module

Savant 3.1 Web Server Overflow

Disclosed
2002-09-10
Created
2018-05-30

Description

This module exploits a stack buffer overflow in Savant 3.1 Web Server. The service
supports a maximum of 10 threads (for a default install). Each exploit attempt
generally causes a thread to die whether successful or not. Therefore, in a default
configuration, you only have 10 chances.

Due to the limited space available for the payload in this exploit module, use of the
"ord" payloads is recommended.

Author

aushack patrick@osisecurity.com.au

Platform

Windows

Architectures

x86

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/windows/http/savant_31_overflow
msf exploit(savant_31_overflow) > show targets
...targets...
msf exploit(savant_31_overflow) > set TARGET < target-id >
msf exploit(savant_31_overflow) > show options
...show and set options...
msf exploit(savant_31_overflow) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.