Jump to content
SlicK

0day Yahoo Messenger remote BOF

Recommended Posts

Posted

Yahoo Messenger remote BOF

Autor: SlicK

Data: 29 Aug 2007

Website: http://www.rstcenter.com

Email: slick@rstcenter.com

Atunci cand este initiat un transfer de fisiere pachetul trimis va contine un cod unic care identifica respectivul transfer.

Daca transferul este oprit de la orice capat si victima inchide fereastra respectiva un nou pachet trimis cu

acelasi cod unic va cauza crashuirea procesului "yahoomessenger.exe" al victimei.

Victima TREBUIE sa inchida fereastra cu transferul altfel procesul nu va crashui.

Exploit: http://www.rootb0x.com/0X0/ym78bug.rar

Testat pe:

7.0.0.437 (WinXP SP2)

7.5.0.647 (WinXP SP2)

8.1.0.209 (WinXP SP2)

8.1.0.249 (WinXP SP2)

8.1.0.401 (WinXP SP2)

8.1.0.402 (WinXP SP2)

8.1.0.415 (WinXP SP2)

8.1.0.419 (WinXP SP2)

Pe versiuni mai mici de 7 nu functioneaza

Greets to vladiii&amprenta

EDIT: Am rezolvat problemele de logare. Linkul de download este acelasi ;)

Guest Nemessis
Posted

Nici la mine nu merge. Slick vezi ca poate mai poti adauga niste servere prin care sa se conecteze.

Posted

Incercati sa va conectat si pe:

cs1.msg.dcn.yahoo.com:80

cs2.msg.dcn.yahoo.com:80

cs3.msg.dcn.yahoo.com:80

etc.

Pe astea ar trebui sa mearga ! Mie mi-a mers perfect ! ;)

Bafta !!! Si bravo SlicK ! :roll:

LE: Slick, urmatorul obiectiv: executia de cod remote :D

Guest Nemessis
Posted

Neah, tot nu merge. O fi de la mine cine stie. Lasand toate astea la o parte, good work Slick!

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...