
Exploit
Exploit的英文意思就是利用,它在黑客眼里就是漏洞利用,有漏洞不一定就有Exploit(利用),有Exploit就肯定有漏洞。
我們幾乎每隔幾天就能聽到最近有一個新發(fā)現(xiàn)的可以被利用(exploit)的漏洞(vulnerability),然后給這個漏洞打上補丁。而事實上,這里面的內容比你想象的要多,因為你不可能知道所有軟件的漏洞,而且那些可利用的漏洞也只是被少數(shù)人所了解。
漏洞是存在于一個程序、算法或者協(xié)議中的錯誤,可能帶來一定的安全問題。但不是所有的漏洞都是能夠被利用來攻擊(exploitable)的,理論上存在的漏洞,并不代表這個漏洞足以讓攻擊者去威脅你的系統(tǒng)。一個漏洞不能攻擊一個系統(tǒng),并不代表兩個或多個漏洞組合就不能攻擊一個系統(tǒng)。例如:空指針對象引用(null-pointerdereferencing)漏洞可以導致系統(tǒng)崩潰(如果想做拒絕服務攻擊就足夠了),但是如果組合另外一個漏洞,將空指針指向一個你存放數(shù)據(jù)的地址并執(zhí)行,那么你可能就利用此來控制這個系統(tǒng)了。
一個利用程序(Anexploit)就是一段通過觸發(fā)一個漏洞(或者幾個漏洞)進而控制目標系統(tǒng)的代碼。攻擊代碼通常會釋放攻擊載荷(payload),里面包含了攻擊者想要執(zhí)行的代碼。exploits利用代碼可以在本地也可在遠程進行。一個遠程攻擊利用允許攻擊者遠程操縱計算機,理想狀態(tài)下能夠執(zhí)行任意代碼。遠程攻擊對攻擊者非常重要,因為攻擊者可以遠程控制他/她的主機,不需要通過其它手段(讓受害者訪問網(wǎng)站,點擊一個可執(zhí)行文件,打開一個郵件附件等等),而本地攻擊一般都是用來提升權限。
Sports Clubs Web Panel 0.0.1 Remote Game Delete Exploit
#!/usr/bin/perl -W # Sports Clubs Web Panel 0.0.1 Remote Game Delete Exploit # File affected: include/draw-delete.php (id) # Vuln Code: # 06: $did = $_GET['id']... 08-10-08pLink 2.07 (linkto.php id) Remote Blind SQL Injection Exploit
<?php ini_set("max_execution_time",0); print_r(' ############################################################### # # pLink 2.07 - ... 08-10-08Yourownbux 4.0 (COOKIE) Authentication Bypass Exploit
#!/usr/bin/perl use LWP::UserAgent; use HTTP::Request; # ------------------------------------------------------------------------------------------------- -# ... 08-10-08The Personal FTP Server 6.0f RETR Denial of Service Exploit
/* *** The Personal FTP Server 6.0f RETR DOS exploit *** A vulnerability exists in the way Personal FTP Server handles multiple RETR commands with overly long fil... 08-10-08Windows Media Encoder wmex.dll ActiveX BOF Exploit (MS08-053)
<html> <pre> ============================================================================= MS08-053 Windows Media Encoder wmex.dll ActiveX Control Buf... 08-10-08- <?php error_reporting(E_ALL); /////////////////////////////////////////////////////////////////////// ////////////////////////////////////////////////////////... 08-10-08
Debian Sarge Multiple IMAP Server Denial of Service Exploit
/* Debian Sarge Multiple IMAP Server DoS (debianimapers.c) Jeremy Brown [0xjbrown41@gmail.com/http://jbrownsec.blogspot.com] Testing Cyrus IMAPd: bash$ .... 08-10-08DESlock 3.2.7 (vdlptokn.sys) Local Denial of Service Exploit
//////////////////////////////////////////////////////////////////////////////////// // ---------------------------------------------------------------------------- ... 08-10-08Sagem Routers F@ST Remote CSRF Exploit (dhcp hostname attack)
#!/usr/bin/env python # # # # OOO OOO OO OOO # O O O ... 08-10-08- #!/usr/bin/perl # # CJ Ultra Plus <= v1.0.4 Cookie SQL Injection # # found and coded by -SmoG- /GermAn hAckZ0r # contact: ICQ - 266836394 # # # #... 08-10-08
Rianxosencabos CMS 0.9 Remote Add Admin Exploit
#!/usr/bin/perl -w # Rianxosencabos CMS 0.9 Remote Add Admin Exploit # Download: http://downloads.sourceforge.net/rsccms/rsccms.tar.gz # written by ka0x <ka0x01... 08-10-08- #!/usr/bin/perl # ---------------------------------------------------------- # iGaming <= 1.5 Multiple Remote SQL Injection Exploit # Perl Exploit - Output: i... 08-10-08
BurnAware NMSDVDXU ActiveX Remote Arbitrary File Creation/Execution
----------------------------------------------------------------------------- BurnAware NMSDVDXU ActiveX Control Remote Arbitrary File Creation/Execution url: http:... 08-10-08ESET Smart Security 3.0.667.0 Privilege Escalation PoC
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - Orange Bat advisory - Name : ESET Smart Security 3.0.667.0 Class : Privilage escalation P... 08-10-08EO Video 1.36 Local Heap Overflow DOS / PoC
#!/usr/bin/python # -------------------------------------------------------------- # EO Video v1.36 Heap Overflow local PoC/DoS exploit # *.eop playlist file in ... 08-10-08WS_FTP Home/Professional FTP Client Remote Format String PoC
################################################################################################################## # # Ipswitch WS_FTP Home/WS_FTP Professional FTP ... 08-10-08FlashGet 1.9.0.1012 (FTP PWD Response) BOF Exploit (safeseh)
#!/usr/bin/perl # k`sOSe 08/17/2008 # bypass safeseh using flash9f.ocx. use warnings; use strict; use IO::Socket; # win32_exec - EXITFUNC=seh CMD=calc Si... 08-10-08webEdition CMS (we_objectID) Blind SQL Injection Exploit
<?php ini_set("max_execution_time",0); print_r(' ############################################################### # # WebEdition CMS ... 08-10-08VMware Workstation (hcmon.sys 6.0.0.45731) Local DoS Vulnerability
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - Orange Bat advisory - Name : VMWare Workstation (hcmon.sys 6.0.0.45731) Class : DoS ... 08-10-08- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ~ Core Security Technologies - CoreLabs Advisory ~ http://www.coresecurity.com/corelabs/ ~ ... 08-10-08