2024-05-02 13:40:33 +02:00
2024-05-02 13:40:33 +02:00
2024-05-01 11:29:30 +02:00
2024-05-02 10:15:48 +02:00
2024-05-01 16:06:40 +02:00
2024-05-02 12:02:13 +02:00
2023-09-07 15:32:05 +02:00
2023-12-12 15:49:22 +01:00
2024-05-01 11:30:26 +02:00

Exploiting a Stack Buffer Overflow on the NETGEAR R6700v3 (CVE-2022-27646) with the Help of Symbolic Execution

Introduction

This repository is intended to demonstrate some functionalities of Morion, a proof-of-concept (PoC) tool to experiment with symbolic execution on real-world (ARMv7) binaries. We show some of Morion's capabilities by giving a concrete example, namely, how it can assist during the process of creating a working exploit for CVE-2022-27646 - a stack buffer overflow vulnerability in NETGEAR R6700v3 routers (version 10.04.120_10.0.91).

The repository contains all files (under firmware, libcircled, morion and server) needed to follow along (e.g. scripts to emulate the vulnerable ARMv7 binary) and reproduce the discussed steps of how to make use of Morion. The documentation (under docs and logs), to demonstrate Morion's workings, contains the following chapters:

  1. Setup - Explains how to setup analysis (running Morion) and target systems (running target binary circled).
  2. Emulation - Explains how to emulate the vulnerable target binary.
  3. Tracing - Explains how to record a concrete execution trace of the target binary using Morion.
  4. Symbolic Execution - Explains how to use Morion for analyzing the recorded trace symbolically.
  5. Vulnerability CVE-2022-27646 - Provides some background information to the targeted vulnerability.
  6. Exploitation - Explains how Morion can assist in crafting an exploit.

References

S
Description
Automated archival mirror of github.com/cyber-defence-campus/netgear_r6700v3_circled
Readme Apache-2.0
59 MiB
Languages
Python 60.2%
GDB 18.2%
C 10.6%
Shell 9.3%
Makefile 1.7%