返回顶部
返回首页 会员充值 我的足迹 返回上一页
跳转三个皮匠报告小程序

当(远程)Shell落入同样的陷阱:在攻击者再次得手之前获取DrayTek路由器的root权限.pdf

2025-11-29
文档编号:981565
文档页数:41
文档大小:3.47MB
下载积分:VIP专享
文档格式:PDF

1、#BHEU BlackHatEventsWhen(Remote)Shells Fall Into The Same Hole:When(Remote)Shells Fall Into The Same Hole:Rooting DrayTekRouters Before Attackers Can Do It AgainStanislav Dashevskyi,Francesco La Spina#BHEU BlackHatEventsInformation Classification:GeneralThe researchersStanislav DashevskyiFrancesco L

2、a SpinaPART 1Motivation and Background#BHEU BlackHatEventsInformation Classification:GeneralIts rough around the edges4 Last year we did research on Sierra Wireless gateways and found critical vulnerabilities We also looked at firmware of five different IoT/OT edge routers and it did not look good l

3、ack of binary hardening,outdated software components,known vulnerabilities,“custom”security patches,default credentials Edge devices serve the threat actors as perfect entry points into businesses*https:/ are hereEdge Router#BHEU BlackHatEventsInformation Classification:GeneralIts rough around the e

4、dges(continued)5 We have chosen a vendor,a seemingly bullet-proof target with lots of past research-DrayTek 4 years of active patching and frequent security advisories With proven interest from threat actors Remote unauthenticated root on the host OS via a trivial buffer overflow in the guest And it

5、 took us about a month to do it*https:/ are hereEdge Router#BHEU BlackHatEventsInformation Classification:GeneralWhats DrayTek?A well-known Taiwanese manufacturer of networking equipment and management systems(founded in 1997)From simple SOHO routers to complex VPN concentrators used by businesses6#

6、BHEU BlackHatEventsInformation Classification:GeneralWhy DrayTek?Researchers like it7 13 security advisories since 2018(excluding ours)with over 100 historical CVEs Typically,a sign of a mature security team.Yet,new findings keep popping up Emulate it until you make it!Pwning a DrayTek Router before

当(远程)Shell落入同样的陷阱:在攻击者再次得手之前获取DrayTek路由器的root权限.pdf_第1页
当(远程)Shell落入同样的陷阱:在攻击者再次得手之前获取DrayTek路由器的root权限.pdf_第2页
当(远程)Shell落入同样的陷阱:在攻击者再次得手之前获取DrayTek路由器的root权限.pdf_第3页
当(远程)Shell落入同样的陷阱:在攻击者再次得手之前获取DrayTek路由器的root权限.pdf_第4页
当(远程)Shell落入同样的陷阱:在攻击者再次得手之前获取DrayTek路由器的root权限.pdf_第5页

点击查看更多