Chapter 10: Windows Shellcoding

  1. Heap spraying.
  2. js_be is big-endian byte ordering; js_le is little-endian.
  3. unescape()
  4. windbg -p 4566 /g
  5. False; da will display the memory location with ASCII encoding.
  6. False; code caves are composed of null bytes.
  7. --xp_mode allows our patched executable to run in Windows XP; BDF default behavior is to crash on XP systems due to the potential use of XP for sandboxing.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.