PDA

View Full Version : Nexland users alert/new firmware fixes security issues!



White00t
02-19-05, 04:27 PM
My Nexland ISB SOHO has been stalling the inet while surfing and dropping my Xbox Live connections for weeks now. While looking for new firmware I found these security issues, http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html.

Symantec has released a new firmware, 16U.

"Corrections Included in this Release:

Issue 1 - Denial of service caused by a fast UDP port scan
A fast map UDP port scan against all ports (i.e. 1-65535) on the WAN interface of the firewall will cause the firewall to lock up and stop responding. Turning the power off and on will reset the firewall.

Issue 2 - Filter bypass on WAN interface
A UDP port scan against the WAN interface of the firewall from a source port of UDP 53 bypasses filter on WAN interface and exposes the tftpd, snmpd and isakmp active services. All other ports are reported as closed.

Issue 3 - Default read/write community string on SNMP service
The default read/write community string used by the firewall is public, allowing an attacker to collect and alter the firewall's configuration. By combining this with issue 2 mentioned above, an attacker is able to exploit this against the WAN interface by sending SNMP GET/SET requests whose source port is UDP 53. The administrative interface for the firewall does not allow the operator to disable the service nor change the community strings."


ISB SOHO version: http://www.symantec.com/techsupp/enterprise/products/isb_soho/isb_soho_4/files.html.

Wavebase: http://www.symantec.com/techsupp/enterprise/products/wavebase/wavebase_wireless/files.html

Pro400, Pro800 and Pro800 turbo: http://www.symantec.com/techsupp/enterprise/products/pro400800/pro400800_all/files.html

for the Pro100 I dont know...some guy in this thread mentions changing the hex in the beginning which went over my head. http://www.dslreports.com/forum/remark,12280172~mode=flat#12280172

Also the readme at Symantec isnt very thorough so I just went by my old Nexland readme for version 15Y:

"Installation Instructions:


Using "<firmwarename>_all.bin" File

***WARNING***
This Process will reset your device to it's factory configuration. All of your settings will be erased. Please make note of all of the settings inside the ISB. See Below for "APP" usage to maintain settings.


1. Extract the Firmware Zip file to a directory on your local computer.

2. Set dip Switches number 1 & 2 to the ON (*DOWN*) position, and press the reset button on the back of the device.

3. Open the directory to where you extracted the firmware file to.

4. Double Click the NXTFTPX.exe file.

5. In the Nexland TFTP v1.00 program, enter the Server IP as the IP address of your Nexland Router (Default: 192.168.0.1).

6. Click the BROWSE button and go to the directory where you extracted the firmware file to, select the <firmwarename>_all.bin file and click OK.

7. Now both the Server IP and the Local File should be populated, Click the PUT button.

8. Once this is completed you should receive a message of SUCCESS. Set dip switches number 1 & 2 to the OFF (*UP*) position and press the reset button on the back of the device again.

Your Firmware has been successfully flashed.

*********************************************************
Using "<firmwarename>_app.bin" File
This process will NOT reset the device to it's factory configuration. Your settings will NOT be erased.
You can use this firmware ONLY if you are upgrading from version 1rel5A firmware or higher.

1. Extract the Firmware Zip file to a directory on your local computer.

2. Set dip Switches number 1 & 2 to the ON (*DOWN*) position, and press the reset button on the back of the device.

3. Open the directory to where you extracted the firmware file to.

4. Double Click the NXTFTPX.exe file.

5. In the Nexland TFTP v1.00 program, enter the Server IP as the IP address of your Nexland Router (Default: 192.168.0.1).

6. Click the BROWSE button and go to the directory where you extracted the firmware file to, select the <firmwarename>_app.bin file and click OK.

7. Now both the Server IP and the Local File should be populated, Click the PUT button.

8. Once this is completed you should receive a message of SUCCESS. Set dip switches number 1 & 2 to the OFF (*UP*) position and press the reset button on the back of the device again.

Your Firmware has been successfully flashed.

If you occur any errors durring this process, please don't hesitate to contact
Technical Support."


Hope this HAS been posted before and helped out every Nexland user! Take care!