˼¿ÆCVE-2019-1663²¹¶¡Ê§Ð§°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£º CVE-2019-1663£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
RV110W Wireless-N VPN Firewall
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router
·ì϶¸ÅÊö
˼¿Æ°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬°µÊ¾ÆäÆóÒµÎÞÏßVPNºÍ·À»ðǽ·ÓÉÆ÷´æÔÚÑϳÁ°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£·ì϶²úÉúÊÇÓÉÓÚÔÚ»ùÓÚwebµÄÖÎÀí½çÃæÖжÔÓû§ÌṩµÄÊý¾Ý½øÐÐÁËÃýÎóµÄÑéÖ¤¡£¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷Õßͨ¹ýÏòÖ¸±êÉ豸·¢ËͶñÒâHTTPÒªÇ󣬣¬£¬£¬£¬£¬£¬¶øºóÒÔ¸ßȨÏÞÓû§µÄÉí·ÝÔÚÊÜÓ°ÏìÉ豸µÄµ×²ã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
˼¿Æ°µÊ¾¸Ã·ì϶ÒѾ´æÔÚÁù¸öÔ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÒѰ䲼²¹¶¡£¬£¬£¬£¬£¬£¬£¬µ«ÊÇ·¢ÏÖ²¹¶¡Ê§Ð§£¬£¬£¬£¬£¬£¬£¬·ì϶ÀûÓÃÒÀÈ»ÔÚ³ÖÐø¡£¡£¡£¡£¡£¡£¡£
·ì϶ϸ½Ú
Ê×ÏÈ¿´Ò»ÏÂCVE-2019-1663·ì϶µÄÆðÒò£º
×êÑÐÈËÔ±×îÔçÊÇÔÚRV130·ÓÉÆ÷ÉÏ·¢Ïָ÷ì϶µÄ£¬£¬£¬£¬£¬£¬£¬RV130·ÓÉÆ÷ÔËÐеIJ¢²»ÊÇCisco IOSϵͳ¶øÊÇǶÈëʽLinuxϵͳ¡£¡£¡£¡£¡£¡£¡£Â·ÓÉÆ÷µÄÖØÒªÖ°ÄÜÊÇÓÉһЩ¶þ½øÔ캯Êý´¦Öõ쬣¬£¬£¬£¬£¬£¬Ô̺¬´¦ÖÃÓû§ÊäÈëºÍʹ·ÓÉÆ÷Õý³£¹¤×÷¡£¡£¡£¡£¡£¡£¡£
´óÎÞÊýµÄÓû§ÊäÈëÀ´×ÔÓÚweb½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¶þ½øÔìÎļþÊÇhttpd webserver¶þ½øÔìÎļþ¡£¡£¡£¡£¡£¡£¡£ÏÖʵÉϸÃÎļþÖ»ÊÇ´¦Öþ¹ý80»ò443¶Ë¿ÚµÄËùº±¼û¾Ý£¬£¬£¬£¬£¬£¬£¬Ëü»ñȡͨ¹ýHTTP´«ÊäµÄÓû§ÊäÈ룬£¬£¬£¬£¬£¬£¬²¢×ª»»ÎªÏµÍ³¼¶µÄÅäÖᣡ£¡£¡£¡£¡£¡£
ÏÂÃæ¿´Ò»ÏÂCVE-2019-1663·ì϶±³ºóµÄÎÊÌâ»úÔ죺
RV130¹Ì¼þ
ÈôÊÇÌ«³¤µÄÊý¾Ý´«µÝµ½login.cgiÖն˵Äpwd²ÎÊý£¬£¬£¬£¬£¬£¬£¬¾Í»á³öÏÖ»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£ÕâÒ»²½ÊÇÈÏ֤֮ǰ²úÉúµÄ£¬£¬£¬£¬£¬£¬£¬ÏÂÃæ¿´Ò»ÏÂÕý³£µÇ½µÄ¹ý³Ì£º
µ½web½Ó¿ÚµÄµÇ½ҪÇó»á·¢Ë͸ølogin.cgiÖÕ¶Ë£¬£¬£¬£¬£¬£¬£¬ÌåʽÈçÏ£º
PwdÖµÏÖʵÉÏÊÇÒÔ32×Ö½Ú³¤µÄ±àÂëÃÜÂëµÄ´ó¾Ö·¢Ë͵쬣¬£¬£¬£¬£¬£¬¸ÃÖµÊÇÔÚÒªÇó·¢ËÍǰͨ¹ýä¯ÀÀÆ÷ÖеÄJS´úÂëÍÆËãµÄ¡£¡£¡£¡£¡£¡£¡£
µÇ½ÊÇÓÉhttpdµÄ0x0002C614´¦µÄº¯Êý´¦Öõġ£¡£¡£¡£¡£¡£¡£ÒªÇó²ÎÊý»á´ÓPOSTÒªÇóÖнøÐзÖÎö£¬£¬£¬£¬£¬£¬£¬¶øºótoken»¯Ö®ºó·ÅÔÚ¿ÉÖ´ÐÐÎļþµÄ¾²Ì¬Êý¾Ý¿â£¨.bss£©¡£¡£¡£¡£¡£¡£¡£
´ÓPOSTÒªÇóÖÐÈ¡³öºóÄÚ´æÖеIJÎÊý
¶øºó£¬£¬£¬£¬£¬£¬£¬ºÏ·¨±àÂëµÄÃÜÂë¾Í»á´ÓNVRAMÉ豸ÖÐÈ¡³ö£¬£¬£¬£¬£¬£¬£¬·ÅÈëÄÚ´æÖС£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬£¬pwd²ÎÊýµÄÖµ¾Í»á´Ó.bssÖÐÈ¡³öÀ´£¬£¬£¬£¬£¬£¬£¬ÕâÀïʹÓÃÁ˳߶ÈCŲÓÃstrcpy½«Ëü·ÅÈ붯̬·ÖÅäµÄÄÚ´æÖС£¡£¡£¡£¡£¡£¡£
*record scratch*.
ÔÚÕý³£µÇ½Çé¿öÏ£¬£¬£¬£¬£¬£¬£¬Ã¿¸öÖµ³ÇÊнøÐÐÒ»ÑùµÄ²é³¡£¡£¡£¡£¡£¡£¡£ÔÚstrcpy½«Öµ¸´Ôìµ½ÄÚ´æÖк󣬣¬£¬£¬£¬£¬£¬strlen¾Í»áÍÆËãÿ¸öÏîÖ÷Õų¤¶È£¬£¬£¬£¬£¬£¬£¬¶øºóstrcmp±ÈÁ¦Á½¸öÖµ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇËùÓв鳶¼Í¨¹ýµÄ»°£¬£¬£¬£¬£¬£¬£¬¾ÍÄܹ»³É¹¦µÇ½¡£¡£¡£¡£¡£¡£¡£
²é³³¤¶È
ÎÊÌâ¾ÍÔÚÓÚstrcpy¡£¡£¡£¡£¡£¡£¡£
strcpyʹÓúܳ£¼û
ʹÓÃC˵»°±à³ÌµÄ¿ª·¢ÈËÔ±ºÍ°²È«ÈËÔ±Çë°ÑÎÈ£ºstrcpyÆäʵÊÇÓиö¼«¶ÈΣÏյĺ¯Êý¡£¡£¡£¡£¡£¡£¡£ÍøÉÏÓÐÉÏǧƪÎÄÕÂÚ¹ÊÍΪʲô¸Ãº¯ÊýºÜΣÏÕ¡£¡£¡£¡£¡£¡£¡£ÏÂÃæµ¥Ò»¿´Ò»Ï£º
Ê×ÏÈ¿´Ò»Ï£¬£¬£¬£¬£¬£¬£¬Ôڳ߶ȵÄC˵»°ÖУ¬£¬£¬£¬£¬£¬£¬strcpy½ç˵ÈçÏ£º
Strcpyº¯Êý»á¸´Ôìs2Ö¸ÏòµÄ×Ö·û´®µ½s1Ö¸ÏòµÄÊý×éÖС£¡£¡£¡£¡£¡£¡£ÈôÊǸ´ÔìÔÚ½»²æµÄ¶ÔÏó¼ä²úÉú£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÇé¿öÊÇûÓÐÔ¤ÏȽç˵µÄ¡£¡£¡£¡£¡£¡£¡£Ò²¾ÍÊÇ˵¿ÉÄÜ»á²úÉúһЩÒâÁÏÖ®±íµÄʼþ¡£¡£¡£¡£¡£¡£¡£ÎªÊ²Ã´ËµstrcpyÓÐÍþÐ²ÄØ£¿£¿£¿£¿£¿£¿ÊÇÓÉÓÚËü»á¸´Ôìs2×Ö·û´®µ½s1Ö¸ÏòµÄÄÚ´æ¡£¡£¡£¡£¡£¡£¡£µ«ÊǸú¯Êý²»´«µÝ³¤¶È£¬£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇ˵strcpyº¯Êý²»¹ØÇÐ×Ö·û´®µÄ³¤¶È¡£¡£¡£¡£¡£¡£¡£¶ÔstrcpyÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬×Ö·û´®µÄ³¤¶ÈÒ»µãÒ²²»³ÁÒª¡£¡£¡£¡£¡£¡£¡£¸´ÔìµÄ¹ý³ÌÖпÉÄÜ»á²úÉú¸²Ð´µÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬¶ø¹¥»÷ÕßÒ²ÕýÊÇÀûÓÃÕâһDZÔÚ·ì϶ÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬£¬Äܹ»¸²Ð´Õ»ÄÚ±£ÁôµÄ·µ»ØÖ¸Õ룬£¬£¬£¬£¬£¬£¬¶øºó³Á¶¨Ïò¹ý³ÌµÄÖ´ÐÐÁ÷¡£¡£¡£¡£¡£¡£¡£
ÏÂͼÊÇÔÚʹÓÃstrcpyʱ¿ÉÄÜ»á²úÉúµÄÇé¿ö£º
A segfault
ÔÚ·¢ËÍÏÂÃæµÄÒªÇó¸øRV130ʱ²úÉúµÄÇé¿ö¾ÍºÍÉÏÃæÒ»Ñù£º
Õ»Öб£ÁôµÄ·µ»ØÖ¸Õë±»¡°ZZZZ¡±¸²Ð´ÁË£¬£¬£¬£¬£¬£¬£¬Òò¶øÖ´ÐÐÁ÷»á±»³Á¶¨Ïòµ½0x5A5A5A5A¡£¡£¡£¡£¡£¡£¡£
×êÑÐÈËÔ±½¨ÒéʹÓÃstrlcpyº¯Êý£¬£¬£¬£¬£¬£¬£¬strlcpyÊÇC˵»°³ß¶È¿âº¯Êý£¬£¬£¬£¬£¬£¬£¬ÊÇÔ½·¢°²È«°æ±¾µÄstrcpyº¯Êý£¬£¬£¬£¬£¬£¬£¬ÔÚÒÑÖªÖ÷ÕŵØÖ·¿Õ¼ä´óÓ×µÄÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬°Ñ´ÓsrcµØÖ·ÆðÍ·ÇÒº¬ÓÐ'\0'ʵÏÖ·ûµÄ×Ö·û´®¸´Ôìµ½ÒÔdestÆðÍ·µÄµØÖ·¿Õ¼ä,²¢²»»áÔì³É»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
˼¿ÆÖ®Ç°ÒѰ䲼²¹¶¡£¬£¬£¬£¬£¬£¬£¬µ«ÊÇ·¢ÏÖ²¹¶¡Ê§Ð§£¬£¬£¬£¬£¬£¬£¬ ÇëÇ×êǹØ×¢¹ÙÍø¸üС£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex#fr
https://www.pentestpartners.com/security-blog/cisco-rv130-its-2019-but-yet-strcpy/


¾©¹«Íø°²±¸11010802024551ºÅ