연구자들이 Anthropic의 Claude를 사용해 PLC 모델 간의 RCE 익스플로잇을 포팅했습니다.
Forescout Research - Vedere Labs는 Anthropic의 Claude를 사용하여 WAGO 프로그래머블 로직 컨트롤러(PLC) 간에 작동하는 사전 인증 원격 코드 실행(RCE) 익스플로잇을 포팅했습니다. 이 익스플로잇은 Nucleus FTP 서버의 USER 명령 처리에서 발생하는 스택 기반 버퍼 오버플로우인 CVE-2021-31886를 겨냥하고 있습니다. 연구진은 공격자가 제공한 ARM 셸코드를 실제 하드웨어에서 실행했습니다.
Researchers used Anthropic's Claude to port an RCE exploit between PLC models.
Forescout Research - Vedere Labs reported using Anthropic's Claude to port a pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another. This exploit targets CVE-2021-31886, which is a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command. The researchers successfully executed attacker-supplied ARM shellcode on live hardware.