• February 24, 2025, 02:52:39 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: HNAP Vulnerability - Which Firmware Version is "Safe"?  (Read 4158 times)

GreenApple

  • Guest
HNAP Vulnerability - Which Firmware Version is "Safe"?
« on: February 02, 2010, 06:04:12 PM »

Which version of the firmware is "Safe" from the HNAP vulnerability?

I have version A1 of the DIR-825 with the original 1.01 firmware.  I have been reading the forums for over six months waiting for a stable firmware that the community agrees on.  I understand that there may still be some issues with v1.13 (such as reporting wireless clients) but is this the only version that prevents the HNAP issue?  If so, it may be time to upgrade.

Thanks for your help.

Logged

user11

  • Level 2 Member
  • **
  • Posts: 62
Re: HNAP Vulnerability - Which Firmware Version is "Safe"?
« Reply #1 on: February 02, 2010, 09:24:58 PM »

There is probably a POC out that you can do your own testing with to see for yourself if 1.01 is safe http://www.sourcesec.com/Lab/dlink_hnap_captcha.pdf I think the captcha addition in 1.10 was attempting to address the HNAP weakness, but even with the captcha it has been proven to be insecure. Firmware 1.13 claims to be secure, but also comes with many bugs. Many who refuse to update from 1.01 for obvious reasons, say the HNAP problem is only LAN side, but you risk visiting a webpage with scripts trying to run LAN side exploiting it and taking over your router remotely. So bugs(1.13)...or risk exploitation(1.0x-1.12)...it may take a long while to get back to the stability that 1.0x firmwares provide, but at least with 1.13 you know it's safe.
« Last Edit: February 05, 2010, 11:09:37 AM by user11 »
Logged
DIR-825 A1 F/W 1.13NA
TRENDnet TEW-652BRP V1.1R F/W DD-WRT v24 build 14896
Netgear FWG114Pv1 F/W 2.0r18