Re: [VulnWatch] Advisory - D-Link Access Point
news <[email protected]> Fri, 9 Jun 2006 13:20:22 -0300 (BRT)
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <26174809.1149870022387.JavaMail.root@debian> |
------=_Part_208_13129484.1149870022339 Content-Type: multipart/alternative; boundary="----=_Part_209_13299949.1149870022340" ------=_Part_209_13299949.1149870022340 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Hi Nicolae,The firmware update is not avaible at D-Link Internationl page b= ecause they ignore our alerts.The D-Link Brizilian Team say that the patch = created work with all versions and languages of D-Link 2100AP.The link to d= irect download is http://www.dlink.com.br/internet/downloads/Wireless/DWL-2= 100AP/DWL2100AP-firmware-v210na-r0343.tfpYou can manual download it accessi= ng the Link: www.dlinkbrasil.com.br/internet, click in the "downloads" link= , which is at the right top of the page. So click the "Wireless" folder, next click in the "DWL-2100AP" folder and y= ou will see the patch avaible (DWL2100AP-firmware-v210na-r0343.tfp)." If you are a D-Link International customer we recommend you to contact D-Li= nk and ask for a patch. As much more clients request for security enforceme= nt, D-Link and other vendors will see the need to deal with security proble= ms.Intersting note: =09=09=09 =09=09=09=09De: =09Niklas <[email protected]> =20 This "flaw" also affects DWL-7100 (tested) and most likely DWL-7000 and possibly other ap:s. D-Link has no fw updates since 1.5 yrs back for the 7100/7000-series. Time to get one out now... Regards------------- Mensagem Original -------------Data: Quarta-feira, 7 de Junho de 2006 20:40De: Nicolae Braham < [email protected] >Para: news < [email protected] >, [email protected]: Re: [VulnWatch] Advisory - D-Link Access Point>>Can anyone verify the solution listed is valid: I am suspicious of dlinkbrasil.com.br because I don't see it listed from dlink.com > >" >1 - Upgrade the firmware of D-Link DWL-2100ap Access Point. >Direct link to download is http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210= 0AP-firmware-v210na-r0343.tfp >" > >Nicolae Braham > > >> ----- Original Message ----- >> From: news=20 >> To: [email protected] >> Subject: [VulnWatch] Advisory - D-Link Access Point >> Date: Tue, 6 Jun 2006 22:09:46 -0300 (BRT) >> >> >> >> INTRUDERS TIGER TEAM SECURITY - SECURITY >> ADVISORYhttp://www.intruders.com.br/http://www.intruders.org.br/ADVISORY/02= 06 >> - D-Link Wireless Access-Point (DWL-2100ap)PRIORITY: HIGHI - >> INTRUDERS:----------------Intruders Tiger Team Security is a >> project entailed with Security Open Source >> (http://www.securityopensource.org.br).The Intruders Tiger Team >> Security (ITTS) is a group of researchers with more than 10 years >> of experience, specialized in the development of intrusion projects >> (Pen-Test) and in special security projects.All the projects of >> intrusion (Pen-Test) realized until the moment by the Intruders >> Tiger Team Security had 100% of success.II - >> INTRODUCTION:------------------D-Link AirPlus XtremeG 2.4GHz >> Wireless Access Point, 54Mbps/108Mbps (802.11g):D-Link, the >> industry pioneer in wireless networking, introduces a performance >> breakthrough in wireless connectivity =96 D-Link AirPlus Xtreme GTM >> series of high-speed devices now capable of delivering transfer >> rates up to 15x faster than the standard 802.11b with the new >> D-Link 108G. With the new AirPlus Xtreme G DWL-2100AP Wireless >> Access Point, D-Link sets a new standard for wireless access >> points.D-Link DWL-2100ap is one of the most popular Access Point in >> the world.III - DESCRIPTION:------------------Intruders Tiger Team >> Security identified during an intrusion project (Pen-Test) an >> unknown vulnerability in the Access Point D-Link DWL-2100ap, that >> allows an attacker to read device's configuration, without >> authentication with web server.Extremely sensible informations are >> avaible in the configuration of the Access Point D-Link DWL-2100ap, >> for example:- User and password used to manage the device.- >> Password used in WEP and WPA.- SSID, IP, subnet mask, MAC Address >> filters, etc.IV - ANALISYS:---------------Making a HTTP request to >> the /cgi-bin/ directory, the Web server will return error 404 (Page >> not found).Making a HTTP request to the /cgi-bin/AnyFile.htm, the >> Web server will return error 404 (Page not found).However, making a >> HTTP request to any file in /cgi-bin/ directory, with .cfg >> extension, will return all the device configuration.For example, >> making the following >> request:http://dlink-DWL-2100ap/cgi-bin/Intruders.cfgWe would have >> a result equivalent to the following:# Copyright (c) 2002 Atheros >> Communications, Inc., All Rights Reserved# DO NOT EDIT -- This >> configuration file is automatically generatedmagic Ar52xxAPfwc: >> 34login adminDHCPServer Eth_Acl nameaddrdomainsuffix IP_Addr >> 10.0.0.30IP_Mask 255.0.0.0Gateway_Addr 10.0.0.1RADIUSaddr >> RADIUSport 1812RADIUSsecret password IntrudersTestpassphrase wlan1 >> passphrase AnewBadPassPhrase# Several lines removed.D-Link >> DWL-2100ap Access Point does not allow disable the Web server, not >> even has options to filter ports. We remember that the D-Link >> DWL-2100ap Access Point comes configured with default user >> /password (user:admin and no password).V. >> DETECTION:-------------Intruders Tiger Team Security confirmed the >> existence of this vulnerability in all firmwares tested, also the >> last version 2.10na. Possibly other(s) D-Link Access Point model(s) >> can be vulnerable also.VI. SUGESTION:--------------D-Link company:1 >> - Use strong cookies to guarantee that only authorized users will >> get access to configuration.2 - Store sensible configurations like >> password(s) using hash(s).3 - Allow create firewall politics and >> rules to filters port(s) and IP(s).4 - Request to the user change >> the default user/password on the first logon, and not allow =20 >> change the password to the last one used.5 - Use HTTP with SSL >> (HTTPS).6 - Contracts specialized companies in Pen-Test and >> security audit, aiming homologate the security of D-Link >> products.D-Link customers:1 - Upgrade the firmware of D-Link >> DWL-2100ap Access Point. Direct link to download is >> http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210= 0AP-firmware-v210na-r0343.tfpVII - CHRONOLOGY:-----------------11/02/2006 - Vulnerability discovered during a Pen-Test.15/02/2006 - D-Link World Wide Team Contacted.17/02/2006 - No response.18/02/2006 - D-Link World Wide Team re-contacted.24/02/2006 - No response.25/02/2006 - D-Link World Wide Team last try of contact.29/02/2006 - No response.29/02/2006 - D-Link Brazil Team Contacted.02/03/2006 - No response.03/03/2006 - D-Link Brazil Team re-contacted.06/03/2006 - D-Link Brazil Team responsed.09/03/2006 - Patch created.14/03/2006 - Patch added to D-Link Brazil download site.06/06/2006 - published advisory.VIII - CREDITS:---------------Wendel Guglielmetti Henrique and Intruders Tiger Team Security had discovered this vulnerability.Gratefulness to Glaudson Ocampos (Intruders Tiger Team Security), Waldemar Nehgme, Jo=E3oArquimedes (Security Open Source) and Ricardo N. Ferreira (Security Open Source).Visit our >> website:http://www.intruders.com.br/http://www.intruders.org.br/ > >> > > >-- >___________________________________________________ >Play 100s of games for FREE! http://games.mail.com/ > > ------=_Part_209_13299949.1149870022340 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Hi Nicolae,<br /><br />The firmware update is not avaible at D-Link Interna= tionl page because they ignore our alerts.<br /><br />The D-Link Brizilian = Team say that the patch created work with all versions and languages of D-L= ink 2100AP.<br /><br />The link to direct download is http://www.dlink.com.= br/internet/downloads/Wireless/DWL-2100AP/DWL2100AP-firmware-v210na-r0343.t= fp<br /><br />You can manual download it accessing the Link: <a target=3D"_= blank" href=3D"http://www.dlinkbrasil.com.br/internet">www.dlinkbrasil.com.= br/internet</a>, click in the "downloads" link, which is at the r= ight top of the page.<br /> <br />So click the "Wireless" folder, next click in the "DWL= -2100AP" folder and you will see the patch avaible (DWL2100AP-firmware-v210na-r0343.tfp)."<br /> <br />If you are a D-Link International customer we recommend you to contac= t D-Link and ask for a patch. As much more clients request for security enf= orcement, D-Link and other vendors will see the need to deal with security = problems.<br /><br />Intersting note:<br /><br /> =09=09=09 =09=09=09=09De: =09Niklas <[email protected]> <br /> <br /> This "flaw" also affects DWL-7100 (tested) and most likely DWL-70= 00 and possibly other ap:s. D-Link has no fw updates since 1.5 yrs back for the 7100/7000-series. Time to get one out now...<br /> <br />Regards<br /><br /><br /><table width=3D"99%" cellspacing=3D"1" cell= padding=3D"2" style=3D"font-family: Verdana; font-size: 10pt;"><tbody><tr><= td bgcolor=3D"#cccccc" align=3D"center" colspan=3D"2">------------- Mensage= m Original -------------</td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" align=3D"ri= ght">Data: </td><td bgcolor=3D"#cccccc">Quarta-feira, 7 de Junho de 2006 20:40</td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" align=3D"right">De:= </td><td bgcolor=3D"#cccccc">Nicolae Braham < [email protected] ></td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" align=3D"right">Para= : </td><td bgcolor=3D"#cccccc">news < [email protected] >, [email protected]</td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" a= lign=3D"right">Assunto: </td><td bgcolor=3D"#cccccc">Re: [VulnWatch] Advisory - D-Link Access Point</td></tr></tbody></table>><br />>Can anyone verify the solution listed is valid: I am suspicious of dlinkbrasil.com.br because I don't see it listed from dlink.com <br />> <br />>" <br />>1 - Upgrade the firmware of D-Link DWL-2100ap Access Point. <br />>Direct link to download is http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210= 0AP-firmware-v210na-r0343.tfp <br />>" <br />> <br />>Nicolae Braham <br />> <br />> <br />>> ----- Original Message ----- <br />>> From: news <news @securityopensource.org.br=3D""> <br />>> To: [email protected] <br />>> Subject: [VulnWatch] Advisory - D-Link Access Point <br />>> Date: Tue, 6 Jun 2006 22:09:46 -0300 (BRT) <br />>> <br />>> <br />>> <br />>> INTRUDERS TIGER TEAM SECURITY - SECURITY <br />>> ADVISORYhttp://www.intruders.com.br/http://www.intruders.org.br/ADVISORY/02= 06 <br />>> - D-Link Wireless Access-Point (DWL-2100ap)PRIORITY: HIGHI - <br />>> INTRUDERS:----------------Intruders Tiger Team Security is a <br />>> project entailed with Security Open Source <br />>> (http://www.securityopensource.org.br).The Intruders Tiger Team <br />>> Security (ITTS) is a group of researchers with more than 10 years <br />>> of experience, specialized in the development of intrusion projects <br />>> (Pen-Test) and in special security projects.All the projects of <br />>> intrusion (Pen-Test) realized until the moment by the Intruders <br />>> Tiger Team Security had 100% of success.II - <br />>> INTRODUCTION:------------------D-Link AirPlus XtremeG 2.4GHz <br />>> Wireless Access Point, 54Mbps/108Mbps (802.11g):D-Link, the <br />>> industry pioneer in wireless networking, introduces a performance <br />>> breakthrough in wireless connectivity =96 D-Link AirPlus Xtreme GTM <br />>> series of high-speed devices now capable of delivering transfer <br />>> rates up to 15x faster than the standard 802.11b with the new <br />>> D-Link 108G. With the new AirPlus Xtreme G DWL-2100AP Wireless <br />>> Access Point, D-Link sets a new standard for wireless access <br />>> points.D-Link DWL-2100ap is one of the most popular Access Point in <br />>> the world.III - DESCRIPTION:------------------Intruders Tiger Team <br />>> Security identified during an intrusion project (Pen-Test) an <br />>> unknown vulnerability in the Access Point D-Link DWL-2100ap, that <br />>> allows an attacker to read device's configuration, without <br />>> authentication with web server.Extremely sensible informations are <br />>> avaible in the configuration of the Access Point D-Link DWL-2100ap, <br />>> for example:- User and password used to manage the device.- <br />>> Password used in WEP and WPA.- SSID, IP, subnet mask, MAC Address <br />>> filters, etc.IV - ANALISYS:---------------Making a HTTP request to <br />>> the /cgi-bin/ directory, the Web server will return error 404 (Page <br />>> not found).Making a HTTP request to the /cgi-bin/AnyFile.htm, the <br />>> Web server will return error 404 (Page not found).However, making a <br />>> HTTP request to any file in /cgi-bin/ directory, with .cfg <br />>> extension, will return all the device configuration.For example, <br />>> making the following <br />>> request:http://dlink-DWL-2100ap/cgi-bin/Intruders.cfgWe would have <br />>> a result equivalent to the following:# Copyright (c) 2002 Atheros <br />>> Communications, Inc., All Rights Reserved# DO NOT EDIT -- This <br />>> configuration file is automatically generatedmagic Ar52xxAPfwc: <br />>> 34login adminDHCPServer Eth_Acl nameaddrdomainsuffix IP_Addr <br />>> 10.0.0.30IP_Mask 255.0.0.0Gateway_Addr 10.0.0.1RADIUSaddr <br />>> RADIUSport 1812RADIUSsecret password IntrudersTestpassphrase wlan1 <br />>> passphrase AnewBadPassPhrase# Several lines removed.D-Link <br />>> DWL-2100ap Access Point does not allow disable the Web server, not <br />>> even has options to filter ports. We remember that the D-Link <br />>> DWL-2100ap Access Point comes configured with default user <br />>> /password (user:admin and no password).V. <br />>> DETECTION:-------------Intruders Tiger Team Security confirmed the <br />>> existence of this vulnerability in all firmwares tested, also the <br />>> last version 2.10na. Possibly other(s) D-Link Access Point model(s) <br />>> can be vulnerable also.VI. SUGESTION:--------------D-Link company:1 <br />>> - Use strong cookies to guarantee that only authorized users will <br />>> get access to configuration.2 - Store sensible configurations like <br />>> password(s) using hash(s).3 - Allow create firewall politics and <br />>> rules to filters port(s) and IP(s).4 - Request to the user change <br />>> the default user/password on the first logon, and not allow =20 <br />>> change the password to the last one used.5 - Use HTTP with SSL <br />>> (HTTPS).6 - Contracts specialized companies in Pen-Test and <br />>> security audit, aiming homologate the security of D-Link <br />>> products.D-Link customers:1 - Upgrade the firmware of D-Link <br />>> DWL-2100ap Access Point. Direct link to download is <br />>> http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210= 0AP-firmware-v210na-r0343.tfpVII - CHRONOLOGY:-----------------11/02/2006 - Vulnerability discovered during a Pen-Test.15/02/2006 - D-Link World Wide Team Contacted.17/02/2006 - No response.18/02/2006 - D-Link World Wide Team re-contacted.24/02/2006 - No response.25/02/2006 - D-Link World Wide Team last try of contact.29/02/2006 - No response.29/02/2006 - D-Link Brazil Team Contacted.02/03/2006 - No response.03/03/2006 - D-Link Brazil Team re-contacted.06/03/2006 - D-Link Brazil Team responsed.09/03/2006 - Patch created.14/03/2006 - Patch added to D-Link Brazil download site.06/06/2006 - published advisory.VIII - CREDITS:---------------Wendel Guglielmetti Henrique and Intruders Tiger Team Security had discovered this vulnerability.Gratefulness to Glaudson Ocampos (Intruders Tiger Team Security), Waldemar Nehgme, Jo=E3oArquimedes (Security Open Source) and Ricardo N. Ferreira (Security Open Source).Visit our <br />>> website:http://www.intruders.com.br/http://www.intruders.org.br/ <br />> <br />>> <br />> <br />> <br />>-- <br />>___________________________________________________ <br />>Play 100s of games for FREE! http://games.mail.com/ <br />> <br />></news> ------=_Part_209_13299949.1149870022340-- ------=_Part_208_13129484.1149870022339--