42 bytes small Linux/x86 execve(/bin/dash) shellcode.
a6a775fc91f31c9ed92c9a6b4fc4bc0eLinux/x86 nc -lvve/bin/sh -p13377 shellcode.
5087da60dad719fa86a58f7745885b72189 bytes small add user t0r with password of Winner shellcode for Linux x86_64.
16d52bf5441ee8466099182427d9c537Sysax Multi Server versions 5.53 and below SSH username buffer overflow pre-authentication remote code execution exploit with egghunter shellcode that binds a shell to port 4444.
efa4237db0195980bc7a8d07b894b4a8Sysax Multi Server version 5.53 SFTP post authentication SEH exploit with egghunter shellcode that binds a shell to port 4444.
9ebc939a18d9148892f51f798563dd3762 bytes small Linux/x86 BackShell-TCP bash[/dev/tcp],execve(/bin/sh) shellcode.
dd08110ce2074ee6db7bef28f638cd26This Metasploit module exploits a flaw within the handling of MixerSequencer objects in Java 6u18 and before. Exploitation id done by supplying a specially crafted MIDI file within an RMF File. When the MixerSequencer objects is used to play the file, the GM_Song structure is populated with a function pointer provided by a SONG block in the RMF. A Midi block that contains a MIDI with a specially crafted controller event is used to trigger the vulnerability. When triggering the vulnerability "ebx" points to a fake event in the MIDI file which stores the shellcode. A "jmp ebx" from msvcr71.dll is used to make the exploit reliable over java updates.
832d568f84262995932885096374fd29Win32 speaking shellcode that says "You are owned!" when injected into a process.
99f385bd5fa8d2441dadf37cbc51df9e97 bytes small OS X / x86 shellcode that binds a shell to port 4444.
16e21c56bf3f6e3c145721c99e4d1712Sysax Multi Server version 5.52 and below file rename buffer overflow exploit with egghunter shellcode that spawns a shell on port 4444.
1dd807e4d7167fce435808be2c8b9c29This whitepaper goes into detail on how to use egg hunting shellcode in order to exploit a BisonWare FTP server.
3b77aa7034edc0a6eb15c7fb213af029Win32/XP Pro SP3 (EN) 32-bit beep beep shellcode.
861c8d26c5ad427084a84f88767aa3d1Kraken Payload Generator is a bash script that makes use of msfpayload to generate various shellcode.
04cf43ad2a6cda9b49c235e34d46bffa180 bytes small Linux/x86 add new user/password shellcode.
cd7399535526f6e2b9460ccc859d6f7dThis Linux/x86 shellcode searches .php files and injects a PHP backdoor into them.
5888da252a52b2b4c0e54a04877f8d94Savant Web Server version 3.1 buffer overflow exploit with shellcode that binds to port 4444.
cc27bdb76e46801b85f79d44bc05de23This shellcode writes down your code in the end of found files. Your code will be added only .html and .php files. Search for files is carried out recursively.
b93d44bee863a235f640f72a1d5153c894 bytes small BSD/x86 execve ('/bin/sh -c "/etc/master.passwd"') setreuid(0,0) shellcode.
35d2e60bbb98af3759a63f4c86856215102 bytes small Linux/x86 sys_execve ["/bin/sh"] setresuid(0,0,0) exit(0) shellcode.
6b5adc9ee8268fcaeaea40123f490188This bug is triggered when the browser handles a JavaScript 'onLoad' handler in conjunction with an improperly initialized 'window()' JavaScript function. This exploit results in a call to an address lower than the heap. The javascript prompt() places the shellcode near where the call operand points to. The module calls prompt() multiple times in separate iframes to place our return address. The module hides the prompts in a popup window behind the main window and then it will spray the heap a second time with the shellcode and point the return address to the heap. It then uses a fairly high address to make this exploit more reliable. IE will crash when the exploit completes. Also, please note that Internet Explorer must allow popups in order to continue exploitation.
0358332ac3ab6a251d1228ddaa934cc8Linux/x86 polymorphic shellcode that escalates uid/gid and adds user iph to /etc/passwd without a password.
5f068501a4c3a979131005f6ce38a5dcWhitepaper called Construindo Shellcodes. It discusses how to build shellcodes and use them. Written in Portuguese.
a6a688208ea6779d6fca62dcb3099476168 bytes small Linux/MIPS connect back shellcode (port 0x7a69).
c282524f8b8a80a24cf73b85f055396532 bytes small Linux/MIPS reboot() shellcode.
3b292fcd03bf83b472bd34b6d7aee65152 bytes small Linux/x86-64 execve(/bin/sh) shellcode.
914e31cdfa121ea06909d162cee3f66c