Full Disclosure mailing list archives
Re: alpha numeric exploitation
From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Fri, 27 May 2005 00:08:18 +1200
RaMatkal wrote:
I'm trying to develop an alphanumeric payload that needs to do a JMP -600 bytes... Anyone got any ideas how to do this with only alpha numeric chars? 'eb' and 'e9' are obviously out of the question...
Think "encoding/decoding" and "self-modifying". EICAR.COM has been doing it for more than decade to get its INT (cd) op- codes executed, so this is hardly revolutionary new territory... Beyond that, I'd be extremely surprised if someone hasn't written tutorials on doing alphanumeric-only payloads, if not even provided toolkits to take arbitrary code and "ASCII-fy" it. Regards, Nick FitzGerald _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- alpha numeric exploitation RaMatkal (May 26)
- Re: alpha numeric exploitation Nick FitzGerald (May 26)
- <Possible follow-ups>
- RE: alpha numeric exploitation Kyle Quest (May 26)
- Re: alpha numeric exploitation Kristian Hermansen (May 26)
- Re: alpha numeric exploitation Berend-Jan Wever (May 30)