Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Rick
    rundll32.exe buffer overflow
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    rundll32.exe buffer overflow

    Hi,



    There is buffer overflow in rundll32.exe when it is passed big string as
    routine name for a module. I've tested this on WindowsXP SP1. But other
    version of windows might be vuln.



    rundll32.exe advpack32.dll,<'A'x499>



    advpack32.dll is just example. Any executable/dll will work. The
    cmdline does get converted to UNICODE. And EIP ends up being 00410041.



    -

    Rick Patel


  2. #2
    wirepair
    rundll32.exe buffer overflow
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: rundll32.exe buffer overflow

    interesting, in win2ksp4 i can't get it to overflow...
    with regular characters.
    if i use a lot of %'s it appears to overwrite eip. but if
    i tack on any character at the end it won't overflow.
    C:\WINNT\system32>rundll32.exe
    rundll32.exe,AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAA%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%% <-- crashes 0x00250025...
    but
    C:\WINNT\system32>rundll32.exe
    rundll32.exe,AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAA%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%A <--- doesn't crash... just quitely exits...
    C:\WINNT\system32>rundll32.exe
    rundll32.exe,AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAA%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
    %%%%%%%%%%%%%%%%%%%%%%%%%
    just enough amount of a's, then i put in the %'s and i get
    error in instruction 0x00250025... This is strange indeed,
    anyone else seeing this? i checked for format string
    vulnerabilities but no luck. Also it looks like in the
    MessageBox that the %'s get doubled, is this due to the
    unicode formatting???
    -wire.
    _____________________________
    For the best comics, toys, movies, and more,
    please visit <http://www.tfaw.com/?qt=wmf>


  3. #3
    Curt Wilson
    rundll32.exe buffer overflow
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: rundll32.exe buffer overflow


    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1


    FYI This does not appear to be exploitable on an en Windows 2000 SP3
    + all current hotfixes (have not loaded SP4 yet however). advpack32.dll
    does not exist on my win2k pro system, however advpack.dll does and this
    was attempted, using 499 chars + more. Tried a few other DLL's to no
    avail.

    Curt Wilson

    On Sun, 06 Jul 2003 11:42:42 -0700 Rick <rikul@bellsouth.net> wrote:
    >There is buffer overflow in rundll32.exe when it is passed big string
    >as routine name for a module. I've tested this on WindowsXP SP1. But
    >other version of windows might be vuln.
    >
    >rundll32.exe advpack32.dll,<'A'x499>
    >
    >advpack32.dll is just example. Any executable/dll will work. The
    >cmdline does get converted to UNICODE. And EIP ends up being 00410041.
    >


    Curt R. Wilson
    Netw3 Security
    www.netw3.com
    -----BEGIN PGP SIGNATURE-----
    Note: This signature can be verified at https://www.hushtools.com/verify
    Version: Hush 2.3

    wkYEARECAAYFAj8KP48ACgkQRnf2MGkR9yv0OwCgmn2cTEZG65 0eKc8VVah61Mm0dyMA
    n2X8Ye9pNyC4S/wXXkxXGfxM8cQc
    =qexc
    -----END PGP SIGNATURE-----


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics