=1
remote_mgt_telnet=0
remote_mgt_https=0

_________________
Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9

Off Site 1

R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4

Off Site 2

R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531


YAMon 3.4.6 | DNSCrypt-Proxy V2
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1952

PostPosted: Thu Jan 19, 2023 19:37    Post subject: Reply with quote
Well, the source of the report is questionable in my opinion, to say the least, anyway. Thank you for your confirmation of no bug related to that, mac913.
_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
matjazk
DD-WRT User


Joined: 21 Aug 2019
Posts: 120
Location: Here, There And Everywhere

PostPosted: Thu Jan 19, 2023 20:08    Post subject: Reply with quote
Router/Version: TP-Link ARCHER-C7 v5
File/Kernel: DD-WRT v3.0-r51440 std (01/19/23) / Linux 3.18.140-d6 #161470 Thu Jan 19 08:12:39 +06 2023 mips
Previous/Reset: No
Mode/Status: WDS Station / Working
Issues/Errors: None so far.
matjazk
DD-WRT User


Joined: 21 Aug 2019
Posts: 120
Location: Here, There And Everywhere

PostPosted: Thu Jan 19, 2023 20:11    Post subject: Reply with quote
Router/Version: Netgear R7800
File/Kernel: DD-WRT v3.0-r51440 std (01/19/23) / Linux 4.9.337 #1492 SMP Thu Jan 19 04:05:30 +07 2023 armv7l
Previous/Reset: No
Mode/Status: WAP & WDS AP, USB, Samba / All working
Issues/Errors: None so far.


Last edited by matjazk on Thu Jan 19, 2023 20:17; edited 1 time in total
matjazk
DD-WRT User


Joined: 21 Aug 2019
Posts: 120
Location: Here, There And Everywhere

PostPosted: Thu Jan 19, 2023 20:16    Post subject: Reply with quote
Router/Version: Netgear Nighthawk X10 (R9000)
File/Kernel: DD-WRT v3.0-r51440 std (01/19/23) / Linux 4.9.337 #658 SMP Mon Jan 9 04:22:19 +07 2023 armv7l
Previous/Reset: No
Mode/Status: Gateway, Wireguard, USB, Samba / Working OK
Issues/Errors: Did not work (respond) at first, but a power cycle helped. Now everything seems to be OK.
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6446
Location: UK, London, just across the river..

PostPosted: Thu Jan 19, 2023 21:51    Post subject: Reply with quote
dale_gribble39 wrote:
Well, the source of the report is questionable in my opinion, to say the least, anyway. Thank you for your confirmation of no bug related to that, mac913.


well... i had a quick look and here what i ve found:

i have web access https only, no remote access enabled on this unit:



so, every time i go to GUI Administration>Management page and hit save and than apply,
remote https becomes enabled, than if i do a nvram set .... manually revert it to 0 than, nvram commit (or even reboot), on check its 0, on save apply on this page it comes back to 1....

root@1043NDv2:~# nvram show | grep remote_mgt_https=
remote_mgt_https=1
root@1043NDv2:~# nvram set remote_mgt_https=0
root@1043NDv2:~# nvram commit
root@1043NDv2:~# nvram show | grep remote_mgt_https=
remote_mgt_https=0

root@1043NDv2:~# nvram show | grep remote_mgt_https=
remote_mgt_https=1

I guess, same happens for the rest units i have...what ever i enter on this page, and i dont do it very often.... on save apply it triggers remote_mgt_https=1 no idea since when... Rolling Eyes
I also tend to carry same setup forward and no reset or manually rebuild, unless is needed...so, no idea when the glitch happened... Rolling Eyes

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
habeIchVergessen
DD-WRT User


Joined: 04 May 2010
Posts: 431

PostPosted: Thu Jan 19, 2023 22:47    Post subject: Reply with quote
hardware: ea8500
software: 51440

webupgrade from 50308

issues:
- ipv4 ssh connection refused (ipv6 works)

syslog output (no password auth line for ipv4)
Code:

Jan 19 23:36:35 router authpriv.info dropbear[12166]: Child connection from 192.168.xx.xx:xxxxx
Jan 19 23:36:50 router authpriv.info dropbear[12171]: Child connection from fe80::xxx:xxx:xxx:xxx%br0:xxxxx
Jan 19 23:36:53 router authpriv.notice dropbear[12171]: Password auth succeeded for 'root' from fe80::xxx:xxx:xxx:xxx%br0:xxxxx
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1952

PostPosted: Fri Jan 20, 2023 0:52    Post subject: Reply with quote
Alozaros wrote:
dale_gribble39 wrote:
Well, the source of the report is questionable in my opinion, to say the least, anyway. Thank you for your confirmation of no bug related to that, mac913.


well... i had a quick look and here what i ve found:

i have web access https only, no remote access enabled on this unit:



so, every time i go to GUI Administration>Management page and hit save and than apply,
remote https becomes enabled, than if i do a nvram set .... manually revert it to 0 than, nvram commit (or even reboot), on check its 0, on save apply on this page it comes back to 1....

root@1043NDv2:~# nvram show | grep remote_mgt_https=
remote_mgt_https=1
root@1043NDv2:~# nvram set remote_mgt_https=0
root@1043NDv2:~# nvram commit
root@1043NDv2:~# nvram show | grep remote_mgt_https=
remote_mgt_https=0

root@1043NDv2:~# nvram show | grep remote_mgt_https=
remote_mgt_https=1

I guess, same happens for the rest units i have...what ever i enter on this page, and i dont do it very often.... on save apply it triggers remote_mgt_https=1 no idea since when... Rolling Eyes
I also tend to carry same setup forward and no reset or manually rebuild, unless is needed...so, no idea when the glitch happened... Rolling Eyes

This may be by design and has always been this way (?). Still have not reviewed code to see.

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
BrainSlayer
Site Admin


Joined: 06 Jun 2006
Posts: 7492
Location: Dresden, Germany

PostPosted: Fri Jan 20, 2023 6:47    Post subject: Reply with quote
dale_gribble39 wrote:
Alozaros wrote:
errors: For some odd reason...I keep seen remote_mgt_https=1 comes enabled by default on all my routers...and its not enabled in the GUI...by default ...so check yours Razz

This might be a glitch in ssh remote being enabled. Or not. Just a guess. I haven't reviewed any code.


its disabled by default. thats a fact. ssh is disabled too by default. it its enabled by default on yours you have issue in your network (trojan horse/virus) or you dont use my firmware or a firmware published on our website

_________________
"So you tried to use the computer and it started smoking? Sounds like a Mac to me.." - Louis Rossmann https://www.youtube.com/watch?v=eL_5YDRWqGE&t=60s
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5700

PostPosted: Fri Jan 20, 2023 8:00    Post subject: Reply with quote
I do not have a problem, settings are default on Administration -> Management tab, but can easily replicate.

Simply copy Alozaros screenshot: uncheck Web Access HTTP, check HTTPS, disable Info Site, Save and Apply.

nvram show | grep remote_mgt
size: 27693 bytes (103379 left)
remote_mgt_ssh=0
remote_mgt_telnet=0
remote_mgt_https=1

Edit note, checked dmesg again and it appears r51440 EA8500 vanilla firmware is still crashing since r50963.

Two additional crashes are results of making changes to replicate Alozaros settings, save & apply then revert.

Edit note 2 Web UI Management (remote_management=0) remained disabled the entire time during the test.
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6446
Location: UK, London, just across the river..

PostPosted: Fri Jan 20, 2023 9:02    Post subject: Reply with quote
Thanks blkt !

P.S. BS its not a trojan...but a small glitch...!

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
whitebeard
DD-WRT User


Joined: 26 Jul 2013
Posts: 121
Location: Canada

PostPosted: Fri Jan 20, 2023 13:45    Post subject: Reply with quote
For what it's worth Netgear R7500v2 here with:
- Web UI Management: Disabled
- SSH Management: Disabled

nvram show | grep remote_
remote_mgt_ssh=0
remote_mgt_telnet=0
remote_mgt_https=0
remote_ip_any=1
remote_ip=0.0.0.0 0
remote_management=0
klancy22
DD-WRT Novice


Joined: 06 Aug 2022
Posts: 2

PostPosted: Fri Jan 20, 2023 17:24    Post subject: Reply with quote
Hardware: R7800
Webupgrade from r49626
Reset: No

Issues:
1. Cannot SSH into my router. Same problem as habeIchVergessen stated. Can't connect with IPv4. Haven't tried IPv6.
SSH daemon enabled. SSH TCP Forwarding disabled. Password Login disabled. Added two ssh keys. Worked fine before the update.

habeIchVergessen wrote:
hardware: ea8500
software: 51440

webupgrade from 50308

issues:
- ipv4 ssh connection refused (ipv6 works)

syslog output (no password auth line for ipv4)
Code:

Jan 19 23:36:35 router authpriv.info dropbear[12166]: Child connection from 192.168.xx.xx:xxxxx
Jan 19 23:36:50 router authpriv.info dropbear[12171]: Child connection from fe80::xxx:xxx:xxx:xxx%br0:xxxxx
Jan 19 23:36:53 router authpriv.notice dropbear[12171]: Password auth succeeded for 'root' from fe80::xxx:xxx:xxx:xxx%br0:xxxxx


2. DNS not available after reboot.

3. Router can not update time because DNS doesn't work. Using 0.europe.pool.ntp.org as ntp server. In Administration -> Commands tab run command `ping -c 3 google.com` returns 'bad host google.com', something like that.

If I understand correctly DNS probably doesn't work because router has wrong time. And it can't update time because DNS doesn't work. Might be wrong here though.

What helps is uncheck 'Use dnsmasq for DNS' in DHCP options. Time updates and DNS works. Then I can check 'Use dnsmasq for DNS' again and all works fine.

Static DNS in DHCP Settings:
208.67.222.222
1.1.1.1
8.8.8.8

Dnsmasq settings:
Encrypt DNS disabled
Cache DNSSEC Data enabled
Validate DNS Replies (DNSSEC) enabled
Check Unsigned DNS Replies enabled
No DNS Rebind enabled
Query DNS in Strict Order enabled
Add Requestor MAC to DNS Query disabled
RFC4039 Rapid Commit Support disabled
Additional options:
Code:
domain-needed
bogus-priv
no-negcache
filterwin2k
no-resolv
all-servers
address=/.site.local/192.168.1.123
server=208.67.220.220
server=208.67.222.222
server=9.9.9.9
server=1.1.1.1
server=8.8.8.8
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12914
Location: Netherlands

PostPosted: Fri Jan 20, 2023 17:47    Post subject: Reply with quote
SSH has been updated, if you have trouble connecting with SSH then download the latest Putty and make sure under SSH/Host keys to move ed25519 to the top and untick "Prefer Algorithms for which a host key is known" or forget your known HOST keys (the fingerprints) from your client.

If you have trouble connecting with WinSCP under Tools/Clean up Clear Cache.

You have a DNS/NTP catch 22 situation because you are using "secure DNS" which needs current time

In your case set IP addresses as NTP server, but frankly your DNS settings needs some attention (what is the use of setting Static DNS as you are using no-resolv?, Query DNS in strict order is not very useful etc.)

If you want proper secure DNS see: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=323896

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Goto page Previous  1, 2, 3, 4, 5  Next Display posts from previous:    Page 2 of 5
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum