最近偶然看到一篇文章,《漏洞分析第一次--漏洞发现》,11年写的,作者当时还是新手,在大牛K_K的指导下完成。分析的是一个普通的栈溢出,原文地址在这里:a96K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3S2A6i4K6u0W2j5X3q4A6k6s2g2Q4x3X3g2U0L8$3#2Q4x3V1k6U0K9r3W2D9L8q4)9#2k6X3u0#2M7s2c8Q4x3V1k6A6N6r3g2E0i4K6u0r3k6o6f1@1x3r3j5@1x3K6V1@1j5U0j5&6z5e0g2V1j5K6x3&6x3X3k6X3j5e0m8U0i4@1f1K6i4K6R3H3i4K6R3J5i4@1f1%4i4K6W2o6i4K6S2n7i4@1f1#2i4@1q4q4i4K6S2o6i4@1f1#2i4K6V1H3i4K6S2q4i4@1f1^5i4K6R3%4i4@1q4m8i4@1f1#2i4@1t1%4i4@1t1I4i4@1f1@1i4@1t1&6i4K6W2r3i4@1f1#2i4K6S2r3i4K6V1%4i4@1f1#2i4K6R3^5i4@1t1H3i4@1f1@1i4@1t1^5i4K6R3H3i4@1f1@1i4@1u0m8i4K6W2n7i4@1f1#2i4K6V1H3i4@1q4r3i4@1f1#2i4K6S2r3i4K6V1I4i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1$3i4K6R3@1i4K6W2r3i4@1f1^5i4@1p5%4i4K6R3&6i4@1f1$3i4K6S2o6i4K6R3&6i4@1f1%4i4K6R3#2i4@1p5%4d9#2)9#2k6V1E0Q4c8e0N6Q4z5f1q4Q4z5o6c8Q4c8e0k6Q4z5o6m8Q4z5f1c8Q4c8e0S2Q4b7U0N6Q4b7f1k6Q4c8f1k6Q4b7V1y4Q4z5p5y4Q4c8e0g2Q4b7V1g2Q4z5o6S2Q4c8e0g2Q4b7e0c8Q4z5f1q4Q4c8e0k6Q4b7e0m8Q4z5o6S2Q4c8e0k6Q4b7V1q4Q4b7e0u0Q4c8e0g2Q4z5o6N6Q4b7V1q4Q4c8e0N6Q4b7U0q4Q4b7V1u0Q4c8e0g2Q4z5f1g2Q4z5p5u0Q4c8e0N6Q4z5f1q4Q4z5o6c8Q4c8e0k6Q4b7V1y4Q4z5p5k6Q4c8e0k6Q4b7U0c8Q4z5f1g2Q4c8e0W2Q4z5o6y4Q4b7V1c8Q4c8e0g2Q4z5p5k6Q4b7f1k6Q4c8e0c8Q4b7V1u0Q4b7e0g2Q4c8e0N6Q4z5e0c8Q4b7e0S2Q4c8e0k6Q4b7f1c8Q4b7e0c8Q4c8e0k6Q4z5e0k6Q4b7U0W2Q4c8e0g2Q4b7V1y4Q4z5p5k6Q4c8e0k6Q4z5f1c8Q4b7e0g2Q4c8e0g2Q4z5o6S2Q4z5o6k6Q4c8e0k6Q4z5f1g2Q4z5e0m8Q4c8f1k6Q4b7V1y4Q4z5p5y4Q4c8e0k6Q4z5o6W2Q4z5o6m8Q4c8e0c8Q4b7V1u0Q4b7e0g2Q4c8e0S2Q4z5o6N6Q4b7f1q4Q4c8e0g2Q4b7U0N6Q4b7U0q4Q4c8e0c8Q4b7U0W2Q4z5f1k6Q4c8e0S2Q4b7f1k6Q4z5e0g2Q4c8e0N6Q4z5f1c8Q4z5o6m8Q4c8e0g2Q4z5o6S2Q4z5o6k6Q4c8e0k6Q4z5f1g2Q4z5e0m8Q4c8e0c8Q4b7V1q4Q4z5o6k6Q4c8e0c8Q4b7U0S2Q4z5o6m8Q4c8e0c8Q4b7U0S2Q4b7f1q4Q4c8f1k6Q4b7V1y4Q4z5p5y4Q4c8e0g2Q4b7U0m8Q4b7U0q4Q4c8e0k6Q4z5e0S2Q4b7f1k6W2P5s2m8D9L8$3W2@1i4@1f1%4i4@1u0o6i4K6V1$3i4@1f1#2i4K6R3$3i4K6V1&6i4@1f1%4i4@1t1K6i4@1u0n7i4@1f1#2i4K6R3^5i4K6V1%4i4@1f1$3i4K6V1#2i4K6V1&6i4@1f1%4i4@1p5^5i4K6S2n7i4@1f1%4i4@1q4o6i4@1q4o6i4@1f1@1i4@1t1^5i4K6R3H3i4@1f1%4i4@1q4r3i4K6R3%4i4@1f1&6i4K6R3%4i4K6S2o6i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1&6i4K6R3J5i4@1p5K6i4@1f1@1i4@1t1^5i4@1q4m8c8h3q4K6P5b7`.`. RM to MP3 Converter 2.7.3.700的栈溢出漏洞。我下载了原作者的exploit,发现在windows xp sp3简体中文版下已经不能运行(当时分析的环境是windows xp sp2 en),并且在调试中发现缓冲区大小也和原作者的分析有差异(他用的是metasploit的一个小工具计算的),于是自己从头到尾分析了这个漏洞,并写出弹计算器的exploit。