Tuesday, June 2, 2020

Router-Exploit-Shovel: An Automated Application Generator For Stack Overflow Types On Wireless Routers

About Router-Exploit-Shovel
   Router-Exploit-Shovel is an automated application generation for Stack Overflow types on Wireless Routers.

   Router exploits shovel is an automated application generation tool for stack overflow types on wireless routers. The tool implements the key functions of exploits, it can adapt to the length of the data padding on the stack, generate the ROP chain, generate the encoded shellcode, and finally assemble them into a complete attack code. The user only needs to attach the attack code to the overflow location of the POC to complete the Exploit of the remote code execution.

   The tool supports MIPSel and MIPSeb.Run on Ubuntu 16.04 64bit.

Router-Exploit-Shovel's Installation
   Open your Terminal and enter these commands:
Usage

   Example: python3 Router_Exploit_Shovel.py -b test_binaries/mipseb-httpd -l test_binaries/libuClibc-0.9.30.so -o 0x00478584

Router-Exploit-Shovel's screenshot

Code structure

ROP chain generation
   This tool uses pattern to generate ROP chains. Extract patterns from common ROP exploitation procedure. Use regex matching to find available gadgets to fill up chain strings. Base64 encoding is to avoid duplicate character escapes. For example:

Attackblocks
   You can get attackblocks generated in results/attackBlocks.txt. Such as:

You might like these similar tools:
Continue reading
  1. Hacking The System
  2. Pentest Windows
  3. Pentest Linux
  4. Pentest Gear
  5. Pentest Hardware
  6. Pentest Partners
  7. Pentest
  8. Pentestbox
  9. Hacking
  10. Pentest Network
  11. Pentest Firewall
  12. Hacking Lab
  13. Hacker0Ne
  14. How To Pentest A Network
  15. Hacking With Linux
  16. Pentest Process
  17. Hacker Prank
  18. Pentest Companies
  19. Hacking Tutorials

No comments:

Post a Comment