3 ms·
I've read all the text yesterday and still don't see an explanation how code is executed. I know Windows atom tables as a feature used in DDE (say for clipboard
by cm3 10y ago
I've read all the text yesterday and still don't see an explanation how code is executed. I know Windows atom tables as a feature used in DDE (say for clipboard infrastructure), and it's been there like forever, but how is the code from the table executed?
- saganus 10y agoIn the research paper there's a bit more of an explanation. I really can't explain it since I'm no expert but I believe the relevant bit is this: "...a new exploitation technique was invented solely to bypass DEP: ROP – Return Oriented Programming. How can we use ROP to our advantage in order to execute our shellcode in the target process? We can copy our code to an RW code cave in the target process (using the method described in stage 1). Then use a meticulously crafted ROP chain to allocate RWX memory, copy the code from the RW code cave to the newly allocated RWX memory, and finally jump to the RWX memory and execute it." Then a bit later it says: "This syscall will set the context (register values) of hThread to the values contained in lpContext. If we can get the target process to call this syscall with an lpContext that will set ESP to point to our ROP chain and set EIP to point to ZwAllocateVirtualMemory, then our ROP chain will execute. The execution of the ROP chain will eventually lead to the execution of our shellcode."
- cm3 10y agoThanks, I need to reread it, because I'm not sure who invokes the syscall. Quite possibly it's automated via an innocuous looking DDE invocation. Basically, I'm wondering what piece of code writes to the table and then makes some other aimed for application run the code from the table. If it's a piece of code that's already running as the same user, then the aim must be to make a higher privileged application to execute the code from the table. Need to brush up my Win32 knowledge to make sense of it, I guess.