Full Version: Boomerang.pl
h4x0re
hello freinds, i assume u guys already know what boomerang is (apache chunked exploiter) have any of u guys used this program? i ask because when i use this program i get this outcome

[*] Listener started on port 666
[*] Using padding size of 360 for server: Apache/1.3.14 (Win32)

[*] Shellcode size is 445 bytes
[*] Using 360 bytes of padding with jmp address 0x1c0f143c
[*] Exploit request is 8578 bytes
[*] Sending 8578 bytes to remote host.
[*] Waiting for shell to spawn.
Unrecognized signal name "USR2" at C:\boom.pl line 242.

i dont know what this error means, but im starting to think maybe i have a bad file. if so can one of u guys maybe upload this? thanks alot freinds


p.s. Hack for fun not to harm wink.gif
MpR
I used this tool before didnt work worth a damn but meh here it is

Grab it at www.google.com

it turns into http://www.digitaldefense.net/labs/securitytools.html

wink.gif
skydance
it works but not from windows.
h4x0re
digital defense is the site i got it from :\
Diablotic
I have identical prob.
Anyone can help??
Cow|
That version of boomerang.pl is (filtered) there is a good/fixed version around of it on the net( got it but lost it with a hdd crash)
Diablotic
Hmmm i couldn't find any other version. Everywhere is that version 12,7 kb.
Do anyone have better version? I need it so much!
predx
is it possible to use pearl to exe?
JaANDniET
yes bro, make a little search for perl2exe
dry.gif
popo0421

This boomerang.pl isn't work. I try to exploit myself linux Host. but failed.
KoNh
QUOTE (popo0421 @ Jan 7 2004, 12:35 AM)
This boomerang.pl isn't work. I try to exploit myself linux Host. but failed.

So you try to own linux host with a win32 exploit hmmmm
no surprise it doesn't work, see:

boomerang.pl - Apache Win32 Chunked Encoding Exploit
======================================================

oh well maybe I don't understand english enough ?! ^^
popo0421

sorry for my type error.
I try Boomerang.pl to exploit my win32 host. but failed.
Anyone try this exploit success?
strasharo
Damn, i crashed 3 Apaches with it (versions 1.3.19;1.3.20;1.3.22),that means that the mashines are vulnerable but something with the exploit is not O.K..
sad.gif
DrI
QUOTE (JaANDniET @ Jan 4 2004, 10:22 AM)
yes bro, make a little search for perl2exe
dry.gif

Perl 2 Exe is crap - perlapp all the way.
BaLooN
QUOTE(h4x0re @ Oct 16 2003, 02:45 PM)
hello freinds, i assume u guys already know what boomerang is (apache chunked exploiter) have any of u guys used this program? i ask because when i use this program i get this outcome

[*] Listener started on port 666
[*] Using padding size of 360 for server: Apache/1.3.14 (Win32)

[*] Shellcode size is 445 bytes
[*] Using 360 bytes of padding with jmp address 0x1c0f143c
[*] Exploit request is 8578 bytes
[*] Sending 8578 bytes to remote host.
[*] Waiting for shell to spawn.
Unrecognized signal name "USR2" at C:\boom.pl line 242.

i dont know what this error means, but im starting to think maybe i have a bad file. if so can one of u guys maybe upload this? thanks alot freinds


p.s. Hack for fun not to harm wink.gif
*



Run it from cygwin. And make sure to install the perl-libwin32 package under system when u choose packages to install.
Cus the exploit isn't working when i run in cmd. But working when using cygwin.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.