˼¿ÆCVE-2019-1663²¹¶¡Ê§Ð§°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£º CVE-2019-1663£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
RV110W Wireless-N VPN Firewall
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router
·ì϶¸ÅÊö
˼¿Æ°ä²¼°²È«²¼¸æ£¬°µÊ¾ÆäÆóÒµÎÞÏßVPNºÍ·À»ðǽ·ÓÉÆ÷´æÔÚÑϳÁ°²È«·ì϶¡£·ì϶²úÉúÊÇÓÉÓÚÔÚ»ùÓÚwebµÄÖÎÀí½çÃæÖжÔÓû§ÌṩµÄÊý¾Ý½øÐÐÁËÃýÎóµÄÑéÖ¤¡£ÔÊÐí¹¥»÷Õßͨ¹ýÏòÖ¸±êÉ豸·¢ËͶñÒâHTTPÒªÇ󣬶øºóÒÔ¸ßȨÏÞÓû§µÄÉí·ÝÔÚÊÜÓ°ÏìÉ豸µÄµ×²ã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
˼¿Æ°µÊ¾¸Ã·ì϶ÒѾ´æÔÚÁù¸öÔ£¬Ä¿Ç°ÒѰ䲼²¹¶¡£¬µ«ÊÇ·¢ÏÖ²¹¶¡Ê§Ð§£¬·ì϶ÀûÓÃÒÀÈ»ÔÚ³ÖÐø¡£
·ì϶ϸ½Ú
Ê×ÏÈ¿´Ò»ÏÂCVE-2019-1663·ì϶µÄÆðÒò£º
×êÑÐÈËÔ±×îÔçÊÇÔÚRV130·ÓÉÆ÷ÉÏ·¢Ïָ÷ì϶µÄ£¬RV130·ÓÉÆ÷ÔËÐеIJ¢²»ÊÇCisco IOSϵͳ¶øÊÇǶÈëʽLinuxϵͳ¡£Â·ÓÉÆ÷µÄÖØÒªÖ°ÄÜÊÇÓÉһЩ¶þ½øÔ캯Êý´¦Öõģ¬Ô̺¬´¦ÖÃÓû§ÊäÈëºÍʹ·ÓÉÆ÷Õý³£¹¤×÷¡£
´óÎÞÊýµÄÓû§ÊäÈëÀ´×ÔÓÚweb½Ó¿Ú£¬ÊÜÓ°ÏìµÄ¶þ½øÔìÎļþÊÇhttpd webserver¶þ½øÔìÎļþ¡£ÏÖʵÉϸÃÎļþÖ»ÊÇ´¦Öþ¹ý80»ò443¶Ë¿ÚµÄËùº±¼û¾Ý£¬Ëü»ñȡͨ¹ýHTTP´«ÊäµÄÓû§ÊäÈ룬²¢×ª»»ÎªÏµÍ³¼¶µÄÅäÖá£
ÏÂÃæ¿´Ò»ÏÂCVE-2019-1663·ì϶±³ºóµÄÎÊÌâ»úÔ죺
RV130¹Ì¼þ
ÈôÊÇÌ«³¤µÄÊý¾Ý´«µÝµ½login.cgiÖն˵Äpwd²ÎÊý£¬¾Í»á³öÏÖ»º³åÇøÒç³ö¡£ÕâÒ»²½ÊÇÈÏ֤֮ǰ²úÉúµÄ£¬ÏÂÃæ¿´Ò»ÏÂÕý³£µÇ½µÄ¹ý³Ì£º
µ½web½Ó¿ÚµÄµÇ½ҪÇó»á·¢Ë͸ølogin.cgiÖÕ¶Ë£¬ÌåʽÈçÏ£º
PwdÖµÏÖʵÉÏÊÇÒÔ32×Ö½Ú³¤µÄ±àÂëÃÜÂëµÄ´ó¾Ö·¢Ë͵쬏ÃÖµÊÇÔÚÒªÇó·¢ËÍǰͨ¹ýä¯ÀÀÆ÷ÖеÄJS´úÂëÍÆËãµÄ¡£
µÇ½ÊÇÓÉhttpdµÄ0x0002C614´¦µÄº¯Êý´¦Öõġ£ÒªÇó²ÎÊý»á´ÓPOSTÒªÇóÖнøÐзÖÎö£¬¶øºótoken»¯Ö®ºó·ÅÔÚ¿ÉÖ´ÐÐÎļþµÄ¾²Ì¬Êý¾Ý¿â£¨.bss£©¡£
´ÓPOSTÒªÇóÖÐÈ¡³öºóÄÚ´æÖеIJÎÊý
¶øºó£¬ºÏ·¨±àÂëµÄÃÜÂë¾Í»á´ÓNVRAMÉ豸ÖÐÈ¡³ö£¬·ÅÈëÄÚ´æÖС£¶øºó£¬pwd²ÎÊýµÄÖµ¾Í»á´Ó.bssÖÐÈ¡³öÀ´£¬ÕâÀïʹÓÃÁ˳߶ÈCŲÓÃstrcpy½«Ëü·ÅÈ붯̬·ÖÅäµÄÄÚ´æÖС£
*record scratch*.
ÔÚÕý³£µÇ½Çé¿öÏ£¬Ã¿¸öÖµ³ÇÊнøÐÐÒ»ÑùµÄ²é³¡£ÔÚstrcpy½«Öµ¸´Ôìµ½ÄÚ´æÖкó£¬strlen¾Í»áÍÆËãÿ¸öÏîÖ÷Õų¤¶È£¬¶øºóstrcmp±ÈÁ¦Á½¸öÖµ¡£ÈôÊÇËùÓв鳶¼Í¨¹ýµÄ»°£¬¾ÍÄܹ»³É¹¦µÇ½¡£
²é³³¤¶È
ÎÊÌâ¾ÍÔÚÓÚstrcpy¡£
strcpyʹÓúܳ£¼û
ʹÓÃC˵»°±à³ÌµÄ¿ª·¢ÈËÔ±ºÍ°²È«ÈËÔ±Çë°ÑÎÈ£ºstrcpyÆäʵÊÇÓиö¼«¶ÈΣÏյĺ¯Êý¡£ÍøÉÏÓÐÉÏǧƪÎÄÕÂÚ¹ÊÍΪʲô¸Ãº¯ÊýºÜΣÏÕ¡£ÏÂÃæµ¥Ò»¿´Ò»Ï£º
Ê×ÏÈ¿´Ò»Ï£¬Ôڳ߶ȵÄC˵»°ÖУ¬strcpy½ç˵ÈçÏ£º
Strcpyº¯Êý»á¸´Ôìs2Ö¸ÏòµÄ×Ö·û´®µ½s1Ö¸ÏòµÄÊý×éÖС£ÈôÊǸ´ÔìÔÚ½»²æµÄ¶ÔÏó¼ä²úÉú£¬ÕâÖÖÇé¿öÊÇûÓÐÔ¤ÏȽç˵µÄ¡£Ò²¾ÍÊÇ˵¿ÉÄÜ»á²úÉúһЩÒâÁÏÖ®±íµÄʼþ¡£ÎªÊ²Ã´ËµstrcpyÓÐÍþÐ²ÄØ£¿ÊÇÓÉÓÚËü»á¸´Ôìs2×Ö·û´®µ½s1Ö¸ÏòµÄÄÚ´æ¡£µ«ÊǸú¯Êý²»´«µÝ³¤¶È£¬Ò²¾ÍÊÇ˵strcpyº¯Êý²»¹ØÇÐ×Ö·û´®µÄ³¤¶È¡£¶ÔstrcpyÀ´Ëµ£¬×Ö·û´®µÄ³¤¶ÈÒ»µãÒ²²»³ÁÒª¡£¸´ÔìµÄ¹ý³ÌÖпÉÄÜ»á²úÉú¸²Ð´µÄÇé¿ö£¬¶ø¹¥»÷ÕßÒ²ÕýÊÇÀûÓÃÕâһDZÔÚ·ì϶ÌáÒé¹¥»÷£¬Äܹ»¸²Ð´Õ»ÄÚ±£ÁôµÄ·µ»ØÖ¸Õ룬¶øºó³Á¶¨Ïò¹ý³ÌµÄÖ´ÐÐÁ÷¡£
ÏÂͼÊÇÔÚʹÓÃstrcpyʱ¿ÉÄÜ»á²úÉúµÄÇé¿ö£º
A segfault
ÔÚ·¢ËÍÏÂÃæµÄÒªÇó¸øRV130ʱ²úÉúµÄÇé¿ö¾ÍºÍÉÏÃæÒ»Ñù£º
Õ»Öб£ÁôµÄ·µ»ØÖ¸Õë±»¡°ZZZZ¡±¸²Ð´ÁË£¬Òò¶øÖ´ÐÐÁ÷»á±»³Á¶¨Ïòµ½0x5A5A5A5A¡£
×êÑÐÈËÔ±½¨ÒéʹÓÃstrlcpyº¯Êý£¬strlcpyÊÇC˵»°³ß¶È¿âº¯Êý£¬ÊÇÔ½·¢°²È«°æ±¾µÄstrcpyº¯Êý£¬ÔÚÒÑÖªÖ÷ÕŵØÖ·¿Õ¼ä´óÓ×µÄÇé¿öÏ£¬°Ñ´ÓsrcµØÖ·ÆðÍ·ÇÒº¬ÓÐ'\0'ʵÏÖ·ûµÄ×Ö·û´®¸´Ôìµ½ÒÔdestÆðÍ·µÄµØÖ·¿Õ¼ä,²¢²»»áÔì³É»º³åÇøÒç³ö¡£
½¨¸´½¨Òé
˼¿ÆÖ®Ç°ÒѰ䲼²¹¶¡£¬µ«ÊÇ·¢ÏÖ²¹¶¡Ê§Ð§£¬ ÇëÇ×êǹØ×¢¹ÙÍø¸üС£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex#fr
https://www.pentestpartners.com/security-blog/cisco-rv130-its-2019-but-yet-strcpy/


¾©¹«Íø°²±¸11010802024551ºÅ