02-07-2012 09:37 PM
Sap2543 wrote:"Linksys will post a wonderful fix" - wonderful would be sooner than at least 3 months - like how about tomorrow or by Friday?
If linksys doesn't like the posts then delete them but folks are not happy with the timetable. A friend of mine bought a linksys router the other day. I asked him which one and looked it up and sure enough, it has WPS and the 8 digit pin on the bottom. I asked him if he knew it could be hacked with Reaver and I told him the soonest it could be patched was in April. He was not too happy about that and said he would not have purchased the router if he had known. Of course, Cisco doesn't want to tell anybody so consumers can make the right decision. What about a consumer notice about it Cisco or better yet a recall from the stores until they are patched? OK, I'm stuck with this router with a hole but selling them and not telling folks about the WPS vulnerability is just no good.
And finally, "the fix will be good and all will be right with the world once again"? Maybe you haven't been keeping scored but the hackers and crooks are having a field day out in the real world. I know you mean well but every level of computer security is very serious business.
Yeah...that post was in very poor taste sarcasm since my previous post and a couple others' posts magically vanished!

02-27-2012 04:51 AM
Have you tried reading their knowledgebase? This might help you guys.
http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&articl
02-27-2012 07:07 AM
Brenda wrote:Have you tried reading their knowledgebase? This might help you guys.
http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&articl
eid=25154
Yes that is a sticky at top.
03-01-2012 11:08 AM
Cisco has begun releasing new firmware (for the E4200 v1 anyway) to address the WPS Vulnerability.
03-01-2012 11:16 AM
03-01-2012 12:09 PM - edited 03-01-2012 12:10 PM
counsil wrote:Cisco has begun releasing new firmware (for the E4200 v1 anyway) to address the WPS Vulnerability.
Download Link for Latest E4200 v1 Firmware
Thanks!
FTW:
==================================================
Last Release Date: Feb 21, 2012
Last Firmware version: 1.0.04 (build 11)
- Added Enabled/Disabled feature for Wi-Fi Protected Setup in the web configuration
- Added WPS lockdown feature
- Fixed Linux kernel IPv6 fragment identification remote Denial-of-Service vulnerability
- Fixed Router cannot get a WAN IP address form some ISP
- Fixed Internet Access Policy issue when disabling Parental Control
- Fixed some minor bugs
==================================================
Downloading now ...
- Dave
03-02-2012 05:02 PM
My understanding is this fix is not really a fix at all but a stopgap measure in a sense. All it does is turn off WPS capability. So from now on WPS is a thing of the past I guess. Not good news for less techno savvy purchases of LInksys routers.
03-02-2012 05:08 PM - edited 03-02-2012 05:10 PM
You have the choice to turn WPS off, or, if you leave it on, they implemented a lockdown (i.e. after x failed attempts and/or timeouts between attempts). The E4200 v2 already has WPS lockdown functionality built-in.
03-02-2012 05:26 PM
The E4200 both versions are susceptible to the WPS security breech with stock firmware. I don't know about after this new firmware upgrade. Even though WPS was turned off it was still vulnerable previously.
03-02-2012 05:34 PM
The latest firmware for the E4200 v1 implemented two features:
1.) WPS lockdown (if you leave WPS turned on)
2.) Ability to turn WPS off (completely)
The latest firmware for the E4200 v2 already has some sort of WPS lockdown functionality as folks have spent days trying to crack WPS without success. Reaver could always get lucky, but I still haven't seen anyone post where they successfully cracked an E4200 v2 with Reaver. After so many attempts the E4200 v2 starts timing out being attempts (like hours between each attempt).