Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
miniupnpd_poc — PoC чтения за пределами буфера для miniupnpd <= v2.1 | Kitploit
Инструменты/GitHubGitHub/b1ack0wl/miniupnpd_poc
Безопасность встроенных системБезопасность IoTАнализ уязвимостейЭксплуатацияЭксфильтрация данныхЭксплуатация Бинарных Файлов
GitHubb1ack0wl/miniupnpd_poc

miniupnpd_poc

PoC чтения за пределами буфера для miniupnpd <= v2.1

Репозиторий
2187 лет назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

Miniupnpd <=v2.1 уязвимость чтения за пределами выделенной памяти (PoC)

  • Данная уязвимость была исправлена в основной ветке miniupnpd (https://github.com/miniupnp/miniupnp/commit/bec6ccec63cadc95655721bc0e1dd49dac759d94).
  • Уязвимость активируется при отправке запроса SUBSCRIBE с callback uri obj->path, длина которого превышает 526 байт.
  • Основная причина заключается в отсутствии проверки возвращаемого значения snprintf(), так как snprintf() возвращает количество байт, которые могли бы быть скопированы, а не фактически скопированные байты.
  • По состоянию на 25 января 2019 года PoC из этого репозитория успешно протестирован против Google Wifi.
    • Прочие устройства, использующие miniupnpd, также могут быть уязвимы.

Первопричина (upnpevents.c)

root@kitploit:~
static void upnp_event_prepare(struct upnp_event_notify * obj)
{

	obj->buffersize = 1024; /* Static Buffer Size */
	obj->buffer = malloc(obj->buffersize);
	[...]
	obj->tosend = snprintf(obj->buffer, obj->buffersize, notifymsg,
	                       obj->path, obj->addrstr, obj->portstr, l+2,
	                       obj->sub->uuid, obj->sub->seq,
	                       l, xml);
	obj->state = ESending;

static void upnp_event_send(struct upnp_event_notify * obj)
{
	int i;
	i = send(obj->s, obj->buffer + obj->sent, obj->tosend - obj->sent, 0);

Запись в man-странице для snprintf()

root@kitploit:~
RETURN VALUE

Upon successful return, functions return the number of characters printed 
(excluding the null byte used to end output to strings).

The functions snprintf() and vsnprintf() do not write more than size bytes 
(including the terminating  null byte ('\0')).  If the output was truncated 
due to this limit, then the return value is the number of characters 
(excluding the terminating null byte) which would have been written to the 
final string if enough space had been available. Thus, a return value of size 
or more means that the output was truncated.

Использование

root@kitploit:~
usage: miniupnpd_poc.py [-h] [--callback_ip CALLBACK_IP]
                        [--callback_port CALLBACK_PORT] [--timeout TIMEOUT]
                        [--leak_amount LEAK_AMOUNT]
                        target_ip target_port

Miniupnpd <= v2.1 read out-of-bounds vulnerability

positional arguments:
  target_ip             IP address of vulnerable device.
  target_port           Target Port.

optional arguments:
  -h, --help            show this help message and exit
  --callback_ip CALLBACK_IP
                        Local IP address for httpd listener. (default: None)
  --callback_port CALLBACK_PORT
                        Local port for httpd listener. (default: None)
  --timeout TIMEOUT     Timeout for http requests (seconds). (default: 5)
  --leak_amount LEAK_AMOUNT
                        Amount of arbitrary heap data to leak (in Kb).
                        (default: 1)

Видео

asciicast

  • 0wl
Скачать инструмент