You are on page 1of 4

ShellCode

0x_1.
0x_2.
0x_3.ShellCode
0x_4.
0x_5.

0x_1.
OfficeAdobe
ReaderPDFKingSoftWPS
flashMedia
Playerm3u

ShellCode

0x_2.
ShellCode

0x_2.1

POC ShellCode
CVE
ShellCode
0x_2.2

file:///C|/Users/overflowexp/Desktop/----ShellCode.txt[2010/9/25 0:58:42]

0Day

API
ShellCodeAPIWinDbgCalls
StackAPIShellCode
API CreateFile,WriteFile,ReadFile,WinExec

0x_2.3.Office
OfficeShellCode
ShellCode ShellCode

ShellCode,

jmp esp0x7ffa4512(
Win7)12 45 fa 7f
ShellCode ShellCode

0x_2.4.PDF
Adobe ReaderPDFAdobe
PDFJavaScript IEsprayPDF
PDFShellCode ShellCode
"%u9090%feeb"IE
ShellCode PDFOffice
JavaScript ShellCode,CVE-2010-0188Adobe
Reader TiffShellCodeTiff
ShellCode TiffShellCode

file:///C|/Users/overflowexp/Desktop/----ShellCode.txt[2010/9/25 0:58:42]


0x_3.ShellCode
ShellCode

0x_3.1
CVE-2010-0188
Adobe ReaderAcrobatPDF
Adobe ReaderAcrobatTIFFlibtiff
TIFFPDF

CVE-2006-3459Adobe
CVE-2006-3459ShellCode
0x_3.2API

0x_3.3
Office(
)jmp esp ,pop ret
0x_3.4PDFShellCodePDFShellCode
PDFJavaScriptShellCodeShellCode
2ShellCode PDFPDFJavaScript
(Adobe Reader ---JavaScript-JavaScript)PDF
ShellCode,PDF ShellCodePDF
PDF PDF
ShellCode (obj)
JavaScriptShellCodeJavaScript

ShellCode
PDF
0x_4.

file:///C|/Users/overflowexp/Desktop/----ShellCode.txt[2010/9/25 0:58:42]

Office-PPTMS-09-017,CVE-2009-0556

PDFCVE-2009-0027,PDFgetIcon() JavaScript

http://bbs.kanxue.com/showthread.php?p=692925
ShellCodeJavaScriptAcroBat---
JavaScriptJavaScriptShellCode
ShellCode,ShellCode

0x_5.
ShellCode
ShellCode
ShellCode
ShellCode
MS-09-017-ppt300501cd
EXP

2010-09-25 1

file:///C|/Users/overflowexp/Desktop/----ShellCode.txt[2010/9/25 0:58:42]

You might also like