ShellcodeHandler Lsass HOD

Vulnerability

FIXME

Description

Reference

Analysis

Pattern

const char *lsasshodbindpcre = ".*(\\xEB\\x10\\x5A\\x4A\\x33\\xC9\\x66\\xB9\\x7D\\x01\\x80\\x34\\x0A\\x99\\xE2\\xFA\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\\x70\\x95\\x98\\x99\\x99\\xC3\\xFD.*\\x99\\xFA\\xF5\\xF6\\xEA\\xFC\\xEA\\xF6\\xFA\\xF2\\xFC\\xED\\x99).*";
const char *lsasshodconnectpcre = ".*(\\xEB\\x10\\x5B\\x4B\\x33\\xC9\\x66\\xB9\\x25\\x01\\x80\\x34\\x0B\\x99\\xE2\\xFA\\xEB\\x05\\xE8\\xEB\\xFF\\xFF\\xFF\\x70\\x62\\x99\\x99\\x99\\xC6\\xFD.*\\xF9\\x7E\\xE0\\x5F\\xE0).*";

Dependencies

 
documentation/modules/shellcodehandler/sch_lsass_hod.txt · Last modified: 2006/02/17 14:01
 
Recent changes RSS feed Creative Commons License Donate Powered by PHP Valid XHTML 1.0 Valid CSS Driven by DokuWiki