The Shadow File

My notes on technology, security, and personal projects

Thursday, April 30, 2015

Broken, Abandoned, and Forgotten Code, Part 2

›
In the part 1 , I showed how the Netgear R6200's upnpd binary contains what appears to be a hidden SOAP action related to the string ...
Thursday, April 23, 2015

Broken, Abandoned, and Forgotten Code, Part 1

›
Introduction This series of posts describes how abandoned, partially implemented functionality can be exploited to gain complete, persiste...
Wednesday, April 22, 2015

Broken, Abandoned, and Forgotten Code: Prologue

›
A Secret Passage to Persistant SOHO Router Pwnage Almost two years ago plus a house selling, a cross-country move, a house buying, a job...
Friday, February 20, 2015

Bowcaster Feature: multipart/form-data

›
Need to reverse engineer or exploit a file upload vulnerability in an embedded web server? I added a multipart/form-data class to Bowcaster...
Saturday, January 31, 2015

Patching, Emulating, and Debugging a Netgear Embedded Web Server

›
Previously I posted about running and remotely debugging a Netgear UPnP daemon using QEMU and IDA Pro. This time we’ll take on the challeng...
Saturday, January 03, 2015

Remote Debugging with QEMU and IDA Pro

›
It's often the case, when analyzing an embedded device's firmware, that static analysis isn't enough. You need to actually execu...
Tuesday, September 23, 2014

Exploit Tunneling and Callback

›
A few years ago, when I worked for my previous employer, I put together a proof-of-concept that was to be part of a client demo. I thought i...
Friday, May 16, 2014

Infiltrate 2014

›
Here are some additional resources I may have mentioned in my Infiltrate 2014 presentation. White Paper:  SQL Injection to MIPS Overflows ...
Monday, December 30, 2013

Emulating and Debugging Workspace

›
A grad student emailed me in response to my Netgear auth bypass post .  He's working on a research project and wanted to know if I knew...
Saturday, December 07, 2013

BayThreat 2013 Presentation - Additional Resources

›
For my presentation at BayThreat, entitled "BT Wireless Routers: Adventures in Reversing and Exploiting", rather than have one or ...
Thursday, October 24, 2013

Netgear Root Compromise via Command Injection

›
At the end of my post on the Netgear wndr3700v4's authentication bugs, I said to expect followup posts. Once the web interface is unloc...
‹
›
Home
View web version
Powered by Blogger.