| Newsgroups |
gmane.mail.blat |
| Message-ID |
<[email protected]> |
Hi,,
Sorry I used you email address for replying..
I am really happy to see such a an usefull tool, BLAT. Currently I was analyzing through a malicious blat.dll file in my customer environment due to its malicious activity..(due to an DLL Injection). my passion into sec has made me to go through some fuzzing on your legitimate files.
And I have found that when the below command is passed to blat.exe while installing, the program crashes with Access Violation.
blat.exe -install smtp.mydomain.com http://smtp.mydomain.com 127.0.0.1 -p <232 A's+2 B's+2 C's>
This causes the crash and overwrites EIP with 0x00430043 and EBP with 0x00420042. Even though I tried to write an exploit, as it is Unicode based one and unicode friendly PPR address couldn't be found.. So it failed (atleast for me)..
As there are many wrapper sripts available for installation and configuration of BLAT files (for noobs), this makes it dangerous.
As you know there are many corporate clients using your awesome tool BLAT.
please find the screenshot/POC attached.
looking forward to talk to you.. Have tested in Windows XP SP3.
thank you for the great tool..
Regards,
Vishnu Raju.