⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 serv-u "mdtm"命令远程溢出分析.mht

📁 精华BBS贴子
💻 MHT
📖 第 1 页 / 共 5 页
字号:
   esp,=20
                        0FFFFF004h       =20
                        =
&nbsp;//=CE=AA=B1=BE=B5=D8=B1=E4=C1=BF=B7=D6=C5=E4=BF=D5=BC=E4<BR>.text:0=
041FAF1&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;push&nbsp; &nbsp;=20
                        eax<BR>.text:0041FAF2&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;add&nbsp;=20
                        &nbsp;&nbsp;&nbsp;esp, 0FFFFFC74h&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; =
&nbsp;//=CE=AA=B1=BE=B5=D8=B1=E4=C1=BF=B7=D6=C5=E4=BF=D5=BC=E4<BR>.text:0=
041FAF8&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;eax,=20
                        offset=20
                        =
unk_59C243&nbsp;&nbsp;//=D6=D8=D2=AA=B3=CC=D0=F2=D7=D4=D2=D1=B5=C4=D2=EC=B3=
=A3=B4=A6=C0=ED=BA=AF=CA=FD=C8=EB=BF=DA<BR>.text:0041FAFD&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;xor&nbsp; =
&nbsp;&nbsp;&nbsp;edx,=20
                        edx<BR>.text:0041FAFF&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;push&nbsp;=20
                        &nbsp; ebx<BR>.text:0041FB00&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;push&nbsp; &nbsp;=20
                        esi<BR>.text:0041FB01&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;push&nbsp;=20
                        &nbsp; edi<BR>.text:0041FB02&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;ebx,=20
                        [ebp+8]&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        =
&nbsp;//=B4=A6=C0=ED=B5=DA=D2=BB=B8=F6=B2=CE=CA=FD<BR>.text:0041FB05&nbsp=
; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;dword ptr=20
                        [ebp-4Ch], offset unk_5B8520&nbsp;=20
                        &nbsp;<BR>.text:0041FB0C&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;mov&nbsp;=20
                        &nbsp;&nbsp;&nbsp;[ebp-48h],=20
                        esp<BR><BR>.text:0041FB0F&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;[ebp-50h],=20
                        eax&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;//=D6=D8=D2=AA=BD=A8=C1=A2ERR=BD=E1=B9=B9=B5=C4=B5=DA=B6=FE=B8=F6=B3=
=C9=D4=B1<BR>&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=D2=B2=BE=CD=CA=C7=B3=CC=D0=F2=D7=D4=D2=D1=B5=C4=D2=EC=
=B3=A3=B4=A6=C0=ED=BA=AF=CA=FD=C8=EB=BF=DA<BR>.text:0041FB12&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;word ptr=20
                        [ebp-44h], 0<BR>.text:0041FB18&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;[ebp-38h],=20
                        edx<BR><BR>.text:0041FB1B&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;ecx, large=20
                        fs:0&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=D6=D8=D2=AA=B5=C3=B5=BD=C9=CF=D2=BB=B8=F6ERR=BD=E1=B9=
=B9=B5=D8=D6=B7<BR>.text:0041FB22&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;[ebp-54h],=20
                        ecx&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;//=BD=A8=C1=A2ERR=BD=E1=B9=B9=B5=C4=B5=DA=D2=BB=B8=F6=B3=C9=D4=B1<B=
R>.text:0041FB25&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;lea&nbsp; =
&nbsp;&nbsp;&nbsp;eax,=20
                        [ebp-54h]&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;//=B5=C3=B5=BD=B5=B1=C7=B0ERR=BD=E1=B9=B9=B5=C4=B5=D8=D6=B7(017AD28=
0)<BR>.text:0041FB28&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;large=20
                        fs:0, eax&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=B7=C5=B5=BDfs:[0]=D6=D0=A3=AC=D5=E2=D1=F9=C8=E7=B9=FB=
=D5=E2=B6=CE=B4=FA=C2=EB<BR>&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;=20
                        =
//=B3=F6=B4=ED=B5=C4=BB=B0=BE=CD=BB=E1=D6=B4=D0=D0ebp-50=C0=EF=B5=C4=B5=C4=
=BA=AF=CA=FD<BR>.text:0041FB2E&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;byte ptr=20
                        [ebp-55h], 0<BR>.text:0041FB32&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;byte ptr=20
                        [ebp-56h],=20
                        =
0<BR>/////////////////////////////////////////////////////<BR>=B3=CC=D0=F2=
=D5=FD=B3=A3=B5=C4=D5=BB=C7=E9=BF=F6=C8=E7=CF=C2:<BR>ebp-56=20
                        017AD27E 00<BR>ebp-55 017AD27F 00<BR>epb-54 =
017AD280=20
                        40<BR>ebp-53 017AD281 E2<BR>ebp-52 017AD282 =
7A<BR>ebp-51=20
                        017AD283 01 =
017AE240=B5=C4=D6=B5=D6=B8=CF=F2=C9=CF=D2=BB=B8=F6ERR=BD=E1=B9=B9<BR>ebp-=
50 017AD284=20
                        43<BR>ebp-4F 017AD285 C2<BR>ebp-4E 017AD286 =
59<BR>ebp-4D=20
                        017AD287 00=20
                        =
0059C243=CA=C7=B3=CC=D0=F2=D7=D4=D2=D1=B5=C4=D2=EC=B3=A3=B4=A6=C0=ED=BA=AF=
=CA=FD=C8=EB=BF=DA<BR><BR>///////////////////////////////////////////////=
/////<BR>.text:0041FB36&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;xor&nbsp; =
&nbsp;&nbsp;&nbsp;edx,=20
                        edx<BR>.text:0041FB38&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;mov&nbsp;=20
                        &nbsp;&nbsp;&nbsp;[ebp-74h], =
edx<BR>.text:0041FB3B&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;[ebp-70h],=20
                        edx<BR>.text:0041FB3E&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;mov&nbsp;=20
                        &nbsp;&nbsp;&nbsp;[ebp-6Ch], =
edx<BR>.text:0041FB41&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;[ebp-68h],=20
                        edx<BR>.text:0041FB44&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;mov&nbsp;=20
                        &nbsp;&nbsp;&nbsp;[ebp-64h], =
edx<BR>.text:0041FB47&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;[ebp-60h],=20
                        edx<BR>.text:0041FB4A&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;mov&nbsp;=20
                        &nbsp;&nbsp;&nbsp;[ebp-5Ch], edx&nbsp; &nbsp;=20
                        =
//=B1=BE=B5=D8=B1=E4=C1=BF=B8=F8=B3=F5=D6=B50<BR>.text:0041FB4D&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;push&nbsp; &nbsp;=20
                        7FFh<BR>.text:0041FB52&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;mov&nbsp;=20
                        &nbsp;&nbsp;&nbsp;eax, [ebp+0Ch]&nbsp; &nbsp;=20
                        =
//=B4=A6=C0=ED=B5=DA=B6=FE=B8=F6=B2=CE=CA=FD=D2=B2=BE=CD=CA=C7=C3=FC=C1=EE=
=D7=D6=B4=AE=B5=C4=B5=D8=D6=B7<BR>.text:0041FB55&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;add&nbsp; =
&nbsp;&nbsp;&nbsp;eax,=20
                        4&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;//=C8=A5=B3=FD=C3=FC=C1=EE=D7=D6=B4=AE=BF=AA=CD=B7=B5=C4MDTM<BR>.te=
xt:0041FB58&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;push&nbsp; &nbsp;=20
                        eax<BR>.text:0041FB59&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;lea&nbsp;=20
                        &nbsp;&nbsp;&nbsp;ecx,=20
                        [ebp-9FCh]<BR>.text:0041FB5F&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;push&nbsp; &nbsp;=20
                        ecx<BR>.text:0041FB60&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;call&nbsp;=20
                        &nbsp; sub_59BFB8&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=CF=E0=B5=B1=D3=DAstrncpy=B0=D1=C3=FC=C1=EE=BF=BD=B5=BD=
=B1=BE=B5=D8=B1=E4=C1=BFebp-9fch=D6=D0<BR>&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=B3=A4=B6=C8=B2=BB=B3=AC=B9=FD2KB<BR>.text:0041FB65&n=
bsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;add&nbsp; =
&nbsp;&nbsp;&nbsp;esp,=20
                        0Ch<BR>.text:0041FB68&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;lea&nbsp;=20
                        &nbsp;&nbsp;&nbsp;eax,=20
                        [ebp-9FCh]<BR>.text:0041FB6E&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;mov&nbsp; =
&nbsp;&nbsp;&nbsp;byte ptr=20
                        [ebp-1FDh], 0<BR>.text:0041FB75&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;push&nbsp; &nbsp;=20
                        eax<BR>.text:0041FB76&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;call&nbsp;=20
                        &nbsp; sub_4422A4&nbsp; &nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=B6=D4=D7=D6=B4=AE=BD=F8=D0=D0=D4=D9=D2=BB=B2=BD=B4=A6=
=C0=ED=C8=A5=B3=FDMDTM=D3=EB<BR>&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=C3=FC=C1=EE=D6=D0=BC=E4=B5=C4=C4=C7=B8=F6=BF=D5=B8=F1=
=A3=AC=C3=FC=C1=EE=BA=F3=C3=E6=B5=C4=BB=D8=B3=B5<BR>&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;=20
                        =
&nbsp;&nbsp;&nbsp;//=BB=B9=D2=AA=C5=D0=B6=CF=C3=FC=C1=EE=CA=C7=B7=F1=CE=AA=
=BF=D5<BR>.text:0041FB7B&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;cmp&nbsp; =
&nbsp;&nbsp;&nbsp;byte ptr=20
                        [ebp-9FCh], 0<BR>.text:0041FB82&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;pop&nbsp;=20
                        &nbsp;&nbsp;&nbsp;ecx<BR>.text:0041FB83&nbsp;=20
                        &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; =
&nbsp;&nbsp;=20
                        &nbsp;&nbsp;&nbsp;jnz&nbsp; =
&nbsp;&nbsp;&nbsp;short=20
                        =
loc_41FBB6&nbsp;&nbsp;//=BA=CF=B7=A8=B5=C4=BB=B0=CC=F8<BR><BR>[2]=20

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -