D-Link DSL-2888A AU_2.31_V1.1.47ae55֮ǰµÄ°æ±¾´æÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¬¾¹ýÉí·ÝÑéÖ¤µÄÓû§¿Éͨ¹ý·ÃÎÊ/cgi-bin/execute_cmd.cgi´¥·¢ÃüÁîÖ´ÐЩ¶´¡£
D-Link DSL-2888A AU_2.31_V1.1.47ae55֮ǰµÄ°æ±¾
Ê×ÏÈÔÚ¹ÜÀíÔ±ÃÜÂëÀ¸´¦ÊäÈëÈÎÒâÃÜÂëµã»÷µÇ¼ºó·ÃÎÊ/cgi-bin/execute_cmd.cgi?timestamp=1&cmd=id¼´¿É´¥·¢ÃüÁîÖ´ÐЩ¶´
Ö´ÐÐÃüÁîbinwal -Me ../IOT_BUG/CVE-2020-24581/DSL-2888A_AU_2.12_V1.1.47Z1-Image-all.bin --run-as=root½«¹Ì¼þÎļþϵͳÌáÈ¡£¬ÌáÈ¡ºóµÄĿ¼½á¹¹ÈçͼËùʾ
Ö´ÐÐÃüÁî
cd jffs2-root
½øÈëÎļþϵͳ£¬Îļþϵͳ½á¹¹ÈçͼËùʾ
¸Ã©¶´ÎªwebÓ¦Óé¶´£¬¸Ã¹Ì¼þÖÐweb×é¼þΪdhttpd£¬Ö´ÐÐÃüÁîfind . -name ¡°dhttpd¡±ËÑË÷web×é¼þλÖã¬ËÑË÷½á¹ûÈçͼËùʾ
ÈçͼËùʾ£¬Í¨¹ýIDA´ò¿ªdhttpd
¸ÃÔ¶³ÌÃüÁîÖ´ÐнӿÚΪ/cgi-bin/execute_cmd.cgi£¬ÈçͼËùʾ£¬ÔÚº¯Êýsub_9C4CÖУ¬Èç¹û·ÃÎÊ·¾¶ÖдæÔÚ/cgi-bin£¬Ôòµ÷ÓÃsub_BEA0º¯Êý½øÐд¦Àí
¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄµÚ52Ðн«cgiÎļþÓëcgi-binĿ¼½øÐÐÆ´½Ó£¬ÔÚµÚ53ÐÐÅжÏcgiÎļþÊÇ·ñ´æÔÚ£¬ÔÚµÚ63ÐÐÅжÏcgiÎļþÊÇ·ñ´æÔÚÖ´ÐÐȨÏÞ
¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄµÚ70Ðн«»ñÈ¡µ±Ç°Îļþ·¾¶£¬ÔÚ71ÐÐÔÚfile²éÕÒ¡±/¡±×îºóÒ»´ÎµÄλÖã¬Èç¹û¸ÃλÖôæÔÚ£¬ÔòÔÚµÚ76ÐнøÈëfileĿ¼

¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄ105-108Ðн«½øÐÐcgiÎļþÖ´Ðл·¾³±äÁ¿ÅäÖÃ
¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄ111-143Ðн«½øÐÐÉí·ÝУÑé
¼ÌÐø¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬Í¨¹ýÉí·ÝУÑéºó£¬ÔÚµÚ149Ðе÷ÓÃsub_BB5Cº¯Êý¶ÔcgiÎļþ½øÐд¦Àí
¸ú½øsub_BB5Cº¯Êý£¬ÔÚsub_BB5Cº¯ÊýµÄµÚ40Ðе÷ÓÃexecveº¯ÊýÖ´ÐÐcgiÎļþ
²éÕÒ´æÔÚ©¶´µÄexecute_cmd.cgiÎļþ£¬execute_cmd.cgiÎļþλÓÚÎļþϵͳϵÄwww/cgi-binĿ¼
²é¿´execute_cmd.cgiÎļþ¾ßÌåÄÚÈÝ£¬execute_cmd.cgiÎļþ¾ßÌåÄÚÈÝÈçͼËùʾ£¬execute_cmd.cgiÎļþÄÚÈÝΪ»ñÈ¡QUERY_STRINGÖеڶþ¸ö²ÎÊýµÄÖµ£¬²¢Í¨¹ý·´ÒýºÅ``ÒÔÖ´ÐÐÃüÁʽִÐиÃÖµ
ÔÚIDAÖÐËÑË÷QUERY_STRING£¬ËÑË÷½á¹ûÈçͼËùʾ
ÔÚjsÎļþĿ¼²éÕÒQueryString£¬²éÕÒ½á¹ûÈçͼËùʾ
·ÃÎÊ´æÔÚQueryString×Ö·ûµÄajax.jsÎļþ£¬ajax.jsÎļþÄÚÈÝÈçͼËùʾ
¹Êµ±Í¨¹ýÉí·ÝУÑéʱ£¬¹¹Ôìuri£º/cgi-bin/execute_cmd.cgi?timestamp=1&cmd=cmd¿ÉÖ´ÐÐÈÎÒâÃüÁÓÉÓڸð汾·ÓÉÆ÷ÔÚÃÜÂëÀ¸ÊäÈëÈÎÒâÃÜÂëºó¼´¿ÉÈÆ¹ýÉí·ÝУÑ飬ËùÒÔ²»ÐèÖªµÀÉ豸ÃÜÂë¼´¿É´¥·¢ÃüÁîÖ´ÐЩ¶´
