• May 20, 2025, 03:24:07 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: HNAP Status  (Read 12080 times)

DU7

  • Level 1 Member
  • *
  • Posts: 2
HNAP Status
« on: January 25, 2010, 06:38:48 AM »

What is the status of the HNAP issue mentioned in:

http://forums.dlink.com/index.php?topic=10458.0

A search didn't turn up any updates other than locked threads. If there is a current thread that gives status updates, would appreciate a pointer.

At present, I don't see any new firmware listed on the support page for the 655.

Has new firmware been released to address the issue?

If not, what is the current ETA for a fix?

Would also appreciate a statement from Dlink about what router models are impacted, etc. (since the various postings on security sites have been updated to include additional models than what was originally posted at said sites).

Thank you.
Logged

Cobra

  • Level 4 Member
  • ****
  • Posts: 477
Re: HNAP Status
« Reply #1 on: January 25, 2010, 07:05:43 AM »

Firmware has been released...look in the beta section.
Logged

thecreator

  • Level 6 Member
  • *
  • Posts: 795
Re: HNAP Status
« Reply #2 on: January 25, 2010, 01:07:58 PM »

What is the status of the HNAP issue mentioned in:

http://forums.dlink.com/index.php?topic=10458.0

A search didn't turn up any updates other than locked threads. If there is a current thread that gives status updates, would appreciate a pointer.

At present, I don't see any new firmware listed on the support page for the 655.

Has new firmware been released to address the issue?

If not, what is the current ETA for a fix?

Would also appreciate a statement from Dlink about what router models are impacted, etc. (since the various postings on security sites have been updated to include additional models than what was originally posted at said sites).

Thank you.

Hi DU7,

HNAP Firmware has no problems or security risks.

HNAP Protocol was written by Pure Networks. Whether or not D-Link employed the protocol was up to them.

HNAP Protocol was to allow Network Magic to work with the D-Link Routers.

I use Network Magic, so I don't see any Security Risks.

It is up to the individual user. Once you install the newer firmware, you can't go back to the original Firmware.

I think that maybe from Cisco / Linksys stated the problem with the HNAP, in order to get D-Link to stop using that HNAP Protocol. (Just my opinion.) Because Cisco acquired Pure Networks.

 
Logged
thecreator - Running a Verizon FIOS / Fios-G1100 Router into a D-Link DIR-859 Router Rev. A3, Firmware 1.03 and a D-Link DWA-552 Wireless Network PCI Adapter Card. OP Sys: Win 10 Pro - DNS-323 with Firmware 1.10

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: HNAP Status
« Reply #3 on: January 25, 2010, 02:52:05 PM »

Also, HNAP isn't a full fledged exploit. It is only useable from inside the LAN.
Logged
DIR-655 H/W: A2 FW: 1.33

Lycan

  • Administrator
  • Level 15 Member
  • *
  • Posts: 5335
Re: HNAP Status
« Reply #4 on: January 25, 2010, 05:00:15 PM »

Either way we've closed it for good and we're doing so in good faith.

The internet has a way of blowing things out of proportion
Logged

DU7

  • Level 1 Member
  • *
  • Posts: 2
Re: HNAP Status
« Reply #5 on: January 26, 2010, 04:17:52 AM »

Thanks for the responses.

As best I can tell the beta code is  'use at your own risk' and isn't an official release, at least at this point.

Is there an ETA when the official, supported version will be released?

Logged

sideloaded2

  • Level 1 Member
  • *
  • Posts: 5
Re: HNAP Status
« Reply #6 on: January 26, 2010, 05:01:31 PM »

Right and your superiors would've made you fix the exploit right away even if the internet didn't blow it out of proportion.  ::)
Logged

lotacus

  • Level 4 Member
  • ****
  • Posts: 450
Re: HNAP Status
« Reply #7 on: January 26, 2010, 05:21:56 PM »

Really. I mean, come on. how long has the router been in production? and it's just made public that there is a "small" exploit and everyone is all on their toes yelling and screaming like their entire lives are going to be swallowed up by some evil-doer.

What about this, did you know that your household dead bolts, your car locks, your bike locks and anything you "lock" up have exploits as well? Everything you lock up isn't safe!! security through obscurity thats all everything is.

I'm suprised that people are not yelling to remove WEP from routers because it's so easy to crack. Or that some other method should be integrated into the routers kernel to prevent rogue ap's. How does one know if they are REALLY connecting to their AP? Just because it has your SSID?
Logged

Lycan

  • Administrator
  • Level 15 Member
  • *
  • Posts: 5335
Re: HNAP Status
« Reply #8 on: January 27, 2010, 10:13:31 AM »

More importantly, if someone already has access to your LAN your security is compromised.
Logged

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: HNAP Status
« Reply #9 on: January 27, 2010, 12:00:54 PM »

How about using Windows (any version)?  ;D
Logged
DIR-655 H/W: A2 FW: 1.33

sideloaded1

  • Level 1 Member
  • *
  • Posts: 21
Re: HNAP Status
« Reply #10 on: January 27, 2010, 09:26:48 PM »

Right so any security hole shouldn't be fixed because your LAN is already compromised. Also do you think exploits aren't parleyed on top of each other? What if a new exploit used this hole like a dns rebind attack?  ;)
Logged

lizzi555

  • Level 5 Member
  • *****
  • Posts: 605
Re: HNAP Status
« Reply #11 on: January 27, 2010, 11:14:09 PM »

Right so any security hole shouldn't be fixed because your LAN is already compromised. Also do you think exploits aren't parleyed on top of each other? What if a new exploit used this hole like a dns rebind attack?  ;)

More than 7 proxies and a new netgear router with DD-WRT and still full of fear ?
You should shut down your internet connection,  perhaps you feel more safe then.

Logged

sideloaded1

  • Level 1 Member
  • *
  • Posts: 21
Re: HNAP Status
« Reply #12 on: January 28, 2010, 06:27:37 AM »

nah ill just use 14 proxies now.
Logged

Cobra

  • Level 4 Member
  • ****
  • Posts: 477
Re: HNAP Status
« Reply #13 on: January 28, 2010, 07:09:45 AM »

It is pretty easy anymore for network admins or websites to see the real IP of someone using a proxy.  :D

Do a search for proxy to real IP if you do not believe me.
Logged

Lycan

  • Administrator
  • Level 15 Member
  • *
  • Posts: 5335
Re: HNAP Status
« Reply #14 on: January 28, 2010, 08:27:43 AM »

Ok. This thread is done.
It's gone way off course. I'm locking it. Sideloaded and any other alt, proxy or not will continue to be banned and have the posts deleted.
Logged