iT邦幫忙

2026 iThome 鐵人賽

DAY 12
0
Security

Like an Exploition:IoT 韌體漏洞鍊成術系列 第 12 篇

【𝕯𝖆𝖞 𝟏𝟐】Pre-Auth 案例分享 (2/2)

  • 分享至 

  • xImage
  •  

前言

0x04 Emulation

靜態分析確認攻擊路徑後,接著直接嘗試把原始 Web Server 跑起來。

這次沒有使用完整 System Emulation,而是先使用 QEMU User Mode:

qemu-mips \
    -L emu_root \
    emu_root/usr/sbin/mini_httpd \
    -d emu_root/www.eng

其中 emu_root 是從原始 rootfs 複製出來的隔離環境,並將原本:

etc -> /tmp/etc
var -> /tmp/var
www -> /tmp/www

等 symlink materialize 成實際目錄,避免 User-mode QEMU 直接碰到 Host 的 /tmp。

最終 mini_httpd 可以正常啟動:

Architecture : MIPS32 Big Endian
libc         : uClibc 0.9.29
Web Root     : www.eng/
HTTP Server  : mini_httpd

並成功載入真正的 NETGEAR Admin UI。

可以直接:

curl http://127.0.0.1/

或從其他主機透過:

ssh -L 8080:localhost:80 kali@<emulation-host>

再瀏覽:

http://localhost:8080/

NVRAM Limitation

目前 User-mode Emulation 最大的限制是 NVRAM。

例如頁面中的:

@model_name#
@wds_mode#
@ap_mode#
@if_wan_up#

仍然會以原始 template placeholder 顯示。

原因是:

mini_httpd
    │
    ▼
nvram_get()
    │
    ▼
NVRAM backend
    │
    X
不存在於目前 User-mode Environment

不過這並不影響 mini_httpd 本身的 HTTP Parsing、靜態資源載入與部分 CGI 測試,因此目前環境已經足以用來驗證前面分析出的 Authentication / Session 行為。

若後續需要完整 Login、Session 與 NVRAM-dependent handler,再考慮透過 Firmadyne / FirmAE 類型的 NVRAM shim 進一步補齊環境。


0x05 Vulnerability Chain

最後把整條漏洞串起來:

                  Attacker
                     │
                     │ HTTP Request
                     ▼
               mini_httpd
                     │
                     ▼
          Authentication Handling
                     │
                     ▼
                 setup.cgi
                     │
              ┌──────┴──────┐
              │             │
            id=0      sp=<invalid>
              │             │
              │             ▼
              │      SessionFile missing
              │             │
              │             ▼
              │      ReadSessionId()
              │             │
              │             ▼
              │             0
              │             │
              └──────┬──────┘
                     ▼
                   0 == 0
                     │
                     ▼
              Session Accepted
                     │
                     ▼
             Pre-auth Access
                     │
                     ▼
               ping_test
                     │
                     ▼
          User-controlled Input
                     │
                     ▼
            Command Construction
                     │
                     ▼
             system() / shell
                     │
                     ▼
            Command Injection

上一篇
【𝕯𝖆𝖞 𝟏𝟏】Pre-Auth 案例分享
下一篇
【𝕯𝖆𝖞 𝟏𝟑】Custom Network Protocol 與 Parser
系列文
Like an Exploition:IoT 韌體漏洞鍊成術 共 18 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言