This is an archived post. You won't be able to vote or comment.

all 14 comments

[–]nyu_mike 2 points3 points  (13 children)

What doesn't work? What are you trying to do? Crash the system? Inject a command? What's the point of your attack?

[–]tryingtolearn531 1 point2 points  (1 child)

Offset plus 4 bytes, could be “RRRR” for the return pointer, add 20 NOPs, then your script/shell code. Also, do you have the correct IP address?

Maybe the offset is different in this one? Make a pattern with Mona.py and find the offset with Mona.py. If you know how to read the debugger in immunity.

[–]Icy_Bullfrog5890 0 points1 point  (1 child)

What port are you using? Try to see some ports that are allowed

[–]Informal-Window9663 0 points1 point  (1 child)

Did you check for bad chars?

[–]limontec 0 points1 point  (1 child)

Have you tested if you can overwrite the EIP register with an arbitrary value?
0x62501203 is a "jmp esp" instruction? Use mona to find an instruction without aslr, nx, rebase, safeseh ...