Backdoor in the TP-Link routers
sekurak.pl
sekurak.pl
Unfortunately, stock firmware that comes with a lot routers has just been no good even if it lacked gaping security holes like this. Fortunately, there are community-developed FOSS alternatives that offer a better user experience; I imagine that having more eyes on the source also helps their security. I use TomatoUSB [2] on my main router (Asus RT-N66U) and OpenWrt on the "experimental" one (TP-Link TL-MR3020) and can highly recommend both distributions.
TPLink routers are great for custom firmware, I use to run DD-WRT but now run OpenWRT.
OpenWRT takes a little longer to get setup but once you do it runs perfectly and doesn't require any changes (I've been running mine for over a year without a hitch, before that years with ddwrt).
Was turned off by the look at the beginning after coming from DD-WRT, but I'm really happy with it so far - especially after getting QoS setup.
The configuration is really quite fantastic, and you can do pretty much anything you could want.
I was having major issues after two years, only last week, with an old Buffalo Wireless-N router. I switched over to DD-WRT last week and all was cured, and I'm getting better wireless performance.
TP-Link make money by selling fast cheap boxes. They cut corners on the firmware and testing.
Other manufacturers may be more expensive but I don't trust they aren't also cutting corners.
More modern web servers (and more lightweight) don't have that problem. They work for most configuration out-of-the-box (and perform better).
I don't know how Apache is configured on this particular router, but I can spot ten httptd-processes in on the process listing. So yes, Apache is likely both a bad choice to start with and beyond that, it is also poorly configured.
Firmware Version: 3.12.4 Build 100910 Rel.57694n
Hardware Version: WR741N v1/v2 00000000
it works :-/Currently I'm running a Netgear Centria WNDR4700 (it was a freebie for various reasons) and it has the lovely habit of storing user names and passwords in plain text (file share user names and passwords are displayed in plain text, and they're always the same as login names and passwords so far as I can tell). Unfortunately I'm not aware of any custom firmwares for it. :(
I have a TP-LINK TL-WDR3500 buried in my closet. I hadn't realized it might work with custom firmware. The physical ports being 10/100 would still be annoying, but it might be worth looking into flashing it. Glad I saw this post. =)
But my inherent laziness is exactly why I keep it disabled. If I left it enabled I'd constantly just su instead of thinking about what it is I am doing and sudo only the relevant bits.