5 ms·
> It's running the Express Logic ThreadX RTOS, has no running services on any TCP ports and appears to listen on two single UDP ports. This is excellent. I can
by MichaelRenor 9y ago
> It's running the Express Logic ThreadX RTOS, has no running services on any TCP ports and appears to listen on two single UDP ports.
This is excellent. I can't even say the same thing about my AT&T fiber gateway. It listens on two random ports with no way to turn it off (and also you can't use your gigabit internet without the AT&T gateway in front). I don't know what it is, but I'm sure it's probably insecure.
- toast0 9y agoThis is super off-topic, but it is possible to bypass the 'residential gateway', if you have the fiber to ethernet gateway (possibly on the outside of your house), and then the separate gateway inside that turns ethernet into ethernet. You basically need to bridge the 802.1x authentication packets, and then you can do whatever.
- matt_wulfeck 9y agoDo you know where I can read more about this?
- toast0 9y agoThis is the definitive thread I've seen: http://www.dslreports.com/forum/r29903721-AT-T-Residential-Gateway-Bypass-True-bridge-mode http://www.dslreports.com/forum/r29903721-AT-T-Residential-G... I implemented it differently, but probably less sensibly. I have a FreeBSD as my NAT box anyway, so I added some network cards, and run a ethernet bridge in front of the gateway (I commented out the lines that dropped traffic to reserved multicast addresses because that include 802.1X), and divert only a small fraction of the incoming packets (ipv6 tunnel from he.net, most udp 123 packets, icmp pings, port 25), that the gateway won't give to the DMZ host (I have the Pace 5268AC gateway which likes to ruin things; the NVG599 one is probably better). You can PM me on DSL Reports with the same username, if you want more details on my crazy setup. :)
- matt_wulfeck 9y agoThank you for sharing! I can't wait until somebody pops the gateway and dumps the cert so I can just use a single DD-WRT router.