asatools icon indicating copy to clipboard operation
asatools copied to clipboard

why the crash poc do not work

Open b33t1e opened this issue 7 years ago • 7 comments

my firmware is asav-941-200.qcow2, the version info are shown below: default of course, the 64 bit catches my eyes! I note this on my config all the time. I enable the snmp, ikev1, ikev2, webvpn on asa by "Configuring a Cisco ASA test environment from ground zero" and "asadbg/config/", thanks a lot. I verified every service works well. default default default every thing is OK, I'm ready to use the poc. But, nothing happend. Do not crash. Why??? default default

b33t1e avatar Feb 26 '18 13:02 b33t1e

I'd double check you're running the public PoC that sends the request twice. The original PoC didn't.

fidgetingbits avatar Feb 26 '18 15:02 fidgetingbits

The poc I use is https://www.exploit-db.com/exploits/43986/, It's that anything wrong? default

b33t1e avatar Feb 27 '18 00:02 b33t1e

I note the http status code is 302, So I changed the poc to allow the request redirect. That is: default I use this poc, and the result is: default And the Cisco ASA is still not crash.

b33t1e avatar Feb 27 '18 00:02 b33t1e

You shouldn't need the redirect enabled. The PoC you linked won't work by default. The authors fixed it on pastebin at some point. I don't recall off the top of my head if the 302 response is normal, and don't have time to test atm, but I'd try the other PoC for now.

fidgetingbits avatar Feb 27 '18 17:02 fidgetingbits

Using the modified POC, I can't trigger crash, can you trigger now?

kiritowch avatar Feb 28 '18 08:02 kiritowch

No :( I will look it further to try make the poc work. Just try, because it's so hard for me. But it's interesting ^_^

b33t1e avatar Mar 01 '18 03:03 b33t1e

hey, bro! The same question I met when I read this tutorial, I do not use this method. I just ignored this. I just show you my network default the ASAv ip: default this cloud should connect some network card(virtual or real): default the ip I use to debug the asav: default That is mean just to make the network connected. Hope this will help. Oh, my id is b33t1e, not b33tle :)

b33t1e avatar Mar 27 '18 08:03 b33t1e