2023-10-05 15:31:29 +02:00
2023-06-01 08:19:48 +02:00
2023-10-05 15:31:29 +02:00
2023-06-26 09:29:33 +02:00
2023-06-26 13:55:27 +02:00
2023-09-07 15:32:05 +02:00
2023-07-12 16:32:11 +02:00
2023-06-01 08:56:33 +02:00

Exploiting a Stack Buffer Overflow on the Netgear R6700v3

1. Individual Binary Emulation

  • Extract the R6700v3 firmware with binwalk
  • Use QEMU to boot an ARM Debian system
  • Upload the firmware's root filesystem to the ARM Debian system
  • Build and copy a statically-linked version of gdbserver to the root filesystem
  • Emulate the circled binary
    • Cross-compile (use bootlin toolchain for armv7-eabihf and ulibc) libnvram to emulate non-volatile RAM (NVRAM)
    • Chroot into the root filesystem
      • sudo mount -t proc /proc/ ./squashfs-root/proc/
      • sudo mount -t sysfs /sys/ ./squashfs-root/sys/
      • sudo mount -o bind /dev/ ./squashfs-root/dev/
      • sudo chroot ./squashfs-root/ /bin/sh
      • export SHELL=/bin/sh
    • Execute the targeted binary (use circled.sh helper script)
  • Trace crash (gdb-multiarch -q -x circled.gdb)

2. References

S
Description
Automated archival mirror of github.com/cyber-defence-campus/netgear_r6700v3_circled
Readme Apache-2.0
59 MiB
Languages
Python 60.2%
GDB 18.2%
C 10.6%
Shell 9.3%
Makefile 1.7%