Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No shell - but crashes ASA..... #2

Open
johnson4d opened this issue Oct 25, 2016 · 3 comments
Open

No shell - but crashes ASA..... #2

johnson4d opened this issue Oct 25, 2016 · 3 comments

Comments

@johnson4d
Copy link

Hey there. I tested this using IKEv2 on a Cisco ASA5510 running v8.4.1 software.

The exploit crashes the ASA "Reason: Heap memory corrupted" and simply reloads - but never attempts a shell on TCP port 4444. My ASA and attacker machine are on the same network. During the crash, I see lots of 0x41 (As) which indicate control of memory....?

I have also attached the console session output during the full crash..... Any idea what needs to be tweaked?

ciscoasa# show crashinfo | include 41 41
0xd8cb5848: 23 01 1c a1 e0 00 00 00 41 41 41 41 41 41 41 41 | #.......AAAAAAAA
0xd8cb5858: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5868: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5878: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5888: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5898: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb58a8: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5848: 23 01 1c a1 e0 00 00 00 41 41 41 41 41 41 41 41 | #.......AAAAAAAA
0xd8cb5858: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5868: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5878: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5888: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb5898: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA
0xd8cb58a8: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 | AAAAAAAAAAAAAAAA

@johnson4d
Copy link
Author

asa.txt

@ghost
Copy link

ghost commented Sep 8, 2017

Were you able to get a shell? I'm also having this issue, I can't get any shell even if I waited for a long time.

@johnson4d
Copy link
Author

No, I could not get a shell. The support for this exploit was very limited sadly, I don't know anyone that got it to actually work outside of the code writers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant