Skip to main content

Posts

Showing posts with the label breaking_code

Breaking code: Warm Up Windows Exploit and RE Challenge Examenes (▀̿Ĺ̯▀̿ ̿) (day 96) part I

It's been three months since my last post on windows exploit and RE, TBH I'm quite rusty so to keep up with the pace we will try to solve some challenges from https://github.com/naivenom/exploiting there is a section called "Windows Exploit Development - Exercises from CLS Exploits" this contains a handful of windows Exploit challenge that fit with my current skills(not too easy but difficult enough to force me to read the assembly code) Prerequisite: I run the challenge in windows 10 VirtualBox from https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/ I suggest to download this VM since it's free and maintain by windows itself . Furthermore, throughout this challenge, I will use immunity debugger as the primary tool for analysis Challenge 1: Open the first challenge file with immunity debugger and you will see a ton of code inside such a small program. We can start the analysis by doing string analysis on the binary this would list all of ...

Breaking code: windows ROP 7 >:) (day 67)

Disclaimer: This post only for education only ! not to cause any destruction on any living system. Be smart! as you guys realize in the previous post we do all of our exploit development inside an old Windows XP OS that is certainly don't have an adequate protection mechanism in its environment if we try to stick with this environment only, it will eventually make everything we learn so far obsolete, we need to step up our game to become better. So in this post, we are going to take a look at how to bypassing common protection mechanism in windows 7 note: this post does not originally come from me this was inspired by http://www.fuzzysecurity.com/tutorials/expDev/7.html and https://packetstormsecurity.com/files/104583/DVD-X-Player-5.5.0-Pro-Standard-Buffer-Overflow.html go check this resource above cause this is really good Background: Ok, so a little bit of background about windows 7 protection mechanism. Basically, starting from Win Server 2003 SP1, windows has impl...

Breaking code: Fuzzing Windows Executable with boofuzz (▀̿Ĺ̯▀̿ ̿) (day 65)

Disclaimer: This post only for education only ! not to cause any destruction on any living system. Be smart! Back again with breaking code series In this post, we are going to take a look at how to use boofuzz tools to trigger a crash in the application that able to help us in the exploitation process. note: this post is based on https://www.exploit-db.com/exploits/42155 so what is boofuzz? (link: https://github.com/jtpereyda/boofuzz ) boofuzz is a fuzzing tools that was based on sulley framework. What I liked about sulley is that I can integrate the tool using python :) this way I am able to set how the boofuzz behave when conducting fuzz testing on my target why we need fuzzing? fuzzing is very critical in finding a vulnerability in software, fuzzing help by inputting lots and unpredictable input testing because of this we would able to trigger a bug that was meant to crash the target. At the end of the fuzzing process, we are able to determine what is the cause of ...