Don't Ruck Us Too Hard - Owning All of Ruckus AP devices | Gal Zror | NULLCON Goa 2020
About this talk
This talk showcases vulnerability research conducted on Ruckus Networks' access points and Wi-Fi controllers, revealing three instances of pre-authentication remote code execution. The speaker discusses various exploited vulnerabilities, including information leak, authentication bypass, command injection, path traversal, stack overflow, and arbitrary file read/write, confirming all ten CVEs identified in the research. A total of 33 different access point firmware and Wi-Fi controllers were evaluated, all of which were found to be vulnerable. Additionally, the talk introduces the framework utilized in this research, featuring a Ghidra script and a dockerized QEMU full system emulation for simplified cross-architecture research setup. Gal Zror, a research team leader at HCL AppScan, presents this in-depth exploration, drawing on his extensive experience in vulnerability research focused on embedded systems and protocols.
More from this event
See all 39 talks →
ML for security and security for ML | Training Tidbits | Nikhil Joshi | NULLCON Goa | March 2020
0:30
Practical IoT Hacking | Training Tidbits | Aseem Jakhar | NULLCON Goa | March 2020
0:54
Hacking iOS Applications, Like A Pro | Training Tidbits | Abhinav Mishra | NULLCON Goa | March 2020
1:14
Windows Kernel Exploitation - Foundation & Advanced | Training Tidbits | Ashfaq Ansari #NULLCON2020
0:36