Yes. It's my login. This is not usual login for bruteforce password lists so I'm wondering how it was matched on first tryIs the user "honza" legit?
Is this really fix?380.65 / 380.4180:
- Fixed a security vulnerability regarding XSS.
- Fixed a security vulnerability regarding CSRF.
- Added protection for Brute-force attack.
And my login and password was stolen as readable or just used hashed?Is this really fix?
Should I completely wipe my nvram and storage before install?
Odesláno z mého SM-G935F pomocí Tapatalk
And my login and password was stolen as readable or just used hashed?
Odesláno z mého SM-G935F pomocí Tapatalk
At this moment in time you'd have to assume that they're retrieving them from the router's NVRAM. So they're not hashed, they're plain text!And my login and password was stolen as readable or just used hashed?
So they're not hashed, they're plain text!
380.65 / 380.4180:
- Fixed a security vulnerability regarding XSS.
- Fixed a security vulnerability regarding CSRF.
- Added protection for Brute-force attack.
I hope the Asus guys will take this one serious. Could potentially be a 'Linksys sized' issue.Asus fixed some security issues in 380.4180, and I fixed an additional security issue on my own. However I have no way of knowing if any of these fixes from either Asus or myself will cover the recent incident.
In any case, I forwarded what info I had to Asus, and will proceed with backporting all of these fixes in a 380.64_1 release. I just need time to compile and test all of those firmwares (the new PC parts can't get here soon enough!).
Just as an FYI...
hulk says smash - I'm going in thru a Chromebook of all things...
Guest Network enabled... we're going thru the web interface...
I'm posting on the same connection - yes, the unauthenticated connection on the router...
I will not disclose publicly how this was done - but I've access to the HTTP server, and since it runs as root, I've got root..
View attachment 8178
If there are any forum members also in the San Diego, CA area - I'd like to borrow your router for a couple of days...
I can loan you another AC1900 class router in the interim...
PM me if you want to help out...
try latest AsusWRT 4180, open webui to wan and watch log.Is this really fix?
Should I completely wipe my nvram and storage before install?
Odesláno z mého SM-G935F pomocí Tapatalk
Welcome to the club. Just read through the whole thread to prevent duplicate questions etc.Yay! Me too hacked
Running latest stock with WAN access enabled.Welcome to the club. Just read through the whole thread to prevent duplicate questions etc.
And this one as well: http://www.snbforums.com/posts/300280/
Running stock or Merlin?
You might want to close your WAN access ASAP. Other steps are explained in this thread and the Merlin thread.Running latest stock with WAN access enabled.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!