Finding a Return Address
This Return Address would be written in the EIP and used to direct the application to where our payload will be located! Mona.py would be used for this as well.
Listing all modules
!mona modules
Analyzing Output

Locating OpCode syscall
Generating OpCode

Finding JMP ESP

Hitting Offset
Setting breakpoint


returnAddress.py
Hitting breakpoint


Last updated
Was this helpful?