<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Binary Exploitation on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/binary-exploitation/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Mon, 06 Jun 2022 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/binary-exploitation/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Rainbow2</title><link>https://wearethebug.dev/posts/vl-rainbow2/</link><pubDate>Mon, 06 Jun 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow2/</guid><description>Rainbow2 is a Hard Windows machine centered around exploit development for a custom network file-sharing service. Initial enumeration reveals anonymous FTP access and an unknown service listening on TCP port 2121. The FTP share exposes the vulnerable service binary, a developer README, and a copy of SysWOW64\kernel32.dll. The README confirms that the service was rebuilt with ASLR, DEP, and GS enabled. Static and dynamic analysis then shows that the service is still vulnerable to a format string issue and a stack-based overflow that overwrites the SEH chain. The format string leak provides a reliable ASLR bypass by disclosing a pointer inside filesrv.exe; the SEH overwrite provides control of the exception handler; and a ROP chain calls VirtualAlloc to bypass DEP. Privilege escalation is achieved by abusing SeDebugPrivilege to migrate into a SYSTEM process.</description></item></channel></rss>