mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
0fbd7b4fa6c7b84b5cedef63154e01cac2a8a211
Exploiting a Stack Buffer Overflow on the Netgear R6700v3
1. Individual Binary Emulation
- Extract the R6700v3 firmware with binwalk
- Use QEMU to boot an ARM Debian system
- Upload the firmware's root filesystem to the ARM Debian system
- Build and copy a statically-linked version of gdbserver to the root filesystem
- Emulate the circled binary
- Cross-compile (use bootlin toolchain for armv7-eabihf and ulibc) libnvram to emulate non-volatile RAM (NVRAM)
- Chroot into the root filesystem
sudo mount -t proc /proc/ ./squashfs-root/proc/sudo mount -t sysfs /sys/ ./squashfs-root/sys/sudo mount -o bind /dev/ ./squashfs-root/dev/sudo chroot ./squashfs-root/ /bin/shexport SHELL=/bin/sh
- Execute the targeted binary (use
circled.shhelper script)
- Trace crash (
gdb-multiarch -q -x circled.gdb)
2. References
- Emulating Netgear R6700v3 cicled binary:
- https://medium.com/@INTfinity/1-1-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-1-5bab391c91f2
- https://medium.com/@INTfinity/1-2-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-2-cf1571493117
- https://medium.com/@INTfinity/1-3-exploiting-and-debugging-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-a80dbaf1245d
- Emulating IoT Firmware Made Easy:
- Defeating the Netgear R6700v3:
- Chroot:
- Ready-to-Use Cross-Compilation Toolchains:
- NVRAM Emulator:
Description
Automated archival mirror of github.com/cyber-defence-campus/netgear_r6700v3_circled
59 MiB
Languages
Python
60.2%
GDB
18.2%
C
10.6%
Shell
9.3%
Makefile
1.7%