Re: Some help With BOF Exploits Writing. - EAX ?!

optikool_at_psyfreakz.org
Date: 08/01/03

  • Next message: Michael Wojcik: "RE: Password Cracking Challenge..."
    Date: Thu, 31 Jul 2003 18:21:27 -0600 (GMT+6)
    To: <vuln-dev@securityfocus.com>
    
    

    Hi all,

    i've a doubt... can you run arbitrary code...by overflowing a buffer that
    overflows EAX only?! ..
    i've a little doubt about bofs... but if i overflow the buffer and set the
    correct ret address of a shellcode, in the EAX ... will it work ?.. cose
    i'm having troubles in running arbitrary code.. :|

    the true is that i don't understand much of MEMORY in linux x86.. i know
    the basic..

    PS - any good books/tutorials about linux (x86) memory.. and what all the
    pointers eax, ebp, eip, etc..etc..) really work..and are there to what for
    ?!

    Thanks in Advanced!

    -- 
    PsyFreakZ.Org - Owning The Psy ScenE!
    

  • Next message: Michael Wojcik: "RE: Password Cracking Challenge..."

    Relevant Pages

    • Detailed analysis: Buffer overflow in Explorer.exe on Windows XP SP1
      ... Actually, I assume the overflowing file, no matter where it is located in ... it assumes the buffer to be as ... We do not know how this bug affects shell32.dll files on other Windows ... unintentionally execute arbitrary code. ...
      (Bugtraq)
    • Re: Ancient history
      ... >> the boundary is between overflowing and access to an extended area ... Changing from the fixed sized queues implemented using an array ... When an entry is made a buffer is requested from the heap. ... paragraph for every line he writes. ...
      (sci.crypt)
    • Re: DEFCON 16 and Hacking OpenVMS
      ... SMG is written in BLISS. ... correctly) is not overflowing the buffer because a null is missing. ... code longer than DEFCONs have been around. ...
      (comp.os.vms)
    • Re: why dosent buffer gets overflowed
      ... "why dosent buffer gets overflowed" ... What makes you think the buffer isn't being overflowed? ... int main(int argc, char **argv) ... and you don't provide any safeguards against that, so you're overflowing ...
      (comp.lang.c)
    • Re: classes and using *
      ... > I've never heard of any city with more than 255 characters, ... Overflowing a buffer is one of the ...
      (comp.lang.cpp)