Full disclousure deep technical analisys below. Beware !!!

Jan 20, 2010

IE 0day CVE-2010-0249 – Exploiting the mass… – Part 2

EXPLOITER STAGE

Let’s see the exploiter..

The ie.html file that exploit IE CVE2010-0249 vulnerability

exploit

has an obfuscated piece in var sss

ie.html-obf

that once decoded reveal deobfuscation step needed for decoding external data in what.jpg  file (referenced by VAR AH01 to AH06)

ie.html-decr

to produce the working shellcode (here not yet unescaped):

sc-decrypt

No comments:

Post a Comment