
Exploit
Exploit的英文意思就是利用,它在黑客眼里就是漏洞利用,有漏洞不一定就有Exploit(利用),有Exploit就肯定有漏洞。
我们几乎每隔几天就能听到最近有一个新发现的可以被利用(exploit)的漏洞(vulnerability),然后给这个漏洞打上补丁。而事实上,这里面的内容比你想象的要多,因为你不可能知道所有软件的漏洞,而且那些可利用的漏洞也只是被少数人所了解。
漏洞是存在于一个程序、算法或者协议中的错误,可能带来一定的安全问题。但不是所有的漏洞都是能够被利用来攻击(exploitable)的,理论上存在的漏洞,并不代表这个漏洞足以让攻击者去威胁你的系统。一个漏洞不能攻击一个系统,并不代表两个或多个漏洞组合就不能攻击一个系统。例如:空指针对象引用(null-pointerdereferencing)漏洞可以导致系统崩溃(如果想做拒绝服务攻击就足够了),但是如果组合另外一个漏洞,将空指针指向一个你存放数据的地址并执行,那么你可能就利用此来控制这个系统了。
一个利用程序(Anexploit)就是一段通过触发一个漏洞(或者几个漏洞)进而控制目标系统的代码。攻击代码通常会释放攻击载荷(payload),里面包含了攻击者想要执行的代码。exploits利用代码可以在本地也可在远程进行。一个远程攻击利用允许攻击者远程操纵计算机,理想状态下能够执行任意代码。远程攻击对攻击者非常重要,因为攻击者可以远程控制他/她的主机,不需要通过其它手段(让受害者访问网站,点击一个可执行文件,打开一个邮件附件等等),而本地攻击一般都是用来提升权限。
Wordpress Plugin Download Manager 0.2 Arbitrary File Upload Exploit
<a name="upload-file"></a><h2>WORDPRESS PLUGIN DOWNLOAD MANAGER 0.2 REMOTE FILE UPLOAD</h2> <h3>SaO</h3> <h4>Biy... 2008-10-08Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit
/* Microsoft Access Snapshot Viewer ActiveX Control Exploit Ms-Acees SnapShot Exploit Snapview.ocx v 10.0.5529.0 Download nice binaries into an arbitrary box ... 2008-10-08BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (c)
/* * Exploit for CVE-2008-1447 - Kaminsky DNS Cache Poisoning Attack * * Compilation: * $ gcc -o kaminsky-attack kaminsky-attack.c `dnet-config --libs` -lm ... 2008-10-08Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control BOF Exploit
<!-- Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control Buffer Overflow Exploit written by e.b. Tested on Windows XP SP2(fully patched) English, IE6 IE7,... 2008-10-08- # Author: __GiReX__ 26/07/08 # Homepage: girex.altervista.org # CMS: IceBB <= 1.0-RC9.2 # Site: icebb.net # Bug: Blind SQL Injection # Exploit: Session Hi... 2008-10-08
e107 Plugin BLOG Engine 2.2 Blind SQL Injection Exploit
#!/usr/bin/perl ##################################################################################### # e107 Plugin BLOG Engine v2.2 Blind SQL Injection Ex... 2008-10-08Cisco IOS 12.3(18) FTP Server Remote Exploit (attached to gdb)
/* Cisco IOS FTP server remote exploit by Andy Davis 2008 Cisco Advisory ID:... 2008-10-08HIOX Browser Statistics 2.0 Arbitrary Add Admin User Exploit
<?php @session_start(); ?> <table align=center width=72% height=95% ><tr><td> <?php /* HIOX Browser Statistics 2.0 Arbitrary ... 2008-10-08HIOX Random Ad 1.3 Arbitrary Add Admin User Exploit
<?php @session_start(); ?> <table align=center width=72% height=95% ><tr><td> <?php /* HIOX Random Ad 1.3 Arbitrary Add Admin... 2008-10-08eNdonesia 8.4 (Calendar Module) Remote SQL Injection Exploit
#!/usr/bin/perl #/----------------------------------------------- #| /----------------------------------------- | #| | Remote SQL Exploit | ... 2008-10-08CoolPlayer m3u File Local Buffer Overflow Exploit
#!/usr/bin/perl # k`sOSe - 07/29/2008 use warnings; use strict; # http://www.metasploit.com # EXITFUNC=seh, CMD=c:WINDOWSsystem32calc.exe # [*] x86/shikat... 2008-10-08- #!/usr/bin/perl -w use LWP::UserAgent; use MIME::Base64; use Digest::MD5 qw(md5_hex); use Getopt::Std; getopts('h:', %args); print "##########... 2008-10-08
NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow Exploit
----------------------------------------------------------------------------- NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow url: http://www.nctsoft.com ... 2008-10-08- #!/usr/bin/perl # Simple DNS Plus 5.0/4.1 < remote Denial of Service exploit # # usage: sdns-dos.pl <dns server> <dns source port> <num of pack... 2008-10-08
Yahoo Messenger 8.1 ActiveX Remote Denial of Service Exploit
Yahoo Messenger 8.1 (latest) Remote DoS Safe for Scripting, Safe for Initialize <html><body> <object id=target classid=clsid:02478D38-C3F9... 2008-10-08Document Imaging SDK 10.95 ActiveX Buffer Overflow PoC
<!-- Document Imaging SDK Buffer Overflow Vulnerability DoS Proof of concept Author: r0ut3r Mail : writ3r [at] gmail.com --------------... 2008-10-08WinRemotePC Full Lite 2008 r.2server Denial of Service Exploit
#include <stdio.h> #include <stdlib.h> #include <sys/socket.h> #include <sys/types.h> #include <netinet/in.h> #include <string.... 2008-10-08Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
#// Bea Weblogic -- Apache Connector Remote Exploit -1day #// Should stack break latest Windows Server 2003 <address space randomization> #// BIG THANKS TO ... 2008-10-08AlstraSoft Article Manager Pro 1.6 Blind SQL Injection Exploit
#/usr/bin/perl #| | Author: GoLd_M #--//--> # -- AlstraSoft Article Manager Pro Blind SQL Injection Exploit -- #--//--> Exploit : use strict; use... 2008-10-08PPMate PPMedia Class ActiveX Control Buffer Overflow PoC
<html> <body> <object id=target classid=clsid:72B15B25-2EC8-4CDD-B284-C89A5F8E8D5F></object> <script language=vbscript> arg1=... 2008-10-08

