reverse shell ?
i use metasploit reverse shellcode . with exe format (./msfpayload ..... X > ...) my shell works very well in win 2k3 but when use shell in service bug in exploit doesn't work. 2k3 connect to random port . what's matter?
Wrong offset for the exploit itself?
There are a lot of reasons, what happens when you debug the issue?
i use exploit for 2k but i change return address for 2k3.
i find return address in dlls of application from olly & findjmp & other way.
how can i find exact return address in 2k3?
i use exploit with reverse shell on port xxxxx, but my server connect to other random port(yyyyy). why?
I already gave you another possible answer and asked you a question, you didn't check either one of em.
there is a point.
if the return address be wrong the session cant established, but in my test i have established connection but the port is wrong. i listen to port 5678 but the server connect to me with 34765 or other.
i use metasploit shells and test exe of shell on 2k3. it works well.
in other shell situation is same.
my server has stablished connection on other ports.
this is pop3 exploit .
1.bad charecters: i check exe of shell .it works. this reason fails.
2.wrong return address: i have established connection. this reason fails too.
3. other reasons?
You know that there is a difference between exe files and shellcode being injected?
Also what happens if you attach a debugger? That should tell you what is wrong.
i attach inetinfo.exe, get INT 3(ntdll!DbgBreakPoint) .
i use (g) command for run it but windbg suspend in busy mode.
i'm in mistake?
Well does your shellcode executed? Compare it to the shellcode you sent if it is the same or if something changed.
now test inetinfo.exe without shellcode in windbg, (BUSY and Debuggee is running) yet.
i do these:
1. i attache inetinfo.exe in windbg.
2.the result is INT 3 and program stop on DbgBreakPoint.
3.i use >g
4.the result is BUSY,Debuggee is Running.
5.then windbg stay in busy mode.
which 1 isn't true!?
It is really hard to understand you and you seem not to understand what I am asking you to try.