Jump to content

Linksys Befsx41 New Exploit?


KraZy

Recommended Posts

How to start...

 

After my last encounter with Linksys tech support, I have decided to try to isolate this problem at a higher level here on the forums.. :P

 

I have had problems with my router resetting itself everytime AOL initiated. I thought this seemed kind of odd, but tolerable. After a few days of playing around and nosing through a few pages of packet dumps, I discovered that it is a very typical connection request being made by the AOL software that shouldn't cause such a drastic action as a reset.

 

I can't give out the details of it now, but I need to know if anyone else out there with this router has had similar problems. It would be most prominent when AOL tries to detect your hardware automatically. I dont have the $$ to start swapping out hardware now, so I need to start collecting other peoples info....

Share this post


Link to post
Share on other sites

I use to have this problem when one of my computers would submit a WU. I tried looking into the problem and at the time it would seem that the packets going through the router would trigger the reboot sequence.

 

It would seem that for some time now there has been no self reboot even when WU are being submitted! I unfortunately don't have a logical answer to how the problem got resolved, but the most recent change was to update the firmware of the VPN/router.

 

My advice is make sure you have the latest firmware from Linksys, not a beta version.

Share this post


Link to post
Share on other sites

Time for a little more detail. This is happening -specifically- when AOL tries to setup a VPN with its severs. With my packet sniffing, I have determined the packet that it is sending is infact the L2TP request that it is sent to the AOL server. I was able to duplicate this by copying the packet and injecting it directly into my network, and causing the reset. I will have to get the folding@home up and running again to see if it is infact the pass-through function of the router. From what you say, it sounds like F@H is doing the same thing with its servers. Any one out there with more info on how F@H makes its connection?

 

Also, I was able to go to the store and buy another router of the same exact model and all was working peachy-keen until I got home from work and noticed that the router was not even talking outside my lan. Well, rather that it was half-way talking to the lan. On a ip scan, I found that I could see all my other static-ip's but not the ip of the router. (-that- would be kind of odd, unless the switching part of the router is not effected by this problem)

 

Excuse the pages of writing here, but I need to figure this one out... I will also try to encapsulate the offending packet inside a TCP packet and see if I can initiate a reset remotely. (ach! I really didn't want to go this far..) If other people are having this problem, I forsee some interesting issues comming out of this, espectially since there have been some buffer-overflow issues recently with Linksys. Personally, this is where I think this going....

 

Btw, the firmware is current.... I'll re-flash... again... and see if I can resolve this.

Share this post


Link to post
Share on other sites

Even though I told you that my reboot problems had stopped it turns out that I was wrong!!! The router just rebooted on me last night when a WU was being submitted, go figure. In my case it might be a sync problem also, that is the packets are being submitted so fast that the router can not handle the traffic, hence it reboots.

 

I would have looked into the problem if I knew how to modify the firmware, but since I have no clue how to do that I just live with the reboots!

 

There is another forum which will be more qualified to answer your questions regarding network communications and so on, I would suggest you try them out. I myself go there quite often to read their extensive list of forums and other information. It's quite an extensive site, maybe you know of it already.

 

The Linksys Forum: http://www.dslreports.com/forum/linksys

 

It's also been noted from the above forum that the problem of reboot with the BEFSX41 is a known issue that has never been resolved by Linksys!

 

Sorry couldn't be of more help :(

Share this post


Link to post
Share on other sites

Yup.

 

I will have to talk /w u IRC... hmm...

 

--Update on that situation--

 

I was able to stop that reboots by adding a block to port 1701 to my routers. This also worked with Norton IIS when I blocked that port with software.

 

As an addition, I was also able to duplicate ANOTHER router crash with a packet loop! :) (which incedently cases a buffer overflow, and it corrupts the firmware after a time, and requires a reflash...) I am punching holes through these routers like there is no tomorrow... Lord only knows what I havent found yet....

Share this post


Link to post
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
×
×
  • Create New...