|
本帖最后由 adsluser11 于 2022-9-10 23:16 编辑
* f. A( Y3 {; w5 P1 R( m" u* i
) h( P( B/ L' K2 X进了telnet,把闪存备份了出来,本着技术共享的原则,发出来给大家研究,看看有什么漏洞可以利用没4 t) z# B; ?6 c2 X0 @6 f
( _% r P$ S6 P, s
# A# L! n9 b# Z* Vrootfs分区是jffs2格式,我在debian下挂在出来然后打包,方便大家直接研究: M: G2 @7 }9 w
/ r# S A2 D$ X8 z4 F2 G" `" o
有几个包含个人信息的无关紧要的分区我就没包含进去了,两个kernel分区是一模一样的,就只传了一个,userconfig目录在删除了个人配置后上传
. E4 j" Y" A7 N8 B0 x0 N; X1 d" J欢迎各位大神研究讨论,打倒奸商
+ ^( J) D# U; J" g) O+ |0 A+ L0 @; c+ B T
( h r8 t5 l; ^; b! @) z& V7 f! }, c$ N$ [
+ L! k3 Q* Z( r
/ C2 L" T& f0 E) Y1 n- J2 V
. [* @8 m( u9 A# \4 q8 R
, H8 X* I7 D- B+ t2 Z' Q- <blockquote>/ # cat /proc/version
复制代码
7 g' ?2 r' q2 @& n0 {4 f6 r p( [' t
- / # cat /proc/mtd
( Y; z+ M4 M$ q: t - dev: size erasesize name8 p2 ]& B4 Y/ I
- mtd0: 10000000 00020000 "whole flash"
; l' B6 @, |4 X3 G - mtd1: 00200000 00020000 "u-boot"9 w# M* w6 n3 i5 _2 \- b2 u
- mtd2: 00200000 00020000 "others"
4 x3 a4 _4 r" Z# ^2 P - mtd3: 00200000 00020000 "parameter tags"
# U" }! H5 v7 h- ~7 m - mtd4: 00200000 00020000 "wlan"% e6 E2 U3 p+ K3 R0 E* O$ o
- mtd5: 00800000 00020000 "usercfg", @& j0 T, C: d* Y* Y) u
- mtd6: 00600000 00020000 "middle"
- ]' M: m$ ^: S5 E - mtd7: 02800000 00020000 "kernel1"/ `8 r t( n K
- mtd8: 02800000 00020000 "kernel2"
0 |9 R/ t! p2 y - mtd9: 03200000 00020000 "osgi1"( |$ i& N% @7 Y G
- mtd10: 03200000 00020000 "osgi2"
7 h; F6 q* n& n' Z) r5 J7 q( s5 \ - mtd11: 03600000 00020000 "plugin_data"% X* o7 @2 C* r& Q" Y
- mtd12: 024e0000 00020000 "rootfs"
复制代码- mount7 R" U& x F/ m- [9 ~7 g
- /dev/root on / type jffs2 (ro,relatime)! ?$ g: p! b$ G4 l2 U. u1 D
- proc on /proc type proc (rw,nosuid,relatime)
$ `- @# W* _8 z$ g3 b8 R - sysfs on /sys type sysfs (rw,nosuid,relatime)9 ?" z) z( t3 a! J7 [+ z
- debugfs on /sys/kernel/debug type debugfs (rw,nosuid,relatime)
& i. }6 Y2 B, y - /dev/mtdblock3 on /tagparam type jffs2 (rw,relatime)2 |$ s- `0 L! z2 w
- tmpfs on /var type tmpfs (rw,relatime,size=20480k)
9 l; j7 l$ Y$ [/ Q - tmpfs on /upgtempfile type tmpfs (rw,relatime,size=102400k)
" v I, N% y6 _1 Y6 l - tmpfs on /var/osstmp type tmpfs (rw,relatime,size=2048k)
- P4 p1 r2 ?( P, `; ] l) h; } - tmpfs on /mnt type tmpfs (rw,relatime,size=2048k)
% Q6 Y8 d m6 i8 Z- U/ X - tmpfs on /var/felix-temp type tmpfs (rw,relatime,size=16384k)
1 l# j1 ?! O% _2 c - tmpfs on /tmp type tmpfs (rw,relatime,size=15360k)
8 ^' ]( {! E" s - /dev/mtdblock5 on /userconfig type jffs2 (rw,relatime)
: V. U. V: p, x& ?$ H# |0 s - /dev/mtdblock6 on /usr/local/ct type jffs2 (rw,relatime)
$ F! t! Q) Q; ~- D1 n - ubi0_0 on /usr/tmp type ubifs (ro,sync,relatime)/ D, c! O- o7 w+ T/ P, a
- /dev/loop0 on /usr/java type squashfs (ro,relatime)
4 L! R4 F2 {& F - ubi1_0 on /usr/plugin type ubifs (rw,sync,relatime)" y! P% a+ i9 f: U+ D4 N
- /dev/mtdblock4 on /wlan type jffs2 (rw,relatime)9 ?/ J4 b3 T4 D+ H4 U o1 a
- cgroup_root on /sys/fs/cgroup type tmpfs (rw,relatime)+ I# l2 X# v( h; M2 `; W
- cpu on /sys/fs/cgroup/cpu type cgroup (rw,relatime,cpu)
. c2 C' |' s, t! l* v - cpuacct on /sys/fs/cgroup/cpuacct type cgroup (rw,relatime,cpuacct)
3 H& L* X! g" P9 L: |0 c5 s8 U; u. ?! j - cpuset on /sys/fs/cgroup/cpuset type cgroup (rw,relatime,cpuset)
9 e1 U* u \: ^* x' z0 G - memory on /sys/fs/cgroup/memory type cgroup (rw,relatime,memory)
) P8 K0 w6 s% Z, `1 J! E$ a - /dev/sda on /mnt/usb1_1 type fuseblk (rw,relatime,user_id=0,group_id=0,allow_other,blksize=4096)
复制代码- /usr/java/bin # ls /bin
" ]5 N( U! f- E" b5 X- | - ash gpon_omci netstat sleep+ B# h; b, u g$ o) a
- bndmange gpontest nice smbd8 s0 e# v% G. k+ B$ [; f/ c+ B
- bobtest grep nmbd smbpasswd/ m. G* n1 y K
- brctl gunzip ntfs-3g switchtst0 O) Z+ U/ m* |6 @6 p
- buservice gzip oamtest sync
; {# `: Q3 V$ b# s - busybox hostname openl2tpd tar
7 N- l$ ]. ?9 i/ A3 D+ B f- I+ j - cat httpd opticaltst tc
" H) U5 j# k: N8 a- x. ^ - chgrp igmp_proxy osgid tcping. }* Y' y" H" }$ \
- chmod ip p910nd telnetd! i5 {) n v+ X) E9 d/ u
- chown ip6tables pc test_minioltlib
5 T) M$ ]' U4 \, y4 A* k - cmapidbg ipsec phddns testftp- V! }" t1 r6 |. z. f
- cp iptables ping touch8 s8 A& o) h8 D
- cpio ipv4protocol ping6 tr069d
7 H1 u3 V2 \9 s3 m - cspd ipv6protocol portmap traceroute1* T. Y$ `3 E$ M$ v
- ctsgw_proxyd kill pppd tso
6 D# `: T6 v& Y; A - date kshell pppoe-server umount
' m2 W# M6 g- K7 I. h' G - dd l2tpconfig ps uname/ K* B; `/ ^7 ]& ~2 P% v7 i, Q+ ~0 g
- devmem2 ln pwd upgradetest) l l' P e( c+ q m4 y
- df login redir upnpd. q8 c% G" ?4 ?
- dipc logtousb rm usbtest3 p$ C8 m: P6 _4 m _" d
- dmesg ls rmdir usbtool
! k1 K7 ?# K+ j2 I f+ h2 ^ - dnsdomainname lzop routed voip
1 ^% K# V3 n5 i1 T - dnsmasq memtest rpm voipstat: e2 X: Q, t5 {% I) G- A& ^5 s. u+ p
- ebtables minioltdebug sdtest vsftpd
p5 ?3 u3 t0 X1 u$ ~0 o( @2 J1 ` - echo mkdir sed wbctl
( c- v# @% G: t( v - egrep mknod sendcmd wgets
0 U; \! p! W& n& t: g0 C - epontest mld_proxy setmac wput
( T* n+ q @3 m' ^4 u - ethdriver_test mount sh wput_ftp4 z# `! t: Y8 u$ n1 r1 F
- fgrep msntp shellproxy wput_tftp
6 i, t. }6 G; |% x, s - fpga multiapd shellproxy_getty xpondrvARM32.bin1 J! C5 R! M# Q* H
- ftest multicast_test shellproxyctrl z3gateway7 ~ v3 \7 t& p4 m8 S1 W
- fw_flashing mv simulation zcat- c1 ^ A8 n' H) t1 l- C
- getopt nand slctool zxspdtest. B" y- g. K/ E1 ?2 U* Y* n0 @
6 ~! G; o4 O6 ~/ c5 P' r6 |$ b- 7 V/ y0 }" Y7 T# |7 P! a
- /usr/java/bin # ls /sbin. J7 A( R% G5 b# l( M+ P
- BCLSockServer hostapd lsmod swapon ubirename7 l9 P, J) ?% e( q) `) X
- band_steering hostapd_2.4g mtd_debug ubiattach ubirmvol
! [( Z8 n7 J; e- G$ j& S8 R - dump_handler hostapd_5g pivot_root ubicrc32 ubirsvol
7 A/ W' [- o/ E* J0 ? - dutserver hostapd_cli poweroff ubidetach ubiupdatevol. R! D& y; e0 x6 ~) \9 Y' c
- dwpal_cli ifconfig reboot ubiformat
7 d) B& Y4 G" M& A/ _8 } - force_roaming init rmmod ubimkvol
& N$ v) R T/ W/ @ - getty insmod route ubinfo
4 {# V* t3 ?& T* y* ~7 f - halt iw swapoff ubinize
, J' G+ M) D5 n
复制代码- /userconfig/cfg # cat /proc/cpuinfo- P2 Z5 A6 a2 c) }. a C/ m
- processor : 0
/ V3 d2 w0 G" ~% D: r. v- h - BogoMIPS : 50.00
3 v- c8 A1 t/ m, i5 L' l( I' D - Features : fp asimd crc32
u& s1 h9 k V+ T' i1 } - CPU implementer : 0x41- u! e0 m6 T% H! s
- CPU architecture: 8
K% E3 S Z; a5 L9 z: Z, e - CPU variant : 0x0: L$ f. x$ C% E8 L& Y6 e8 t
- CPU part : 0xd03, F9 c! w- E# d. {& _+ [
- CPU revision : 40 h) H( N4 O0 k. C8 M8 u+ O
" K: N6 c; Y) t/ \- processor : 1
, ~2 k3 ^: `1 c" G" P6 e9 J0 [ - BogoMIPS : 50.004 y8 V- K# e0 Y1 J. Y
- Features : fp asimd crc32
$ Y* ]1 L8 D& N: ?5 z/ t$ ^ - CPU implementer : 0x41
2 V n9 y4 A c7 n- U* y4 e - CPU architecture: 8+ M9 ~4 b" `0 [$ C: }: h
- CPU variant : 0x0
: N, Y( s2 h5 c7 y - CPU part : 0xd03' S) ~) c0 N1 r8 l" E, P
- CPU revision : 4+ u$ C j+ o$ w: R
% |( Z) s8 ~# s0 { k- processor : 2
; L; n- W, H. v* I; ~- Z& A% Z) t - BogoMIPS : 50.00
- ~& {. R, m' R6 u3 Y1 C- G - Features : fp asimd crc32
: z2 z" F; X* u7 ]! d$ i. U7 r - CPU implementer : 0x41; N1 M* c- ?+ o5 e
- CPU architecture: 8$ h" d2 {+ U/ V; C
- CPU variant : 0x0* i2 A+ Z9 d$ i4 t7 t; @; U
- CPU part : 0xd03
; [8 K3 V4 f/ H' O - CPU revision : 4
. ]8 t- ^$ G, h9 G. s- c
- E& N- b3 c0 g! K2 [0 Y6 \- processor : 3
. g8 H9 c: O: @) ? - BogoMIPS : 50.00
0 a2 {0 B2 t l - Features : fp asimd crc32
/ p* g' `; a! v0 l) ]- w m - CPU implementer : 0x41) v' e4 W, h7 c: ~, G
- CPU architecture: 8
8 p/ u9 @# z$ E3 I# z - CPU variant : 0x0
8 D: ^ A( O/ z7 T5 V - CPU part : 0xd03
0 B# b) {2 r4 }/ V# h% I - CPU revision : 4
复制代码
5 V6 }6 E& r" {1 R) l2 L4 Z# B9 v" n
" G" w% v' x: h9 Z- p9 \6 z a |
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有账号?注册
×
|