Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures |
|---|---|
| Date: | Tue, 26 Sep 2006 10:17:07 -0500 |
Nice work Aviv! All of these methods, along with a few extras, are implemented in the Metasploit 2.6 version of this module. Last I checked, not a single AV or IPS could pick it up. This module should work on every version and service pack of Windows. http://metasploit.com/projects/Framework/exploits.html#ie_vml_rectfill -HD On Tuesday 26 September 2006 09:04, avivra wrote:
I've used 5 simple methods, trying to evade being detected by the signature: 1) I've replaced the location where EIP should jump when the exploit is activated, with a different valid address. 2) I've replaced the VML element from "rect" with one of the other VML elements. 3) I've replaced the payload with a different valid shell code. 4) I've replaced the namespace key with a random key. 5) A combination of all of the above. Please note that when I changed the code using any of the methods, the exploit still worked.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures, avivra |
|---|---|
| Next by Date: | [Full-disclosure] [ GLSA 200609-14 ] ImageMagick: Multiple Vulnerabilities, Sune Kloppenborg Jeppesen |
| Previous by Thread: | [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures, avivra |
| Next by Thread: | Re: [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures, Dude VanWinkle |
| Indexes: | [Date] [Thread] [Top] [All Lists] |