Bypass ASLR+NX Part 2
data:image/s3,"s3://crabby-images/66522/66522e431bdd09d2073c5cd06b99fd43c8f1337a" alt="Image"
hi guys today we will continue in ways to bypass ASLR and NX if you dont know what means please read Part 1 will will find way to control EIP and in this part we will focus on another technique called Ret2eax. before going to explain it we need to understand what EAX and what it's purpose in program. EAX is general purpose register used in arithmetic calc and store results of arithmetic operations and function return value , like C built in function strcpy will save string pointer in EAX without assign it EAX will save pointer to buffer . we will take example to login system use strcmp to compare between two strings return 0 if two strings are same or return 1 if not equal . run it simple program user enter password compare it using strcmp you notice that strcmp we compare it to 0 if condition True i.e return 0 will print "you Login in" else "Ops LOL"...