vendor:
ophcrack
by:
xis_one@STM Solutions
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ophcrack
Affected Version From: 3.5.2000
Affected Version To: 3.5.2000
Patch Exists: NO
Related CWE:
CPE: a:ophcrack_project:ophcrack:3.5.0
Platforms Tested: Windows XP SP3
2013
ophcrack v3.5.0 – Local Code Execution BOF
Stack based buffer overflow - direct EIP overwrite in this case (SEH based exploitation is possible as well). In order to exploit go to: Load -> Remote SAM -> put the content of buffer.txt file generated by this exploit into the "Host name:" field -> "Don't send" once you see the crash. pwdump6_setup.exe will be run by ophrack.It will nicely crash and execute the payload. pwdump6_setup itself doesn't look to be exploitable outside of ophrack. Kudos to Hostess for pointing me to http://www.mattandreko.com/2013/04/buffer-overflow-in-hexchat-294.html
Mitigation:
Unknown