Am I correct that this is only a problem if you&#39;re doing remote administration via HTTPS?<br><br>For instance, I have a dd-wrt router at home, but it is only accessable via http on the internal ports.<br><br>-dc<br><br>
<div class="gmail_quote">On Thu, Dec 23, 2010 at 1:23 PM, Barry Von Ahsen <span dir="ltr">&lt;<a href="mailto:barry@vonahsen.com">barry@vonahsen.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">
you can download the code here:<br>
<br>
<a href="http://code.google.com/p/littleblackbox/" target="_blank">http://code.google.com/p/littleblackbox/</a><br>
<br>
then it&#39;s in an sqllite db file in bin - it&#39;s mostly DD-WRT<br>
<br>
&quot;Cisco&quot;,&quot;6&quot;<br>
&quot;D-Link&quot;,&quot;4&quot;<br>
&quot;DD-WRT&quot;,&quot;6524&quot;<br>
&quot;Linksys&quot;,&quot;16&quot;<br>
&quot;Netgear&quot;,&quot;2&quot;<br>
<br>
vendors and models posted here:<br>
<br>
<a href="http://pastebin.com/cbhUZ7HZ" target="_blank">http://pastebin.com/cbhUZ7HZ</a><br>
<br>
vendors and firmware here:<br>
<br>
<a href="http://pastebin.com/uyzjh4yw" target="_blank">http://pastebin.com/uyzjh4yw</a><br>
<br>
<br>
<br>
-barry<br>
<div class="im"><br>
<br>
<br>
<br>
Nathan C. Smith wrote:<br>
&gt; Josh,<br>
&gt;<br>
&gt; thanks for pointing this out.  Is there a plain listing of suspect manufacturers/devices somewhere?<br>
&gt;<br>
&gt; -Nate<br>
&gt;<br>
&gt; From: <a href="mailto:cialug-bounces@cialug.org">cialug-bounces@cialug.org</a> [mailto:<a href="mailto:cialug-bounces@cialug.org">cialug-bounces@cialug.org</a>] On Behalf Of Josh More<br>
&gt; Sent: Thursday, December 23, 2010 10:09 AM<br>
&gt; To: <a href="mailto:cialug@cialug.org">cialug@cialug.org</a><br>
&gt; Subject: [Cialug] DD-WRT (and others) Risk<br>
&gt;<br>
&gt; Since we still have a list right now, and since I know that tomorrow is a down day for everyone with no obligations other than reading and responding to security threats, I thought I&#39;d share this link:  <a href="http://seclists.org/fulldisclosure/2010/Dec/492" target="_blank">http://seclists.org/fulldisclosure/2010/Dec/492</a><br>

&gt;<br>
&gt; Nutshell version:  If you&#39;re running DD-WRT, you might want to roll your own self-signed cert.  If you&#39;re running one of the others in the DB, you&#39;re probably out of luck.  If you typically have to analyze SSL traffic for fun or profit, merry Christmas.<br>

&gt;<br>
&gt;<br>
&gt; Josh More | Senior Security Consultant - CISSP, GIAC-GSLC, GIAC-GCIH<br>
</div>&gt; Alliance Technologies | <a href="http://www.AllianceTechnologies.net" target="_blank">www.AllianceTechnologies.net</a>&lt;<a href="http://www.alliancetechnologies.net" target="_blank">http://www.alliancetechnologies.net</a>&gt;<br>

<div class="im">&gt; 400 Locust St., Suite 840 | Des Moines, IA 50309<br>
&gt; 515.245.7701 | 888.387.5670 x7701<br>
&gt;<br>
&gt; Santa is Secure.  Are you?<br>
&gt; <a href="http://www.alliancetechnologies.net/security/santa-2010" target="_blank">http://www.alliancetechnologies.net/security/santa-2010</a><br>
&gt;<br>
&gt; How are we doing? Let us know here:<br>
&gt; <a href="http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey" target="_blank">http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey</a><br>
&gt;<br>
&gt;<br>
&gt;<br>
</div>&gt; ------------------------------------------------------------------------<br>
&gt;<br>
&gt; _______________________________________________<br>
&gt; Cialug mailing list<br>
&gt; <a href="mailto:Cialug@cialug.org">Cialug@cialug.org</a><br>
&gt; <a href="http://cialug.org/mailman/listinfo/cialug" target="_blank">http://cialug.org/mailman/listinfo/cialug</a><br>
<br>
_______________________________________________<br>
Cialug mailing list<br>
<a href="mailto:Cialug@cialug.org">Cialug@cialug.org</a><br>
<a href="http://cialug.org/mailman/listinfo/cialug" target="_blank">http://cialug.org/mailman/listinfo/cialug</a><br>
</blockquote></div><br>