New Zealand ADSL Mailing List


DSL-500/504 SNMP Security Problem

From: Regan Murphy <regan.murphy_at_oasystems.co.nz>
Date: Mon, 4 Aug 2003 19:05:21 +1200
Message-ID: <A4C042FF77ABFA4BAAF465910AA06B2B448C7A@sabre.oasystems.co.nz>

Thought a subject change was appropriate here.

I am assuming that the DSL-500 is the same as the DSL-504 and you should
be able to remove all SNMP access using the CLI interface (via Serial or
Telnet connection). Obviously not a simple solution for the average
home user, but a valid workaround nonetheless.

CLI command is as follows:

>snmp access flush

Other CLI commands available:

Check the CLI command reference available on the following page:
http://www.thecaretaker.org.uk/routers/dsl504/dsl504.htm

--
Regards,
Regan	
-----Original Message-----
From: Robert McDonald [mailto:rob@nzpages.net] 
Sent: Monday, 4 August 2003 4:39 p.m.
To: d simak; Chris Day
Cc: Regan Murphy; adsl@lists.unixathome.org
Subject: Re: which modem is best (Linux)
dont go with the DSL-500
It has VERY nasty backdoors in the firmware (eg, you can rip out
someones 
username and password using SNMP management. And its not firewalled to
the 
internal interface only. It only takes a quick nmap of an ISPs DSL
network 
and you'll find lots.
Dlink said they fixed the problem with a firmware update. But they lied
(or at 
least didn't tell all of the truth)
Cheers,
Rob
On Mon, 04 Aug 2003 14:12, d simak wrote:
> Hi Reagan Chris & everone else ..
>
> so whats the verdict PCI / external ... i did some reading through 
> past months lists and got alarmed and confused by the PPPoA stuff
>
> how about the Dlink DSL-500 ?
>
> Thanks in advance
> Dean
>
> On Mon, 2003-08-04 at 13:23, Chris Day wrote:
> > Good point:
> > - last time I looked at PCI cards under Linux, ran into PPPoA issues
> > - the Linux drivers for the cards we were testing were only 1/2 
> > written - the initial email also indicated 2x nics so assumed this 
> > was a preference
> > - the old story, if you assume you make an ass-u-me - should have
known
> > better - OK, will shut up now...
> >
> >
> > Surely an internal PCI ADSL modem would be the easiest to set up for
> > this purpose.  You don't need to mess around with VPNs and NAT and 
> > other nasty things - the PCI card should appear as an eth interface 
> > and should be assigned the real world ip address.  I imagine it 
> > would also be the cheapest option too?  As for performance and speed
> > PCI Card vs Router might be an issue though as I remember arguments 
> > about quality and power consumption etc.
> >
> > --
> >
> > On Mon, 2003-08-04 at 10:47, Chris Day wrote:
> > > Suggest you keep it simple as far as hardware is concerned and use
> > > the
> > >
> > > power of Linux to take care of routing, firewall, etc. Products 
> > > like DSL500 or DSE XH1149 in 1/2 bridge mode (so real world IP 
> > > ends up at your box) are the shot (even an old Nokia Ni500 would 
> > > probably do). You don't need fancy things like NAT/NAPT, ports, 
> > > etc - leave Linux to
> > >
> > > do all that. All you need is something to take ADSL off the phone 
> > > line
> > >
> > > and present it to your inbound (WAN) 10/100Mbps UTP NIC port - and
> > > if hardware only runs at 10Mbps, thats no problem either - ADSL is
> > > simply
> > >
> > > not that fast.
> > >
> > > Now if it was a Win box, I'd be looking for some form of hardware 
> > > firewall...
> > >
> > > Rgds, Chris...
> > >
> > > -----Original Message-----
> > > From: d simak [mailto:greylake@spunge.org]
> > > Sent: Monday, August 04, 2003 10:29 AM
> > > To: adsl@lists.unixathome.org
> > > Subject: which modem is best (linux)
> > >
> > >
> > > Hello all ,
> > >
> > > I am new to ADSL,and do not yet have a connection,i wish to know 
> > > what available modems will work best with my Linux Box which will 
> > > have two nics and perform firewall nat etc for the lan and any 
> > > other helpfull advice.
> > >
> > > Thanks in advance
> > > Dean
> > >
> > > --
> > > This message is part of the NZ ADSL mailing list.
> > > see http://unixathome.org/adsl/ for archives, FAQ,
> > > and various documents.
> > > To unsubscribe: send mail to majordomo@lists.unixathome.org with 
> > > "unsubscribe adsl" in the body of the message
> >
> > --
> > This message is part of the NZ ADSL mailing list.
> > see http://unixathome.org/adsl/ for archives, FAQ,
> > and various documents.
> > To unsubscribe: send mail to majordomo@lists.unixathome.org with 
> > "unsubscribe adsl" in the body of the message
-- 
--------------
Robert McDonald
NZPages.Net Web Services
Ph: 021 1770061
ICQ: 86984875
http://www.nzpages.net
-- 
This message is part of the NZ ADSL mailing list. 
see http://unixathome.org/adsl/ for archives, FAQ, 
and various documents. 
To unsubscribe: send mail to majordomo@lists.unixathome.org 
with "unsubscribe adsl" in the body of the message 
 
Received on Mon Aug 4 19:05:29 2003

This archive was generated by hypermail 2.2.0 : Thu Nov 30 11:48:26 2006 EST