[Full-disclosure] Authentication Issue DD-WRT



Hi,
Does anyone noticed that to authenticate in any wireless router running
DD-WRT firmware (lastest version), it only check the first 8 characters of
the password???
E.g. you can set the root password to yellowmonkey123@123 and when you try
to authenticate with yellowmonkey@blablabla ... got root!
Some other firmware users noticed and reported to the developer, but no
action was taken.
It´s a excelent firmware to use with linksys routers, many extras resources,
etc, but not from the security point of view.
[]´s
João Castilho
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • Re: Serious issue with SATA disks again
    ... you might want to try flashing the firmware for the ... controller/motherboard with the lastest versions. ... got up to the lastest firmware. ...
    (freebsd-questions)
  • Re: Compressed firmware?
    ... It seems quite a decent percent. ... Maybe I can't find any characters because the contents are encrypted? ... First thing to try is see if the firmware uses some random permuted bit ordering. ... Hiding any plaintext by XOR tricks is not uncommon in firmware. ...
    (comp.compression)
  • Re: NetscreenOS + 5XP
    ... Ginger wrote: ... 3.0.0r2.0 and I am after upgrading it to the lastest version. ... You can get the firmware from them. ...
    (comp.security.firewalls)
  • Re: NetscreenOS + 5XP
    ... Ginger wrote: ... 3.0.0r2.0 and I am after upgrading it to the lastest version. ... You can get the firmware from them. ...
    (comp.security.firewalls)