<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3801485324556381326</id><updated>2011-12-02T01:07:24.290-08:00</updated><title type='text'>MoAxB - Month of ActiveX Bug</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>35</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-8148973659992858773</id><published>2007-05-30T16:07:00.000-07:00</published><updated>2007-05-30T07:06:43.497-07:00</updated><title type='text'>MoAxB #30: Zenturi ProgramChecker ActiveX (sasatl.dll) Arbitrary file download/overwrite Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070530/zenturi.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070530/zenturitxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-8148973659992858773?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/8148973659992858773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=8148973659992858773' title='257 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8148973659992858773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8148973659992858773'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-30-zenturi-programchecker-activex.html' title='MoAxB #30: Zenturi ProgramChecker ActiveX (sasatl.dll) Arbitrary file download/overwrite Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>257</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-3739968048494731734</id><published>2007-05-29T12:18:00.000-07:00</published><updated>2007-05-30T03:17:13.669-07:00</updated><title type='text'>MoAxB #29: EDraw Office Viewer Component (edrawofficeviewer.ocx v. 4.0.5.20) Denial of Service Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070529/edrawhttp.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070529/edrawhttptxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-3739968048494731734?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/3739968048494731734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=3739968048494731734' title='116 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/3739968048494731734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/3739968048494731734'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.html' title='MoAxB #29: EDraw Office Viewer Component (edrawofficeviewer.ocx v. 4.0.5.20) Denial of Service Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>116</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-8421622239262358297</id><published>2007-05-28T11:31:00.000-07:00</published><updated>2007-05-30T02:30:40.059-07:00</updated><title type='text'>MoAxb #28: EDraw Office Viewer Component (edrawofficeviewer.ocx v. 4.0.5.20) Unsafe Method Vulnerability</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070528/edraw.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070528/edrawtxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-8421622239262358297?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/8421622239262358297/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=8421622239262358297' title='135 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8421622239262358297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8421622239262358297'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-28-edraw-office-viewer-component.html' title='MoAxb #28: EDraw Office Viewer Component (edrawofficeviewer.ocx v. 4.0.5.20) Unsafe Method Vulnerability'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>135</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-1087283047013613314</id><published>2007-05-27T18:13:00.000-07:00</published><updated>2007-05-28T09:13:24.899-07:00</updated><title type='text'>MoAxB #27: LeadTools Raster ISIS Object (LTRIS14e.DLL v. 14.5.0.44) Remote Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070527/leadrasterisis.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070527/leadrasterisistxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-1087283047013613314?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/1087283047013613314/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=1087283047013613314' title='115 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1087283047013613314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1087283047013613314'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-27-leadtools-raster-isis-object.html' title='MoAxB #27: LeadTools Raster ISIS Object (LTRIS14e.DLL v. 14.5.0.44) Remote Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>115</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-1577691643731931113</id><published>2007-05-26T15:14:00.000-07:00</published><updated>2007-05-27T06:14:14.361-07:00</updated><title type='text'>MoAxB #26: LeadTools Raster OCR Document Object Library (ltrdc14e.dll v. 14.5.0.44) Remote Memory corruption Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070526/leadocr.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070526/leadocrtxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-1577691643731931113?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/1577691643731931113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=1577691643731931113' title='124 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1577691643731931113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1577691643731931113'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-26-leadtools-raster-ocr-document.html' title='MoAxB #26: LeadTools Raster OCR Document Object Library (ltrdc14e.dll v. 14.5.0.44) Remote Memory corruption Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>124</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-1871984995873915239</id><published>2007-05-25T14:18:00.000-07:00</published><updated>2007-05-25T05:07:16.448-07:00</updated><title type='text'>MoAxB #25: LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL v. 14.5.0.44) Remote Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070525/leadrdfd.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070525/leadrdfdtxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-1871984995873915239?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/1871984995873915239/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=1871984995873915239' title='74 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1871984995873915239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1871984995873915239'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-25-leadtools-raster-dialog-filed.html' title='MoAxB #25: LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL v. 14.5.0.44) Remote Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>74</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-2192665248222119306</id><published>2007-05-24T12:42:00.000-07:00</published><updated>2007-05-24T03:41:01.517-07:00</updated><title type='text'>MoAxB #24: LeadTools Raster Dialog File Object (LTRDF14e.DLL v. 14.5.0.44) Remote Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070524/leaddfo.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070524/leaddfotxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-2192665248222119306?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/2192665248222119306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=2192665248222119306' title='86 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/2192665248222119306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/2192665248222119306'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-24-leadtools-raster-dialog-file.html' title='MoAxB #24: LeadTools Raster Dialog File Object (LTRDF14e.DLL v. 14.5.0.44) Remote Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>86</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-6689177413588019152</id><published>2007-05-23T11:15:00.000-07:00</published><updated>2007-05-23T02:14:34.228-07:00</updated><title type='text'>MoAxB #23: Microsoft Office 2000 (OUACTRL.OCX v. 1.0.1.9) "HelpPopup" method Remote Buffer Overflow and winhlp32.exe Denial of Service</title><content type='html'>&lt;span style="font-family: courier new;font-size:85%;" &gt;E alla fine arriva Microsoft :-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070523/ouactrl.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070523/ouactrltxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Contenuto dei registri:&lt;br /&gt;&lt;/span&gt;&lt;pre style="font-family: courier new;" id="line21"&gt;&lt;span style="font-size:85%;"&gt;EAX 00000000&lt;br /&gt;ECX 7E39EC0C USER32.7E39EC0C&lt;br /&gt;EDX 7C91EB94 ntdll.KiFastSystemCallRet&lt;br /&gt;EBX 38CFD2D0 OUACTRL.38CFD2D0&lt;br /&gt;ESP 01D0F434 UNICODE "aaaa..."&lt;br /&gt;EBP 00610061&lt;br /&gt;ESI 02ACC86C&lt;br /&gt;EDI 00000000&lt;br /&gt;&lt;br /&gt;EIP 00610061&lt;/span&gt;&lt;/pre&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-6689177413588019152?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/6689177413588019152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=6689177413588019152' title='68 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6689177413588019152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6689177413588019152'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-23-microsoft-office-2000.html' title='MoAxB #23: Microsoft Office 2000 (OUACTRL.OCX v. 1.0.1.9) &quot;HelpPopup&quot; method Remote Buffer Overflow and winhlp32.exe Denial of Service'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>68</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-688913677433476069</id><published>2007-05-22T15:56:00.000-07:00</published><updated>2007-05-25T02:18:36.368-07:00</updated><title type='text'>MoAxB #22 Bonus: Dart ZipLite Compression for ActiveX (DartZipLite.dll v. 1.8.5.3) Remote Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;Bonus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070522/dartziplite.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070522/dartziplitetxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-688913677433476069?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/688913677433476069/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=688913677433476069' title='26 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/688913677433476069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/688913677433476069'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-22-bonus-dart-ziplite-compression.html' title='MoAxB #22 Bonus: Dart ZipLite Compression for ActiveX (DartZipLite.dll v. 1.8.5.3) Remote Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>26</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7889489332377590198</id><published>2007-05-22T10:31:00.000-07:00</published><updated>2007-05-22T01:30:49.481-07:00</updated><title type='text'>MoAxB #22: LeadTools ISIS Control (ltisi14E.ocx v. 14.5.0.44) Remote Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Oggi non ho voglia di commentare...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070522/leadisis.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070522/leadisistxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7889489332377590198?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7889489332377590198/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7889489332377590198' title='38 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7889489332377590198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7889489332377590198'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-22-leadtools-isis-control.html' title='MoAxB #22: LeadTools ISIS Control (ltisi14E.ocx v. 14.5.0.44) Remote Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>38</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7539527283761978098</id><published>2007-05-21T12:24:00.000-07:00</published><updated>2007-05-21T03:23:38.477-07:00</updated><title type='text'>MoAxB #21: LeadTools Raster Variant Object Library (LTRVR14e.dll v. 14.5.0.44) Remote Arbitrary File Overwrite</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;E' possibile, usando il metodo "&lt;span style="font-weight: bold;"&gt;WriteDataToFile&lt;/span&gt;" di questo ActiveX, sovrascrivere con dati random il contenuto di file arbitrariamente.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Tale operazione risulta rischiosa in quanto, modificando il contenuto di file come system.ini, si può compromettere il funzionamento del pc di un utente.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070521/ltrvol.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070521/ltrvoltxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7539527283761978098?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7539527283761978098/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7539527283761978098' title='24 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7539527283761978098'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7539527283761978098'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-21-leadtools-raster-variant.html' title='MoAxB #21: LeadTools Raster Variant Object Library (LTRVR14e.dll v. 14.5.0.44) Remote Arbitrary File Overwrite'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>24</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-6692942370469497456</id><published>2007-05-20T19:44:00.000-07:00</published><updated>2007-05-18T10:45:47.732-07:00</updated><title type='text'>MoAxB #20: LeadTools Raster Thumbnail Object Library (LTRTM14e.DLL v. 14.5.0.44) Remote Stack-Based Buffer Overflow</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Stessa ragione del post MoAxB #19 :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070520/leadraster.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070520/leadrastertxt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-6692942370469497456?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/6692942370469497456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=6692942370469497456' title='26 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6692942370469497456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6692942370469497456'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-20-leadtools-raster-thumbnail.html' title='MoAxB #20: LeadTools Raster Thumbnail Object Library (LTRTM14e.DLL v. 14.5.0.44) Remote Stack-Based Buffer Overflow'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>26</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-1850299595694167023</id><published>2007-05-19T19:42:00.000-07:00</published><updated>2007-05-18T10:42:58.679-07:00</updated><title type='text'>MoAxB #19: LeadTools Thumbnail Browser Control (lttmb14E.ocx v. 14.5.0.44) Remote Stack-Based Buffer Overflow</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Siccome nei prossimi due giorni non avro accesso a pc di sorta, pubblico in anticipo i bug relativi al 19 e 20 Maggio 2007.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Il titolo parla da solo :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070519/lademthumb.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070519/lademthumbtxt.html"&gt;&lt;br /&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-1850299595694167023?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/1850299595694167023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=1850299595694167023' title='64 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1850299595694167023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1850299595694167023'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-19-leadtools-thumbnail-browser.html' title='MoAxB #19: LeadTools Thumbnail Browser Control (lttmb14E.ocx v. 14.5.0.44) Remote Stack-Based Buffer Overflow'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>64</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-6728585196843956728</id><published>2007-05-18T13:26:00.000-07:00</published><updated>2007-05-18T04:25:43.747-07:00</updated><title type='text'>MoAxB #18: LeadTools JPEG 2000 COM Objejct (LTJ2K14.ocx v. 14.5.0.35) Remote Stack-Based Buffer Overflow</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Questo ActiveX consente di gestire immagine anche da web browser.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Il metodo "BitmapDataPath" è vulnerabile a stack-based buffer overflow che consente l'esecuzione di codice arbitrario sul pc di un utente.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070518/lead.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070518/leadtxt.html"&gt;Formato testo&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-6728585196843956728?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/6728585196843956728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=6728585196843956728' title='44 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6728585196843956728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6728585196843956728'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-18-leadtools-jpeg-2000-com.html' title='MoAxB #18: LeadTools JPEG 2000 COM Objejct (LTJ2K14.ocx v. 14.5.0.35) Remote Stack-Based Buffer Overflow'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>44</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-1962716321263761237</id><published>2007-05-17T10:52:00.000-07:00</published><updated>2007-05-17T01:53:14.819-07:00</updated><title type='text'>MoAxB #17: Sienzo Digital Music Mentor (DMM) 2.6.0.4 (ltmm15.dll) Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Un'altra dll (ltmm15.dll) distribuita col DMM Sienzo risulta vulnerabile ad uno stack-based buffer overflow che consente l'esecuzione di codice arbitrario sul pc di un utente che avesse installato questo software.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Il vendor continua a non rispondere.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070517/sienzo2.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070517/sienzo2txt.html"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-1962716321263761237?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/1962716321263761237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=1962716321263761237' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1962716321263761237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/1962716321263761237'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-17-sienzo-digital-music-mentor.html' title='MoAxB #17: Sienzo Digital Music Mentor (DMM) 2.6.0.4 (ltmm15.dll) Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-3924379925764182981</id><published>2007-05-16T14:38:00.000-07:00</published><updated>2007-05-16T05:37:28.246-07:00</updated><title type='text'>MoAxB #16 Bonus: IE 6 PrecisionID Barcode ActiveX 1.9 0day (PrecisionID_Barcode.dll) Remote Arbitrary File Overwrite</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Un bonus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070516/precisionafo.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-3924379925764182981?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/3924379925764182981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=3924379925764182981' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/3924379925764182981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/3924379925764182981'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-16-bonus-ie-6-precisionid-barcode.html' title='MoAxB #16 Bonus: IE 6 PrecisionID Barcode ActiveX 1.9 0day (PrecisionID_Barcode.dll) Remote Arbitrary File Overwrite'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-8821300361155410280</id><published>2007-05-16T14:27:00.000-07:00</published><updated>2007-05-16T05:26:47.095-07:00</updated><title type='text'>MoAxB #16: IE 6 PrecisionID Barcode ActiveX 1.9 0day (PrecisionID_Barcode.dll) Denail of Service</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;In data 14/05/2007 è stata rilasciata una nuova versione di questo ActiveX, la 1.9&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Come un altro componente dello stesso produttore, è soggetto ad uno stack-based buffer overflow che può consentire l'esecuzione di codice arbitrario sul pc di un utente.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;L'exploit è stato provato su IE6, testandolo su IE7 il browser smette di rispondere.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070516/precision.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-8821300361155410280?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/8821300361155410280/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=8821300361155410280' title='94 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8821300361155410280'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8821300361155410280'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-16-ie-6-precisionid-barcode.html' title='MoAxB #16: IE 6 PrecisionID Barcode ActiveX 1.9 0day (PrecisionID_Barcode.dll) Denail of Service'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>94</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-5974153496069032484</id><published>2007-05-15T13:36:00.000-07:00</published><updated>2007-05-15T04:35:40.239-07:00</updated><title type='text'>MoAxB #15: DB Software Laboratory DeWizardX (DEWizardAX.ocx) Remote Arbitrary File Overwrite</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;E' possibile, usando il metodo "SaveToFile" di questo ActiveX, sovrascrivere con dati random il contenuto&lt;/span&gt; di file arbitrariamente.&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Tale operazione risulta rischiosa in quanto, modificando il contenuto di file come system.ini, si può compromettere il funzionamento del pc di un utente.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070515/dbsoftware.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-5974153496069032484?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/5974153496069032484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=5974153496069032484' title='28 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/5974153496069032484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/5974153496069032484'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-15-db-software-laboratory.html' title='MoAxB #15: DB Software Laboratory DeWizardX (DEWizardAX.ocx) Remote Arbitrary File Overwrite'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>28</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-2984089559187267337</id><published>2007-05-14T13:15:00.000-07:00</published><updated>2007-05-14T04:15:04.928-07:00</updated><title type='text'>MoAxB #14: Clever Database Comparer ActiveX version 2.2 Remote Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;Questo ActiveX serve a comparare due database e il metodo "ConnectToDatabase" è vulnerabile a Buffer Overflow che consente l'esecuzione di codice arbitrario sul pc di un utente.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070514/clever.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Contenuto dei registri al momento del crash:&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;pre id="line1"&gt;&lt;span style="font-size:78%;"&gt;12:58:35.492  pid=0570 tid=07FC  EXCEPTION (first-chance)&lt;br /&gt;             ----------------------------------------------------------------&lt;br /&gt;             Exception C0000005 (ACCESS_VIOLATION reading [41414141])&lt;br /&gt;             ----------------------------------------------------------------&lt;br /&gt;             EAX=01D04141: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00&lt;br /&gt;             EBX=41418282: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             ECX=01D0EA01: 41 41 41 41 41 41 41 41-41 41 41 41 41 41 41 41&lt;br /&gt;             EDX=00000001: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             ESP=01D0E510: 58 DD 0A 03 41 41 41 41-41 41 41 41 00 00 14 00&lt;br /&gt;             EBP=01D0E540: E0 EA D0 01 28 6F 93 03-41 41 41 41 58 DD 0A 03&lt;br /&gt;             ESI=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             EDI=030ADD58: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00&lt;br /&gt;             EIP=039316BC: 38 0E 74 1F 66 85 D2 6A-00 74 07 68 C8 32 95 03&lt;br /&gt;                           --&gt; CMP [ESI],CL&lt;br /&gt;             ----------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;12:58:35.492  pid=0570 tid=07FC  EXCEPTION (first-chance)&lt;br /&gt;             ----------------------------------------------------------------&lt;br /&gt;             Exception C0000005 (ACCESS_VIOLATION reading [41414141])&lt;br /&gt;             ----------------------------------------------------------------&lt;br /&gt;             EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             EBX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             ECX=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             EDX=7C9137D8: 8B 4C 24 04 F7 41 04 06-00 00 00 B8 01 00 00 00&lt;br /&gt;             ESP=01D0E140: BF 37 91 7C 28 E2 D0 01-28 EC D0 01 44 E2 D0 01&lt;br /&gt;             EBP=01D0E160: 10 E2 D0 01 8B 37 91 7C-28 E2 D0 01 28 EC D0 01&lt;br /&gt;             ESI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             EDI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;             EIP=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;br /&gt;                           --&gt; N/A&lt;br /&gt;             ----------------------------------------------------------------&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-2984089559187267337?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/2984089559187267337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=2984089559187267337' title='69 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/2984089559187267337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/2984089559187267337'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-14-clever-database-comparer.html' title='MoAxB #14: Clever Database Comparer ActiveX version 2.2 Remote Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>69</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-4892575507173639230</id><published>2007-05-13T11:45:00.000-07:00</published><updated>2007-05-13T02:45:17.847-07:00</updated><title type='text'>MoAxB #13: ID Automation Linear Barcode ActiveX Control (IDAutomationLinear6.dll) v. 1.6.0.5 DoS</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Altro ActiveX per barcode...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070513/IDAutomation.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-4892575507173639230?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/4892575507173639230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=4892575507173639230' title='64 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/4892575507173639230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/4892575507173639230'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-13-id-automation-linear-barcode.html' title='MoAxB #13: ID Automation Linear Barcode ActiveX Control (IDAutomationLinear6.dll) v. 1.6.0.5 DoS'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>64</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-9004105862672418484</id><published>2007-05-12T10:12:00.000-07:00</published><updated>2007-05-12T01:12:16.133-07:00</updated><title type='text'>MoAxB #12: PrecisionID Barcode ActiveX (PrecisionID_DataMatrix.DLL) 1.3 Denail of Service</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Un altro ActiveX col quale è possibile creare barcode. Come si può vedere, con l'exploit riusciamo a sovrascrivere EAX quindi non escludo la possibilità di esecuzione di codice arbitrario.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070512/precision.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-9004105862672418484?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/9004105862672418484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=9004105862672418484' title='28 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/9004105862672418484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/9004105862672418484'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-12-precisionid-barcode-activex.html' title='MoAxB #12: PrecisionID Barcode ActiveX (PrecisionID_DataMatrix.DLL) 1.3 Denail of Service'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>28</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-9194332575665463269</id><published>2007-05-11T18:17:00.000-07:00</published><updated>2007-05-11T09:16:04.621-07:00</updated><title type='text'>MoAxB #11 Bonus: GDivX Zenith Player AviFixer Class ActiveX BOF</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Questo ActiveX viene distribuito col player in oggetto.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;L'autore/scopritore del bug e &lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;rgod&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Ecco il link all'exploit:&lt;/span&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://retrogod.altervista.org/ie_gdivx_activex_bof.html"&gt;http://retrogod.altervista.org/ie_gdivx_activex_bof.html&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-9194332575665463269?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/9194332575665463269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=9194332575665463269' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/9194332575665463269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/9194332575665463269'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-11-bonus-gdivx-zenith-player.html' title='MoAxB #11 Bonus: GDivX Zenith Player AviFixer Class ActiveX BOF'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7158416295017095459</id><published>2007-05-11T12:13:00.000-07:00</published><updated>2007-05-11T09:17:00.379-07:00</updated><title type='text'>MoAxB #11: Morovia Barcode ActiveX Professional Arbitrary file overwrite</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;E' possibile, usando il metodo "Save" di questo ActiveX, sovrascrivere con dati random il contenuto&lt;/span&gt; di file arbitrariamente.&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Tale operazione risulta rischiosa in quanto, modificando il contenuto di file come system.ini, si può compromettere il funzionamento del pc di un utente.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070511/morovia.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7158416295017095459?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7158416295017095459/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7158416295017095459' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7158416295017095459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7158416295017095459'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/morovia-barcode-activex-professional.html' title='MoAxB #11: Morovia Barcode ActiveX Professional Arbitrary file overwrite'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7070663881864933991</id><published>2007-05-10T14:04:00.000-07:00</published><updated>2007-05-10T05:03:49.761-07:00</updated><title type='text'>MoAxB #10: RControl.dll v. 1.2.1.0 Denial of Service Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;Anche questo controllo è un VNC manager e anche questo è vulnerabile a stack overflow.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Giostrando la lunghezza della stringa si possono controllare di volta in volta diversi registri, quindi non escludo la possibilità di esecuzione di codice arbitrario.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070510/rControl.html"&gt;Dimostrazione Online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070510/rControl.txt"&gt;Formato testo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P.S.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Se si prova con una stringa inferiore a 4000 caratteri si verifica uno strano crash. Sembra un heap overflow nella ntdll.dll ma non ne sono sicuro e non ho tempo di indagare a fondo :)&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7070663881864933991?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7070663881864933991/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7070663881864933991' title='25 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7070663881864933991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7070663881864933991'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-10-rcontroldll-v-1210-denial-of.html' title='MoAxB #10: RControl.dll v. 1.2.1.0 Denial of Service Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>25</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-4220030710885113420</id><published>2007-05-09T10:18:00.000-07:00</published><updated>2007-05-09T01:19:03.196-07:00</updated><title type='text'>MoAxB #09: BarCodeWiz ActiveX Control 2.0 (BarcodeWiz.dll) Remote Buffer Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;Questo controllo consente di creare, visualizzare e stampare codici a barre. Il metodo "verify" di questo controllo è vulnerabile a buffer overflow grazie al quale il registro EIP viene sovrascritto dando la possibilità di eseguire codice arbitrario.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070509/barcodewiz.html"&gt;&lt;span style="font-family: courier new;"&gt;Dimostrazione online&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070509/barcodewiz.txt"&gt;&lt;span style="font-family: courier new;"&gt;Formato txt&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Ecco la situazione dei registri al momento del crash:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family: courier new;"&gt;14:39:21.000  pid=1244 tid=1534  EXCEPTION (first-chance)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              Exception C0000005 (ACCESS_VIOLATION reading [61616239])&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EAX=61616161: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EBX=03558474: 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ECX=01D1E375: 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EDX=01D1F020: 41 41 41 41 41 41 41 41-41 41 41 41 41 41 41 41&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ESP=01D1F014: 00 00 00 00 1C 0A 57 03-70 1B EB 03 41 41 41 41&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EBP=01D1F420: 41 41 41 41 41 41 41 41-61 61 61 61 41 41 41 41&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ESI=770F4C3B: 8B FF 55 8B EC 8B 45 08-85 C0 74 05 8B 40 FC D1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EDI=01D1F010: 7C 9E 55 03 00 00 00 00-1C 0A 57 03 70 1B EB 03&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EIP=03E9F9C6: 8B 88 D8 00 00 00 52 8B-01 FF 50 0C 85 C0 8B 45&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;                            --&gt; MOV ECX,[EAX+000000D8]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;14:39:21.000  pid=1244 tid=1534  EXCEPTION (first-chance)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              Exception C0000005 (ACCESS_VIOLATION reading [62626262])&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EBX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ECX=62626262: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EDX=7C9137D8: 8B 4C 24 04 F7 41 04 06-00 00 00 B8 01 00 00 00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ESP=01D1EC44: BF 37 91 7C 2C ED D1 01-94 F8 D1 01 48 ED D1 01&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EBP=01D1EC64: 14 ED D1 01 8B 37 91 7C-2C ED D1 01 94 F8 D1 01&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ESI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EDI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              EIP=62626262: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;                            --&gt; N/A&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-4220030710885113420?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/4220030710885113420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=4220030710885113420' title='56 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/4220030710885113420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/4220030710885113420'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-09-barcodewiz-activex-control-20.html' title='MoAxB #09: BarCodeWiz ActiveX Control 2.0 (BarcodeWiz.dll) Remote Buffer Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>56</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-8003740235864430807</id><published>2007-05-08T10:26:00.000-07:00</published><updated>2007-05-08T01:26:21.946-07:00</updated><title type='text'>MoAxB #08: SmartCode VNC Manager 3.6 (scvncctrl.dll) Denial of service</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;-----------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt; SmartCode VNC Manager 3.6 (scvncctrl.dll) Denial of service&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt; url: http://www.s-code.com/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt; price: from $98.94 to $2,500&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt; author: shinnai&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt; mail: shinnai[at]autistici[dot]org&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt; site: http://shinnai.altervista.org&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt; Tested on Windows XP Professional SP2 all patched, with Internet Explorer 7 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;-----------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;La maggior parte dei metodi di questo activex sono vulnerabili a DoS. L'exploit&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;che riporto consente di controllare il contenuto di EAX e ECX ma lo scenario &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;varia a seconda della lunghezza della stringa passata.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Lo propongo come DoS ma non escludo la possibilità di trovare il modo di&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;eseguire codice arbitrario.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070508/scvncctrl.html"&gt;&lt;span style="font-family:courier new;"&gt;Dimostrazione online&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070508/scvncctrl.txt"&gt;&lt;span style="font-family:courier new;"&gt;Formato txt&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Ecco il contenuto dei registri al momento del crash&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EAX 61616161&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ECX 62626262&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDX 02DFECA0 ASCII "aaaabbbbBBB..." &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBX 02DF0000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESP 0173F068&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBP 0173F288&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESI 02DFEC98 ASCII "AAAAAAAAaaaabbbbBBB..."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDI 00000221&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EIP 7C92142E ntdll.7C92142E&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;7C92142E   8B39             MOV EDI,DWORD PTR DS:[ECX] &lt;-- CRASH&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-8003740235864430807?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/8003740235864430807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=8003740235864430807' title='20 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8003740235864430807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/8003740235864430807'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-08-smartcode-vnc-manager-36.html' title='MoAxB #08: SmartCode VNC Manager 3.6 (scvncctrl.dll) Denial of service'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>20</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7286383401440380066</id><published>2007-05-07T09:48:00.000-07:00</published><updated>2007-05-07T00:47:35.690-07:00</updated><title type='text'>MoAxB #07: Versalsoft HTTP File Uploader (UFileUploaderD.dll) 'AddFile' method Buffer Overflow</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;Riporto, in questo exploit, solo il contenuto dei registri visto che credo sia chiaro che l'esecuzione di codice arbitrario è possibile.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070507/ufile.html"&gt;&lt;span style="font-family:courier new;"&gt;Dimostrazione online&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070507/ufile.txt"&gt;&lt;span style="font-family:courier new;"&gt;Formato txt&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family:courier new;"&gt;11:40:51.172  pid=08E4 tid=0AB0  EXCEPTION (first-chance)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              Exception C0000005 (ACCESS_VIOLATION reading [41414141])&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              EBX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              ECX=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              EDX=7C9137D8: 8B 4C 24 04 F7 41 04 06-00 00 00 B8 01 00 00 00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              ESP=0173E26C: BF 37 91 7C 54 E3 73 01-84 F2 73 01 70 E3 73 01&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              EBP=0173E28C: 3C E3 73 01 8B 37 91 7C-54 E3 73 01 84 F2 73 01&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              ESI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              EDI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              EIP=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                            --&gt; N/A&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7286383401440380066?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7286383401440380066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7286383401440380066' title='57 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7286383401440380066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7286383401440380066'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-07-versalsoft-http-file-uploader.html' title='MoAxB #07: Versalsoft HTTP File Uploader (UFileUploaderD.dll) &apos;AddFile&apos; method Buffer Overflow'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>57</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7343182384586133860</id><published>2007-05-06T10:26:00.000-07:00</published><updated>2007-05-06T01:26:14.064-07:00</updated><title type='text'>MoAxB #06: Sienzo Digital Music Mentor (DMM) 2.6.0.4 (DSKernel2.dll) multiple method local Stack Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;DSKernel2.dll, distribuita con l'ultima versione del software in oggetto, contiene due metodi che sono vulnerabili ad uno stack-based overflow che consente l'esecuzione di codice arbitrario sul pc dell'utente.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;I metodi sono "LockModules" e "UnlockModule" ai quali, passando una stringa rispettivamente di 263 e 296 caratteri, causano lo stack overflow.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070506/sienzo.txt"&gt;Formato txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Il contenuto dei registri al momento del crash è:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;per "Lockmodules:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EAX 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ECX 7C92056D ntdll.7C92056D&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EDX 03CF0000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EBX 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ESP 0173E554 ASCII "BBB..."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EBP 41414141&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ESI 0173E560 ASCII "BBBB..."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EDI 00000600&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EIP 62626262&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;-----------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;per "UnlockModule":&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EAX 80070057&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ECX 02D56F1A UNICODE "         (((((                  H"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EDX 0173EC48&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EBX 02D3D250 DSKernel.02D3D250&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ESP 0173ED80 ASCII "BBB..."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EBP 41414141&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ESI 0173F064&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EDI 00000000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;EIP 62626262&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Il resto è storia...&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7343182384586133860?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7343182384586133860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7343182384586133860' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7343182384586133860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7343182384586133860'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-06-sienzo-digital-music-mentor.html' title='MoAxB #06: Sienzo Digital Music Mentor (DMM) 2.6.0.4 (DSKernel2.dll) multiple method local Stack Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-5487866453880368374</id><published>2007-05-05T11:55:00.000-07:00</published><updated>2007-05-05T02:56:40.630-07:00</updated><title type='text'>MoAxB #05: East Wind Software (advdaudio.ocx v. 1.5.1.1) 'OpenDVD' method Stack Buffer Overflow</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;Bene, volevo lasciare i bug più interessanti per la seconda metà del mese ma, siccome sta nascendo un putiferio (sul mio modo di parlare in inglese e sulle mie capacità tecniche), posto un exploit che sfrutta uno stack overflow causato dall'ocx per eseguire codice arbitrario su un pc.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070505/east.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070505/east.txt"&gt;Formato txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Analizziamo meglio lo scenario: al momento del crash la situazione dei registri è la seguente:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;14:51:52.171  pid=0A90 tid=0E40  EXCEPTION (first-chance)&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              Exception C0000005 (ACCESS_VIOLATION reading [616165E5])&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EAX=61616161: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBX=0174EDE0: 42 42 42 42 42 42 42 42-42 42 42 42 42 42 42 42&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ECX=000035D1: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDX=01750110: 6F 00 F2 00 ED F2 F2 00-ED F2 F2 00 ED F2 F2 00&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESP=0174EA40: 10 EB FF 02 1C EB 74 01-61 1E 94 7C 1C EB 74 01&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBP=0174EDB8: 42 42 42 42 42 42 42 42-42 42 42 42 42 42 42 42&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESI=00000008: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDI=02FE056E: 20 20 20 20 3C 2F 70 3E-0D 0A 20 20 20 20 20 20&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EIP=03D2187D: 8B 90 84 04 00 00 8D 88-7C 04 00 00 85 D2 7E 09&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;                            --&gt; MOV EDX,[EAX+00000484]&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;14:51:52.171  pid=0A90 tid=0E40  EXCEPTION (first-chance)&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              Exception C0000005 (ACCESS_VIOLATION reading [42424242])&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ECX=42424242: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDX=7C9137D8: 8B 4C 24 04 F7 41 04 06-00 00 00 B8 01 00 00 00&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESP=0174E670: BF 37 91 7C 58 E7 74 01-AC ED 74 01 74 E7 74 01&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBP=0174E690: 40 E7 74 01 8B 37 91 7C-58 E7 74 01 AC ED 74 01&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDI=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EIP=42424242: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;                            --&gt; N/A&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Come potete notare, l'errore avviene nel momento in cui si cerca di leggere il contenuto di EAX mentre, nel passo successivo, vediamo EIP sovrascritto con dati arbitrari.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Bene, la prima cosa da fare è passare ad EAX un "readable" address, così da superare la prima limitazione.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Passiamo allora 0x77D7AAEB call ESP (from user32.dll) e vediamo cosa succede ai registri:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;15:03:32.855  pid=0A98 tid=06E0  EXCEPTION (first-chance)&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              Exception C0000005 (ACCESS_VIOLATION reading [63636363])&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EAX=73E186D4: 00 00 00 00 84 6A DF 73-00 00 00 00 2E 3F 41 56&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBX=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ECX=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDX=7608F260: 10 05 46 03 FF FF FF FF-00 00 00 00 00 00 00 00&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESP=0174EDEC: 90 EB 03 59 EB 05 E8 F8-FF FF FF 4F 49 49 49 49&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBP=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESI=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDI=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EIP=42424242: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;                            --&gt; N/A&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;15:03:32.855  pid=0A98 tid=06E0  EXCEPTION (unhandled)&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              Exception C0000005 (ACCESS_VIOLATION reading [63636363])&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EAX=73E186D4: 00 00 00 00 84 6A DF 73-00 00 00 00 2E 3F 41 56&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBX=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ECX=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDX=7608F260: 10 05 46 03 FF FF FF FF-00 00 00 00 00 00 00 00&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESP=0174EDEC: 90 EB 03 59 EB 05 E8 F8-FF FF FF 4F 49 49 49 49&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EBP=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ESI=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EDI=41414141: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              EIP=42424242: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;                            --&gt; N/A&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;font-size:78%;"&gt;              ----------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Bingo! Ora controlliamo EIP e abbiamo in ESP il contenuto della shellcode, il resto è storia...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;That's all folks!&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-5487866453880368374?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/5487866453880368374/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=5487866453880368374' title='32 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/5487866453880368374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/5487866453880368374'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-05-east-wind-software.html' title='MoAxB #05: East Wind Software (advdaudio.ocx v. 1.5.1.1) &apos;OpenDVD&apos; method Stack Buffer Overflow'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>32</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-3197352899234194694</id><published>2007-05-04T11:48:00.000-07:00</published><updated>2007-05-05T02:52:49.516-07:00</updated><title type='text'>MoAxB #04 bonus: ActSoft DVD-Tools (dvdtools.ocx v. 3.8.5.0) Stack Overflow Exploit</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;Questo è semplicemente un bonus. Gli advisories originale sono questi:&lt;/span&gt;&lt;span style="text-decoration: underline;font-family:courier new;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/viewtopic.php?id=41&amp;t_id=30"&gt;http://www.shinnai.altervista.org/viewtopic.php?id=41&amp;amp;t_id=30&lt;/a&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.milw0rm.com/exploits/3307"&gt;http://www.milw0rm.com/exploits/3307&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;poi ne è stato pubblicato uno da Umesh Wanve per Windows 2000 SP4 Server English e            Windows 2000 SP4 Professional English qui:&lt;/span&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.milw0rm.com/exploits/3610"&gt;http://www.milw0rm.com/exploits/3610&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;e ora ne rilascio una versione per Windows XP Professional SP2.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070504/actsoft.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070504/actsoft.txt"&gt;Formato txt&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-3197352899234194694?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/3197352899234194694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=3197352899234194694' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/3197352899234194694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/3197352899234194694'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-04-bonus-actsoft-dvd-tools.html' title='MoAxB #04 bonus: ActSoft DVD-Tools (dvdtools.ocx v. 3.8.5.0) Stack Overflow Exploit'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>16</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-6281778696516748448</id><published>2007-05-04T09:10:00.000-07:00</published><updated>2007-05-04T00:12:10.729-07:00</updated><title type='text'>MoAxB #04: Office Viewer (OA.ocx v. 3.2) multiple methods DoS</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;Questo bug si commenta da solo e non ho molto da aggiungere se non che, vista la quantità di critiche mosse al mio inglese, che come avevo preannunciato e sottolineato era meno che scolastico (e vi assicuro che avrei sopportato molto di più critiche ai bug che non al mio modo di parlare in inglese), da ora scriverò gli advisories in italiano, mia madrelingua, così che, chi ne avrà voglia, se li tradurrà da sè.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070504/oa.html"&gt;Dimostrazione online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070504/oa.txt"&gt;Formato txt&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Ecco il contenuto dei registri al momento del crash dell'applicazione.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EAX 000EC484&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ECX 01642A44&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDX 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBX 0173EA68&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESP 0173EA3C&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBP 0173EC74&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESI 000F4241&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDI 039F0024 UNICODE "AAA..."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EIP 77527420 ole32.77527420&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;77527420   8501             TEST DWORD PTR DS:[ECX],EAX &lt;-- CRASH&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;Devo doverosamente ringraziare The Wanderer al quale ho rotto i cosiddetti per le traduzioni e che ora vede reso inutile il proprio lavoro. Mi spiace e cercherò di farmi perdonare ma, che diavolo, talvolta bisogna essere nazionalisti: sono Italiano, sono fiero di esserlo e chi vuol leggere quello che scrivo se lo traduca da sè o vada a farsi benedire.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-6281778696516748448?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/6281778696516748448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=6281778696516748448' title='23 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6281778696516748448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/6281778696516748448'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-04-office-viewer-oaocx-v-32.html' title='MoAxB #04: Office Viewer (OA.ocx v. 3.2) multiple methods DoS'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>23</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-2441204161657723302</id><published>2007-05-03T09:06:00.000-07:00</published><updated>2007-05-03T02:59:56.362-07:00</updated><title type='text'>MoAxB #03: WordViewer.ocx 3.2 multiple methods DoS</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;This component allows you to visualize, create and modify doc files.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Some methods are unable to handle exceptional conditions, and this causes the crash of the application that uses this component.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070503/doc.html"&gt;Online demonstration&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: courier new;" href="http://www.shinnai.altervista.org/moaxb/20070503/doc.txt"&gt;Text format&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;This is the content of registers when the crash happens:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EAX 003042D4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ECX 01642A24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDX 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBX 0173EA48&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESP 0173EA1C&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBP 0173EC54&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESI 00200169&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDI 03F2002C UNICODE "AAA..."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EIP 77527420 ole32.77527420&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;77527420 8501 TEST DWORD PTR DS:[ECX],EAX &lt;-- CRASH&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-2441204161657723302?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/2441204161657723302/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=2441204161657723302' title='143 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/2441204161657723302'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/2441204161657723302'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html' title='MoAxB #03: WordViewer.ocx 3.2 multiple methods DoS'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>143</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7830759429476397322</id><published>2007-05-02T09:26:00.000-07:00</published><updated>2007-05-03T02:59:35.045-07:00</updated><title type='text'>MoAxB #02: ExcelViewer.ocx 3.1 multiple methods DoS</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;This component allows you to visualize, create and modify xls files.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Some methods are unable to handle exceptional conditions, and this causes the&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;crash of the application that uses this component.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070502/xls.html"&gt;Online demonstration&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070502/xls.txt"&gt;Text version&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;This is the content of registers when the crash happens:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EAX 003042D4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ECX 01642A34&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDX 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBX 0173EA58&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESP 0173EA2C&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBP 0173EC64&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESI 00200169&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDI 03C20024 UNICODE "AAA..."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EIP 77527420 ole32.77527420&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;77527420   8501             TEST DWORD PTR DS:[ECX],EAX &lt;-- CRASH&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7830759429476397322?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7830759429476397322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7830759429476397322' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7830759429476397322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7830759429476397322'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-02-excelviewerocx-v-31-multiple.html' title='MoAxB #02: ExcelViewer.ocx 3.1 multiple methods DoS'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7549185167369921299</id><published>2007-05-01T12:24:00.000-07:00</published><updated>2007-05-03T02:58:34.552-07:00</updated><title type='text'>MoAxB #01: PowerPointViewer.ocx 3.1 multiple methods DoS</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;well, let's start the MoAxB with a DoS. This component allows you to visualize, &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;create and modify ppt files.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Some methods are unable to handle exceptional conditions, and this causes the &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;crash of the application that uses this component.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070501/ppt.html"&gt;Online demonstration&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.altervista.org/moaxb/20070501/ppt.txt"&gt;Text format&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;This is the content of registers when the crash happens:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EAX 000EC484&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ECX 01642A38&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDX 00000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBX 0173EA5C&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESP 0173EA30&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EBP 0173EC68&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ESI 000F4241&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EDI 039E0024 UNICODE "AAA..."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EIP 77527420 ole32.77527420&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;77527420   8501             TEST DWORD PTR DS:[ECX],EAX &lt;-- CRASH&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7549185167369921299?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7549185167369921299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7549185167369921299' title='24 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7549185167369921299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7549185167369921299'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/05/moaxb-01-powerpointviewerocx-31.html' title='MoAxB #01: PowerPointViewer.ocx 3.1 multiple methods DoS'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>24</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3801485324556381326.post-7936352721999945328</id><published>2007-04-19T10:29:00.000-07:00</published><updated>2007-05-02T02:51:15.868-07:00</updated><title type='text'>Month of ActiveX Bug announced</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;well, first of all sorry for my poor english then some informations about &lt;a href="http://en.wikipedia.org/wiki/ActiveX_control"&gt;activex controls from wikipedia&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;so I'm here and I'm proud to announce that on 2007 MAY will start the Month of ActiveX Bug (&lt;span style="font-weight: bold;"&gt;MoAxB&lt;/span&gt;).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;most of them are simple DoS (don't worry there are also some code execution) but that's because MoAxB has only a sense: to inform developers about the risk of using activex controls.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;naturally everyone's invited to post activex bug or to ask for information or simply to post comments.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Greetz to:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;my wife and my &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;            daughter&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt; for all the love they give to me and for their patience&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;in alphabetical order :)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;auron, GiampaZ, hawake, ppanico2, redeemer, rgod, str0ke, The Wanderer, wicker25 and to all I forgot to mention for their support and friendship.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;now be safe brothers, see you on 2007/05/01&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3801485324556381326-7936352721999945328?l=moaxb.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://moaxb.blogspot.com/feeds/7936352721999945328/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3801485324556381326&amp;postID=7936352721999945328' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7936352721999945328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3801485324556381326/posts/default/7936352721999945328'/><link rel='alternate' type='text/html' href='http://moaxb.blogspot.com/2007/04/month-of-activex-bug-announced.html' title='Month of ActiveX Bug announced'/><author><name>shinnai</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>11</thr:total></entry></feed>
