/crush

I'm not an MPlayer, I just Crush a lot.

Primary LanguageCGNU General Public License v2.0GPL-2.0

crush

I'm not an MPlayer, I just Crush a lot.

This is a payload generator for exploiting LZO based multi-media players. The demonstration payloads target MPlayer2, as that application does not require more than one vulnerability to gain full remote code execution.

All other applications based on FFmpeg/Libav are exploitable, but require multiple vulnerabilities to disclose memory addresses, or to place data at certain locations in memory.

Use for testing or demonstration purposes only.

Don A. Bailey @InfoSecMouse https://www.securitymouse.com/vulnerability