Penetration Testing mailing list archives

Re: Analyzing Shellcode


From: Michel Chamberland <merc () securitywire com>
Date: Fri, 06 Nov 2009 22:39:17 -0500

give this a try:

http://blog.securitywire.com/2009/07/18/decoding-and-disassembling-shellcode/

Enjoy!

-- 
Michel Chamberland 
CEH, Security+, Network+, A+, MCP, CIW Associate
http://www.securitywire.com


On Thu, 2009-11-05 at 18:38 +0100, cAs wrote:
Good evening everybody,

i am trying to analyze the shellcode used in this exploit:
http://www.milw0rm.com/exploits/7477

If i echo the unescaped shellcode i only get wierd chinese (i think)
letters.

What's the right way to analyze what kind of shellcode is beeing used
and what command is beeing executed by it.

Greetings,
cAs


------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: