Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How to block the port from the LAN side? #105

Open
elvisangelaccio opened this issue Jan 19, 2015 · 2 comments
Open

How to block the port from the LAN side? #105

elvisangelaccio opened this issue Jan 19, 2015 · 2 comments

Comments

@elvisangelaccio
Copy link

Hi all, my Netgear DG834G was affected by the backdoor. I fixed it, from the WAN side, by simply blocking the port 32764 using a new firewall rule for the incoming connections. This was the biggest security issue and now I should be protected.
However, the backdoor is still working from within the LAN and this is annoying.
How do I block the backdoor port from the LAN side? As far as I know there is no firewall between the router itself and the LAN hosts, right? Indeed I tried to add also an outgoing firewall rule for port 32764 but this didn't worked. I suspect that when I run poc.py --ip 192.168.0.1 this does not even reach the firewall.

Other ideas?

@knanan
Copy link

knanan commented Jan 19, 2015

Buying a new modem/router was my ultimate solution (I actually used my newer backup modem, after googling the model name and seeing no obvious security issues, I eased)

@elvisangelaccio
Copy link
Author

Yeah, I know. But since I trust the users of my LAN (they all know the admin password), actually I'm fine with the backdoor active and with my current router. It's just a matter of principle, I would like to shut down that port regardless if it's not used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants