Re: [VulnWatch] Advisory - D-Link Access Point

"Nicolae Braham" <[email protected]> Wed, 07 Jun 2006 18:40:34 -0500
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Can anyone verify the solution listed is valid: I am suspicious of dlinkbra=
sil.com.br because I don't see it listed from dlink.com

"
1 - Upgrade the firmware of D-Link DWL-2100ap Access Point.
Direct link to download is http://www.dlinkbrasil.com.br/internet/downloads=
/Wireless/DWL-2100AP/DWL2100AP-firmware-v210na-r0343.tfp
"

Nicolae Braham


> ----- Original Message -----
> From: news <[email protected]>
> To: [email protected]
> Subject: [VulnWatch] Advisory - D-Link Access Point
> Date: Tue, 6 Jun 2006 22:09:46 -0300 (BRT)
>=20
>=20
>=20
>   INTRUDERS TIGER TEAM SECURITY - SECURITY=20
> ADVISORYhttp://www.intruders.com.br/http://www.intruders.org.br/ADVISORY/=
0206=20
> - D-Link Wireless Access-Point (DWL-2100ap)PRIORITY: HIGHI -=20
> INTRUDERS:----------------Intruders Tiger Team Security is a=20
> project entailed with Security Open Source=20
> (http://www.securityopensource.org.br).The Intruders Tiger Team=20
> Security (ITTS) is a group of researchers with more than 10 years=20
> of experience, specialized in the development of intrusion projects=20
> (Pen-Test) and in special security projects.All the projects of=20
> intrusion (Pen-Test) realized until the moment by the Intruders=20
> Tiger Team Security had 100% of success.II -=20
> INTRODUCTION:------------------D-Link AirPlus XtremeG 2.4GHz=20
> Wireless Access Point, 54Mbps/108Mbps (802.11g):D-Link, the=20
> industry pioneer in wireless networking, introduces a performance=20
> breakthrough in wireless connectivity =96 D-Link AirPlus Xtreme GTM=20
> series of high-speed devices now capable of delivering transfer=20
> rates up to 15x faster than the standard 802.11b with the new=20
> D-Link 108G. With the new AirPlus Xtreme G DWL-2100AP Wireless=20
> Access Point, D-Link sets a new standard for wireless access=20
> points.D-Link DWL-2100ap is one of the most popular Access Point in=20
> the world.III - DESCRIPTION:------------------Intruders Tiger Team=20
> Security identified during an intrusion project (Pen-Test) an=20
> unknown vulnerability in the Access Point D-Link DWL-2100ap, that=20
> allows an attacker to read device's configuration, without=20
> authentication with web server.Extremely sensible informations are=20
> avaible in the configuration of the Access Point D-Link DWL-2100ap,=20
> for example:- User and password used to manage the device.-=20
> Password used in WEP and WPA.- SSID, IP, subnet mask, MAC Address=20
> filters, etc.IV - ANALISYS:---------------Making a HTTP request to=20
> the /cgi-bin/ directory, the Web server will return error 404 (Page=20
> not found).Making a HTTP request to the /cgi-bin/AnyFile.htm, the=20
> Web server will return error 404 (Page not found).However, making a=20
> HTTP request to any file in /cgi-bin/ directory, with .cfg=20
> extension, will return all the device configuration.For example,=20
> making the following=20
> request:http://dlink-DWL-2100ap/cgi-bin/Intruders.cfgWe would have=20
> a result equivalent to the following:# Copyright (c) 2002 Atheros=20
> Communications, Inc., All Rights Reserved# DO NOT EDIT -- This=20
> configuration file is automatically generatedmagic Ar52xxAPfwc:=20
> 34login adminDHCPServer Eth_Acl nameaddrdomainsuffix IP_Addr=20
> 10.0.0.30IP_Mask 255.0.0.0Gateway_Addr 10.0.0.1RADIUSaddr=20
> RADIUSport 1812RADIUSsecret password IntrudersTestpassphrase wlan1=20
> passphrase AnewBadPassPhrase# Several lines removed.D-Link=20
> DWL-2100ap Access Point does not allow disable the Web server, not=20
> even has options to filter ports. We remember that the D-Link=20
> DWL-2100ap Access Point comes configured with default user=20
> /password (user:admin and no password).V.=20
> DETECTION:-------------Intruders Tiger Team Security confirmed the=20
> existence of this vulnerability in all firmwares tested, also the=20
> last version 2.10na. Possibly other(s) D-Link Access Point model(s)=20
> can be vulnerable also.VI. SUGESTION:--------------D-Link company:1=20
> - Use strong cookies to guarantee that only authorized users will=20
> get access to configuration.2 - Store sensible configurations like=20
> password(s) using hash(s).3 - Allow create firewall politics and=20
> rules to filters port(s) and IP(s).4 - Request to the user change=20
> the default user/password on the first logon, and not allow=20=20=20=20=
=20
> change the password to the last one used.5 - Use HTTP with SSL=20
> (HTTPS).6 - Contracts specialized companies in Pen-Test and=20
> security audit, aiming homologate the     security of D-Link=20
> products.D-Link customers:1 - Upgrade the firmware of D-Link=20
> DWL-2100ap Access Point.     Direct link to download is=20
> http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL2=
100AP-firmware-v210na-r0343.tfpVII - CHRONOLOGY:-----------------11/02/2006=
 - Vulnerability discovered during a Pen-Test.15/02/2006 - D-Link World Wid=
e Team Contacted.17/02/2006 - No response.18/02/2006 - D-Link World Wide Te=
am re-contacted.24/02/2006 - No response.25/02/2006 - D-Link World Wide Tea=
m last try of contact.29/02/2006 - No response.29/02/2006 - D-Link Brazil T=
eam Contacted.02/03/2006 - No response.03/03/2006 - D-Link Brazil Team re-c=
ontacted.06/03/2006 - D-Link Brazil Team responsed.09/03/2006 - Patch creat=
ed.14/03/2006 - Patch added to D-Link Brazil download site.06/06/2006 - pub=
lished advisory.VIII - CREDITS:---------------Wendel Guglielmetti Henrique =
and Intruders Tiger Team Security had discovered this vulnerability.Gratefu=
lness to Glaudson Ocampos (Intruders Tiger Team Security), Waldemar Nehgme,=
 Jo=E3oArquimedes (Security Open Source) and Ricardo N. Ferreira (Security =
Open Source).Visit our=20
> website:http://www.intruders.com.br/http://www.intruders.org.br/

>


--=20
___________________________________________________
Play 100s of games for FREE! http://games.mail.com/