what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

dlink-arp.txt

dlink-arp.txt
Posted Dec 12, 2006
Authored by poplix

The D-LINK DWL-2000AP+ with firmware version 2.11 is prone to two remote denial of service vulnerabilities because it fails to handle arp flooding.

tags | advisory, remote, denial of service, vulnerability
SHA-256 | 87d03a41d7205746c6fdc2717648002c7605bc5def176cb29db02f70e7827bcf

dlink-arp.txt

Change Mirror Download
D-LINK DWL-2000AP+ with firmware version 2.11 is prone to two remote denial of service vulnerability because it fails to handle arp flooding. 
The first vuln causes the wireless link (802.11) to be resetted and the arp table to be rebuilded. All clients connected to the AP are disconnected.
This bug can be triggered by sending lots of arp replies through the wired link or the radio one at a very high speed.
The second vulnerability affects the wireless link only and are quite harder to trigger but causes the AP firmware to crash making a manual reboot mandatory.
This bug can be triggered only if no other D-LINK ethernet products are visible to AP, if wep encryption is enabled and it needs a very large amount of arp-requests to be broadcasted through its wireless link at a very high speed.
This exploit works in the 90% of cases because sometimes the AP is able to ban the flooding client before the exploiting process is complete.
D-LINK doesn't support this product anymore so no solution is available.
Other products can be vulnerable.

Not vulnerable: DWL-700AP


Proof-of-concept availale,
it floods an ethernet device with arp-reply or arp-request
http://tripp.dynalias.org/arpflood.c

cheers

-poplix

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    0 Files
  • 16
    Apr 16th
    0 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close