** Important if you are a K26 user you should read this **

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Goto page Previous  1, 2, 3, 4, 5  Next

Need an update for older K26 kongmod with ssl fix
Yes
91%
 91%  [ 43 ]
No
8%
 8%  [ 4 ]
Total Votes : 47

Author Message
<Kong>
DD-WRT Guru


Joined: 15 Dec 2010
Posts: 4339
Location: Germany

PostPosted: Mon Apr 14, 2014 21:13    Post subject: Re: build confusion Reply with quote
blogthis wrote:
First of all, thank you Kong for updating the Linksys / Cisco / Belkin e3000 aka broadcom nv60k chain!! Cool

I've read this thread and Kong's comments very carefully, but I'm still just a bit confused by builds/chains...

Filename: usb-ftp-samba3-vpn-nv60k-broadcom.bin

--- old prior build ---

OLD stable build we've been using located here:
http://www.desipro.de/ddwrt/K26/archive/r22200/

Shows detailed version info of:

DD-WRT v24-sp2 (08/19/13) vpnkong - build 22200M
Kernel Version Linux 2.6.24.111 #611 mips

--- versus newly patched ---

NEW Patched OpenSSL / OpenVPN located here:
http://www.desipro.de/ddwrt/K26/r22000+/

Shows detailed version info of:

DD-WRT v24-sp2 (04/14/14) vpnkong - build 22000M
Kernel Version Linux 2.6.24.111 #609 mips

-- Questions: regarding recent update --

1.) Why did the build decrease from 22,200 down to 22,000?

2.) Why did the linux kernel go down from #611 to #609?

3.) What exact OpenSSL and OpenVPN versions were in prior build r22200m, and what's now within the more recent build r22000m? (Please feel free to just give me links to this type of embedded library version info, so I can also find it for myself later).

4.) If this is an intentional build/chain regression, then what kind of fixes were lost and why? Specifically, any security concerns, or just functionality like USB?

Sorry I'm honestly confused, thank you for the kind responses. Again, we are very grateful for VPN fixes to our old routers!! Smile


As my kongmod builds had lots of differences with regular dd-wrt I couldn't just go back to that revision with an svn up. I don't have any K26 unit anymore, so I can't test anything, but I had a few backup vms and the latest was from 22000.

Since I know the build that comes from this vm works, I choose it for an update.

Thus updated this specific build with openssl and integrated a few fixes that I fixed in later revisions, and I know these fixes don't break other things:-)

The build is security wise fine includes a few bugfixes for the most annoying things that people complained a lot.

_________________
KONG PB's: http://www.desipro.de/ddwrt/
KONG Info: http://tips.desipro.de/
Sponsor
nyrang3rs
DD-WRT Novice


Joined: 07 May 2013
Posts: 31

PostPosted: Tue Apr 15, 2014 0:13    Post subject: Reply with quote
Kong, I have a bricked E3000 that probably just needs serial recovery that you can have for free. Will it help you test k26 builds?
pianoguy
DD-WRT Novice


Joined: 16 Jan 2013
Posts: 21

PostPosted: Tue Apr 15, 2014 13:22    Post subject: Reply with quote
Thank you, Kong. I'll install the K26 Image for my RT-N16 as soon as i need to activate OpenVPN next time.

Good to see you stay in charge.
Gonzo_WRTer
DD-WRT Novice


Joined: 20 Feb 2014
Posts: 29

PostPosted: Tue Apr 15, 2014 14:47    Post subject: Reply with quote
Just wanted to say THANKS BIG TIME to Kong for supporting the folks who are still using the older KONG releases.

I've got 22000+ up on my WNR3500l v1 and am currently stressing it with some local network activity before I get onto my air-gapped machine to generate some new Certs for OPENVPN.

I use and rely on OpenVPN in my work so this was a life saver.

Kong, do you have a PayPal acct for donations if folks are so inclined?

Thanks.
notorious.dds
DD-WRT User


Joined: 24 May 2012
Posts: 376
Location: Michigan

PostPosted: Tue Apr 15, 2014 14:52    Post subject: Reply with quote
Gonzo_WRTer wrote:
Just wanted to say THANKS BIG TIME to Kong for supporting the folks who are still using the older KONG releases.
Kong, do you have a PayPal acct for donations if folks are so inclined?
Thanks.


I second that. THANK YOU KONG. How/where do I contribute to the "Huge thanks to Kong for bailing our butts out" fund?
slobodan
DD-WRT Guru


Joined: 03 Nov 2011
Posts: 1557
Location: Zwolle

PostPosted: Wed Apr 16, 2014 22:15    Post subject: Reply with quote
chjohans wrote:
So you're saying I can't mount any USB drives with ext2 or ext3 filesystems with this build? If so that's a bummer as I use that for optware.

kong, if this is the case then please fix this.

Well, it was flopped, twice, but three times is maritime law (I don't know if there's such expression in English, Dutch certainly has it).

_________________
2 times APU2 Opnsense 21.1 with Sensei

2 times RT-AC56U running DD-WRT 45493 (one as Gateway, the other as AP, both bridged with LAN cable)

3 times Asus RT-N16 shelved

E4200 V1 running freshtomato 2020.8 (bridged with LAN cable)

3 times Linksys WRT610N V2 converted to E3000 and 1 original E3000 running freshtomato 2020.8 (bridged with LAN cable)


srirams
DD-WRT Novice


Joined: 05 Jul 2006
Posts: 13

PostPosted: Thu Apr 17, 2014 3:34    Post subject: Reply with quote
The openvpn version in the new builds is:

Code:
OpenVPN 2.3.2 mipsel-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Apr 13 2014


Is this the patched version? I thought 2.3.3 was the patched version?
primexx
DD-WRT Novice


Joined: 22 Jun 2008
Posts: 49

PostPosted: Thu Apr 17, 2014 4:38    Post subject: Reply with quote
It looks like the last build of regular DD-WRT is from end of March. Are updated regular DD-WRT builds going to be released soon or is this Kong Mod going to be the only fixed version for the next little while?
<Kong>
DD-WRT Guru


Joined: 15 Dec 2010
Posts: 4339
Location: Germany

PostPosted: Thu Apr 17, 2014 7:37    Post subject: Reply with quote
notorious.dds wrote:
Gonzo_WRTer wrote:
Just wanted to say THANKS BIG TIME to Kong for supporting the folks who are still using the older KONG releases.
Kong, do you have a PayPal acct for donations if folks are so inclined?
Thanks.


I second that. THANK YOU KONG. How/where do I contribute to the "Huge thanks to Kong for bailing our butts out" fund?


You can use the paypal button in my builds, lower part of the webif.

_________________
KONG PB's: http://www.desipro.de/ddwrt/
KONG Info: http://tips.desipro.de/
<Kong>
DD-WRT Guru


Joined: 15 Dec 2010
Posts: 4339
Location: Germany

PostPosted: Thu Apr 17, 2014 7:41    Post subject: Reply with quote
srirams wrote:
The openvpn version in the new builds is:

Code:
OpenVPN 2.3.2 mipsel-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Apr 13 2014


Is this the patched version? I thought 2.3.3 was the patched version?


OpenVPN doesn't have the bug, openssl has. You are probably talking about the binary Windows version that shipped openssl.

@primexx

They are all updated, K26, K3-AC and K3-AC-Arm -> http://www.desipro.de/ddwrt/

_________________
KONG PB's: http://www.desipro.de/ddwrt/
KONG Info: http://tips.desipro.de/
blaser
DD-WRT Guru


Joined: 16 Jul 2006
Posts: 525

PostPosted: Sun Apr 20, 2014 17:50    Post subject: Reply with quote
has anyone tried to run pptp server on this build?
I can't get default gateway after connection

_________________
Netgear R9000 main router
RAX80 as AP
can't flash
DD-WRT User


Joined: 14 Jan 2010
Posts: 73
Location: Flint, Michigan

PostPosted: Sun Apr 27, 2014 3:24    Post subject: Reply with quote
<Kong> wrote:
srirams wrote:
The openvpn version in the new builds is:

Code:
OpenVPN 2.3.2 mipsel-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Apr 13 2014


Is this the patched version? I thought 2.3.3 was the patched version?


OpenVPN doesn't have the bug, openssl has. You are probably talking about the binary Windows version that shipped openssl.

@primexx

They are all updated, K26, K3-AC and K3-AC-Arm -> http://www.desipro.de/ddwrt/


Hey Kong. I know you have plenty of other things going on; but according to the OpenVPN Wiki, version 2.3.3 adds support for TLSv1.2 cipher suites. If there's any chance at all you could update this in your 20000+ build, you'd be even more the man than you are now! Very Happy

_________________
Netgear R7800
DD-WRT v3.0-r54545 std
Release: 12/18/2023 (SVN revision: 54545)
nolimitz
DD-WRT Guru


Joined: 26 Nov 2010
Posts: 597

PostPosted: Sun Apr 27, 2014 9:32    Post subject: Reply with quote
flashed r22000+ usb-ftp-samba3-vpn-nv60k-broadcom to E3000, did a reset. tried to use Privoxy/Adblock but web pages do not load. i had to turn off privoxy so websites can load.
can anyone confirm?
slobodan
DD-WRT Guru


Joined: 03 Nov 2011
Posts: 1557
Location: Zwolle

PostPosted: Mon Apr 28, 2014 9:50    Post subject: Reply with quote
nolimitz wrote:
flashed r22000+ usb-ftp-samba3-vpn-nv60k-broadcom to E3000, did a reset. tried to use Privoxy/Adblock but web pages do not load. i had to turn off privoxy so websites can load.
can anyone confirm?

Well, if you use it in transparent mode, that could be the problem. I use it with:

Privoxy: Enable
Transparent Mode: Disable
Custom Configuratio: Disable

And I have set a proxy to 192.168.1.1:8118 in my browser.

_________________
2 times APU2 Opnsense 21.1 with Sensei

2 times RT-AC56U running DD-WRT 45493 (one as Gateway, the other as AP, both bridged with LAN cable)

3 times Asus RT-N16 shelved

E4200 V1 running freshtomato 2020.8 (bridged with LAN cable)

3 times Linksys WRT610N V2 converted to E3000 and 1 original E3000 running freshtomato 2020.8 (bridged with LAN cable)


blaser
DD-WRT Guru


Joined: 16 Jul 2006
Posts: 525

PostPosted: Mon Apr 28, 2014 10:24    Post subject: Reply with quote
Kong
Any way you can post only the binaries for openssl with upgrade instructions?
I have still 15962 with optware and wanted to upgrade openssl.

_________________
Netgear R9000 main router
RAX80 as AP
Goto page Previous  1, 2, 3, 4, 5  Next Display posts from previous:    Page 4 of 5
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum