TraceExploit
21 Aug 2010 Yongchuan Koh explot format protocol replay
The Discoverer module (see zhongjie’s blog entry) has been completed.
It consists of 2 programs, the Format Discovery and Pre-Replay processing.
Format Discovery is pretty much what i’ve blogged about in my earlier post.
Since that entry, I’ve completed the to-do tasks:
-
have a function to summarise all output for this program.
-
solve a memory leak problem in this program.
-
match replay packet to format, and if length segment changes (eg: due to shellcode change), then length field needs to change.