mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
Update README.md
This commit is contained in:
@@ -1,19 +1,4 @@
|
||||
# Exploiting a Stack Buffer Overflow on the Netgear R6700v3
|
||||
```
|
||||
git clone https://github.com/pdamian/netgear_r6700v3_circled.git && cd netgear_r6700v3_circled/
|
||||
binwalk -e -M -C firmware/ firmware/R6700v3-V1.0.4.120_10.0.91.zip
|
||||
export ROOTFS="`pwd`/firmware/_R6700v3-V1.0.4.120_10.0.91.zip.extracted/_R6700v3-V1.0.4.120_10.0.91.chk.extracted/squashfs-root"
|
||||
cp binaries/gdbserver $ROOTFS/usr/bin/gdbserver
|
||||
cp binaries/libnvram.so $ROOTFS/libnvram.so
|
||||
python3 circled.patch.py $ROOTFS/bin/circled $ROOTFS/bin/circled.patched
|
||||
chmod +x $ROOTFS/bin/circled.patched
|
||||
cp circled.sh $ROOTFS/circled.sh
|
||||
chmod +x $ROOTFS/circled.sh
|
||||
cd libcricled/
|
||||
make
|
||||
cp libcircled.so $ROOTFS/libcricled.so
|
||||
cd ../
|
||||
```
|
||||
- Use *QEMU* to boot an ARMHF Debian system
|
||||
- Upload the firmware's root filesystem (`$ROOTFS`) to the ARM Debian system
|
||||
## 1. Individual Binary Emulation
|
||||
@@ -50,3 +35,49 @@ cd ../
|
||||
- https://toolchains.bootlin.com/
|
||||
- NVRAM Emulator:
|
||||
- https://github.com/firmadyne/libnvram
|
||||
## 3. Notes
|
||||
```
|
||||
git clone https://github.com/pdamian/netgear_r6700v3_circled.git && cd netgear_r6700v3_circled/
|
||||
binwalk -e -M -C firmware/ firmware/R6700v3-V1.0.4.120_10.0.91.zip
|
||||
export ROOTFS="`pwd`/firmware/_R6700v3-V1.0.4.120_10.0.91.zip.extracted/_R6700v3-V1.0.4.120_10.0.91.chk.extracted/squashfs-root"
|
||||
cp binaries/gdbserver $ROOTFS/usr/bin/gdbserver
|
||||
cp binaries/libnvram.so $ROOTFS/libnvram.so
|
||||
python3 circled.patch.py $ROOTFS/bin/circled $ROOTFS/bin/circled.patched
|
||||
chmod +x $ROOTFS/bin/circled.patched
|
||||
cp circled.sh $ROOTFS/circled.sh
|
||||
chmod +x $ROOTFS/circled.sh
|
||||
cd libcricled/
|
||||
make
|
||||
cp libcircled.so $ROOTFS/libcricled.so
|
||||
cd ../
|
||||
```
|
||||
## 4. Setup
|
||||
### Ubuntu Host
|
||||
- Clone the repository:
|
||||
```
|
||||
git clone https://github.com/pdamian/netgear_r6700v3_circled.git && cd netgear_r6700v3_circled/
|
||||
- Extract the R6700v3 firmware with *binwalk*:
|
||||
```
|
||||
binwalk -e -M -C firmware/ firmware/R6700v3-V1.0.4.120_10.0.91.zip
|
||||
```
|
||||
- Copy files to the firmware's root filesystem:
|
||||
```
|
||||
# Variable to the root filesystem
|
||||
export ROOTFS="`pwd`/firmware/_R6700v3-V1.0.4.120_10.0.91.zip.extracted/_R6700v3-V1.0.4.120_10.0.91.chk.extracted/squashfs-root"
|
||||
|
||||
# Copy prebuilt gdbserver binary (or cross-compile your own statically-linked version)
|
||||
cp binaries/gdbserver $ROOTFS/usr/bin/gdbserver
|
||||
|
||||
# Copy prebuilt libnvram.so library (or cross-compile your own version)
|
||||
cp binaries/libnvram.so $ROOTFS/libnvram.so
|
||||
|
||||
# Copy prebuilt libcircled.so library (or cross-compile your own version)
|
||||
cp binaries/libcircled.so $ROOTFS/libcircled.so
|
||||
|
||||
# Copy circled.sh script
|
||||
cp circled.sh $ROOTFS/circled.sh
|
||||
|
||||
# Patch the circled binary
|
||||
python3 circled.patch.py $ROOTFS/bin/circled $ROOTFS/bin/circled.patched
|
||||
```
|
||||
### QEMU Debian ARMHF VM
|
||||
|
||||
Reference in New Issue
Block a user