Software And Internet Blog





March 24, 2008

Bug - Buffer-overflow in ASUS Remote Console 2.0.0.24

Filed under: System Security

Luigi Auriemma

Application: ASUS Remote Console
http://www.asus.com/999/html/share/9/icon/9/index.htm#asmb3
Versions: <= 2.0.0.24
Platforms: Windows
Bug: buffer overflow
Exploitation: remote
Date: 21 Mar 2008
Author: Luigi Auriemma
e-mail: aluigi (at) autistici (dot) org [email concealed]
web: aluigi.org

1) Introduction
2) Bug
3) The Code
4) Fix

#######################################################################

===============
1) Introduction
===============

From the manual:
“The ASUS Remote Console (ARC) is an efficient and flexible application
that allows monitoring and control of the remote host.”

The main component of this service is a telnet server listening on port
623 which is called DpcProxy and provides an IPMI interface.

======
2) Bug
======

The DPC Proxy is affected by a buffer-overflow vulnerability located in
the function which gets the data received from the client, stores them
in a stack buffer of about 1024 bytes and checks the presence of an end
of line delimiter (carriage return).

===========
3) The Code
===========

http://aluigi.org/poc/asuxdpc.txt

nc SERVER 623 -v -v -w 2 < asuxdpc.txt

======
4) Fix
======

No fix


Luigi Auriemma
http://aluigi.org

Comments »

The URI to TrackBack this entry is: http://blackraptor.blogsome.com/2008/03/24/bug-buffer-overflow-in-asus-remote-console-20024/trackback/

No comments yet.

RSS feed for comments on this post.

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>



Anti-spam measure: please retype the above text into the box provided.








Get free blog up and running in minutes with Blogsome
Theme designed by B A Khan