Re: [OpenWrt-Devel] OpenWRT www version banner a security risk

2015-09-14 Thread MauritsVB
x27;re not skilled enough to limit access to LuCI (or better, build an >>image without LuCI and just use SSH) to the specific trusted hosts >> (preferably by combination of MAC address and IP address) in the >>firewall, or (better) to use a 'management' VPN or VLA

Re: [OpenWrt-Devel] OpenWRT www version banner a security risk

2015-09-13 Thread MauritsVB
on is for LuCI to have a banner that > indicates that the LuCI is visible on the WAN, thus alerting the user to a > misconfiguration, if it is that. > > Regards, > > Daniel > > On 2015-09-13 10:21 AM, MauritsVB wrote: >> At the moment the OpenWRT www login screen pr

[OpenWrt-Devel] OpenWRT www version banner a security risk

2015-09-13 Thread MauritsVB
At the moment the OpenWRT www login screen provides *very* detailed version information before anyone has even entered a password. It displays not just “15.05” or “Chaos Calmer” but even the exact git version on the banner. While it’s not advised to open this login screen to the world, fact is t