Re: [VulnWatch] Advisory - D-Link Access Point
"Nicolae Braham" <[email protected]> Wed, 07 Jun 2006 18:40:34 -0500
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
Can anyone verify the solution listed is valid: I am suspicious of dlinkbra= sil.com.br because I don't see it listed from dlink.com " 1 - Upgrade the firmware of D-Link DWL-2100ap Access Point. Direct link to download is http://www.dlinkbrasil.com.br/internet/downloads= /Wireless/DWL-2100AP/DWL2100AP-firmware-v210na-r0343.tfp " Nicolae Braham > ----- Original Message ----- > From: news <[email protected]> > To: [email protected] > Subject: [VulnWatch] Advisory - D-Link Access Point > Date: Tue, 6 Jun 2006 22:09:46 -0300 (BRT) >=20 >=20 >=20 > INTRUDERS TIGER TEAM SECURITY - SECURITY=20 > ADVISORYhttp://www.intruders.com.br/http://www.intruders.org.br/ADVISORY/= 0206=20 > - D-Link Wireless Access-Point (DWL-2100ap)PRIORITY: HIGHI -=20 > INTRUDERS:----------------Intruders Tiger Team Security is a=20 > project entailed with Security Open Source=20 > (http://www.securityopensource.org.br).The Intruders Tiger Team=20 > Security (ITTS) is a group of researchers with more than 10 years=20 > of experience, specialized in the development of intrusion projects=20 > (Pen-Test) and in special security projects.All the projects of=20 > intrusion (Pen-Test) realized until the moment by the Intruders=20 > Tiger Team Security had 100% of success.II -=20 > INTRODUCTION:------------------D-Link AirPlus XtremeG 2.4GHz=20 > Wireless Access Point, 54Mbps/108Mbps (802.11g):D-Link, the=20 > industry pioneer in wireless networking, introduces a performance=20 > breakthrough in wireless connectivity =96 D-Link AirPlus Xtreme GTM=20 > series of high-speed devices now capable of delivering transfer=20 > rates up to 15x faster than the standard 802.11b with the new=20 > D-Link 108G. With the new AirPlus Xtreme G DWL-2100AP Wireless=20 > Access Point, D-Link sets a new standard for wireless access=20 > points.D-Link DWL-2100ap is one of the most popular Access Point in=20 > the world.III - DESCRIPTION:------------------Intruders Tiger Team=20 > Security identified during an intrusion project (Pen-Test) an=20 > unknown vulnerability in the Access Point D-Link DWL-2100ap, that=20 > allows an attacker to read device's configuration, without=20 > authentication with web server.Extremely sensible informations are=20 > avaible in the configuration of the Access Point D-Link DWL-2100ap,=20 > for example:- User and password used to manage the device.-=20 > Password used in WEP and WPA.- SSID, IP, subnet mask, MAC Address=20 > filters, etc.IV - ANALISYS:---------------Making a HTTP request to=20 > the /cgi-bin/ directory, the Web server will return error 404 (Page=20 > not found).Making a HTTP request to the /cgi-bin/AnyFile.htm, the=20 > Web server will return error 404 (Page not found).However, making a=20 > HTTP request to any file in /cgi-bin/ directory, with .cfg=20 > extension, will return all the device configuration.For example,=20 > making the following=20 > request:http://dlink-DWL-2100ap/cgi-bin/Intruders.cfgWe would have=20 > a result equivalent to the following:# Copyright (c) 2002 Atheros=20 > Communications, Inc., All Rights Reserved# DO NOT EDIT -- This=20 > configuration file is automatically generatedmagic Ar52xxAPfwc:=20 > 34login adminDHCPServer Eth_Acl nameaddrdomainsuffix IP_Addr=20 > 10.0.0.30IP_Mask 255.0.0.0Gateway_Addr 10.0.0.1RADIUSaddr=20 > RADIUSport 1812RADIUSsecret password IntrudersTestpassphrase wlan1=20 > passphrase AnewBadPassPhrase# Several lines removed.D-Link=20 > DWL-2100ap Access Point does not allow disable the Web server, not=20 > even has options to filter ports. We remember that the D-Link=20 > DWL-2100ap Access Point comes configured with default user=20 > /password (user:admin and no password).V.=20 > DETECTION:-------------Intruders Tiger Team Security confirmed the=20 > existence of this vulnerability in all firmwares tested, also the=20 > last version 2.10na. Possibly other(s) D-Link Access Point model(s)=20 > can be vulnerable also.VI. SUGESTION:--------------D-Link company:1=20 > - Use strong cookies to guarantee that only authorized users will=20 > get access to configuration.2 - Store sensible configurations like=20 > password(s) using hash(s).3 - Allow create firewall politics and=20 > rules to filters port(s) and IP(s).4 - Request to the user change=20 > the default user/password on the first logon, and not allow=20=20=20=20= =20 > change the password to the last one used.5 - Use HTTP with SSL=20 > (HTTPS).6 - Contracts specialized companies in Pen-Test and=20 > security audit, aiming homologate the security of D-Link=20 > products.D-Link customers:1 - Upgrade the firmware of D-Link=20 > DWL-2100ap Access Point. Direct link to download is=20 > http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL2= 100AP-firmware-v210na-r0343.tfpVII - CHRONOLOGY:-----------------11/02/2006= - Vulnerability discovered during a Pen-Test.15/02/2006 - D-Link World Wid= e Team Contacted.17/02/2006 - No response.18/02/2006 - D-Link World Wide Te= am re-contacted.24/02/2006 - No response.25/02/2006 - D-Link World Wide Tea= m last try of contact.29/02/2006 - No response.29/02/2006 - D-Link Brazil T= eam Contacted.02/03/2006 - No response.03/03/2006 - D-Link Brazil Team re-c= ontacted.06/03/2006 - D-Link Brazil Team responsed.09/03/2006 - Patch creat= ed.14/03/2006 - Patch added to D-Link Brazil download site.06/06/2006 - pub= lished advisory.VIII - CREDITS:---------------Wendel Guglielmetti Henrique = and Intruders Tiger Team Security had discovered this vulnerability.Gratefu= lness to Glaudson Ocampos (Intruders Tiger Team Security), Waldemar Nehgme,= Jo=E3oArquimedes (Security Open Source) and Ricardo N. Ferreira (Security = Open Source).Visit our=20 > website:http://www.intruders.com.br/http://www.intruders.org.br/ > --=20 ___________________________________________________ Play 100s of games for FREE! http://games.mail.com/