Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ##########################################################
- ### ~EVERYTHING STAGEFRIGHT~ (Constantly updating) ###
- ##########################################################
- VIDEO TUTORIAL W/ download links: https://www.youtube.com/watch?v=zlLtJ6wfguw
- #########################---------------------------------------------- + ----------------------------------------------#########################
- .mp4 CVE Exploit for RCE Vulnerability CVE-2015-1538 #1: https://github.com/jduck/cve-2015-1538-1/blob/master/Stagefright_CVE-2015-1538-1_Exploit.py
- # Integer Overflow in the libstagefright MP4 'stsc' atom handling
- #
- # Don't forget, the output of "create_mp4" can be delivered many ways!
- # MMS is the most dangerous attack vector, but not the only one...
- #
- # DISCLAIMER: This exploit is for testing and educational purposes only. Any
- # other usage for this code is not allowed. Use at your own risk.
- #
- # "With great power comes great responsibility." - Uncle Ben
- #########################---------------------------------------------- + ----------------------------------------------#########################
- https://blog.zimperium.com/stagefright-vulnerability-details-stagefright-detector-tool-released/
- https://github.com/WhisperSystems/TextSecure/issues/3817
- https://github.com/omxcodec/stagefright-plugins
- https://www.kb.cert.org/vuls/id/924951
- https://source.android.com/devices/media.html
- http://www.linuxveda.com/2015/07/29/stagefright-worst-android-exploit/
- https://github.com/WhisperSystems/TextSecure/issues/3817
- http://www.droidfeed.net/2015/08/latest-cyanogenmod-12-1-nightly-not-affected-by-stagefright-exploit/
- #########################---------------------------------------------- + ----------------------------------------------#########################
- POC: https://s3.amazonaws.com/zhafiles/Zimperium-Handset-Alliance/ZHA-Crash-PoC.zip
- Patch: https://s3.amazonaws.com/zhafiles/Zimperium-Handset-Alliance/ZHA-Stagefright-Patches.zip
- MMS Disable App: https://s3.amazonaws.com/zhafiles/Zimperium-Handset-Alliance/Samsung_KNOX_and_ZHA_ap_MMSCtrl.apk
- STAGEFRIGHT DETECTOR APP
- Today Zimperium launched the ‘Stagefright detector App’ for Android users to test if their device is vulnerable. The app is available for download on the Android store. Download link: https://play.google.com/store/apps/details?id=com.zimperium.stagefrightdetector
- - See more at: https://blog.zimperium.com/stagefright-vulnerability-details-stagefright-detector-tool-released/#sthash.Wgztldfv.dpuf
- SOURCES: https://pastebin.com/fhx47gx2
- #########################---------------------------------------------- + ----------------------------------------------#########################
- CVE-2015-1538, P0006, Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
- CVE-2015-1538, P0004, Google Stagefright ‘ctts’ MP4 Atom Integer Overflow Remote Code Execution
- CVE-2015-1538, P0004, Google Stagefright ‘stts’ MP4 Atom Integer Overflow Remote Code Execution
- CVE-2015-1538, P0004, Google Stagefright ‘stss’ MP4 Atom Integer Overflow Remote Code Execution
- CVE-2015-1539, P0007, Google Stagefright ‘esds’ MP4 Atom Integer Underflow Remote Code Execution
- CVE-2015-3827, P0008, Google Stagefright ‘covr’ MP4 Atom Integer Underflow Remote Code Execution
- CVE-2015-3826, P0009, Google Stagefright 3GPP Metadata Buffer Overread
- CVE-2015-3828, P0010, Google Stagefright 3GPP Integer Underflow Remote Code Execution
- CVE-2015-3824, P0011, Google Stagefright ‘tx3g’ MP4 Atom Integer Overflow Remote Code Execution
- CVE-2015-3829, P0012, Google Stagefright ‘covr’ MP4 Atom Integer Overflow Remote Code Execution - See more at: https://blog.zimperium.com/stagefright-vulnerability-details-stagefright-detector-tool-released/#sthash.Wgztldfv.dpuf
- ##########################################################
- //BaSs_HaXoR
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement