
ASUS RT-N66U Firmware version 3.0.0.4.374.5517
Security related issues:
1. Fixed remote command execution vulnerability
2. Fixed cross site scripting vulnerability
3. Fixed parameters buffer overflow vulnerability
4. Fixed XSS(Cross Site Scripting) vulnerability
5. Fixed CSRF(Cross Site Request Forgery) vulnerability
6. Added auto logout function. The timeout time can be configured in - Administration--> System
7. Included patches related to network map. Thanks for Merlin's contribution.
8. Fixed password disclosure in source code when administrator logged in.
9. Changed OpenSSL Library from 1.0.0.b to 1.0.0.d. Both OpenSSL versions are not vulnerable to heartbleed bug.
Others:
1. Fixed IPTV related issues.
2. Modified the 3G/LTE dongle setting process in quick internet setup wizard.
3. Fixed the Cloud sync problem
4. Fixed Parental control check box UI issues.
5. Modified the FTP/ Samba permission setting UI
6. Modified media server setting UI
7.Samba/ media server/ iTunes server name can be changed.
8. Dual wan fail over now support fail back
9. Fixed wake on lan magic packet sending issue.
10. Fixed false alarm for samba and ftp permission.
11. Fixed IPv6 related issues.
Special thanks for David and Palula’s research
CVE-2014-2719 http://dnlongen.blogspot.com/2014/04/CVE-2014-2719-Asus-RT-Password-Disclosure.html
Remote command execution http://seclists.org/fulldisclosure/2014/Apr/58
Reflected XSS: http://seclists.org/fulldisclosure/2014/Apr/59
大家趕快更新吧
這次也修正了 OpenSSL 的超重大 BUG:Heartbleed
OpenSSL重大漏洞Heartbleed 全球網路加密傳輸安全拉警報
jackblackevo wrote:
大家趕快更新吧
這次也修正了 OpenSSL 的超重大 BUG:Heartbleed
感謝大大提醒,但一般家用真的無須過度緊張,除非架站又掛了SSL憑證(由其是使用OpenSSL加密的Server),不然要影響到家用群實在微乎其微。再說連試了幾次最新版,測到目前為止依舊老版本v3.0.0.4.374.257 最適合我家惡劣環境!速度唯它最穩、最速。
===============================
老實說,我已經麻木了不想再測試新版....

再v3.0.0.4.374.257之後的任何版本,無線能力實在有夠差!
縱使有訊號網路品質卻非常差!
愛把手機拿直向錄影,不知很浪費畫面嗎?
內文搜尋

X