[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : SHOUTcast 1.9.4 File Request Format String Remote Exploit (win)
# Published : 2005-02-19
# Author : mandragore
# Previous Title : BadBlue 2.55 Web Server Remote Buffer Overflow
# Next Title : Knox Arkeia Server Backup 5.3.x Remote Root Exploit
/*
Object: PoC for Nullsoft SHOUTcast 1.9.4 File Request Format String Vulnerability
From the securityfocus bid at http://www.securityfocus.com/bid/12096 :
"This issue was reported to exist in version 1.9.4 on Linux. It is likely that versions for other
platforms are also affected by the vulnerability, though it is not known to what degree they are
exploitable."
This is now clarified, it's exploitable.
notes: This is a two steps exploitation: the format bug is used to compute a buffer
that will overwrite the stack later, resulting in a SEH overwriting.
The exploit works for both the GUI and the console servers.
greets: Sputnik
`date`: Sat Feb 19 15:48:45 2005
credits: Tomasz Trojanowski
author: mandragore, mandragore@turingtest@gmail.com
Disclaimer:
This exploit is not to be published on any french site, including k-otic.com, because of the law
against vulnerability research (the LEN). We all know what security through obscurity means,
but I don't make the laws.
*/
#include <stdio.h>
#include <strings.h>
#include <signal.h>
#include <netinet/in.h>
#include <netdb.h>
#define NORM "