Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Tutorial: VNC Buffer Overflow

Loading...

Sign in or sign up now!
19,657
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Mar 11, 2008

Using Metasploit for a Buffer Overflow attack

My favorite video: http://www.youtube.com/watch?v=z00kuZIVXlU

Visit us at http://binslashshell.wordpress.com and join our growing community! UltraVNC v1.01 client buffer overflow...Using server 192.168.1.102 on my wlan, I force the VNC viewer to crash and attempt to launch shellcode by overwriting data on the stack. I'm pretty sure DEP isn't letting the shellcode run completely.

Category:

Entertainment

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Uploader Comments (ajatkinson2004)

  • wtf are you using windows lol, backtrack much more efficient

  • @Tajnost1337 well yeah but EVERYBODY shows it using Backtrack. I figured I'd use the Windows version for laughs. You'll notice I use various OSs in my videos so people know its diverse.

  • does the victim need to be running vnc client? Or can you just hack some computer running windows only remotely?

  • Gotta be running VNC. And they must be running a vulnerable version for it to work. Google "VNC Vulnerability" to find out which version are effected.

see all

All Comments (30)

Sign In or Sign Up now to post a comment!
  • this video would be way more useful if you would just use a god dam mic

    what is it with you noob hacker types playing songs in videos.

  • post a better resolution , plz !

  • Do you think that there's always a vulnerability in any internet connection no matter what people do? But can we use these vulnerabilities untraced and undetected you think? Is it possible to gain control while keeping it not known? And can they trace me through a proxy network? Probably right?

  • yes

  • This exploit uses VNC. There are several exploits that can be used if VNC isn't running. But since you asked this 11 months ago, I trust you know that by now.

  • Yes with netcat you probably could. Netcat can essentially and effectively take control of things like ssh and file sharing ports. Even though these aren't necessarily "programs" they are "services" You could then pump data in and suck data out.

  • And don't forget, older versions of VNC store a hash of the password in the registry which is easily decrypted.

  • yes you can check out my channel =)

    Zero Code

Loading...
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more