Reversing D-Link’s WPS Pin Algorithm
devttys0.com
devttys0.com
In case anyone is interested, the (very hacky) scripts are on Github: https://github.com/michielappelman/router-stats
Well... I'd guess that this D-Link router also has a sticker with the WPS pin on it. So that means that the same (stupid, predictable) algorithm is used in the factory for printing the labels.
Also: Even for the devices which have the PIN stored separately in the NVRAM there's no guarantee that some stupid/lazy guy didn't just copy the algorithm for label-printing used for the former devices, to generate the NVRAM-PINs for the latter ones.
I seem to remember being able to use an exploit to break into my own router that had WPS enabled about a year ago using a program called reaver.
The exploit had something to do with routers telling the attacker whether or not they guessed the first 4 digits correctly and then it narrowed it down enough to where bruteforcing was easy.
"An attacker can derive information about the correctness of parts the PIN from the AP´s responses.
> If the attacker receives an EAP-NACK message after sending M4, he knows that the 1st half of the PIN was incorrect.
> If the attacker receives an EAP-NACK message after sending M6, he knows that the 2nd half of the PIN was incorrect.
This form of authentication dramatically decreases the maximum possible authentication attempts needed from 108 (=100.000.000) to 104 + 104 (=20.000).
As the 8th digit of the PIN is always a checksum of digit one to digit seven, there are at most 104 + 103 (=11.000) attempts needed to find the correct PIN."
Reference - http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf
Since WAN mac addresses don't travel very far upstream. Typically only to the local exchange. So in order for someone to utilise that to generate a WPS key they would have to sit at the exchange (on your side of the connection) and do it.
The manufacturer might also store the WAN mac addresses of each piece of equipment they produce (along with serial, etc) and depending on the supply chain you purchased the router down or if you registered it, they could figure out your router's WAN/WPS pin that way.
In general PIN-based WPS is a bad idea. Turn it off and do button WPS only. Or turn it on only as needed.
This doesn't matter, and it's addressed in the post. He mentions many devices actually do use the BSSID (which is sent in every wireless frame), and the WAN MAC is usually very close to the BSSID anyway so you can guess it in very few tries.
The LAN MAC address is what is broadcasted.
But the article says that the two are just 1 off from each other on many routers, so knowing one, you can find the other.
I even have a note here wondering where they read from NVRAM or similar related to WPS because I couldn't spot it. Guess I have the answer now!
I doubt I will have the time to investigate it, but my feeling is that there is a lot of funky stuff in /sbin/ncc and the companion binaries.
To answer your question: yes, but that's not (typically) necessary.
Years ago I read about a similar predictability for ISP-supplied routers that used the MAC as seed for the default WPA key and the SSID. Once someone decoded the algorithm it was trivial to access many home networks.
At the end of the day, I believe it's cheaper to flash the same firmware image on all of the boards and differentiate them during the first boot or even at runtime like in this case.