Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3361. PoCs published by Wojciech Pawlikowski, Koshi.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in IntelliTamper 2.07 via a maliciously crafted HTTP Location header. It uses a standard stack-based overflow with a NOP sled, a return address override (0x7c941EED from ntdll.dll), and Metasploit-generated Alpha2-encoded shellcode to achieve remote code execution.
Description
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header.
Exploits (2)
This exploit targets a buffer overflow vulnerability in IntelliTamper 2.07 via a maliciously crafted HTTP Location header. It uses a standard stack-based overflow with a NOP sled, a return address override (0x7c941EED from ntdll.dll), and Metasploit-generated Alpha2-encoded shellcode to achieve remote code execution.
This exploit targets a buffer overflow vulnerability in IntelliTamper 2.07 via a maliciously crafted HTTP 'Server' header. It uses a call to ESP in NTDLL.DLL to execute Alpha2-encoded shellcode that spawns calc.exe.