Outline ·
[ Standard ] ·
Linear+
TIME [OFFICIAL] TIME Fibre Broadband™ v3.o, 500 Mbps of rocket science
|
cherroy
|
Sep 23 2017, 11:47 AM
|
20k VIP Club
|
QUOTE(jjj2 @ Sep 23 2017, 09:12 AM) D-LINK DIR850L ROUTER -- FIRMWARE AVAILABLE FOR DOWNLOAD (PATCHING ZERO DAY FLAWS) DOWNLOAD HERE» Click to show Spoiler - click again to hide... « NOTE : --- Please first upgrade the Router with the transitional firmware, DIR-850L Bx_FW208SGb01 --- And proceed with the DIR-850L Bx_FW210SGb01 firmware upgrade *Please read the enclosed DIR-850L HW B Firmware upgrade guide . Problems Resolved: Fixed the security issues reported by Researcher Pierre Kim on Sep 8th, 2017. • Firmware Protection • WAN && LAN - Retrieving admin password, gaining full access using the custom mydlink Cloud protocol (CVE-2017-14417, CVE-2017-14418) • WAN - Weak Cloud protocol (CVE-2017-14419, CVE-2017-14420) • LAN - Backdoor access (CVE-2017-14421) • WAN && LAN - Stunnel private keys (CVE-2017-14422) • Local - Weak files permission and credentials stored in clear text (CVE-2017-14424, CVE-2017-14425, CVE-2017-14426, CVE-2017-14427, CVE-2017-14428) • WAN - Pre-Auth RCEs as root (L2) (CVE-2017-14429) • LAN - DoS attack against some daemons (CVE-2017-14430)
SUMMARY OF PREVIOUS 0-DAY FLAWS FOUND ON DLINK DIR850L ROUTER (RevA & RevB)
1) Weak or NO protection on Firmware. 2) Weak File permissions are stored in clear text. 3) Cross-site scriting flaws which enables attacker to steal the authentication cookies. 4) Vulnerabilities in MyDLink cloud protocol enables attacker to gain full access to the Router. 5) RevB backdoor access. 6) Hardcoded private keys in the firmware RevA & RevB enables MiTM attcks. 7) DNS Hijack on RevA. 8) Vulnerabilities in RevB enables command injection attacks. 9) DOS flaws in some daemons running in both RevA & RevB can be crashed via LAN. * If you would like to wait for Telco-specific firmware, suggest you to wait for their own release. The above upgrade & patch has been tested on v2.07TT firmware by my team & it works fine.
 Hope Time can clarify whether the firmware whether it is suitable for router distributed by Time. As mentioned in the article, the firmware update is for retail version. https://www.lowyat.net/2017/142516/dlink-di...date-my-retail/QUOTE That being said though, this particular update is made specifically for the retail unit. For units that were distributed by TM and TIME Internet, customers have to wait for further instructions from their respective ISPs.
Meanwhile, the 19.3MB zip file contained two firmware: v2.08SGb01 and v2.10SGb01. Users must first implement the v2.08SGv01 firmware first before moving on to v2.10SGb01. Despite the name, we were informed that the firmware is indeed for retail units sold in Malaysia.
|
|
|
|
|
|
cherroy
|
Oct 1 2018, 04:28 PM
|
20k VIP Club
|
Old router (non-gigabit), switches, Cat5 cable all need to throw away with the lowest entry speed is 500mbps...
|
|
|
|
|
|
cherroy
|
Oct 1 2018, 04:33 PM
|
20k VIP Club
|
Got free gigabit router given?
If not, stuck with max speed of 100mbps.
|
|
|
|
|
|
cherroy
|
Oct 2 2018, 10:08 AM
|
20k VIP Club
|
QUOTE(jjj2 @ Oct 1 2018, 11:37 PM) Hi, please look at your Huawei ONU, it should be either HG8240 / 8240H... this ONU has no problem supporting at all...we have tested it on 1Gbps line at it performed flawlessly. Here comes slight problem with Dlink DIR850L.. it has problem going up to 500Mbps or beyond, eventhough on LAN...rarely get beyond that... You definitely need a better router if your speed really goes beyond 800Mbps. Thanks. Those still under contract with 850L unit given, can request for replacement?
|
|
|
|
|