<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8379551625482719438</id><updated>2012-01-18T20:28:51.366+01:00</updated><title type='text'>Muhblog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-3628028061437776048</id><published>2007-04-10T16:00:00.000+01:00</published><updated>2007-04-10T16:22:21.258+01:00</updated><title type='text'>Autoupdate v0.7.1r3</title><content type='html'>There is a new firmware update to version 0.7.1r3. You can browse the contents &lt;a href="http://stefans.datenbruch.de/lafonera/upgrades/0.7.1-3/"&gt;here&lt;/a&gt;. Thanks Stefan!&lt;br /&gt;&lt;br /&gt;Kolofonium still working :-)&lt;br /&gt;&lt;br /&gt;Here a &lt;a href="http://www.fon.com/en/download/changelog"&gt;quote&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;Improvements:&lt;br /&gt;&lt;br /&gt;[Web Interface] New input chars accepted: added new chars as valid for some specific PPPoE usernames.&lt;br /&gt;[Time system] Improved network time server selection.&lt;br /&gt;Bugs:&lt;br /&gt;&lt;br /&gt;[Bandwidth sharing] Upload limitation error fixed.&lt;br /&gt;[Web Interface] Fixed Asian languages. Korean, Traditional Chinese and Japanese should work fine now.&lt;br /&gt;[Web Interface] Fixed port forwarding page. It will not fail anymore when trying to delete rules if the set is empty.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-3628028061437776048?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/3628028061437776048/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=3628028061437776048' title='19 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3628028061437776048'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3628028061437776048'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/04/autoupdate-v071r3.html' title='Autoupdate v0.7.1r3'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>19</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-6904038631812867130</id><published>2007-03-19T11:23:00.000+01:00</published><updated>2007-03-19T11:26:55.189+01:00</updated><title type='text'>Stefan vs. FON</title><content type='html'>For the German guys. &lt;a href="http://stefans.datenbruch.de/lafonera/stefanvsfonblog.shtml"&gt;Here&lt;/a&gt; is an interesting story about the FON's blog-comment policy.&lt;br /&gt;&lt;br /&gt;BTW, Kolofonium freed nearly 300 La Foneras.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-6904038631812867130?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/6904038631812867130/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=6904038631812867130' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/6904038631812867130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/6904038631812867130'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/03/httpstefansdatenbruchdelafonerastefanvs.html' title='Stefan vs. FON'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-8793272481173332334</id><published>2007-03-13T14:54:00.000+01:00</published><updated>2007-03-14T21:19:40.758+01:00</updated><title type='text'>Kolofonium is out!</title><content type='html'>To all the naggers: "Here you are!"&lt;br /&gt;&lt;br /&gt;Kolofonium is described in detail at &lt;a href="http://stefans.datenbruch.de/lafonera/#kolofonium"&gt;Stefan's website&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For all the road runners:&lt;br /&gt;Change the &lt;b&gt;nameserver&lt;/b&gt; (DNS) of your La Fonera to &lt;code&gt;88.198.165.155&lt;/code&gt; and reboot. Now you should be able to connect via SSH. This should work with other firmwares, too. Please change the nameserver according to your ISP or network setup after the reboot.&lt;br /&gt;&lt;br /&gt;That's it! Have fun!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here is a cute counter. For each "freed" La Fonera there is one icon:&lt;/br&gt;&lt;br /&gt;&lt;iframe src="http://stefans.datenbruch.de/lafonera/kolofonium-indicator.sh" width="239" frameborder="0"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-8793272481173332334?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/8793272481173332334/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=8793272481173332334' title='61 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8793272481173332334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8793272481173332334'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/03/kolofonium-is-out.html' title='Kolofonium is out!'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>61</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-7015675449420998677</id><published>2007-02-28T16:40:00.001+01:00</published><updated>2007-03-13T09:25:57.961+01:00</updated><title type='text'>Kolofonium is coming very soon!</title><content type='html'>&lt;strike&gt;Just a few more days! Be patient.&lt;/strike&gt;&lt;br /&gt;&lt;br /&gt;Just a few more hours!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://stefans.datenbruch.de/lafonera/#kolofonium"&gt;http://stefans.datenbruch.de/lafonera/#kolofonium&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-7015675449420998677?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/7015675449420998677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=7015675449420998677' title='45 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/7015675449420998677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/7015675449420998677'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/02/kolofonium-is-coming.html' title='Kolofonium is coming very soon!'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>45</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-3426233727987508746</id><published>2007-01-24T11:17:00.000+01:00</published><updated>2007-01-24T12:28:47.262+01:00</updated><title type='text'>FON reminds users to use unmodified software</title><content type='html'>The German FON blog &lt;a href="http://blog.fon.com/de/archive/technology/registrierung-der-la-fonera.html"&gt;reminds the users&lt;/a&gt; to use only official FON software. They quote point 6.7 of the general conditions.&lt;br /&gt;&lt;br /&gt;The German version:&lt;br /&gt;&lt;blockquote&gt;Um eine korrekte Funktion der FON Hotspots zu gewährleisten, müssen die Linuse und Bills ausschließlich offizielle Versionen der FON Software einsetzen.&lt;/blockquote&gt;The English version:&lt;br /&gt;&lt;blockquote&gt;In order to guarantee the correct functioning of the FON Hotspots, the Linuses and Bills shall exclusively use the official versions of the FON Software.&lt;/blockquote&gt;&lt;br /&gt;It is interesting that the German version says "müssen" (engl. to have to) and the English version says "shall". I am not a lawyer, but it looks strange to me. Anyone (especially lawyers) knows how to interpret such terms please leave a comment.&lt;br /&gt;&lt;br /&gt;The following is fully neutral: Please read the comments and answers of Peter of the blog. Very interesting... Sorry, but this is in German. But the non-German readers can try &lt;a href="http://translate.google.com/translate?u=http%3A%2F%2Fblog.fon.com%2Fde%2Farchive%2Ftechnology%2Fregistrierung-der-la-fonera.html&amp;langpair=de%7Cen&amp;hl=en&amp;ie=UTF8"&gt;Google translate&lt;/a&gt;. (Bear in mind that the quoted part of the condition is also translated from the German version.)&lt;br /&gt;&lt;br /&gt;Furthermore the German FON blog is moderated, this means submitted comments need further approval. Stefan offered them information about &lt;a href="http://stefans.datenbruch.de/lafonera/flaws.shtml"&gt;a security flaw with the firewall rules when using multiple IP subnets&lt;/a&gt;. His comment is still not published yet...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-3426233727987508746?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/3426233727987508746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=3426233727987508746' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3426233727987508746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3426233727987508746'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/01/fon-reminds-users-to-use-unmodified.html' title='FON reminds users to use unmodified software'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-7606481785169184871</id><published>2007-01-13T11:46:00.000+01:00</published><updated>2007-01-13T11:57:28.615+01:00</updated><title type='text'>Codename Kolofonium release date</title><content type='html'>Hey guys, Stefan and me won't release the hack for the new 0.7.1-2 version until the first La Foneras with a flashed 0.7.1-2 firmware will be shipped. Its codename is "kolofonium" and it is easy as using the La Fonera's web interface (this time with your standard browser!).&lt;br /&gt;&lt;br /&gt;We won't release it earlier, because you can reset the La Foneras to its flashed firmware and use one the known hacks. Freddy described several ways to do it &lt;a href="http://fon.freddy.eu.org/fonera/howto-factory-reset.txt"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Please leave a comment when you get your first 0.7.1-2 flashed La Fonera.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-7606481785169184871?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/7606481785169184871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=7606481785169184871' title='172 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/7606481785169184871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/7606481785169184871'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/01/codename-kolofonium-realease-date.html' title='Codename Kolofonium release date'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>172</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-6913896991973123785</id><published>2007-01-08T20:36:00.000+01:00</published><updated>2007-01-08T21:45:41.863+01:00</updated><title type='text'>We did it again!</title><content type='html'>After a few days of searching and trying, we found yet another way to open the SSH port of a La Fonera. It works with all firware versions (also the new 0.7.1-2). Stay tuned!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-6913896991973123785?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/6913896991973123785/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=6913896991973123785' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/6913896991973123785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/6913896991973123785'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/01/we-did-it-again.html' title='We did it again!'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-6940577766344227004</id><published>2007-01-03T17:53:00.000+01:00</published><updated>2007-01-05T17:10:12.849+01:00</updated><title type='text'>Fonera Autoupdate version 0.7.1 rev 2</title><content type='html'>My La Fonera just wants a new autoupdate. The extracted &lt;code&gt;.fon&lt;/code&gt; is available &lt;a href="http://stefans.datenbruch.de/lafonera/upgrades/0.7.1-2/unpacked/upgrade_0712.tar.gz-unpacked/"&gt;here&lt;/a&gt;  (thanks to Stefan).&lt;br /&gt;&lt;br /&gt;It updates the webinterface, the &lt;code&gt;validate.awk&lt;/code&gt; (checks correct input of the webinterface) and &lt;code&gt;haserl&lt;/code&gt; (CGI wrapper for shell scripts).&lt;br /&gt;&lt;br /&gt;&lt;strike&gt;We will investigate if they fixed webinterface.&lt;/strike&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Update:&lt;/span&gt; We tried a lot, but still with no luck. It looks like, the FON developers did a good job (this time). But we didn't give up yet...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-6940577766344227004?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/6940577766344227004/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=6940577766344227004' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/6940577766344227004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/6940577766344227004'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/01/fonera-autoupdate-version-071-rev-2.html' title='Fonera Autoupdate version 0.7.1 rev 2'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-2902954733009508915</id><published>2007-01-02T23:06:00.000+01:00</published><updated>2007-01-02T23:35:38.707+01:00</updated><title type='text'>Chillispot for OpenWrt for FON</title><content type='html'>FON &lt;a href="http://stefans.datenbruch.de/lafonera/sources/extracted/package/chillispot/patches/"&gt;patched&lt;/a&gt; &lt;code&gt;chillispot&lt;/code&gt; a little bit. E.g. the &lt;code&gt;001-endian_fix.patch&lt;/code&gt; fixes the dhcp server of &lt;code&gt;chillispot&lt;/code&gt;. This one and &lt;code&gt;100-fon.patch&lt;/code&gt; works fine with &lt;code&gt;chillispot&lt;/code&gt; 1.1, but the others need further attention. I am not a C programmer. Maybe someone could help.&lt;br /&gt;&lt;br /&gt;Anyway you can use the &lt;code&gt;chillispot&lt;/code&gt; of the &lt;a href="http://download.fon.com/firmware/fonera/latest/fonera.tar.bz2"&gt;FON sources&lt;/a&gt;. It is version 1.0. It also installs &lt;code&gt;chilli_radconfig&lt;/code&gt;. You can generate the long string - describe in the previous post. Thanks Anton for the comment. He says, that you can just use &lt;code&gt;uamserver https://login.fon.com/cp/index.php&lt;/code&gt; in the &lt;code&gt;chilli.conf&lt;/code&gt;. Anyway, I generated the string with &lt;code&gt;chilli_radconfig&lt;/code&gt;. Maybe the string is needed for the first time registration of a La Fonera. &lt;a href="https://fon-en.custhelp.com/cgi-bin/fon_en.cfg/php/enduser/std_adp.php?p_faqid=144"&gt;This&lt;/a&gt; would support the assumption. But this is all speculations.&lt;br /&gt;&lt;br /&gt;I tried to use it but with no success yet. The chilli.conf looks like that:&lt;br /&gt;&lt;pre class="listing"&gt;radiusserver1 radius01.fon.com&lt;br /&gt;radiusserver2 radius02.fon.com&lt;br /&gt;radiussecret garrafon&lt;br /&gt;# MAC address of wlan device (wifi0)&lt;br /&gt;radiusnasid XX:XX:XX:XX:XX:XX&lt;br /&gt;&lt;br /&gt;# IP of the OpenFonera&lt;br /&gt;dns1 192.168.1.223&lt;br /&gt;dns2 192.168.1.223&lt;br /&gt;&lt;br /&gt;# interface of the FON_AP&lt;br /&gt;dhcpif ath0&lt;br /&gt;&lt;br /&gt;uamsecret garrafon&lt;br /&gt;uamanydns&lt;br /&gt;uamallowed www.martinvarsavsky.net,www.google.com,www.flickr.com,static.flickr.com,video.google.com,216.239.51.0/24,66.249.81.0/24&lt;br /&gt;uamallowed www.fon.com,www.paypal.com,www.paypalobjects.com,www.skype.com,66.249.93.0/24,72.14.207.0/24,72.14.209.0/24,84.96.67.0/24,213.91.9.0/24,80.118.99.0/24&lt;br /&gt;uamallowed shop.fon.co.kr,secure.nuguya.com,inilite.inicis.com,fon-en.custhelp.com,maps.fon.com,c20.statcounter.com&lt;br /&gt;uamserver https://login.fon.com/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX/cp/index.php&lt;/pre&gt;&lt;br /&gt;When I start it with &lt;code&gt;chilli -d -f -c /etc/chilli.conf&lt;/code&gt; and connecting a peer to the FON_AP the output is:&lt;pre class="listing"&gt;chillispot[675]: chilli.c: 3090: New DHCP request from MAC=XX-XX-XX-XX-XX-XX&lt;br /&gt;New DHCP connection established&lt;br /&gt;DHCP requested IP address&lt;br /&gt;chillispot[675]: ippool.c: 436: No more IP addresses available&lt;br /&gt;chillispot[675]: chilli.c: 3045: Failed allocate dynamic IP address&lt;br /&gt;DHCP requested IP address&lt;br /&gt;chillispot[675]: chilli.c: 3051: Client MAC=XX-XX-XX-XX-XX-XX assigned IP 192.168.182.2&lt;/pre&gt;&lt;br /&gt;When I try to open a webpage, &lt;code&gt;chillispot&lt;/code&gt; reports several times:&lt;pre class="listing"&gt;cb_dhcp_data_ind. Packet received. DHCP authstate: 5&lt;br /&gt;cb_tun_ind. Packet received: Forwarding to link layer&lt;/pre&gt;&lt;br /&gt;But it won't open a webpage. The redirection doesn't work. I think the problem is my iptables configuration. Anyone who knows how to set up iptables proper for &lt;code&gt;chillispot&lt;/code&gt; please leave a comment.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-2902954733009508915?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/2902954733009508915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=2902954733009508915' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2902954733009508915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2902954733009508915'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/01/chillispot-for-openwrt-for-fon.html' title='Chillispot for OpenWrt for FON'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-8804303162917488006</id><published>2007-01-02T10:58:00.000+01:00</published><updated>2007-01-02T11:07:46.976+01:00</updated><title type='text'>Chillispot configuration for OpenWRT for FON</title><content type='html'>As you know in the last days I flashed a La Fonera with OpenWRT (Kamikaze). Currently I am working on a proper configuration for chillispot, to make it possible to add FON support (FON AP) to every device running OpenWRT.&lt;br /&gt;&lt;br /&gt;Configuration is simple, but the problem is, that the &lt;code&gt;/etc/chilli.conf&lt;/code&gt; of an original La Fonera contains a line like:&lt;br /&gt;&lt;pre class="listing"&gt;uamserver https://login.fon.com/&lt;b&gt;XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&lt;/b&gt;/cp/index.php&lt;/pre&gt;&lt;br /&gt;The XXX... is a string of numbers and letters. This string is created by &lt;code&gt;/usr/sbin/chilli_radconfig&lt;/code&gt;. Stefan told me that &lt;code&gt;chilli_radconfig&lt;/code&gt; fetches the configuration file somehow from FON. One of the parameters for it is the MAC address of the WIFI device.&lt;br /&gt;&lt;br /&gt;I'll keep you up to date on any progress.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-8804303162917488006?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/8804303162917488006/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=8804303162917488006' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8804303162917488006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8804303162917488006'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2007/01/chillispot-configuration-for-openwrt.html' title='Chillispot configuration for OpenWRT for FON'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-8798578417646152677</id><published>2006-12-29T20:24:00.000+01:00</published><updated>2006-12-29T22:01:08.342+01:00</updated><title type='text'>OpenFonera</title><content type='html'>After receiving my second La Fonera I was brave enough to flash OpenWRT Kamikaze. The &lt;a href="http://www.dd-wrt.com/phpBB2/viewtopic.php?t=9011"&gt;used HOWTO&lt;/a&gt; described it very well and it worked without problems.&lt;br /&gt;&lt;br /&gt;Now my first La Fonera serves a FON hotspot and my private (bridged) LAN. The second La Fonera is connected to my privat LAN via WPA over the first La Fonera. Now I can play with OpenWRT (Kamikaze) on my second La Fonera.&lt;br /&gt;&lt;br /&gt;The described method uses the RedBoot shell. I don't know exactly how RedBoot works and wonder if it is possible to rescue the La Fonera in any case (wrong flashing, wrong configuration, ...). If anyone knows, please tell.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-8798578417646152677?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/8798578417646152677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=8798578417646152677' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8798578417646152677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8798578417646152677'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/12/openfonera.html' title='OpenFonera'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-2374261363355921570</id><published>2006-12-26T12:34:00.000+01:00</published><updated>2006-12-26T12:47:28.845+01:00</updated><title type='text'>OpenWRT for the La Fonera?</title><content type='html'>It is nothing new, that the firmware for the La Fonera is based on &lt;a href="http://www.openwrt.org"&gt;OpenWRT&lt;/a&gt;. But in the last few days the developers are making progress to get OpenWRT running on the La Fonera. I found an &lt;a href="http://forum.openwrt.org/viewtopic.php?id=7799"&gt;interesting thread&lt;/a&gt; on the OpenWRT forum. The developers &lt;a href="https://dev.openwrt.org/changeset/5898"&gt;added support&lt;/a&gt; for Atheros based devices (La Fonera, Meraki) to the Kamikaze (the experimental branch of OpenWRT). So don't grab the sources, compile it and flash it, unless you know what you are doing.&lt;br /&gt;&lt;br /&gt;My advice: Be patient and stay tuned!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-2374261363355921570?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/2374261363355921570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=2374261363355921570' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2374261363355921570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2374261363355921570'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/12/openwrt-for-la-fonera.html' title='OpenWRT for the La Fonera?'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-7349758661472699864</id><published>2006-12-22T18:25:00.000+01:00</published><updated>2006-12-24T14:57:55.362+01:00</updated><title type='text'>Code injection without the FON servers</title><content type='html'>Stefan and me have written another script to open your La Fonera. It works with the firmware version 0.7.1 rev 1. The script and more information is available &lt;a href="http://stefans.datenbruch.de/lafonera/#local"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;UPDATE:&lt;/span&gt; There are now two scripts available. One for the new and one for the old firmware version.&lt;br /&gt;&lt;br /&gt;Have yourself some happy holidays and Merry Christmas!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-7349758661472699864?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/7349758661472699864/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=7349758661472699864' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/7349758661472699864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/7349758661472699864'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/12/code-injection-withoug-fon-servers.html' title='Code injection without the FON servers'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-8279469078109131328</id><published>2006-12-22T10:29:00.000+01:00</published><updated>2006-12-22T13:50:58.398+01:00</updated><title type='text'>ipkg of the La Fonera broken?</title><content type='html'>Before christmas a new post. There are some issues with the ikpg system of the La Fonera. You can use repositories like &lt;a href="http://downloads.openwrt.org/people/mbm/mips/packages/"&gt;this&lt;/a&gt;, &lt;a href="http://olsrexperiment.de/sven-ola/fonera/"&gt;this&lt;/a&gt; and &lt;a href="http://fon.rogue.be/"&gt;this&lt;/a&gt;. I installed successfully e.g. the wol (Wake On Lan) package with &lt;code&gt;ipkg install wol&lt;/code&gt; after adding one of the repositories above. But after executing &lt;code&gt;ipkg remove wol&lt;/code&gt; it took too long, so I hit Ctrl-C. ipkg started to delete the &lt;code&gt;/usr/bin/&lt;/code&gt; directory. There is something wrong with the ipkg version of the La Fonera. &lt;b&gt;USE IT WITH CAUTION!&lt;/b&gt; I will try to investigate this issue.&lt;br /&gt;&lt;br /&gt;Hmm, it tried to install and remove a package again - without a flaw. Last night I did it, and the &lt;code&gt;/usr/bin&lt;/code&gt; was partly deleted. The difference between the two cases: &lt;span style="font-style:italic;"&gt;Last night I was a little bit impatient and hit Ctrl-C.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So my advice, keep it running and be patient. :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-8279469078109131328?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/8279469078109131328/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=8279469078109131328' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8279469078109131328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/8279469078109131328'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/12/ipkg-of-fonera-broken.html' title='ipkg of the La Fonera broken?'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-2065941575336385360</id><published>2006-11-27T21:15:00.000+01:00</published><updated>2006-11-29T15:31:28.381+01:00</updated><title type='text'>Updates explained and bridging mode</title><content type='html'>Yesterday I updated my La Fonera manually to version 0.7.1-1. There is an &lt;a href="http://de.fon.com/downloads/download_gateway.php?firmware=FONERA"&gt;update&lt;/a&gt; available, which really flashes the La Fonera. The &lt;a href="http://download.fon.com/firmware/update/0.7.0/4/upgrade.fon"&gt;update&lt;/a&gt; of the autoupdate is just a gzipped tarball containing updated files. I updated it without flashing, so in case of any bricking stuff I can reset my La Fonera. Stefan is &lt;a href="http://stefans.datenbruch.de/lafonera/upgrades.shtml"&gt;hosting information about it&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Finally the bridging mode with the private network works. It was really annoying that associated clients with the private network are masqueraded. Associated clients could access the LAN, but hosts of the LAN could not acces associated clients of the private signal.&lt;br /&gt;With the bridging mode associated clients are in the same subnet of the LAN - no more masquerading is needed. The bridging mode only affects the private signal, the public FON hotspot still uses masquerading.&lt;br /&gt;&lt;br /&gt;Frederik &lt;a href="http://fon.freddy.eu.org/fonera/bridge-private-wlan/"&gt;released a script&lt;/a&gt; for the bridging mode, but the FON hotspot did not function. I changed reworked it and now it works like a charm. Please start it manually and do not put it in /etc/init.d/. It possible it will not work with any version. It tried 0.7.1 rev 1 only.&lt;br /&gt;&lt;br /&gt;Ok, here it is. &lt;b&gt;You have to replace XX-XX-XX-XX-XX-XX with the MAC of the public FON hotspot! Please use it only if you know what you are doing.&lt;/b&gt;&lt;br /&gt;&lt;pre class="listing"&gt;#!/bin/ash&lt;br /&gt;echo "Setting up LAN bridge"&lt;br /&gt;&lt;br /&gt;# Kill DHCP server+ client&lt;br /&gt;/usr/bin/killall dnsmasq&lt;br /&gt;/usr/bin/killall -9 udhcpc&lt;br /&gt;&lt;br /&gt;# create bridge interface&lt;br /&gt;/usr/sbin/brctl addbr br0&lt;br /&gt;/usr/sbin/brctl stp br0 off &lt;br /&gt;/usr/sbin/brctl setfd br0 0&lt;br /&gt;&lt;br /&gt;# shutdown/remove IPs from the old interfaces&lt;br /&gt;/sbin/ifconfig eth0:1 down &lt;br /&gt;/sbin/ifconfig eth0 0.0.0.0&lt;br /&gt;/sbin/ifconfig ath1 0.0.0.0&lt;br /&gt;&lt;br /&gt;# bring up the bridge interface&lt;br /&gt;/sbin/ifconfig br0 up&lt;br /&gt;&lt;br /&gt;# add the old interfaces to the bridge&lt;br /&gt;/usr/sbin/brctl addif br0 ath1&lt;br /&gt;/usr/sbin/brctl addif br0 eth0&lt;br /&gt;&lt;br /&gt;# Set IP for the bridge&lt;br /&gt;/sbin/udhcpc -i br0 -R # get new IP via dhcp&lt;br /&gt;#/sbin/ifconfig br0 192.168.0.103 # static IP&lt;br /&gt;&lt;br /&gt;# set firewall rules&lt;br /&gt;iptables -A INPUT -i br0 -j ACCEPT&lt;br /&gt;iptables -A OUTPUT -o br0 -j ACCEPT&lt;br /&gt;&lt;br /&gt;# add bridge to hostapd.conf and restart hostapd (allows to use WPA) &lt;br /&gt;[ `grep -c bridge=br0 /tmp/hostapd.conf` = "0" ] &amp;&amp; echo bridge=br0 &gt;&gt; /tmp/hostapd.conf&lt;br /&gt;/usr/bin/killall killall hostapd&lt;br /&gt;/usr/sbin/hostapd -B /tmp/hostapd.conf&lt;br /&gt;&lt;br /&gt;# stopping chillispot&lt;br /&gt;/etc/init.d/N50chillispot stop&lt;br /&gt;&lt;br /&gt;# bringing ath0 (hotspot interface) down&lt;br /&gt;/sbin/ifdown hotspot&lt;br /&gt;&lt;br /&gt;# bringing it manually up&lt;br /&gt;wlanconfig ath0 create wlandev wifi0 wlanmode ap&lt;br /&gt;iwconfig ath0 essid "FON_AP"&lt;br /&gt;ifconfig ath0 up&lt;br /&gt;&lt;br /&gt;# restarting dnsmasq but without dhcp&lt;br /&gt;dnsmasq&lt;br /&gt;&lt;br /&gt;# restarting chilli&lt;br /&gt;chilli --dns1=192.168.1.222 --dns2=192.168.1.222 --radiusnasid=XX-XX-XX-XX-XX-XX --dhcpif ath0&lt;br /&gt;&lt;br /&gt;# configuring iptables&lt;br /&gt;iptables -R NET_ACCESS 6 -i br0 -j ACCEPT&lt;br /&gt;iptables -R NET_ACCESS 7 -o br0 -j ACCEPT&lt;br /&gt;iptables -t nat -R POSTROUTING 2 -o br0 -j MASQUERADE&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-2065941575336385360?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/2065941575336385360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=2065941575336385360' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2065941575336385360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2065941575336385360'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/updates-explained-and-bridging-mode.html' title='Updates explained and bridging mode'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>16</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-4220991633617107409</id><published>2006-11-24T20:05:00.000+01:00</published><updated>2006-11-29T17:53:20.359+01:00</updated><title type='text'>La Foneras want an autoupdate</title><content type='html'>FON wants all La Foneras to update. Here is the shellcode to be executed:&lt;br /&gt;&lt;pre class="listing"&gt;cd /tmp&lt;br /&gt;wget http://download.fon.com/firmware/update/0.7.0/4/upgrade.fon&lt;br /&gt;/bin/fonverify /etc/public_fon_rsa_key.der /tmp/upgrade.fon&lt;br /&gt;&lt;br /&gt;rm -f /tmp/.thinclient.sh&lt;br /&gt;&lt;br /&gt;exit&lt;/pre&gt;It will upgrade the La Fonera to 0.7.1 rev 1.&lt;br /&gt;&lt;br /&gt;Btw, if you want to have a look into the .fon files you can use this short unfonify.sh script:&lt;br /&gt;&lt;pre class="listing"&gt;#!/bin/sh&lt;br /&gt;SIZE=$(du -b $1 | cut -f1)&lt;br /&gt;tail -c $((SIZE-519)) $1 &gt; $1.tar.gz&lt;/pre&gt;Usage: unfonify.sh upgrade.fon&lt;br /&gt;It will cut off the first bytes containing the signature and generate a gzipped tarball, which you can easily extract.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;WARNING: If you still waiting for your La Fonera and want to gain ssh access, you should NOT connect it to the internet. Just plug in the powercable, connect to the private network (the WPA key is the serial no.) and &lt;a href="http://www.dd-wrt.com/phpBB2/viewtopic.php?p=40812#40812"&gt;exploit it via the webinterface&lt;/a&gt;.&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-4220991633617107409?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/4220991633617107409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=4220991633617107409' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/4220991633617107409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/4220991633617107409'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/fon-wants-to-autoupdate.html' title='La Foneras want an autoupdate'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-5716167842935117337</id><published>2006-11-24T09:59:00.000+01:00</published><updated>2006-11-24T20:54:00.015+01:00</updated><title type='text'>New Fonera Firmware v0.7.1 rev 1</title><content type='html'>As you can read on the &lt;a href="http://blog.fon.com/de/archive/technology/fonfirmware-v0711.html"&gt;german blog&lt;/a&gt; FON released a new firmware for the La Fonera. It's too bad they are not releasing the source along with it. I postet a comment on the blog&lt;strike&gt;, but it needs further aproval&lt;/strike&gt;.&lt;br /&gt;&lt;br /&gt;Among other things the changelog says:&lt;br /&gt;&lt;span style="font-style:italic;"&gt;"[Web interface] Corrected bug that caused a security problem when using strange characters on the forms."&lt;/span&gt;&lt;br /&gt;We will see if FON fixed the holes to get into the blackbox.&lt;br /&gt;&lt;br /&gt;Btw, yesterday we (Stefan and me) had a short meeting with Florian Forster in Cologne. He contacted us a few days after releasing our hack and is responsible for marketing in Germany. In the next days I will post a little bit about it. Here is a picture of his business card (of course some informations are disguised).&lt;br /&gt;&lt;br /&gt;&lt;img src="http://photos1.blogger.com/x/blogger2/4302/1022894485532558/320/549967/forster_businesscard.jpg"/&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-5716167842935117337?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/5716167842935117337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=5716167842935117337' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/5716167842935117337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/5716167842935117337'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/new-fonera-firmware-v0711.html' title='New Fonera Firmware v0.7.1 rev 1'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-3912726759794240715</id><published>2006-11-20T21:38:00.000+01:00</published><updated>2006-11-20T21:56:01.739+01:00</updated><title type='text'>2nd Hack</title><content type='html'>&lt;a href="http://bingobommel.blogspot.com"&gt;BingoBommel&lt;/a&gt; released another hack without using the webinterface of Fon which is fixed anyway. He also offers two HTML files to make it very easy to start and open SSH.&lt;br /&gt;&lt;br /&gt;BingoBommel uses one security hole, but there are more vulnerabilities in the webinterface of the La Fonera enabling code injection...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-3912726759794240715?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/3912726759794240715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=3912726759794240715' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3912726759794240715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3912726759794240715'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/2nd-hack.html' title='2nd Hack'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-1616391524580589795</id><published>2006-11-08T22:37:00.000+01:00</published><updated>2006-11-20T21:56:05.771+01:00</updated><title type='text'>FON fixed it</title><content type='html'>It looks like FON has fixed their webinterface. It is no longer possible to submit manipulated ESSIDs to the remote configuration interface.&lt;br /&gt;&lt;br /&gt;If you try it anyway, the section in the shell script is just gone. Same for the ESSID of your private network.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-1616391524580589795?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/1616391524580589795/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=1616391524580589795' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/1616391524580589795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/1616391524580589795'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/fon-fixed-it.html' title='FON fixed it'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-2013811375639916337</id><published>2006-11-07T00:23:00.000+01:00</published><updated>2006-11-07T22:51:26.397+01:00</updated><title type='text'>We did it, that's why</title><content type='html'>The release of "Hacking the La Fonera" set of an avalanche of discussions. To explain our motives we released &lt;a href="http://stefans.datenbruch.de/lafonera/whywedidit.shtml"&gt;"Hacking the La Fonera: Why we did it"&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Feel free to post comments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-2013811375639916337?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/2013811375639916337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=2013811375639916337' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2013811375639916337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2013811375639916337'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/we-did-it-thats-why.html' title='We did it, that&apos;s why'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-5992673156980393423</id><published>2006-11-05T22:26:00.000+01:00</published><updated>2006-11-06T18:33:30.911+01:00</updated><title type='text'>Open your La Fonera</title><content type='html'>We decided to publish a guide to "open" your La Fonera. Stefan is hosting it &lt;a href="http://stefans.datenbruch.de/lafonera/"&gt;here&lt;/a&gt;. You will find a detailed description of the remote configuration of La Fonera. Besides, a small Perl script is available to easily execute any shell code.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-5992673156980393423?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/5992673156980393423/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=5992673156980393423' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/5992673156980393423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/5992673156980393423'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/open-your-la-fonera.html' title='Open your La Fonera'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-605037132217026952</id><published>2006-11-04T18:38:00.000+01:00</published><updated>2006-11-04T18:55:33.676+01:00</updated><title type='text'>So FON decided not to read the man page, which turned out rather nasty...</title><content type='html'>After a little bit experimenting and a short chat with &lt;a href="http://stefans.datenbruch.de/"&gt;Stefan Tomanek&lt;/a&gt;, we successfully injected some code into the La Fonera without opening it.&lt;br /&gt;&lt;br /&gt;We are now able to connect via SSH (dropbear) to the La Fonera.&lt;br /&gt;&lt;br /&gt;So guys, get yourself a free La Fonera (at least in &lt;a href="http://de.fon.com/promise/"&gt;germany&lt;/a&gt;)!&lt;br /&gt;&lt;br /&gt;And thanks Stefan!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-605037132217026952?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/605037132217026952/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=605037132217026952' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/605037132217026952'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/605037132217026952'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/so-fon-decided-not-to-read-man-page.html' title='So FON decided not to read the man page, which turned out rather nasty...'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-3652888708452996670</id><published>2006-11-04T09:17:00.000+01:00</published><updated>2006-11-28T18:10:42.033+01:00</updated><title type='text'>The SSH Connection</title><content type='html'>La Fonera uses the dropbear SSH client with public key authentication. The private key of La Fonera is available in the &lt;a href="http://blog.fon.com/en/archive/general/la-fonera-source-code.html"&gt;sources&lt;/a&gt; (/etc/dropbear/key) and &lt;a href="http://fon.freddy.eu.org/fonera/fon-0.7.0-rev4/etc/dropbear/"&gt;here&lt;/a&gt;. It looks like every La Fonera uses the same private key with no passphrase. You can connect to download.fon.com and get the shell script (described earlier), if you type:&lt;br /&gt;&lt;pre class="listing"&gt;echo "mode='start' wlmac='&lt;span style="font-weight: bold;"&gt;FONERASWLANMAC&lt;/span&gt;' mac='&lt;span style="font-weight: bold;"&gt;FONERASETHERNETMAC&lt;/span&gt;' fonrev='4' firmware='0.7.0' chillver='1.0' thclver='1.0' device='fonera'" | dbclient -T -i &lt;span style="font-weight: bold;"&gt;PATHTOTHEPRIVATEKEY&lt;/span&gt; -p 1937 openwrt@download.fon.com&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-3652888708452996670?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/3652888708452996670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=3652888708452996670' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3652888708452996670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/3652888708452996670'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/ssh-connection.html' title='The SSH Connection'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-708358831285673424</id><published>2006-11-04T08:49:00.000+01:00</published><updated>2006-11-29T17:54:05.656+01:00</updated><title type='text'>Fonera phones home</title><content type='html'>Fonera starts a small sript &lt;a href="http://fon.freddy.eu.org/fonera/fon-0.7.0-rev4/bin/thinclient"&gt;thinclient&lt;/a&gt; at every bootup and &lt;a href="http://fon.freddy.eu.org/fonera/fon-0.7.0-rev4/etc/crontabs/root"&gt;every hour&lt;/a&gt;. The thinclient connects via SSH to download.fon.com:1937 and sends its mac addresses and version. It gets back a shell script which is dropped at /tmp/.thinclient.sh. This shell script is executed by the thinclient. Fon could paste any code there and has full control of La Fonera...&lt;br /&gt;&lt;br /&gt;Normally the shell script contains harmless code:&lt;br /&gt;&lt;pre class="listing"&gt;rm -f /tmp/.thinclient.sh&lt;br /&gt;exit&lt;/pre&gt;But you can configure La Fonera via the webpage of &lt;a href="http://www.fon.com/"&gt;FON&lt;/a&gt;. You can change the WPA key of the private WLAN, change the admin password, change the ESSIDs. If you do so the sended script looks different.&lt;br /&gt;&lt;br /&gt;Updating your ESSIDs:&lt;br /&gt;&lt;pre class="listing"&gt;# begin # setssidprivate&lt;br /&gt;awk -v cfgfile="/etc/config/fon" -v "updatestr=private.essid=&lt;span style="font-weight: bold;"&gt;YOURPRIVATEESSID&lt;/span&gt;" -f /usr/lib/webif/uci-update.awk -f - &gt; /etc/config/fon.new &amp;lt;&amp;lt;EOF&lt;br /&gt;BEGIN {&lt;br /&gt;       cfg = read_file(cfgfile)&lt;br /&gt;       print update_config(cfg, updatestr)&lt;br /&gt;}&lt;br /&gt;EOF&lt;br /&gt;if [ $? -eq 0 ]; then&lt;br /&gt;       mv /etc/config/fon.new /etc/config/fon&lt;br /&gt;       ifup lan&lt;br /&gt;else&lt;br /&gt;       rm /etc/config/fon.new&lt;br /&gt;fi&lt;br /&gt;# end # set ssid fonera&lt;br /&gt;&lt;br /&gt;# begin # set ssid fonera&lt;br /&gt;awk -v cfgfile="/etc/config/fon" -v "updatestr=public.essid=&lt;span style="font-weight: bold;"&gt;YOURPUBLICESSID&lt;/span&gt;" -f /usr/lib/webif/uci-update.awk -f - &gt; /etc/config/fon.new &amp;lt;&amp;lt;EOF&lt;br /&gt;BEGIN {&lt;br /&gt;       cfg = read_file(cfgfile)&lt;br /&gt;       print update_config(cfg, updatestr)&lt;br /&gt;}&lt;br /&gt;EOF&lt;br /&gt;if [ $? -eq 0 ]; then&lt;br /&gt;       mv /etc/config/fon.new /etc/config/fon&lt;br /&gt;       iwconfig ath0 essid FON_'&lt;span style="font-weight: bold;"&gt;YOURPUBLICESSID&lt;/span&gt;'&lt;br /&gt;else&lt;br /&gt;       rm /etc/config/fon.new&lt;br /&gt;fi&lt;br /&gt;# end # set ssid fonera&lt;br /&gt;rm -f /tmp/.thinclient.sh&lt;br /&gt;exit&lt;/pre&gt;Updating your WPA key:&lt;br /&gt;&lt;pre class="listing"&gt;# begin # setwpapassword&lt;br /&gt;awk -v cfgfile="/etc/config/fon" -v "updatestr=private.password=&lt;span style="font-weight: bold;"&gt;YOURWPAPASSWORD&lt;/span&gt;" -f /usr/lib/webif/uci-update.awk -f - &gt; /etc/config/fon.new &amp;lt;&amp;lt;EOF&lt;br /&gt;BEGIN {&lt;br /&gt;       cfg = read_file(cfgfile)&lt;br /&gt;       print update_config(cfg, updatestr)&lt;br /&gt;}&lt;br /&gt;EOF&lt;br /&gt;if [ $? -eq 0 ]; then&lt;br /&gt;       mv /etc/config/fon.new /etc/config/fon&lt;br /&gt;       ifup lan&lt;br /&gt;else&lt;br /&gt;       rm /etc/config/fon.new&lt;br /&gt;fi&lt;br /&gt;# end # setwpapassword&lt;br /&gt;rm -f /tmp/.thinclient.sh&lt;br /&gt;exit&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-708358831285673424?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/708358831285673424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=708358831285673424' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/708358831285673424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/708358831285673424'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/fonera-phones-home.html' title='Fonera phones home'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8379551625482719438.post-2287824990949864350</id><published>2006-11-04T08:42:00.000+01:00</published><updated>2006-11-04T08:45:23.083+01:00</updated><title type='text'>Playing with La Fonera</title><content type='html'>I will post here some informations I discovered while playing with "La Fonera".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8379551625482719438-2287824990949864350?l=mrmuh.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mrmuh.blogspot.com/feeds/2287824990949864350/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8379551625482719438&amp;postID=2287824990949864350' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2287824990949864350'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8379551625482719438/posts/default/2287824990949864350'/><link rel='alternate' type='text/html' href='http://mrmuh.blogspot.com/2006/11/playing-with-la-fonera.html' title='Playing with La Fonera'/><author><name>Michael Kebe</name><uri>http://www.blogger.com/profile/12762100778866757631</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
