Skip to content

Commit 430511c

Browse files
author
jvazquez-r7
committed
Land rapid7#1937, @wchen-r7's fix for heap spray js code
2 parents fe32a74 + 081baad commit 430511c

11 files changed

+0
-13
lines changed

modules/exploits/windows/browser/aladdin_choosefilepath_bof.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -148,7 +148,6 @@ def ie_heap_spray(my_target, p)
148148
for (var i=1; i < 0x300; i++) {
149149
heap_obj.alloc(block);
150150
}
151-
var overflow = nops.substring(0, 10);
152151
|
153152

154153
js = heaplib(js, {:noobfu => true})

modules/exploits/windows/browser/crystal_reports_printcontrol.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -157,7 +157,6 @@ def ie_heap_spray(my_target, p)
157157
for (var i=1; i < 0x300; i++) {
158158
heap_obj.alloc(block);
159159
}
160-
var overflow = nops.substring(0, 10);
161160
|
162161

163162
js = heaplib(js, {:noobfu => true})

modules/exploits/windows/browser/hp_alm_xgo_setshapenodetype_exec.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -164,7 +164,6 @@ def ie_heap_spray(my_target, p)
164164
for (var i=1; i < 0x300; i++) {
165165
heap_obj.alloc(block);
166166
}
167-
var overflow = nops.substring(0, 10);
168167
|
169168

170169
end

modules/exploits/windows/browser/ibm_spss_c1sizer.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -150,7 +150,6 @@ def ie_heap_spray(my_target, p)
150150
for (var i=1; i < 0x300; i++) {
151151
heap_obj.alloc(block);
152152
}
153-
var overflow = nops.substring(0, 10);
154153
|
155154

156155
js = heaplib(js, {:noobfu => true})

modules/exploits/windows/browser/ie_execcommand_uaf.rb

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -234,8 +234,6 @@ def get_spray(t, js_code, js_nops)
234234
for (var i=1; i < 0x300; i++) {
235235
heap_obj.alloc(block);
236236
}
237-
238-
var overflow = nops.substring(0, 10);
239237
JS
240238
end
241239

modules/exploits/windows/browser/indusoft_issymbol_internationalseparator.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -174,7 +174,6 @@ def ie_heap_spray(my_target, p)
174174
for (var i=1; i < 0x300; i++) {
175175
heap_obj.alloc(block);
176176
}
177-
var overflow = nops.substring(0, 10);
178177
|
179178

180179
end

modules/exploits/windows/browser/inotes_dwa85w_bof.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -179,7 +179,6 @@ def ie_heap_spray(my_target, p)
179179
for (var i=1; i < 0x300; i++) {
180180
heap_obj.alloc(block);
181181
}
182-
var overflow = nops.substring(0, 10);
183182
|
184183

185184
end

modules/exploits/windows/browser/ms11_081_option.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,6 @@ def ie_heap_spray(my_target, p)
111111
for (var i=1; i < 0x300; i++) {
112112
heap_obj.alloc(block);
113113
}
114-
var overflow = nops.substring(0, 10);
115114
}
116115
|
117116

modules/exploits/windows/browser/ms13_009_ie_slayoutrun_uaf.rb

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -102,8 +102,6 @@ def heap_spray(my_target, p)
102102
for (var i=1; i < 0x300; i++) {
103103
heap_obj.alloc(block);
104104
}
105-
var overflow = nops.substring(0, 10);
106-
107105
|
108106

109107
js = heaplib(js, {:noobfu => true})

modules/exploits/windows/browser/novell_groupwise_gwcls1_actvx.rb

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -174,7 +174,6 @@ def ie_heap_spray(my_target, p)
174174
for (var i=1; i < 0x300; i++) {
175175
heap_obj.alloc(block);
176176
}
177-
var overflow = nops.substring(0, 10);
178177
|
179178

180179
end

0 commit comments

Comments
 (0)