Reply
somms
Posts: 129
Registered: ‎03-20-2008

Re: Urgent: WPS vulnerability fix ETA?


Sap2543 wrote:

"Linksys will post a wonderful fix" - wonderful would be sooner than at least 3 months - like how about tomorrow or by Friday?

 

If linksys doesn't like the posts then delete them but folks are not happy with the timetable.  A friend of mine bought a linksys router the other day.  I asked him which one and looked it up and sure enough, it has WPS and the 8 digit pin on the bottom.  I asked him if he knew it could be hacked with Reaver and I told him the soonest it could be patched was in April.  He was not too happy about that and said he would not have purchased the router if he had known.  Of course, Cisco doesn't want to tell anybody so consumers can make the right decision.  What about a consumer notice about it Cisco or better yet a recall from the stores until they are patched?  OK, I'm stuck with this router with a hole but selling them and not telling folks about the WPS vulnerability is just no good.

 

And finally, "the fix will be good and all will be right with the world once again"?  Maybe you haven't been keeping scored but the hackers and crooks are having a field day out in the real world.  I know you mean well but every level of computer security is very serious business.


Yeah...that post was in very poor taste sarcasm since my previous post and a couple others' posts magically vanished!



FTTH

Member of the Professional Aviation Safety Specialists Union!
Brenda
Posts: 585
Registered: ‎07-01-2006

Re: Urgent: WPS vulnerability fix ETA?

Have you tried reading their knowledgebase? This might help you guys.

http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&articleid=25154

__________________________________________________
Yesterday is history. Tomorrow is mystery. Today is a gift.
sabretooth
Posts: 4,382
Registered: ‎11-11-2008

Re: Urgent: WPS vulnerability fix ETA?


Brenda wrote:

Have you tried reading their knowledgebase? This might help you guys.

http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&articleid=25154


Yes that is a sticky at top. 

counsil
Posts: 88
Registered: ‎04-02-2009

Re: Urgent: WPS vulnerability fix ETA?

Cisco has begun releasing new firmware (for the E4200 v1 anyway) to address the WPS Vulnerability.

 

Download Link for Latest E4200 v1 Firmware

Gonzoatlarge
Posts: 13
Registered: ‎01-22-2012

Re: Urgent: WPS vulnerability fix ETA?

too little too late.....
ViperGeek
Posts: 3
Registered: ‎01-27-2012

Re: Urgent: WPS vulnerability fix ETA?

[ Edited ]

counsil wrote:

Cisco has begun releasing new firmware (for the E4200 v1 anyway) to address the WPS Vulnerability.

 

Download Link for Latest E4200 v1 Firmware


Thanks!  

 

FTW:

 

===========================================================================
Last Release Date: Feb 21, 2012
Last Firmware version: 1.0.04 (build 11)

- Added Enabled/Disabled feature for Wi-Fi Protected Setup in the web configuration
- Added WPS lockdown feature
- Fixed Linux kernel IPv6 fragment identification remote Denial-of-Service vulnerability
- Fixed Router cannot get a WAN IP address form some ISP
- Fixed Internet Access Policy issue when disabling Parental Control
- Fixed some minor bugs

===========================================================================

 

Downloading now ...

 

- Dave

donfm
Posts: 12
Registered: ‎02-29-2012

Re: Urgent: WPS vulnerability fix ETA?

My understanding is this fix is not really a fix at all but a stopgap measure in a sense. All it does is turn off WPS capability. So from now on WPS is a thing of the past I guess. Not good news for less techno savvy purchases of LInksys routers.

counsil
Posts: 88
Registered: ‎04-02-2009

Re: Urgent: WPS vulnerability fix ETA?

[ Edited ]

You have the choice to turn WPS off, or, if you leave it on, they implemented a lockdown (i.e. after x failed attempts and/or timeouts between attempts).  The E4200 v2 already has WPS lockdown functionality built-in.

donfm
Posts: 12
Registered: ‎02-29-2012

Re: Urgent: WPS vulnerability fix ETA?

The E4200 both versions are susceptible to the WPS security breech with stock firmware. I don't know about after this new firmware upgrade. Even though WPS was turned off it was still vulnerable previously.

counsil
Posts: 88
Registered: ‎04-02-2009

Re: Urgent: WPS vulnerability fix ETA?

The latest firmware for the E4200 v1 implemented two features:

 

1.)  WPS lockdown (if you leave WPS turned on)

2.)  Ability to turn WPS off (completely)

 

The latest firmware for the E4200 v2 already has some sort of WPS lockdown functionality as folks have spent days trying to crack WPS without success.  Reaver could always get lucky, but I still haven't seen anyone post where they successfully cracked an E4200 v2 with Reaver.  After so many attempts the E4200 v2 starts timing out being attempts (like hours between each attempt).