Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2015-6086 — PoC for CVE-2015-6086 | Kitploit
ツール/GitHubGitHub/payatu/cve-2015-6086
脆弱性分析エクスプロイトウェブアプリケーション悪用学習と教育バイナリエクスプロイトラボと実践
GitHubpayatu/cve-2015-6086

CVE-2015-6086

PoC for CVE-2015-6086

リポジトリを見る
673210年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

クラッシュからエクスプロイトへ: CVE-2015-6086 - 境界外読み取り/ASLR バイパス

root@kitploit:~
 $$$$$$\  $$\    $$\ $$$$$$$$\       $$$$$$\   $$$$$$\    $$\  $$$$$$$\          $$$$$$\   $$$$$$\   $$$$$$\
$$  __$$\ $$ |   $$ |$$  _____|     $$  __$$\ $$$ __$$\ $$$$ | $$  ____|        $$  __$$\ $$$ __$$\ $$  __$$\
$$ /  \__|$$ |   $$ |$$ |           \__/  $$ |$$$$\ $$ |\_$$ | $$ |             $$ /  \__|$$$$\ $$ |$$ /  $$ |
$$ |      \$$\  $$  |$$$$$\ $$$$$$\  $$$$$$  |$$\$$\$$ |  $$ | $$$$$$$\ $$$$$$\ $$$$$$$\  $$\$$\$$ | $$$$$$  |
$$ |       \$$\$$  / $$  __|\______|$$  ____/ $$ \$$$$ |  $$ | \_____$$\\______|$$  __$$\ $$ \$$$$ |$$  __$$<
$$ |  $$\   \$$$  /  $$ |           $$ |      $$ |\$$$ |  $$ | $$\   $$ |       $$ /  $$ |$$ |\$$$ |$$ /  $$ |
\$$$$$$  |   \$  /   $$$$$$$$\      $$$$$$$$\ \$$$$$$  /$$$$$$\\$$$$$$  |        $$$$$$  |\$$$$$$  /\$$$$$$  |
 \______/     \_/    \________|     \________| \______/ \______|\______/         \______/  \______/  \______/

Copyright 2016 © Payatu Technologies Pvt. Ltd.

改行文字と空白文字の不適切な処理により、CDOMStringDataList::InitFromString で境界外読み取り (Out of Bound Read) が発生しました。 この欠陥を利用すると、MSHTML.DLL のベースアドレスを漏えいさせ、Address Space Layout Randomization を効果的にバイパスできます。

影響を受けるバージョン

  • Internet Explorer 9
  • Internet Explorer 10
  • Internet Explorer 11

テスト環境

  • IE: 10 & 11
  • KB: KB3087038
  • OS: Windows 7 SP1 x86

アドバイザリ

  • http://www.payatu.com/advisory-ie_cdomstringdatalist/
  • https://technet.microsoft.com/library/security/MS15-112
  • http://www.zerodayinitiative.com/advisories/ZDI-15-547/

ブログ記事

http://www.payatu.com/from-crash-to-exploit/

著者

Ashfaq Ansari

ashfaq[at]payatu[dot]com

@HackSysTeam | ブログ | null

Payatu Technologies

http://www.payatu.com/

実施されたワークショップ

  • From Crash to Exploit: CVE-2015-6086

http://hacksys.vfreaks.com

HackSys Team

ツールをダウンロード