PDA

Bekijk de volledige versie : Back door in firmware?



Mark Koshelev
22-01-2005, 21:03
I’m using 500g with 1.9.2.7-3b firmware.
Today I looked at port forwarding table and little confused.
Really I have virtual server for ports 4672, 4662, 8000, 5900.
I newer allowed ports 23531 and 50154.
What is the magic?
83.237.36.48 UDP 4672 192.168.0.10
83.237.36.48 TCP 4662 192.168.0.10
83.237.36.48 TCP 8000 192.168.0.10
83.237.36.48 TCP 5900 192.168.0.10
83.237.36.48 TCP 23531 192.168.0.10
83.237.36.48 UDP 50154 192.168.0.10

Rynno
22-01-2005, 21:14
Maybe the ports are opened by uPNP :rolleyes:
You can enable/disable this:

IP Config
IP Config - Miscellaneous
Enable UPnP?
Yes/No

Mark Koshelev
23-01-2005, 19:23
Actually UPnP was enabled. I thought that it is the reason of opened ports too.
But after UPnP has been disabled (then save and reboot step) the wrong forwarding ports were still exist.
May Save/Reboot action keep wrong ports?

Antiloop
23-01-2005, 22:09
Actually UPnP was enabled. I thought that it is the reason of opened ports too.
But after UPnP has been disabled (then save and reboot step) the wrong forwarding ports were still exist.
May Save/Reboot action keep wrong ports?
do a cold boot
or reset to defaults first

Mark Koshelev
24-01-2005, 21:05
Reset to default is undesirable as well as cold reset.
Can I edit something in router configuratin to change forwarding policy?

Antiloop
24-01-2005, 21:19
Reset to default is undesirable as well as cold reset.
Can I edit something in router configuratin to change forwarding policy?
flush iptables and remove entries from nvram

Mark Koshelev
26-01-2005, 20:14
Thanks, it's working. What is the reason for saving UPnP configured port to nvram?

Oleg
26-01-2005, 20:20
Ask ASUS tech support about this. :D Probably to survive reboots.

phedny
03-02-2005, 20:10
Thanks, it's working. What is the reason for saving UPnP configured port to nvram?

I think it is for the web interface, as it can only fetch dynamic information from nvram (although, that's how far I understand the httpd process).

barsju
09-03-2005, 08:24
flush iptables and remove entries from nvram

Could you please post code on how to do this?

S

PS: Has there been any attempts to change/replace the UPnP service? Would this be possible?

EDIT: Solution can be found here: http://wl500g.info/showthread.php?t=1933