4 ms·
Background on the underlying context of the bug: https://www.youtube.com/watch?v=-vpGswuYVg8 https://www.youtube.com/watch?v=-vpGswuYVg8 -- It's objectively unf
by smitelli 2y ago
Background on the underlying context of the bug: https://www.youtube.com/watch?v=-vpGswuYVg8 https://www.youtube.com/watch?v=-vpGswuYVg8 -- It's objectively unforgivable.
- amiga386 2y agoTL;DW: Call GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27 account_mgr.cgi is safe, it takes web parameters "name", "pw" and calls the equivalent of execlp(..., "account", "-u", name, "-p", pw); "account" was written by the intern and runs sprintf(buf, "adduser \"%s\" -p \"%s\" >/dev/null", opt_u, opt_p); system(buf);
- jasonladuke0311 2y agoThat’s insane.
- rstuart4133 2y agoIt's also wrong. If the C code presented is accurate the URL would have to contain &name=%22;shell-command-to-run;%22, or perhaps &name=$(shell-command-to-run). name=%27;shell-command-to-run%27 is mostly harmless. That's nit-picky I know, but when some dude on the internet is trying to get clicks via manufactured rage at incompetent programmers, it's kinda ironic his code is buggy too.
- amiga386 2y agoDon't shoot the messenger. This is from the people who discovered it: https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07 https://netsecfish.notion.site/Command-Injection-Vulnerabili... > The vulnerability is localized to the account_mgr.cgi script, particularly in the handling of the cgi_user_add command. The name parameter in this script does not adequately sanitize input, allowing for command execution. > /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27 I know, I know, that would mean the exact command run, based on the reversed code shown on screen at https://youtu.be/-vpGswuYVg8?t=656 https://youtu.be/-vpGswuYVg8?t=656 would be adduser -u "';<INJECTED_SHELL_COMMAND>;'" -p "" >/dev/null which would be harmless, so clearly if the PoC says %27 then the real format string must be more like "adduser -u '%s' ...". Maybe the Youtuber reversed the wrong firmware. But nonetheless, the point is gotten across.
- zahlman 2y agoNever mind the actual mistake "the intern" made. Not only was "the intern" tapped to write code that accepts user input from HTTP and also use system administration shell commands - and use C to do raw string handling, for that matter; who knows if `buf` is properly allocated? - but there was either no review/oversight or nobody saw the problem. Plus there are two layers of invoking a new program where surely one would suffice; and it's obviously done in a different way each time. Even programmers who have never used Linux and know nothing about its shells or core utilities, should be raising an eyebrow at that. Meanwhile, people want to use AI to generate boilerplate so that their own company's "the intern" can feel like a "10x developer" (or managers can delude themselves that they found one).