News:

RAID is not a replacement for a backup! Here's why.

Main Menu

AirStation HP N300 DD-WRT CVE-2002-1463 ISN vulnerability

Started by DoctorDOS, November 05, 2018, 01:06:20 PM

Previous topic - Next topic

DoctorDOS

A customer has a dedicated Internet connection for their point of sale debit machine.  In order to pass PCI compliance they they have to have their network scanned by a third party. https://www.pcicomplianceguide.org/faq/ .  It's basically a NESSUS scan.  The AIRSTATION_HIGHPOWER_N300_DD-WRT with the most recent firmware failed that test.  From the report...

The remote host seems to generate Initial Sequence Numbers (ISN) in a weak
manner which seems to solely depend on the source and dest port of the TCP
packets.
http://seclists.org/bugtraq/2002/Aug/60
http://securityresponse.symantec.com/avcenter/security/Content/2002.08.05.html

This is a bug that goes way back to 2002 that should have been patched with kernel V 2.4.  Any suggestions or alternative FW that we could try?  I did download the latest DD-WRT FW but it would not load from the web interface and I don't wish to brick the unit.

Browser ID: smf (is_webkit)
Templates: 4: index (default), Display (default), GenericControls (default), GenericControls (default).
Sub templates: 6: init, html_above, body_above, main, body_below, html_below.
Language files: 5: index+Modifications.english (default), Post.english (default), Editor.english (default), Drafts.english (default), StopForumSpam.english (default).
Style sheets: 4: index.css, attachments.css, jquery.sceditor.css, responsive.css.
Hooks called: 118 (show)
Files included: 35 - 1354KB. (show)
Memory used: 934KB.
Tokens: post-login.
Queries used: 15.

[Show Queries]