EggSandwich – An Egghunter with Integrity
data:image/s3,"s3://crabby-images/96d57/96d57c6320de042ec4bd662374ba0574c211c252" alt="eggsandwich6"
Introduction A while back I introduced the EggSandwich in my tutorial on Egghunting as a means to implement some basic integrity checks into the traditional Egghunter and overcome the problem of fragmented / corrupted shellcode. I recently took the opportunity to update my implementation so it could accomodate shellcode of any size. The code and a brief explanation follows. What is the EggSandwich? I ran into a situation when developing an exploit for an…
Read more...Windows Exploit Development – Part 5: Locating Shellcode With Egghunting
are closed
data:image/s3,"s3://crabby-images/34420/34420344012d8f305f1b6189f35e9647ce506519" alt="win_exploit_5_7"
Overview In Part 4 we looked at how to find and execute your shellcode using various jump methods. In Part 5 we’re going to look at another method to find your shellcode called Egghunting. This method is especially useful when you’re faced with a small, reachable buffer (in which you can execute code) but the placement of your larger shellcode in memory is unpredictable. This post will get into quite…
Read more...Tags:coolplayer , egg sandwich , egghunter , egghunting , exploit , exploit development , omelette , shellcode , windows
are closed