TCPDump Flag Injection on the CT47
When Quoting Isn't Enough: TCPDump Flag Injection on the CT47
The same XML that gave us root RCE through the kernel-log path (see the companion piece) carries a second, quieter injection. The DeviceInterface value for TCPDump commands is handed to hxlogger_tcpdumpd.sh, which passes it to tcpdump.
The flaw
The script appears to quote its variables — and does, against shell metacharacters. But tcpdump parses what it receives as arguments, and the interface string survives quoting intact enough to be treated as flags. Append -w and a path, and tcpdump stops sniffing the radio's USB tether and starts writing capture files wherever you point it:
DeviceInterface: "rndis0 -w /data/local/tmp/cap.pcap" → tcpdump -i rndis0 -w /data/local/tmp/cap.pcap
Impact
- Arbitrary file writes outside the intended log directories, as the dump service's privileged context.
- Information disclosure — captures land in attacker-readable locations, and an attacker who controls the interface can also choose what traffic gets sniffed.
- A second stage for the world-writable XML: the same file that yields root via the kerdynalog path also yields this, with no extra access needed.
Why it matters
This is the instructive one for developers: quoting stops shell interpretation, not argument interpretation. Every value that crosses from config into a command line has to be validated against the target program's flag grammar, not just the shell's. A whitelist of interface names (or if_nametoindex validation that the name exists and is a real interface) closes this completely.
-- end-of-options and a fixed capture directory; never let a config value pick both the interface and the output path.frankSx / frankhacks.blogspot.com — part of the CT47 series: HxLogger root RCE (critical), WWAN engineering mode, AutoInstall hash collision, wildcard triggers.
Comments
Post a Comment