Re: WebDAV exploit: using wide character decoder scheme

From: Dave Aitel (daveat_private)
Date: Wed Mar 26 2003 - 08:14:43 PST

  • Next message: Tonu Samuel: "Re: PHPNuke viewpage.php allows Remote File retrieving"

    Unfortunately, on my US Windows 2K SP3 build (and I assume all others),
    those %u directives get translated into question marks. (0x003F in hex)
    :<
    
    This exploit must be much easier to get reliable on other language
    versions. A shame, really.
    
    Did you use my encoder or did you write your shellcode manually, just
    out of curiosity?
    
    Dave Aitel
    Advanced Engineering Directorate
    Immunity, Inc.
    http://www.immunitysec.com/CANVAS/ "Hacking like it's done in the
    movies."
    
    On Wed, 26 Mar 2003 22:55:12 +0900
    ¿ÀÁ¤¿í <matat_private> wrote:
    > my @return_addresses=(
    > "%u32ac%u77e2",
    > "%uc1b5%u76ae",
    > "%u005d%u77a5",
    



    This archive was generated by hypermail 2b30 : Wed Mar 26 2003 - 14:16:49 PST