본문 바로가기

Metasploit

Yokogawa CENTUM CS 3000 BKHOdeq.exe Buffer Overflow

728x90

Yokogawa CENTUM CS 3000 BKHOdeq.exe Buffer Overflow

This module exploits a stack based buffer overflow in Yokogawa CENTUM CS 3000. The vulnerability exists in the service BKHOdeq.exe when handling specially crafted packets. This module has been tested successfully on Yokogawa CENTUM CS 3000 R3.08.50 over Windows XP SP3 and Windows 2003 SP2.

Module Name

exploit/windows/scada/yokogawa_bkhodeq_bof

Authors

  • juan vazquez <juan.vazquez [at] metasploit.com>
  • Redsadic <julian.vilas [at] gmail.com>

References

Targets

  • Yokogawa CENTUM CS 3000 R3.08.50 / Windows [ XP SP3 / 2003 SP2 ]

Platforms

  • windows

Reliability

Development

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use exploit/windows/scada/yokogawa_bkhodeq_bof msf exploit(yokogawa_bkhodeq_bof) > show targets ...targets... msf exploit(yokogawa_bkhodeq_bof) > set TARGET <target-id> msf exploit(yokogawa_bkhodeq_bof) > show options ...show and set options... msf exploit(yokogawa_bkhodeq_bof) > exploit


728x90