11 ms·
Don't use Linksys routers
- dz0ny 14y agoI use Linksys routers, but not with default software (which we know is "limited"). I would recommend alternatives from here http://tomatousb.org/mods http://tomatousb.org/mods
- tjoff 14y agoWhich makes it a bit odd that he mentions the "uber-popular Linksys WRT54GL router" specifically. The "L" stands for linux, and it was brought back because people specifically wanted to install third party software on it. And the reason for it becoming popular in the first place was probably a security issue that allowed third party software to be installed. The "L" version was introduced because newer routers didn't have this capability/vulnerability and people wanted something they could install third party software on. So when the "L" version (which I use) came it was just an older model, with even less memory than the original and a much heftier price. Unless you wanted to run third party software on it it was really bad value for your money. Anyway, all of this truly sucks. But really, I don't expect more of any consumer router. EDIT: Oh wow, the WRT54GL was introduced in 2005, nothing too fancy at the time and you can still buy it today - lots of stores have it in stock even.
- reefab 14y agoThat's inexact. The WRT54GL was brought in as the (at the time) retail version of the WRT54G had much less RAM and flash because they switched from Linux to VXWORKS. It's not that they didn't have the "security vulnerability" but they just weren't able to run Linux in a useful manner due to low hardware resources. I also don't remember if the WRT54G became popular in the first place because of a security issue, I think it just enabled you to upload any firmware to it and that the original firmware eventually became open-source after they received GPL violation complaints. But my memory might be fuzzy, it was a while ago.
- UnoriginalGuy 14y agoYour memory is how I remember it too. Basically the WRT54G with base firmware was better than anything else on the market at the time of release (within the same market segment - retail routers). Just to put that into some perspective before the WRT54G, some of the functionality in the base firmware was being sold to small-medium businesses by companies like Cisco for thousands of dollars. Word spread quickly and instead of your local coffee shop paying Cisco $20,000 to install their WiFi, they could spend $100 on a Linksys router. This meant companies could afford to give away WiFi for free because it cost them little or nothing to install the WiFi initially. But what happened next is what turned the Linksys WRT54G from a "great" to a "legendary" product - people found out it ran on Linux. Now Linux is open source but more specifically it is under the GPL license. What that meant is that legally Linksys were required to share the source code that made the WRT54G run. Which after some not-so-gentle prodding and legal threats they did. People then made distro's (in the Linux sense) which updated the Linksys firmware to add new functionality, fix issues, and similar. This made the thing even more powerful than perhaps even Linksys wanted, and ate into Cisco's small-medium business space even more. Word spread like wildfire and soon everyone and their brother owned a Linksys WRT54G. Linksys improved the base firmware only mildly while the third party firmware was steamrolling ahead. Cisco eventually purchased Linksys and started cutting corners on all of their retail products. Using less powerful CPUs, less RAM, and stripping out functionality while not altering the cost. Linksys stagnated. This was likely in no small part to try and get some of their small-medium customers back onto Cisco's books, but by then it was too late. The market that Linksys had created had spread to Linksys's competitors and soon everyone was "letting" their routers get firmware updates that turned a cheap little home router into something able to fend off medium-business level commercial equipment.
- yuhong 14y agoAFAIK Cisco bought Linksys back in March 2003.
- johnsoft 14y agoThe reason it became popular in the first place is because Linksys included GPL code in their stock firmware, and because of the terms of the license, they were forced to release the entire firmware source under the same license. Once the full source was available, modding and porting Linux became straightforward.
- spindritf 14y agoOr just put OpenWRT[1] on it. It's a real Linux distribution with a package manager and everything. You can even disable the webinterface, if you don't trust it, and use SSH. EDIT: WRT54GL is pretty old and it won't run the default build of OpenWRT Attitude Adjustment (the newest release). It also probably won't have enough memory to operate the package manager or the webinterface. But I do have one running a custom build. The only downside is that you need to decide which software to include upfront. Their build tool is rather friendly[2]. EDIT2: You can have a VPN server and any routing you like on OpenWRT, same with Samba, radvd, vnstat... There are even webUI pluings (luci-app-whatever) so you can control those from the webinterface for ease of access. It is a real Linux distro that just happens to run on routers. [1] https://openwrt.org/ https://openwrt.org/ [2] http://wiki.openwrt.org/doc/howto/build http://wiki.openwrt.org/doc/howto/build
- tobbez 14y ago> It also probably won't have enough memory to operate [...] the webinterface. It does have enough memory for the web interface - at least for the one in KAMIKAZE (8.09.2, r18961), the version mine is running.
- AnthonyMouse 14y agoThe trouble with the WRT54G series (and most of these little routers) is that they have ~200MHz CPUs and ~16MB of RAM. This is, incidentally, why they often crash when you open a lot of simultaneous connections -- memory exhaustion. I find that if you're interested in experimenting with a Linux router, old PCs are a much better choice. You can get a PowerPC G3 or G4 or a late model Pentium III for practically zero money (if not literally zero money out of a trash heap) and PCI NICs for secondary interfaces are similarly inexpensive. For only slightly more money the G4 Mac Mini is an excellent choice for a wireless router. Then you have a processor that is several times faster and can put arbitrarily much memory and storage in it to suit your needs and then put your favorite Linux router distribution (or Debian) on it and have at it.
- TylerE 14y agoYou might be shocked by the power bill for running one of those older beasts 24/7.
- UnoriginalGuy 14y agoLinksys went from being the "iPhone of home networking" to being something I won't recommend. In Cisco's care the company has gone from being a market leader to a dud. Now a lot of people might say "I doesn't matter who makes it, I'll just flash OpenWRT or DD-WRT onto it!" But I say to that, "then why buy a Linksys?" Asus for one example are cheaper, they often have external antenna giving you more power and flexibility (both literally and figuratively) plus and most importantly they can be flashed with OpenWRT or DD-WRT at your pleasure. Even without the security issues there is no good reason to buy a Linksys. Right now I am using my ISP supplied "router" in cable-modem "mode" (i.e. just dumb pass-through to ethernet) and have a cheap MikroTik/RouterOS device sitting behind it which was cheaper than most retail grade routers but with the functionality of commercial grade equipment. RouterOS might not be as easy to use as DD-WRT, but if you can use it then it is far more powerful as a web-based environment. Just for one example, want a VPN server? RouterOS supports IPSec/L2TP, PPtP/GRE, SSTP, and OpenVPN. Basically everything. The list of its network functionality is almost endless...
- illuminate 14y ago"being the "iPhone of home networking"" Howso? All I remember from their heyday was that they were good enough, cheap enough, and flashable. I don't remember them commanding a premium for any particular reason.
- mbreese 14y agoI think they meant it not in terms of a premium price, but rather as the default product to buy. They were never that much more expensive (if at all), but back in the day it was the one most people bought.
- dasil003 14y agoShould have said iPod then as I don't think iPhone ever attained "default" status outside of SF.
- NelsonMinar 14y agoThe modern equivalent of a Linksys WRT54GL is the ASUS RT-N16. It runs OpenWrt, DD-WRT, and Tomato variants really well, does 802.11n (only one frequency) and has plenty of memory and flash storage for extra hacking. The ASUS RT-N66U is frequently advised if you want 5GHz 802.11n as well. The other router mentioned in this article, the Linksys EA2700, doesn't seem compatible with third party firmware. And apparently the Cisco firmware is buggy, no surprise there. It is an awfully cheap Dual-Band 802.11n router, but if you can't put working software on it it's useless. I don't understand why some major router manufacturer doesn't just sell routers pre-installed with Tomato. It's easy to use, stable, and works way better than any crap the router companies cobble together. Flashing new firmware on a stock ASUS router is too complex for ordinary consumers.
- vacri 14y agoThank you for the info - do you know if there's an ADSL modem that's good for DD-WRT these days? Last I looked (yeeeaaaars ago) there were only two models, long since out of production, and they didn't seem to be going in that direction anymore.
- justincormack 14y agoStill seems to be very little. You can get some boxes that convert adsl to ethernet (ATM over ethernet or whatever standard your country uses) that basically have no config and connect those to a router.
- StavrosK 14y agoThat's how I did it, connected my WRT-54GL (Tomato) to a D-Link modem/router, works fantastically well.
- uxp 14y agoAre you thinking of Bridged mode? I used to do this until something happened at my ISP and my router can no longer authenticate against my ISP's PPPoE server. Now I have my modem providing NAT and DHCP, and my router is just a dumb access point. The only problem is my modem has an externally accessible administration page running on port 4567, and telnet on port 1111 that I can't turn off, even when all remote management configuration options are turned off. I've had to set up a cronscript to attempt to telnet into the thing continuously, and if successful it will kill the httpd server and telnet daemon. It's absolutely ridiculous how insecure home network equipment is.
- mikecane 14y agoHaving looked at the post, doesn't he really mean don't buy "these models" of Linksys? Or are all models open to certain vulnerabilities?
- happycube 14y agoThis indicates that they're not doing enough testing of any of their routers. Not conclusive, of course...
- brooksbp 14y agoI highly recommend Mikrotik to anyone fed up with traditional consumer wifi routers/APs. I dont know how they compare to other vendor hw eg Asus + OpenWRT, but this little guy has been rock solid and a joy to use: http://routerboard.com/RB2011UAS-2HnD-IN http://routerboard.com/RB2011UAS-2HnD-IN
- waffle_ss 14y agoThanks for the recommendation. I'm absolutely fed up with my D-Link DIR-655 always needing to be restarted when the wireless decides to stop working, and was looking for something exactly like this. I was beginning to dread having to build something like a Smoothwall/pfSense box; I did that around 2005 with an old desktop computer and it didn't work that well. I've actually heard of Mikrotik before; about 10 years ago I was doing some work planning a 2.4GHz wireless ISP (WISP) and I think Mikrotik equipment was highly regarded then (especially in the 900MHz spectrum IIRC) so looking forward to this. Here's a link to a distributor where it can be purchased: http://www.roc-noc.com/mikrotik/routerboard/RB2011UAS-2HnD-IN.html http://www.roc-noc.com/mikrotik/routerboard/RB2011UAS-2HnD-I...
- nmolo 14y agoThe smaller versions also work as well and are only $80! http://www.roc-noc.com/mikrotik/routerboard/RB951G-2HnD.html http://www.roc-noc.com/mikrotik/routerboard/RB951G-2HnD.html
- sctechie 14y agoLook well-made. I've never seen that brand in any US stores unfortunately. There were a few US distributors listed but most were tiny shops.
- nucleardog 14y agoWe've ordered thousands of dollars worth of stuff from roc-noc.com over a couple of years. Chatted on the phone with them a bit too. I'd definitely vouch for them if you're looking to make an order.
- FollowSteph3 14y agoWhat recommendations do people here have for an entry level commercial router instead of a high consumer level router?
- hp50g 14y agoDraytek Vigor. Any of the mid range units. Bomb proof, well supported and have VoIP support that isn't a piece of shit.
- rdl 14y agoJuniper SRX100 ($500), with Ubiquiti APs (~$100).
- MertsA 14y agoThat's a bit overkill don't you think? Do you really think a home user would have a need to run BGP?
- rdl 14y agoOverkill for a random home, but maybe OK if you WFH and need to vpn/IT wants manage a bunch of devices centrally/etc. $1k in equipment vs. $300 in equipment isn't that big a difference for a few important home users if you're already using all the same equipment in your other offices. (also a lot of startups have like 20 people working out of a home or condo, and they bump up against memory/crapiness/etc. limits of consumer routers and APs pretty hard.) OP asked for "low end commercial router", though.
- newman314 14y agoI'll add on the following requirements. Working QoS IPSec (roadwarrior config w/ certs) CoDel (big plus but optional) VoIP (optional)
- autotravis 14y agoMy ISP makes me use a "gateway"[1][2] with a wireless router built into it. In the name of reducing electricity usage, I forego running my own router and surrender to using theirs. I would be willing to bet many others do the same. I wonder how secure it is? [1]http://www.att.com/u-verse/explore/residential-gateway.jsp http://www.att.com/u-verse/explore/residential-gateway.jsp [2]http://verrytechnical.com/wp-content/uploads/2011/10/ATTUverse2WireRG.jpg http://verrytechnical.com/wp-content/uploads/2011/10/ATTUver...
- tjbiddle 14y agoI just had U-Verse installed yesterday, the tech said you can use your own router if you like. My router is still with my old roommate though, so I haven't tried it - But I see plenty of ethernet ports so I don't see why it wouldn't work.
- cdjk 14y agoMy router uses about 3 watts. That adds about $5 per year to my electric bill, which I'm happy to pay to avoid the painful ISP-provided router.
- GoodIntentions 14y agoMy ISP also sent an "all-in-one" device when I hooked up. All I really wanted was to set it up in bridge mode in front of my pfsense box, but couldn't do this. I cloned their router's MAC, put their router back in the box and used my existing 'dumb' modem. Perhaps this would work for you as well.
- deleted 14y ago[deleted]
- lazyjones 14y agoMy Linksys router has had Tomato on it from the first day, it's the only sane thing to do (OpenWRT or DD-WRT would work too) when closed-source software is regularly exploited and not patched in a timely manner - and when noone knows what kind of government-friendly backdoors exist in such products (made by companies that earn significant revenue from government contracts). Also, there's plenty of very cheap router hardware coming from China nowdays, from TP-Link you can get OpenWRT-capable routers for less than $15, so there's not much point in paying a lot more for Linksys products.
- sctechie 14y agoLet me just get this in before the cries of JUST INSTALL OPENWRT come raining down. Your mother / father / grandmother / etc are not installing openWRT on their routers. Installing one of these CISCO home routers is pretty much hacking yourself. And, just update the firmware is not gonna work. Try it one day, go up like 10 people and ask them what's a firmware. If the user isn't technical, you're going to get a 0/10 correct responses.
- jiggy2011 14y agoMaybe they should just ship with the alternative firmware installed if the open source is doing a better job?
- happycube 14y agoI've read (but haven't personally confirmed) that Netgear used skinned OpenWRT on some of their routers (like the wndr3700v1)
- justincormack 14y agoIt is true http://www.myopenrouter.com/ http://www.myopenrouter.com/ is their info page. They make it really easy to flash, and provide specs as well so they are well supported so you can use a different version, but it does ship with it too.
- fnordfnordfnord 14y agoHave a look, quite a few mfrs have products that either ship with DDWRT or at least advertise "support" (I guess they mean compatibility?) for DDWRT. http://www.amazon.com/s/?url=search-alias%3Delectronics&field-keywords=ddwrt http://www.amazon.com/s/?url=search-alias%3Delectronics&... http://www.dd-wrt.com/site/index http://www.dd-wrt.com/site/index
- fnordfnordfnord 14y ago>Your mother / father / grandmother / etc are not installing openWRT on their routers. My mother / father / grandmother / etc are typically not buying the routers. They are saying things like, "next time you visit, can you fix my internet?" Or, "since you're here, can you check what's wrong with the internet? I can't get it to work." which is when you install and configure the xxxWRT device for them.
- Sami_Lehtinen 14y agoShouldn't 'hardware' firewalls be secure? And everyone knows that software firewalls are crap. Isn't this common knowledge with professionals. ;)
- happycube 14y ago;) In the end, all routers are software. A properly set up Linux or BSD router/firewall on a regular PC can be very, very good. A higher end hardware router actually has tested and (mostly) secured software, these don't...
- danielweber 14y agoI mostly-bricked a Linksys doing a security analysis on it. It still works, but the UI is completely locked up; I can change nothing on it.
- ville 14y agoI also bricked my Linksys by opening /upgrade.cgi (mentioned in the article) on a browser. I was able to finally fix it by downloading a firmware from Linksys, doing a 30/30/30 reset (push reset button for 30 s, turn power off for 30 s and keep on pushing reset for another 30 s after turning it on again) and flashing it with tftp as explained in http://community.linksys.com/t5/Wireless-Routers/E4200-Firmware-Upgrade-failed-Cannot-access-Linksys/m-p/552862/highlight/true#M236523 http://community.linksys.com/t5/Wireless-Routers/E4200-Firmw... After that I was able to login using the web interface again. For Mac OS X the command to flash is just tftp, and then in the console that opens type: connect 192.168.1.1 binary rexmt 1 timeout 60 put firmware_filename.bin
- moonboots 14y agoIt should be pretty easy to upgrade vulnerable WRT54GL routers. Any volunteers to setup a page that POSTs a newer firmware like OpenWrt or Tomato?
- StavrosK 14y agoWhat use is that? If people don't know enough to upload a file to their router, they definitely won't know enough to configure it after it's been done.
- fnordfnordfnord 14y agoEmbed the link in a joke/lolcat/puppy/political forward-email and spam it to all of our relatives/acquaintances who regularly do the same.
- jiggy2011 14y agoIs this a problem if I have DD-WRT?
- joenathan 14y agoNo.
- cdjk 14y agoI'm a fan of pfsense [1] on an alix board [2]. The alix boards a little pricey for a router, but has a real amount of memory (256MB). The only downside is that pfsense, since it's based on FreeBSD, doesn't support any 802.11n cards, so you're either stuck with 802.11g, or using a separate access point like I do. Add in a managed switched and you have the start of a real network at home. [1] http://pfsense.org/ http://pfsense.org/ [2] http://pcengines.ch/alix.htm http://pcengines.ch/alix.htm
- Freaky 14y agoFreeBSD supports some 802.11n cards, doesn't it? https://wiki.freebsd.org/WiFi80211n https://wiki.freebsd.org/WiFi80211n
- cdjk 14y agoThere are no drivers for 802.11n cards in pfsense 2.0 (current stable version), which is based on FreeBSD 8.1. Some b/g/n cards will work, but only in b/g modes: http://doc.pfsense.org/index.php/Is_802.11n_wireless_supported http://doc.pfsense.org/index.php/Is_802.11n_wireless_support... Drivers for 802.11n are in FreeBSD 9.0 and later, but that won't be the base for pfsense until 2.2: http://doc.pfsense.org/index.php/PfSense_and_FreeBSD_Versions http://doc.pfsense.org/index.php/PfSense_and_FreeBSD_Version...
- underdown 14y agoWhat? Linksys routers are a great deal - you can find them at goodwill for $5, flash the firmware & configure it in 15 minutes and they work great. My one beef is why don't they put a cheap fan on them when they cost upwards of $100 now that they come with a cisco logo slapped on them.
- drakaal 14y agoOpenSource is a vulnerability not an Asset according to #5. For small projects which few contributors I would agree but, for projects as large as OpenWRT and DDWRT and such, I don't agree.
- btilly 14y agoIn an ideal world, whether code is open source is neutral. The extra ease of finding bugs is balanced by the fact that people can and do find then fix them. Theory says that these two are, to first order, equivalent. So end user security is the same. (But code quality tends to be higher with open source software.) However whenever code moves towards being more open, you've got all of the vulnerabilities of closed source software, and all of the bug-finding ease of open source software. This is the worst of all possible worlds. Therefore #5 is true. The fact that you have easy access to known-to-be-crappy code increases the vulnerability of that code.
- LucasCollecchia 14y agoJust curious, but wouldn't this indicate that open source code which allow iterators to close off their improvements would produce less vulnerable code overall?
- btilly 14y agoIf a vulnerability is found in open source code, people will try it on yours. So they won't be finding it directly in yours, but that is not protecting you. The real consequence is that how secure a product is depends more on the project than on whether it is open source. Apache and OpenBSD are two examples of very good open source code. Java and Rails are two examples of not so good open source code. Google's website is an example of good closed source code. The software shipped by Linksys is an example of bad closed source code.
- LucasCollecchia 14y agoI get that there are different levels of quality regardless of the type of code. I was more interested in the security effects of hiding code after the open source community has had a chance to deal with vulnerabilities. None of the examples you gave were specific to code which has transitioned between open to closed. What I've gotten from your answer so far is that it isn't an effect which is general, and it'll depend on the project in question. Am I on the mark?
- duncans 14y agoMitigating factor, the attacker would need to have been granted access to your network in the first place?
- InclinedPlane 14y agoNot at all. That's what CSRF is all about. All the attacker needs to do is get you to visit a page on the internet that they control. Then the code on the page does its magic and runs on the browser and because you and the browser are on your network it can work. As a simple example, imagine that you had a test server behind a firewall in your own home network, totally inaccessible from the internet. Now let's say you have it set up so that it will, oh, let's say turn on the oven if you hit a specific URL without any authentication (like testserver/actions/oven/on, or some such). If someone knows of this then they could contrive to have you visit a web page with some embedded resource such as an inline image that causes you to hit that url from your browser. Boom, now your oven is on and you didn't even know it. Even if you switch to using logins and cookies on your test server to ensure that only authorized users on your network can use it then you'll still have the same problem, because when your browser hits that URL it will be in your name, and all of the right cookies will be there. That's the nature of CSRF.
- seqizz 14y agoI think this is just what topic meant: Error 102 (net::ERR_CONNECTION_REFUSED): The server refused the connection. LOL'd
- mschuster91 14y agoHalf-OT: does anyone know a DD-WRT/OpenWRT compatible WiFi router with support for 2.4/5 GHz WiFi, as well as VLAN on the ports? Bonus points for individual VLAN assignment to the individual ports.
- jrabone 14y agoJust buy Draytek. Playtime is over. Pricy but mine lasted 7 years before I replaced it with another Draytek (for dual WAN support). Bomb proof and great VPN support out of the box. I bridge my parent's network to mine over VPN, and the Linux servers at either end provide failover DNS, mail etc. So useful, especially for remote support.
- fsckin 14y agoGoogle Cache of the site since it's having issues. [0] I enjoy my Asus RT-AC66U. [1] Best commercial router I've seen, and Asus Merlin [2] firmware makes it better. [0] http://webcache.googleusercontent.com/search?q=cache:JNu4Z9XbAz0J:https://superevr.com/blog/2013/dont-use-linksys-routers/&hl=en&gl=us&strip=1 http://webcache.googleusercontent.com/search?q=cache:JNu4Z9X... [1] http://www.newegg.com/Product/Product.aspx?Item=N82E16833320115 http://www.newegg.com/Product/Product.aspx?Item=N82E16833320... [2] https://github.com/RMerl/asuswrt-merlin https://github.com/RMerl/asuswrt-merlin
- MertsA 14y agoThe only problem with Asus Merlin is that it uses the older "stable" wifi drivers. I've been running the unreleased Russian build 3.0.0.4.321 for months now and it's stable as a rock.
- Arainach 14y agoSo this researcher went from notifying Linksys to open disclosure to the internet after only a month? That hardly seems responsible.