exploit-db-mirror/shellcodes/linux_x86-64
Offensive Security 970f7b1104 DB: 2019-05-24
18 changes to exploits/shellcodes

macOS < 10.14.5 / iOS < 12.3 DFG JIT Compiler - 'HasIndexedProperty' Use-After-Free
macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - AIR Optimization Incorrectly Removes Assignment to Register
macOS < 10.14.5 / iOS < 12.3 XNU - Wild-read due to bad cast in stf_ioctl
macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
Apple macOS < 10.14.5 / iOS < 12.3 DFG JIT Compiler - 'HasIndexedProperty' Use-After-Free
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - AIR Optimization Incorrectly Removes Assignment to Register
Apple macOS < 10.14.5 / iOS < 12.3 XNU - Wild-read due to bad cast in stf_ioctl
Apple macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
NetAware 1.20 - 'Add Block' Denial of Service (PoC)
NetAware 1.20 - 'Share Name' Denial of Service (PoC)
Terminal Services Manager 3.2.1 - Denial of Service
Visual Voicemail for iPhone - IMAP NAMESPACE Processing Use-After-Free
Microsoft Windows 10 (17763.379) - Install DLL
Microsoft Windows (x84/x64) - 'Error Reporting' Discretionary Access Control List / Local Privilege Escalation
Microsoft Windows 10 1809 - 'CmKeyBodyRemapToVirtualForEnum' Arbitrary Key Enumeration Privilege Escalation
Apple Mac OS X - Feedback Assistant Race Condition (Metasploit)
Microsoft Windows (x84) - Task Scheduler' .job' Import Arbitrary Discretionary Access Control List Write / Local Privilege Escalation
Microsoft Internet Explorer 11 - Sandbox Escape
Microsoft Windows - 'Win32k' Local Privilege Escalation

Axis Network Camera - .srv to parhand RCE (Metasploit)
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)

HP Intelligent Management - Java Deserialization RCE (Metasploit)
HP Intelligent Management - Java Deserialization Remote Code Execution (Metasploit)

Erlang - Port Mapper Daemon Cookie RCE (Metasploit)
Erlang - Port Mapper Daemon Cookie Remote Code Execution (Metasploit)

CMS Made Simple (CMSMS) Showtime2 - File Upload RCE (Metasploit)
CMS Made Simple (CMSMS) Showtime2 - File Upload Remote Code Execution (Metasploit)
AIS logistics ESEL-Server - Unauth SQL Injection RCE (Metasploit)
Pimcore < 5.71 - Unserialize RCE (Metasploit)
AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit)
Pimcore < 5.71 - Unserialize Remote Code Execution (Metasploit)

Shopware - createInstanceFromNamedArguments PHP Object Instantiation Remote Code Execution (Metasploit)

Nagios XI 5.6.1 - SQL injection

BSD/x86 - setuid(0) + Bind (31337/TCP) Shell Shellcode (94 bytes)
BSD/x86 - setuid(0) + Bind (31337/TCP) Shell (/bin/sh) Shellcode (94 bytes)

Linux/x86 - execve(/sbin/iptables -F) Shellcode (70 bytes)
Linux/x86 - Flush IPTables Rules (execve(/sbin/iptables -F)) Shellcode (70 bytes)

Linux/x86 - /sbin/iptables --flush Shellcode (69 bytes)
Linux/x86 - Flush IPTables Rules (/sbin/iptables --flush) Shellcode (69 bytes)

Linux/x86 - iptables --flush Shellcode (43 bytes)
Linux/x86 - Flush IPTables Rules (iptables --flush) Shellcode (43 bytes)

Linux/x86 - iptables -F Shellcode (43 bytes)
Linux/x86 - Flush IPTables Rules (iptables -F) Shellcode (43 bytes)

Linux/x86 - Reverse TCP (::FFFF:192.168.1.5:4444/TCP) Shell (/bin/sh) + Null-Free + IPv6 Shellcode (86 bytes)
Linux/x86 - Reverse (::FFFF:192.168.1.5:4444/TCP) Shell (/bin/sh) + Null-Free + IPv6 Shellcode (86 bytes)

Linux/x86 - Reverse TCP (fd15:4ba5:5a2b:1002:61b7:23a9:ad3d:5509:1337/TCP) Shell (/bin/sh) + IPv6 Shellcode (Generator) (94 bytes)
Linux/x86 - Reverse (fd15:4ba5:5a2b:1002:61b7:23a9:ad3d:5509:1337/TCP) Shell (/bin/sh) + IPv6 Shellcode (Generator) (94 bytes)

Linux/MIPS (Big Endian) - execve(/bin/sh) + Reverse TCP 192.168.2.157/31337 Shellcode (181 bytes)
Linux/MIPS (Big Endian) - execve(/bin/sh) + Reverse TCP (192.168.2.157/31337) Shellcode (181 bytes)

Linux/x86 - wget chmod execute over execve /bin/sh -c Shellcode (119 bytes)
Linux/x86 - execve(/bin/sh -c) + wget (http://127.0.0.1:8080/evilfile) + chmod 777 + execute Shellcode (119 bytes)
macOS - Reverse (::1:4444/TCP) Shell (/bin/sh) +IPv6 Shellcode (119 bytes)
macOS - Bind (4444/TCP) Shell (/bin/sh) + IPv6 Shellcode (129 bytes)
macOS - Reverse (127.0.0.1:4444/TCP) Shell (/bin/sh) + Null-Free Shellcode (103 bytes)
macOS - Bind (4444/TCP) Shell (/bin/sh) + Null-Free Shellcode (123 bytes)
macOS - execve(/bin/sh) + Null-Free Shellcode (31 bytes)
Apple macOS - Reverse (::1:4444/TCP) Shell (/bin/sh) +IPv6 Shellcode (119 bytes)
Apple macOS - Bind (4444/TCP) Shell (/bin/sh) + IPv6 Shellcode (129 bytes)
Apple macOS - Reverse (127.0.0.1:4444/TCP) Shell (/bin/sh) + Null-Free Shellcode (103 bytes)
Apple macOS - Bind (4444/TCP) Shell (/bin/sh) + Null-Free Shellcode (123 bytes)
Apple macOS - execve(/bin/sh) + Null-Free Shellcode (31 bytes)

Linux/x86 - Polymorphic execve(/bin/sh) Shellcode (63 bytes)
Linux/x86 - execve(/bin/sh) + Polymorphic Shellcode (63 bytes)

Linux/x86 - Add User (sshd/root) to Passwd File Shellcode (149 bytes)
Linux/x86 - Add User (sshd/root) to /etc/passwd Shellcode (149 bytes)
Linux/x86 - Cat File Encode to base64 and post via curl to Webserver Shellcode (125 bytes)
Linux/ARM - Password-Protected Reverse TCP Shellcode (100 bytes)
Linux/x86 - Rabbit Shellcode Crypter (200 bytes)
Linux/x86 - Reverse Shell Shellcode (91 Bytes) + Python Wrapper
Linux/x86 - Openssl Encrypt Files With aes256cbc Shellcode (185 bytes)
Linux/x86 - cat (.bash_history)+ base64 Encode + curl data (http://localhost:8080) Shellcode (125 bytes)
Linux/ARM - Reverse (127.0.0.1:4444/TCP) Shell (/bin/sh) + Password (S59!) + Null-Free Shellcode (100 bytes)
Linux/x86 - Rabbit Encoder Shellcode  (200 bytes)
Linux/x86 - Reverse (127.0.0.1:8080/TCP) Shell (/bin/sh) + Generator Shellcode (91 Bytes)
Linux/x86 - OpenSSL Encrypt (aes256cbc) Files (test.txt) Shellcode (185 bytes)
Linux/x86 - shred file Shellcode (72 bytes)
Linux/x86 - execve /bin/sh Shellcode (20 bytes)
Linux/x86 - /sbin/iptables -F Shellcode (43 bytes)
Linux x86_64 - Delete File Shellcode (28 bytes)
Linux/x86 - Shred file (test.txt) Shellcode (72 bytes)
Linux/x86 - execve(/bin/sh) Shellcode (20 bytes)
Linux/x86 - Flush IPTables Rules (/sbin/iptables -F) Shellcode (43 bytes)
Linux/x86_64 - Delete File (test.txt) Shellcode (28 bytes)
Linux/x64 - Execve(/bin/sh) Shellcode (23 bytes)
2019-05-24 05:02:03 +00:00
..
13296.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
13320.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
13463.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
13464.s DB: 2018-01-13 2018-01-13 05:02:13 +00:00
13688.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
13691.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
13908.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
13915.c DB: 2018-01-25 2018-01-25 18:22:06 +00:00
13943.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
14305.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
18197.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
18585.s DB: 2018-01-13 2018-01-13 05:02:13 +00:00
34667.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
35205.asm DB: 2018-01-25 2018-01-25 18:22:06 +00:00
35586.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
35587.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
36359.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
36858.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
37362.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
37401.asm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
38150.txt DB: 2018-01-13 2018-01-13 05:02:13 +00:00
38239.asm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
38469.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
38708.asm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
38815.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39149.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39152.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39185.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39203.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39312.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39383.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39388.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39390.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39578.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39617.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39624.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39625.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39684.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39700.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39718.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39758.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39763.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39847.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
39869.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
40029.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
40052.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
40061.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
40079.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
40122.c DB: 2018-01-25 2018-01-25 18:22:06 +00:00
40139.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
40808.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
41089.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41128.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41174.nasm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41398.nasm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41439.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41468.nasm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41477.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41498.nasm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41503.nasm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41509.nasm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41510.nsam DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41750.asm DB: 2018-01-25 2018-01-25 18:22:06 +00:00
41883.txt DB: 2018-01-13 2018-01-13 05:02:13 +00:00
41970.asm DB: 2018-01-13 2018-01-13 05:02:13 +00:00
42126.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
42179.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
42339.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
42485.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
42522.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
42523.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
42791.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
43549.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
43550.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
43551.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
43552.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
43553.c DB: 2018-01-13 2018-01-13 05:02:13 +00:00
43554.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43555.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43556.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43557.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43558.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43559.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43561.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43562.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43563.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43564.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43565.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43566.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43568.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43570.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43597.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43598.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43599.c DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43601.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43602.asm DB: 2018-01-16 2018-01-16 05:02:18 +00:00
43603.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
43604.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
43605.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
43606.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
43607.c DB: 2019-03-08 2019-03-08 05:01:50 +00:00
43951.nasm DB: 2018-02-03 2018-02-03 05:01:48 +00:00
43952.nasm DB: 2018-02-03 2018-02-03 05:01:48 +00:00
43953.nasm DB: 2018-02-03 2018-02-03 05:01:48 +00:00
43954.nasm DB: 2018-02-03 2018-02-03 05:01:48 +00:00
43956.c DB: 2018-02-03 2018-02-03 05:01:48 +00:00
45039.c DB: 2018-07-18 2018-07-18 05:01:47 +00:00
45185.asm DB: 2018-08-14 2018-08-14 05:01:45 +00:00
45943.c DB: 2018-12-05 2018-12-05 05:01:44 +00:00
46007.c DB: 2018-12-20 2018-12-20 05:01:43 +00:00
46492.c DB: 2019-03-05 2019-03-05 05:01:50 +00:00
46870.c DB: 2019-05-21 2019-05-21 05:02:05 +00:00
46907.c DB: 2019-05-24 2019-05-24 05:02:03 +00:00