Security Basics mailing list archives

Re: Finding Bad Characters in Exploit Research?


From: John Nash <rootsecurityfreak () gmail com>
Date: Sat, 19 Feb 2011 08:11:15 +0530

Msfencode is only useful if you know the bad character set. My problem
was finding the bad characters in fast and reliable way.

On Fri, Feb 18, 2011 at 10:44 PM,  <danuxx () gmail com> wrote:
What don't you just encode it with msfencode?
Sent via BlackBerry from Danux Network

-----Original Message-----
From: John Nash <rootsecurityfreak () gmail com>
Sender: listbounce () securityfocus com
Date: Thu, 17 Feb 2011 22:06:09
To: security-basics<security-basics () securityfocus com>
Subject: Finding Bad Characters in Exploit Research?

Hello All,

Just dived into exploit research and finding bad characters is killing me!

Can someone point me to a good document / methodology / automated way
to find bad characters?

Any help will be greatly appreciated!

Rgds,

JN

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: