
Exploit
Exploit的英文意思就是利用,它在黑客眼里就是漏洞利用,有漏洞不一定就有Exploit(利用),有Exploit就肯定有漏洞。
我們幾乎每隔幾天就能聽到最近有一個(gè)新發(fā)現(xiàn)的可以被利用(exploit)的漏洞(vulnerability),然后給這個(gè)漏洞打上補(bǔ)丁。而事實(shí)上,這里面的內(nèi)容比你想象的要多,因?yàn)槟悴豢赡苤浪熊浖穆┒?,而且那些可利用的漏洞也只是被少?shù)人所了解。
漏洞是存在于一個(gè)程序、算法或者協(xié)議中的錯(cuò)誤,可能帶來一定的安全問題。但不是所有的漏洞都是能夠被利用來攻擊(exploitable)的,理論上存在的漏洞,并不代表這個(gè)漏洞足以讓攻擊者去威脅你的系統(tǒng)。一個(gè)漏洞不能攻擊一個(gè)系統(tǒng),并不代表兩個(gè)或多個(gè)漏洞組合就不能攻擊一個(gè)系統(tǒng)。例如:空指針對(duì)象引用(null-pointerdereferencing)漏洞可以導(dǎo)致系統(tǒng)崩潰(如果想做拒絕服務(wù)攻擊就足夠了),但是如果組合另外一個(gè)漏洞,將空指針指向一個(gè)你存放數(shù)據(jù)的地址并執(zhí)行,那么你可能就利用此來控制這個(gè)系統(tǒng)了。
一個(gè)利用程序(Anexploit)就是一段通過觸發(fā)一個(gè)漏洞(或者幾個(gè)漏洞)進(jìn)而控制目標(biāo)系統(tǒng)的代碼。攻擊代碼通常會(huì)釋放攻擊載荷(payload),里面包含了攻擊者想要執(zhí)行的代碼。exploits利用代碼可以在本地也可在遠(yuǎn)程進(jìn)行。一個(gè)遠(yuǎn)程攻擊利用允許攻擊者遠(yuǎn)程操縱計(jì)算機(jī),理想狀態(tài)下能夠執(zhí)行任意代碼。遠(yuǎn)程攻擊對(duì)攻擊者非常重要,因?yàn)楣粽呖梢赃h(yuǎn)程控制他/她的主機(jī),不需要通過其它手段(讓受害者訪問網(wǎng)站,點(diǎn)擊一個(gè)可執(zhí)行文件,打開一個(gè)郵件附件等等),而本地攻擊一般都是用來提升權(quán)限。
Wordpress Plugin Download Manager 0.2 Arbitrary File Upload Exploit
<a name="upload-file"></a><h2>WORDPRESS PLUGIN DOWNLOAD MANAGER 0.2 REMOTE FILE UPLOAD</h2> <h3>SaO</h3> <h4>Biy... 08-10-08Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit
/* Microsoft Access Snapshot Viewer ActiveX Control Exploit Ms-Acees SnapShot Exploit Snapview.ocx v 10.0.5529.0 Download nice binaries into an arbitrary box ... 08-10-08BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (c)
/* * Exploit for CVE-2008-1447 - Kaminsky DNS Cache Poisoning Attack * * Compilation: * $ gcc -o kaminsky-attack kaminsky-attack.c `dnet-config --libs` -lm ... 08-10-08Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control BOF Exploit
<!-- Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control Buffer Overflow Exploit written by e.b. Tested on Windows XP SP2(fully patched) English, IE6 IE7,... 08-10-08- # Author: __GiReX__ 26/07/08 # Homepage: girex.altervista.org # CMS: IceBB <= 1.0-RC9.2 # Site: icebb.net # Bug: Blind SQL Injection # Exploit: Session Hi... 08-10-08
e107 Plugin BLOG Engine 2.2 Blind SQL Injection Exploit
#!/usr/bin/perl ##################################################################################### # e107 Plugin BLOG Engine v2.2 Blind SQL Injection Ex... 08-10-08Cisco IOS 12.3(18) FTP Server Remote Exploit (attached to gdb)
/* Cisco IOS FTP server remote exploit by Andy Davis 2008 Cisco Advisory ID:... 08-10-08HIOX Browser Statistics 2.0 Arbitrary Add Admin User Exploit
<?php @session_start(); ?> <table align=center width=72% height=95% ><tr><td> <?php /* HIOX Browser Statistics 2.0 Arbitrary ... 08-10-08HIOX Random Ad 1.3 Arbitrary Add Admin User Exploit
<?php @session_start(); ?> <table align=center width=72% height=95% ><tr><td> <?php /* HIOX Random Ad 1.3 Arbitrary Add Admin... 08-10-08eNdonesia 8.4 (Calendar Module) Remote SQL Injection Exploit
#!/usr/bin/perl #/----------------------------------------------- #| /----------------------------------------- | #| | Remote SQL Exploit | ... 08-10-08CoolPlayer m3u File Local Buffer Overflow Exploit
#!/usr/bin/perl # k`sOSe - 07/29/2008 use warnings; use strict; # http://www.metasploit.com # EXITFUNC=seh, CMD=c:WINDOWSsystem32calc.exe # [*] x86/shikat... 08-10-08- #!/usr/bin/perl -w use LWP::UserAgent; use MIME::Base64; use Digest::MD5 qw(md5_hex); use Getopt::Std; getopts('h:', %args); print "##########... 08-10-08
NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow Exploit
----------------------------------------------------------------------------- NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow url: http://www.nctsoft.com ... 08-10-08- #!/usr/bin/perl # Simple DNS Plus 5.0/4.1 < remote Denial of Service exploit # # usage: sdns-dos.pl <dns server> <dns source port> <num of pack... 08-10-08
Yahoo Messenger 8.1 ActiveX Remote Denial of Service Exploit
Yahoo Messenger 8.1 (latest) Remote DoS Safe for Scripting, Safe for Initialize <html><body> <object id=target classid=clsid:02478D38-C3F9... 08-10-08Document Imaging SDK 10.95 ActiveX Buffer Overflow PoC
<!-- Document Imaging SDK Buffer Overflow Vulnerability DoS Proof of concept Author: r0ut3r Mail : writ3r [at] gmail.com --------------... 08-10-08WinRemotePC Full Lite 2008 r.2server Denial of Service Exploit
#include <stdio.h> #include <stdlib.h> #include <sys/socket.h> #include <sys/types.h> #include <netinet/in.h> #include <string.... 08-10-08Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
#// Bea Weblogic -- Apache Connector Remote Exploit -1day #// Should stack break latest Windows Server 2003 <address space randomization> #// BIG THANKS TO ... 08-10-08AlstraSoft Article Manager Pro 1.6 Blind SQL Injection Exploit
#/usr/bin/perl #| | Author: GoLd_M #--//--> # -- AlstraSoft Article Manager Pro Blind SQL Injection Exploit -- #--//--> Exploit : use strict; use... 08-10-08PPMate PPMedia Class ActiveX Control Buffer Overflow PoC
<html> <body> <object id=target classid=clsid:72B15B25-2EC8-4CDD-B284-C89A5F8E8D5F></object> <script language=vbscript> arg1=... 08-10-08