标签 ‘Overflow’ 下的日志

IE NCTAudioFile2.AudioFile ActiveX Remote Stack Overflow Exploit 2

鬼仔注:前段时间还发过 这个

来源:milw0rm

阅读全文 »

Tags: , ,

MS Windows DNS RPC Remote Buffer Overflow Exploit (port 445) v2

鬼仔注:V2
看到有朋友留言说不知道怎么编译,这里说下用VC里用Makefile文件编译的方法:
运行cmd.exe
进到vc/bin目录
运行vc-vars32.bat
进到makefile所在的目录
nmake /f makefile

来源:milw0rm

Exploit v2 features:
- Target Remote port 445 (by default but requires auth)
- Manual target for dynamic tcp port (without auth)
- Automatic search for dynamic dns rpc port
- Local and remote 阅读全文 »

Tags: , , ,

XAMPP Mssql_Connect Remote Buffer Overflow Vulnerability

鬼仔注:XAMPP(Apache+MySQL+PHP+PERL)是一个功能强大的建站集成软件包。我见过有不少站为了省事直接用这个做,我以前测试东西也用这个搭建过环境。影响的版本挺多:
XAMPP Apache Distribution 1.4.14
XAMPP Apache Distribution 1.4.13
XAMPP Apache Distribution 1.4.12
XAMPP Apache Distribution 1.4.11
XAMPP Apache Distribution 1.4.10 a
XAMPP Apache Distribution 1.4.10
XAMPP Apache Distribution 1.4.9
XAMPP Apache Distribution 1.4.8
阅读全文 »

Tags: , , ,

MS Windows DNS RPC Remote Buffer Overflow Exploit (port 445)

来源:milw0rm

Microsoft DNS Server Remote Code execution Exploit and analysis
Advisory: http://www.microsoft.com/technet/security/advisory/935964.mspx
This remote exploit works against port 445 (also Microsoft RPC api used)

Author:
* Mario Ballano ( mballano~gmail.com )
* Andres Tarasco ( atarasco~gmail.com )

Timeline:
阅读全文 »

Tags: , , ,

MS Windows DNS DnssrvQuery Remote Stack Overflow Exploit

来源:milw0rm
阅读全文 »

Tags: , , ,

IE (79+ Exes) NCTAudioFile2.AudioFile ActiveX Remote Overflow Exploit

来源:milw0rm
阅读全文 »

Tags: , , ,