˼¿ÆCVE-2019-1663²¹¶¡Ê§Ð§Ç徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-06Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£º CVE-2019-1663£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
RV110W Wireless-N VPN Firewall
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router
Îó²î¸ÅÊö
˼¿ÆÐû²¼Ç徲ͨ¸æ£¬£¬ÌåÏÖÆäÆóÒµÎÞÏßVPNºÍ·À»ðǽ·ÓÉÆ÷±£´æÑÏÖØÇå¾²Îó²î¡£¡£¡£Îó²î±¬·¢ÊÇÓÉÓÚÔÚ»ùÓÚwebµÄÖÎÀí½çÃæÖжÔÓû§ÌṩµÄÊý¾Ý¾ÙÐÐÁ˹ýʧµÄÑéÖ¤¡£¡£¡£ÔÊÐí¹¥»÷Õßͨ¹ýÏòÄ¿µÄ×°±¸·¢ËͶñÒâHTTPÇëÇ󣬣¬È»ºóÒÔ¸ßȨÏÞÓû§µÄÉí·ÝÔÚÊÜÓ°Ïì×°±¸µÄµ×²ã²Ù×÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
˼¿ÆÌåÏÖ¸ÃÎó²îÒѾ±£´æÁù¸öÔ£¬£¬ÏÖÔÚÒÑÐû²¼²¹¶¡£¬£¬¿ÉÊÇ·¢Ã÷²¹¶¡Ê§Ð§£¬£¬Îó²îʹÓÃÈÔÈ»ÔÚ¼ÌÐø¡£¡£¡£
Îó²îϸ½Ú
Ê×ÏÈ¿´Ò»ÏÂCVE-2019-1663Îó²îµÄÒòÓÉ£º
Ñо¿Ö°Ô±×îÔçÊÇÔÚRV130·ÓÉÆ÷ÉÏ·¢Ã÷¸ÃÎó²îµÄ£¬£¬RV130·ÓÉÆ÷ÔËÐеIJ¢²»ÊÇCisco IOSϵͳ¶øÊÇǶÈëʽLinuxϵͳ¡£¡£¡£Â·ÓÉÆ÷µÄÖ÷Òª¹¦Ð§ÊÇÓÉһЩ¶þ½øÖƺ¯Êý´¦Öóͷ£µÄ£¬£¬°üÀ¨´¦Öóͷ£Óû§ÊäÈëºÍʹ·ÓÉÆ÷Õý³£ÊÂÇé¡£¡£¡£
´ó´ó¶¼µÄÓû§ÊäÈëÀ´×ÔÓÚweb½Ó¿Ú£¬£¬ÊÜÓ°ÏìµÄ¶þ½øÖÆÎļþÊÇhttpd webserver¶þ½øÖÆÎļþ¡£¡£¡£ÏÖʵÉϸÃÎļþÖ»ÊÇ´¦Öóͷ£¾ÓÉ80»ò443¶Ë¿ÚµÄËùÓÐÊý¾Ý£¬£¬Ëü»ñȡͨ¹ýHTTP´«ÊäµÄÓû§ÊäÈ룬£¬²¢×ª»»ÎªÏµÍ³¼¶µÄÉèÖᣡ£¡£
ÏÂÃæ¿´Ò»ÏÂCVE-2019-1663Îó²î±³ºóµÄÎÊÌâ»úÖÆ£º
RV130¹Ì¼þ
ÈôÊÇÌ«³¤µÄÊý¾Ýת´ïµ½login.cgiÖն˵Äpwd²ÎÊý£¬£¬¾Í»á·ºÆð»º³åÇøÒç³ö¡£¡£¡£ÕâÒ»²½ÊÇÈÏ֤֮ǰ±¬·¢µÄ£¬£¬ÏÂÃæ¿´Ò»ÏÂÕý³£Éϰ¶µÄÀú³Ì£º
µ½web½Ó¿ÚµÄÉϰ¶ÇëÇó»á·¢Ë͸ølogin.cgiÖÕ¶Ë£¬£¬ÃûÌÃÈçÏ£º
PwdÖµÏÖʵÉÏÊÇÒÔ32×Ö½Ú³¤µÄ±àÂëÃÜÂëµÄÐÎʽ·¢Ë͵쬣¬¸ÃÖµÊÇÔÚÇëÇó·¢ËÍǰͨ¹ýä¯ÀÀÆ÷ÖеÄJS´úÂëÅÌËãµÄ¡£¡£¡£
Éϰ¶ÊÇÓÉhttpdµÄ0x0002C614´¦µÄº¯Êý´¦Öóͷ£µÄ¡£¡£¡£ÇëÇó²ÎÊý»á´ÓPOSTÇëÇóÖоÙÐÐÆÊÎö£¬£¬È»ºótoken»¯Ö®ºó·ÅÔÚ¿ÉÖ´ÐÐÎļþµÄ¾²Ì¬Êý¾Ý¿â£¨.bss£©¡£¡£¡£
´ÓPOSTÇëÇóÖÐÈ¡³öºóÄÚ´æÖеIJÎÊý
È»ºó£¬£¬Õýµ±±àÂëµÄÃÜÂë¾Í»á´ÓNVRAM×°±¸ÖÐÈ¡³ö£¬£¬·ÅÈëÄÚ´æÖС£¡£¡£È»ºó£¬£¬pwd²ÎÊýµÄÖµ¾Í»á´Ó.bssÖÐÈ¡³öÀ´£¬£¬ÕâÀïʹÓÃÁ˱ê×¼CŲÓÃstrcpy½«Ëü·ÅÈ붯̬·ÖÅɵÄÄÚ´æÖС£¡£¡£
*record scratch*.
ÔÚÕý³£Éϰ¶ÇéÐÎÏ£¬£¬Ã¿¸öÖµ¶¼»á¾ÙÐÐÏàͬµÄ¼ì²é¡£¡£¡£ÔÚstrcpy½«Öµ¸´ÖƵ½ÄÚ´æÖк󣬣¬strlen¾Í»áÅÌËãÿ¸öÏîÄ¿µÄ³¤¶È£¬£¬È»ºóstrcmp½ÏÁ¿Á½¸öÖµ¡£¡£¡£ÈôÊÇËùÓмì²é¶¼Í¨¹ýµÄ»°£¬£¬¾Í¿ÉÒÔÀÖ³ÉÉϰ¶¡£¡£¡£
¼ì²é³¤¶È
ÎÊÌâ¾ÍÔÚÓÚstrcpy¡£¡£¡£
strcpyʹÓúܳ£¼û
ʹÓÃCÓïÑÔ±à³ÌµÄ¿ª·¢Ö°Ô±ºÍÇå¾²Ö°Ô±Çë×¢ÖØ£ºstrcpy×ÅʵÊÇÓиöºÜÊÇΣÏյĺ¯Êý¡£¡£¡£ÍøÉÏÓÐÉÏǧƪÎÄÕÂÚ¹ÊÍΪʲô¸Ãº¯ÊýºÜΣÏÕ¡£¡£¡£ÏÂÃæ¼òÆÓ¿´Ò»Ï£º
Ê×ÏÈ¿´Ò»Ï£¬£¬ÔÚ±ê×¼µÄCÓïÑÔÖУ¬£¬strcpy½ç˵ÈçÏ£º
Strcpyº¯Êý»á¸´ÖÆs2Ö¸ÏòµÄ×Ö·û´®µ½s1Ö¸ÏòµÄÊý×éÖС£¡£¡£ÈôÊǸ´ÖÆÔÚ½»Ö¯µÄ¹¤¾ß¼ä±¬·¢£¬£¬ÕâÖÖÇéÐÎÊÇûÓÐÔ¤ÏȽç˵µÄ¡£¡£¡£Ò²¾ÍÊÇ˵¿ÉÄܻᱬ·¢Ò»Ð©ÒâÁÏÖ®ÍâµÄÊÂÇé¡£¡£¡£ÎªÊ²Ã´ËµstrcpyÓÐÍþÐ²ÄØ£¿£¿£¿£¿£¿£¿ÊÇÓÉÓÚËü»á¸´ÖÆs2×Ö·û´®µ½s1Ö¸ÏòµÄÄÚ´æ¡£¡£¡£¿ÉÊǸú¯Êý²»×ª´ï³¤¶È£¬£¬Ò²¾ÍÊÇ˵strcpyº¯Êý²»ÌåÌù×Ö·û´®µÄ³¤¶È¡£¡£¡£¶ÔstrcpyÀ´Ëµ£¬£¬×Ö·û´®µÄ³¤¶ÈÒ»µãÒ²²»Ö÷Òª¡£¡£¡£¸´ÖƵÄÀú³ÌÖпÉÄܻᱬ·¢¸²Ð´µÄÇéÐΣ¬£¬¶ø¹¥»÷ÕßÒ²ÕýÊÇʹÓÃÕâһDZÔÚÎó²îÌᳫ¹¥»÷£¬£¬¿ÉÒÔ¸²Ð´Õ»ÄÚÉúÑĵķµ»ØÖ¸Õ룬£¬È»ºóÖØ¶¨ÏòÀú³ÌµÄÖ´ÐÐÁ÷¡£¡£¡£
ÏÂͼÊÇÔÚʹÓÃstrcpyʱ¿ÉÄܻᱬ·¢µÄÇéÐΣº
A segfault
ÔÚ·¢ËÍÏÂÃæµÄÇëÇó¸øRV130ʱ±¬·¢µÄÇéÐξͺÍÉÏÃæÒ»Ñù£º
Õ»ÖÐÉúÑĵķµ»ØÖ¸Õë±»¡°ZZZZ¡±¸²Ð´ÁË£¬£¬Òò´ËÖ´ÐÐÁ÷»á±»Öض¨Ïòµ½0x5A5A5A5A¡£¡£¡£
Ñо¿Ö°Ô±½¨ÒéʹÓÃstrlcpyº¯Êý£¬£¬strlcpyÊÇCÓïÑÔ±ê×¼¿âº¯Êý£¬£¬ÊÇÔ½·¢Çå¾²°æ±¾µÄstrcpyº¯Êý£¬£¬ÔÚÒÑ֪ĿµÄµØµã¿Õ¼ä¾ÞϸµÄÇéÐÎÏ£¬£¬°Ñ´ÓsrcµØµã×îÏÈÇÒº¬ÓÐ'\0'¿¢Ê·ûµÄ×Ö·û´®¸´ÖƵ½ÒÔdest×îÏȵĵصã¿Õ¼ä,²¢²»»áÔì³É»º³åÇøÒç³ö¡£¡£¡£
ÐÞ¸´½¨Òé
˼¿ÆÖ®Ç°ÒÑÐû²¼²¹¶¡£¬£¬¿ÉÊÇ·¢Ã÷²¹¶¡Ê§Ð§£¬£¬ ÇëÇ×½ü¹Ø×¢¹ÙÍø¸üС£¡£¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex#fr
https://www.pentestpartners.com/security-blog/cisco-rv130-its-2019-but-yet-strcpy/


¾©¹«Íø°²±¸11010802024551ºÅ