Skip to content

Comment on CVE-2017-16544: A Busybox autocompletion vulnerabilityparent

Comments

Hi, I'm the author of the article. To stress your point, there really are so many embedded devices using Busybox, and most of them were never designed to be updated (or nobody cares enough to update them).

Also I never got to fuzzing networking applets (wget is the most obvious) but this is definitely something I plan to look into, if no one did that before, there are definitely vulnerabilities there too.

When you ssh to your device are you not running Busybox shell on the device? I don't understand why this is less of a problem?

Yes absolutely. Whew. Updated my comment accordingly, thanks.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.