mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
Update Analysis section
This commit is contained in:
@@ -39,29 +39,29 @@ could trick vulnerable routers to download a malicious file (e.g. using DNS or T
|
||||
leading to arbitrary code being executed on the router. Since `circled` runs as *root*, attackers
|
||||
may gain full privileges on the targeted devices.
|
||||
## Analysis
|
||||
In the following, we briefly examine relevant aspects of the **reverse engineered binary** and
|
||||
discuss its improper handling of buffer sizes that culminates in the stack buffer overflow we
|
||||
intend to exploit.
|
||||
In the following, we examine some excerpts from the **reverse engineered binary** and discuss its
|
||||
improper handling of buffer sizes that culminates in the stack buffer overflow we intend to exploit.
|
||||
|
||||
Figure 1 shows the de-compiled pseudo C-code that deals with the reading and parsing of file
|
||||
Figure 1 shows the de-compiled pseudo C-code that deals with the **reading and parsing** of file
|
||||
`/tmp/circleinfo.txt` - a copy of the downloaded file as mentioned in the previous section. Using
|
||||
the *libc* function `fgets`, the file's content is read line-by-line into a stack buffer (here
|
||||
called `line`) of size 1024 (0x400). Using the *libc* function `sscanf`, each read line is then
|
||||
split into two strings (space-separated), which are copied to stack buffers `db_checksum` and
|
||||
`db_checksum_val` respectively.
|
||||
`db_checksum_val`, respectively. As long as the string in buffer `db_checksum` is not equal to
|
||||
"db_checksum" (`strcmp`), we move on to the next line in the file, if any. The buffer `line` may
|
||||
therefore contain a maximum of 1023 characters (plus a terminating null-byte).
|
||||
<hr>
|
||||
<figure>
|
||||
<img src="../images/RE_Vuln_02.svg" alt="Reading and parsing file content"/>
|
||||
<figcaption>
|
||||
Figure 1: Reverse Engineering - Reading file contents line-by-line and parsing to two strings per line.
|
||||
Figure 1: Reverse Engineering - Read file contents line-by-line and split each line into two strings.
|
||||
</figcaption>
|
||||
</figure>
|
||||
<hr>
|
||||
|
||||
As can be seen in Figure 2 below, stack buffers `db_checksum` and `db_checksum_val`, however, only
|
||||
have a size of 256 bytes each. A line e.g. consisting of the string `"A"*1021 + " X"` (plus a null
|
||||
or newline character) will therefore lead to a stack buffer overflow (of buffer `db_checksum` in
|
||||
the listed example string).
|
||||
have a size of 256 bytes each. A line e.g. consisting of the string `"A"*1021 + " X"` will therefore
|
||||
lead to a stack buffer overflow (of buffer `db_checksum` in the listed example string).
|
||||
<hr>
|
||||
<figure>
|
||||
<img src="../images/RE_Vuln_01.svg" alt="Initializing of stack buffers"/>
|
||||
|
||||
Reference in New Issue
Block a user