|------------------------------------------------------------------| | __ __ | | _________ ________ / /___ _____ / /____ ____ _____ ___ | | / ___/ __ \/ ___/ _ \/ / __ `/ __ \ / __/ _ \/ __ `/ __ `__ \ | | / /__/ /_/ / / / __/ / /_/ / / / / / /_/ __/ /_/ / / / / / / | | \___/\____/_/ \___/_/\__,_/_/ /_/ \__/\___/\__,_/_/ /_/ /_/ | | | | http://www.corelan.be:8800 | | | |-------------------------------------------------[ EIP Hunters ]--| [+] IP2Location.dll v1.0.0.1 Initialize() Buffer Overflow [+] http://www.corelan.be:8800/advisories.php?id=CORELAN-10-044 [+] Tested on Windows XP SP3 + IE 6.0 + IP2Location.dll v1.0.0.1 [+] Found and coded by sinn3r - x90.sinner{at}gmail{d0t}c0m [+] http://twitter.com/_sinn3r [+] Special thanks to: corelanc0d3r and Sud0 Download the DLL, do a "regsvr32 IP2Location.dll", and run the proof of concept. When successful, this POC should pop up a MessageBox.