[Full-disclosure] w32 SEH omelet shellcode stage
berendjanwever at gmail.com
Mon Mar 16 18:30:17 GMT 2009
I'm releasing some code for a technique which I call "omelet shellcode" that
may be useful in some exploits. It is similar to egg-hunt shellcode, but
will search user-land address space for multiple smaller eggs and recombine
them into one larger block of shellcode and execute it. This is useful in
situation where you cannot inject a block of sufficient size into a target
process to store your shellcode in one piece, but you can inject multiple
smaller blocks and execute one of them.
More details can be found here:
I have not had a chance to test this newer version in a live exploit, so do
let me know if you have a chance to use it.
Berend-Jan Wever <berendjanwever at gmail.com>
.----. , , ,
( ' / / . _ _ __/
, `'-._ /_-'/ / / / / ) /_) / /
( )/` )(_/ / / / / (__ (_/
`------' __/ '-------'
-------------- next part --------------
An HTML attachment was scrubbed...
Full-Disclosure is hosted and sponsored by Secunia.