Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
MOEW — Whitepaper | Kitploit
Tools/GitHubGitHub/harryeetsource/moew
Defensive ToolsExploitationReverse EngineeringDebuggersMalware AnalysisLearning & EducationBinary Exploitation
GitHubharryeetsource/moew

MOEW

Whitepaper

View Repository
1621310 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Invisible Threats, Visible Solutions.

Misaligned Opcode Exception Waterfall (MOEW)

3‑Stage SEH Waterfall PoC (Benign, x86/Wow64)

TL;DR: This PoC demonstrates a 3‑stage Structured Exception Handling (SEH) cascade caused by deliberate misaligned execution into raw byte blobs whose first valid instruction is a faulting div reg with a zero divisor.
Each exception stage installs the next SEH handler, triggers a new misaligned divide‑by‑zero, and executes a benign observable payload before restoring the original SEH chain and terminating cleanly.


1. Overview

MOEW (Misaligned Opcode Exception Waterfall) is a defensive research sample that showcases controlled exception‑driven multi‑stage execution on x86/Wow64 Windows. It demonstrates:

  • Manual SEH chain manipulation via fs:[0]
  • Deliberate misalignment into hand‑crafted byte sequences (blob1, blob2, blob3)
  • Stage‑chained SEH handlers
  • Multi‑fault recursion through:
    • KiUserExceptionDispatcher
    • RtlDispatchException
    • Custom user‑mode handlers
  • A clean termination path that restores the original SEH chain

All payloads are benign:

  • Stage 1: Launches Notepad
  • Stage 2: Writes a marker file to %TEMP%
  • Final Stage: Launches Calculator

The PoC is intentionally defanged. No data is encrypted, modified, or destroyed.


2. Features

  • Fully deterministic SEH recursion through 3 staged handlers
  • Naked x86 byte blobs with multiple valid decode paths
  • Misaligned div at controlled offsets (ECX/EDX/EBX = 0)
  • Per‑stage global counter for logging and tracing
  • Complete restoration of the original SEH head (ORIGINAL_SEH)
  • Rust nightly + inline assembly + naked functions
  • Benign but visible “payloads” for telemetry and debugger testing

3. Environment Requirements

3.1 Architecture

  • x86 (32‑bit) only
  • Compiled with the MSVC toolchain
  • Runs on 64‑bit Windows under WoW64 as well

3.2 Rust Nightly

The PoC uses nightly‑only features:

#![feature(asm_experimental_arch)]
#![feature(naked_functions)]

Install the necessary components:

rustup toolchain install nightly
rustup target add i686-pc-windows-msvc --toolchain nightly

3.3 Disable SAFESEH

Since the PoC installs custom SEH handlers that are not present in the SAFESEH table, the linker must be instructed to disable SAFESEH validation.

Create .cargo/config.toml:

[target.i686-pc-windows-msvc]
rustflags = [
  "-C", "link-arg=/SAFESEH:NO",
]

4. Build Instructions

Build the binary:

cargo +nightly build --target i686-pc-windows-msvc --release

Output is located at:

target\i686-pc-windows-msvc\release\seh_waterfall.exe

5. Running the PoC

Execute:

seh_waterfall.exe

Expected control‑flow:

Stage 0 → misaligned blob1 → Stage 1 handler
Stage 1 → misaligned blob2 → Stage 2 handler
Stage 2 → misaligned blob3 → Final handler
Final  → restore SEH       → exit

Visible artifacts:

  • notepad.exe launches (Stage 1)
  • %TEMP%\moew_stage2.txt is created (Stage 2)
  • calc.exe launches (Final handler)

6. Technical Breakdown

6.1 SEH Record Layout

On 32‑bit Windows, SEH records form a linked list stored at fs:[0]:

#[repr(C)]
struct SehRec {
    next: *mut SehRec,
    handler: usize,
}

Each handler uses the standard SEH signature:

extern "system" fn handler(
    record: *mut u8,
    frame: *mut u8,
    context: *mut u8,
    dispatcher: *mut u8,
) -> i32

6.2 Global State

static STAGE_COUNTER: AtomicU32 = AtomicU32::new(0);
static mut ORIGINAL_SEH: *mut SehRec = std::ptr::null_mut();

Used to:

  • Count handler recursion depth
  • Restore the original SEH head at the end of the waterfall

7. Stage Logic

Stage 0 — Initial Frame Setup

  1. Save fs:[0] as ORIGINAL_SEH.
  2. Build an SEH record pointing to the Stage 1 handler.
  3. Overwrite fs:[0] with this new record.
  4. Misalign into blob1 + 5, which decodes as div ecx (after setting ECX = 0).

Stage 1 — First SEH Handler

  1. Launch notepad.exe.
  2. Build an SEH record for the Stage 2 handler and chain it on top.
  3. Misalign into blob2 + 3 → div edx (with EDX = 0).

Stage 2 — Second SEH Handler

  1. Write %TEMP%\moew_stage2.txt.
  2. Install the Final handler on the SEH chain.
  3. Misalign into blob3 + 3 → div ebx (with EBX = 0).

Final Handler — Termination

  1. Launch calc.exe.
  2. Restore ORIGINAL_SEH into fs:[0].
  3. Exit the process cleanly via process::exit(0).

8. Misaligned Fault Blobs

8.1 blob1

#[unsafe(naked)]
pub extern "C" fn blob1() {
    naked_asm! {
        ".byte 0xB8, 0x10, 0x00, 0x00, 0x00", // mov eax, 0x10
        ".byte 0xF7, 0xF1",                   // div ecx
        ".byte 0xC3",                         // ret
        ".byte 0x90, 0x90, 0x90",             // nop padding
    }
}
  • Aligned decode: mov eax, 0x10; div ecx; ret
  • Misaligned at +5: div ecx (with ECX = 0 → #DE)

8.2 blob2

#[unsafe(naked)]
pub extern "C" fn blob2() {
    naked_asm! {
        ".byte 0x55",                         // push ebp
        ".byte 0x8B, 0xEC",                   // mov ebp, esp
        ".byte 0xF7, 0xF2",                   // div edx
        ".byte 0xC3",                         // ret
        ".byte 0x90, 0x90, 0x90",             // nop padding
    }
}
  • Aligned decode: push ebp; mov ebp, esp; div edx; ret
  • Misaligned at +3: div edx (with EDX = 0 → #DE)

8.3 blob3

#[unsafe(naked)]
pub extern "C" fn blob3() {
    naked_asm! {
        ".byte 0x53",                         // push ebx
        ".byte 0x8B, 0xD8",                   // mov ebx, eax
        ".byte 0xF7, 0xF3",                   // div ebx
        ".byte 0xC3",                         // ret
        ".byte 0x90, 0x90, 0x90",             // nop padding
    }
}
  • Aligned decode: push ebx; mov ebx, eax; div ebx; ret
  • Misaligned at +3: div ebx (with EBX = 0 → #DE)

9. Exception Pipeline

Each faulted stage re‑enters the Windows user‑mode exception pipeline:

KiUserExceptionDispatcher
    → RtlDispatchException
        → SEH chain walk (fs:[0])
            → MOEW handler

Typical debugger view:

seh_waterfall!blobX+offset
ntdll!KiUserExceptionDispatcher
ntdll!RtlDispatchException
seh_waterfall!stageN_handler

The waterfall is entirely driven by genuine hardware faults and SEH dispatch; no synthetic or fake exceptions are used.


10. Marker File Output

The file written in Stage 2 looks like:

MOEW Stage 2 Marker
-------------------
This file was written by the Stage 2 SEH handler
as a benign demonstration payload.

Its presence in %TEMP% serves as a simple, observable proof that Stage 2 executed via the SEH chain.


11. Safety Notes

  • PoC is benign and for defensive research only.
  • No persistence, registry modification, or encryption.
  • All exceptions are caught and handled.
  • The original SEH chain is restored before termination.

12. Future Enhancements

Potential extensions include:

  • YARA and behavioral rules for SEH waterfalls and recursive exception patterns.
  • ETW / EDR signal mapping for staged hardware faults.
  • Graphical diagrams of SEH chain evolution over time.
  • Side‑by‑side comparison with real‑world malware exception chains.

13. Full Source Code

The complete PoC implementation is available in this repository (see src/main.rs).


14. License

This project is intended for defensive research and education. Copyright <2025>

Download Tool