Skip to content

some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G.

License

Notifications You must be signed in to change notification settings

elvanderb/TCP-32764

Repository files navigation

I WILL NOT MANUALLY UPDATE THIS REPOSITORY ANYMORE

If you want to add a router in the list, please make a pull-request, also remember to USE THE POC and paste the result in your pull-request. Telnet clients and other solutions may not be relevant (some false negative / positive reported).

Some random code/data about the backdoor I found in my Linksys WAG200G (TCP/32764).

The backdoor may be present in other hardware, I'll update this readme accordingly. :)

Possible fix :

Probable source of the backdoor:

Backdoor LISTENING ON THE INTERNET confirmed in :

  • Linksys WAG120N (@p_w999)
  • Netgear DG834B V5.01.14 (@domainzero)
  • Netgear DGN2000 1.1.1, 1.1.11.0, 1.3.10.0, 1.3.11.0, 1.3.12.0 (issue 44)
  • Netgear WPNT834 (issue 79)
  • OpenWAG200 maybe a little bit TOO open ;) (issue 49)

Backdoor confirmed in:

Backdoor may be present in:

Backdoor is not working in:

Some clarifications: I didn't want to waste my time in writing a full report, it's a very simple backdoor that really doesn't deserve more than some crappy slides. Moreover, my English is quite bad.

I had a lot of fun in writing / drawing the slides, all the necessary information is in them. If people don't understand them or find them "too full of meme" then - well - it's too bad for them. :)

About

some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 18