当前位置:首页 > 报告详情

当(远程)Shell落入同样的陷阱:在攻击者再次得手之前获取DrayTek路由器的root权限.pdf

上传人: 竿*** 编号:981565 2025-11-29 41页 3.47MB

1、#BHEU BlackHatEventsWhen(Remote)Shells Fall Into The Same Hole:When(Remote)Shells Fall Into The Same Hole:Rooting DrayTekRouters Before Attackers Can Do It AgainStanislav Dashevskyi,Francesco La Spina#BHEU BlackHatEventsInformation Classification:GeneralThe researchersStanislav DashevskyiFrancesco L

2、a SpinaPART 1Motivation and Background#BHEU BlackHatEventsInformation Classification:GeneralIts rough around the edges4 Last year we did research on Sierra Wireless gateways and found critical vulnerabilities We also looked at firmware of five different IoT/OT edge routers and it did not look good l

3、ack of binary hardening,outdated software components,known vulnerabilities,“custom”security patches,default credentials Edge devices serve the threat actors as perfect entry points into businesses*https:/ are hereEdge Router#BHEU BlackHatEventsInformation Classification:GeneralIts rough around the e

4、dges(continued)5 We have chosen a vendor,a seemingly bullet-proof target with lots of past research-DrayTek 4 years of active patching and frequent security advisories With proven interest from threat actors Remote unauthenticated root on the host OS via a trivial buffer overflow in the guest And it

5、 took us about a month to do it*https:/ are hereEdge Router#BHEU BlackHatEventsInformation Classification:GeneralWhats DrayTek?A well-known Taiwanese manufacturer of networking equipment and management systems(founded in 1997)From simple SOHO routers to complex VPN concentrators used by businesses6#

6、BHEU BlackHatEventsInformation Classification:GeneralWhy DrayTek?Researchers like it7 13 security advisories since 2018(excluding ours)with over 100 historical CVEs Typically,a sign of a mature security team.Yet,new findings keep popping up Emulate it until you make it!Pwning a DrayTek Router before

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据报告的内容,全文主要内容概括如下: - 研究人员发现DrayTek路由器存在多个安全漏洞,包括弱加密、凭证重用、缓冲区溢出等。 - DrayTek路由器被多个威胁行为者针对,存在大量暴露的设备。 - 研究人员发现WebUI存在缓冲区溢出漏洞(CVE-2024-41592),可导致远程执行代码。 - 研究人员还发现命令注入漏洞(CVE-2024-41585),可逃逸虚拟机并执行任意命令。 - DrayTek迅速发布了补丁,但研究人员对补丁的全面性表示怀疑。 - 研究人员建议资产所有者定期更新设备,进行安全评估,并不要过度依赖历史CVE数量来评估供应商的安全立场。 - 研究人员建议供应商加强安全措施,包括使用静态分析工具、进行代码审计、进行渗透测试,并考虑对软件进行重设计。
"DrayTek路由器漏洞揭秘" "如何安全使用DrayTek路由器?" DrayTek漏洞警示"
客服
商务合作
小程序
服务号
折叠