czwartek, 9 maja 2019

Crashing Alternate Pic View

This time I decided to check Alternate Pic View. Below you will find few details. Here we go...
We will start here:


TL;DR - here you can find the small pack with few fuzzed samples and windbg log file :)

#01 - User Mode Write AV
---
eax=0159ec5c ebx=0159463c ecx=00000006 edx=00ffffff esi=00000034 edi=0159463c
eip=00553b38 esp=0012f6fc ebp=0012f728 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010206
PicViewer!PerfgrapFinalize+0xa8868:
00553b38 895a04          mov     dword ptr [edx+4],ebx ds:0023:01000003=????????
---



#02 - Read Access Violation at the Instruction Pointer
---
eax=00994874 ebx=00000000 ecx=02546a61 edx=00000001 esi=0099fbfc edi=00000000
eip=c0000000 esp=0012f74c ebp=0012f7b4 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010206
c0000000 ??              ???
---


#03 - Exception Handler Chain Corrupted
---
eax=00000000 ebx=00000000 ecx=0056443d edx=776e660d esi=00000000 edi=00000000
eip=0056443d esp=0012ecec ebp=0012ed0c iopl=0         nv up ei pl zr na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010246
PicViewer!PerfgrapFinalize+0xb916d:
0056443d 0174d20f        add     dword ptr [edx+edx*8+0Fh],esi ds:0023:32e19684=????????
---

Described cases you will find here.

See you next time.

Cheers

Brak komentarzy:

Prześlij komentarz