QNAP NAS/NVR Administrator Hash Disclosure...

- AV AC AU C I A
发布: 2024-08-31
修订: 2024-12-11

This Metasploit module exploits combined heap and stack buffer overflows for QNAP NAS and NVR devices to dump the admin (root) shadow hash from memory via an overwrite of __libc_argv[0] in the HTTP-header-bound glibc backtrace. A binary search is performed to find the correct offset for the BOFs. Since the server forks, blind remote exploitation is possible, provided the heap does not have ASLR.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息