Part 5 is up. In this and the next several parts we start analyzing the structure of Netgear R6200 firmware updates. We switch over to the HTTP daemon because it's less broken and a little easier to analyze than upnpd. The overall goal is to reverse engineer the firmware format so we can generate a malicious firmware image to use when exploiting the SetFirmware SOAP action described in parts 1-4. Binary patching, emulating with QEMU, and debugging with IDA Pro are recommended for the next several installments. Here is some recommended reading to help get that set up: - Remote Debugging with QEMU and IDA Pro http://ift.tt/1AIcSPm - Patching, Emulating, and Debugging a Netgear Embedded Web Server http://ift.tt/1CY9qA4 If you missed my post to Full Disclosure where I introduced the series, here's that: http://ift.tt/1F6IUWA As always I welcome feedback via email or Twitter. I'm @zcutlip. I hope you enjoy it. Cheers! Zach
Source: Gmail -> IFTTT-> Blogger
No comments:
Post a Comment