<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-5498266518143777458.post8090180487034277524..comments</id><updated>2009-12-26T09:39:05.949+01:00</updated><category term='msvc'/><category term='merging'/><category term='shellcode'/><category term='cloudburst'/><category term='dynamic binary instrumentation'/><category term='aslan'/><category term='mathcad'/><category term='mmmbop'/><category term='graphs'/><category term='instructions'/><category term='smb2'/><category term='kon-boot'/><category term='hacktro'/><category term='dbi'/><category term='static binary rewriting'/><category term='4514N'/><category term='detection'/><category term='mitigations'/><category term='loop analysis'/><category term='rop'/><category term='pin'/><category term='welding'/><category term='bypass'/><category term='useless'/><category term='eaf'/><category term='jit'/><category term='papers'/><category term='binary code manipulation'/><category term='paper'/><category term='dataflow'/><category term='ring0'/><category term='usb'/><category term='vmware'/><category term='basic block'/><category term='CFI'/><category term='disassembler'/><category term='evading network level emulation'/><category term='games'/><category term='emet'/><category term='autodiff'/><category term='ferrie is disgusted :-)'/><category term='pwnie awards'/><category term='asm'/><category term='life'/><category term='patents'/><category term='Control Flow Integrity'/><category term='matlab'/><category term='movie'/><category term='return-oriented programming'/><category term='problems'/><category term='integration'/><category term='spiderpig'/><category term='the fall'/><category term='binary analysis'/><category term='article'/><category term='statistics'/><category term='circuit theory'/><category term='mesh analysis'/><category term='exploit'/><category term='ksplice'/><category term='deadlock'/><category term='bindiff'/><category term='unpacking'/><title type='text'>Comments on Piotr Bania Chronicles &lt;br&gt;http://blog.piotrbania.com: SMB2: 351 Packets from the Trampoline released!</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.piotrbania.com/feeds/8090180487034277524/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default'/><link rel='alternate' type='text/html' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html'/><author><name>Piotr Bania</name><uri>http://www.blogger.com/profile/16139783712412229709</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5498266518143777458.post-5306574523231857794</id><published>2009-10-18T21:15:31.249+01:00</published><updated>2009-10-18T21:15:31.249+01:00</updated><title type='text'>@mish: no problem :-)</title><content type='html'>@mish: no problem :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/5306574523231857794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/5306574523231857794'/><link rel='alternate' type='text/html' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html?showComment=1255896931249#c5306574523231857794' title=''/><author><name>Piotr Bania</name><uri>http://www.blogger.com/profile/16139783712412229709</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html' ref='tag:blogger.com,1999:blog-5498266518143777458.post-8090180487034277524' source='http://www.blogger.com/feeds/5498266518143777458/posts/default/8090180487034277524' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1777124786'/></entry><entry><id>tag:blogger.com,1999:blog-5498266518143777458.post-7313682835075877770</id><published>2009-10-17T20:04:57.172+01:00</published><updated>2009-10-17T20:04:57.172+01:00</updated><title type='text'>Thank you for posting it, Piotr!  I didn&amp;#39;t see...</title><content type='html'>Thank you for posting it, Piotr!  I didn&amp;#39;t see it earlier, hence the late gratitude :-).&lt;br /&gt;&lt;br /&gt;--Mish</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/7313682835075877770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/7313682835075877770'/><link rel='alternate' type='text/html' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html?showComment=1255806297172#c7313682835075877770' title=''/><author><name>mish</name><uri>http://www.blogger.com/profile/13727369528689120304</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_6d-EnF19dKk/SYIZlWGzznI/AAAAAAAAAlY/LSZAb0OCUDk/S220/images.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html' ref='tag:blogger.com,1999:blog-5498266518143777458.post-8090180487034277524' source='http://www.blogger.com/feeds/5498266518143777458/posts/default/8090180487034277524' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1754275198'/></entry><entry><id>tag:blogger.com,1999:blog-5498266518143777458.post-4281688894568158773</id><published>2009-10-07T18:04:37.397+01:00</published><updated>2009-10-07T18:04:37.397+01:00</updated><title type='text'>@Rolf: Thanks man! :-)

@mish: Im glad u liked it....</title><content type='html'>@Rolf: Thanks man! :-)&lt;br /&gt;&lt;br /&gt;@mish: Im glad u liked it. I don&amp;#39;t think the &amp;quot;dump-proggie&amp;quot; is worth publishing and moreover i never thought someone would like to see it. It&amp;#39;s one of the tools you write in 5 mins just to proceed with another research step. Anyway im attaching a little code fragment perhaps it can help you a little. This one uses libdasm but any diassembler library will be fine. Of course it reads from the already dumped srv2.sys file (you can dump the memory contents in few different ways in example: by writing a windbg plugin and using ReadMemory, writing a windows device driver etc.). The addresses are hardcoded for SP2 AFAIR, and finally the code is ugly and shouldn&amp;#39;t be viewed by anyone :-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://piotrbania.com/all/smb_just_snap.c" rel="nofollow"&gt;http://piotrbania.com/all/smb_just_snap.c&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/4281688894568158773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/4281688894568158773'/><link rel='alternate' type='text/html' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html?showComment=1254935077397#c4281688894568158773' title=''/><author><name>Piotr Bania</name><uri>http://www.blogger.com/profile/16139783712412229709</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html' ref='tag:blogger.com,1999:blog-5498266518143777458.post-8090180487034277524' source='http://www.blogger.com/feeds/5498266518143777458/posts/default/8090180487034277524' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1777124786'/></entry><entry><id>tag:blogger.com,1999:blog-5498266518143777458.post-3904621811314277684</id><published>2009-10-06T03:20:24.052+01:00</published><updated>2009-10-06T03:20:24.052+01:00</updated><title type='text'>Good work, Piotr :-)</title><content type='html'>Good work, Piotr :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/3904621811314277684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/3904621811314277684'/><link rel='alternate' type='text/html' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html?showComment=1254795624052#c3904621811314277684' title=''/><author><name>Rolf Rolles</name><uri>http://www.blogger.com/profile/11281039521454183084</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html' ref='tag:blogger.com,1999:blog-5498266518143777458.post-8090180487034277524' source='http://www.blogger.com/feeds/5498266518143777458/posts/default/8090180487034277524' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-972865435'/></entry><entry><id>tag:blogger.com,1999:blog-5498266518143777458.post-2092533348308696067</id><published>2009-10-05T20:55:56.102+01:00</published><updated>2009-10-05T20:55:56.102+01:00</updated><title type='text'>Piotr,

I really enjoyed reading your guest post o...</title><content type='html'>Piotr,&lt;br /&gt;&lt;br /&gt;I really enjoyed reading your guest post on the Metasploit blog, congrats on the reliable exploit!&lt;br /&gt;&lt;br /&gt;I know you won&amp;#39;t share the exploit code, honestly I&amp;#39;m a novice and I&amp;#39;m not sure it would make too much sense to me.  But I am learning, and I thought if you could share the bit of code you wrote to enumerate the memory regions in SRV2.SYS that can be reached with the vulnerable function it would be pretty informative.  If not I understand, but it might make a(nother) good blog post :-).&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;--Mike</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/2092533348308696067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5498266518143777458/8090180487034277524/comments/default/2092533348308696067'/><link rel='alternate' type='text/html' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html?showComment=1254772556102#c2092533348308696067' title=''/><author><name>mish</name><uri>http://www.blogger.com/profile/13727369528689120304</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_6d-EnF19dKk/SYIZlWGzznI/AAAAAAAAAlY/LSZAb0OCUDk/S220/images.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.piotrbania.com/2009/10/smb2-351-packets-from-trampoline.html' ref='tag:blogger.com,1999:blog-5498266518143777458.post-8090180487034277524' source='http://www.blogger.com/feeds/5498266518143777458/posts/default/8090180487034277524' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1754275198'/></entry></feed>
