Deprecated FON Boards !

Visit forum.fon.com
It is currently Thu Sep 09, 2010 09:00

All times are UTC + 1 hour




Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 27 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: WRT54GL | a WDS repeater will bypass authentication!
PostPosted: Thu Nov 23, 2006 10:18 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
Hello world.

After purchasing a Siemens SE505 router (which are sold for cheap at eBay) I flashed DD-WRT v23 SP2 micro on it and configured my FON hotspot (WRT54GL) as well as my SE505 for WDS.

It works, but as soon as you connect to the SE505 there's no need for authentication! Neither will the FON portal appear - you just get direct internet access.

So, am I mistaking something or is it just another great FON feature?

regards,

Christian

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 11:48 
Offline
Fonero Pub A
Fonero Pub A
 WWW  Profile

Joined: Wed Jul 26, 2006 13:27
Posts: 231
Location: Germany
nothing new
this "feature" already has been reported some weeks ago ;)

_________________
status: Linus
setup: Debian Router » Linksys WRT54G + La Fonera
firmware: custom (based on dd-wrt) overclocked to 216 mhz and a modified Fonera firmware
link: 3Mbit down 512 kbit/s up

My Fonera Stuff
How to add a third signal to your Fonera


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 12:17 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
Since it was me, who reported this bug explicitly on this board, I know that. But I thought only wired computers, that are connected to the WDS slave are affected. Actually also wireless clients on the WDS slave will bypass authentication.
As automatic WDS is still enabled by default (at least on the WRT54GL), FON is absolutely unsafe!

And our friends in Munich keep posting on their blog, that FON has a secure authentication system. (see: "FON.com bietet diese geforderte Schutzmöglichkeit in idealer Weise, da der Zugang zum Internet über den FON:Router nicht ungeschützt, sondern mit Userkennung und Passwort geschützt ist.")

Since they don't take action, it's time to report this to the press and consumer protection. Also T-Mobile - as their competitor - may be interested in admonishing this for "unfair competition".

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 16:14 
Offline
Fonero A
Fonero A
 Profile

Joined: Tue Feb 21, 2006 13:24
Posts: 42
I guess if it's possible with a WDS router, that it will also be possible without one: Just make you pc 'pretend' to be a WDS router, and surf all Fonspots without authentication?


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 16:18 
Offline
Fonero Pub A
Fonero Pub A
 WWW  Profile

Joined: Wed Jul 26, 2006 13:27
Posts: 231
Location: Germany
PanMan wrote:
I guess if it's possible with a WDS router, that it will also be possible without one: Just make you pc 'pretend' to be a WDS router, and surf all Fonspots without authentication?


It's, I did it with my notebook and firmware v. 6.6.0.

_________________
status: Linus
setup: Debian Router » Linksys WRT54G + La Fonera
firmware: custom (based on dd-wrt) overclocked to 216 mhz and a modified Fonera firmware
link: 3Mbit down 512 kbit/s up

My Fonera Stuff
How to add a third signal to your Fonera


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 17:38 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
A couple of editors have contacted me and are likely to report about this issue after FON hasn't taken action for two months now.
Does anyone know, if la Fonera is of this affected, too?

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 17:45 
Offline
Fonero Pub A
Fonero Pub A
 WWW  Profile

Joined: Wed Jul 26, 2006 13:27
Posts: 231
Location: Germany
inquisitor wrote:
A couple of editors have contacted me and are likely to report about this issue after FON hasn't taken action for two months now.
Does anyone know, if la Fonera is of this affected, too?


fonera isn't afflicted, no WDS at all.

_________________
status: Linus
setup: Debian Router » Linksys WRT54G + La Fonera
firmware: custom (based on dd-wrt) overclocked to 216 mhz and a modified Fonera firmware
link: 3Mbit down 512 kbit/s up

My Fonera Stuff
How to add a third signal to your Fonera


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 17:45 
Offline
MOD
MOD
User avatar
 WWW  Profile

Joined: Thu Feb 09, 2006 02:25
Posts: 976
Hello, I will have our development team investigate. If you discover a bug in the future please e-mail or PM me and I will get it fixed.


Top
 
 Post subject:
PostPosted: Thu Nov 23, 2006 18:02 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
Thank you for your quick reaction, Ross.

It would be great if the development team acutally fixes the problem and doesn't only disable WDS.

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
 Post subject:
PostPosted: Wed Dec 06, 2006 16:27 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
Any progress of the bug fixing so far?

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
 Post subject: Nothing new
PostPosted: Fri Dec 08, 2006 04:11 
Offline
Fonero
Fonero
 Profile

Joined: Sat May 13, 2006 22:15
Posts: 7
This problem has been around for a long time. I found it when I first got my Fon AP, and reported it in May. Your "editor" friends should go ahead with the expose - this is very old news.

Here's the thread:
http://boards.fon.com/viewtopic.php?t=718


Top
 
 Post subject:
PostPosted: Sat Dec 30, 2006 20:43 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
@Ross

5 weeks have passed now - will you guys ever fix this or not?

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
 Post subject: pending reply
PostPosted: Sun Jan 07, 2007 12:28 
Offline
Fonero
Fonero
 Profile

Joined: Thu Mar 02, 2006 19:49
Posts: 5
Location: Germany, Munich, Neuhausen
Hi,

@inquisitor : had you sent an email to ross ?

I have the problem to - sent an email to bugs@fon.com.
(according to: http://boards.fon.com/viewtopic.php?t=2006)

Can anyone post a current state ?

Thanks !

Ansas

_________________
QotM: "You can't stop the signal, Mal, everything goes somewhere, and I go everywhere."

T-DSL 6000 & meOme Flat
Fritz!BoxFon Wlan 7050 providing POTS & VoiP of: T-Online, 1&1, sipgate.de
WRT54GSv4 with FON FW attached to the FritzBox 7050 LAN Port
SX541 via WDS attached to FON
Fritz!Box Fon Wlan via WDS attached to FON


Top
 
 Post subject:
PostPosted: Sun Jan 07, 2007 17:03 
Offline
FON-FRIENDS
FON-FRIENDS
User avatar
 WWW  YIM  Profile

Joined: Fri Feb 24, 2006 23:16
Posts: 5869
Location: Austin, Texass
I think Ross is on vacation right now.

_________________
AustinTX: is the top board poster and a Fon blogger, but is not a Fon rep. His posts are personal opinion.
Professional background: IT Supervisor, ISP NOC Tech, DSL - ISDN - Dialup - Web Hosting
Web Links: << El Fon Blog >><< Blog RSS Feed >><< skype/gizmo/aim/yahoo/gtalk:elfonblog >>
Latest Blog Entry Feb 13, 2010: Martin Heroicly Rallies Support For New Fon SIMPL


Top
 
 Post subject: on this matter
PostPosted: Tue Jan 09, 2007 07:05 
Offline
Fonero
Fonero
 Profile

Joined: Thu Mar 02, 2006 19:49
Posts: 5
Location: Germany, Munich, Neuhausen
@austinTX

Ross answered my email on the 8th and promised an answer this week.

Also my eMail to bugs@fon.com had been recieved...

Lets see what comes out of it....

Updates:
20070110 Got Ticket NR 070108-000085 - it is in development...
20070112 no further information

_________________
QotM: "You can't stop the signal, Mal, everything goes somewhere, and I go everywhere."

T-DSL 6000 & meOme Flat
Fritz!BoxFon Wlan 7050 providing POTS & VoiP of: T-Online, 1&1, sipgate.de
WRT54GSv4 with FON FW attached to the FritzBox 7050 LAN Port
SX541 via WDS attached to FON
Fritz!Box Fon Wlan via WDS attached to FON


Top
 
 Post subject:
PostPosted: Mon Jan 15, 2007 11:38 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
The week has passed and we're still waiting for an answer. Exemplary for FON.

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
 Post subject:
PostPosted: Mon Jan 15, 2007 12:45 
Offline
FON Support Community
FON Support Community
User avatar
 WWW  Profile

Joined: Fri Jul 21, 2006 01:08
Posts: 669
Location: Vienna / Austria
Hi inquisitor, hi AustinTX,

as Ross told me in an past talk last summer there will be no further FON developement on the 0.6.6. firmware for the old routers.
I don't know if this statement is still valid for FON but I think thus we can forget about this bugfix.

Regards, Kyros

_________________
Image


Top
 
 Post subject: no FON reply - update 2
PostPosted: Mon Jan 15, 2007 13:40 
Offline
Fonero
Fonero
 Profile

Joined: Thu Mar 02, 2006 19:49
Posts: 5
Location: Germany, Munich, Neuhausen
Hi,

in generally when, where and which Firmware this behavior is fixed is up to FON - because their people/resources/money are working on it.

But to have informations about it as "we are working on it" - or something else would be needed. Current status for me is: FON could not reproduce in the past (which I am am) so I can assist in this matter.

Simply - in a few weeks further - this goes to some IT newstickers - the pressure will come.
(known as Heise DOS.. 8-) )

I am not pushing anyone - and I do not thread FON with this, I simply cannot spread the FON "signal".

See you later in this matter....

Ansas

update 20070115:1502

Ross mailed via PM, he escalated this issue and will update this post with info.

_________________
QotM: "You can't stop the signal, Mal, everything goes somewhere, and I go everywhere."

T-DSL 6000 & meOme Flat
Fritz!BoxFon Wlan 7050 providing POTS & VoiP of: T-Online, 1&1, sipgate.de
WRT54GSv4 with FON FW attached to the FritzBox 7050 LAN Port
SX541 via WDS attached to FON
Fritz!Box Fon Wlan via WDS attached to FON


Top
 
 Post subject:
PostPosted: Mon Jan 15, 2007 16:39 
Offline
FON-FRIENDS
FON-FRIENDS
User avatar
 WWW  YIM  Profile

Joined: Fri Feb 24, 2006 23:16
Posts: 5869
Location: Austin, Texass
kyros wrote:
...there will be no further FON developement on the 0.6.6. firmware for the old routers. I don't know if this statement is still valid for FON but I think thus we can forget about this bugfix.
If true, this would be very poor policy, and also another slap in the face of those who still find themselves bound to obligations by a company which does not see fit to uphold those obligations which it suggested it would. :(

Fon would do well to fully support the Linksys routers at least until the very last Linksys they sold has been on for a full year. It would also be unwise to dump thousands of people then, just because they don't have the proprietary el cheapo router.

Fon needs to move forward as a community which makes shared wifi accessible through whatever equipment that can be made compatible. In order to survive, Fon needs to move forward as a flexible system that shares a common membership base, not as a B-grade competitor that focuses too much on proprietary hardware, locked down systems and one-size-doesn't-fit-all financial terms.

If Fon could only learn to encourage cooperation instead of marching on, seeking ways to seize control.

_________________
AustinTX: is the top board poster and a Fon blogger, but is not a Fon rep. His posts are personal opinion.
Professional background: IT Supervisor, ISP NOC Tech, DSL - ISDN - Dialup - Web Hosting
Web Links: << El Fon Blog >><< Blog RSS Feed >><< skype/gizmo/aim/yahoo/gtalk:elfonblog >>
Latest Blog Entry Feb 13, 2010: Martin Heroicly Rallies Support For New Fon SIMPL


Top
 
 Post subject:
PostPosted: Wed Jan 24, 2007 11:00 
Offline
FONBetaTester
FONBetaTester
User avatar
 Profile

Joined: Tue Feb 07, 2006 00:48
Posts: 620
Location: Germany
Ross' answer is overdue more than a week now and the bug is unfixed for 2 months since FON officially took notice of it.

Great job guys!

_________________
status: former Fonero (abandoned FON in 9/2008)
turnover/earnings from 3/2006 until 9/2008: € 36.88 / € 10.90


Top
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 27 posts ]  Go to page 1, 2  Next

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group  
Design By Poker Bandits