
Exploit
Exploit的英文意思就是利用,它在黑客眼里就是漏洞利用,有漏洞不一定就有Exploit(利用),有Exploit就肯定有漏洞。
我們幾乎每隔幾天就能聽到最近有一個(gè)新發(fā)現(xiàn)的可以被利用(exploit)的漏洞(vulnerability),然后給這個(gè)漏洞打上補(bǔ)丁。而事實(shí)上,這里面的內(nèi)容比你想象的要多,因?yàn)槟悴豢赡苤浪熊浖穆┒矗夷切┛衫玫穆┒匆仓皇潜簧贁?shù)人所了解。
漏洞是存在于一個(gè)程序、算法或者協(xié)議中的錯(cuò)誤,可能帶來一定的安全問題。但不是所有的漏洞都是能夠被利用來攻擊(exploitable)的,理論上存在的漏洞,并不代表這個(gè)漏洞足以讓攻擊者去威脅你的系統(tǒng)。一個(gè)漏洞不能攻擊一個(gè)系統(tǒng),并不代表兩個(gè)或多個(gè)漏洞組合就不能攻擊一個(gè)系統(tǒng)。例如:空指針對(duì)象引用(null-pointerdereferencing)漏洞可以導(dǎo)致系統(tǒng)崩潰(如果想做拒絕服務(wù)攻擊就足夠了),但是如果組合另外一個(gè)漏洞,將空指針指向一個(gè)你存放數(shù)據(jù)的地址并執(zhí)行,那么你可能就利用此來控制這個(gè)系統(tǒng)了。
一個(gè)利用程序(Anexploit)就是一段通過觸發(fā)一個(gè)漏洞(或者幾個(gè)漏洞)進(jìn)而控制目標(biāo)系統(tǒng)的代碼。攻擊代碼通常會(huì)釋放攻擊載荷(payload),里面包含了攻擊者想要執(zhí)行的代碼。exploits利用代碼可以在本地也可在遠(yuǎn)程進(jìn)行。一個(gè)遠(yuǎn)程攻擊利用允許攻擊者遠(yuǎn)程操縱計(jì)算機(jī),理想狀態(tài)下能夠執(zhí)行任意代碼。遠(yuǎn)程攻擊對(duì)攻擊者非常重要,因?yàn)楣粽呖梢赃h(yuǎn)程控制他/她的主機(jī),不需要通過其它手段(讓受害者訪問網(wǎng)站,點(diǎn)擊一個(gè)可執(zhí)行文件,打開一個(gè)郵件附件等等),而本地攻擊一般都是用來提升權(quán)限。
- #!/usr/bin/perl use LWP::UserAgent; use Getopt::Long; # # [!] Discovered.: DNX # [!] Vendor.....: http://www.shooter-szene.de | http://www.ultrastats.o... 08-10-08
- -[*] ================================================================================ [*]- -[*] Real Estate Script <= 1.1 Remote SQL Injection Vulnerability ... 08-10-08
trixbox (langChoice) Local File Inclusion Exploit (connect-back)
#!/usr/bin/perl -w # Jean-Michel BESNARD - LEXSI Audit # 2008-07-08 # perl trixbox_fi.pl 192.168.1.212 # Please listen carefully as our menu option has chan... 08-10-08Boonex Dolphin 6.1.2 Multiple Remote File Inclusion Vulnerabilities
# Name Of Script : Dolphin PHP # Version : 6.1.2 # Download From : http://heanet.dl.sourceforge.net/sourceforge/boonex-dolphin/Dolphin-v.6.1.2-Free.zip # F... 08-10-08BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit
#!/usr/bin/perl #================================================= # BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit #==============================================... 08-10-08- -[*] ================================================================================ [*]- -[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability... 08-10-08
Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln
------------------------------------------------------------------------------------------- Joomla Component com_content SQL I... 08-10-08- #!/usr/bin/perl # k1tk4t Public Security Advisory # //////////////////////////////////////////////////////////// # AuraCMS <= 2.2.2 (pages_data.php) Arbitrary... 08-10-08
BoonEx Ray 3.5 (sIncPath) Remote File Inclusion Vulnerability
# Name Of Script : Ray # Version : 3.5 # Download From : http://get.boonex.com/Ray-v.3.5-Suite-Free # Found By : RoMaNcYxHaCkEr [ RoMaNTiC-TeaM ] ... 08-10-08Dreampics Builder (page) Remote SQL Injection Vulnerability
######################################################### # # PICS BUILDER (page) SQL Injection Vulnerability #==============================================... 08-10-08Download Accelerator Plus - DAP 8.x (m3u) Local BOF Exploit 0day
#!/usr/bin/python # Download Accelerator Plus - DAP 8.x (m3u) 0day Local Buffer Overflow Exploit # Bug discovered by Krystian Kloskowski (h07) <h07@interia.pl>... 08-10-08OllyDBG v1.10 and ImpREC v1.7f (export name) BOF PoC
;-------------------------------------------------------------------------; ; OllyDBG v1.10 and ImpREC v1.7f export name buffer overflow vulnerability ; PoC (probab... 08-10-08Download Accelerator Plus - DAP 8.x m3u File Buffer Overflow Exploit (c)
#include <stdio.h> #include <stdlib.h> /* DAP 8.x (.m3u) File BOF C Exploit for XP SP2,SP3 English SecurityFocus Advisory: Download Acceler... 08-10-08- ########################################################################## #### Felipe Andres Manzano * fmanzano@fceia.unr.edu.ar #### #### updates... 08-10-08
Wordpress 2.6.1 (SQL Column Truncation) Admin Takeover Exploit
#!/usr/bin/php <?php # ------------------------------------------------------------ # quick'n'dirty wordpress admin-take0ver poc # by iso^kpsbr in august 2... 08-10-08Adobe Acrobat 9 ActiveX Remote Denial of Service Exploit
<!-- Jeremy Brown (0xjbrown41@gmail.com/jbrownsec.blogspot.com) Adobe Acrobat 9 Remote DoS (--) Tested on AA9/IE7/Vista I can't seem to reproduce this ... 08-10-08minb 0.1.0 Remote Code Execution Exploit
#!/usr/bin/python ##################################################################################### #### minb Remote Code Execution Exploit ... 08-10-08Maxthon Browser 2.1.4.443 UNICODE Remote Denial of Service PoC
<!-- Maxthon Browser 2.1.4.443 UNICODE Remote Denial of Service PoC Summary: Maxthon Browser is a powerful tabbed browser built for all users. Besides basi... 08-10-08Easy Photo Gallery 2.1 XSS/FD/Bypass/SQL Injection Exploit
#!/usr/bin/perl #---------------------------------------------------------------- # #Script : Ezphotogallery 2.1 # #Type : Multiple Vulnerabilities ( Xss/L... 08-10-08phsBlog 0.2 Bypass SQL Injection Filtering Exploit
#!/usr/bin/perl #---------------------------------------------------------------- # #Script : PhsBlog v0.2 # #Type : Bypass Sql injection Filtering Exploit... 08-10-08