Hi! As some of you may know, 2 weeks ago I posted an exploit module for metasploit and it got committed in revision 8975. Weaponizing actual PoC in working exploit is quite an interesting process in understanding and getting some exploit writing techniques. Thanks to Joshua Drake for helping me on this one. It was prolly a SEH based exploit, there was a buffer overflow in the m3u parsing routine. There wasn't anything really special about this exploit, it's a classic SEH exploit. We have a direct ret overwrite at offset 1024 and SEH overwrite at offset 1040. For bad chars, there was the classic NULL, then tried "\r\d" and turns out they were bad chars. 0x5c was found later to be a bad char too. We found the pointers using msfpescan mostly, immunity debug and some plugins to see if they were SafeSEH modules or not. The SEH exploit buffer is as follow : [encoder] [payload] [junk] [ret] [stub] [jmp] [se handler] The ret version : [encoder] [payload] [junk] [ret] The SEH ...
Awaz Apni Baat Apni is started in new Vision of Pakistan, We want to see a real image of Pakistan in public Point of View, Our Pakistan with New Vision.

