My super hub (which I will refer to a router from here on as it's neither super nor a hub) is a Netgear VMDG480, I have no idea what the firmware was before the update but it is now on boot code 2.3.0beta7 software version R36. This info can be found by connecting to your router in a browser and going to router status in the top right of the page (before you log on).
I was worried that this would mean re-configuring my wireless and port forwards etc but thought it was worth it for the potential fix to ssh.
The first step was to press and hold the reset button on the router for 20 seconds. I counted this out much to the amusement of the tech support operative however it looks like 20 seconds is when the virgin logo on the front of the router (normally Blue) turns red. I released the reset button and waited for the lights to calm down.
After renewing the dhcp lease on my PC ( start, run, cmd, ipconfig /renew) I logged onto the router which was now on 192.168.0.1, my first task was to change the ip address back to 192.168.1.1 as that's what the rest of my network would be expecting. Turns out this is not as simple as it ought to be.


The DHCP setup is a little different to "normal". You enter the starting IP address for the DHCP range and then specify how many users you want. This then sets the end IP address. A little backward if you ask me but then since when has the router IP address been a DHCP option?
Please note that you need to click the Apply button from the bottom right of the window, wait for the router to restart, renew your IP and log back on to the router each time you change the IP address. Failure to do so will cause problems.
At this point I decided it would be a good idea to change the admin password, no option to change the username unfortunately but I wasn't expecting miracles. From the advanced menu you will find the password option in the "user interface management" part of the "device management" section. Turns out they are doing something wrong with the passwords as there is a limit of 15 characters and can only be letters and numbers. No salted hashing going on there then.....Still, that's not a bad length and alphabet size.
Last but not least there are two very insecure, flawed systems turned on by default that need turning off.


That's about it for now. You could go and change the ssid and wpa key too as I always think having those on the back of the router is a bad plan (especially if someone can look through the window and see it) but I'm not going into that.
The Super-Dud also broadcasts its ssid un-encrypted for 7 seconds after a reboot. A reboot can be forced remotely.
ReplyDelete