hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

dr0zaxx
I have attached the compiled code for the Microsoft IIS SSL Remote Denial of Service Exploit (MS04-011)

Use it wisely, not blindly wink.gif


Compiled on a OpenBSD machine~
Brady
thanks for the complitaion man...14 d/ls and no thanks given yet..tsk tsk...smile.gif
eddy
thanks man nice work wink.gif
buzzons
27 now :S

thanks a lot , not needed cos i just compiled on my box as well.. but thanks for the effort

buz
Erra
Not for me, but thanks for posting, I have no use for DOS's
BLaCkOuT
thanks a lot wink.gif
xdccpt
Thanks a lot m8


gonna check it
tazthedev
thx
tweakz20
error on run...
title- 16 bit MS-DOS Subsystem
C:\DOCUME~1\ADMINI~1.000\DESKTOP\05152004.exe
The NTVDM CPU has encountered an illegal instruction.
CS:0000 IP:0077 OP:f0 37 05 0e 02 Choose 'Close' to terminate the application

(my cpu is AMD XP 2600+.. dunno what NTVDM is suppost to stand for...?)
point- i got an error on run... it said it was an illeagal instruction so i'm guessing it's not only me...?
MxMx
hope a shellcode will be added soon biggrin.gif
Killaloop
QUOTE (tweakz20 @ Apr 15 2004, 02:19 AM)
error on run...
title- 16 bit MS-DOS Subsystem
C:\DOCUME~1\ADMINI~1.000\DESKTOP\05152004.exe
The NTVDM CPU has encountered an illegal instruction.
CS:0000 IP:0077 OP:f0 37 05 0e 02 Choose 'Close' to terminate the application

(my cpu is AMD XP 2600+.. dunno what NTVDM is suppost to stand for...?)
point- i got an error on run... it said it was an illeagal instruction so i'm guessing it's not only me...?

ntvdm is Windows 16-bit Virtual Machine used to execute a 16-bit process on a 32-bit platform.
however can't get this one to run

MxMx
You won't see a working exploit with shellcode for this because there is no universal adress... on every exploitation you jump somewhere else.
impossible for a remote exploit with shellcode.
langzi
thanks !!!
BuzzDee
CODE
You won't see a working exploit with shellcode for this because there is no universal adress... on every exploitation you jump somewhere else.
impossible for a remote exploit with shellcode.


how did u find out that? i mean why does it jump somewhere else on every exploitation? u overflow the buffer and overwrite the return address with ur own (where the sellcode starts). so it jumps to the adress u want to and not to somewhere else on every exploitation. or did i get anything wrong? if yes - sry - im still learning all this wink.gif

greetz,
buzz
Killaloop
QUOTE (BuzzDee @ Apr 15 2004, 09:42 AM)
CODE
You won't see a working exploit with shellcode for this because there is no universal adress... on every exploitation you jump somewhere else.
impossible for a remote exploit with shellcode.


how did u find out that? i mean why does it jump somewhere else on every exploitation? u overflow the buffer and overwrite the return address with ur own (where the sellcode starts). so it jumps to the adress u want to and not to somewhere else on every exploitation. or did i get anything wrong? if yes - sry - im still learning all this wink.gif

greetz,
buzz

it depends on how big the adress space is. but forget it I mixed it up with another 0day vulnerability (too many lately).
you cannot include a shellcode for this vulnerability because it allows no code execution or something its just good old DoS which stops the SSL service to respond to requests.

this one is what we have to wait for

Windows Local Security Authority Service Remote Buffer Overflow

smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.