Vulnerability Development mailing list archives

Linksys Cable Router DOS?


From: Steven Taylor <stillio () NETSCAPE NET>
Date: Sun, 25 Mar 2001 22:38:54 -0500

Hi all,

Is anyone aware of an exploit developed which specifically hits Linksys cable modems?  And when I say DOS, I mean 
deletes everything but the firmware... configs, logs, everything goes blank.  It happens about twice a night on 
Adelphia.net, so curiousity forced me to put a sniffer on a shared hub between the cable modem and the Linksys and 
other than occasional arp parties (arp storms) and CDP, the only really odd traffic I've noted has been sunrpc's 
(pretty clear indicator there...) from addresses that aren't individually resolvable.

Has anyone seen any of this?  I'd love to capture the packet that does this, but normally the whole segment goes out 
when this happens... even the upstream default router (Cisco).  I'm trying to troubleshoot this to determine if it's 
just a bad Linksys box or somebody blowing it up on a regular basis...

Regards

__________________________________________________________________
Get your own FREE, personal Netscape Webmail account today at http://webmail.netscape.com/


Current thread: