I have already submitted supout files for both routers and the response I got back from them says they didn't read my message in the first place. "Check the proxy, config, etc". The only way I know it's active is the output traffic from it's preferred IP address, and the fact that port 64312 is open. I can telnet to it and connect but it doesn't say anything and disconnects when you send a line. I have two IP addresses on the router, the exploit only talks on the preferred IP. I have that blocked via the output chain in the firewall but can still reach the device and verify the port via the second IP address. If I remove the blocks connections pour in over 64312 and the router initiates a bunch of HTTP, HTTPS, IMAPS, and SMTP connections. The routers does not NAT any user traffic except for DNS port 53. So it shouldn't have any of this traffic. It's blocked via the output chain when it shouldn't be there at all.
Both routers run a satellite connection for a rural ISP, that critter has got to go.
I tried using reset to force a netinstall on one of the yesterday. When reset is held in the unit will not BOOT, it had to be power cycled for it to become active again. This did erase the config. Once setup again the unwanted traffic was still active.
torch.gif
torch2.gif
You do not have the required permissions to view the files attached to this post.