Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Re: 3COM TFTPD Overflow: SEH Overwrite

Re: Re: 3COM TFTPD Overflow: SEH Overwrite

From: <jeremy.junginger_at_gmail.com>
Date: 6 Feb 2008 13:52:12 -0000
('binary' encoding is not supported, stored as-is) I was asking if ws2_32.dll was compiled with SafeSEH (didn't know about the Olly plugin). Regarding the return address...I already have control of EIP, but can't point it directly to the stack, so I'm searching for a module with a suitable return address (with pop/pop/ret) to help me get back to that buffer. The issue was with the return address I was pointing to, and the fact that it the module was compiled with SafeSEH. Is that enough detail?
Received on Feb 06 2008
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos