Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

NETGEAR DGN1000 vulnerable #27

Closed
monga opened this issue Jan 3, 2014 · 7 comments
Closed

NETGEAR DGN1000 vulnerable #27

monga opened this issue Jan 3, 2014 · 7 comments

Comments

@monga
Copy link

monga commented Jan 3, 2014

I can confirm the vulnerability on this model (Firmware Version V1.1.00.46_ww).

Thank you for your work.

@elvanderb
Copy link
Owner

Thank you, I updated the list :)
Do you know if there is any difference between your router and the other DGN1000 mentionned in the readme?

@monga
Copy link
Author

monga commented Jan 3, 2014

No, I don't, sorry: they are very likely to be the same. I've sent the issue message just to document also the firmware version.

@elvanderb
Copy link
Owner

Ok, thank you :)

@stirech
Copy link

stirech commented Feb 14, 2014

Has anyone found a alternative firmware that can be applied. DD-WRT? Open WRT & Tomato don't have firmware for this router. I have tried to block the port using exiting firmware without success.

@zmaile
Copy link

zmaile commented Apr 7, 2014

I brought this issue up with netgear support (2014/01/17), and just in the last few days they have released a new firmware version that resolves the port 32764 issue. The new firmware is available on their website (http://downloadcenter.netgear.com/other/)

I've confirmed that the below version works correctly.
http://www.downloads.netgear.com/files/GDC/DGN1000/DGN1000-V1.1.00.49WW.zip

If the original backdoor was a planned 'feature', then its possible that there is a knocking sequence required to unlock port 32764 (that is, port 32764 opens after trying port 5000, then 8000 before 32764 as an example).

@elvanderb
Copy link
Owner

I'll have a look, thank you :)

@elvanderb
Copy link
Owner

Oh god :')
Expect some lolz in the next few days :)

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants