Hacking The Interwebs

本文探讨了如何利用UPnP协议中的漏洞进行攻击,详细介绍了使用Flash构造SOAP请求的方法,无需XSS即可远程配置路由器。

通过flash构造soap请求走UPNP协议来黑家庭用的小交换机

“With great power comes great responsibility”, but those with great power
usually aren’t that responsible. Nevertheless, we try to be responsible as
much as we can. In the following post, ap
<http://www.gnucitizen.org/about/ap>  (Adrian Pastor; pagvac) and I
<http://www.gnucitizen.org/about/pdp>  (pdp) are going to expose some
secrets, which may make you question our values at first, will definitely
make you feel worried about “Why is all this possible?”, and may even make
you hate us in your guts for what we have done. It is important to
understand the magnitude of the problem we are planning to talk about, and
that we cannot go to any vendor to ask for a solution, because it is not a
bug what we have to deal with, but rather a combination of design problems.
It is an issue, which needs to be resolved right now and the only way to do
that is to go public with whatever we’ve got on our table.

During the last week we’ve tried to prepare you for this very moment by
exposing bits
<http://www.gnucitizen.org/blog/hacking-with-upnp-universal-plug-and-play>
and pieces on how UPnP works and why it is so important to keep it in mind
when testing and securing networks. We’ve also talked
<http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-5>  about
how the Universal Plug and Play can be combined with simple XSS attacks in
order to create a powerful mechanism for remotely reconfiguring vulnerable
routers without any means of authentication or authorization with the
targeted device. Today, we are going to show you that UPnP can be exploited
across the Web without the need of XSS. This is the next logical,
evolutionary step of UPnP exploitation which by far has the highest level of
severity.

We’ve talked
<http://www.gnucitizen.org/blog/hacking-with-upnp-universal-plug-and-play>
earlier that the UPnP stack consists of several technologies: SSDP (Simple
Service Discovery Protocol), GENA (Generic Event Notification Architecture),
SOAP (Simple Object Access Protocol) and XML. The UPnP control process
starts with the discovery stage. Here, a multicast SSDP packet is submitted
to 239.255.255.250:1900. Any device that listens on this multicast port will
then respond with information about their service description if they are
happy with the body of the discovery packet. The UPnP control actuator will
then read the description and look for available methods. Each method is
associated with a control point (URL and a header) and method parameters
which may or may not be required. Once the method information is obtained,
the UPnP actuator will pick the method that suits best the given task that
needs to be performed and submit a SOAP message to the control point in
order to actualize it. “This is how UPnP works in general!”

When attacking UPnP from within the network where the UPnP enabled device is
located, we pretty much proceed with the method described above. If we want
to attack a UPnP enabled device across the Web, then we have a few problems
that needs to be solved. First of all, from the Web, we cannot send and
process SSDP. SSDP is based on UDP and it deals with multicast packets which
is something browsers and Web technologies in general will probably never
learn how to work with. The only stage that we can safely perform from the
Web is the actual SOAP request, which is the very last stage of the control
mechanism described in the previous paragraph.

Adrian did an amazing job explaining
<http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-5>  how
someone can reconfigure your BT Home Hub router via a pre-auth XSS. In his
post, Adrian describes a mechanism where the victim visits a malicious page,
which makes use of a XSS vulnerability that exists within the BT Home Hub
router, in order to add a portforwarding rule within the targeted device
firewall. Once the XSSed SOAP request is actualized, the attacker will be
able to get access to an internal service over the portforward. Given the
fact that the attacker can change the primary DNS server of the target
router, as well, the problem seams to be more then scary and very, very
concerning. At this stage you are probably thinking that closing the XSS
hole on the router pre-auth pages will definitely solve the problem for
good, but I am afraid to inform you that you will be wrong.

To the point: SOAP Messages are nothing but POST requests with contentType
equal to application/xml, a SOAPAction header and a request body that
complies with the SOAP message format. These three request values cannot be
changed with JavaScript unless we deal with the XMLHttpRequest object.
Though, in order to successfully use this object, we need to comply with the
Same Origin Policies (SOP) and that will mean that we need an XSS
vulnerability, as Adrian proposed
<http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-5>  in
his article. However, it is less known that these values can be easily set
with Flash. The following code demonstrates the attack vector:

http://www.gnucitizen.org/projects/hacking-the-interwebs/Test.mxml

The Test.mxml Flash Application performs several operations.

1.      At first, the MXML script creates an URLRequest object to the
targeted UPnP control point URL. In our case, this is
http://192.168.1.254/upnp/control/igd/wanpppcInternet, which is the PPP
control point of BT Home Hub. Keep in mind that other devices can be
exploited as well by changing that URL to match their setup.
2.      Then we define the request method which has to be POST.
3.      The next expression defines the request data. This is the actual
SOAP Message which will add the portforwarding rule.
4.      We need to set the contentType to application/xml.
5.      Then we push the SOAPAction header into the Array of headers.
6.      And finally we open the URLRequest with navigateToURL. The respond
will render within _self.

Shockwave Flash 9.0 r115 (the latest at the time of writing but not
automatically deployed) seams to incorrectly supply the request headers.
This may make the attack to fail if you use Firefox, Opera or Safari and the
attacked router or UPnP device is picky about CR and CRLF line endings.
Earlier flash versions does not have this problem/bug. Keep in mind that
most devices will accept the request although the line endings are mixed up
a bit.

When the victim visits the malicious SWF file, the above 6 steps will
silently execute in the background. At that moment the attacker will have
control over the service the portforwarding rule was assigned for for. Keep
in mind that no XSS is required, it is a matter of visiting the wrong
resource at the wrong time. Also, keep in mind that 99% of home routers are
vulnerable to this attack as all of them support UPnP to one degree or
another.

I repeat myself far too much, but I guess I have another opportunity to
mention that adding a portforwarding is only one of the many things someone
can do to your router. The most malicious of all malicious things is to
change the primary DNS server. That will effectively turn the router and the
network it controls into a zombie which the attacker can take advantage of
whenever they feel like it. It is also possible to reset the admin
credentials and create the sort of onion routing network all the bad guys
want. We hope that by exposing this information, we will drastically improve
the situation for the future. I think that this is a lot better than keeping
it for ourselves or risking it all by given the criminals the opportunity to
have in possession a secret which no one else is aware of.

GNUCITIZEN is a Cutting Edge, Ethical Hacker Outfit, Information Think Tank,
which primarily deals with all aspects of the art of hacking. Our work has
been featured in established magazines and information portals, such as
Wired, Eweek, The Register, PC Week, IDG, BBC and many others. The members
of the GNUCITIZEN group are well known and well established experts in the
Information Security, Black Public Relations (PR) Industries and Hacker
Circles with widely recognized experience in the government and corporate
sectors and the open source community.

GNUCITIZEN is an ethical, white-hat organization that doesn’t hide
anything. We strongly believe that knowledge belongs to everyone and we make
everything to ensure that our readers have access to the latest cutting-edge
research and get alerted of the newest security threats when they come. Our
experience shows that the best way of protection is mass information. And we
mean that literally!!! It is in the public’s best interest to make our
findings accessible to vast majority of people, simply because it is proven
that the more people know about a certain problem, the better.

download: Harmless/Useless
<http://www.gnucitizen.org/projects/hacking-the-interwebs/Test.mxml>  Proof
of Concept - use for demonstration and eduction purposes only

The only way to protect yourself is to turn off UPnP. Yes, that will make
your life harder and probably your skype or msn wont work as flawlessly as
before but it is a trade-off you have to learn to live with.

 
内容概要:本文提出了一种基于非合作博弈理论的居民负荷分层调度模型,并结合双层鲸鱼优化算法(Two-level Whale Optimization Algorithm)进行高效求解,模型与算法均通过Matlab代码实现。研究针对电力系统中居民侧用电负荷的复杂调度问题,引入非合作博弈机制刻画各用户之间的利益竞争关系,实现负荷的分层优化分配;同时设计双层优化架构,上层优化资源配置,下层模拟用户自主决策行为,提升了模型的实用性与合理性。通过智能优化算法求解多层级、非凸非线性的博弈模型,有效提高了调度方案的收敛性与全局寻优能力,适用于现代智能电网中的需求侧管理与能源优化场景。; 适合人群:具备电力系统基础理论知识和Matlab编程能力,从事智能电网、能源优化调度、需求侧管理、博弈论应用等方向的科研人员、高校研究生及工程技术人员。; 使用场景及目标:①应用于居民区电力负荷的分层优化调度系统设计与仿真分析;②为非合作博弈在多主体能源系统建模中的应用提供方法论支持;③利用双层鲸鱼算法解决具有嵌套结构的复杂双层优化问题,提升求解效率与调度方案的可行性。; 阅读建议:建议读者结合提供的Matlab代码深入理解模型构建逻辑与算法实现流程,重点关注博弈模型的效用函数设计、纳什均衡求解思路以及双层优化结构的迭代机制,宜配合实际用电数据开展复现实验以验证模型有效性与鲁棒性。
内容概要:本文围绕基于自适应神经模糊推理系统(ANFIS)智能控制器的可再生能源微电网功率管理系统展开研究,结合Simulink仿真实现,深入探讨了微电网中功率的智能调控与经济机组组合调度问题。通过引入ANFIS控制器,有效应对风能、光伏等可再生能源出力的波动性与不确定性,提升系统运行的稳定性与电能质量。研究内容涵盖微电网多源协调控制策略、功率平衡管理、优化调度模型构建及仿真验证,实现了对分布式电源、储能系统和负荷的协同优化,兼顾经济性与可靠性目标,并通过仿真平台验证了所提方法的有效性与优越性。; 适合人群:具备电力系统、自动化或新能源相关专业背景,熟悉Matlab/Simulink仿真环境,从事微电网能量管理、智能控制、能源优化等领域研究的研究生、科研人员及工程技术人员。; 使用场景及目标:①用于高比例可再生能源接入场景下的微电网能量管理系统研发与教学实践;②为实现微电网功率稳定控制与经济高效运行提供先进的智能控制解决方案;③支撑高水平学术论文复现、科研课题攻关及实际工程项目的仿真验证与方案优化。; 阅读建议:建议结合提供的Simulink模型与相关代码进行动手实践,重点关注ANFIS控制器的设计流程、规则库构建与参数调优方法,并通过与传统PID或MPC控制策略的对比实验,深入理解其在动态响应与鲁棒性方面的优势。同时可进一步拓展文中提出的优化调度逻辑,应用于多目标、多约束的复杂实际应用场景中。
内容概要:本文档聚焦于“直流电机双闭环控制Matlab仿真”,系统阐述了基于Matlab/Simulink平台实现直流电机双闭环控制系统(主要包括速度环与电流环)的设计与仿真全过程。通过构建直流电机的数学模型,结合PI控制器进行调控,实现对电机转速和电枢电流的高精度动态控制,验证控制策略的稳定性与响应性能。文档详细介绍了仿真模型的搭建流程、关键参数的整定方法、系统动态波形的分析手段以及仿真结果的有效性验证,体现了经典自动控制理论在实际电机系统中的工程应用,是电机控制与电力电子技术相结合的典型研究案例。; 适合人群:具备自动控制原理、电机与拖动基础、电力电子技术和Matlab/Simulink仿真能力的电气工程、自动化、机电一体化等专业的本科生、研究生及从事电机驱动系统研发的工程技术人员。; 使用场景及目标:①作为高校课程设计或实验教学材料,帮助学生深入理解双闭环调速系统的工作机理与工程实现;②服务于科研项目,为新型电机控制算法(如滑模、模糊PID等)的开发与性能对比提供基础仿真验证平台;③作为工业界产品前期设计的仿真工具,用于评估不同控制策略在动态响应、抗干扰能力和稳态精度方面的可行性。; 阅读建议:建议读者在学习过程中紧密结合自动控制理论知识,亲手在Simulink环境中搭建完整的双闭环仿真模型,通过反复调整PI控制器的比例与积分参数,观察并分析转速、电流的阶跃响应曲线,从而深刻理解反馈控制的本质、系统稳定性条件以及参数整定对动态性能的影响,进而掌握电机控制系统的设计精髓。
内容概要:本文研究了基于Benders分解与输电网运营商(TSO)和配电网运营商(DSO)协调机制的不确定环境下输配电网双层优化模型,旨在提升高比例可再生能源接入背景下电网系统的协调性与鲁棒性。模型上层以系统整体经济性为目标进行优化调度,下层采用Benders分解实现TSO与DSO之间的信息交互与协同决策,通过引入割平面迭代机制保障求解的收敛性与全局最优性。研究充分考虑新能源出力与负荷需求的不确定性,构建了具有强适应性的双层优化框架,并基于Matlab完成了模型的编程实现与仿真验证,有效解决了多主体、多层级、多不确定性因素耦合下的电力系统优化调度难题。; 适合人群:具备电力系统分析、运筹学与优化理论基础,熟悉Matlab编程环境,从事智能电网、能源互联网、分布式能源集成、电力市场等方向的研究生、科研人员及工程技术人员。; 使用场景及目标:①研究高渗透率可再生能源条件下输配电网协同优化调度策略;②掌握Benders分解在电力系统双层优化建模中的应用方法与实现技巧;③构建TSO-DSO多主体协调机制,实现跨层级电网资源的高效互动与决策解耦;④提升对不确定性建模、分解算法设计及大规模优化问题求解能力。; 阅读建议:建议读者结合Matlab代码逐模块剖析模型构建流程,重点理解Benders割的生成逻辑、主从问题的信息传递机制及收敛判据设定,推荐在标准IEEE测试系统上复现实验以深入掌握模型特性与算法性能。
内容概要:本文系统研究了基于灰狼优化算法(GWO)优化Elman神经网络的方法,并提供了完整的Matlab代码实现。研究重点在于利用灰狼优化算法强大的全局搜索能力,对Elman神经网络的关键参数进行智能优化,从而克服传统训练方法易陷入局部最优的缺陷,显著提升模型在时序预测与非线性系统建模任务中的精度与稳定性。文章详细阐述了Elman网络的动态反馈机制及其在处理时间序列数据方面的优势,构建了GWO与Elman相结合的混合预测框架,涵盖了从模型搭建、参数寻优、仿真测试到结果分析的全流程,特别适用于风电功率预测、电力负荷预测等具有强时变性和不确定性的工程应用场景。; 适合人群:具备一定Matlab编程能力和神经网络基础知识,从事智能优化算法、时间序列预测、电力系统分析或新能源出力预测等相关领域的研究生、科研人员及工程技术人员。; 使用场景及目标:①掌握灰狼优化算法在神经网络超参数优化中的具体实施路径与技术细节;②深入理解Elman递归神经网络与群体智能优化算法融合的建模范式;③将其应用于风电、光伏等新能源发电功率预测及复杂动态系统的建模与仿真,提升预测性能。; 阅读建议:建议读者结合所提供的Matlab代码进行动手实践,重点关注GWO算法与Elman网络的接口设计、适应度函数构建及参数优化迭代过程,可通过调整数据集或迁移至其他预测场景以深化理解和验证模型泛化能力。
源码直接下载地址: https://pan.quark.cn/s/a4b39357ea24 JMeter的录制方法及过滤策略、线程组构成要素是什么? JMeter能够借助第三方录制工具(如BadBoy)或其自带的录制功能来完成录制工作,JMeter的录制机制:是借助HTTP代理服务器来捕获用户在操作网站时产生的链接信息。JMeter允许在配置HTTP代理服务器时,排除掉非必要的CSS、GIF等资源,以此减轻不必要的负担。 线程组涵盖:线程组的名称标识、附加注释说明、线程组内的用户数量、线程组完成请求的时间分配、循环执行次数、时间调度机制 【JMeter性能测试详解】 JMeter是一款功能强大的性能测试软件,常用于模拟大规模用户同时访问Web应用,用以衡量系统的性能表现和稳定性。接下来将具体说明JMeter的操作方法、线程组的设置以及性能测试的重要环节。 **JMeter录制与过滤** JMeter可以通过BadBoy等外部工具或其自带的HTTP代理服务器来记录用户的行为。其录制原理是JMeter作为HTTP代理,拦截用户浏览器发出的所有网络请求。在配置代理服务器时,能够过滤掉不必要的CSS、GIF等静态资源,以减少无效的负载。 **线程组配置** 线程组是JMeter测试计划的核心部分,包含以下几个关键参数: 1. **线程组名**:用于区分测试计划中的不同测试区域。 2. **注释**:用于记录测试目标或注意事项。 3. **线程数**:用于模拟并发用户的数量。 4. **循环次数**:每个线程需要执行的循环次数,可以设置为无限循环。 5. **Ramp-up period**:规定所有线程启动的时间跨度,旨在平滑增加负载。 6. **定时器**:例如思考时间或...
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值