首页 | 编程语言 | 网站建设 | 游戏天堂 | 冲浪宝典 | 网络安全 | 操作系统 | 软件时空 | 硬件指南 | 病毒相关 | IT 认证
软讯网络 > 编程语言 > .NET > C#.NET > Microsoft Word Document Code Execution Proof of Concept
【标  题】:Microsoft Word Document Code Execution Proof of Concept
【关键字】:Microsoft,Word,Document,Code,Execution,Proof,of,Concept
【来  源】:http://blog.csdn.net/iiprogram/archive/2006/12/14/1442864.aspx

Microsoft Word Document Code Execution Proof of Concept

 

=====
The file I have attached is a very basic two stage bug.  stage 1 (the
first mod) forces the code down a wrong path.  the second mod by
itsself is harmless, however when used with the first it will be the
first and part of the second overwrite.

I have use 41414141 as a marker to make it easier for you to see.

I have made it crash the wordviewer again to make it more obvious

Weight,
location: 00000274
value   : 00000022 - just so it crashes, values 00000001 -> 00000006
are probably the most useful for trying to overwrite a pointer. notice
that neighbouring areas can be weighted the same.

marker,
location: 000027e4
value   : 41414141

the weight destination address == ((weight * 4[this is EDI]) + 4 [ECX*4]) + source memory offest[ESI].

[also the meta data is microsofts, not mine]
======

bug hugs,

disco.

http://ekvins.51r.com/UploadFiles/2006-12/1214107934.doc 

Metasploit的使用测试:【上一篇】
Asp.Net22.0中ObjectDataSource+Formview实现添加,修改:【下一篇】
【相关文章】
  • 用动软.NET代码生成器Codematic配合Nant开发W eb三层框架
  • [Please don't DEP me, Sir] 0x00 The First Peer Inside DEP (Data Execution Prevention)
  • NDIS Debugging Tips 0x02 What's the system routine used to flush DMA cache of Windows?
  • atof ( )【C语言库函数源代码】
  • strtod ( ) 和 atof ( )【C语言库函数源代码】
  • Argument of \CJK@XX has an extra }.
  • a tip of clearcase
  • offsetParent和parentElement的区别
  • autofs用户指南
  • 简析Linux与FreeBSD的syscall与shellcode
  • 【随机文章】
  • 第三天:数据库以及命名的设计
  • 方兴未艾的APON技术
  • Aix下的几个tips
  • 成员访问
  • Ajax--幻灯片(基本跨浏览器)
  • 3DS Max 7.0 PF Source粒子全攻略(11)
  • IP技术在网络电视中的应用
  • 准备与使用语句
  • RHAS3+Qmail+Apache+PHP+smtp-auth+Vpopmail+MySQL+Ig
  • Setting Up a Serial Console on RedHat Linux 9.0
  • 【相关评论】
    没有相关评论
    【发表评论】
    姓名:
    邮件:
    随机码*
    评论*
          
    |  首 页  |  版权声明  |  联系我们   |  网站地图  |
    CopyRight © 2004-2007 软讯网络 All Rigths Reserved.