˼¿ÆCVE-2019-1663²¹¶¡Ê§Ð§°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£º CVE-2019-1663£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

RV110W Wireless-N VPN Firewall

RV130W Wireless-N Multifunction VPN Router

RV215W Wireless-N VPN Router


·ì϶¸ÅÊö


˼¿Æ°ä²¼°²È«²¼¸æ£¬°µÊ¾ÆäÆóÒµÎÞÏßVPNºÍ·À»ðǽ·ÓÉÆ÷´æÔÚÑϳÁ°²È«·ì϶¡£·ì϶²úÉúÊÇÓÉÓÚÔÚ»ùÓÚwebµÄÖÎÀí½çÃæÖжÔÓû§ÌṩµÄÊý¾Ý½øÐÐÁËÃýÎóµÄÑéÖ¤¡£ÔÊÐí¹¥»÷Õßͨ¹ýÏòÖ¸±êÉ豸·¢ËͶñÒâHTTPÒªÇ󣬶øºóÒÔ¸ßȨÏÞÓû§µÄÉí·ÝÔÚÊÜÓ°ÏìÉ豸µÄµ×²ã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£


˼¿Æ°µÊ¾¸Ã·ì϶ÒѾ­´æÔÚÁù¸öÔ£¬Ä¿Ç°ÒѰ䲼²¹¶¡£¬µ«ÊÇ·¢ÏÖ²¹¶¡Ê§Ð§£¬·ì϶ÀûÓÃÒÀÈ»ÔÚ³ÖÐø¡£


·ì϶ϸ½Ú


Ê×ÏÈ¿´Ò»ÏÂCVE-2019-1663·ì϶µÄÆðÒò£º

×êÑÐÈËÔ±×îÔçÊÇÔÚRV130·ÓÉÆ÷ÉÏ·¢Ïָ÷ì϶µÄ£¬RV130·ÓÉÆ÷ÔËÐеIJ¢²»ÊÇCisco IOSϵͳ¶øÊÇǶÈëʽLinuxϵͳ¡£Â·ÓÉÆ÷µÄÖØÒªÖ°ÄÜÊÇÓÉһЩ¶þ½øÔ캯Êý´¦ÖõÄ£¬Ô̺¬´¦ÖÃÓû§ÊäÈëºÍʹ·ÓÉÆ÷Õý³£¹¤×÷¡£


´óÎÞÊýµÄÓû§ÊäÈëÀ´×ÔÓÚweb½Ó¿Ú£¬ÊÜÓ°ÏìµÄ¶þ½øÔìÎļþÊÇhttpd webserver¶þ½øÔìÎļþ¡£ÏÖʵÉϸÃÎļþÖ»ÊÇ´¦Öþ­¹ý80»ò443¶Ë¿ÚµÄËùº±¼û¾Ý£¬Ëü»ñȡͨ¹ýHTTP´«ÊäµÄÓû§ÊäÈ룬²¢×ª»»ÎªÏµÍ³¼¶µÄÅäÖá£


ÏÂÃæ¿´Ò»ÏÂCVE-2019-1663·ì϶±³ºóµÄÎÊÌâ»úÔ죺


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



RV130¹Ì¼þ


ÈôÊÇÌ«³¤µÄÊý¾Ý´«µÝµ½login.cgiÖն˵Äpwd²ÎÊý£¬¾Í»á³öÏÖ»º³åÇøÒç³ö¡£ÕâÒ»²½ÊÇÈÏ֤֮ǰ²úÉúµÄ£¬ÏÂÃæ¿´Ò»ÏÂÕý³£µÇ½µÄ¹ý³Ì£º


µ½web½Ó¿ÚµÄµÇ½ҪÇó»á·¢Ë͸ølogin.cgiÖÕ¶Ë£¬ÌåʽÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


PwdÖµÏÖʵÉÏÊÇÒÔ32×Ö½Ú³¤µÄ±àÂëÃÜÂëµÄ´ó¾Ö·¢Ë͵Ä£¬¸ÃÖµÊÇÔÚÒªÇó·¢ËÍǰͨ¹ýä¯ÀÀÆ÷ÖеÄJS´úÂëÍÆËãµÄ¡£


µÇ½ÊÇÓÉhttpdµÄ0x0002C614´¦µÄº¯Êý´¦ÖõÄ¡£ÒªÇó²ÎÊý»á´ÓPOSTÒªÇóÖнøÐзÖÎö£¬¶øºótoken»¯Ö®ºó·ÅÔÚ¿ÉÖ´ÐÐÎļþµÄ¾²Ì¬Êý¾Ý¿â£¨.bss£©¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ÓPOSTÒªÇóÖÐÈ¡³öºóÄÚ´æÖеIJÎÊý


¶øºó£¬ºÏ·¨±àÂëµÄÃÜÂë¾Í»á´ÓNVRAMÉ豸ÖÐÈ¡³ö£¬·ÅÈëÄÚ´æÖС£¶øºó£¬pwd²ÎÊýµÄÖµ¾Í»á´Ó.bssÖÐÈ¡³öÀ´£¬ÕâÀïʹÓÃÁ˳߶ÈCŲÓÃstrcpy½«Ëü·ÅÈ붯̬·ÖÅäµÄÄÚ´æÖС£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


*record scratch*.


ÔÚÕý³£µÇ½Çé¿öÏ£¬Ã¿¸öÖµ³ÇÊнøÐÐÒ»ÑùµÄ²é³­¡£ÔÚstrcpy½«Öµ¸´Ôìµ½ÄÚ´æÖкó£¬strlen¾Í»áÍÆËãÿ¸öÏîÖ÷Õų¤¶È£¬¶øºóstrcmp±ÈÁ¦Á½¸öÖµ¡£ÈôÊÇËùÓв鳭¶¼Í¨¹ýµÄ»°£¬¾ÍÄܹ»³É¹¦µÇ½¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²é³­³¤¶È


ÎÊÌâ¾ÍÔÚÓÚstrcpy¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


strcpyʹÓúܳ£¼û


ʹÓÃC˵»°±à³ÌµÄ¿ª·¢ÈËÔ±ºÍ°²È«ÈËÔ±Çë°ÑÎÈ£ºstrcpyÆäʵÊÇÓиö¼«¶ÈΣÏյĺ¯Êý¡£ÍøÉÏÓÐÉÏǧƪÎÄÕÂÚ¹ÊÍΪʲô¸Ãº¯ÊýºÜΣÏÕ¡£ÏÂÃæµ¥Ò»¿´Ò»Ï£º


Ê×ÏÈ¿´Ò»Ï£¬Ôڳ߶ȵÄC˵»°ÖУ¬strcpy½ç˵ÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Strcpyº¯Êý»á¸´Ôìs2Ö¸ÏòµÄ×Ö·û´®µ½s1Ö¸ÏòµÄÊý×éÖС£ÈôÊǸ´ÔìÔÚ½»²æµÄ¶ÔÏó¼ä²úÉú£¬ÕâÖÖÇé¿öÊÇûÓÐÔ¤ÏȽç˵µÄ¡£Ò²¾ÍÊÇ˵¿ÉÄÜ»á²úÉúһЩÒâÁÏÖ®±íµÄʼþ¡£ÎªÊ²Ã´ËµstrcpyÓÐÍþÐ²ÄØ£¿ÊÇÓÉÓÚËü»á¸´Ôìs2×Ö·û´®µ½s1Ö¸ÏòµÄÄÚ´æ¡£µ«ÊǸú¯Êý²»´«µÝ³¤¶È£¬Ò²¾ÍÊÇ˵strcpyº¯Êý²»¹ØÇÐ×Ö·û´®µÄ³¤¶È¡£¶ÔstrcpyÀ´Ëµ£¬×Ö·û´®µÄ³¤¶ÈÒ»µãÒ²²»³ÁÒª¡£¸´ÔìµÄ¹ý³ÌÖпÉÄÜ»á²úÉú¸²Ð´µÄÇé¿ö£¬¶ø¹¥»÷ÕßÒ²ÕýÊÇÀûÓÃÕâһDZÔÚ·ì϶ÌáÒé¹¥»÷£¬Äܹ»¸²Ð´Õ»ÄÚ±£ÁôµÄ·µ»ØÖ¸Õ룬¶øºó³Á¶¨Ïò¹ý³ÌµÄÖ´ÐÐÁ÷¡£


ÏÂͼÊÇÔÚʹÓÃstrcpyʱ¿ÉÄÜ»á²úÉúµÄÇé¿ö£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


A segfault


ÔÚ·¢ËÍÏÂÃæµÄÒªÇó¸øRV130ʱ²úÉúµÄÇé¿ö¾ÍºÍÉÏÃæÒ»Ñù£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Õ»Öб£ÁôµÄ·µ»ØÖ¸Õë±»¡°ZZZZ¡±¸²Ð´ÁË£¬Òò¶øÖ´ÐÐÁ÷»á±»³Á¶¨Ïòµ½0x5A5A5A5A¡£


×êÑÐÈËÔ±½¨ÒéʹÓÃstrlcpyº¯Êý£¬strlcpyÊÇC˵»°³ß¶È¿âº¯Êý£¬ÊÇÔ½·¢°²È«°æ±¾µÄstrcpyº¯Êý£¬ÔÚÒÑÖªÖ÷ÕŵØÖ·¿Õ¼ä´óÓ×µÄÇé¿öÏ£¬°Ñ´ÓsrcµØÖ·ÆðÍ·ÇÒº¬ÓÐ'\0'ʵÏÖ·ûµÄ×Ö·û´®¸´Ôìµ½ÒÔdestÆðÍ·µÄµØÖ·¿Õ¼ä,²¢²»»áÔì³É»º³åÇøÒç³ö¡£


½¨¸´½¨Òé


˼¿ÆÖ®Ç°ÒѰ䲼²¹¶¡£¬µ«ÊÇ·¢ÏÖ²¹¶¡Ê§Ð§£¬ ÇëÇ×êǹØ×¢¹ÙÍø¸üС£


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex#fr

https://www.pentestpartners.com/security-blog/cisco-rv130-its-2019-but-yet-strcpy/