Remote tftp???

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Author Message
wifi_is_simple
DD-WRT User


Joined: 25 Dec 2006
Posts: 88

PostPosted: Mon Apr 30, 2007 11:08    Post subject: Remote tftp??? Reply with quote
well i was recently wondering about like if suppose someone knows my routers WAN IP, although i do know if i disable REmote access they cant access my router etc etc

but this question boggles me is it possible to remote tftp directly? that would be very exploitable as someone can upload a corrupt firmware and my router woudl go crazy and bricked..

i guess this applies to all routers apart rfom those running dd0wrt as i am currently using dd-wrt v24 on my wrt54gs v3....

so what do u ppl think? i am not knowledgabel into tftp stuff..so i wud apprecuiate feedback...
Sponsor
pjm
DD-WRT User


Joined: 07 Jun 2006
Posts: 57

PostPosted: Mon Apr 30, 2007 11:27    Post subject: Nice paranoid though Reply with quote
TFTP only works as far as I know from the CFE bootloader at that point the WAN port could not pass information through at all from the internet. You could flash a firmware through remote access if the router was not pass protected or security enabled. I have seen many routers still set on default. One could easily flash DDWRT or other firemare to these units or even change any and all settings. Of course a rest to default would take care of everything execpt a firmware flash.
PJM
frater
DD-WRT Guru


Joined: 07 Jun 2006
Posts: 2777

PostPosted: Mon Apr 30, 2007 12:47    Post subject: Reply with quote
One could not only flash DD-WRT on such a device, but also a modified firmware that would give you access to the router always even if all security-settings in the webinterface are enabled.

resetting it to its default settings wouldn't make any difference...

_________________
Asus RT16N + OTRW
Kingston 4GB USB-disk 128 MB swap + 1.4GB ext3 on /opt + 2 GB ext3 on /mnt
Copperjet 1616 modem in ZipB-config
Asterisk, pixelserv & Pound running on router
Another Asus RT16N as WDS-bridge

DD-WRT v24-sp2 vpn (c) 2010 NewMedia-NET GmbH
Release: 12/16/10 (SVN revision: 15758M)
wifi_is_simple
DD-WRT User


Joined: 25 Dec 2006
Posts: 88

PostPosted: Tue May 01, 2007 4:17    Post subject: Reply with quote
but is it possible to tftp without entering the outer password on internet??
wifi_is_simple
DD-WRT User


Joined: 25 Dec 2006
Posts: 88

PostPosted: Tue May 01, 2007 4:22    Post subject: Reply with quote
i need someone to answer who is very much knowledgaebale in tftp ...has nayone tried this via the internet? i mean otuside the LAN...?
pjm
DD-WRT User


Joined: 07 Jun 2006
Posts: 57

PostPosted: Tue May 01, 2007 10:40    Post subject: tft[ flash Reply with quote
TFTP flash is only possible durning bootwait or when the CFE has entered a call to receive TFTP flash. One cannot do it throught the WAN port from the outside because it is NOT loaded yet.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum