2014-01-09 19:25:28 +00:00
|
|
|
##
|
2017-07-24 13:26:21 +00:00
|
|
|
# This module requires Metasploit: https://metasploit.com/download
|
2014-01-09 19:25:28 +00:00
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
|
|
|
##
|
|
|
|
|
2016-03-08 13:02:44 +00:00
|
|
|
class MetasploitModule < Msf::Auxiliary
|
2014-01-09 19:25:28 +00:00
|
|
|
include Msf::Exploit::Remote::Tcp
|
|
|
|
include Msf::Auxiliary::Scanner
|
2014-01-13 19:53:47 +00:00
|
|
|
include Msf::Auxiliary::Report
|
2014-01-09 19:25:28 +00:00
|
|
|
|
|
|
|
def initialize(info={})
|
|
|
|
super(update_info(info,
|
|
|
|
'Name' => 'SerComm Network Device Backdoor Detection',
|
|
|
|
'Description' => %q{
|
|
|
|
This module can identify SerComm manufactured network devices which
|
|
|
|
contain a backdoor, allowing command injection or account disclosure.
|
|
|
|
},
|
2014-01-09 19:33:54 +00:00
|
|
|
'Author' =>
|
|
|
|
[
|
|
|
|
'Eloi Vanderbeken <eloi.vanderbeken[at]gmail.com>', # Initial discovery, poc
|
|
|
|
'Matt "hostess" Andreko <mandreko[at]accuvant.com>' # Msf module
|
|
|
|
],
|
|
|
|
'License' => MSF_LICENSE,
|
|
|
|
'References' =>
|
|
|
|
[
|
2017-06-05 21:25:02 +00:00
|
|
|
[ 'CVE', '2014-0659' ],
|
2016-07-15 17:00:31 +00:00
|
|
|
[ 'OSVDB', '101653' ],
|
2014-01-09 19:33:54 +00:00
|
|
|
[ 'URL', 'https://github.com/elvanderb/TCP-32764' ]
|
|
|
|
],
|
|
|
|
'DisclosureDate' => "Dec 31 2013" ))
|
2014-01-09 19:25:28 +00:00
|
|
|
|
|
|
|
register_options([
|
|
|
|
Opt::RPORT(32764)
|
|
|
|
])
|
|
|
|
end
|
|
|
|
|
2014-01-13 19:53:47 +00:00
|
|
|
def do_report(ip, endianess)
|
|
|
|
report_vuln({
|
|
|
|
:host => ip,
|
|
|
|
:port => rport,
|
|
|
|
:name => "SerComm Network Device Backdoor",
|
|
|
|
:refs => self.references,
|
|
|
|
:info => "SerComm Network Device Backdoor found on a #{endianess} device"
|
|
|
|
})
|
|
|
|
end
|
2014-01-09 19:25:28 +00:00
|
|
|
|
2014-01-13 19:53:47 +00:00
|
|
|
def run_host(ip)
|
2014-01-09 19:25:28 +00:00
|
|
|
begin
|
|
|
|
connect
|
|
|
|
sock.put(Rex::Text.rand_text(5))
|
|
|
|
res = sock.get_once
|
|
|
|
disconnect
|
|
|
|
|
|
|
|
if (res && res.start_with?("MMcS"))
|
|
|
|
print_good("#{ip}:#{rport} - Possible backdoor detected - Big Endian")
|
2014-01-13 19:53:47 +00:00
|
|
|
do_report(ip, "Big Endian")
|
2014-01-09 19:25:28 +00:00
|
|
|
elsif (res && res.start_with?("ScMM"))
|
|
|
|
print_good("#{ip}:#{rport} - Possible backdoor detected - Little Endian")
|
2014-01-13 19:53:47 +00:00
|
|
|
do_report(ip, "Little Endian")
|
2014-01-09 19:25:28 +00:00
|
|
|
else
|
2014-01-13 19:53:47 +00:00
|
|
|
vprint_status("#{ip}:#{rport} - Backdoor not detected.")
|
2014-01-09 19:25:28 +00:00
|
|
|
end
|
|
|
|
rescue Rex::ConnectionError => e
|
2017-07-19 11:48:52 +00:00
|
|
|
vprint_error("#{ip}:#{rport} - Connection failed: #{e.class}: #{e}")
|
2014-01-09 19:25:28 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|