begood Posted May 15, 2010 Report Posted May 15, 2010 # Title: Safari 4.0.5 parent.close() Memory Corruption exploit (w/ASLR and DEP bypass) # EDB-ID: 12614 # CVE-ID: () # OSVDB-ID: () # Author: Alexey Sintsov # Published: 2010-05-15 # Verified: no # Download Exploit Code# Download N/A Download:http://www.exploit-db.com/sploits/safari_parent_close_sintsov.zipUnzip and run START.htmThis exploit use JIT-SPRAY for DEP and ASLR bypass.jit-shellcode: system("notepad")0day.html - use 0x09090101 address for CALL JITed shellcode.START.htm -> iff.htm -> if1.htm -> 0day.html| || |JIT-SPRAY parent.close();0x09090101 - JITed * ESI=0x09090101shellcode * CALL ESIBy Alexey SintsovfromDigital Security Research Group[/"]www.dsecrg.com] Quote