
Exploit
Exploit的英文意思就是利用,它在黑客眼里就是漏洞利用,有漏洞不一定就有Exploit(利用),有Exploit就肯定有漏洞。
我们几乎每隔几天就能听到最近有一个新发现的可以被利用(exploit)的漏洞(vulnerability),然后给这个漏洞打上补丁。而事实上,这里面的内容比你想象的要多,因为你不可能知道所有软件的漏洞,而且那些可利用的漏洞也只是被少数人所了解。
漏洞是存在于一个程序、算法或者协议中的错误,可能带来一定的安全问题。但不是所有的漏洞都是能够被利用来攻击(exploitable)的,理论上存在的漏洞,并不代表这个漏洞足以让攻击者去威胁你的系统。一个漏洞不能攻击一个系统,并不代表两个或多个漏洞组合就不能攻击一个系统。例如:空指针对象引用(null-pointerdereferencing)漏洞可以导致系统崩溃(如果想做拒绝服务攻击就足够了),但是如果组合另外一个漏洞,将空指针指向一个你存放数据的地址并执行,那么你可能就利用此来控制这个系统了。
一个利用程序(Anexploit)就是一段通过触发一个漏洞(或者几个漏洞)进而控制目标系统的代码。攻击代码通常会释放攻击载荷(payload),里面包含了攻击者想要执行的代码。exploits利用代码可以在本地也可在远程进行。一个远程攻击利用允许攻击者远程操纵计算机,理想状态下能够执行任意代码。远程攻击对攻击者非常重要,因为攻击者可以远程控制他/她的主机,不需要通过其它手段(让受害者访问网站,点击一个可执行文件,打开一个邮件附件等等),而本地攻击一般都是用来提升权限。
Belkin wireless G router ADSL2 modem Auth Bypass Exploit
<html> <head> </head> <body> <b>html code to bypass the webinterface password protection of the Belkin wireless G router adsl2... 2008-10-08Pars4U Videosharing V1 XSS / Remote Blind SQL Injection Exploit
#!/usr/bin/perl use LWP::UserAgent; use Getopt::Long; if(!$ARGV[1]) { print " n&quo... 2008-10-08- ################################################################################ [ ] NoName Script 1.1 BETA Multiple Remote Vulnerabilities [ ] Discovered By SirG... 2008-10-08
- #!/usr/bin/perl use warnings; use strict; use LWP::UserAgent; use HTTP::Request::Common; print <<INTRO; ... 2008-10-08
Dana IRC 1.4a Remote Buffer Overflow Exploit
#!/usr/bin/perl # k`sOSe - 08/24/2008 # This is a useless and not portable exploit code, tested only on my winxp-sp3 VM. # I was looking for a vuln to write an ex... 2008-10-08Ultra Office ActiveX Control Remote Arbitrary File Corruption Exploit
----------------------------------------------------------------------------- Ultra Office ActiveX Control Remote Arbitrary File Corruption url: http://www.ultrashare... 2008-10-08- <? /* sIMPLE php bLOG 0.5.0 eXPLOIT bY mAXzA 2008 */ function curl($url,$postvar){ global $cook; $ch = curl_init( $url ); curl_seto... 2008-10-08
- #!/usr/bin/perl # # Acoustica Mixcraft (mx4 file) Local Buffer Overflow Exploit # Author: Koshi # # Date: 08-28-08 ( 0day ) # Application: Acoustica Mixcraft ... 2008-10-08
- <?php // forum mybb <= 1.2.11 remote sql injection vulnerability // bug found by Janek Vind "waraxe" http://www.waraxe.us/advisory-64.html // exp... 2008-10-08
Microsoft Visual Studio (Msmask32.ocx) ActiveX Remote BOF Exploit
Microsoft Visual Studio (Msmask32.ocx) ActiveX Remote Buffer Overflow Exploit Author: Koshi Original POC: http://www.milw0rm.com/exploits/6244 ( Not by me ) My fir... 2008-10-08Ultra Office ActiveX Control Remote Buffer Overflow Exploit
----------------------------------------------------------------------------- Ultra Office ActiveX Control Remote Buffer Overflow url: http://www.ultrashareware.com... 2008-10-08IntelliTamper 2.07 (imgsrc) Remote Buffer Overflow Exploit
/* * IntelliTamper 2.07 (imgsrc) Remote Buffer Overflow Expoit * * Discovered & Written by r0ut3r (writ3r [at] gmail.com) * Many Thanks to Luigi Auriemma ... 2008-10-08Friendly Technologies (fwRemoteCfg.dll) ActiveX Remote BOF Exploit
<!-- "Friendly Technologies" provide software like L2TP and PPPoE clients to ISPs, who give the software to their customers on CD so they have less troub... 2008-10-08Friendly Technologies (fwRemoteCfg.dll) ActiveX Command Exec Exploit
<!-- In addition to the overflow found in the "Friendly Technologies" dialers ActiveX, Here is a "remote command execution" exploit. Its so s... 2008-10-08Joomla Component EZ Store Remote Blind SQL Injection Exploit
#!/usr/bin/perl #Note:Sometimes you have to change the regexp to viewcategory/catid,".$cid." use LWP::UserAgent; use Getopt::Long; if(!$ARGV[1]) ... 2008-10-08moziloCMS 1.10.1 (download.php) Arbitrary Download File Exploit
#!/usr/bin/perl # # moziloCMS 1.10.1 Perl exploit # # discovered & written by Ams # ax330d [doggy] gmail [dot] com # # DESCRIPTION: # Vulnerability hides ... 2008-10-08Xerox Phaser 8400 (reboot) Remote Denial of Service Exploit
#!/usr/bin/perl # carved-out by: crit3rion, just making th3 world a b3tt3r plac3! # Xerox_Remote_DoS.20080801.ver01 (tanx to dr0pz0N3 for reminding me to close my #... 2008-10-08LoveCMS 1.6.2 Final Remote Code Execution Exploit
#!/usr/bin/ruby # ## Exploit by PoMdaPiMp! ## --------------------- ## pomdapimp(at)gmail(dotcom) ## ## LoveCMS Exploit Series ## Episode 1: ad... 2008-10-08BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (spoof on ircd)
/* h0dns_spoof.c - zmda - saik0pod@yahoo.com * - spoof dns on ircd's using the h0dns code * * - spoof dns on anything using the adns (asynchronous dns resolv... 2008-10-08TGS CMS 0.3.2r2 Remote Code Execution Exploit
# TGS CMS Remote Code Execution Exploit # by 0in # from Dark-Coders Group! # www.dark-coders.pl # Contact: 0in(dot)email[at]gmail(dot)com # Greetings to:... 2008-10-08

