that first we must make a code of fuzzer :
after making fuzzer we which must do that is save is name of fuzzer, if menyimpan me of name of fuzzer by the name of
moapato.py.
My second step OllyDbg running application. and open the
application RM2MP3 Converter.exe. in the application fuzzer on filename is
"salim.smi". the file will extarct in python folder, and must move in
windows xp.
and click open, hence its result will seen like
hereunder.
after mentioned step
us start to run its mini stream.
after opening is mini our stream return to
backtrack to make result of smi by using root, follow the example of like
picture hereunder.
after making in root, hence its result will
like this.
after that drag the salim.smi in mini stream converter.
hence its result will like this.
in address ESP we get chracter AAAAAA as much 25000, and EIP
41414141
like picture hereunder.
skrip which we earn mentioned we input can to
python, see the example.
step hereinafter its us , if our success step
into windows to run Ollydbg, after running Ollydbg hence will seen its result
like picture hereunder.
and now try the pattern_offset. i'm have get the EIP
36695735 and ESP i8Wi9Wj0.
after us get EIP address and ESP we can make
script care of EIP we which have find.
and we can see result of compile Ollydbg
picture hereunder, in this case to check there real correct position from
existing EIP there.
and from picture above we can look for JMP
ESP, usually JMP ESP searched in SHELL32, but [do] not always JMP ESP in
SHELL32 hence from that we use command to searching it one by one.
after us get JMP ESP hence its result will
seen like hereunder.
first active us use root, like picture
hereunder.
if have is active, open last browser typing
browser 127.0.0.1:55555 hence will go out its result like picture hereunder.
afterwards select shell bind windows
searching and payload hence will go out its result like this.
after us chosen shell bind windows we have to
fill what there in the example shell
bind windows see picture.
after in direct content just click Generate
Payload hence will seen result of like picture following.
make new script.
extract
the python file name="salim.smi". and run ollydbg and running
converter.
converter loading, and us return to root for the chek of she have IP or not.
after getting our IP to root to activating
talnet.
we dir input.
Success, likely will be mad
Tidak ada komentar:
Posting Komentar