Directory Traversal #define: Directory Traversal is a form of attack where an attacker can access files and directories outside of the intended directory
26
Testing for Directory Traversal
27
Directory Traversal - Vulnerable Code ?php
28
Directory Traversal Countermeasures
29
Directory Traversal Demo
30
Testing for Buffer Overflows
31
Buffer Overflow - Vulnerable Code
32
Buffer Overflow Countermeasures
33
MIPS Architecture
34
ASUS RT-AC66U ROP Chain
35
MIPS Shellcode (RT-AC66U Exploit)
36
LIVE DEMO
Description:
Explore the critical security vulnerabilities in SOHO routers in this comprehensive DerbyCon 3.0 conference talk. Delve into the implications of pervasive vulnerabilities, examining various SOHO router products and the associated security risks. Learn about testing methodologies, including information gathering, scanning, and enumeration techniques. Analyze web applications, servers, and conduct static code analysis and fuzzing. Gain insights into reverse engineering tools and techniques, exploit development, and testing for cross-site request forgery and command injection. Discover directory traversal attacks, buffer overflows, and MIPS architecture specifics. Witness live demonstrations of vulnerabilities and exploits, including an ASUS RT-AC66U ROP chain and MIPS shellcode exploit.
So Hopelessly Broken - The Implications of Pervasive Vulnerabilities in SOHO Routers