Re: [VulnWatch] Advisory - D-Link Access Point

news <[email protected]> Fri, 9 Jun 2006 13:20:22 -0300 (BRT)
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <26174809.1149870022387.JavaMail.root@debian>
------=_Part_208_13129484.1149870022339
Content-Type: multipart/alternative; 
	boundary="----=_Part_209_13299949.1149870022340"

------=_Part_209_13299949.1149870022340
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable


Hi Nicolae,The firmware update is not avaible at D-Link Internationl page b=
ecause they ignore our alerts.The D-Link Brizilian Team say that the patch =
created work with all versions and languages of D-Link 2100AP.The link to d=
irect download is http://www.dlink.com.br/internet/downloads/Wireless/DWL-2=
100AP/DWL2100AP-firmware-v210na-r0343.tfpYou can manual download it accessi=
ng the Link: www.dlinkbrasil.com.br/internet, click in the "downloads" link=
, which is at the right top of the page.
So click the "Wireless" folder, next click in the "DWL-2100AP" folder and y=
ou will see the patch avaible
(DWL2100AP-firmware-v210na-r0343.tfp)."
If you are a D-Link International customer we recommend you to contact D-Li=
nk and ask for a patch. As much more clients request for security enforceme=
nt, D-Link and other vendors will see the need to deal with security proble=
ms.Intersting note:
=09=09=09
=09=09=09=09De: =09Niklas <[email protected]>   =20

This "flaw" also affects DWL-7100 (tested) and most likely DWL-7000 and
possibly other ap:s. D-Link has no fw updates since 1.5 yrs back for
the 7100/7000-series. Time to get one out now...
 Regards------------- Mensagem Original
-------------Data: Quarta-feira, 7 de Junho de 2006
20:40De: Nicolae Braham < [email protected]
>Para: news <
[email protected] >,
[email protected]:
Re: [VulnWatch] Advisory -
D-Link Access
Point>>Can anyone
verify the solution listed is valid: I am suspicious of
dlinkbrasil.com.br because I don't see it listed from dlink.com
>
>"
>1 - Upgrade the firmware of D-Link DWL-2100ap Access
Point.
>Direct link to download is
http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210=
0AP-firmware-v210na-r0343.tfp
>"
>
>Nicolae Braham
>
>
>> ----- Original Message -----
>> From: news=20
>> To: [email protected]
>> Subject: [VulnWatch] Advisory - D-Link Access Point
>> Date: Tue, 6 Jun 2006 22:09:46 -0300 (BRT)
>> >> >>
>>   INTRUDERS TIGER TEAM SECURITY - SECURITY
>>
ADVISORYhttp://www.intruders.com.br/http://www.intruders.org.br/ADVISORY/02=
06
>> - D-Link Wireless Access-Point (DWL-2100ap)PRIORITY:
HIGHI - >> INTRUDERS:----------------Intruders Tiger
Team Security is a >> project entailed with Security
Open Source >>
(http://www.securityopensource.org.br).The Intruders Tiger Team
>> Security (ITTS) is a group of researchers with more
than 10 years >> of experience, specialized in the
development of intrusion projects >> (Pen-Test) and in
special security projects.All the projects of >>
intrusion (Pen-Test) realized until the moment by the Intruders
>> Tiger Team Security had 100% of success.II -
>> INTRODUCTION:------------------D-Link AirPlus
XtremeG 2.4GHz >> Wireless Access Point, 54Mbps/108Mbps
(802.11g):D-Link, the >> industry pioneer in wireless
networking, introduces a performance >> breakthrough in
wireless connectivity =96 D-Link AirPlus Xtreme GTM >>
series of high-speed devices now capable of delivering transfer
>> rates up to 15x faster than the standard 802.11b
with the new >> D-Link 108G. With the new AirPlus
Xtreme G DWL-2100AP Wireless >> Access Point, D-Link
sets a new standard for wireless access >>
points.D-Link DWL-2100ap is one of the most popular Access Point in
>> the world.III -
DESCRIPTION:------------------Intruders Tiger Team >>
Security identified during an intrusion project (Pen-Test) an
>> unknown vulnerability in the Access Point D-Link
DWL-2100ap, that >> allows an attacker to read device's
configuration, without >> authentication with web
server.Extremely sensible informations are >> avaible
in the configuration of the Access Point D-Link DWL-2100ap,
>> for example:- User and password used to manage the
device.- >> Password used in WEP and WPA.- SSID, IP,
subnet mask, MAC Address >> filters, etc.IV -
ANALISYS:---------------Making a HTTP request to >> the
/cgi-bin/ directory, the Web server will return error 404 (Page
>> not found).Making a HTTP request to the
/cgi-bin/AnyFile.htm, the >> Web server will return
error 404 (Page not found).However, making a >> HTTP
request to any file in /cgi-bin/ directory, with .cfg
>> extension, will return all the device
configuration.For example, >> making the following
>>
request:http://dlink-DWL-2100ap/cgi-bin/Intruders.cfgWe would have
>> a result equivalent to the following:# Copyright (c)
2002 Atheros >> Communications, Inc., All Rights
Reserved# DO NOT EDIT -- This >> configuration file is
automatically generatedmagic Ar52xxAPfwc: >> 34login
adminDHCPServer Eth_Acl nameaddrdomainsuffix IP_Addr >>
10.0.0.30IP_Mask 255.0.0.0Gateway_Addr 10.0.0.1RADIUSaddr
>> RADIUSport 1812RADIUSsecret password
IntrudersTestpassphrase wlan1 >> passphrase
AnewBadPassPhrase# Several lines removed.D-Link >>
DWL-2100ap Access Point does not allow disable the Web server, not
>> even has options to filter ports. We remember that
the D-Link >> DWL-2100ap Access Point comes configured
with default user >> /password (user:admin and no
password).V. >> DETECTION:-------------Intruders Tiger
Team Security confirmed the >> existence of this
vulnerability in all firmwares tested, also the >> last
version 2.10na. Possibly other(s) D-Link Access Point model(s)
>> can be vulnerable also.VI.
SUGESTION:--------------D-Link company:1 >> - Use
strong cookies to guarantee that only authorized users will
>> get access to configuration.2 - Store sensible
configurations like >> password(s) using hash(s).3 -
Allow create firewall politics and >> rules to filters
port(s) and IP(s).4 - Request to the user change >> the
default user/password on the first logon, and not allow   =20
>> change the password to the last one used.5 - Use
HTTP with SSL >> (HTTPS).6 - Contracts specialized
companies in Pen-Test and >> security audit, aiming
homologate the     security of D-Link >>
products.D-Link customers:1 - Upgrade the firmware of D-Link
>> DWL-2100ap Access Point.     Direct link
to download is >>
http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210=
0AP-firmware-v210na-r0343.tfpVII
- CHRONOLOGY:-----------------11/02/2006 - Vulnerability discovered
during a Pen-Test.15/02/2006 - D-Link World Wide Team
Contacted.17/02/2006 - No response.18/02/2006 - D-Link World Wide Team
re-contacted.24/02/2006 - No response.25/02/2006 - D-Link World Wide
Team last try of contact.29/02/2006 - No response.29/02/2006 - D-Link
Brazil Team Contacted.02/03/2006 - No response.03/03/2006 - D-Link
Brazil Team re-contacted.06/03/2006 - D-Link Brazil Team
responsed.09/03/2006 - Patch created.14/03/2006 - Patch added to D-Link
Brazil download site.06/06/2006 - published advisory.VIII -
CREDITS:---------------Wendel Guglielmetti Henrique and Intruders Tiger
Team Security had discovered this vulnerability.Gratefulness to
Glaudson Ocampos (Intruders Tiger Team Security), Waldemar Nehgme,
Jo=E3oArquimedes (Security Open Source) and Ricardo N. Ferreira (Security
Open Source).Visit our >>
website:http://www.intruders.com.br/http://www.intruders.org.br/
>
>>
>
>
>--
>___________________________________________________
>Play 100s of games for FREE! http://games.mail.com/
>
>
------=_Part_209_13299949.1149870022340
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable


Hi Nicolae,<br /><br />The firmware update is not avaible at D-Link Interna=
tionl page because they ignore our alerts.<br /><br />The D-Link Brizilian =
Team say that the patch created work with all versions and languages of D-L=
ink 2100AP.<br /><br />The link to direct download is http://www.dlink.com.=
br/internet/downloads/Wireless/DWL-2100AP/DWL2100AP-firmware-v210na-r0343.t=
fp<br /><br />You can manual download it accessing the Link: <a target=3D"_=
blank" href=3D"http://www.dlinkbrasil.com.br/internet">www.dlinkbrasil.com.=
br/internet</a>, click in the &quot;downloads&quot; link, which is at the r=
ight top of the page.<br />
<br />So click the &quot;Wireless&quot; folder, next click in the &quot;DWL=
-2100AP&quot; folder and you will see the patch avaible
(DWL2100AP-firmware-v210na-r0343.tfp).&quot;<br />
<br />If you are a D-Link International customer we recommend you to contac=
t D-Link and ask for a patch. As much more clients request for security enf=
orcement, D-Link and other vendors will see the need to deal with security =
problems.<br /><br />Intersting note:<br /><br />
=09=09=09
=09=09=09=09De: =09Niklas &lt;[email protected]&gt;    <br />
<br />
This &quot;flaw&quot; also affects DWL-7100 (tested) and most likely DWL-70=
00 and
possibly other ap:s. D-Link has no fw updates since 1.5 yrs back for
the 7100/7000-series. Time to get one out now...<br />
 <br />Regards<br /><br /><br /><table width=3D"99%" cellspacing=3D"1" cell=
padding=3D"2" style=3D"font-family: Verdana; font-size: 10pt;"><tbody><tr><=
td bgcolor=3D"#cccccc" align=3D"center" colspan=3D"2">------------- Mensage=
m Original
-------------</td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" align=3D"ri=
ght">Data: </td><td bgcolor=3D"#cccccc">Quarta-feira, 7 de Junho de 2006
20:40</td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" align=3D"right">De:=
 </td><td bgcolor=3D"#cccccc">Nicolae Braham &lt; [email protected]
&gt;</td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" align=3D"right">Para=
: </td><td bgcolor=3D"#cccccc">news &lt;
[email protected] &gt;,
[email protected]</td></tr><tr><td width=3D"60" bgcolor=3D"#cccccc" a=
lign=3D"right">Assunto:
</td><td bgcolor=3D"#cccccc">Re: [VulnWatch] Advisory -
D-Link Access
Point</td></tr></tbody></table>&gt;<br />&gt;Can anyone
verify the solution listed is valid: I am suspicious of
dlinkbrasil.com.br because I don't see it listed from dlink.com
<br />&gt;
<br />&gt;&quot;
<br />&gt;1 - Upgrade the firmware of D-Link DWL-2100ap Access
Point.
<br />&gt;Direct link to download is
http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210=
0AP-firmware-v210na-r0343.tfp
<br />&gt;&quot;
<br />&gt;
<br />&gt;Nicolae Braham
<br />&gt;
<br />&gt;
<br />&gt;&gt; ----- Original Message -----
<br />&gt;&gt; From: news <news @securityopensource.org.br=3D"">
<br />&gt;&gt; To: [email protected]
<br />&gt;&gt; Subject: [VulnWatch] Advisory - D-Link Access Point
<br />&gt;&gt; Date: Tue, 6 Jun 2006 22:09:46 -0300 (BRT)
<br />&gt;&gt; <br />&gt;&gt; <br />&gt;&gt;
<br />&gt;&gt;   INTRUDERS TIGER TEAM SECURITY - SECURITY
<br />&gt;&gt;
ADVISORYhttp://www.intruders.com.br/http://www.intruders.org.br/ADVISORY/02=
06
<br />&gt;&gt; - D-Link Wireless Access-Point (DWL-2100ap)PRIORITY:
HIGHI - <br />&gt;&gt; INTRUDERS:----------------Intruders Tiger
Team Security is a <br />&gt;&gt; project entailed with Security
Open Source <br />&gt;&gt;
(http://www.securityopensource.org.br).The Intruders Tiger Team
<br />&gt;&gt; Security (ITTS) is a group of researchers with more
than 10 years <br />&gt;&gt; of experience, specialized in the
development of intrusion projects <br />&gt;&gt; (Pen-Test) and in
special security projects.All the projects of <br />&gt;&gt;
intrusion (Pen-Test) realized until the moment by the Intruders
<br />&gt;&gt; Tiger Team Security had 100% of success.II -
<br />&gt;&gt; INTRODUCTION:------------------D-Link AirPlus
XtremeG 2.4GHz <br />&gt;&gt; Wireless Access Point, 54Mbps/108Mbps
(802.11g):D-Link, the <br />&gt;&gt; industry pioneer in wireless
networking, introduces a performance <br />&gt;&gt; breakthrough in
wireless connectivity =96 D-Link AirPlus Xtreme GTM <br />&gt;&gt;
series of high-speed devices now capable of delivering transfer
<br />&gt;&gt; rates up to 15x faster than the standard 802.11b
with the new <br />&gt;&gt; D-Link 108G. With the new AirPlus
Xtreme G DWL-2100AP Wireless <br />&gt;&gt; Access Point, D-Link
sets a new standard for wireless access <br />&gt;&gt;
points.D-Link DWL-2100ap is one of the most popular Access Point in
<br />&gt;&gt; the world.III -
DESCRIPTION:------------------Intruders Tiger Team <br />&gt;&gt;
Security identified during an intrusion project (Pen-Test) an
<br />&gt;&gt; unknown vulnerability in the Access Point D-Link
DWL-2100ap, that <br />&gt;&gt; allows an attacker to read device's
configuration, without <br />&gt;&gt; authentication with web
server.Extremely sensible informations are <br />&gt;&gt; avaible
in the configuration of the Access Point D-Link DWL-2100ap,
<br />&gt;&gt; for example:- User and password used to manage the
device.- <br />&gt;&gt; Password used in WEP and WPA.- SSID, IP,
subnet mask, MAC Address <br />&gt;&gt; filters, etc.IV -
ANALISYS:---------------Making a HTTP request to <br />&gt;&gt; the
/cgi-bin/ directory, the Web server will return error 404 (Page
<br />&gt;&gt; not found).Making a HTTP request to the
/cgi-bin/AnyFile.htm, the <br />&gt;&gt; Web server will return
error 404 (Page not found).However, making a <br />&gt;&gt; HTTP
request to any file in /cgi-bin/ directory, with .cfg
<br />&gt;&gt; extension, will return all the device
configuration.For example, <br />&gt;&gt; making the following
<br />&gt;&gt;
request:http://dlink-DWL-2100ap/cgi-bin/Intruders.cfgWe would have
<br />&gt;&gt; a result equivalent to the following:# Copyright (c)
2002 Atheros <br />&gt;&gt; Communications, Inc., All Rights
Reserved# DO NOT EDIT -- This <br />&gt;&gt; configuration file is
automatically generatedmagic Ar52xxAPfwc: <br />&gt;&gt; 34login
adminDHCPServer Eth_Acl nameaddrdomainsuffix IP_Addr <br />&gt;&gt;
10.0.0.30IP_Mask 255.0.0.0Gateway_Addr 10.0.0.1RADIUSaddr
<br />&gt;&gt; RADIUSport 1812RADIUSsecret password
IntrudersTestpassphrase wlan1 <br />&gt;&gt; passphrase
AnewBadPassPhrase# Several lines removed.D-Link <br />&gt;&gt;
DWL-2100ap Access Point does not allow disable the Web server, not
<br />&gt;&gt; even has options to filter ports. We remember that
the D-Link <br />&gt;&gt; DWL-2100ap Access Point comes configured
with default user <br />&gt;&gt; /password (user:admin and no
password).V. <br />&gt;&gt; DETECTION:-------------Intruders Tiger
Team Security confirmed the <br />&gt;&gt; existence of this
vulnerability in all firmwares tested, also the <br />&gt;&gt; last
version 2.10na. Possibly other(s) D-Link Access Point model(s)
<br />&gt;&gt; can be vulnerable also.VI.
SUGESTION:--------------D-Link company:1 <br />&gt;&gt; - Use
strong cookies to guarantee that only authorized users will
<br />&gt;&gt; get access to configuration.2 - Store sensible
configurations like <br />&gt;&gt; password(s) using hash(s).3 -
Allow create firewall politics and <br />&gt;&gt; rules to filters
port(s) and IP(s).4 - Request to the user change <br />&gt;&gt; the
default user/password on the first logon, and not allow   =20
<br />&gt;&gt; change the password to the last one used.5 - Use
HTTP with SSL <br />&gt;&gt; (HTTPS).6 - Contracts specialized
companies in Pen-Test and <br />&gt;&gt; security audit, aiming
homologate the     security of D-Link <br />&gt;&gt;
products.D-Link customers:1 - Upgrade the firmware of D-Link
<br />&gt;&gt; DWL-2100ap Access Point.     Direct link
to download is <br />&gt;&gt;
http://www.dlinkbrasil.com.br/internet/downloads/Wireless/DWL-2100AP/DWL210=
0AP-firmware-v210na-r0343.tfpVII
- CHRONOLOGY:-----------------11/02/2006 - Vulnerability discovered
during a Pen-Test.15/02/2006 - D-Link World Wide Team
Contacted.17/02/2006 - No response.18/02/2006 - D-Link World Wide Team
re-contacted.24/02/2006 - No response.25/02/2006 - D-Link World Wide
Team last try of contact.29/02/2006 - No response.29/02/2006 - D-Link
Brazil Team Contacted.02/03/2006 - No response.03/03/2006 - D-Link
Brazil Team re-contacted.06/03/2006 - D-Link Brazil Team
responsed.09/03/2006 - Patch created.14/03/2006 - Patch added to D-Link
Brazil download site.06/06/2006 - published advisory.VIII -
CREDITS:---------------Wendel Guglielmetti Henrique and Intruders Tiger
Team Security had discovered this vulnerability.Gratefulness to
Glaudson Ocampos (Intruders Tiger Team Security), Waldemar Nehgme,
Jo=E3oArquimedes (Security Open Source) and Ricardo N. Ferreira (Security
Open Source).Visit our <br />&gt;&gt;
website:http://www.intruders.com.br/http://www.intruders.org.br/
<br />&gt;
<br />&gt;&gt;
<br />&gt;
<br />&gt;
<br />&gt;--
<br />&gt;___________________________________________________
<br />&gt;Play 100s of games for FREE! http://games.mail.com/
<br />&gt;
<br />&gt;</news>
------=_Part_209_13299949.1149870022340--

------=_Part_208_13129484.1149870022339--