Senin, 13 Februari 2012

BUFFER OVERFLOW MINI STREAM MP3


that first we must make a code of fuzzer :
after making fuzzer we which must do that is save is name of fuzzer, if menyimpan me of name of fuzzer by the name of moapato.py.
My second step OllyDbg running application. and open the application RM2MP3 Converter.exe. in the application fuzzer on filename is "salim.smi". the file will extarct in python folder, and must move in windows xp.
and  click  open, hence its result will seen like hereunder.
after mentioned step  us start to run its mini stream.
after opening is mini our stream return to backtrack to make result of smi by using root, follow the example of like picture hereunder.
after making in root, hence its result will like this.
after that drag the salim.smi in mini stream converter.

hence its result will like this.
in address ESP we get chracter AAAAAA as much 25000, and EIP 41414141
like picture hereunder.
skrip which we earn mentioned we input can to python, see the example.
step hereinafter its us , if our success step into windows to run Ollydbg, after running Ollydbg hence will seen its result like picture hereunder.

and now try the pattern_offset. i'm have get the EIP 36695735 and ESP i8Wi9Wj0.


after us get EIP address and ESP we can make script care of EIP we which have find.


and we can see result of compile Ollydbg picture hereunder, in this case to check there real correct position from existing EIP there.


afterwards we try script following.




after compile hence its result like this.




and from picture above we can look for JMP ESP, usually JMP ESP searched in SHELL32, but [do] not always JMP ESP in SHELL32 hence from that we use command to searching it one by one.




after us get JMP ESP hence its result will seen like hereunder.





first active us use root, like picture hereunder.




if have is active, open last browser typing browser 127.0.0.1:55555 hence will go out its result like picture hereunder.




afterwards select shell bind windows searching and payload hence will go out its result like this.





after us chosen shell bind windows we have to fill what there  in the example shell bind windows see picture.





after in direct content just click Generate Payload hence will seen result of like picture following.


make new script.

extract the python file name="salim.smi". and run ollydbg and running converter.



converter loading, and us return to root for the chek of she have IP or not.


after getting our IP to root to activating talnet.



we dir input.


Success, likely will be mad





Tidak ada komentar:

Posting Komentar