TD-W8901g DNS redirect hack. Please FIX FIRMWARE!

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

TD-W8901g DNS redirect hack. Please FIX FIRMWARE!

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-03-28 11:17:37
Region : Australia

Model : TD-W8901G

Hardware Version : V3

Firmware Version : 3.0.1 Build 100603 Rel.26888

ISP :


I know this is an old modem, but a company had an obligation to fix security exploits!
  0      
  0      
#1
Options
11 Reply
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-05-03 15:47:21

crazyazz wrote

Region : Australia

Model : TD-W8901G

Hardware Version : V3

Firmware Version : 3.0.1 Build 100603 Rel.26888

ISP :


I know this is an old modem, but a company had an obligation to fix security exploits!


Same problem:
Model : TD-W8901G
Hardware Version : V3
Firmware Version : 3.0.1 Build 100901 Rel.23594
ISP : Infostrada

DNS regularly change also resetting the Router.

Refers to: http://arstechnica.com/security/2014/03/hackers-hijack-300000-plus-wireless-routers-make-malicious-changes/

Is not a good advertising for TP-Link
  0  
  0  
#2
Options
What will you do if they do not fix it?
2014-05-18 17:29:57

crazyazz wrote



I know this is an old modem, but a company had an obligation to fix security exploits!


I agree with you but what would you do if the Customer care tells you that since it is no longer in production they are not planning to release a new firmware (I called them ten minutes ago)???

I have been a huge fan of TP-Link in the past years, suggesting it to tenths of friends and customers, but with this unpredictable attitude from the technical support I am afraid I will have to review my opinion thoroughly and, I hope, you will do the same.
  0  
  0  
#3
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-05-18 21:36:46
Hi
That was their response?
"since it is no longer in production they are not planning to release a new firmware "
I'm italian too, from perugia, i have td-w8901g v3.1 and i think that tp-link should release a new firmware also out of warranty.
I was attacked yesterday with this dns redirect ,i dunno if from a site or whatelse.
mbagni : what models of tp-link new routers (with modem adsl2+switch+ access point wireless N) do you know don't have this vulnerability/exploit of the firmware ?
Maybe i will buy a new router, pheraps tp-link brand, and i must choose the model. a cheap model. or from another brand.
Should be better to avoid tp-link if they don't release a fixed firmware !!
  0  
  0  
#4
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-05-18 23:05:07

meow81 wrote


mbagni : what models of tp-link new routers (with modem adsl2+switch+ access point wireless N) do you know don't have this vulnerability/exploit of the firmware ?


I nave your same model, but it seems that the faulty firmware is present also in the new models.

http://cxsecurity.com/issue/WLB-2012100027

And is affecting also other brands.

Maybe the cure could be to configure, for the wifi network card in you PC/tablet having a user defined DNS server, like the google one (8.8.8.8), so if the malware resets your modem you can still navigate safe!
  0  
  0  
#5
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-05-19 01:19:52
  0  
  0  
#6
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-05-19 03:47:31
I have kaspersky 2014 antivirus (also kaspersky pure in another pc) and it prevents/inhibits the dns change in a pc where it is installed, also while the dns in the router is changed.
But i don't know if the inhibition is because/from the wifi network card user defined dns change (google dns) or because/from the antivirus.
I had switched to the google dns months ago.

Jimasek i need to know if are right these changes:
from access management - acl

active : yes
secure ip address: 0.0.0.0 - 0.0.0.0 (all ips)
application : all
interface: lan

explanation : for using a pc with an ethernet cable to the lan, a pc physically linked to router switch and it can modify router settings.


And another rule:

active :yes
secure ip address : 192.168.1.2 - 192.168.1.5

explanation: because when i connect 4 devices in wireless they use those ips and those devices can modify router settings remotely.. with url 192.168.1.1 in broswer, giving password and modifying settings.

application : web
interface : both
  0  
  0  
#7
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-05-20 21:52:11
they replied to my email :

Gentile Cliente,
i prodotti end of life da più di 3 anni non sono più sviluppati.
Grazie per aver contattato il Supporto Tecnico TP-LINK, che rimane naturalmente a Sua completa disposizione.

i prodotti end of life da più di 3 anni non sono più sviluppati. ---> the end of life products from more than 3 years are no longer developed.
  0  
  0  
#8
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2014-08-21 22:50:27
new firmware available

new firmware available for TD-W8901G v3 (my model)

http://www.tp-link.it/support/download/?model=TD-W8901G&version=V3

Improved security mechanism.
  0  
  0  
#9
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2018-05-13 18:30:15
I have a problem with my TD-W8901
It does not automatically detects the DNS and also does not assign DNS on DHCP. I have to set it manually.
Any solution for this?
  0  
  0  
#10
Options
Re:TD-W8901g DNS redirect hack. Please FIX FIRMWARE!
2018-05-14 22:29:35
you have explained very nicely
  0  
  0  
#11
Options

Information

Helpful: 0

Views: 2011

Replies: 11

Related Articles