Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re[2]: Can't Preventing exploitation with rebasing
From: dullien () gmx de
Date: Thu, 6 Feb 2003 20:14:03 +0100

Hey all,

bghn> DIGRESSION:
bghn>         Dave Litchfield says you can call esp.  I don't know Dave's
bghn>         relationships with his registers but this doesn't work if I want
bghn>         to get my eip on top of my shellcode.  Always starts executing a
bghn>         memory address for me.  Maybe if I took esp out to dinner more
bghn>         often then I could call it instead of having to jump on top of it.
bghn>         Dave, any suggestions for the wine list?
bghn> END DIGRESSION.

Problem here is Intel ignoring it's own standards. The standard says
to first transfer control, then push the old EIP on the stack -- but
Intel CPU's since Pentium have done it the other way around, first
pushing EIP (and decreasing ESP), then setting EIP=ESP.

Cheers,
Thomas


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]