• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

Exploiting “Vulnerable Server” for Windows 7

February 27, 2017 by BIlaal Williams 3 Comments

This is a tutorial I found which shows how to discover and test an exploit in Windows 7. The tutorial involves using a debugger to test an application that has been sent a buffer overflow and identify the spot in memory to place the shellcode. The tutorial doesn’t get too much into assembly and offers a pretty clear description when needed. There is also a tutorial to exploit Windows applications that have DEP using ROP (a topic that was touched on in Metasploit Unleashed in “Exploit Payloads-MSFrop”).

https://samsclass.info/127/proj/vuln-server.htm
https://samsclass.info/127/proj/rop.htm

Filed Under: Uncategorized, Week 07 Tagged With:

Reader Interactions

Comments

  1. Jason A Lindsley says

    February 28, 2017 at 9:29 pm

    Interesting Bilaal – did you give this a try? I’d be a little concerned with downloading a program that makes your image vulnerable, but I guess that’s similar to installing Metasploitable.

    Log in to Reply
    • Loi Van Tran says

      March 1, 2017 at 11:56 am

      Thanks Bilaal,

      I’m pretty sure this would come in handy when we try to the Operating Security class’ Windows 7 virtual machines. I will be sure to give it a try on my Windows 7 that is all patched with really no programs on it.

      Log in to Reply
  2. Mauchel Barthelemy says

    March 4, 2017 at 1:28 pm

    Interesting piece of discovery. I will give this a try on a virtual Windows 7 machine in my testing environment. But first, for how long these exploits have been around? Aren’t these vulnerabilities Microsoft should have already addressed by now?

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in