D-Link Forums

The Graveyard - Products No Longer Supported => Routers / COVR => DIR-635 => Topic started by: Tinchote on June 04, 2015, 11:17:30 AM

Title: Security scan fails w/ TFTP Server open - how to close??
Post by: Tinchote on June 04, 2015, 11:17:30 AM
This is not a fake scan. On my DIR 632, using tftp, I was able to read /etc/passwd and /etc/hosts, and to upload a file to; to make it worse, I was able to do this from outside the LAN.
Title: Re: Security scan fails w/ TFTP Server open - how to close??
Post by: FurryNutz on June 04, 2015, 11:20:40 AM
Link>Welcome! (http://forums.dlink.com/index.php?topic=48135.0)

Title: Re: Security scan fails w/ TFTP Server open - how to close??
Post by: Tinchote on June 04, 2015, 11:25:47 AM
Thanks. It's a DIR 632. hardware A1, firmware 1.01NA.

I'm in Canada. I'm accessing the router through the internet, I'm some 4km away from it; that's the scary thing, I don't mind if a port is opened towards the LAN, but this is opened wide to the world.

I run, on my console, "tftp my-router-ip GET /etc/passwd" and I was able to retrieve the file. I was also able to upload a file.
Title: Re: Security scan fails w/ TFTP Server open - how to close??
Post by: FurryNutz on June 04, 2015, 11:30:46 AM
I recommend upgrading the routers FW and see if this issue is closed:
http://support.dlink.ca/ProductInfo.aspx?m=DIR-632 (http://support.dlink.ca/ProductInfo.aspx?m=DIR-632)

Please follow this for updating FW: Link> >FW Update Process (http://forums.dlink.com/index.php?topic=42457.0)

"This product has been discontinued.
Free support for this product has ended on 08/02/2014"
Title: Re: Security scan fails w/ TFTP Server open - how to close??
Post by: Tinchote on June 04, 2015, 11:35:44 AM
Thanks, I'll try that.
Title: Re: Security scan fails w/ TFTP Server open - how to close??
Post by: FurryNutz on June 04, 2015, 11:40:27 AM
Let us know how it turns out.
Title: Re: Security scan fails w/ TFTP Server open - how to close??
Post by: Tinchote on June 05, 2015, 09:33:55 AM
So, I upgraded to the latest firmware (1.03) and port 69 UDP is still wide open. I tried to check some of the options to see where this could come from, but I came up empty; in particular, remote management is disabled.
Title: Re: Security scan fails w/ TFTP Server open - how to close??
Post by: FurryNutz on June 05, 2015, 09:40:20 AM
There any programs like logging or other on the PC that could have this port open?

Is check up dates on the router enabled if there is this feature on this model router? Disable and check.