一款利用内存转储漏洞(CVE-2018-17240)从 Netwave IP 摄像头中获取登录凭据的工具。本项目受 expcamera 启发,并在性能和效率上有所改进。该工具适用于所有平台,因为它不像 expcamera 那样通过 shell 命令调用任何 Linux CLI 工具。
在 Linux 系统上,/proc/kcore 是一个虚拟文件,将系统内存以 ELF core 映像的形式暴露出来。这些摄像头在无 MMU 的 ARM7 核心上运行 uClinux,因此只有一个平坦的地址空间——转储内容既包含摄像头应用程序的内存,也包含内核的内存,其中包括它保存在全局变量中的配置数据块。
该文件之所以可被访问,是因为 Web 服务器存在未认证的任意文件读取漏洞:请求处理程序仅剥离一个前导斜杠,并在没有任何路径遍历过滤的情况下调用 fopen(),以 root 身份返回结果。因此 //proc/kcore 会解析为 /proc/kcore,这就是请求路径带有前导双斜杠的原因。
配置数据块具有固定的布局,因此可以直接从中读取凭据:
| 偏移量 | 字段 |
|---|---|
0x00 | uint32 魔数,始终为 0x440C9ABD |
0x04 | uint32 校验和 |
0x08 | uint32 长度 |
0x0C | char device_id[13] 12 个大写十六进制字符加一个 NUL |
0x36 | struct { char name[13]; char pwd[13]; uint8 pri; } users[8] |
该工具会流式读取 /proc/kcore,并在每个数据块中搜索该魔数。一旦找到,它就会从用户表中返回权限最高的账户。
该工具支持两种不同的方式来指定要检查漏洞的主机。主机必须采用 ip:port 格式。
| 参数 | 描述 |
|---|---|
--host | 要检查的主机,可多次指定 |
--file | 包含要检查的主机列表的文件 |
该工具支持从 Censys、Shodan 和 ZoomEye 获取主机以检查漏洞。
| IoT 搜索引擎 | 参数 | 必需的环境变量 |
|---|---|---|
| Censys | --censys | CENSYS_PERSONAL_ACCESS_TOKEN |
| Shodan | --shodan | SHODAN_API_KEY |
| ZoomEye | --zoomeye | ZOOMEYE_API_KEY |
Censys 使用 Platform API。在 platform.censys.io 创建个人访问令牌;同时设置 CENSYS_ORGANIZATION_ID,以便将搜索费用计入组织账户而非你的免费钱包。请注意,Platform 搜索端点需要付费计划,因为免费账户仅限于查询端点。
$ pip install -r requirements.txt
Usage: main.py [-h] (--host HOST | -f FILE | --censys | --shodan | --zoomeye) [-n NUMBER] [-c CONCURRENT] [-t TIMEOUT] [-o OUTPUT]
A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)
Options:
-h, --help show this help message and exit
--host HOST A host to check, can be specified multiple times
-f, --file FILE A file containing the hosts to check
--censys Retrieve hosts from the Censys Platform API using the personal access token specified with the CENSYS_PERSONAL_ACCESS_TOKEN environment variable
--shodan Retrieve hosts from the Shodan API using the API key specified with the SHODAN_API_KEY environment variable
--zoomeye Retrieve hosts from the ZoomEye API using the API key specified with the ZOOMEYE_API_KEY environment variable
-n, --number NUMBER The number of hosts to retrieve from the IoT search engine, by default 100
-c, --concurrent CONCURRENT
The number of hosts to check concurrently, by default 25
-t, --timeout TIMEOUT
The timeout in seconds for retrieving the credentials from the memory dump of each host, by default 300
-o, --output OUTPUT The file to write the credentials to, by default credentials.txt
本工具仅供教育目的使用。本项目的贡献者不对因使用本工具而可能产生的任何损害或法律问题承担责任。使用风险自负。