Sim Editor Stack Based Buffer Overflow

Last week I bought a SIM card reader. Along with it came the software for it. It was SIM Card Editor 6.6. You can download it from here. The app is pretty cool. You can manipulate the SIM card’s data with it. However I noticed something strange in this application. When we are loading file for example suppose with 4 β€œA” characters we would get the output as β€œΒͺΒͺ”. Just two characters will be displayed. When I gave the input as β€œ4141” the result would be β€œAA”. This time the correct output we need. What was the reason for this? From what I noticed was that when we enter β€œAAAA” the hex values would be β€œ\x41\x41\x41\x41” the app will take two values each and evaluate to hex.

View post on imgur.com

When we give the input as β€œ4141” this is what happens.

View post on imgur.com

So suppose we want to enter a hex string we have to just give the input. For example we want to give the application β€œAA” we have to give just β€œ4141”. Taking that into consideration the rest was easy. The return address is overwritten with our buffer.

buff = "41" * 500
with open("ex.sms", 'w') as f:
    f.write(buff)

(more…)