exploiting:windows:milleniump3:start
Differences
This shows you the differences between two versions of the page.
exploiting:windows:milleniump3:start [2019/08/10 21:11] – created ebaer | exploiting:windows:milleniump3:start [2019/08/10 21:16] (current) – ebaer | ||
---|---|---|---|
Line 4: | Line 4: | ||
===== Windbg/mona notes ===== | ===== Windbg/mona notes ===== | ||
- | < | + | < |
0:000> r | 0:000> r | ||
eax=00185748 ebx=00185748 ecx=00000000 edx=46376846 esi=0018471c edi=0623c00c | eax=00185748 ebx=00185748 ecx=00000000 edx=46376846 esi=0018471c edi=0623c00c | ||
Line 18: | Line 18: | ||
00185730: 68463068 | 00185730: 68463068 | ||
Invalid exception stack at 46396746 | Invalid exception stack at 46396746 | ||
- | |||
- | 0:000> db esp L30 | ||
- | 00184708 | ||
- | 00184718 | ||
- | 00184728 | ||
C: | C: | ||
Line 52: | Line 47: | ||
0053: | 0053: | ||
0053: | 0053: | ||
+ | 00185e7c | ||
0:000> dp 00185e7c | 0:000> dp 00185e7c | ||
- | 00185e7c | + | 00185e7c |
- | 00185e8c | + | 00185e8c |
- | 00185e9c | + | 00185e9c |
- | 00185eac | + | |
- | 00185ebc | + | |
- | 00185ecc | + | |
- | 00185edc | + | |
+ | # some memo shortly after the seh chain is zeroed out -> jump over | ||
</ | </ | ||
exploiting/windows/milleniump3/start.1565464298.txt.gz · Last modified: 2019/08/10 21:11 by ebaer